Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Fri, 30 Oct 2015 01:55:29 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196898@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         spam2 at rhsoft dot net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

nonsense, besides that's not useable in backwards compatible code
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15

[30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice:  Use of undefined constant
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed
'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in
/Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266

__________________________________

      if($this->ssl && $this->host != 'localhost')
      {
       $flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
       $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
      }
      switch($persistent)
      {
       case 1:  $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
       default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
      }


Previous Comments:
------------------------------------------------------------------------
[2015-10-29 12:52:32] andrey@php.net

mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL);


should work now, certificates won't be checked. However, if mysqli_ssl_set is used() then
certificate will be checked. In this case, however, it can be forced not to check by passing another
flag MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT.
$db = mysqli_init();
$db->ssl_set(, , , , , );
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);

------------------------------------------------------------------------
[2015-10-29 12:26:14] clint at ostalks dot com

This bug has been biting me as I use php 5.6 to connect to Google SQL (part of the Google Cloud
services).  This simply doesn't work.  There are a number of people who have this similar issue
as well: http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
and http://stackoverflow.com/questions/28777416/mysqli-real-connect-getting-ssl3-get-server-certificatecertificate-verify-fai

I do not want to downgrade as much as possible to 5.5.

------------------------------------------------------------------------
[2015-10-29 09:59:19] tyrael@php.net

for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16

------------------------------------------------------------------------
[2015-10-26 07:29:19] arekm at maven dot pl

> As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of
> a stable branch. So it is either OFF or ON. For 7.0 I need to push a change for
> the third state.

Actually you change behaviour since currently (without these patches) default 5.6 behaviour is to
verifify ssl certificates (annoying for many but well... it is a change).

> What MySQL 5.7 has to do with this?
Nothing beside me wondering what's "default" for 5.7 libmysqclient and if php should
follow (or not).

------------------------------------------------------------------------
[2015-10-26 07:21:34] andrey@php.net

Hi,


>Tested 5.6.14 with patches:
>afd31489d0d9999f701467e99ef2b40794eed196
>8292260515a904b4d515484145c78f33a06ae1ae

>Now it doesn't verify SSL certificate at all. Connection is being made even if peer
>certificate doesn't match >hostname. What's worse even settting:

>$opts = array('ssl'=>array('verify_peer'=> true,
>'verify_peer_name' => true));
>stream_context_set_default($opts);

yes, defaults never had power over the mysqlnd connnections.

>doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't
>obey default context >stream options BUT...

yes

>What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
>(CLIENT_SSL_VERIFY_SERVER_CERT >in libmysqlclient API) mysql_connect option. It works now though
>but is NOT default on.

yes, because we need 3 states. OFF (no check), ON (check), DEFAULT (the default behavior of the PHP
streams). As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of a
stable branch. So it is either OFF or ON. For 7.0 I need to push a change for the third state.

>So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:

>"6. These include enabling peer verification by default, supporting certificate fingerprint
>matching, >mitigating against TLS renegotiation attacks, and many new SSL context options to
>allow more fine grained >control over protocol and verification settings when using encrypted
>streams."

>is not being applied to mysql SSL/TLS connections?

Because I want to give the developers a change to migrate to 5.6 from 5.5 . In 7.0 the behavior will
be the advertised in this page. The developers then need to change their applications.

>No strong opinion though. mysql 5.7 probably still doesn't default that option to be on
>(would be nice to >verify that).

What MySQL 5.7 has to do with this?

>So summary, php5.6 + these two patches:

>- back to 5.5 state by default

yes

>- $opts = array('ssl'=>array('verify_peer'=> true/false,
>'verify_peer_name' => true/false));
>stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection

>- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as
>MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT) and works >but turning ON verify_peer/verify_peer_name (is
>off by default; as it was in 5.5 state)\

yes, for explicit check one needs to set this flag, for 5.6 . For 7.0 I will push a change that make
verify the default value.

Thanks for the input. This is what I needed to hear :)

Andrey

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196898) next »