Bug #71040 [Opn->Csd]: MySQLi does not provide way to disable peer certificate validation

From: Date: Sun, 06 Dec 2015 16:47:12 +0000
Subject: Bug #71040 [Opn->Csd]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197637@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71040&edit=1 ID: 71040 Updated by: ab@php.net Reported by: James dot Sanders at knightsforgod dot com Summary: MySQLi does not provide way to disable peer certificate validation -Status: Open +Status: Closed Type: Bug Package: MySQLi related Operating System: N/A PHP Version: 7.0.0 -Assigned To: +Assigned To: ab Block user comment: N Private report: N New Comment: Thanks for the report. The fix is under way into the next 7.0 version. See also bug #71004; Thanks. Previous Comments: ------------------------------------------------------------------------ [2015-12-06 05:21:05] James dot Sanders at knightsforgod dot com Description: ------------ This is the same problem that has been solved in BUG #68344 for version 5.6.16. Please provide patch to 7.0.0 so we can utilize self-signed certificates. Thank you. Test script: --------------- Public Function Open() { // Set Access to Global Variables: Global $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema; // Initialize Database Object: If (!$this -> MySQLi = MySQLi_Init()) { // Output Error if initialization fails: Die("MySQLi_Init Failed to initialize Database Object."); } Else { // Set SSL Connection Paramaters: MySQLi_SSL_Set($this -> MySQLi , 'client-key.pem', 'client-cert.pem', 'ca.pem', NULL, NULL); MySQLi_Options($this -> MySQLi , MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, False); } // Connect to Database for Editing: MySQLi_Real_Connect($this -> MySQLi , $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema, 3306, NULL, MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT); // Verify Connection & Return Status: If ($this -> MySQLi) { // Set SSL Status in Private Variable: $SQL = "SHOW STATUS LIKE 'Ssl_cipher';"; $Result = $this -> MySQLi -> Query($SQL) Or Die($this -> MySQLi -> Error.__LINE__); If($Result -> num_rows > 0) { While($Row = $Result->Fetch_Assoc()) { If (!IsSet($_SESSION['WebUser']['SSLStatus'])) { $this -> SSLStatus = $Row['Variable_name'].": {".$Row['Value']."}"; } } } Else { $this -> SSLStatus = "None"; } // Return Status: Return True; } Else { // Check Connection Status: If (mysqli_connect_errno()) { print_r(openssl_get_cert_locations()); Die ('Connect error ('.mysqli_connect_errno().'): '.mysqli_connect_error()."\n"); Exit(); } // Return Status: Return False; } } Expected result: ---------------- I expect the connection to return successful using self-signed certificates. Actual result: -------------- Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed in D:\Apache\htdocs\Secure\Sessions.php on line 559 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71040&edit=1

« previous php.bugs (#197637) next »