Bug #68344 [ReO->Fbk]: MySQLi does not provide way to disable peer certificate validation
From: andrey@php.net Date: Wed, 21 Oct 2015 14:55:25 +0000 Subject: Bug #68344 [ReO->Fbk]: MySQLi does not provide way to disable peer certificate validation References: 1 Groups: php.bugs Request: Send a blank email to php-bugs+get-196727@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Updated by: andrey@php.net
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
-Status: Re-Opened
+Status: Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
Could you try the latest git code (5.6 or 7.0)?
Cheers,
Andrey
Previous Comments:
------------------------------------------------------------------------
[2015-10-02 08:08:47] spam2 at rhsoft dot net
this was reported for 5.6.2 and now we have 5.6.14 with *nothing* changed and so we still can't
consider using PHP 5.6 in production - WTF!
------------------------------------------------------------------------
[2015-09-02 16:11:02] flound1129 at gmail dot com
The above patch is working for me. Can we get something like it merged into the next patch so we
can close this year-old bug?
------------------------------------------------------------------------
[2015-08-10 13:00:50] arekm at maven dot pl
Also... other approach - maybe php_stream_context_alloc() should inherit options of default stream
automatically (so no need for new API) ?
------------------------------------------------------------------------
[2015-08-10 11:42:18] arekm at maven dot pl
Previous comment was describing IMO nicest solution (provide an API to copy options and use it) and
in mean time for those who need some workaround, tested on 5.6.12:
; obey few default context options
; https://bugs.php.net/bug.php?id=68344
diff -urbB php-5.6.12/ext/mysqlnd/mysqlnd_net.c php-5.6.12/ext/mysqlnd/mysqlnd_net.c
--- php-5.6.12/ext/mysqlnd/mysqlnd_net.c 2015-08-06 09:55:57.000000000 +0200
+++ php-5.6.12/ext/mysqlnd/mysqlnd_net.c 2015-08-10 13:25:30.187912101 +0200
@@ -29,6 +29,7 @@
#include "mysqlnd_ext_plugin.h"
#include "php_network.h"
#include "zend_ini.h"
+#include "ext/standard/file.h"
#ifdef MYSQLND_COMPRESSION_ENABLED
#include <zlib.h>
#endif
@@ -868,6 +868,21 @@ MYSQLND_METHOD(mysqlnd_net, enable_ssl)(
DBG_RETURN(FAIL);
}
+ if (FG(default_context)) {
+ zval **tmpzval = NULL;
+ int i = 0;
+ /* copy values from default stream settings */
+ char *opts[] = { "allow_self_signed", "cafile", "capath",
"ciphers", "CN_match",
+ "disable_compression", "local_cert", "local_pk",
"no_ticket", "passphrase",
+ "peer_fingerprint", "peer_name", "SNI_enabled",
"SNI_server_certs", "SNI_server_name",
+ "verify_depth", "verify_peer", "verify_peer_name", NULL };
+ while (opts[i]) {
+ if (php_stream_context_get_option(FG(default_context), "ssl", opts[i], &tmpzval)
== SUCCESS)
+ php_stream_context_set_option(context, "ssl", opts[i], *tmpzval);
+ i++;
+ }
+ }
+
if (net->data->options.ssl_key) {
zval key_zval;
ZVAL_STRING(&key_zval, net->data->options.ssl_key, 0);
------------------------------------------------------------------------
[2015-08-10 10:50:41] arekm at maven dot pl
Note, this is only to show the idea. It's a ugly patch, no error checking, exposing internal
ext/standard function in unfriendly way.
Anyway with this patch newly created mysqlnd stream inherits all options from default stream thus
obeying what we want - ssl verify_peer, verify_peer_name etc settings.
mysqli then works just fine and with verify_peer_name==false no longer yelds " Peer certificate
CN=... did not match expected CN=..." error.
diff -urbB ../1/php-5.6.12/ext/mysqlnd/mysqlnd_net.c ../php-5.6.12/ext/mysqlnd/mysqlnd_net.c
--- ../1/php-5.6.12/ext/mysqlnd/mysqlnd_net.c 2015-08-06 09:55:57.000000000 +0200
+++ ../php-5.6.12/ext/mysqlnd/mysqlnd_net.c 2015-08-10 12:44:58.377480518 +0200
@@ -29,6 +29,7 @@
#include "mysqlnd_ext_plugin.h"
#include "php_network.h"
#include "zend_ini.h"
+#include "ext/standard/file.h"
#ifdef MYSQLND_COMPRESSION_ENABLED
#include <zlib.h>
#endif
@@ -39,7 +40,7 @@
#include <winsock.h>
#endif
-
+extern int parse_context_options(php_stream_context *context, zval *options TSRMLS_DC);
/* {{{ mysqlnd_set_sock_no_delay */
static int
mysqlnd_set_sock_no_delay(php_stream * stream TSRMLS_DC)
@@ -858,12 +859,14 @@
static enum_func_status
MYSQLND_METHOD(mysqlnd_net, enable_ssl)(MYSQLND_NET * const net TSRMLS_DC)
{
#ifdef MYSQLND_SSL_SUPPORTED
php_stream_context * context = php_stream_context_alloc(TSRMLS_C);
php_stream * net_stream = net->data->m.get_stream(net TSRMLS_CC);
+ parse_context_options(context, FG(default_context)->options TSRMLS_CC) ;
+
DBG_ENTER("mysqlnd_net::enable_ssl");
if (!context) {
DBG_RETURN(FAIL);
}
diff -urbB ../1/php-5.6.12/ext/standard/streamsfuncs.c ../php-5.6.12/ext/standard/streamsfuncs.c
--- ../1/php-5.6.12/ext/standard/streamsfuncs.c 2015-08-06 09:55:57.000000000 +0200
+++ ../php-5.6.12/ext/standard/streamsfuncs.c 2015-08-10 12:44:41.237035776 +0200
@@ -913,7 +913,7 @@
}
}
-static int parse_context_options(php_stream_context *context, zval *options TSRMLS_DC)
+int parse_context_options(php_stream_context *context, zval *options TSRMLS_DC)
{
HashPosition pos, opos;
zval **wval, **oval;
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1
Thread (57 messages)
- Bug #68344 [Opn->Asn]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Asn]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Asn]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Asn->Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [NoF]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [NoF->ReO]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [ReO->Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [NoF->Csd]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Csd]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
- Bug #68344 [PATCH]: MySQLi does not provide way to disable peer certificate validation
| « previous | php.bugs (#196727) | next » |
|---|