Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Fri, 30 Oct 2015 01:58:33 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196899@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         spam2 at rhsoft dot net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

why in the world can't this crap just accept
stream_context_set_default(array('ssl'=>array('verify_peer'=>false,
'verify_peer_name'=>false, 'allow_self_signed'=>true)));


Previous Comments:
------------------------------------------------------------------------
[2015-10-30 01:55:27] spam2 at rhsoft dot net

nonsense, besides that's not useable in backwards compatible code
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15

[30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice:  Use of undefined constant
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed
'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in
/Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266

__________________________________

      if($this->ssl && $this->host != 'localhost')
      {
       $flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
       $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
      }
      switch($persistent)
      {
       case 1:  $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
       default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
      }

------------------------------------------------------------------------
[2015-10-29 12:52:32] andrey@php.net

mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL);


should work now, certificates won't be checked. However, if mysqli_ssl_set is used() then
certificate will be checked. In this case, however, it can be forced not to check by passing another
flag MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT.
$db = mysqli_init();
$db->ssl_set(, , , , , );
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);

------------------------------------------------------------------------
[2015-10-29 12:26:14] clint at ostalks dot com

This bug has been biting me as I use php 5.6 to connect to Google SQL (part of the Google Cloud
services).  This simply doesn't work.  There are a number of people who have this similar issue
as well: http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
and http://stackoverflow.com/questions/28777416/mysqli-real-connect-getting-ssl3-get-server-certificatecertificate-verify-fai

I do not want to downgrade as much as possible to 5.5.

------------------------------------------------------------------------
[2015-10-29 09:59:19] tyrael@php.net

for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16

------------------------------------------------------------------------
[2015-10-26 07:29:19] arekm at maven dot pl

> As I am pushing to 5.6.14 I don't want to change behavior in the 14th release of
> a stable branch. So it is either OFF or ON. For 7.0 I need to push a change for
> the third state.

Actually you change behaviour since currently (without these patches) default 5.6 behaviour is to
verifify ssl certificates (annoying for many but well... it is a change).

> What MySQL 5.7 has to do with this?
Nothing beside me wondering what's "default" for 5.7 libmysqclient and if php should
follow (or not).

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196899) next »