Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Fri, 07 Aug 2015 12:08:33 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195001@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         t dot launer at intershop dot de
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             No Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

I've been watching this bug entry for some time now and actually thought this issue was too
important not to be fixed fast. A number of our systems are affected by this bug, seeing that we
maintain a set of distributed applications and a central MySQL server that hosts all the
company's MySQL database instances with which every application server (OTRS, Wikis, ...) must
communicate via X509. I simply cannot upgrade their PHP to 5.6 because that required abandoning our
security policy.
I agree with "spam2 at rhsoft dot net" in that it is a security measure to create server
and client certificates from a CA that is hidden to everyone.

Please consider fixing this bug in 5.6 soon - or at least make the 5.5 functionality available as
option again in version 7.


Previous Comments:
------------------------------------------------------------------------
[2015-08-07 07:31:24] spam2 at rhsoft dot net

and another month is gone where peole which using encryption for anything which make sit to a
ethernet cable the last years CAN NOT UPGRADE TO PHP 5.6 - holy crap mysql encryption in general
broke repeatly without even push a fixing update in a tiemly manner, now it's broken again -
that's all a joke

------------------------------------------------------------------------
[2015-07-10 10:17:29] spam2 at rhsoft dot net

stream_context_set_default(array('ssl'=>array('verify_peer'=>false,
'verify_peer_name'=>false, 'allow_self_signed'=>true))); has to work
anyways but it does not

http://php.net/manual/de/function.stream-context-set-default.php
Set the default stream context which will be used whenever file operations (fopen(),
file_get_contents(), etc...) are called without a context parameter. Uses the same syntax as
stream_context_create()

is pretty clear in the documentation and so PHP is once again not consistent, but that should
anyways be only a temporary workaround because in production environments you want the peer
verification for file_get_contents() to remote server and using stream_context_set_default() for the
sake of mysql-over-tls would disable that too

------------------------------------------------------------------------
[2015-07-10 10:13:34] andrey@php.net

"Try using mysqli_real_connect() and pass (1<<30) as a flag
(CLIENT_SSL_VERIFY_SERVER_CERT which however is not exported as PHP define) together with
CLIENT_SSL. If that works, then the proposed patch should work too."
Sorry, I misread the code:
Please try:
mysqli_init()
mysqli_ssl_set()
mysqli_options($conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false);
mysqli_real_connect(,MYSQLI_CLIENT_SSL);

------------------------------------------------------------------------
[2015-07-10 09:49:44] spam2 at rhsoft dot net

> Try using mysqli_real_connect() and pass (1<<30) 
> as a flag (CLIENT_SSL_VERIFY_SERVER_CERT which 
> however is not exported as PHP define)

if (1<<30) is CLIENT_SSL_VERIFY_SERVER_CERT it's the complete opposite to disable that
nonsense and even if: how would you write portable code running on PHP < 5.6?

$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
$flags = (1<<30) | MYSQLI_CLIENT_SSL;
$rw = mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd,
$this->db, $this->port, '', $flags);

PHP Warning:  mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273

------------------------------------------------------------------------
[2015-07-10 08:11:29] spam2 at rhsoft dot net

WTF - 25 Jun 2015, PHP 5.6.11RC1 still no change

do you guys realize that you broke *multiple times* mysql encryption and that this bug is a
SHOWSTOPPER and forces users to stay at 5.5.x while as already explained that behavior is idiotic
since you DO NOT WANT ca-signed certificates BUT on both sides a certificate from the same (private)
CA
__________________________________________________

FRANKLY THAT IS HOW YOU GENERATE SECURE CERTIFICATES FOR MYSQL AND PHP SO THAT NOBODY WHICH DOES NOT
HAVE THE CA CERTIFICATE CAN'T EVEN CONNECT (GIVEN YOU ENFORCE ENCRYPTED CONNECTIONS IN MYSQL AS
WE DO)

[root@buildserver:~]$ cat /buildserver/ssl-cert/mysql/generate.sh 
#!/usr/bin/bash

umask 066
KEY_LENGTH="4096"
HASH_METHOD="sha256"

UUID=$(cat /proc/sys/kernel/random/uuid)
RANDOM_FILE="/tmp/openssl-$UUID-seed"
touch "$RANDOM_FILE"
chmod 0600 "$RANDOM_FILE"

DIR="/buildserver/ssl-cert/mysql"

rm -rf "$DIR/cert/"
rm -rf "$DIR/db/"
mkdir "$DIR/cert/"
mkdir "$DIR/db/"

touch "$DIR/db/index.txt"
echo "01" > $DIR/db/serial

rm -f "$DIR/ca.key"
rm -f "$DIR/cert/ca.crt"

echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -x509 -days 3650 -keyout "$DIR/ca.key" -out "$DIR/cert/ca.crt"
-config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
chmod 0600 "$DIR/ca.key"

echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -keyout "$DIR/cert/server.key" -out "$DIR/cert/server.csr"
-days 3650 -config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
openssl rsa -in "$DIR/cert/server.key" -out "$DIR/cert/server.key"
openssl ca -policy policy_anything -out "$DIR/cert/server.crt" -days 3650 -config
"$DIR/openssl.cnf" -infiles "$DIR/cert/server.csr"

echo "Random-Seed...."
dd if=/dev/random of="$RANDOM_FILE" bs=1 count=1024 2> /dev/null
sleep 2
openssl req -new -keyout "$DIR/cert/client.key" -out "$DIR/cert/client.csr"
-days 3650 -config "$DIR/openssl.cnf" -$HASH_METHOD -newkey rsa:$KEY_LENGTH -rand
"$RANDOM_FILE"
openssl rsa -in "$DIR/cert/client.key" -out "$DIR/cert/client.key"
openssl ca -policy policy_anything -out "$DIR/cert/client.crt" -days 3650 -config
"$DIR/openssl.cnf" -infiles "$DIR/cert/client.csr"

rm -f "$DIR/cert/server.csr"
rm -f "$DIR/cert/client.csr"
rm -f "$DIR/cert/01.pem"
rm -f "$DIR/cert/02.pem"
rm -f "$DIR/ca.key"

cat "$DIR/cert/server.crt" "$DIR/cert/server.key" >
"$DIR/cert/server.pem"
rm -f "$DIR/cert/server.crt"
rm -f "$DIR/cert/server.key"

cat "$DIR/cert/client.crt" "$DIR/cert/client.key" >
"$DIR/cert/client.pem"
rm -f "$DIR/cert/client.crt"
rm -f "$DIR/cert/client.key"

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#195001) next »