Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
| From: | spam2 at rhsoft dot net | Date: | Mon, 15 Jun 2015 17:21:28 +0000 |
| Subject: | Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193523@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Comment by: spam2 at rhsoft dot net
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
Status: Assigned
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
what a bullshit - nobody cares about the CN in that context, you just use the same CA-certificate on
client *and* servers - server*s* not just only one
[15-Jun-2015 19:05:05 Europe/Vienna] PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=
MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 272
Previous Comments:
------------------------------------------------------------------------
[2015-06-15 17:14:25] spam2 at rhsoft dot net
jesus christ the whole purpose of mysql with certificates is NOT TO TRUST any CA
why?
just because you use the same CA-cert for ssl_set() on both sides and *that verfies* the connection,
looks like people coding things they don't understand at all - try it out by replace the certs
and CA only on one side - tls connection will fail
------------------------------------------------------------------------
[2015-02-28 09:15:35] andrey@php.net
Hi,
does the following patch : http://pastebin.com/D2ZQFNCn
solve the problem for you?
Andrey
------------------------------------------------------------------------
[2015-02-28 08:50:25] justin at commando dot io
We just upgraded from php 5.4 to php 5.6 and got stuck with this. Previously MySQL connected via SSL
just fine, but now we are getting:
Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed in
/MySQLConnection.php on line 31
Here is the connection code we are using:
$mysql_certs_path = "/path/to/mysql/certs";
mysqli_ssl_set($db_connection, $mysql_certs_path . "/client-key.pem", $mysql_certs_path .
"/client-cert.pem", $mysql_certs_path . "/ca-cert.pem", null, null);
$connected = mysqli_real_connect($db_connection, $host, $username, $password, $database, $port,
$socket, MYSQLI_CLIENT_SSL);
What we can do to fix this? This is blocking for us, and required us to downgrade back to php 5.4.
------------------------------------------------------------------------
[2015-01-28 08:36:12] arekm at maven dot pl
It also affects old mysql_connect(). I just got hit by this ugly bug (which is a regression BTW
since it worked fine before mysqlnd).
------------------------------------------------------------------------
[2014-12-16 20:12:06] dz at heroku dot com
It also looks like MYSQLI_OPT_SSL_VERIFY_SERVER_CERT only takes effect when it's set to true,
which means that verify_peer can't be disabled using current means (see mysqlnd_net.c...
net->data->options.ssl_verify_peer)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1