Bug #76694 [Ana->Csd]: native Windows cert verification uses CN as sever name
| From: | git@php.net | Date: | Mon, 31 May 2021 12:38:37 +0000 |
| Subject: | Bug #76694 [Ana->Csd]: native Windows cert verification uses CN as sever name | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234105@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76694&edit=1
ID: 76694
Updated by: git@php.net
Reported by: anrdaemon at freemail dot ru
Summary: native Windows cert verification uses CN as sever
name
-Status: Analyzed
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Windows
PHP Version: 5.6.37
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/7fd48264de5c828d0898d48875fc6c5a6f292386
Log: Fix #76694: native Windows cert verification uses CN as sever name
Previous Comments:
------------------------------------------------------------------------
[2021-05-27 10:09:07] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #76694: native Windows cert verification uses CN as sever name
On GitHub: https://github.com/php/php-src/pull/7060
Patch: https://github.com/php/php-src/pull/7060.patch
------------------------------------------------------------------------
[2021-05-26 15:20:07] cmb@php.net
Okay, the problem is that we only check the subject CN (which is
"Rootdir CA webserver"), but not the subjectAltNames (which have
the required "ca.rootdir.org").
------------------------------------------------------------------------
[2021-05-25 11:36:52] cmb@php.net
The Windows CA cert store is definitely used (not yet sure if 100%
correctly), but currently https://ca.rootdir.org/ca.cer
is
apparently down.
------------------------------------------------------------------------
[2021-05-24 11:39:42] cmb@php.net
Thanks! I'll have a closer look.
------------------------------------------------------------------------
[2021-05-24 09:39:29] anrdaemon at yandex dot ru
> Well, requesting https://packagist.org works for me with and
> without setting openssl.cacert,
Because its CA was added to the internal bundle since then.
> but requesting https://ca.rootdir.org/ does not even work from
> a browser (NET::ERR_CERT_AUTHORITY_INVALID).
Why invalid? Should be "issuer unknown". Add https://ca.rootdir.org/ca.cer to your system PKI.
> So maybe this has been fixed in the meantime. Or do you still experience the issue with any of
> the actively supported PHP versions[1].
Tested with PHP 7.4, nothing changed.
<?php
print file_get_contents(__FILE__);
var_dump(PHP_VERSION);
var_dump(ini_get("openssl.cafile"));
var_dump(ini_get("openssl.capath"));
var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16));
var_dump(error_get_last());
With Cygwin PKI:
<?php
print file_get_contents(__FILE__);
var_dump(PHP_VERSION);
var_dump(ini_get("openssl.cafile"));
var_dump(ini_get("openssl.capath"));
var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16));
var_dump(error_get_last());
string(6) "7.4.16"
string(76) "C:\Programs\Cygwin_64\etc\pki\ca-trust\extracted\openssl\ca-bundle.trust.crt"
string(35) "C:\Programs\Cygwin_64\usr\ssl\certs"
string(16) "<html>
<body>
<h"
NULL
Without specific PKI:
<?php
print file_get_contents(__FILE__);
var_dump(PHP_VERSION);
var_dump(ini_get("openssl.cafile"));
var_dump(ini_get("openssl.capath"));
var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16));
var_dump(error_get_last());
string(6) "7.4.16"
string(0) ""
string(0) ""
string(0) ""
array(4) {
["type"]=>
int(2)
["message"]=>
string(83) "file_get_contents(https://ca.rootdir.org/): failed to open stream: operation
failed"
["file"]=>
string(71) "C:\Users\anrdaemon\Documents\Bugs\PHP\76694-openssl-system-PKI\test.php"
["line"]=>
int(6)
}
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76694
--
Edit this bug report at https://bugs.php.net/bug.php?id=76694&edit=1