Bug #71040 [NEW]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sun, 06 Dec 2015 05:21:10 +0000
Subject: Bug #71040 [NEW]: MySQLi does not provide way to disable peer certificate validation
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197625@lists.php.net to get a copy of this message
From: James dot Sanders at knightsforgod dot com Operating system: N/A PHP version: 7.0.0 Package: MySQLi related Bug Type: Bug Bug description:MySQLi does not provide way to disable peer certificate validation Description: ------------ This is the same problem that has been solved in BUG #68344 for version 5.6.16. Please provide patch to 7.0.0 so we can utilize self-signed certificates. Thank you. Test script: --------------- Public Function Open() { // Set Access to Global Variables: Global $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema; // Initialize Database Object: If (!$this -> MySQLi = MySQLi_Init()) { // Output Error if initialization fails: Die("MySQLi_Init Failed to initialize Database Object."); } Else { // Set SSL Connection Paramaters: MySQLi_SSL_Set($this -> MySQLi , 'client-key.pem', 'client-cert.pem', 'ca.pem', NULL, NULL); MySQLi_Options($this -> MySQLi , MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, False); } // Connect to Database for Editing: MySQLi_Real_Connect($this -> MySQLi , $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema, 3306, NULL, MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT); // Verify Connection & Return Status: If ($this -> MySQLi) { // Set SSL Status in Private Variable: $SQL = "SHOW STATUS LIKE 'Ssl_cipher';"; $Result = $this -> MySQLi -> Query($SQL) Or Die($this -> MySQLi -> Error.__LINE__); If($Result -> num_rows > 0) { While($Row = $Result->Fetch_Assoc()) { If (!IsSet($_SESSION['WebUser']['SSLStatus'])) { $this -> SSLStatus = $Row['Variable_name'].": {".$Row['Value']."}"; } } } Else { $this -> SSLStatus = "None"; } // Return Status: Return True; } Else { // Check Connection Status: If (mysqli_connect_errno()) { print_r(openssl_get_cert_locations()); Die ('Connect error ('.mysqli_connect_errno().'): '.mysqli_connect_error()."\n"); Exit(); } // Return Status: Return False; } } Expected result: ---------------- I expect the connection to return successful using self-signed certificates. Actual result: -------------- Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed in D:\Apache\htdocs\Secure\Sessions.php on line 559 -- Edit bug report at https://bugs.php.net/bug.php?id=71040&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71040&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71040&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71040&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71040&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71040&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71040&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71040&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71040&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71040&r=support Expected behavior: https://bugs.php.net/fix.php?id=71040&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71040&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71040&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71040&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71040&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71040&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71040&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71040&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71040&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71040&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71040&r=mysqlcfg

« previous php.bugs (#197625) next »