Bug #71040 [NEW]: MySQLi does not provide way to disable peer certificate validation
| From: | James dot Sanders at knightsforgod dot com | Date: | Sun, 06 Dec 2015 05:21:10 +0000 |
| Subject: | Bug #71040 [NEW]: MySQLi does not provide way to disable peer certificate validation | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-197625@lists.php.net to get a copy of this message | ||
From: James dot Sanders at knightsforgod dot com
Operating system: N/A
PHP version: 7.0.0
Package: MySQLi related
Bug Type: Bug
Bug description:MySQLi does not provide way to disable peer certificate validation
Description:
------------
This is the same problem that has been solved in BUG #68344 for version
5.6.16.
Please provide patch to 7.0.0 so we can utilize self-signed
certificates.
Thank you.
Test script:
---------------
Public Function Open() {
// Set Access to Global Variables:
Global $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema;
// Initialize Database Object:
If (!$this -> MySQLi = MySQLi_Init()) {
// Output Error if initialization fails:
Die("MySQLi_Init Failed to initialize Database Object.");
} Else {
// Set SSL Connection Paramaters:
MySQLi_SSL_Set($this -> MySQLi , 'client-key.pem', 'client-cert.pem',
'ca.pem', NULL, NULL);
MySQLi_Options($this -> MySQLi , MYSQLI_OPT_SSL_VERIFY_SERVER_CERT,
False);
}
// Connect to Database for Editing:
MySQLi_Real_Connect($this -> MySQLi , $MySQLServer, $ApacheUserID,
$ApachePasswd, $ApacheSchema, 3306, NULL, MYSQLI_CLIENT_SSL |
MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);
// Verify Connection & Return Status:
If ($this -> MySQLi) {
// Set SSL Status in Private Variable:
$SQL = "SHOW STATUS LIKE 'Ssl_cipher';";
$Result = $this -> MySQLi -> Query($SQL) Or Die($this -> MySQLi ->
Error.__LINE__);
If($Result -> num_rows > 0) {
While($Row = $Result->Fetch_Assoc()) {
If (!IsSet($_SESSION['WebUser']['SSLStatus'])) {
$this -> SSLStatus = $Row['Variable_name'].":
{".$Row['Value']."}";
}
}
} Else {
$this -> SSLStatus = "None";
}
// Return Status:
Return True;
} Else {
// Check Connection Status:
If (mysqli_connect_errno()) {
print_r(openssl_get_cert_locations());
Die ('Connect error ('.mysqli_connect_errno().'):
'.mysqli_connect_error()."\n");
Exit();
}
// Return Status:
Return False;
}
}
Expected result:
----------------
I expect the connection to return successful using self-signed
certificates.
Actual result:
--------------
Warning: mysqli_real_connect(): SSL operation failed with code 1.
OpenSSL Error messages: error:14090086:SSL
routines:ssl3_get_server_certificate:certificate verify failed in
D:\Apache\htdocs\Secure\Sessions.php on line 559
--
Edit bug report at https://bugs.php.net/bug.php?id=71040&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71040&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71040&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71040&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71040&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71040&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71040&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71040&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71040&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71040&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71040&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71040&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71040&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71040&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71040&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71040&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71040&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71040&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71040&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71040&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71040&r=mysqlcfg