Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sun, 28 Jun 2015 04:22:19 +0000
Subject: Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193948@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:               68344
 Updated by:       php-bugs@lists.php.net
 Reported by:      james at jamesreno dot com
 Summary:          MySQLi does not provide way to disable peer
                   certificate validation
-Status:           Feedback
+Status:           No Feedback
 Type:             Bug
 Package:          MySQLi related
 Operating System: NA
 PHP Version:      5.6.2
 Assigned To:      mysql
 Private report:   N

 New Comment:

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.


Previous Comments:
------------------------------------------------------------------------
[2015-06-17 11:22:32] andrey@php.net

Try using mysqli_real_connect() and pass (1<<30) as a flag (CLIENT_SSL_VERIFY_SERVER_CERT
which however is not exported as PHP define) together with CLIENT_SSL. If that works, then the
proposed patch should work too.

------------------------------------------------------------------------
[2015-06-17 10:51:29] spam2 at rhsoft dot net

well, that idiotic change without an option to disable it when you know what you are doing becomes
famous

http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation

https://discussion.heroku.com/t/ssl-connection-for-cleardb/802

thank you for making upgrade to PHP 5.6 impossible for people using unconditional TLS encryption
when a connection does not use localhost

------------------------------------------------------------------------
[2015-06-15 17:29:51] spam2 at rhsoft dot net

"this needs a good interface"

yes, damned, a global option useable with ini_set() which could be used per-dir to disable the
verification for a testing environment - but, hey, implement the stream options in a dozen of ways
and touch every piece of php-code is so much cooler - and then you wonder why half of the world just
don#t upgrade their servers?

------------------------------------------------------------------------
[2015-06-15 17:21:27] spam2 at rhsoft dot net

what a bullshit - nobody cares about the CN in that context, you just use the same CA-certificate on
client *and* servers - server*s* not just only one

[15-Jun-2015 19:05:05 Europe/Vienna] PHP Warning:  mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 272

------------------------------------------------------------------------
[2015-06-15 17:14:25] spam2 at rhsoft dot net

jesus christ the whole purpose of mysql with certificates is NOT TO TRUST any CA

why?

just because you use the same CA-cert for ssl_set() on both sides and *that verfies* the connection,
looks like people coding things they don't understand at all - try it out by replace the certs
and CA only on one side - tls connection will fail

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#193948) next »