Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Mon, 15 Jun 2015 17:21:28 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193523@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1 ID: 68344 Comment by: spam2 at rhsoft dot net Reported by: james at jamesreno dot com Summary: MySQLi does not provide way to disable peer certificate validation Status: Assigned Type: Bug Package: MySQLi related Operating System: NA PHP Version: 5.6.2 Assigned To: mysql Block user comment: N Private report: N New Comment: what a bullshit - nobody cares about the CN in that context, you just use the same CA-certificate on client *and* servers - server*s* not just only one [15-Jun-2015 19:05:05 Europe/Vienna] PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]: Peer certificate CN=MySQL-Administrator' did not match expected CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 272 Previous Comments: ------------------------------------------------------------------------ [2015-06-15 17:14:25] spam2 at rhsoft dot net jesus christ the whole purpose of mysql with certificates is NOT TO TRUST any CA why? just because you use the same CA-cert for ssl_set() on both sides and *that verfies* the connection, looks like people coding things they don't understand at all - try it out by replace the certs and CA only on one side - tls connection will fail ------------------------------------------------------------------------ [2015-02-28 09:15:35] andrey@php.net Hi, does the following patch : http://pastebin.com/D2ZQFNCn solve the problem for you? Andrey ------------------------------------------------------------------------ [2015-02-28 08:50:25] justin at commando dot io We just upgraded from php 5.4 to php 5.6 and got stuck with this. Previously MySQL connected via SSL just fine, but now we are getting: Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed in /MySQLConnection.php on line 31 Here is the connection code we are using: $mysql_certs_path = "/path/to/mysql/certs"; mysqli_ssl_set($db_connection, $mysql_certs_path . "/client-key.pem", $mysql_certs_path . "/client-cert.pem", $mysql_certs_path . "/ca-cert.pem", null, null); $connected = mysqli_real_connect($db_connection, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL); What we can do to fix this? This is blocking for us, and required us to downgrade back to php 5.4. ------------------------------------------------------------------------ [2015-01-28 08:36:12] arekm at maven dot pl It also affects old mysql_connect(). I just got hit by this ugly bug (which is a regression BTW since it worked fine before mysqlnd). ------------------------------------------------------------------------ [2014-12-16 20:12:06] dz at heroku dot com It also looks like MYSQLI_OPT_SSL_VERIFY_SERVER_CERT only takes effect when it's set to true, which means that verify_peer can't be disabled using current means (see mysqlnd_net.c... net->data->options.ssl_verify_peer) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68344 -- Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1

« previous php.bugs (#193523) next »