Bug #80770 [NEW]: It is not possible to get client peer certificate with stream_socket_server
| From: | mcmic@php.net | Date: | Thu, 18 Feb 2021 16:11:25 +0000 |
| Subject: | Bug #80770 [NEW]: It is not possible to get client peer certificate with stream_socket_server | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-232257@lists.php.net to get a copy of this message | ||
From: mcmic
Operating system:
PHP version: 7.3.27
Package: OpenSSL related
Bug Type: Bug
Bug description:It is not possible to get client peer certificate with stream_socket_server
Description:
------------
It is not possible to get the client certificate when accepting TLS
connections, without forcing the client to provide a (valid)
certificate.
This forbids writing a fully compliant Gemini server in PHP, because it
is not possible to accept client certificates without forcing them on
all pages.
See https://www.openssl.org/docs/man1.0.2/man3/SSL_CTX_set_verify.html
Test script:
---------------
$context = stream_context_create(
[
'ssl' => [
'allow_self_signed' => true,
'SNI_enabled' => true,
'SNI_server_certs' => ['example.com' =>
'/path/to/cert.pem'],
'capture_peer_cert' => true,
]
]
);
$socket = stream_socket_server(
'tcp://[::]:' . $port,
$errno,
$errstr,
STREAM_SERVER_BIND | STREAM_SERVER_LISTEN,
$context,
);
if ($socket === false) {
throw new \Exception($errstr, $errno);
} else {
while ($conn = stream_socket_accept($socket, -1, $peername)) {
$tlsSuccess = stream_socket_enable_crypto(
$conn,
true,
STREAM_CRYPTO_METHOD_TLS_SERVER
);
if ($tlsSuccess !== true) {
fclose($conn);
continue;
}
var_dump(stream_context_get_options($conn));
}
}
Expected result:
----------------
Have the client certificate in 'peer_certificate' key of $conn, if the
client sends one.
Actual result:
--------------
No 'peer_certificate' option.
If I set 'verify_peer' to true, it works, but then it is not possible
for a client to connect without a certificate.
--
Edit bug report at https://bugs.php.net/bug.php?id=80770&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80770&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80770&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80770&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80770&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80770&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80770&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80770&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80770&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80770&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80770&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80770&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80770&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80770&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80770&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80770&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80770&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80770&r=mysqlcfg