Bug #79589 [Com]: error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading

From: Date: Thu, 12 May 2022 01:56:04 +0000
Subject: Bug #79589 [Com]: error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241466@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79589&edit=1

 ID:                 79589
 Comment by:         gilperon at gmail dot com
 Reported by:        mumu at seznam dot cz
 Summary:            error:14095126:SSL routines:ssl3_read_n:unexpected
                     eof while reading
 Status:             Re-Opened
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        7.4.5
 Block user comment: N
 Private report:     N

 New Comment:

I gave up providing you the contents of my openssl.cnf file... php.net blocked me everytime I pasted
the content of the file, saying there are links not allowed... anyway, if you want the file I can
provide you by mail.


Previous Comments:
------------------------------------------------------------------------
[2022-05-12 01:55:04] gilperon at gmail dot com

#
# OpenSSL example configuration file.
# See doc/man5/config.pod for more info.
#
# This is mostly being used for generation of certificate requests,
# but may be used for auto loading of providers

# Note that you can include other files from the main configuration
# file using the .include directive.
#.include filename

# This definition stops the following lines choking if HOME isn't
# defined.
HOME			= .

 # Use this in order to automatically load providers.
openssl_conf = openssl_init

# Comment out the next line to ignore configuration errors
config_diagnostics = 1

# Extra OBJECT IDENTIFIER info:
# oid_file       = $ENV::HOME/.oid
oid_section = new_oids

# To use this configuration file with the "-extfile" option of the
# "openssl x509" utility, name here the section containing the
# X.509v3 extensions to use:
# extensions		=
# (Alternatively, use a configuration file that has only
# X.509v3 extensions in its main [= default] section.)

[ new_oids ]
# We can add new OIDs in here for use by 'ca', 'req' and 'ts'.
# Add a simple OID like this:
# testoid1=1.2.3.4
# Or use config file substitution like this:
# testoid2=${testoid1}.5.6

# Policies used by the TSA examples.
tsa_policy1 = 1.2.3.4.1
tsa_policy2 = 1.2.3.4.5.6
tsa_policy3 = 1.2.3.4.5.7

[openssl_init]
providers = provider_sect
# Load default TLS policy configuration
ssl_conf = ssl_module

# Uncomment the sections that start with ## below to enable the legacy provider.
# Loading the legacy provider enables support for the following algorithms:
# Hashing Algorithms / Message Digests: MD2, MD4, MDC2, WHIRLPOOL, RIPEMD160
# Symmetric Ciphers: Blowfish, CAST, DES, IDEA, RC2, RC4,RC5, SEED
# Key Derivation Function (KDF): PBKDF1
# In general it is not recommended to use the above mentioned algorithms for
# security critical operations, as they are cryptographically weak or vulnerable
# to side-channel attacks and as such have been deprecated.

[provider_sect]
default = default_sect
##legacy = legacy_sect
##
[default_sect]
activate = 1

##[legacy_sect]
##activate = 1

------------------------------------------------------------------------
[2022-05-12 01:53:21] gilperon at gmail dot com

My openssl version is below:

[root@localhost ~]# openssl version
OpenSSL 3.0.1 14 Dec 2021 (Library: OpenSSL 3.0.1 14 Dec 2021)


My openssl.cnf file is below (the changes proposed to this file in order to prevent the warning were
not done below, I am pasting you the original file contents):

------------------------------------------------------------------------
[2022-05-12 01:47:07] gilperon at gmail dot com

After upgrading my CentOS to Stream 9 and installing PHP 8.1.x I started receiving the warning
message below:

Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages:
error:0A000126:SSL routines::unexpected eof while reading in /test.php on line 5

I changed the file "/etc/ssl/openssl.cnf" (as other people suggested), enabling legacy,
but the warning message still shows up (even after rebooting the server). Some people had success
with this change but all of them were on Ubuntu. I didnt find any person using CentOS that managed
to make the warning disappear changing the openssl.cnf file.!

------------------------------------------------------------------------
[2022-05-05 01:02:03] kravetzpm at gmail dot com

I got rid of the error message by modifying openssl.cnf as described here:

https://gist.github.com/rdh27785

My setup: Ubuntu Server 22.04 LTS, apache2, php8.1

------------------------------------------------------------------------
[2022-04-27 10:22:20] joke2k at gmail dot com

I had the same error with php8.0 after updating Ubuntu to 22.04 (which upgrades OpenSSL to 3.0).

Running sudo apt install php8.0-curl the issue disappeared.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79589


--
Edit this bug report at https://bugs.php.net/bug.php?id=79589&edit=1


Thread (16 messages)

« previous php.bugs (#241466) next »