Re: Problems with Verisign Connection and Apache SSL
| From: | John Donagher | Date: | Mon, 30 Oct 2000 14:34:54 +0000 |
| Subject: | Re: Problems with Verisign Connection and Apache SSL | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-36480@lists.php.net to get a copy of this message | ||
Robert-
I've been working on the problem on and off for about a month but have not contacted Verisign
yet.
If you're familiar with C at all, the problem is due to strings conflicting from OpenSSL and
the closed-source binary libpfpro.so that Verisign provides with their SDK. Their .so appears to be
linked against an older version of OpenSSL.
If you run a 'strings libpfpro.so' and 'strings libssl.{a,so}' you'll see
that a lot of the same strings are defined. This is normally, from what I understand, not a problem
if you link all of the libraries with the same linker and against the same libraries. But we
can't touch libpfpro.so since it's binary-only.
So, the two situations which I've seen cause this problem to occur are:
a) Apache+modssl+openssl with PHP+pfpro
b) CGI version of PHP+pfpro+curl(ssl)
Note that I've never seen compile-time problems, only run-time segmentation faults.
By playing around with .so's vs .a's, you can sort of suppress the problem to a
crash-on-function-call as opposed to crash-on-startup. But that won't help much for most
people.
When David and I first wrote the extension, we (or at least I) made the mistake of not testing it in
a production environment before contributing it back to the PHP tree. Right now, the only real use
the extension has is for use in batch billing (driven by cron jobs for instance) in a standalone PHP
executable. I do think a solution will be found to this problem but it may take some time.
Thanks
John
On Sun, 29 Oct 2000, Robert Dyke wrote:
> Hi Lars:
>
> Thanks so much for your response. I'm a VB developer very new to all things
> Linux/Unix/php/apache, so please pardon my posting mistakes. I first
> noticed the problem described in the PHP online documentation at:
> http://www.php.net/manual/ref.pfpro.php you can see the
> comment posted by
> David Croft, who wrote the Verisign connection.
>
> I did some more research and checked the searchable mailing lists and found
> the following detailed description of the problem at:
> $õ½û
> ßš�œ°M·
http://marc.theaimsgroup.com/?l=php-dev&m=97190416313588&w=2
>
> I haven't tried the installing it yet.
>
> Basically, I'm a VB/ASP developer. I need to set up a web server to handle
> an e-commerce site, and I'll be tying in with Verisign Payflow Pro to
> process credit cards. I'm trying desperately to stay away from an NT/2K
> server for multiple reasons. PHP seemed like a good solution, but now I've
> discovered this problem, so I'm back to square one.
>
> Any advice?
>
>
> Robert Dyke
> Montana Software
> http://www.montanasoft.com/
> robert@montanasoft.com
>
> * For the best results please include the text of this message (cut and
> paste if necessary) in your reply *
>
>
>
>
>
> "Lars Torben Wilson" <torben@php.net> wrote in message
> news:14844.54104.257905.747827@shanna.outlander.ca...
> > Robert Dyke writes:
> > > Hello:
> > >
> > > The Verisign connection doesn't work when SSL is compiled into apache.
> This
> > > is a confirmed problem. Can anybody fix this or tell me how to get it
> to
> > > work? I'll be happy to do what I can to help you with things I'm able
> to do
> > > (WinHelp files, Windows installation packages with Wise Installer, etc.)
> > > Let me know what you think.
> > >
> > >
> > > Robert Dyke
> > > Montana Software
> > > http://www.montanasoft.com/
> > > robert@montanasoft.com
> > >
> > > * For the best results please include the text of this message (cut and
> > > paste if necessary) in your reply *
> >
> > The php-general list--where you originally asked--was the correct
> > place, unless you have information that will help track down a
> > confirmed bug in PHP, in which case it should go into the Bug Database
> > (check out http://bugs.php.net).
> >
> > In any case, while questions on these lists are generally answered
> > fairly quickly, on a Sunday there is no guarantee--it might be a good
> > idea to wait a day or two before reposting the same question.
