From: source dot spider at gmail dot com
Operating system: centos 7
PHP version: 7.0.4
Package: PDO MySQL
Bug Type: Bug
Bug description:Impossible to use PDO with ssl connections
Description:
------------
Services such as Google Cloud SQL have SSL certificates signed as
CN=`project:instance-name' (literally). However to connect to them IPs
are required. In some cases you may also need to connect to multiple
servers, but the certificate remains unchanged (the service in question
provide only one set of certificates). As such the verification done by
php (or mysqlnd?) is pointless and simply serves to break the
application establishing a secure connection[1].
The error will manifest as "PDO::__construct(): Peer certificate
CN=project:instance-name' did not match expected CN=123.456.78.9' in
/path/to/script.php"
None of the mechanisms that would disable the verification, such as
stream_context_set_default[2], actually affect the connection in any
way.
There appears to be a MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT (which
was introduced to fix the same mistake on mysqli apparently) however the
functionality wasn't ported to any of the other interfaces even though
it's clearly just as broken everywhere else.
___________
[1] many applications require the connection to be secure to ensure
sensitive information isn't just traveling in plain text over pipes to
and from the database
[2] full example of stream_context_set_default
stream_context_set_default([
'ssl' => [
'verify_peer_name' => false,
'verify_peer' => false
]
]);
Test script:
---------------
<?php
#
# The following parameters will need to be filled in and the
certificate
# must not match the dbhost parameter. Ideally we wouldn't need to
modify
# the default context and could customize via $options instead
#
$dbhost = '';
$dbname = '';
$dbuser = '';
$dbpass = '';
stream_context_set_default([
'ssl' => [
'verify_peer_name' => false,
'verify_peer' => false
]
]);
$options = [
\PDO::MYSQL_ATTR_SSL_KEY => __DIR__.'/client-key.pem',
\PDO::MYSQL_ATTR_SSL_CERT => __DIR__.'/client-cert.pem',
\PDO::MYSQL_ATTR_SSL_CA => __DIR__.'/server-ca.pem'
];
$dsn = 'mysql:host='.$dbhost.';dbname='.$dbname.';charset=utf8';
try {
$pdo = new \PDO($dsn, $dbuser, $dbpass, $options);
echo "SUCCESS!\n\n";
}
catch (\Exception $e) {
echo "FAILED!\n\n";
throw $e;
}
Expected result:
----------------
The script should print "SUCCESS!"
Actual result:
--------------
The script prints "FAILED!" and throws the error saying
"PDO::__construct(): Peer certificate CN=`project:instance-name' did not
match expected CN=`123.456.78.9' in /path/to/script.php"
--
Edit bug report at https://bugs.php.net/bug.php?id=71845&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71845&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71845&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71845&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71845&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71845&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71845&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71845&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71845&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71845&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71845&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71845&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71845&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71845&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71845&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71845&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71845&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71845&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71845&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71845&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71845&r=mysqlcfg