Bug #76694 [Ana->Csd]: native Windows cert verification uses CN as sever name

From: Date: Mon, 31 May 2021 12:38:37 +0000
Subject: Bug #76694 [Ana->Csd]: native Windows cert verification uses CN as sever name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234105@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76694&edit=1 ID: 76694 Updated by: git@php.net Reported by: anrdaemon at freemail dot ru Summary: native Windows cert verification uses CN as sever name -Status: Analyzed +Status: Closed Type: Bug Package: OpenSSL related Operating System: Windows PHP Version: 5.6.37 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/7fd48264de5c828d0898d48875fc6c5a6f292386 Log: Fix #76694: native Windows cert verification uses CN as sever name Previous Comments: ------------------------------------------------------------------------ [2021-05-27 10:09:07] cmb@php.net The following pull request has been associated: Patch Name: Fix #76694: native Windows cert verification uses CN as sever name On GitHub: https://github.com/php/php-src/pull/7060 Patch: https://github.com/php/php-src/pull/7060.patch ------------------------------------------------------------------------ [2021-05-26 15:20:07] cmb@php.net Okay, the problem is that we only check the subject CN (which is "Rootdir CA webserver"), but not the subjectAltNames (which have the required "ca.rootdir.org"). ------------------------------------------------------------------------ [2021-05-25 11:36:52] cmb@php.net The Windows CA cert store is definitely used (not yet sure if 100% correctly), but currently https://ca.rootdir.org/ca.cer is apparently down. ------------------------------------------------------------------------ [2021-05-24 11:39:42] cmb@php.net Thanks! I'll have a closer look. ------------------------------------------------------------------------ [2021-05-24 09:39:29] anrdaemon at yandex dot ru > Well, requesting https://packagist.org works for me with and > without setting openssl.cacert, Because its CA was added to the internal bundle since then. > but requesting https://ca.rootdir.org/ does not even work from > a browser (NET::ERR_CERT_AUTHORITY_INVALID). Why invalid? Should be "issuer unknown". Add https://ca.rootdir.org/ca.cer to your system PKI. > So maybe this has been fixed in the meantime. Or do you still experience the issue with any of > the actively supported PHP versions[1]. Tested with PHP 7.4, nothing changed. <?php print file_get_contents(__FILE__); var_dump(PHP_VERSION); var_dump(ini_get("openssl.cafile")); var_dump(ini_get("openssl.capath")); var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16)); var_dump(error_get_last()); With Cygwin PKI: <?php print file_get_contents(__FILE__); var_dump(PHP_VERSION); var_dump(ini_get("openssl.cafile")); var_dump(ini_get("openssl.capath")); var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16)); var_dump(error_get_last()); string(6) "7.4.16" string(76) "C:\Programs\Cygwin_64\etc\pki\ca-trust\extracted\openssl\ca-bundle.trust.crt" string(35) "C:\Programs\Cygwin_64\usr\ssl\certs" string(16) "<html> <body> <h" NULL Without specific PKI: <?php print file_get_contents(__FILE__); var_dump(PHP_VERSION); var_dump(ini_get("openssl.cafile")); var_dump(ini_get("openssl.capath")); var_dump(substr(file_get_contents('https://ca.rootdir.org/'), 0, 16)); var_dump(error_get_last()); string(6) "7.4.16" string(0) "" string(0) "" string(0) "" array(4) { ["type"]=> int(2) ["message"]=> string(83) "file_get_contents(https://ca.rootdir.org/): failed to open stream: operation failed" ["file"]=> string(71) "C:\Users\anrdaemon\Documents\Bugs\PHP\76694-openssl-system-PKI\test.php" ["line"]=> int(6) } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76694 -- Edit this bug report at https://bugs.php.net/bug.php?id=76694&edit=1

« previous php.bugs (#234105) next »