Bug #76694 [ReO->Fbk]: OpenSSL don't use Windows system CA store

From: Date: Thu, 29 Apr 2021 12:41:53 +0000
Subject: Bug #76694 [ReO->Fbk]: OpenSSL don't use Windows system CA store
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233620@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76694&edit=1 ID: 76694 Updated by: cmb@php.net Reported by: anrdaemon at freemail dot ru Summary: OpenSSL don't use Windows system CA store -Status: Re-Opened +Status: Feedback Type: Bug Package: OpenSSL related Operating System: Windows PHP Version: 5.6.37 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Well, requesting https://packagist.org works for me with and without setting openssl.cacert, but requesting https://ca.rootdir.org/ does not even work from a browser (NET::ERR_CERT_AUTHORITY_INVALID). So maybe this has been fixed in the meantime. Or do you still experience the issue with any of the actively supported PHP versions[1]. [1] <https://www.php.net/supported-versions.php> Previous Comments: ------------------------------------------------------------------------ [2018-11-19 13:39:31] anrdaemon at freemail dot ru Same test with Cygwin PKI string(6) "7.1.22" string(76) "C:\Programs\Cygwin_64\etc\pki\ca-trust\extracted\openssl\ca-bundle.trust.crt" string(35) "C:\Programs\Cygwin_64\usr\ssl\certs" <and no error messages> ------------------------------------------------------------------------ [2018-11-19 13:35:55] anrdaemon at freemail dot ru Yes, browsers that use system CA store (IE, Chrome-based) operate correctly. Yes, I can use OpenSSL functionality (particularly curl) without an issue after pointing openssl.ca* settings to Cygwin PKI that contains the necessary root CA certificate. The further error message wasn't helping. And no, it doesn't work with packagist either. <?php print file_get_contents(__FILE__); var_dump(PHP_VERSION); var_dump(ini_get("openssl.cafile")); var_dump(ini_get("openssl.capath")); file_get_contents('https://packagist.org/'); ?> string(6) "7.1.22" string(0) "" string(0) "" PHP Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed in ...\76694-openssl-system-PKI\test.php on line 6 PHP Warning: file_get_contents(): Failed to enable crypto in ...\76694-openssl-system-PKI\test.php on line 6 PHP Warning: file_get_contents(https://packagist.org/): failed to open stream: operation failed in ...\76694-openssl-system-PKI\test.php on line 6 ------------------------------------------------------------------------ [2018-11-19 10:27:13] nikic@php.net The report was suspended because no response was provided to the questions that were asked by @daverandom. The issue can be reopened once requested feedback is provided. ------------------------------------------------------------------------ [2018-11-19 10:09:16] anrdaemon at freemail dot ru So, the report was suspended based on semi-educated guess? Without actual investigation? I knew bugs.php.net tend to be like that, but not on such a scale. ------------------------------------------------------------------------ [2018-11-18 22:31:27] cmb@php.net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76694 -- Edit this bug report at https://bugs.php.net/bug.php?id=76694&edit=1

« previous php.bugs (#233620) next »