Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Comment by: spam2 at rhsoft dot net
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
Status: Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
nonsense, besides that's not useable in backwards compatible code
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15
[30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice: Use of undefined constant
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed
'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in
/Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266
__________________________________
if($this->ssl && $this->host != 'localhost')
{
$flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
}
switch($persistent)
{
case 1: $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
}
Previous Comments:
------------------------------------------------------------------------
[2015-10-29 12:52:32] andrey@php.net
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL);
should work now, certificates won't be checked. However, if mysqli_ssl_set is used() then
certificate will be checked. In this case, however, it can be forced not to check by passing another
flag MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT.
$db = mysqli_init();
$db->ssl_set(, , , , , );
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);
------------------------------------------------------------------------
[2015-10-29 12:26:14] clint at ostalks dot com
This bug has been biting me as I use php 5.6 to connect to Google SQL (part of the Google Cloud
services). This simply doesn't work. There are a number of people who have this similar issue
as well: http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
and http://stackoverflow.com/questions/28777416/mysqli-real-connect-getting-ssl3-get-server-certificatecertificate-verify-fai
I do not want to downgrade as much as possible to 5.5.
------------------------------------------------------------------------
[2015-10-29 09:59:19] tyrael@php.net
for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16
------------------------------------------------------------------------
[2015-10-26 07:29:19] arekm at maven dot pl
> As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of
> a stable branch. So it is either OFF or ON. For 7.0 I need to push a change for
> the third state.
Actually you change behaviour since currently (without these patches) default 5.6 behaviour is to
verifify ssl certificates (annoying for many but well... it is a change).
> What MySQL 5.7 has to do with this?
Nothing beside me wondering what's "default" for 5.7 libmysqclient and if php should
follow (or not).
------------------------------------------------------------------------
[2015-10-26 07:21:34] andrey@php.net
Hi,
>Tested 5.6.14 with patches:
>afd31489d0d9999f701467e99ef2b40794eed196
>8292260515a904b4d515484145c78f33a06ae1ae
>Now it doesn't verify SSL certificate at all. Connection is being made even if peer
>certificate doesn't match >hostname. What's worse even settting:
>$opts = array('ssl'=>array('verify_peer'=> true,
>'verify_peer_name' => true));
>stream_context_set_default($opts);
yes, defaults never had power over the mysqlnd connnections.
>doesn't turn ssl verification. So looks to be back to 5.5 state by default, doesn't
>obey default context >stream options BUT...
yes
>What these patches seem to implement is MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT
>(CLIENT_SSL_VERIFY_SERVER_CERT >in libmysqlclient API) mysql_connect option. It works now though
>but is NOT default on.
yes, because we need 3 states. OFF (no check), ON (check), DEFAULT (the default behavior of the PHP
streams). As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of a
stable branch. So it is either OFF or ON. For 7.0 I need to push a change for the third state.
>So the question is - why major feature announced at http://php.net/manual/en/migration56.new-features.php:
>"6. These include enabling peer verification by default, supporting certificate fingerprint
>matching, >mitigating against TLS renegotiation attacks, and many new SSL context options to
>allow more fine grained >control over protocol and verification settings when using encrypted
>streams."
>is not being applied to mysql SSL/TLS connections?
Because I want to give the developers a change to migrate to 5.6 from 5.5 . In 7.0 the behavior will
be the advertised in this page. The developers then need to change their applications.
>No strong opinion though. mysql 5.7 probably still doesn't default that option to be on
>(would be nice to >verify that).
What MySQL 5.7 has to do with this?
>So summary, php5.6 + these two patches:
>- back to 5.5 state by default
yes
>- $opts = array('ssl'=>array('verify_peer'=> true/false,
>'verify_peer_name' => true/false));
>stream_context_set_default($opts); will not work - not obeyed by mysql ssl connection
>- CLIENT_SSL_VERIFY_SERVER_CERT support got implemented (as
>MYSQLI_CLIENT_SSL_VERIFY_SERVER_CERT) and works >but turning ON verify_peer/verify_peer_name (is
>off by default; as it was in 5.5 state)\
yes, for explicit check one needs to set this flag, for 5.6 . For 7.0 I will push a change that make
verify the default value.
Thanks for the input. This is what I needed to hear :)
Andrey
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1