Req #79280 [Com]: Add support for TLS-PSK

From: Date: Wed, 11 Mar 2020 22:40:31 +0000
Subject: Req #79280 [Com]: Add support for TLS-PSK
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226041@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79280&edit=1

 ID:                 79280
 Comment by:         rowan dot collins at gmail dot com
 Reported by:        php at tudorholton dot com
 Summary:            Add support for TLS-PSK
 Status:             Open
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   Irrelevant
 PHP Version:        Next Major Version
 Block user comment: N
 Private report:     N

 New Comment:

OK, looking at that library, it seems what they actually use to make HTTP requests is this library:
https://github.com/zendframework/zend-http

That in turn uses either PHP's curl bindings, or raw socket connections (with PHP's socket
library providing the TLS encapsulation).

So the PHP support which would be needed would be:

- an option for the tls:// stream type, which is based on openssl: https://www.php.net/manual/en/context.ssl.php
- an option in the curl bindings: https://www.php.net/manual/en/function.curl-setopt.php

I don't know what support either openssl or libcurl have for this, so I can't comment
further on how easy it would be to add.


Previous Comments:
------------------------------------------------------------------------
[2020-02-25 23:19:58] php at tudorholton dot com

The request is for a connection from PHP as a client to a server where the connection is encrypted
with TLS-PSK.  Yes, a shared key needs to be supplied for the connection to work.  I believe that
this is similar to PHP as a TLS client with a client certificate except that there's a shared
key in place of two separate certificates (and no third-party verifier).  I've seen TLS-PSK
used mainly in networks where a certificate authority is not available.

BareOS comes with a "WebUI" client which is where I got the example from.  The webui
client source is here:

https://github.com/bareos/bareos/tree/master/webui

There is also a non-PHP (C++) client which successfully uses TLS-PSK here:

https://github.com/bareos/bareos/tree/master/core/src/console

Every other part of this system defaults to TLS-PSK.  It's only the PHP part that can't do
it, which is why I submit this bug request.  Seems a bit odd to me.

------------------------------------------------------------------------
[2020-02-25 14:34:24] rowan dot collins at gmail dot com

It's unclear what PHP support is wanted here, because it's not clear how this tool needs
to interact with PHP. TLS connections *into* PHP are the responsibility of whatever web server you
put in front of it; TLS connections *from* PHP would generally be the responsibility of either an
extension like curl, or a stream wrapper (e.g. used with file_get_contents).

I'd not heard of TLS-PSK before, so I'm not clear how it is used in practice, but my guess
would be that you'd need a way to specify the pre-shared key to use for a particular
connection. Does this tool come with a PHP client of some sort, which would need this to connect
over TLS?

------------------------------------------------------------------------
[2020-02-19 00:43:26] php at tudorholton dot com

I couldn't find any mention of it in the php documentation (positive or otherwise).

------------------------------------------------------------------------
[2020-02-19 00:35:04] php at tudorholton dot com

Description:
------------
According to the current example config of BareOS Backup Management System
(https://github.com/bareos/bareos/blob/bddd6c0b853e94cb9c06464d9ba8bbe562042a01/webui/install/bareos/bareos-dir.d/console/admin.conf.example#L10):

...php does not support TLS-PSK...

Why is this?  Is it possible to add it as a configuration option?



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79280&edit=1


Thread (9 messages)

« previous php.bugs (#226041) next »