xref: /PHP-8.4/ext/openssl/tests/bug65729.phpt (revision 74859783)
1--TEST--
2Bug #65729: CN_match gives false positive when wildcard is used
3--EXTENSIONS--
4openssl
5--SKIPIF--
6<?php
7if (!function_exists("proc_open")) die("skip no proc_open");
8?>
9--FILE--
10<?php
11$certFile = __DIR__ . DIRECTORY_SEPARATOR . 'bug65729.pem.tmp';
12$cacertFile = __DIR__ . DIRECTORY_SEPARATOR . 'bug65729-ca.pem.tmp';
13
14$serverCode = <<<'CODE'
15    $serverUri = "ssl://127.0.0.1:64321";
16    $serverFlags = STREAM_SERVER_BIND | STREAM_SERVER_LISTEN;
17    $serverCtx = stream_context_create(['ssl' => [
18        'local_cert' => '%s'
19    ]]);
20
21    $server = stream_socket_server($serverUri, $errno, $errstr, $serverFlags, $serverCtx);
22    phpt_notify();
23
24    $expected_names = ['foo.test.com.sg', 'foo.test.com', 'FOO.TEST.COM', 'foo.bar.test.com'];
25    foreach ($expected_names as $name) {
26        @stream_socket_accept($server, 1);
27    }
28CODE;
29$serverCode = sprintf($serverCode, $certFile);
30
31$clientCode = <<<'CODE'
32    $serverUri = "ssl://127.0.0.1:64321";
33    $clientFlags = STREAM_CLIENT_CONNECT;
34
35    phpt_wait();
36
37    $expected_names = ['foo.test.com.sg', 'foo.test.com', 'FOO.TEST.COM', 'foo.bar.test.com'];
38    foreach ($expected_names as $expected_name) {
39        $clientCtx = stream_context_create(['ssl' => [
40            'verify_peer'        => true,
41            'peer_name'          => $expected_name,
42            'cafile'             => '%s',
43        ]]);
44
45        var_dump(stream_socket_client($serverUri, $errno, $errstr, 2, $clientFlags, $clientCtx));
46    }
47CODE;
48$clientCode = sprintf($clientCode, $cacertFile);
49
50include 'CertificateGenerator.inc';
51$certificateGenerator = new CertificateGenerator();
52$certificateGenerator->saveCaCert($cacertFile);
53$certificateGenerator->saveNewCertAsFileWithKey('*.test.com', $certFile);
54
55include 'ServerClientTestCase.inc';
56ServerClientTestCase::getInstance()->run($clientCode, $serverCode);
57?>
58--CLEAN--
59<?php
60@unlink(__DIR__ . DIRECTORY_SEPARATOR . 'bug65729.pem.tmp');
61@unlink(__DIR__ . DIRECTORY_SEPARATOR . 'bug65729-ca.pem.tmp');
62?>
63--EXPECTF--
64Warning: stream_socket_client(): Peer certificate CN=`*.test.com' did not match expected CN=`foo.test.com.sg' in %s on line %d
65
66Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
67
68Warning: stream_socket_client(): Unable to connect to ssl://127.0.0.1:64321 (Unknown error) in %s on line %d
69bool(false)
70resource(%d) of type (stream)
71resource(%d) of type (stream)
72
73Warning: stream_socket_client(): Peer certificate CN=`*.test.com' did not match expected CN=`foo.bar.test.com' in %s on line %d
74
75Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
76
77Warning: stream_socket_client(): Unable to connect to ssl://127.0.0.1:64321 (Unknown error) in %s on line %d
78bool(false)
79