Patch: provides SSL capability for sockets in PHP 4.0.1pl2
| From: | Wez Furlong | Date: | Tue, 22 Aug 2000 13:42:43 +0000 |
| Subject: | Patch: provides SSL capability for sockets in PHP 4.0.1pl2 | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-30192@lists.php.net to get a copy of this message | ||
Hi,
I hope this is the right place to post this; I couldn't see where to submit
patches on the php web page.
This patch against the released php 4.0.1pl2 provides some rudimentary SSL
capabilities (using openssl) to sockets created via fsockopen.
If a socket is opened using fsockopen("ssl://hostname", ...) an SSL client
context is allocated and initialized. Read and write operations on the
socket use the SSL equivalents, so everything is transparent to the user.
This is good for rolling-your own HTTPS implementation in php, so that you
can take advantage of encryption, but not verification of certs (this is a
job for the future).
Caveats/Possible problems:
==========================
There is a macro for writing to sockets in main/fopen-wrappers.h
(SOCK_WRITEL); in an ideal world, this should be changed to use some kind of
abstraction. I have changed the code in fputs() so that it checks for an
SSL socket and uses the SSL_write API instead; if code elsewhere uses
SOCK_WRITEL then you may need to adjust the code there. I didn't want to
touch that macro, just in case it broke something.
Error reporting on SSL connections might not be very useful to the user; I
haven't had an error with SSL yet, so I don't know...
To enable the code, you need to pass --with-ssl to configure; this will
check for openssl using the same method in the snmp extension, but with a
different macro name so it doesn't conflict. You may want to move the SSL
check somewhere more centralized.
If SSL support is not built in, some of the SSL variables (use_ssl on the
internal fsockopen function, and the SSL pointer in the sockbuf structure)
are left behind to make the code more readable (not so many #ifdefs). If
size is an issue, you may want to make some changes.
The SSL connection uses SSLv2_client_method; there is no way to specify an
alternative method.
I don't know how thread-safe the SSL library is.
Future Ideas:
=============
You may want to revise the way that the fsock code works, to make it a bit
more like the fopen wrappers stuff: this would allow you to specify the SSL
connection method in the fsockopen call: fsockopen("ssl:SSLv2//", ...) or
fsockopen("ssl:SSLv3//", ...) for example.
There is currently no way to look at the SSL certificate used by the
connection; this could form the basis of an extension that opens up the SSL
api, but operates on the socket handles themselves; this hinges on getting
at the SSL pointer in the sockbuf structure from outside the "standard"
extension; I haven't looked at this yet.
The code I have contributed is based on the cli.cpp example that comes with
the openssl distribution.
If you integrate this patch into the main distribution, please credit my
employer for the time I have spent this morning: Ryland Technology Ltd
(www.ryltech.net).
--
Wez Furlong
Ryland Technology Ltd. http://www.ryltech.net
20 Cressex Enterprise Centre, Lincoln Road, High Wycombe. HP12 3RL
Tel: 44 (0)1494 472707
Attachment: [application/octet-stream] php4.diff
Attachment: [application/octet-stream] php4.diff