Req #77108 [Opn->Nab]: Use SNI with TLS

From: Date: Fri, 30 Aug 2019 10:21:23 +0000
Subject: Req #77108 [Opn->Nab]: Use SNI with TLS
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222491@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77108&edit=1

 ID:                 77108
 Updated by:         requinix@php.net
 Reported by:        christian at rishoj dot net
 Summary:            Use SNI with TLS
-Status:             Open
+Status:             Not a bug
 Type:               Feature/Change Request
 Package:            IMAP related
 Operating System:   Ubuntu Linux
 PHP Version:        7.2.11
 Block user comment: N
 Private report:     N

 New Comment:

Closing per above.


Previous Comments:
------------------------------------------------------------------------
[2019-08-30 04:09:59] dzuelke at gmail dot com

This issue can be closed as "invalid", since it's not a bug in PHP.

FYI, Ubuntu's bionic-updates (and newer) now has a fixed libc-client2007e package.

------------------------------------------------------------------------
[2019-07-25 23:13:43] dzuelke at gmail dot com

This is a problem in the underlying UW IMAP client library (which is basically abandoned). There is
nothing that can be done on the PHP extension level.

------------------------------------------------------------------------
[2019-06-26 15:02:15] amontero at tinet dot org

Same here.
Also filed https://bugs.launchpad.net/ubuntu/+source/php-imap/+bug/1834340

------------------------------------------------------------------------
[2018-11-15 13:44:31] jcutting at enable dot services

This is can be replicated on stock Debian unstable and testing

------------------------------------------------------------------------
[2018-11-05 08:34:09] christian at rishoj dot net

Description:
------------
Using PHP 7.2.11 with OpenSSL 1.1.1, the IMAP extension fails to connect to Gmail.

Quoting from the bug tracker of Python's imaplib2, which was affected by the same issue:

> This is because [IMAP extension] does not support SNI, and Google returns an invalid
> certificate in that case. 
>
> Some sites want to encourage the use of SNI and configure a default certificate that fails
> WebPKI authentication when the client supports TLS 1.3.

The IMAP extension should use SNI if TLS version is 1.3.


Actual result:
--------------
Error message when connecting to Gmail:

> RuntimeException: Certificate failure for imap.gmail.com: self signed certificate: /OU=No SNI
> provided; please fix your client./CN=invalid2.invalid



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77108&edit=1


Thread (6 messages)

« previous php.bugs (#222491) next »