Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sun, 25 Oct 2015 21:13:57 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196803@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         arekm at maven dot pl
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

Tested 5.6.14 with patches:
afd31489d0d9999f701467e99ef2b40794eed196
8292260515a904b4d515484145c78f33a06ae1ae

Now it doesn't verify SSL certificate at all. Connection is being made even if peer certificate
doesn't match hostname. What's worse even settting:

$opts = array('ssl'=>array('verify_peer'=> true,
'verify_peer_name' => true));
stream_context_set_default($opts);

doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't obey
default context stream options BUT...

What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
(CLIENT_SSL_VERIFY_SERVER_CERT in libmysqlclient API) mysql_connect option. It works now though but
is NOT default on.

So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:

"6. These include enabling peer verification by default, supporting certificate fingerprint
matching, mitigating against TLS renegotiation attacks, and many new SSL context options to allow
more fine grained control over protocol and verification settings when using encrypted
streams."

is not being applied to mysql SSL/TLS connections?

No strong opinion though. mysql 5.7 probably still doesn't default that option to be on (would
be nice to verify that).

So summary, php5.6 + these two patches:

- back to 5.5 state by default

- $opts = array('ssl'=>array('verify_peer'=> true/false,
'verify_peer_name' => true/false));
stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection

- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT)
and works but turning ON verify_peer/verify_peer_name (is off by default; as it was in 5.5 state)


Previous Comments:
------------------------------------------------------------------------
[2015-10-25 20:33:51] spam2 at rhsoft dot net

no, i can't try git code since i rely on rpm-builds from release tarballs but i can't see
anything proposed in the newsfile of the next 5.6.x release

while i would like to avoid using stream_context_set_default() to work around this it would be at
least better if *that* works correctly instead stay on 5.5.x forever

https://github.com/php/php-src/blob/php-5.6.15RC1/NEWS
nothing about this issue

------------------------------------------------------------------------
[2015-10-21 14:55:22] andrey@php.net

Could you try the latest git code (5.6 or 7.0)?

Cheers,
Andrey

------------------------------------------------------------------------
[2015-10-02 08:08:47] spam2 at rhsoft dot net

this was reported for 5.6.2 and now we have 5.6.14 with *nothing* changed and so we still can't
consider using PHP 5.6 in production - WTF!

------------------------------------------------------------------------
[2015-09-02 16:11:02] flound1129 at gmail dot com

The above patch is working for me.  Can we get something like it merged into the next patch so we
can close this year-old bug?

------------------------------------------------------------------------
[2015-08-10 13:00:50] arekm at maven dot pl

Also... other approach - maybe php_stream_context_alloc() should inherit options of default stream
automatically (so no need for new API) ?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196803) next »