Req #77108 [Com]: Use SNI with TLS
| From: | amontero at tinet dot org | Date: | Wed, 26 Jun 2019 15:02:15 +0000 |
| Subject: | Req #77108 [Com]: Use SNI with TLS | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221504@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77108&edit=1
ID: 77108
Comment by: amontero at tinet dot org
Reported by: christian at rishoj dot net
Summary: Use SNI with TLS
Status: Open
Type: Feature/Change Request
Package: IMAP related
Operating System: Ubuntu Linux
PHP Version: 7.2.11
Block user comment: N
Private report: N
New Comment:
Same here.
Also filed https://bugs.launchpad.net/ubuntu/+source/php-imap/+bug/1834340
Previous Comments:
------------------------------------------------------------------------
[2018-11-15 13:44:31] jcutting at enable dot services
This is can be replicated on stock Debian unstable and testing
------------------------------------------------------------------------
[2018-11-05 08:34:09] christian at rishoj dot net
Description:
------------
Using PHP 7.2.11 with OpenSSL 1.1.1, the IMAP extension fails to connect to Gmail.
Quoting from the bug tracker of Python's imaplib2, which was affected by the same issue:
> This is because [IMAP extension] does not support SNI, and Google returns an invalid
> certificate in that case.
>
> Some sites want to encourage the use of SNI and configure a default certificate that fails
> WebPKI authentication when the client supports TLS 1.3.
The IMAP extension should use SNI if TLS version is 1.3.
Actual result:
--------------
Error message when connecting to Gmail:
> RuntimeException: Certificate failure for imap.gmail.com: self signed certificate: /OU=No SNI
> provided; please fix your client./CN=invalid2.invalid
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77108&edit=1