Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
| From: | nj dot johansson at gmail dot com | Date: | Mon, 04 Apr 2016 09:23:19 +0000 |
| Subject: | Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200341@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Comment by: nj dot johansson at gmail dot com
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Open
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Block user comment: N
Private report: N
New Comment:
A nice solution would be to be able to explicitly pass a peer name that should be expected using http://php.net/manual/en/context.ssl.php#context.ssl.verify-peer-name
My use case is that we have a CNAME record pointing at an AWS RDS instance (*.rds.amazonaws.com) to
be able to easily switch the underlying instance. However, lacking other information PHP will since
5.6 try to guess the peer name using the hostname provided and peer name verification will as such
fail.
I also understand that for some use cases (see http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation)
it is out of the developer's control what the Common Name (CN) for the remote database will be
assigned to, however, given the same option as suggested above it would still be possible to
connect.
Previous Comments:
------------------------------------------------------------------------
[2016-03-14 10:25:02] php at yblew dot com
Any update on this?
------------------------------------------------------------------------
[2015-11-30 23:43:28] tmatsuo at google dot com
Description:
------------
According to the bug #68344, with PHP 5.6.16, you can ignore the peer name verification upon
establishing the connection. This is great, however according to https://secure.php.net/manual/en/ref.pdo-mysql.php,
this option is not exposed to PDO interface.
Please provide a way to specify MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT when using the PDO
interface.
Expected result:
----------------
You can somehow instruct PDO that it ignores the peer name of the certificate upon establish an SSL
connection.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1