Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sun, 25 Oct 2015 20:33:58 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196801@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         spam2 at rhsoft dot net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

no, i can't try git code since i rely on rpm-builds from release tarballs but i can't see
anything proposed in the newsfile of the next 5.6.x release

while i would like to avoid using stream_context_set_default() to work around this it would be at
least better if *that* works correctly instead stay on 5.5.x forever

https://github.com/php/php-src/blob/php-5.6.15RC1/NEWS
nothing about this issue


Previous Comments:
------------------------------------------------------------------------
[2015-10-21 14:55:22] andrey@php.net

Could you try the latest git code (5.6 or 7.0)?

Cheers,
Andrey

------------------------------------------------------------------------
[2015-10-02 08:08:47] spam2 at rhsoft dot net

this was reported for 5.6.2 and now we have 5.6.14 with *nothing* changed and so we still can't
consider using PHP 5.6 in production - WTF!

------------------------------------------------------------------------
[2015-09-02 16:11:02] flound1129 at gmail dot com

The above patch is working for me.  Can we get something like it merged into the next patch so we
can close this year-old bug?

------------------------------------------------------------------------
[2015-08-10 13:00:50] arekm at maven dot pl

Also... other approach - maybe php_stream_context_alloc() should inherit options of default stream
automatically (so no need for new API) ?

------------------------------------------------------------------------
[2015-08-10 11:42:18] arekm at maven dot pl

Previous comment was describing IMO nicest solution (provide an API to copy options and use it) and
in mean time for those who need some workaround, tested on 5.6.12:

; obey few default context options
; https://bugs.php.net/bug.php?id=68344
diff -urbB php-5.6.12/ext/mysqlnd/mysqlnd_net.c php-5.6.12/ext/mysqlnd/mysqlnd_net.c
--- php-5.6.12/ext/mysqlnd/mysqlnd_net.c	2015-08-06 09:55:57.000000000 +0200
+++ php-5.6.12/ext/mysqlnd/mysqlnd_net.c	2015-08-10 13:25:30.187912101 +0200
@@ -29,6 +29,7 @@
 #include "mysqlnd_ext_plugin.h"
 #include "php_network.h"
 #include "zend_ini.h"
+#include "ext/standard/file.h"
 #ifdef MYSQLND_COMPRESSION_ENABLED
 #include <zlib.h>
 #endif
@@ -868,6 +868,21 @@ MYSQLND_METHOD(mysqlnd_net, enable_ssl)(
 		DBG_RETURN(FAIL);
 	}
 
+	if (FG(default_context)) {
+		zval **tmpzval = NULL;
+		int i = 0;
+		/* copy values from default stream settings */
+		char *opts[] = { "allow_self_signed", "cafile", "capath",
"ciphers", "CN_match",
+			"disable_compression", "local_cert", "local_pk",
"no_ticket", "passphrase",
+			"peer_fingerprint", "peer_name", "SNI_enabled",
"SNI_server_certs", "SNI_server_name",
+			"verify_depth", "verify_peer", "verify_peer_name", NULL };
+		while (opts[i]) {
+			if (php_stream_context_get_option(FG(default_context), "ssl", opts[i], &tmpzval)
== SUCCESS)
+				php_stream_context_set_option(context, "ssl", opts[i], *tmpzval);
+			i++;
+		}
+	}
+
 	if (net->data->options.ssl_key) {
 		zval key_zval;
 		ZVAL_STRING(&key_zval, net->data->options.ssl_key, 0);

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196801) next »