Bug #80854 [Opn->Nab]: SAN Certificate Wildcard fails with verify_peer_name
Edit report at https://bugs.php.net/bug.php?id=80854&edit=1
ID: 80854
Updated by: cmb@php.net
Reported by: ricardo dot branco at covermg dot com
Summary: SAN Certificate Wildcard fails with verify_peer_name
-Status: Open
+Status: Not a bug
Type: Bug
-Package: Sockets related
+Package: OpenSSL related
Operating System: Centos 7
PHP Version: 7.4.16
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> This has been open for ages.
> https://bugs.php.net/bug.php?id=67666
No, it has not. Actually, that bug had been fixed within less
than 48 hours.
> PHP Warning: stream_socket_enable_crypto(): Peer certificate
> CN=*.smtp.sendgrid.net' did not match expected CN=smtp.sendgrid.com' in
> /home/ips/library/Zend/Mail/Protocol/Smtp.php on line 206
From RFC 6125[1]:
| A "*" wildcard character MAY be used as the left-most name
| component in the certificate. For example, *.example.com would
| match a.example.com, foo.example.com, etc. but would not match
| example.com.
So this doesn't look like a bug in PHP.
[1] <https://tools.ietf.org/html/rfc6125
Previous Comments:
------------------------------------------------------------------------
[2021-03-10 23:48:21] ricardo dot branco at covermg dot com
Description:
------------
Since verify_peer_name/verify_peer is now default on it can not validate certificates with multiple
SAN entries.
```
PHP Warning: stream_socket_enable_crypto(): Peer certificate CN=*.smtp.sendgrid.net' did
not match expected CN=smtp.sendgrid.com' in
/home/ips/library/Zend/Mail/Protocol/Smtp.php on line 206
```
Currently only way to correct this id by disabling verify.
This has been open for ages.
https://bugs.php.net/bug.php?id=67666
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80854&edit=1
Thread (3 messages)