Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Thu, 29 Oct 2015 12:26:17 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196872@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         clint at ostalks dot com
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

This bug has been biting me as I use php 5.6 to connect to Google SQL (part of the Google Cloud
services).  This simply doesn't work.  There are a number of people who have this similar issue
as well: http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
and http://stackoverflow.com/questions/28777416/mysqli-real-connect-getting-ssl3-get-server-certificatecertificate-verify-fai

I do not want to downgrade as much as possible to 5.5.


Previous Comments:
------------------------------------------------------------------------
[2015-10-29 09:59:19] tyrael@php.net

for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16

------------------------------------------------------------------------
[2015-10-26 07:29:19] arekm at maven dot pl

> As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of
> a stable branch. So it is either OFF or ON. For 7.0 I need to push a change for
> the third state.

Actually you change behaviour since currently (without these patches) default 5.6 behaviour is to
verifify ssl certificates (annoying for many but well... it is a change).

> What MySQL 5.7 has to do with this?
Nothing beside me wondering what's "default" for 5.7 libmysqclient and if php should
follow (or not).

------------------------------------------------------------------------
[2015-10-26 07:21:34] andrey@php.net

Hi,


>Tested 5.6.14 with patches:
>afd31489d0d9999f701467e99ef2b40794eed196
>8292260515a904b4d515484145c78f33a06ae1ae

>Now it doesn't verify SSL certificate at all. Connection is being made even if peer
>certificate doesn't match >hostname. What's worse even settting:

>$opts = array('ssl'=>array('verify_peer'=> true,
>'verify_peer_name' => true));
>stream_context_set_default($opts);

yes, defaults never had power over the mysqlnd connnections.

>doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't
>obey default context >stream options BUT...

yes

>What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
>(CLIENT_SSL_VERIFY_SERVER_CERT >in libmysqlclient API) mysql_connect option. It works now though
>but is NOT default on.

yes, because we need 3 states. OFF (no check), ON (check), DEFAULT (the default behavior of the PHP
streams). As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of a
stable branch. So it is either OFF or ON. For 7.0 I need to push a change for the third state.

>So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:

>"6. These include enabling peer verification by default, supporting certificate fingerprint
>matching, >mitigating against TLS renegotiation attacks, and many new SSL context options to
>allow more fine grained >control over protocol and verification settings when using encrypted
>streams."

>is not being applied to mysql SSL/TLS connections?

Because I want to give the developers a change to migrate to 5.6 from 5.5 . In 7.0 the behavior will
be the advertised in this page. The developers then need to change their applications.

>No strong opinion though. mysql 5.7 probably still doesn't default that option to be on
>(would be nice to >verify that).

What MySQL 5.7 has to do with this?

>So summary, php5.6 + these two patches:

>- back to 5.5 state by default

yes

>- $opts = array('ssl'=>array('verify_peer'=> true/false,
>'verify_peer_name' => true/false));
>stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection

>- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as
>MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT) and works >but turning ON verify_peer/verify_peer_name (is
>off by default; as it was in 5.5 state)\

yes, for explicit check one needs to set this flag, for 5.6 . For 7.0 I will push a change that make
verify the default value.

Thanks for the input. This is what I needed to hear :)

Andrey

------------------------------------------------------------------------
[2015-10-25 21:13:55] arekm at maven dot pl

Tested 5.6.14 with patches:
afd31489d0d9999f701467e99ef2b40794eed196
8292260515a904b4d515484145c78f33a06ae1ae

Now it doesn't verify SSL certificate at all. Connection is being made even if peer certificate
doesn't match hostname. What's worse even settting:

$opts = array('ssl'=>array('verify_peer'=> true,
'verify_peer_name' => true));
stream_context_set_default($opts);

doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't obey
default context stream options BUT...

What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
(CLIENT_SSL_VERIFY_SERVER_CERT in libmysqlclient API) mysql_connect option. It works now though but
is NOT default on.

So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:

"6. These include enabling peer verification by default, supporting certificate fingerprint
matching, mitigating against TLS renegotiation attacks, and many new SSL context options to allow
more fine grained control over protocol and verification settings when using encrypted
streams."

is not being applied to mysql SSL/TLS connections?

No strong opinion though. mysql 5.7 probably still doesn't default that option to be on (would
be nice to verify that).

So summary, php5.6 + these two patches:

- back to 5.5 state by default

- $opts = array('ssl'=>array('verify_peer'=> true/false,
'verify_peer_name' => true/false));
stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection

- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT)
and works but turning ON verify_peer/verify_peer_name (is off by default; as it was in 5.5 state)

------------------------------------------------------------------------
[2015-10-25 20:33:51] spam2 at rhsoft dot net

no, i can't try git code since i rely on rpm-builds from release tarballs but i can't see
anything proposed in the newsfile of the next 5.6.x release

while i would like to avoid using stream_context_set_default() to work around this it would be at
least better if *that* works correctly instead stay on 5.5.x forever

https://github.com/php/php-src/blob/php-5.6.15RC1/NEWS
nothing about this issue

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196872) next »