Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation
| From: | php-bugs at lists dot php dot net | Date: | Sun, 08 Nov 2015 04:22:14 +0000 |
| Subject: | Bug #68344 [Fbk->NoF]: MySQLi does not provide way to disable peer certificate validation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197110@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1
ID: 68344
Updated by: php-bugs@lists.php.net
Reported by: james at jamesreno dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: MySQLi related
Operating System: NA
PHP Version: 5.6.2
Assigned To: mysql
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2015-10-30 07:17:24] andrey@php.net
From what I see, 5.6.15 was branched from code that did not include the constant. And from the
checkout of the tag, there is no changes to 5.6.14 compared to 5.6.15.
This is why Tyrael said :
[2015-10-29 09:59 UTC] tyrael@php.net
for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16
------------------------------------------------------------------------
[2015-10-30 02:30:10] spam2 at rhsoft dot net
it makes me terrible angry
$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
mysqli_options($this->conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false);
mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd, $this->db,
$this->port, '', $flags);
[30-Oct-2015 03:27:08 Europe/Vienna] PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=
MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273
------------------------------------------------------------------------
[2015-10-30 01:58:30] spam2 at rhsoft dot net
why in the world can't this crap just accept
stream_context_set_default(array('ssl'=>array('verify_peer'=>false,
'verify_peer_name'=>false, 'allow_self_signed'=>true)));
------------------------------------------------------------------------
[2015-10-30 01:55:27] spam2 at rhsoft dot net
nonsense, besides that's not useable in backwards compatible code
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15
[30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice: Use of undefined constant
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed
'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in
/Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266
__________________________________
if($this->ssl && $this->host != 'localhost')
{
$flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
}
switch($persistent)
{
case 1: $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
}
------------------------------------------------------------------------
[2015-10-29 12:52:32] andrey@php.net
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL);
should work now, certificates won't be checked. However, if mysqli_ssl_set is used() then
certificate will be checked. In this case, however, it can be forced not to check by passing another
flag MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT.
$db = mysqli_init();
$db->ssl_set(, , , , , );
mysqli_real_connect($db, $host, $username, $password, $database, $port, $socket, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68344
--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1