Bug #68344 [Asn]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sat, 28 Feb 2015 09:15:36 +0000
Subject: Bug #68344 [Asn]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191006@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Updated by:         andrey@php.net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Assigned
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

Hi,
does the following patch : http://pastebin.com/D2ZQFNCn
solve the problem for you?
Andrey


Previous Comments:
------------------------------------------------------------------------
[2015-02-28 08:50:25] justin at commando dot io

We just upgraded from php 5.4 to php 5.6 and got stuck with this. Previously MySQL connected via SSL
just fine, but now we are getting:

Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed in
/MySQLConnection.php on line 31

Here is the connection code we are using:

$mysql_certs_path = "/path/to/mysql/certs";
mysqli_ssl_set($db_connection, $mysql_certs_path . "/client-key.pem", $mysql_certs_path .
"/client-cert.pem", $mysql_certs_path . "/ca-cert.pem", null, null);

$connected = mysqli_real_connect($db_connection, $host, $username, $password, $database, $port,
$socket, MYSQLI_CLIENT_SSL);

What we can do to fix this? This is blocking for us, and required us to downgrade back to php 5.4.

------------------------------------------------------------------------
[2015-01-28 08:36:12] arekm at maven dot pl

It also affects old mysql_connect(). I just got hit by this ugly bug (which is a regression BTW
since it worked fine before mysqlnd).

------------------------------------------------------------------------
[2014-12-16 20:12:06] dz at heroku dot com

It also looks like MYSQLI_OPT_SSL_VERIFY_SERVER_CERT only takes effect when it's set to true,
which means that verify_peer can't be disabled using current means (see mysqlnd_net.c...
net->data->options.ssl_verify_peer)

------------------------------------------------------------------------
[2014-11-12 16:58:58] james at jamesreno dot com

That would work as well, just so long as we could pass in the options.

MySQL exposes a ssl-verify-server-cert option in /etc/my.cnf. Is there a way to make the mysqli
driver read that option from the config and then pass that down through to the streams api layer in
mysqlnd? That would also potentially solve this problem in a more uniform fashion?

Regards,
~james

------------------------------------------------------------------------
[2014-11-12 16:42:23] johannes@php.net

Adding the option that way works only for specially crafted applications, not off the shelf apps. On
the other hand I know no generic application (wordpress etc.) offering SSL so maybe that's no
issue. Second issue is whether allowing any stream option will cause issues if users are "too
smart" ... if that is safe my favorite would be a mysqlnd_set_default_stream_context() function
or similar which works for all APIs.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#191006) next »