> >
> > In the meantime, can you provide any more specific information than
> > just "it doesn't work"? Such as what part doesn't work? Does httpd not
> > start, or the connection not get made, or PHP segfaults, or what? If
> > PHP segfaults (or I guess GPFs in your case), can you get a backtrace?
> > Have you checked the mailing list archives, the bug database, and
> > tried with an updated version of PHP? What version of PHP are you
> > using? What Apache version are you using?
> >
> > These are all things which would help in tracking down the source of
> > the problem, if it comes down to making a bug report. But again,
> > you'll probably get more replies tomorrow when folks get back to work
> > after the weekend. :)
> >
> >
> > Good luck,
> >
> > Torben
> >
> > --
> > +----------------------------------------------------------------+
> > |Torben Wilson <torben@php.net> Netmill iTech|
> > |http://www.coastnet.com/~torben º
> > Æ.�¥ A‹9¹T‰Whttp://www.netmill.fi|
> > |Ph: 1 250 383-9735 torben@netmill.fi|
> > +----------------------------------------------------------------+
> >
> > --
> > PHP Development Mailing List <http://www.php.net/>
> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-dev-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
>
>
>
>
--
John Donagher
Application Engineer
Intacct Corp. - Powerful Accounting on the Web
408-395-0989
720 University Ave.
Los Gatos CA 95032
www.intacct.com
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org
mQGiBDnCZ1oRBACFgkFCV6p3dWic1qm1FLhip5beIyzZSt+ccTDYQQdPZA/t5H+k
PZ7ZFBIUrXz/oEqwQwlEKlg8JQqg7hgtcL+xrIJ0BInLeSJG4lvvB551g59Thr7/
OsdxNVxKci775+K+GkdAz4xcULMuB+QE7t665Ri46EAS8ALos5UG6DGmhwCguD0v
1cxwy/KlKr+oi4sWM9caueED/RmjiSD3vmBZQt6PMisVe1AmkEf6cJoemduCSJxu
0eMz/LIeu+CqfpuJH2N/dZ3hRj9xMSHF4l71wKqV99zhm58kDGwG1u3yVzULPDqz
0yL+8nunlkoOUyn3zOnh3Zmz4POFVMZQ5oian3QkLllUwly5JCi5tWULxZ2vOkb0
zzjuA/4jigNxYV4NAyCl+wAbnyzk9/Iz8EHv4/0Ex8ytlcMtvBJKa9HjJxlyIl74
yOILHk3+GSAdM0b3ZmbavpoCpebinOMBhqEVBwCI4VUIAqf86gx+2dKBGxfKPnU4
Xxvqs/BOl/EbeJjyd4uieYndGRaWg+kYXqZ7SxrlFN24fohnd7QgSm9obiBEb25h
Z2hlciA8am9obkB3ZWJtZXRhLmNvbT6IVgQTEQIAFgUCOcJnWgQLCgQDAxUDAgMW
AgECF4AACgkQIt6tVu6+jd3SHwCgjssFktMXf8NjE9JBR+sJ2gDIsW8An0CFNdFd
dU+DJYC6ogYP9AsVfM27uQENBDnCZ2MQBAD8E0qe1gBKjtoRmyiyORtwhOz/2XZE
mqiZN2NouAUWRRZd4dHggFAA1jUsp2MVIZZQyY9ajNVy3Oaxj5kYz8LR5GItxxcD
jC8RFXKM40ZfTJeR7fH6eJa689w+le71Tt4ALyN4xcjSWuksr8795AhHFjonDi8D
rgGIq6GtWvi/KwADBgQAmeBbcjPzhqR2M8TdvEyNfVTQSSp/RNoTjNNWpHui8V0p
kiQ49tbsqeMjXGToGgMugfmrX77JidXyuVjgYjT9xUdaaA25qKAR75M9izDliT7Y
h5L+QZTAw0/5X9go7XK3WI3LYfFrp4TP0veXgSWxDqccqsRzWKW7IoXsliTCbVqI
RgQYEQIABgUCOcJnYwAKCRAi3q1W7r6N3YIcAKCkJMTPLu6tOPnXPl2s3xmnSawy
BACeOx83WlBhVScYWo+BUzntJ6ks4T0=
=OkJU
-----END PGP PUBLIC KEY BLOCK-----