Bug #68344 [NoF->Csd]: MySQLi does not provide way to disable peer certificate validation

From: Date: Mon, 16 Nov 2015 11:48:20 +0000
Subject: Bug #68344 [NoF->Csd]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197284@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Updated by:         andrey@php.net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
-Status:             No Feedback
+Status:             Closed
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of andrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=822400ef3b807f0a73b4c0879cdf4a802bf7e4fe
Log: News for fixed bug #68344


Previous Comments:
------------------------------------------------------------------------
[2015-11-16 11:29:03] spam2 at rhsoft dot net

http://downloads.php.net/~tyrael/php-5.6.16RC1.tar.xz

congratulations, after *16* minor updates now we can consider deploy PHP 5.6, the changelog
don't contain any hint!

       /** SSL aktivieren */
       if(defined('MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT'))
       {
        $flags = MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
       }
       $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
      }
      /** Verbindung herstellen */
      switch($persistent)
      {
       case 1:  $rw = @mysqli_real_connect($this->conn, 'p:' . $this->host,
$this->user, $this->pwd, $this->db, $this->port, '', $flags); break;
       default: $rw = @mysqli_real_connect($this->conn, $this->host, $this->user,
$this->pwd, $this->db, $this->port, '', $flags); break;
      }

------------------------------------------------------------------------
[2015-11-14 00:48:30] rossmann dot wade at realestatewebmasters dot com

https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98#diff-42d60d67366718db1ee0d4e876c859eaR107

1. Why do there need to be separate 'VERIFY' and 'DONT_VERIFY' flags?
Wouldn't the absence of the 'VERIFY' flag imply 'DONT_VERIFY'?

2. Given that this is an issue in the mysqlnd driver should there not also be a fix applied for PDO
as well?

------------------------------------------------------------------------
[2015-11-08 04:22:13] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2015-10-30 07:17:24] andrey@php.net

From what I see, 5.6.15 was branched from code that did not include the constant. And from the
checkout of the tag, there is no changes to 5.6.14 compared to 5.6.15.

This is why Tyrael said :
[2015-10-29 09:59 UTC] tyrael@php.net

for the record there is a recent fix regarding this problem from Andrey:
https://github.com/php/php-src/commit/6d51b7b2e3468601acdaaf9041c9131b5aa47f98
this will be part of php 5.6.16

------------------------------------------------------------------------
[2015-10-30 02:30:10] spam2 at rhsoft dot net

it makes me terrible angry

$this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL,
'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:RSA-AES256-SHA');
mysqli_options($this->conn, MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, false);
mysqli_real_connect($this->conn, $this->host, $this->user, $this->pwd, $this->db,
$this->port, '', $flags);

[30-Oct-2015 03:27:08 Europe/Vienna] PHP Warning:  mysqli_real_connect() [<a href='http://at.php.net/manual/de/function.mysqli-real-connect.php'>function.mysqli-real-connect.php</a>]:
Peer certificate CN=MySQL-Administrator' did not match expected
CN=192.168.196.12' in /Volumes/dune/www-servers/phpincludes/global_mysql_class.inc.php
on line 273

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#197284) next »