Default https encryption wrapper
| From: | Daniel Lowrey | Date: | Thu, 19 Dec 2013 14:39:17 +0000 |
| Subject: | Default https encryption wrapper | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-70752@lists.php.net to get a copy of this message | ||
I'd like to gauge support for another update in the spirit of the openssl
changes scheduled for 5.6. Currently the http fopen wrapper defaults to the
ssl:// scheme when retrieving an https:// resource as seen here:
http://lxr.php.net/xref/PHP_5_6/ext/standard/http_fopen_wrapper.c#196
What this means to the underlying openssl lib is that the SSLv23 crypto
method is used for handshake negotiation. The SSLv23 handshake method
provides compatibility for SSL2, SSL3 and TLS1.0 protocols.
Citing the "SSL/TLS Deployment Best Practices" report linked at the end of
this message:
- SSL v2 is insecure and must not be used.
- SSL v3 is very old and obsolete. Because it lacks some key features and
because virtually all clients support TLS 1.0 and better, you should not
support SSL v3 unless you have a very good reason.
- TLS v1.0 is largely still secure; we do not know of major security flaws
when they are used for protocols other than HTTP. When used with HTTP, it
can almost be made secure with careful configuration.
- TLS v1.1 and v1.2 are without known security issues.
While this allows more transfers to succeed in the wild it's also insecure.
I personally don't believe it's a good idea to enable the use of SSL2 and
SSL3 by default. Instead, I think the http fopen wrapper should use the
tls:// scheme and send the TLS1.0 handshake by default. Will this cause
some transfers that worked previously to fail? Yes. However, potential
breakage when requesting resources from servers still using the (very)
outdated protocols can be eliminated because as of 5.6 encrypted stream
transports can be configured to use a specific crypto method (see link in
references section) via the stream context at call time, e.g.:
// Override the default with a specific protocol for this call
$context = stream_context_create(['ssl' => [
"crypto_method" => STREAM_CRYPTO_METHOD_SSLv3_CLIENT
]]);
file_get_contents('https://somesite', FALSE,
$context);
To me, this change is a necessary one. Most users should not notice the
change as TLSv1.0 is well established and supported by *virtually* all
servers. Default to the more secure protocols here would dovetail nicely
alongside the other security enhancements in 5.6.
Thoughts?
-- References --
SSL/TLS Deployment Best Practices:
https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Practices_1.3.pdf
Encrypted stream transports can now be configured in the stream context:
https://github.com/php/php-src/commit/ce2789558a970057539094ca9019d98ff09e831e