Bug #79589 [Com]: error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading

From: Date: Thu, 12 May 2022 01:55:04 +0000
Subject: Bug #79589 [Com]: error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241465@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79589&edit=1 ID: 79589 Comment by: gilperon at gmail dot com Reported by: mumu at seznam dot cz Summary: error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading Status: Re-Opened Type: Bug Package: OpenSSL related PHP Version: 7.4.5 Block user comment: N Private report: N New Comment: # # OpenSSL example configuration file. # See doc/man5/config.pod for more info. # # This is mostly being used for generation of certificate requests, # but may be used for auto loading of providers # Note that you can include other files from the main configuration # file using the .include directive. #.include filename # This definition stops the following lines choking if HOME isn't # defined. HOME = . # Use this in order to automatically load providers. openssl_conf = openssl_init # Comment out the next line to ignore configuration errors config_diagnostics = 1 # Extra OBJECT IDENTIFIER info: # oid_file = $ENV::HOME/.oid oid_section = new_oids # To use this configuration file with the "-extfile" option of the # "openssl x509" utility, name here the section containing the # X.509v3 extensions to use: # extensions = # (Alternatively, use a configuration file that has only # X.509v3 extensions in its main [= default] section.) [ new_oids ] # We can add new OIDs in here for use by 'ca', 'req' and 'ts'. # Add a simple OID like this: # testoid1=1.2.3.4 # Or use config file substitution like this: # testoid2=${testoid1}.5.6 # Policies used by the TSA examples. tsa_policy1 = 1.2.3.4.1 tsa_policy2 = 1.2.3.4.5.6 tsa_policy3 = 1.2.3.4.5.7 [openssl_init] providers = provider_sect # Load default TLS policy configuration ssl_conf = ssl_module # Uncomment the sections that start with ## below to enable the legacy provider. # Loading the legacy provider enables support for the following algorithms: # Hashing Algorithms / Message Digests: MD2, MD4, MDC2, WHIRLPOOL, RIPEMD160 # Symmetric Ciphers: Blowfish, CAST, DES, IDEA, RC2, RC4,RC5, SEED # Key Derivation Function (KDF): PBKDF1 # In general it is not recommended to use the above mentioned algorithms for # security critical operations, as they are cryptographically weak or vulnerable # to side-channel attacks and as such have been deprecated. [provider_sect] default = default_sect ##legacy = legacy_sect ## [default_sect] activate = 1 ##[legacy_sect] ##activate = 1 Previous Comments: ------------------------------------------------------------------------ [2022-05-12 01:53:21] gilperon at gmail dot com My openssl version is below: [root@localhost ~]# openssl version OpenSSL 3.0.1 14 Dec 2021 (Library: OpenSSL 3.0.1 14 Dec 2021) My openssl.cnf file is below (the changes proposed to this file in order to prevent the warning were not done below, I am pasting you the original file contents): ------------------------------------------------------------------------ [2022-05-12 01:47:07] gilperon at gmail dot com After upgrading my CentOS to Stream 9 and installing PHP 8.1.x I started receiving the warning message below: Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages: error:0A000126:SSL routines::unexpected eof while reading in /test.php on line 5 I changed the file "/etc/ssl/openssl.cnf" (as other people suggested), enabling legacy, but the warning message still shows up (even after rebooting the server). Some people had success with this change but all of them were on Ubuntu. I didnt find any person using CentOS that managed to make the warning disappear changing the openssl.cnf file.! ------------------------------------------------------------------------ [2022-05-05 01:02:03] kravetzpm at gmail dot com I got rid of the error message by modifying openssl.cnf as described here: https://gist.github.com/rdh27785 My setup: Ubuntu Server 22.04 LTS, apache2, php8.1 ------------------------------------------------------------------------ [2022-04-27 10:22:20] joke2k at gmail dot com I had the same error with php8.0 after updating Ubuntu to 22.04 (which upgrades OpenSSL to 3.0). Running sudo apt install php8.0-curl the issue disappeared. ------------------------------------------------------------------------ [2022-04-12 08:38:39] rando dot hinn at ahhaa dot ee Is there a temporary workaround for this on php 8.1.2 or when could we expect the patch to be shipped? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79589 -- Edit this bug report at https://bugs.php.net/bug.php?id=79589&edit=1

« previous php.bugs (#241465) next »