Doc #72717 [Ver->Csd]: ftp_ssl_connect doesn't validate certificates

From: Date: Tue, 16 Aug 2016 10:23:20 +0000
Subject: Doc #72717 [Ver->Csd]: ftp_ssl_connect doesn't validate certificates
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-13821@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72717&edit=1 ID: 72717 Updated by: cmb@php.net Reported by: fernando at null-life dot com Summary: ftp_ssl_connect doesn't validate certificates -Status: Verified +Status: Closed Type: Documentation Problem Package: FTP related Operating System: * PHP Version: 7.0.9 Assigned To: cmb Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2016-08-16 10:22:37] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=339891 Log: Fix #72717: ftp_ssl_connect doesn't validate certificates That also integrates user note 106931. ------------------------------------------------------------------------ [2016-08-16 09:43:21] cmb@php.net This is expected behavior. ext/ftp implements the explicit method[1] of FTPS, and so *connecting* does not require any certificate validation. This will only happen when you try to ftp_login(), in which case ext/ftp will send the AUTH command (which is supposed to fail for the given test script). I'm changing to doc bug, because that has to be documented, as a user note[2] also hints at. [1] <https://en.wikipedia.org/wiki/FTPS#Explicit> [2] <http://php.net/manual/en/function.ftp-ssl-connect.php#106931> ------------------------------------------------------------------------ [2016-08-02 08:15:52] stas@php.net Doesn't look like this needs to be private. ------------------------------------------------------------------------ [2016-07-31 09:04:49] fernando at null-life dot com Description: ------------ Description ============ ftp_ssl_connect will establish a connection even if the certificate is not valid for the supplied hostname. There's no way to force the verification of certificates while using ftp_ssl_connect, however certificates are verified when used with the ftps:// wrapper. http://php.net/manual/en/function.ftp-ssl-connect.php Test script: --------------- <?php error_reporting(E_ALL); // ssl verification fails echo file_get_contents("ftps://test:test@beford.net/www/index.php"); $ftp_server = "beford.net"; $ftp_user_name = "test"; $ftp_user_pass = "test"; // set up basic ssl connection $conn_id = ftp_ssl_connect($ftp_server); if ($conn_id !== false) print "ftp_ssl_connect should have failed too..." . PHP_EOL; else die("ftp_ssl_connect failed"); var_dump($conn_id); // close the ssl connection ftp_close($conn_id); Expected result: ---------------- PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net' did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5 PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable to activate SSL mode in /home/operac/ftpssl/x.php on line 5 ftp_ssl_connect failed Actual result: -------------- PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net' did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5 PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable to activate SSL mode in /home/operac/ftpssl/x.php on line 5 ftp_ssl_connect should have failed too... resource(6) of type (FTP Buffer) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72717&edit=1

« previous php.doc.bugs (#13821) next »