Doc #53471 [Opn->Csd]: accepting self signed certs regarless of Stream Context
| From: | frozenfire@php.net | Date: | Wed, 07 Dec 2011 05:29:01 +0000 |
| Subject: | Doc #53471 [Opn->Csd]: accepting self signed certs regarless of Stream Context | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7611@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=53471&edit=1
ID: 53471
Updated by: frozenfire@php.net
Reported by: f at case dot edu
Summary: accepting self signed certs regarless of Stream
Context
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: OpenSSL related
Operating System: Windows
PHP Version: 5.3.1RC2
-Assigned To:
+Assigned To: frozenfire
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in SVN.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2011-12-07 05:28:47] frozenfire@php.net
Automatic comment from SVN on behalf of frozenfire
Revision: http://svn.php.net/viewvc/?view=revision&revision=320557
Log: Clarified that allow_self_signed requires verify_peer to function. Closes bug #53471.
------------------------------------------------------------------------
[2011-04-19 01:07:43] cataphract@php.net
You also need "verify_peer". The manual should be clearer on this.
------------------------------------------------------------------------
[2010-12-04 04:05:39] f at case dot edu
Description:
------------
self signed certificates seem to be accepted when using the protocol wrappers regardless of the
allow_self_signed stream context
the ftp package seems to reject self signed certificates however.
Test script:
---------------
$con=stream_context_create(array('ssl'=>array('allow_self_signed',false)));
var_dump(file_get_contents('ftps://John:pass@selfsigned.example.com/test.php,false,$con'));
$ftp=ftp_ssl_connect('selfsigned.example.com');
ftp_login($ftp,'John','pass');
Expected result:
----------------
file_get_contents and ftp_login should both throw some sort of error to the effect of "SSL/TLS
handshake failed"
Actual result:
--------------
file_get_contents retrieves the file with no warnings
ftp_login throws the error "SSL/TLS handshake failed"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=53471&edit=1