Bug #68344 [Asn->Fbk]: MySQLi does not provide way to disable peer certificate validation

From: Date: Wed, 17 Jun 2015 11:22:33 +0000
Subject: Bug #68344 [Asn->Fbk]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193601@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Updated by:         andrey@php.net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
-Status:             Assigned
+Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

Try using mysqli_real_connect() and pass (1<<30) as a flag (CLIENT_SSL_VERIFY_SERVER_CERT
which however is not exported as PHP define) together with CLIENT_SSL. If that works, then the
proposed patch should work too.


Previous Comments:
------------------------------------------------------------------------
[2015-06-17 10:51:29] spam2 at rhsoft dot net

well, that idiotic change without an option to disable it when you know what you are doing becomes
famous

http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation

https://discussion.heroku.com/t/ssl-connection-for-cleardb/802

thank you for making upgrade to PHP 5.6 impossible for people using unconditional TLS encryption
when a connection does not use localhost

------------------------------------------------------------------------
[2015-06-15 17:29:51] spam2 at rhsoft dot net

"this needs a good interface"

yes, damned, a global option useable with ini_set() which could be used per-dir to disable the
verification for a testing environment - but, hey, implement the stream options in a dozen of ways
and touch every piece of php-code is so much cooler - and then you wonder why half of the world just
don#t upgrade their servers?

------------------------------------------------------------------------
[2015-06-15 17:21:27] spam2 at rhsoft dot net

what a bullshit - nobody cares about the CN in that context, you just use the same CA-certificate on
client *and* servers - server*s* not just only one

[15-Jun-2015 19:05:05 Europe/Vienna] PHP Warning:  mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 272

------------------------------------------------------------------------
[2015-06-15 17:14:25] spam2 at rhsoft dot net

jesus christ the whole purpose of mysql with certificates is NOT TO TRUST any CA

why?

just because you use the same CA-cert for ssl_set() on both sides and *that verfies* the connection,
looks like people coding things they don't understand at all - try it out by replace the certs
and CA only on one side - tls connection will fail

------------------------------------------------------------------------
[2015-02-28 09:15:35] andrey@php.net

Hi,
does the following patch : http://pastebin.com/D2ZQFNCn
solve the problem for you?
Andrey

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#193601) next »