Bug #81213 [NEW]: Stream crypto methods SSLv2 and v3 switch to TLS1.0
| From: | camille at affinez dot nl | Date: | Thu, 01 Jul 2021 12:01:52 +0000 |
| Subject: | Bug #81213 [NEW]: Stream crypto methods SSLv2 and v3 switch to TLS1.0 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-234724@lists.php.net to get a copy of this message | ||
From: camille at affinez dot nl
Operating system: Windows, Linux
PHP version: 8.0.7
Package: OpenSSL related
Bug Type: Bug
Bug description:Stream crypto methods SSLv2 and v3 switch to TLS1.0
Description:
------------
Forcing an SMTP encryption channel to either SSLv2 or SSLv3 doesn't work
as expected. When creating a network trace with Wireshark, it appears
the stream is utilizing TLS1.0 instead.
Google's SMTP servers return a false positive result when forcing SSLv2
and SSLv3, as Google supports TLS1.0 and up.
When testing with Microsoft's 365 SMTP servers, a correct result is
given as Microsoft only supports TLS1.2.
Verified with OpenSSL 1.1.1h and the following command:
openssl s_client -connect aspmx.l.google.com:25 -starttls smtp
-servername mail.domain.com -no_tls1 -no_tls1_1 -no_tls1_2 -no_tls1_3
OpenSSL fails as expected.
Test script:
---------------
$SMTPconn = fsockopen("aspmx.l.google.com", 25, $error_int,
$error_string, 10);
fwrite($SMTPconn, "EHLO " . "tls.php.net" . "\r\n");
while (!feof($SMTPconn)) {
$line = fgets($SMTPconn);
$read = array($SMTPconn); $write = null; $except = null; $timeout = 0;
$utimeout = 200000;
if (!stream_select($read, $write, $except, $timeout, $utimeout))
break;
}
fwrite($SMTPconn, "STARTTLS" . "\r\n");
while (!feof($SMTPconn)) {
$line = fgets($SMTPconn);
$read = array($SMTPconn); $write = null; $except = null; $timeout = 0;
$utimeout = 200000;
if (!stream_select($read, $write, $except, $timeout, $utimeout))
break;
}
stream_context_set_option($SMTPconn, 'ssl', 'verify_peer', false);
stream_context_set_option($SMTPconn, 'ssl', 'verify_peer_name', false);
stream_context_set_option($SMTPconn, 'ssl', 'allow_self_signed', true);
stream_context_set_option($SMTPconn, 'ssl', 'capture_peer_cert', true);
stream_context_set_option($SMTPconn, 'ssl', 'capture_peer_cert_chain',
true);
$res = @stream_socket_enable_crypto($SMTPconn, true,
STREAM_CRYPTO_METHOD_SSLv2_CLIENT);
var_dump($res);
Expected result:
----------------
int(0) or bool(false)
The connection should fail, as SSLv2 or SSLv3 are not supported.
Actual result:
--------------
bool(true)
The connection (falsely) succeeds by utilizing TLS1.0 instead of SSLv2
or SSLv3.
--
Edit bug report at https://bugs.php.net/bug.php?id=81213&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81213&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81213&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81213&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81213&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81213&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81213&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81213&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81213&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81213&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81213&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81213&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81213&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81213&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81213&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81213&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81213&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81213&r=mysqlcfg