Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sat, 14 Nov 2015 00:48:35 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197248@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1 ID: 68344 Comment by: rossmann dot wade at realestatewebmasters dot com Reported by: james at jamesreno dot com Summary: MySQLi does not provide way to disable peer certificate validation Status: No Feedback Type: Bug Package: MySQLi related Operating System: NA PHP Version: 5.6.2 Assigned To: mysql Block user comment: N Private report: N New Comment: https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98#diff-42d60d67366718db1ee0d4e876c859eaR107 1. Why do there need to be separate 'VERIFY' and 'DONT_VERIFY' flags? Wouldn't the absence of the 'VERIFY' flag imply 'DONT_VERIFY'? 2. Given that this is an issue in the mysqlnd driver should there not also be a fix applied for PDO as well? Previous Comments: ------------------------------------------------------------------------ [2015-11-08 04:22:13] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2015-10-30 07:17:24] andrey@php.net From what I see, 5.6.15 was branched from code that did not include the constant. And from the checkout of the tag, there is no changes to 5.6.14 compared to 5.6.15. This is why Tyrael said : [2015-10-29 09:59 UTC] tyrael@php.net for the record there is a recent fix regarding this problem from Andrey: https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98 this will be part of php 5.6.16 ------------------------------------------------------------------------ [2015-10-30 02:30:10] spam2 at rhsoft dot net it makes me terrible angry $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL, 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA'); mysqli_options($this->conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false); mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd, $this->db, $this->port, '', $flags); [30-Oct-2015 03:27:08 Europe/Vienna] PHP Warning: mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]: Peer certificate CN=MySQL-Administrator' did not match expected CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 273 ------------------------------------------------------------------------ [2015-10-30 01:58:30] spam2 at rhsoft dot net why in the world can't this crap just accept stream_context_set_default(array('ssl'=>array('verify_peer'=>false, 'verify_peer_name'=>false, 'allow_self_signed'=>true))); ------------------------------------------------------------------------ [2015-10-30 01:55:27] spam2 at rhsoft dot net nonsense, besides that's not useable in backwards compatible code MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is *NOT* known in PHP 5.6.15 [30-Oct-2015 02:49:36 Europe/Vienna] PHP Notice: Use of undefined constant MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT - assumed 'MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php on line 266 __________________________________ if($this->ssl && $this->host != 'localhost') { $flags = MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT; $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL, 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA'); } switch($persistent) { case 1: $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host, $this->user, $this->pwd, $this->db, $this->port, '', $flags); break; default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd, $this->db, $this->port, '', $flags); break; } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68344 -- Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1

« previous php.bugs (#197248) next »