Sec Bug->Doc #72717 [Opn->Ver]: ftp_ssl_connect doesn't validate certificates

From: Date: Tue, 16 Aug 2016 09:43:26 +0000
Subject: Sec Bug->Doc #72717 [Opn->Ver]: ftp_ssl_connect doesn't validate certificates
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-13820@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72717&edit=1 ID: 72717 Updated by: cmb@php.net Reported by: fernando at null-life dot com Summary: ftp_ssl_connect doesn't validate certificates -Status: Open +Status: Verified -Type: Security +Type: Documentation Problem Package: FTP related Operating System: * PHP Version: 7.0.9 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This is expected behavior. ext/ftp implements the explicit method[1] of FTPS, and so *connecting* does not require any certificate validation. This will only happen when you try to ftp_login(), in which case ext/ftp will send the AUTH command (which is supposed to fail for the given test script). I'm changing to doc bug, because that has to be documented, as a user note[2] also hints at. [1] <https://en.wikipedia.org/wiki/FTPS#Explicit> [2] <http://php.net/manual/en/function.ftp-ssl-connect.php#106931> Previous Comments: ------------------------------------------------------------------------ [2016-08-02 08:15:52] stas@php.net Doesn't look like this needs to be private. ------------------------------------------------------------------------ [2016-07-31 09:04:49] fernando at null-life dot com Description: ------------ Description ============ ftp_ssl_connect will establish a connection even if the certificate is not valid for the supplied hostname. There's no way to force the verification of certificates while using ftp_ssl_connect, however certificates are verified when used with the ftps:// wrapper. http://php.net/manual/en/function.ftp-ssl-connect.php Test script: --------------- <?php error_reporting(E_ALL); // ssl verification fails echo file_get_contents("ftps://test:test@beford.net/www/index.php"); $ftp_server = "beford.net"; $ftp_user_name = "test"; $ftp_user_pass = "test"; // set up basic ssl connection $conn_id = ftp_ssl_connect($ftp_server); if ($conn_id !== false) print "ftp_ssl_connect should have failed too..." . PHP_EOL; else die("ftp_ssl_connect failed"); var_dump($conn_id); // close the ssl connection ftp_close($conn_id); Expected result: ---------------- PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net' did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5 PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable to activate SSL mode in /home/operac/ftpssl/x.php on line 5 ftp_ssl_connect failed Actual result: -------------- PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net' did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5 PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable to activate SSL mode in /home/operac/ftpssl/x.php on line 5 ftp_ssl_connect should have failed too... resource(6) of type (FTP Buffer) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72717&edit=1

« previous php.doc.bugs (#13820) next »