Add support for SCRAM-SHA-*-PLUS channel binding in PHP streams (e.g., tls-unique, tls-exporter)
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- C
- Star
- 40.4k
- Fork
- 8.1k
- Merge trung bình
- 2 ngày 13 giờ
- Pull request đã merge (30 ngày)
- 96
Mô tả
Description
Hello,
I'm the maintainer of the fabiang/sasl library, which implements various SASL mechanisms. Since many SASL mechanisms have been deprecated over the years due to security issues, I am interested in improving the security of the SCRAM-SHA-* SASL mechanisms.
The SCRAM-SHA-*-PLUS mechanisms offer better security through channel binding. The recommended channel binding types are:
- tls-unique for TLS <= 1.2
- tls-server-end-point
- tls-exporter for TLS >= 1.3
Currently, PHP lacks support for channel binding, as no API is exposed to access data from the underlying secure socket. Additionally, more and more server software is adding support for channel binding.
For example, Python:
- supports at least "tls-unique" through SSLSocket.get_channel_binding
- and has an open Pull Request for tls-exporter.
To enable this in PHP, a simple API to retrieve channel binding data from a stream context would be beneficial.
A potential function could:
- return data from OpenSSL's
SSL_get_peer_finishedwhen channel binding is set to "tls-unique" and TLS 1.2 is used, - use OpenSSL's
SSL_export_keying_materialwhen channel binding is set to "tls-exporter" and TLS <= 1.3 is used, - trigger a warning when "tls-unique" is used with TLS 1.3,
- and trigger an error if the stream or context is not a TLS connection.
(Note: "tls-exporter" should also be supported on TLS 1.2 connections.)
stream_crypto_channel_binding(resource $stream_or_context, string $channel_binding_type): string;
Making this function compatible with both streams and contexts should cover all use cases.
Thank you.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu bằng việc xem xét các API PHP streams và stream-context, sau đó là các giao diện OpenSSL được nêu trong issue: SSL_get_peer_finished và SSL_export_keying_material. Công việc được xem là hoàn tất khi một API đã được tài liệu hóa có thể truy xuất dữ liệu channel binding được yêu cầu cho các TLS stream hoặc context và báo cáo các trường hợp kết nối không được hỗ trợ và phiên bản TLS được chỉ định; payload không nêu tên các tệp triển khai hoặc test.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- c, php
- Lĩnh vực
- api, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 32/100