php / php/php-src

check_cert() insists on all provided certificates to validate against system CA store

Đang mở
#8,371 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Extension: openssl Feature
Ngôn ngữ chính
C
Star
40.4k
Fork
8.2k
Merge trung bình
2 ngày 13 giờ
Pull request đã merge (30 ngày)
96

Mô tả

Description

The following code:

php -r  "var_dump(openssl_x509_checkpurpose(file_get_contents('v_crt.pem'), X509_PURPOSE_SSL_SERVER, array('v_ca.pem')));"

Resulted in this output:

bool(false)

But I expected this output instead:

bool(true)

where v_cert.pem contains any letsencrypt issued certificate, v_ca.pem contains two intermediate certs (it's default chain from letsencrypt):
a)
Issuer: C = US, O = Internet Security Research Group, CN = ISRG Root X1
Subject: C = US, O = Let's Encrypt, CN = R3
b)
Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3
Subject: C = US, O = Internet Security Research Group, CN = ISRG Root X1

b) is issued by "DST Root CA X3" which is already expired certificate [1] that (this is important) no longer exists in local (system wide) ca-certificates store (verify that on your ca-certificates store).

openssl_x509_checkpurpose() uses check_cert() which calls X509_verify_cert().

Behaviour of this is all intermediate certs need to validate agains system ca store otherwise check fails. It will fail EVEN if we have one chain path that validates agains our ca system store.

Impact of this is that perfectly valid certificate chains are considered to be not ok for any purpose.

There is a flag that changes this bahaviour to say "ok" when at least single validated chain is found - X509_V_FLAG_PARTIAL_CHAIN. It makes logic sense for what openssl_x509_checkpurpose() is trying to do.

Some other users of this flag:
https://github.com/curl/curl/pull/4655
https://github.com/curl/curl/pull/4655/commits/146ccff7a7c9cdc5bfc9d4f2076a9e57a03c1eb8
https://github.com/noxxi/p5-io-socket-ssl/blob/master/lib/IO/Socket/SSL.pm#L2475

  1. https://community.letsencrypt.org/t/production-chain-changes/150739/3
PHP Version

PHP 8.1.4

Operating System

No response

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Tái hiện lệnh PHP trong issue, sau đó lần theo openssl_x509_checkpurpose() qua check_cert() đến X509_verify_cert(). So sánh hành vi xác minh hiện tại với X509_V_FLAG_PARTIAL_CHAIN và xác nhận rằng một chuỗi thay thế hợp lệ thành công mà không cần chứng chỉ đã hết hạn; thêm hoặc cập nhật coverage cho trường hợp chuỗi chứng chỉ này trước khi xác minh kết quả.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
c, php
Lĩnh vực
cryptography, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
45/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.