Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Comment by: arekm at maven dot pl
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
Status: Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
> As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of
> a stable branch. So it is either OFF or ON. For 7.0 I need to push a change for
> the third state.
Actually you change behaviour since currently (without these patches) default 5.6 behaviour is to
verifify ssl certificates (annoying for many but well... it is a change).
> What MySQL 5.7 has to do with this?
Nothing beside me wondering what's "default" for 5.7 libmysqclient and if php should
follow (or not).
Previous Comments:
------------------------------------------------------------------------
[2015-10-26 07:21:34] andrey@php.net
Hi,
>Tested 5.6.14 with patches:
>afd31489d0d9999f701467e99ef2b40794eed196
>8292260515a904b4d515484145c78f33a06ae1ae
>Now it doesn't verify SSL certificate at all. Connection is being made even if peer
>certificate doesn't match >hostname. What's worse even settting:
>$opts = array('ssl'=>array('verify_peer'=> true,
>'verify_peer_name' => true));
>stream_context_set_default($opts);
yes, defaults never had power over the mysqlnd connnections.
>doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't
>obey default context >stream options BUT...
yes
>What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
>(CLIENT_SSL_VERIFY_SERVER_CERT >in libmysqlclient API) mysql_connect option. It works now though
>but is NOT default on.
yes, because we need 3 states. OFF (no check), ON (check), DEFAULT (the default behavior of the PHP
streams). As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of a
stable branch. So it is either OFF or ON. For 7.0 I need to push a change for the third state.
>So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:
>"6. These include enabling peer verification by default, supporting certificate fingerprint
>matching, >mitigating against TLS renegotiation attacks, and many new SSL context options to
>allow more fine grained >control over protocol and verification settings when using encrypted
>streams."
>is not being applied to mysql SSL/TLS connections?
Because I want to give the developers a change to migrate to 5.6 from 5.5 . In 7.0 the behavior will
be the advertised in this page. The developers then need to change their applications.
>No strong opinion though. mysql 5.7 probably still doesn't default that option to be on
>(would be nice to >verify that).
What MySQL 5.7 has to do with this?
>So summary, php5.6 + these two patches:
>- back to 5.5 state by default
yes
>- $opts = array('ssl'=>array('verify_peer'=> true/false,
>'verify_peer_name' => true/false));
>stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection
>- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as
>MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT) and works >but turning ON verify_peer/verify_peer_name (is
>off by default; as it was in 5.5 state)\
yes, for explicit check one needs to set this flag, for 5.6 . For 7.0 I will push a change that make
verify the default value.
Thanks for the input. This is what I needed to hear :)
Andrey
------------------------------------------------------------------------
[2015-10-25 21:13:55] arekm at maven dot pl
Tested 5.6.14 with patches:
afd31489d0d9999f701467e99ef2b40794eed196
8292260515a904b4d515484145c78f33a06ae1ae
Now it doesn't verify SSL certificate at all. Connection is being made even if peer certificate
doesn't match hostname. What's worse even settting:
$opts = array('ssl'=>array('verify_peer'=> true,
'verify_peer_name' => true));
stream_context_set_default($opts);
doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't obey
default context stream options BUT...
What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
(CLIENT_SSL_VERIFY_SERVER_CERT in libmysqlclient API) mysql_connect option. It works now though but
is NOT default on.
So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:
"6. These include enabling peer verification by default, supporting certificate fingerprint
matching, mitigating against TLS renegotiation attacks, and many new SSL context options to allow
more fine grained control over protocol and verification settings when using encrypted
streams."
is not being applied to mysql SSL/TLS connections?
No strong opinion though. mysql 5.7 probably still doesn't default that option to be on (would
be nice to verify that).
So summary, php5.6 + these two patches:
- back to 5.5 state by default
- $opts = array('ssl'=>array('verify_peer'=> true/false,
'verify_peer_name' => true/false));
stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection
- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT)
and works but turning ON verify_peer/verify_peer_name (is off by default; as it was in 5.5 state)
------------------------------------------------------------------------
[2015-10-25 20:33:51] spam2 at rhsoft dot net
no, i can't try git code since i rely on rpm-builds from release tarballs but i can't see
anything proposed in the newsfile of the next 5.6.x release
while i would like to avoid using stream_context_set_default() to work around this it would be at
least better if *that* works correctly instead stay on 5.5.x forever
https://github.com/php/php-src/blob/php-5.6.15RC1/NEWS
nothing about this issue
------------------------------------------------------------------------
[2015-10-21 14:55:22] andrey@php.net
Could you try the latest git code (5.6 or 7.0)?
Cheers,
Andrey
------------------------------------------------------------------------
[2015-10-02 08:08:47] spam2 at rhsoft dot net
this was reported for 5.6.2 and now we have 5.6.14 with *nothing* changed and so we still can't
consider using PHP 5.6 in production - WTF!
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1