Bug #79501 [ReO]: TLS connections freezing on 7.4 (all versions after 7.3.17)
| From: | cmb@php.net | Date: | Fri, 08 May 2020 11:41:24 +0000 |
| Subject: | Bug #79501 [ReO]: TLS connections freezing on 7.4 (all versions after 7.3.17) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226956@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79501&edit=1
ID: 79501
Updated by: cmb@php.net
Reported by: imnieves at gmail dot com
Summary: TLS connections freezing on 7.4 (all versions after
7.3.17)
Status: Re-Opened
Type: Bug
-Package: *Encryption and hash functions
+Package: OpenSSL related
Operating System: Linux
PHP Version: 7.4.5
Block user comment: N
Private report: N
New Comment:
According to a comment on the PhpRedis issue[1] this might be an
issue with our tlsv1.3 stream wrapper implementation:
| [â¦] because right now it looks like something may be wrong in
| PhpRedis even if it just wraps php streams.
[1] <https://github.com/phpredis/phpredis/issues/1726#issuecomment-625319182>
Previous Comments:
------------------------------------------------------------------------
[2020-05-06 20:54:16] imnieves at gmail dot com
In a separate method of testing, I constrained TLS versions of phpredis (instead of constraining TLS
versions of nginx)
In this way I have verified on php 7.4.5-fpm that TLS 1.2 results in consistent working connections.
TLS 1.3 results in some connections that work and most other connections that fail.
I can also say the cipher suite being used in all my TLS 1.3 connections (consistent and freezing):
TLS_AES_256_GCM_SHA384
------------------------------------------------------------------------
[2020-05-06 20:51:54] imnieves at gmail dot com
I have verified that TLS 1.2 connections work consistently, while TLS 1.3 connections freeze (fail
to establish) on PHP 7.4.5-fpm.
On the other side of the testing, both TLS 1.2 and TLS 1.3 connections work consistently on PHP
7.3.17-fpm.
To perform this test I put nginx in front of my Redis, disabled TLS on Redis entirely, and enabled
TLS on nginx. I varied the TLS settings on nginx as follows: TLS 1.2 only, then TLS 1.3 only, then
both TLS 1.2 and TLS 1.3.
Interesting to note, when nginx has:
only TLS 1.2, the connections always work
only TLS 1.3, the connections always freeze
both TLS 1.2 and TLS 1.3, the connections work for the first 5 attempts, and then one freezes. If I
attempt another connection then the next 4 or 5 connections succeed and then another one freezes.
And this cycle repeats.
------------------------------------------------------------------------
[2020-05-06 19:00:45] imnieves at gmail dot com
I will investigate
------------------------------------------------------------------------
[2020-05-04 14:52:30] nikic@php.net
One relevant difference that comes to mind is that PHP 7.4 will negotiate TLS 1.3 by default. Do you
know which TLS version actually gets used?
------------------------------------------------------------------------
[2020-05-03 12:46:16] cmb@php.net
Related To: Bug #79559
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79501
--
Edit this bug report at https://bugs.php.net/bug.php?id=79501&edit=1