Bug #81213 [NEW]: Stream crypto methods SSLv2 and v3 switch to TLS1.0

From: Date: Thu, 01 Jul 2021 12:01:52 +0000
Subject: Bug #81213 [NEW]: Stream crypto methods SSLv2 and v3 switch to TLS1.0
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234724@lists.php.net to get a copy of this message
From: camille at affinez dot nl Operating system: Windows, Linux PHP version: 8.0.7 Package: OpenSSL related Bug Type: Bug Bug description:Stream crypto methods SSLv2 and v3 switch to TLS1.0 Description: ------------ Forcing an SMTP encryption channel to either SSLv2 or SSLv3 doesn't work as expected. When creating a network trace with Wireshark, it appears the stream is utilizing TLS1.0 instead. Google's SMTP servers return a false positive result when forcing SSLv2 and SSLv3, as Google supports TLS1.0 and up. When testing with Microsoft's 365 SMTP servers, a correct result is given as Microsoft only supports TLS1.2. Verified with OpenSSL 1.1.1h and the following command: openssl s_client -connect aspmx.l.google.com:25 -starttls smtp -servername mail.domain.com -no_tls1 -no_tls1_1 -no_tls1_2 -no_tls1_3 OpenSSL fails as expected. Test script: --------------- $SMTPconn = fsockopen("aspmx.l.google.com", 25, $error_int, $error_string, 10); fwrite($SMTPconn, "EHLO " . "tls.php.net" . "\r\n"); while (!feof($SMTPconn)) { $line = fgets($SMTPconn); $read = array($SMTPconn); $write = null; $except = null; $timeout = 0; $utimeout = 200000; if (!stream_select($read, $write, $except, $timeout, $utimeout)) break; } fwrite($SMTPconn, "STARTTLS" . "\r\n"); while (!feof($SMTPconn)) { $line = fgets($SMTPconn); $read = array($SMTPconn); $write = null; $except = null; $timeout = 0; $utimeout = 200000; if (!stream_select($read, $write, $except, $timeout, $utimeout)) break; } stream_context_set_option($SMTPconn, 'ssl', 'verify_peer', false); stream_context_set_option($SMTPconn, 'ssl', 'verify_peer_name', false); stream_context_set_option($SMTPconn, 'ssl', 'allow_self_signed', true); stream_context_set_option($SMTPconn, 'ssl', 'capture_peer_cert', true); stream_context_set_option($SMTPconn, 'ssl', 'capture_peer_cert_chain', true); $res = @stream_socket_enable_crypto($SMTPconn, true, STREAM_CRYPTO_METHOD_SSLv2_CLIENT); var_dump($res); Expected result: ---------------- int(0) or bool(false) The connection should fail, as SSLv2 or SSLv3 are not supported. Actual result: -------------- bool(true) The connection (falsely) succeeds by utilizing TLS1.0 instead of SSLv2 or SSLv3. -- Edit bug report at https://bugs.php.net/bug.php?id=81213&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81213&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81213&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81213&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81213&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81213&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81213&r=support Expected behavior: https://bugs.php.net/fix.php?id=81213&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81213&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81213&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81213&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81213&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81213&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81213&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81213&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81213&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81213&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81213&r=mysqlcfg

« previous php.bugs (#234724) next »