Bug->Doc #78311 [Opn]: SoapClient stream_context ignored
| From: | giftrac+php at gmail dot com | Date: | Thu, 18 Jul 2019 03:34:17 +0000 |
| Subject: | Bug->Doc #78311 [Opn]: SoapClient stream_context ignored | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-16826@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78311&edit=1
ID: 78311
User updated by: giftrac+php at gmail dot com
Reported by: giftrac+php at gmail dot com
Summary: SoapClient stream_context ignored
Status: Open
-Type: Bug
+Type: Documentation Problem
Package: HTTP related
Operating System: CentOS Linux 7
PHP Version: 7.3.7
Block user comment: N
Private report: N
New Comment:
Changed from Bug to Documentation Problem.
Previous Comments:
------------------------------------------------------------------------
[2019-07-18 03:31:26] giftrac+php at gmail dot com
It appears that the cause of the issue is that the default cipher(s) being used changed between PHP
5.6 and 7.3. Explicitly calling out the cipher(s) to be used via the stream_context ssl
'cipher' option allows the SoapClient communicate in PHP 7.3.
------------------------------------------------------------------------
[2019-07-17 22:27:38] giftrac+php at gmail dot com
Description:
------------
In PHP 5.6.40, a stream_context can be provided to a SoapClient, that specifies that the ssl cert of
the peer should not be verified. In PHP 7.3.7 the SoapClient appears to be ignoring the provided
stream_context and attempts to verify the peer's cert. Similarly, a capath and cafile
specified in a stream_context are used in PHP 5.6.40 to successfully verify a peer; however, they
appear to be ignored in PHP 7.3.7.
Test script:
---------------
$opts = [
'ssl' => [
'crypto_method' => STREAM_CRYPTO_METHOD_TLS_CLIENT,
'verify_peer' => false,
],
];
$stream_context = stream_context_create($opts);
$options = [
'stream_context' => $stream_context,
];
$client = new SoapClient("https://...?wsdl",
$options);
$client->SomeMethod();//executes OK in PHP 5.6, errors out in PHP 7.3.7
Expected result:
----------------
It is expected that the ssl options in the stream_context are adhered to in PHP 7, including but not
limited to: verify_peer, verify_peer_name, allow_self_signed, capath, cafile.
Actual result:
--------------
It appears the ssl options in the stream_context are ignored as evidenced by the SoapClient
production a SoapFault exception detailing that it is unable to load from the provided WSDL URL (or
when operating in location/uri mode, throwing an exception about being unable to import schema).
PHP Fatal error: Uncaught SoapFault exception: [WSDL] SOAP-ERROR: Parsing WSDL: Couldn't load
from 'https://...' : failed to load external entity
"https://..."
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78311&edit=1