Req #70939 [Com]: socket_import_stream does not indicate missing support for SSL

From: Date: Fri, 05 Feb 2021 00:07:41 +0000
Subject: Req #70939 [Com]: socket_import_stream does not indicate missing support for SSL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231956@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70939&edit=1

 ID:                 70939
 Comment by:         bugs dot php at codifier dot nl
 Reported by:        lcharron at meditech dot com
 Summary:            socket_import_stream does not indicate missing
                     support for SSL
 Status:             Open
 Type:               Feature/Change Request
 Package:            Sockets related
 Operating System:   Any
 PHP Version:        5.5.30
 Block user comment: N
 Private report:     N

 New Comment:

This still appears to an issue (at least in PHP 7.3.26). However, I may have found a workaround,
albeit a convoluted one and one of which I still don't know the full implications for. I still
need to do more testing to actually see what my workaround means for the actual state of the
low-level socket, that now can be acquired with socket_import_stream(), and the stream's
encryption state when fiddling with the low-level socket. 

==========
WARNING
Because this involves security-sensitive stuff, USE THIS AT YOUR OWN RISK and thoroughly test it, to
verify that the intended encryption is not broken!
==========

Here's my temporary workaround:

----------

$host = "host";
$port = "443";
$stream = stream_socket_client( "ssl://{$host}:{$port}" );

stream_socket_enable_crypto( $stream, false );
$socket = socket_import_stream( $stream );
var_dump( gettype( $socket ) ); // string(8) "resource"

// If the stream is blocked, it needs to be temporarily unblocked first,
// otherwise you'll get the warning: SSL/TLS already set-up for this stream
// See https://github.com/php/php-src/blob/3e01f5afb1b52fe26a956190296de0192eedeec1/ext/openssl/xp_ssl.c#L1635
$blocked = stream_get_meta_data( $stream )[ 'blocked' ];
if( $blocked ) {
  stream_set_blocking( $stream, false );
}
// Be sure to apply the correct $crypto_type, if you've used a different one before
stream_socket_enable_crypto( $stream, true, STREAM_CRYPTO_METHOD_ANY_CLIENT );
// Maybe re-apply blocking
if( $blocked ) {
  stream_set_blocking( $stream, true );
}

----------


Previous Comments:
------------------------------------------------------------------------
[2020-01-13 10:36:56] alex dot bucher at myposter dot de

Hi There,
4 Years later - any updates / workarounds for this?

just hitting the Problem with 
https://github.com/php-amqplib/php-amqplib/issues/371


currently adding TICKS and a tickhandler as a workaround, but that's not a really nice
solution...

------------------------------------------------------------------------
[2016-02-23 10:02:59] adrian dot sandu at asandu dot eu

Someone recommended:

$socket = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
socket_set_option($socket, SOL_SOCKET, SO_KEEPALIVE, 1);
socket_connect($socket, $host, $port);

------------------------------------------------------------------------
[2016-02-22 17:52:43] lcharron at meditech dot com

I could find no work around.

------------------------------------------------------------------------
[2016-02-21 19:47:19] adrian dot sandu at asandu dot eu

Any updates/workarounds ?

------------------------------------------------------------------------
[2015-12-12 18:16:24] contact at sshilko dot com

Same issue, i thought its "by design", at the moment there is no option to enable
SO_KEEPALIVE when using stream_socket_client() with SSL/TLS

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70939


--
Edit this bug report at https://bugs.php.net/bug.php?id=70939&edit=1


Thread (7 messages)

« previous php.bugs (#231956) next »