Bug #80770 [Opn->Ver]: It is not possible to get client peer certificate with stream_socket_server

From: Date: Thu, 18 Feb 2021 17:13:57 +0000
Subject: Bug #80770 [Opn->Ver]: It is not possible to get client peer certificate with stream_socket_server
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232265@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80770&edit=1 ID: 80770 Updated by: daverandom@php.net Reported by: mcmic@php.net Summary: It is not possible to get client peer certificate with stream_socket_server -Status: Open +Status: Verified Type: Bug Package: OpenSSL related PHP Version: 7.3.27 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2021-02-18 17:13:07] daverandom@php.net My apologies, you are correct and I have actually now remembered encountering the same limitation a few months ago. I do also have a (theoretical) work-around, which is to obtain the ClientHello message (and potentially other traffic) via stream_socket_recvfrom() and STREAM_PEEK before calling stream_socket_enable_crypto(). I think I even wrote a PoC partial implementation of it, I cannot find it at the moment but if I do I will make a gist and link it here. As for a proper fix for the issue, I have touched this code in the (distant) past and I from what I remember it should be reasonably easy to optionally store a client certificate into the stream's context during the peer verification callback, though I think this would not work if peer verification was completely disabled. I'm not sure if this would be considered an acceptable limitation. ------------------------------------------------------------------------ [2021-02-18 16:34:03] mcmic@php.net See section 4.3 of https://gemini.circumlunar.space/docs/specification.html for more information about client certificate use in Gemini protocol. ------------------------------------------------------------------------ [2021-02-18 16:32:20] mcmic@php.net @daverandom: The test you linked to is about getting the server certificate from the client, I want the other way around, get the client certificate from the server. And without making the client certificate mandatory, I still need to accept certificate-less requests. ------------------------------------------------------------------------ [2021-02-18 16:26:58] daverandom@php.net Ah no I think I see the problem, you need to pass $context instead of $conn to stream_context_get_options() ------------------------------------------------------------------------ [2021-02-18 16:26:04] daverandom@php.net Note that there is a test for this behaviour which is not marked as XFAIL, so I believe this functionality should work - although I cannot immediately see an issue with your sample code https://heap.space/xref/php-src/ext/openssl/tests/capture_peer_cert_001.phpt?r=1fab01be#38 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=80770 -- Edit this bug report at https://bugs.php.net/bug.php?id=80770&edit=1

« previous php.bugs (#232265) next »