Doc #53471 [Opn->Csd]: accepting self signed certs regarless of Stream Context

From: Date: Wed, 07 Dec 2011 05:29:01 +0000
Subject: Doc #53471 [Opn->Csd]: accepting self signed certs regarless of Stream Context
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7611@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53471&edit=1 ID: 53471 Updated by: frozenfire@php.net Reported by: f at case dot edu Summary: accepting self signed certs regarless of Stream Context -Status: Open +Status: Closed Type: Documentation Problem Package: OpenSSL related Operating System: Windows PHP Version: 5.3.1RC2 -Assigned To: +Assigned To: frozenfire Block user comment: N Private report: N New Comment: This bug has been fixed in SVN. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2011-12-07 05:28:47] frozenfire@php.net Automatic comment from SVN on behalf of frozenfire Revision: http://svn.php.net/viewvc/?view=revision&revision=320557 Log: Clarified that allow_self_signed requires verify_peer to function. Closes bug #53471. ------------------------------------------------------------------------ [2011-04-19 01:07:43] cataphract@php.net You also need "verify_peer". The manual should be clearer on this. ------------------------------------------------------------------------ [2010-12-04 04:05:39] f at case dot edu Description: ------------ self signed certificates seem to be accepted when using the protocol wrappers regardless of the allow_self_signed stream context the ftp package seems to reject self signed certificates however. Test script: --------------- $con=stream_context_create(array('ssl'=>array('allow_self_signed',false))); var_dump(file_get_contents('ftps://John:pass@selfsigned.example.com/test.php,false,$con')); $ftp=ftp_ssl_connect('selfsigned.example.com'); ftp_login($ftp,'John','pass'); Expected result: ---------------- file_get_contents and ftp_login should both throw some sort of error to the effect of "SSL/TLS handshake failed" Actual result: -------------- file_get_contents retrieves the file with no warnings ftp_login throws the error "SSL/TLS handshake failed" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=53471&edit=1

« previous php.doc.bugs (#7611) next »