Req #77108 [Com]: Use SNI with TLS
Edit report at https://bugs.php.net/bug.php?id=77108&edit=1
ID: 77108
Comment by: dzuelke at gmail dot com
Reported by: christian at rishoj dot net
Summary: Use SNI with TLS
Status: Open
Type: Feature/Change Request
Package: IMAP related
Operating System: Ubuntu Linux
PHP Version: 7.2.11
Block user comment: N
Private report: N
New Comment:
This is a problem in the underlying UW IMAP client library (which is basically abandoned). There is
nothing that can be done on the PHP extension level.
Previous Comments:
------------------------------------------------------------------------
[2019-06-26 15:02:15] amontero at tinet dot org
Same here.
Also filed https://bugs.launchpad.net/ubuntu/+source/php-imap/+bug/1834340
------------------------------------------------------------------------
[2018-11-15 13:44:31] jcutting at enable dot services
This is can be replicated on stock Debian unstable and testing
------------------------------------------------------------------------
[2018-11-05 08:34:09] christian at rishoj dot net
Description:
------------
Using PHP 7.2.11 with OpenSSL 1.1.1, the IMAP extension fails to connect to Gmail.
Quoting from the bug tracker of Python's imaplib2, which was affected by the same issue:
> This is because [IMAP extension] does not support SNI, and Google returns an invalid
> certificate in that case.
>
> Some sites want to encourage the use of SNI and configure a default certificate that fails
> WebPKI authentication when the client supports TLS 1.3.
The IMAP extension should use SNI if TLS version is 1.3.
Actual result:
--------------
Error message when connecting to Gmail:
> RuntimeException: Certificate failure for imap.gmail.com: self signed certificate: /OU=No SNI
> provided; please fix your client./CN=invalid2.invalid
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77108&edit=1
Thread (6 messages)