Doc #72717 [Ver->Csd]: ftp_ssl_connect doesn't validate certificates
| From: | cmb@php.net | Date: | Tue, 16 Aug 2016 10:23:20 +0000 |
| Subject: | Doc #72717 [Ver->Csd]: ftp_ssl_connect doesn't validate certificates | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-13821@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72717&edit=1
ID: 72717
Updated by: cmb@php.net
Reported by: fernando at null-life dot com
Summary: ftp_ssl_connect doesn't validate certificates
-Status: Verified
+Status: Closed
Type: Documentation Problem
Package: FTP related
Operating System: *
PHP Version: 7.0.9
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2016-08-16 10:22:37] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=339891
Log: Fix #72717: ftp_ssl_connect doesn't validate certificates
That also integrates user note 106931.
------------------------------------------------------------------------
[2016-08-16 09:43:21] cmb@php.net
This is expected behavior. ext/ftp implements the explicit
method[1] of FTPS, and so *connecting* does not require any
certificate validation. This will only happen when you try to
ftp_login(), in which case ext/ftp will send the AUTH command
(which is supposed to fail for the given test script).
I'm changing to doc bug, because that has to be documented, as a
user note[2] also hints at.
[1] <https://en.wikipedia.org/wiki/FTPS#Explicit>
[2] <http://php.net/manual/en/function.ftp-ssl-connect.php#106931>
------------------------------------------------------------------------
[2016-08-02 08:15:52] stas@php.net
Doesn't look like this needs to be private.
------------------------------------------------------------------------
[2016-07-31 09:04:49] fernando at null-life dot com
Description:
------------
Description
============
ftp_ssl_connect will establish a connection even if the certificate is not valid for the supplied
hostname. There's no way to force the verification of certificates while using ftp_ssl_connect,
however certificates are verified when used with the ftps:// wrapper.
http://php.net/manual/en/function.ftp-ssl-connect.php
Test script:
---------------
<?php
error_reporting(E_ALL);
// ssl verification fails
echo file_get_contents("ftps://test:test@beford.net/www/index.php");
$ftp_server = "beford.net";
$ftp_user_name = "test";
$ftp_user_pass = "test";
// set up basic ssl connection
$conn_id = ftp_ssl_connect($ftp_server);
if ($conn_id !== false)
print "ftp_ssl_connect should have failed too..." . PHP_EOL;
else
die("ftp_ssl_connect failed");
var_dump($conn_id);
// close the ssl connection
ftp_close($conn_id);
Expected result:
----------------
PHP Warning: file_get_contents(): Peer certificate CN=
asylum.dynamicwebsolutions.net'
did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5
PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable
to activate SSL mode in /home/operac/ftpssl/x.php on line 5
ftp_ssl_connect failed
Actual result:
--------------
PHP Warning: file_get_contents(): Peer certificate CN=asylum.dynamicwebsolutions.net'
did not match expected CN=beford.net' in /home/operac/ftpssl/x.php on line 5
PHP Warning: file_get_contents(ftps://...@beford.net/www/index.php): failed to open stream: Unable
to activate SSL mode in /home/operac/ftpssl/x.php on line 5
ftp_ssl_connect should have failed too...
resource(6) of type (FTP Buffer)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72717&edit=1