Sec Bug->Doc #72717 [Opn->Ver]: ftp_ssl_connect doesn't validate certificates
| From: | cmb@php.net | Date: | Tue, 16 Aug 2016 09:43:26 +0000 |
| Subject: | Sec Bug->Doc #72717 [Opn->Ver]: ftp_ssl_connect doesn't validate certificates | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-13820@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72717&edit=1
ID: 72717
Updated by: cmb@php.net
Reported by: fernando at null-life dot com
Summary: ftp_ssl_connect doesn't validate certificates
-Status: Open
+Status: Verified
-Type: Security
+Type: Documentation Problem
Package: FTP related
Operating System: *
PHP Version: 7.0.9
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This is expected behavior. ext/ftp implements the explicit
method[1] of FTPS, and so *connecting* does not require any
certificate validation. This will only happen when you try to
ftp_login(), in which case ext/ftp will send the AUTH command
(which is supposed to fail for the given test script).
I'm changing to doc bug, because that has to be documented, as a
user note[2] also hints at.
[1] <https://en.wikipedia.org/wiki/FTPS#Explicit>
[2] <http://php.net/manual/en/function.ftp-ssl-connect.php#106931>
Previous Comments:
------------------------------------------------------------------------
[2016-08-02 08:15:52] stas@php.net
Doesn't look like this needs to be private.
------------------------------------------------------------------------
[2016-07-31 09:04:49] fernando at null-life dot com
Description:
------------
Description
============
ftp_ssl_connect will establish a connection even if the certificate is not valid for the supplied
hostname. There's no way to force the verification of certificates while using ftp_ssl_connect,
however certificates are verified when used with the ftps:// wrapper.
http://php.net/manual/en/function.ftp-ssl-connect.php
Test script:
---------------
<?php
error_reporting(E_ALL);
// ssl verification fails
echo file_get_contents("ftps://test:test@beford.net/www/index.php");
$ftp_server = "beford.net";
$ftp_user_name = "test";
$ftp_user_pass = "test";
// set up basic ssl connection
$conn_id = ftp_ssl_connect($ftp_server);
if ($conn_id !== false)
print "ftp_ssl_connect should have failed too..." . PHP_EOL;
else
die("ftp_ssl_connect failed");
var_dump($conn_id);
// close the ssl connection
ftp_close($conn_id);
Expected result:
----------------
PHP Warning: file_get_contents(): Peer certificate CN=
asylum.dynamicwebsolutions.net'
did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5
PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable
to activate SSL mode in /home/operac/ftpssl/x.php on line 5
ftp_ssl_connect failed
Actual result:
--------------
PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net'
did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5
PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable
to activate SSL mode in /home/operac/ftpssl/x.php on line 5
ftp_ssl_connect should have failed too...
resource(6) of type (FTP Buffer)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72717&edit=1