openssl - Socket connection error connecting to sandbox at www.sandbox.paypal.com -
when try connect fsockopen:
$fp = fsockopen('tls://www.sandbox.paypal.com', 443, $errno, $errstr, 30); the function shows following errors:
warning: fsockopen() [function.fsockopen]: ssl operation failed code 1. openssl error messages: error:14094410:ssl routines:ssl3_read_bytes:sslv3 alert handshake failure in /home/puntodec/public_html/test_socket.php on (line number) warning: fsockopen() [function.fsockopen]: failed enable crypto in /home/puntodec/public_html/test_socket.php on (line number) warning: fsockopen() [function.fsockopen]: unable connect tls://www.sandbox.paypal.com:443 (unknown error) in (line number) but if use tls://www.paypal.com there no show errors. has paypal has changed socket configuration of sandbox? or else wrong?
please me, help.
has paypal has changed socket configuration of sandbox? or else wrong?
it looks paypal disabled tls 1.0 , 1.1. or, supporting aes/gcm cipher suites (and similar). must use tls 1.2.
you can find blog post or press release stating same...
tls 1.0
$ /usr/local/bin/openssl s_client -connect www.sandbox.paypal.com:443 -tls1 -servername www.sandbox.paypal.com connected(00000003) 140735201563100:error:14094410:ssl routines:ssl3_read_bytes:sslv3 alert handshake failure:s3_pkt.c:1472:ssl alert number 40 140735201563100:error:1409e0e5:ssl routines:ssl3_write_bytes:ssl handshake failure:s3_pkt.c:656: --- no peer certificate available --- no client certificate ca names sent --- ssl handshake has read 7 bytes , written 0 bytes --- new, (none), cipher (none) secure renegotiation not supported compression: none expansion: none no alpn negotiated ssl-session: protocol : tlsv1 cipher : 0000 ... tls 1.2
$ /usr/local/bin/openssl s_client -connect www.sandbox.paypal.com:443 -tls1_2 -servername www.sandbox.paypal.com connected(00000003) ... --- certificate chain 0 s:/jurisdictionc=us/jurisdictionst=delaware/businesscategory=private organization/serialnumber=3014267/c=us/postalcode=95131-2021/st=california/l=san jose/street=2211 n 1st st/o=paypal, inc./ou=paypal production/cn=www.sandbox.paypal.com i:/c=us/o=symantec corporation/ou=symantec trust network/cn=symantec class 3 ev ssl ca - g3 1 s:/c=us/o=symantec corporation/ou=symantec trust network/cn=symantec class 3 ev ssl ca - g3 i:/c=us/o=verisign, inc./ou=verisign trust network/ou=(c) 2006 verisign, inc. - authorized use only/cn=verisign class 3 public primary certification authority - g5 --- server certificate -----begin certificate----- miifjdccbhsgawibagiqveuz+egdzkxfsknpa78etzanbgkqhkig9w0baqsfadb3 mqswcqydvqqgewjvuzedmbsga1uechmuu3ltyw50zwmgq29ycg9yyxrpb24xhzad bgnvbastfln5bwfudgvjifrydxn0ie5ldhdvcmsxkdambgnvbamth1n5bwfudgvj