|   | php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login | 
| 
  [2007-06-21 19:21 UTC] cardoe@php.net
 Description:
------------
Essentially this bug is a mash up of #39283, #35758, #41021, #39039 and possibly others.
Essentially the code I'm using looks like:
$fd = fsockopen("ssl://myhost, myport, $error, $timeout);
$data = fread($fd, 8192);
But you can create the same error using:
 - SoapClient to fetch a WSDL file.
 - file_get_contents()
 - file()
The backend can be an Apache server or a custom app internally that serves SSL encrypted data. It doesn't matter.
If the transmitted data is smaller then the $length passed to fread, everything works successfully. I chose 8192 in my example because file(), file_get_contents() and SoapClient all use 8192 internally based on how the work.
Now if the actual data being transmitted is 10000 for example, you will receive the first block of data fine. Then the next time you call fread(), or in the case of SoapClient, file_get_contents(), file() they will do this internally. You will get:
"SSL: fatal protocol error" printed out and any subsequent action on the file descriptor will result in an OpenSSL error saying the socket has already been shutdown, as per line 116 (current CVS) of ext/openssl/xp_ssl.c
Now you can create this situation with 2048 of data as well. Just call fread($fd, 1024); or fread($fd, 2000); and it will trigger. Basically the $length has to be less then your total amount of data and it will occur.
A lot of the previous bugs PHP developer mention IIS while users mention Apache. I have not tested IIS. I have only tested Apache and a custom app which serves data over SSL. I have tested the output of Apache with wget and the custom app with openssl s_client and both work properly.
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits             | |||||||||||||||||||||||||||||||||||||
|  Copyright © 2001-2025 The PHP Group All rights reserved. | Last updated: Sat Oct 25 13:00:01 2025 UTC | 
I get this bug too,using fsockopen('ssl://...') followed by fgets() I'm using PHP 5.2.1 on Solaris 9 using OpenSSL/0.9.7b. If I call @fgets(...) my application seems to work but it would be better if the bug was fixed properly! The ssl server I'm connecting to is an IIS one.