Bug #80770 [Com]: It is not possible to get client peer certificate with stream_socket_server

From: Date: Sat, 31 Dec 2022 05:09:56 +0000
Subject: Bug #80770 [Com]: It is not possible to get client peer certificate with stream_socket_server
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243296@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80770&edit=1

 ID:                 80770
 Comment by:         marlynrasavong at gmail dot com
 Reported by:        mcmic@php.net
 Summary:            It is not possible to get client peer certificate
                     with stream_socket_server
 Status:             Verified
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        7.3.27
 Block user comment: N
 Private report:     N

 New Comment:

Hey it is not possible to get certificate without TLS. 
(https://www.benefitscal.biz/)github.com


Previous Comments:
------------------------------------------------------------------------
[2021-02-18 17:13:07] daverandom@php.net

My apologies, you are correct and I have actually now remembered encountering the same limitation a
few months ago. I do also have a (theoretical) work-around, which is to obtain the ClientHello
message (and potentially other traffic) via stream_socket_recvfrom() and STREAM_PEEK before calling
stream_socket_enable_crypto().

I think I even wrote a PoC partial implementation of it, I cannot find it at the moment but if I do
I will make a gist and link it here.

As for a proper fix for the issue, I have touched this code in the (distant) past and I from what I
remember it should be reasonably easy to optionally store a client certificate into the
stream's context during the peer verification callback, though I think this would not work if
peer verification was completely disabled. I'm not sure if this would be considered an
acceptable limitation.

------------------------------------------------------------------------
[2021-02-18 16:34:03] mcmic@php.net

See section 4.3 of https://gemini.circumlunar.space/docs/specification.html
for more information about client certificate use in Gemini protocol.

------------------------------------------------------------------------
[2021-02-18 16:32:20] mcmic@php.net

@daverandom:
The test you linked to is about getting the server certificate from the client, I want the other way
around, get the client certificate from the server.
And without making the client certificate mandatory, I still need to accept certificate-less
requests.

------------------------------------------------------------------------
[2021-02-18 16:26:58] daverandom@php.net

Ah no I think I see the problem, you need to pass $context instead of $conn to
stream_context_get_options()

------------------------------------------------------------------------
[2021-02-18 16:26:04] daverandom@php.net

Note that there is a test for this behaviour which is not marked as XFAIL, so I believe this
functionality should work - although I cannot immediately see an issue with your sample code

https://heap.space/xref/php-src/ext/openssl/tests/capture_peer_cert_001.phpt?r=1fab01be#38

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80770


--
Edit this bug report at https://bugs.php.net/bug.php?id=80770&edit=1


Thread (9 messages)

« previous php.bugs (#243296) next »