Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Comment by: spam2 at rhsoft dot net
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
Status: No Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
> Try using mysqli_real_connect() and pass (1<<30)
> as a flag (CLIENT_SSL_VERIFY_SERVER_CERT which
> however is not exported as PHP define)
if (1<<30) is CLIENT_SSL_VERIFY_SERVER_CERT it's the complete opposite to disable that
nonsense and even if: how would you write portable code running on PHP < 5.6?
$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
$flags = (1<<30) | MYSQLI_CLIENT_SSL;
$rw = mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd,
$this->db, $this->port, '', $flags);
PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273
Previous Comments:
------------------------------------------------------------------------
[2015-07-10 08:11:29] spam2 at rhsoft dot net
WTF - 25 Jun 2015, PHP 5.6.11RC1 still no change
do you guys realize that you broke *multiple times* mysql encryption and that this bug is a
SHOWSTOPPER and forces users to stay at 5.5.x while as already explained that behavior is idiotic
since you DO NOT WANT ca-signed certificates BUT on both sides a certificate from the same (private)
CA
__________________________________________________
FRANKLY THAT IS HOW YOU GENERATE SECURE CERTIFICATES FOR MYSQL AND PHP SO THAT NOBODY WHICH DOES NOT
HAVE THE CA CERTIFICATE CAN'T EVEN CONNECT (GIVEN YOU ENFORCE ENCRYPTED CONNECTIONS IN MYSQL AS
WE DO)
[root@buildserver:~]$ cat /buildserver/ssl-cert/mysql/generate.sh
#!/usr/bin/bash
umask 066
KEY_LENGTH="4096"
HASH_METHOD="sha256"
UUID=$(cat /proc/sys/kernel/random/uuid)
RANDOM_FILE="/tmp/openssl-$UUID-seed"
touch "$RANDOM_FILE"
chmod 0600 "$RANDOM_FILE"
DIR="/buildserver/ssl-cert/mysql"
rm -rf "$DIR/cert/"
rm -rf "$DIR/db/"
mkdir "$DIR/cert/"
mkdir "$DIR/db/"
touch "$DIR/db/index.txt"
echo "01" > $DIR/db/serial
rm -f "$DIR/ca.key"
rm -f "$DIR/cert/ca.crt"
echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -x509 -days 3650 -keyout "$DIR/ca.key" -out "$DIR/cert/ca.crt"
-config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
chmod 0600 "$DIR/ca.key"
echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -keyout "$DIR/cert/server.key" -out "$DIR/cert/server.csr"
-days 3650 -config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
openssl rsa -in "$DIR/cert/server.key" -out "$DIR/cert/server.key"
openssl ca -policy policy_anything -out "$DIR/cert/server.crt" -days 3650 -config
"$DIR/openssl.cnf" -infiles "$DIR/cert/server.csr"
echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -keyout "$DIR/cert/client.key" -out "$DIR/cert/client.csr"
-days 3650 -config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
openssl rsa -in "$DIR/cert/client.key" -out "$DIR/cert/client.key"
openssl ca -policy policy_anything -out "$DIR/cert/client.crt" -days 3650 -config
"$DIR/openssl.cnf" -infiles "$DIR/cert/client.csr"
rm -f "$DIR/cert/server.csr"
rm -f "$DIR/cert/client.csr"
rm -f "$DIR/cert/01.pem"
rm -f "$DIR/cert/02.pem"
rm -f "$DIR/ca.key"
cat "$DIR/cert/server.crt" "$DIR/cert/server.key" >
"$DIR/cert/server.pem"
rm -f "$DIR/cert/server.crt"
rm -f "$DIR/cert/server.key"
cat "$DIR/cert/client.crt" "$DIR/cert/client.key" >
"$DIR/cert/client.pem"
rm -f "$DIR/cert/client.crt"
rm -f "$DIR/cert/client.key"
------------------------------------------------------------------------
[2015-06-28 04:22:19] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2015-06-17 11:22:32] andrey@php.net
Try using mysqli_real_connect() and pass (1<<30) as a flag (CLIENT_SSL_VERIFY_SERVER_CERT
which however is not exported as PHP define) together with CLIENT_SSL. If that works, then the
proposed patch should work too.
------------------------------------------------------------------------
[2015-06-17 10:51:29] spam2 at rhsoft dot net
well, that idiotic change without an option to disable it when you know what you are doing becomes
famous
http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
https://discussion.heroku.com/t/ssl-connection-for-cleardb/802
thank you for making upgrade to PHP 5.6 impossible for people using unconditional TLS encryption
when a connection does not use localhost
------------------------------------------------------------------------
[2015-06-15 17:29:51] spam2 at rhsoft dot net
"this needs a good interface"
yes, damned, a global option useable with ini_set() which could be used per-dir to disable the
verification for a testing environment - but, hey, implement the stream options in a dozen of ways
and touch every piece of php-code is so much cooler - and then you wonder why half of the world just
don#t upgrade their servers?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1