Bug #79501 [ReO]: TLS connections freezing on 7.4 (all versions after 7.3.17)

From: Date: Fri, 08 May 2020 11:41:24 +0000
Subject: Bug #79501 [ReO]: TLS connections freezing on 7.4 (all versions after 7.3.17)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226956@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79501&edit=1 ID: 79501 Updated by: cmb@php.net Reported by: imnieves at gmail dot com Summary: TLS connections freezing on 7.4 (all versions after 7.3.17) Status: Re-Opened Type: Bug -Package: *Encryption and hash functions +Package: OpenSSL related Operating System: Linux PHP Version: 7.4.5 Block user comment: N Private report: N New Comment: According to a comment on the PhpRedis issue[1] this might be an issue with our tlsv1.3 stream wrapper implementation: | […] because right now it looks like something may be wrong in | PhpRedis even if it just wraps php streams. [1] <https://github.com/phpredis/phpredis/issues/1726#issuecomment-625319182> Previous Comments: ------------------------------------------------------------------------ [2020-05-06 20:54:16] imnieves at gmail dot com In a separate method of testing, I constrained TLS versions of phpredis (instead of constraining TLS versions of nginx) In this way I have verified on php 7.4.5-fpm that TLS 1.2 results in consistent working connections. TLS 1.3 results in some connections that work and most other connections that fail. I can also say the cipher suite being used in all my TLS 1.3 connections (consistent and freezing): TLS_AES_256_GCM_SHA384 ------------------------------------------------------------------------ [2020-05-06 20:51:54] imnieves at gmail dot com I have verified that TLS 1.2 connections work consistently, while TLS 1.3 connections freeze (fail to establish) on PHP 7.4.5-fpm. On the other side of the testing, both TLS 1.2 and TLS 1.3 connections work consistently on PHP 7.3.17-fpm. To perform this test I put nginx in front of my Redis, disabled TLS on Redis entirely, and enabled TLS on nginx. I varied the TLS settings on nginx as follows: TLS 1.2 only, then TLS 1.3 only, then both TLS 1.2 and TLS 1.3. Interesting to note, when nginx has: only TLS 1.2, the connections always work only TLS 1.3, the connections always freeze both TLS 1.2 and TLS 1.3, the connections work for the first 5 attempts, and then one freezes. If I attempt another connection then the next 4 or 5 connections succeed and then another one freezes. And this cycle repeats. ------------------------------------------------------------------------ [2020-05-06 19:00:45] imnieves at gmail dot com I will investigate ------------------------------------------------------------------------ [2020-05-04 14:52:30] nikic@php.net One relevant difference that comes to mind is that PHP 7.4 will negotiate TLS 1.3 by default. Do you know which TLS version actually gets used? ------------------------------------------------------------------------ [2020-05-03 12:46:16] cmb@php.net Related To: Bug #79559 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79501 -- Edit this bug report at https://bugs.php.net/bug.php?id=79501&edit=1

« previous php.bugs (#226956) next »