Bug #55236 [Ver->Nab]: Can't open a connection via TLS

From: Date: Mon, 28 Jun 2021 13:10:32 +0000
Subject: Bug #55236 [Ver->Nab]: Can't open a connection via TLS
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234661@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55236&edit=1 ID: 55236 Updated by: cmb@php.net Reported by: mark_lanthaler at gmx dot net Summary: Can't open a connection via TLS -Status: Verified +Status: Not a bug Type: Bug Package: OpenSSL related Operating System: Ubuntu PHP Version: 5.3.6 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > openssl s_client -starttls smtp -connect smtp.live.com:587 If you try openssl s_client -connect smtp.live.com:587 instead, you basically get the same error message: 3580:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:ssl\record\ssl3_record.c:332: That is because the server requires STARTTLS, i.e. you start with an unencrypted TCP connection, and only later the SSL handshake is supposed to happen. The exact details of this negotiation depend on the protocol (that is why openssl's -starttls option requires to pass it). Thus, with low level sockets, the behavior is actually expected (i.e. you'd need to implement STARTTLS support yourself). Previous Comments: ------------------------------------------------------------------------ [2018-09-05 14:09:27] alan at inspirometer dot com Has this been looked at? I am running 7.1 and still experiencing this. ------------------------------------------------------------------------ [2016-03-03 16:15:04] ar dot dev at ange7 dot com I have the same problem with PHP 5.6.17+dfsg-0+deb8u1 on debian jessie can't open fsockopen('tls://domain.tld', 587); -- my script -- <?php $fp = fsockopen("tls://devnco.fr", 587); var_dump($fp); ?> -- actual result -- PHP Warning: fsockopen(): SSL operation failed with code 1. OpenSSL Error messages: error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number in Command line code on line 1 PHP Warning: fsockopen(): Failed to enable crypto in Command line code on line 1 PHP Warning: fsockopen(): unable to connect to tls://devnco.fr:587 (Unknown error) in Command line code on line 1 bool(false) it's very important for me :/ ------------------------------------------------------------------------ [2011-07-19 04:49:40] mark_lanthaler at gmx dot net Description: ------------ When opening a socket to smtp.live.com with TLS via $fp = fsockopen("tls://smtp.live.com", 587, $errno, $errstr, 3); It's neither a problem to establish a SSL connection via PHP or to connect to smtp.live.com via openssl at the command line: openssl s_client -starttls smtp -connect smtp.live.com:587 Test script: --------------- $fp = fsockopen("tls://smtp.live.com", 587, $errno, $errstr, 3); if (!$fp) { echo "$errstr ($errno)"; } Expected result: ---------------- A connection being established. Actual result: -------------- PHP Warning: fsockopen(): SSL operation failed with code 1. OpenSSL Error messages: error:1408F10B:SSL routines:func(143):reason(267) in /var/www/test.php on line 4 PHP Warning: fsockopen(): Failed to enable crypto in /var/www/test.php on line 4 PHP Warning: fsockopen(): unable to connect to tls://smtp.live.com:587 (Unknown error) in /var/www/test.php on line 4 Reason 267 is according to ssl.h "SSL_R_WRONG_VERSION_NUMBER". Thus I suspect that's the same issue as in bug #29296. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=55236&edit=1

« previous php.bugs (#234661) next »