Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Comment by: arekm at maven dot pl
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
Status: No Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
"Warning: mysqli_real_connect(): Peer certificate CN=.... did not match expected CN" comes
from openssl/xp_ssl.c
That code uses php stream functions like:
stream = php_stream_alloc_rel(&php_openssl_socket_ops, sslsock, persistent_id, "r+");
...
then php_openssl_socket_ops structure has php_openssl_sockop_set_option function which then call few
functions and is some cases raises above error.
apply_peer_verification_policy actually checks verify_peer:
must_verify_peer = GET_VER_OPT("verify_peer")
? zend_is_true(*val)
: sslsock->is_client;
so it should be possible to switch this check off. Unfortunately for me php 5.6.12 is ignoring
setting for this:
$opts = array('ssl'=>array('verify_peer'=> false,
'verify_peer_name' => false));
stream_context_set_default($opts);
$cb = mysqli_init();
mysqli_ssl_set($cb, null, null, null, null, null);
mysqli_real_connect($cb,$db_host, $db_user, $db_pass, $db_name, false, false, MYSQLI_CLIENT_SSL)
and yet I'm getting
"Warning: mysqli_real_connect(): Peer certificate CN=.... did not match expected CN"
So the question is - why openssl code ignores verify_peer setting from default context?
Previous Comments:
------------------------------------------------------------------------
[2015-08-07 12:08:28] t dot launer at intershop dot de
I've been watching this bug entry for some time now and actually thought this issue was too
important not to be fixed fast. A number of our systems are affected by this bug, seeing that we
maintain a set of distributed applications and a central MySQL server that hosts all the
company's MySQL database instances with which every application server (OTRS, Wikis, ...) must
communicate via X509. I simply cannot upgrade their PHP to 5.6 because that required abandoning our
security policy.
I agree with "spam2 at rhsoft dot net" in that it is a security measure to create server
and client certificates from a CA that is hidden to everyone.
Please consider fixing this bug in 5.6 soon - or at least make the 5.5 functionality available as
option again in version 7.
------------------------------------------------------------------------
[2015-08-07 07:31:24] spam2 at rhsoft dot net
and another month is gone where peole which using encryption for anything which make sit to a
ethernet cable the last years CAN NOT UPGRADE TO PHP 5.6 - holy crap mysql encryption in general
broke repeatly without even push a fixing update in a tiemly manner, now it's broken again -
that's all a joke
------------------------------------------------------------------------
[2015-07-10 10:17:29] spam2 at rhsoft dot net
stream_context_set_default(array('ssl'=>array('verify_peer'=>false,
'verify_peer_name'=>false, 'allow_self_signed'=>true))); has to work
anyways but it does not
http://php.net/manual/de/function.stream-context-set-default.php
Set the default stream context which will be used whenever file operations (fopen(),
file_get_contents(), etc...) are called without a context parameter. Uses the same syntax as
stream_context_create()
is pretty clear in the documentation and so PHP is once again not consistent, but that should
anyways be only a temporary workaround because in production environments you want the peer
verification for file_get_contents() to remote server and using stream_context_set_default() for the
sake of mysql-over-tls would disable that too
------------------------------------------------------------------------
[2015-07-10 10:13:34] andrey@php.net
"Try using mysqli_real_connect() and pass (1<<30) as a flag
(CLIENT_SSL_VERIFY_SERVER_CERT which however is not exported as PHP define) together with
CLIENT_SSL. If that works, then the proposed patch should work too."
Sorry, I misread the code:
Please try:
mysqli_init()
mysqli_ssl_set()
mysqli_options($conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false);
mysqli_real_connect(,MYSQLI_CLIENT_SSL);
------------------------------------------------------------------------
[2015-07-10 09:49:44] spam2 at rhsoft dot net
> Try using mysqli_real_connect() and pass (1<<30)
> as a flag (CLIENT_SSL_VERIFY_SERVER_CERT which
> however is not exported as PHP define)
if (1<<30) is CLIENT_SSL_VERIFY_SERVER_CERT it's the complete opposite to disable that
nonsense and even if: how would you write portable code running on PHP < 5.6?
$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
$flags = (1<<30) | MYSQLI_CLIENT_SSL;
$rw = mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd,
$this->db, $this->port, '', $flags);
PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1