iensyxnzidmgrvygu1nmienbic0grzmwhhcnmtuwote4mdawmdawwhcnmtcwoti5 mjm1otu5wjccarcxezarbgsrbgeeayi3paibaxmcvvmxgtaxbgsrbgeeayi3paib agwirgvsyxdhcmuxhtabbgnvba8tffbyaxzhdgugt3jnyw5pemf0aw9umrawdgyd vqqfewczmde0mjy3mqswcqydvqqgewjvuzetmbega1ueeqwkotuxmzetmjaymtet mbega1uecawkq2fsawzvcm5pyterma8ga1uebwwiu2fuiepvc2uxfjaubgnvbakm dtiymtegtiaxc3qgu3qxftatbgnvbaomdfbhevbhbcwgsw5jljeambgga1uecwwr ugf5ugfsifbyb2r1y3rpb24xhzadbgnvbammfnd3dy5zyw5kym94lnbhexbhbc5j b20wggeima0gcsqgsib3dqebaquaa4ibdwawggekaoibaqdoqlgp1/ogaq7tlb1a 1kwr6a3eifzrkl5ht9fmwr5sligjbzqc4udjukcoqybqzcwfrvc486avttave2jk pvp1oertrt7rqh8oq/d60x2cv32pmvwo0nnpsiqwwektqavfhouzf+4nfp3lxfga gb4k4nbeq/pegcarixlgc06m85urz3b10jqitnwgihdrywzh9plhnpf6m/zvtlqw gyzxu11gtq8wb5ot4q2vlqtf1wcr4li5hmafivhyxgjnlpfdi3pmnkjtizegn1at kqkxyxztt9v4ynwm7jevygbpxrjkrhgyy52o35ukndo+8j27hnx8kwnshi1ogpc+ dezbagmbaagjggfwmiibbdahbgnvhreegjayghz3d3cuc2fuzgjvec5wyxlwywwu y29tmakga1udewqcmaawdgydvr0paqh/baqdagwgmb0ga1udjqqwmbqgccsgaquf bwmbbggrbgefbqcdajbmbgnvhsaexzbdmfsgc2cgsagg+eubbxcgmewwiwyikwyb bquhagewf2h0dhbzoi8vzc5zew1jyi5jb20vy3bzmcugccsgaqufbwicmbkaf2h0 dhbzoi8vzc5zew1jyi5jb20vcnbhmb8ga1udiwqymbaafafzq+fdogtzpmrj1s8g b1fvkedqmcsga1udhwqkmciwikaeobyggmh0dha6ly9zci5zew1jyi5jb20vc3iu y3jsmfcgccsgaqufbwebbeswstafbggrbgefbqcwayytahr0cdovl3nylnn5bwnk lmnvbtambggrbgefbqcwaoyaahr0cdovl3nylnn5bwnilmnvbs9zci5jcnqwdqyj kozihvcnaqelbqadggebacezzkmkatekssutabf+qerp2cqqjlzefggnlxdm8hnb mh05rq95fsqgqmskprbdnwxyqperee7r2wvw4egmm0kmtu+pwlm/w1dase0e/5qn 6gx9is0wc7df4w3usgt8m4itp225wf9doh2d3+acw19xhfmri0fqiogrpso3u0/x td7qkpfnlrgpxh5xz5qreijeznbi89dw1ileddjni/oczmygupfzs2vy4eqr0w+s 0nwsfhzijxkjug2nrdjxjamzasagwr8acyoi8l86hjp8gc554z6tiua6of2gxvzx ngm1+klnbghy5nrtejg10kcqkldh6nmdor1zjajm7mw= -----end certificate----- subject=/jurisdictionc=us/jurisdictionst=delaware/businesscategory=private organization/serialnumber=3014267/c=us/postalcode=95131-2021/st=california/l=san jose/street=2211 n 1st st/o=paypal, inc./ou=paypal production/cn=www.sandbox.paypal.com issuer=/c=us/o=symantec corporation/ou=symantec trust network/cn=symantec class 3 ev ssl ca - g3 --- no client certificate ca names sent peer signing digest: sha1 server temp key: ecdh, p-256, 256 bits --- ssl handshake has read 3263 bytes , written 474 bytes --- new, tlsv1/sslv3, cipher ecdhe-rsa-aes128-gcm-sha256 server public key 2048 bit secure renegotiation supported compression: none expansion: none no alpn negotiated ssl-session: protocol : tlsv1.2 cipher : ecdhe-rsa-aes128-gcm-sha256 session-id: 9e01cd86fa9cf328ad505f17e34c0a9be6846f89e553d8d0f2946f8859f695c7 session-id-ctx: master-key: bb1ac5e8c2aaf6b393eb85558c25f2ad8a28ca071e5605d3cea714a15dc8e9d1 16948150238a67245bbe5c3bd7b81ec2 ...
Comments
Post a Comment