Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation

From: Date: Fri, 30 Oct 2015 07:17:29 +0000
Subject: Bug #68344 [Fbk]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196908@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Updated by:         andrey@php.net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

From what I see, 5.6.15 was branched from code that did not include the constant. And from the
checkout of the tag, there is no changes to 5.6.14 compared to 5.6.15.

This is why Tyrael said :
[2015-10-29 09:59 UTC] tyrael@php.net

for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16


Previous Comments:
------------------------------------------------------------------------
[2015-10-30 02:30:10] spam2 at rhsoft dot net

it makes me terrible angry

$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
mysqli_options($this->conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false);
mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd, $this->db,
$this->port, '', $flags);

[30-Oct-2015 03:27:08 Europe/Vienna] PHP Warning:  mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273

------------------------------------------------------------------------
[2015-10-30 01:58:30] spam2 at rhsoft dot net

why in the world can't this crap just accept
stream_context_set_default(array('ssl'=>array('verify_peer'=>false,
'verify_peer_name'=>false, 'allow_self_signed'=>true)));

------------------------------------------------------------------------
[2015-10-30 01:55:27] spam2 at rhsoft dot net

nonsense, besides that's not useable in backwards compatible code
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15

[30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice:  Use of undefined constant
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed
'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in
/Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266

__________________________________

      if($this->ssl && $this->host != 'localhost')
      {
       $flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
       $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
      }
      switch($persistent)
      {
       case 1:  $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
       default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
      }

------------------------------------------------------------------------
[2015-10-29 12:52:32] andrey@php.net

mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL);


should work now, certificates won't be checked. However, if mysqli_ssl_set is used() then
certificate will be checked. In this case, however, it can be forced not to check by passing another
flag MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT.
$db = mysqli_init();
$db->ssl_set(, , , , , );
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);

------------------------------------------------------------------------
[2015-10-29 12:26:14] clint at ostalks dot com

This bug has been biting me as I use php 5.6 to connect to Google SQL (part of the Google Cloud
services).  This simply doesn't work.  There are a number of people who have this similar issue
as well: http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation
and http://stackoverflow.com/questions/28777416/mysqli-real-connect-getting-ssl3-get-server-certificatecertificate-verify-fai

I do not want to downgrade as much as possible to 5.5.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#196908) next »