Bug #71040 [Opn->Csd]: MySQLi does not provide way to disable peer certificate validation
| From: | ab@php.net | Date: | Sun, 06 Dec 2015 16:47:12 +0000 |
| Subject: | Bug #71040 [Opn->Csd]: MySQLi does not provide way to disable peer certificate validation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197637@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71040&edit=1
ID: 71040
Updated by: ab@php.net
Reported by: James dot Sanders at knightsforgod dot com
Summary: MySQLi does not provide way to disable peer
certificate validation
-Status: Open
+Status: Closed
Type: Bug
Package: MySQLi related
Operating System: N/A
PHP Version: 7.0.0
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Thanks for the report. The fix is under way into the next 7.0 version. See also bug #71004;
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-12-06 05:21:05] James dot Sanders at knightsforgod dot com
Description:
------------
This is the same problem that has been solved in BUG #68344 for version 5.6.16.
Please provide patch to 7.0.0 so we can utilize self-signed certificates.
Thank you.
Test script:
---------------
Public Function Open() {
// Set Access to Global Variables:
Global $MySQLServer, $ApacheUserID, $ApachePasswd, $ApacheSchema;
// Initialize Database Object:
If (!$this -> MySQLi = MySQLi_Init()) {
// Output Error if initialization fails:
Die("MySQLi_Init Failed to initialize Database Object.");
} Else {
// Set SSL Connection Paramaters:
MySQLi_SSL_Set($this -> MySQLi , 'client-key.pem', 'client-cert.pem',
'ca.pem', NULL, NULL);
MySQLi_Options($this -> MySQLi , MYSQLI_OPT_SSL_VERIFY_SERVER_CERT, False);
}
// Connect to Database for Editing:
MySQLi_Real_Connect($this -> MySQLi , $MySQLServer, $ApacheUserID, $ApachePasswd,
$ApacheSchema, 3306, NULL, MYSQLI_CLIENT_SSL | MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);
// Verify Connection & Return Status:
If ($this -> MySQLi) {
// Set SSL Status in Private Variable:
$SQL = "SHOW STATUS LIKE 'Ssl_cipher';";
$Result = $this -> MySQLi -> Query($SQL) Or Die($this -> MySQLi -> Error.__LINE__);
If($Result -> num_rows > 0) {
While($Row = $Result->Fetch_Assoc()) {
If (!IsSet($_SESSION['WebUser']['SSLStatus'])) {
$this -> SSLStatus = $Row['Variable_name'].":
{".$Row['Value']."}";
}
}
} Else {
$this -> SSLStatus = "None";
}
// Return Status:
Return True;
} Else {
// Check Connection Status:
If (mysqli_connect_errno()) {
print_r(openssl_get_cert_locations());
Die ('Connect error ('.mysqli_connect_errno().'):
'.mysqli_connect_error()."\n");
Exit();
}
// Return Status:
Return False;
}
}
Expected result:
----------------
I expect the connection to return successful using self-signed certificates.
Actual result:
--------------
Warning: mysqli_real_connect(): SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed in
D:\Apache\htdocs\Secure\Sessions.php on line 559
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71040&edit=1