We switched the PHP from 5.5 to 5.6, this leads to the result that email sending via smtp (with TLS enabled) module failed. A quick look at the official documentation (https://secure.php.net/manual/en/migration56.incompatible.php), a section "Stream wrappers now verify peer certificates and host names by default when using SSL/TLS" drew our attention.

I created a patch and uploaded it here for sharing those who facing the same issue. the patch is based on 7.x-1.0.

Comments

@Mover created an issue. See original summary.

@James’s picture

Issue summary: View changes
StatusFileSize
new70.7 KB
@James’s picture

Status: Needs work » Needs review
StatusFileSize
new77.48 KB

Another patch for 7.x-1.x

damienmckenna’s picture

Assigned: @James » Unassigned

Don't forget to unassign the issue after you upload a patch.

damienmckenna’s picture

Title: PHP 5.6 upgrade and SMTP incompatibility » PHP 5.6 upgrade and SMTP incompatibility (updated phpmailer)
Version: 7.x-1.0 » 7.x-1.x-dev

So basically you updated phpmailer to 5.2.14? Does the patch include any additional changes to that file?

@James’s picture

Thank you Damien.
No, the verify_peer_name option is set to be FALSE in the patch and What I did is to lowercase those methods of smtp called in smtp.phpmailer.inc module, since those method names start with lowercase letter now.

btafoya’s picture

Is this going to be included in the 8 development version as well?

damienmckenna’s picture

@btafoya: Someone would have to port the patch to the D8 branch first.

Anonymous’s picture

Thanks @Mover for the patch! Helped us quite a lot.

We were running into the same issue, but setting verify_peer_name = false wasn't enough for us - due to using a self-signed SSL cert we also needed to set allow_self_signed = false. PHP 5.6 did change verify_peer from false to true [1] (which triggered the validations with verify_peer_name and allow_self_signed).
Therefore I think it would be better to either resort to the previous behaviour (and set verify_peer = false) or - given the security implications of this - make it an configurable option?

[1] http://php.net/manual/en/context.ssl.php#refsect1-context.ssl-changelog

mpv’s picture

StatusFileSize
new66.15 KB

I've updated the patch for the latest dev. I have also removed some the changes in #3. The previous patch replaced the logging with echo and removed some exceptions (those changes are reverted in this patch). It's working for me with the minimal testing I've done but someone should review and test more thoroughly.

chris matthews’s picture

Status: Needs review » Needs work
Issue tags: +Needs reroll, +Needs rework

The year old patch to smtp.phpmailer.inc and smtp.transport.inc in #10 does not apply to the latest 7.x-1.x-dev snapshot and needs to be rerolled again.

bluegeek9’s picture

Status: Needs work » Closed (outdated)
Issue tags: -, -
//www.flaticon.com/free-icons/thank-you Thank you for your contribution!

Unfortunatly, Drupal 7 is End of Life and no longer supported. We strondly encourage you to upgrade to a supported version of Drupal.

Now that this issue is closed, please review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, please credit people who helped resolve this issue.