Bug #80770 [Opn->Ver]: It is not possible to get client peer certificate with stream_socket_server
| From: | daverandom@php.net | Date: | Thu, 18 Feb 2021 17:13:57 +0000 |
| Subject: | Bug #80770 [Opn->Ver]: It is not possible to get client peer certificate with stream_socket_server | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232265@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80770&edit=1
ID: 80770
Updated by: daverandom@php.net
Reported by: mcmic@php.net
Summary: It is not possible to get client peer certificate
with stream_socket_server
-Status: Open
+Status: Verified
Type: Bug
Package: OpenSSL related
PHP Version: 7.3.27
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2021-02-18 17:13:07] daverandom@php.net
My apologies, you are correct and I have actually now remembered encountering the same limitation a
few months ago. I do also have a (theoretical) work-around, which is to obtain the ClientHello
message (and potentially other traffic) via stream_socket_recvfrom() and STREAM_PEEK before calling
stream_socket_enable_crypto().
I think I even wrote a PoC partial implementation of it, I cannot find it at the moment but if I do
I will make a gist and link it here.
As for a proper fix for the issue, I have touched this code in the (distant) past and I from what I
remember it should be reasonably easy to optionally store a client certificate into the
stream's context during the peer verification callback, though I think this would not work if
peer verification was completely disabled. I'm not sure if this would be considered an
acceptable limitation.
------------------------------------------------------------------------
[2021-02-18 16:34:03] mcmic@php.net
See section 4.3 of https://gemini.circumlunar.space/docs/specification.html
for more information about client certificate use in Gemini protocol.
------------------------------------------------------------------------
[2021-02-18 16:32:20] mcmic@php.net
@daverandom:
The test you linked to is about getting the server certificate from the client, I want the other way
around, get the client certificate from the server.
And without making the client certificate mandatory, I still need to accept certificate-less
requests.
------------------------------------------------------------------------
[2021-02-18 16:26:58] daverandom@php.net
Ah no I think I see the problem, you need to pass $context instead of $conn to
stream_context_get_options()
------------------------------------------------------------------------
[2021-02-18 16:26:04] daverandom@php.net
Note that there is a test for this behaviour which is not marked as XFAIL, so I believe this
functionality should work - although I cannot immediately see an issue with your sample code
https://heap.space/xref/php-src/ext/openssl/tests/capture_peer_cert_001.phpt?r=1fab01be#38
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80770
--
Edit this bug report at https://bugs.php.net/bug.php?id=80770&edit=1