Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Mon, 15 Jun 2015 17:14:26 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193522@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         spam2 at rhsoft dot net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Assigned
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

jesus christ the whole purpose of mysql with certificates is NOT TO TRUST any CA

why?

just because you use the same CA-cert for ssl_set() on both sides and *that verfies* the connection,
looks like people coding things they don't understand at all - try it out by replace the certs
and CA only on one side - tls connection will fail


Previous Comments:
------------------------------------------------------------------------
[2015-02-28 09:15:35] andrey@php.net

Hi,
does the following patch : http://pastebin.com/D2ZQFNCn
solve the problem for you?
Andrey

------------------------------------------------------------------------
[2015-02-28 08:50:25] justin at commando dot io

We just upgraded from php 5.4 to php 5.6 and got stuck with this. Previously MySQL connected via SSL
just fine, but now we are getting:

Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed in
/MySQLConnection.php on line 31

Here is the connection code we are using:

$mysql_certs_path = "/path/to/mysql/certs";
mysqli_ssl_set($db_connection, $mysql_certs_path . "/client-key.pem", $mysql_certs_path .
"/client-cert.pem", $mysql_certs_path . "/ca-cert.pem", null, null);

$connected = mysqli_real_connect($db_connection, $host, $username, $password, $database, $port,
$socket, MYSQLI_CLIENT_SSL);

What we can do to fix this? This is blocking for us, and required us to downgrade back to php 5.4.

------------------------------------------------------------------------
[2015-01-28 08:36:12] arekm at maven dot pl

It also affects old mysql_connect(). I just got hit by this ugly bug (which is a regression BTW
since it worked fine before mysqlnd).

------------------------------------------------------------------------
[2014-12-16 20:12:06] dz at heroku dot com

It also looks like MYSQLI_OPT_SSL_VERIFY_SERVER_CERT only takes effect when it's set to true,
which means that verify_peer can't be disabled using current means (see mysqlnd_net.c...
net->data->options.ssl_verify_peer)

------------------------------------------------------------------------
[2014-11-12 16:58:58] james at jamesreno dot com

That would work as well, just so long as we could pass in the options.

MySQL exposes a ssl-verify-server-cert option in /etc/my.cnf. Is there a way to make the mysqli
driver read that option from the config and then pass that down through to the streams api layer in
mysqlnd? That would also potentially solve this problem in a more uniform fashion?

Regards,
~james

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#193522) next »