san_peer_matching.phpt 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. --TEST--
  2. Peer verification matches SAN names
  3. --EXTENSIONS--
  4. openssl
  5. --SKIPIF--
  6. <?php
  7. if (!function_exists("proc_open")) die("skip no proc_open");
  8. ?>
  9. --FILE--
  10. <?php
  11. $certFile = __DIR__ . DIRECTORY_SEPARATOR . 'san_peer_matching.pem.tmp';
  12. $san = 'DNS:example.org, DNS:www.example.org, DNS:test.example.org';
  13. $serverCode = <<<'CODE'
  14. $serverUri = "ssl://127.0.0.1:64321";
  15. $serverFlags = STREAM_SERVER_BIND | STREAM_SERVER_LISTEN;
  16. $serverCtx = stream_context_create(['ssl' => [
  17. 'local_cert' => '%s',
  18. ]]);
  19. $server = stream_socket_server($serverUri, $errno, $errstr, $serverFlags, $serverCtx);
  20. phpt_notify();
  21. @stream_socket_accept($server, 1);
  22. @stream_socket_accept($server, 1);
  23. CODE;
  24. $serverCode = sprintf($serverCode, $certFile);
  25. $clientCode = <<<'CODE'
  26. $serverUri = "ssl://127.0.0.1:64321";
  27. $clientFlags = STREAM_CLIENT_CONNECT;
  28. $clientCtx = stream_context_create(['ssl' => [
  29. 'verify_peer' => false,
  30. ]]);
  31. phpt_wait();
  32. stream_context_set_option($clientCtx, 'ssl', 'peer_name', 'example.org');
  33. var_dump(stream_socket_client($serverUri, $errno, $errstr, 1, $clientFlags, $clientCtx));
  34. stream_context_set_option($clientCtx, 'ssl', 'peer_name', 'moar.example.org');
  35. var_dump(stream_socket_client($serverUri, $errno, $errstr, 1, $clientFlags, $clientCtx));
  36. CODE;
  37. include 'CertificateGenerator.inc';
  38. $certificateGenerator = new CertificateGenerator();
  39. $certificateGenerator->saveNewCertAsFileWithKey(null, $certFile, null, $san);
  40. include 'ServerClientTestCase.inc';
  41. ServerClientTestCase::getInstance()->run($clientCode, $serverCode);
  42. ?>
  43. --CLEAN--
  44. <?php
  45. @unlink(__DIR__ . DIRECTORY_SEPARATOR . 'san_peer_matching.pem.tmp');
  46. ?>
  47. --EXPECTF--
  48. resource(%d) of type (stream)
  49. Warning: stream_socket_client(): Unable to locate peer certificate CN in %s on line %d
  50. Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
  51. Warning: stream_socket_client(): Unable to connect to ssl://127.0.0.1:64321 (Unknown error) in %s on line %d
  52. bool(false)