Bug #80854 [Com]: SAN Certificate Wildcard fails with verify_peer_name
Edit report at https://bugs.php.net/bug.php?id=80854&edit=1
ID: 80854
Comment by: sdsdsdsdsd at dfgfgfgfg dot net
Reported by: ricardo dot branco at covermg dot com
Summary: SAN Certificate Wildcard fails with verify_peer_name
Status: Not a bug
Type: Bug
Package: OpenSSL related
Operating System: Centos 7
PHP Version: 7.4.16
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> Peer certificate CN=`*.smtp.sendgrid.net' did not
> match expected CN=`smtp.sendgrid.com'
*.smtp.sendgrid.net != smtp.sendgrid.com
when you have a certificate with "*.example.com" without explicit "example.com"
no client would accept it and that's intentional! you need to list all names and besides
wildcards for subdomains the subdomain itself explicit
Previous Comments:
------------------------------------------------------------------------
[2021-05-07 16:08:17] cmb@php.net
> This has been open for ages.
> https://bugs.php.net/bug.php?id=67666
No, it has not. Actually, that bug had been fixed within less
than 48 hours.
> PHP Warning: stream_socket_enable_crypto(): Peer certificate
> CN=*.smtp.sendgrid.net' did not match expected CN=smtp.sendgrid.com' in
> /home/ips/library/Zend/Mail/Protocol/Smtp.php on line 206
From RFC 6125[1]:
| A "*" wildcard character MAY be used as the left-most name
| component in the certificate. For example, *.example.com would
| match a.example.com, foo.example.com, etc. but would not match
| example.com.
So this doesn't look like a bug in PHP.
[1] <https://tools.ietf.org/html/rfc6125
------------------------------------------------------------------------
[2021-03-10 23:48:21] ricardo dot branco at covermg dot com
Description:
------------
Since verify_peer_name/verify_peer is now default on it can not validate certificates with multiple
SAN entries.
```
PHP Warning: stream_socket_enable_crypto(): Peer certificate CN=*.smtp.sendgrid.net' did
not match expected CN=smtp.sendgrid.com' in
/home/ips/library/Zend/Mail/Protocol/Smtp.php on line 206
```
Currently only way to correct this id by disabling verify.
This has been open for ages.
https://bugs.php.net/bug.php?id=67666
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80854&edit=1
Thread (3 messages)