Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Wed, 28 Jan 2015 08:36:13 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190260@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         arekm at maven dot pl
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Assigned
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

It also affects old mysql_connect(). I just got hit by this ugly bug (which is a regression BTW
since it worked fine before mysqlnd).


Previous Comments:
------------------------------------------------------------------------
[2014-12-16 20:12:06] dz at heroku dot com

It also looks like MYSQLI_OPT_SSL_VERIFY_SERVER_CERT only takes effect when it's set to true,
which means that verify_peer can't be disabled using current means (see mysqlnd_net.c...
net->data->options.ssl_verify_peer)

------------------------------------------------------------------------
[2014-11-12 16:58:58] james at jamesreno dot com

That would work as well, just so long as we could pass in the options.

MySQL exposes a ssl-verify-server-cert option in /etc/my.cnf. Is there a way to make the mysqli
driver read that option from the config and then pass that down through to the streams api layer in
mysqlnd? That would also potentially solve this problem in a more uniform fashion?

Regards,
~james

------------------------------------------------------------------------
[2014-11-12 16:42:23] johannes@php.net

Adding the option that way works only for specially crafted applications, not off the shelf apps. On
the other hand I know no generic application (wordpress etc.) offering SSL so maybe that's no
issue. Second issue is whether allowing any stream option will cause issues if users are "too
smart" ... if that is safe my favorite would be a mysqlnd_set_default_stream_context() function
or similar which works for all APIs.

------------------------------------------------------------------------
[2014-11-12 15:16:31] james at jamesreno dot com

Even adding the cert, the problem is the 'peer-name' validity.

We have a cert installed for say "db1.example.com" on our cluster. So long as we connect
to db1.example.com we're golden and everything works. The second we try to connect to a single
node ie: "db1a.wdc01.example.com" the certname validation fails and mysqli is unable to
connect.

What about the ability to pass in a context into mysqli_init($ctx) or new mysqli($ctx) that would
allow you to specify the stream context? Would that option be a good path forward for now?

Regards,
~James

------------------------------------------------------------------------
[2014-11-12 10:49:38] johannes@php.net

I agree we have to export that option from stream layer somehow, this needs a good interface. As a
work-around you should be able to add your own key to your system's key storage.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#190260) next »