Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface

From: Date: Wed, 13 Apr 2016 15:13:28 +0000
Subject: Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200527@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1 ID: 71003 Comment by: phpbugs at bazoink dot com Reported by: tmatsuo at google dot com Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface Status: Open Type: Feature/Change Request Package: PDO MySQL PHP Version: 5.6.16 Block user comment: N Private report: N New Comment: I'm still working on getting PDO to support CLIENT_SSL_DONT_VERIFY_SERVER_CERT, in the meantime, if you want to change the default for PDO (and it's set to use mysqlnd, which it probably is, change this line and recompile: php-5.6.20/ext/mysqlnd/mysqlnd_structs.h line 215 change #define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_VERIFY to #define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_DONT_VERIFY That will give you the pre-5.6 behavior of not verifying the CN. I hope to have a working patch to add the option to PDO this weekend. I'm close, but not complete. Mark Previous Comments: ------------------------------------------------------------------------ [2016-04-04 09:23:14] nj dot johansson at gmail dot com A nice solution would be to be able to explicitly pass a peer name that should be expected using http://php.net/manual/en/context.ssl.php#context.ssl.verify-peer-name My use case is that we have a CNAME record pointing at an AWS RDS instance (*.rds.amazonaws.com) to be able to easily switch the underlying instance. However, lacking other information PHP will since 5.6 try to guess the peer name using the hostname provided and peer name verification will as such fail. I also understand that for some use cases (see http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation) it is out of the developer's control what the Common Name (CN) for the remote database will be assigned to, however, given the same option as suggested above it would still be possible to connect. ------------------------------------------------------------------------ [2016-03-14 10:25:02] php at yblew dot com Any update on this? ------------------------------------------------------------------------ [2015-11-30 23:43:28] tmatsuo at google dot com Description: ------------ According to the bug #68344, with PHP 5.6.16, you can ignore the peer name verification upon establishing the connection. This is great, however according to https://secure.php.net/manual/en/ref.pdo-mysql.php, this option is not exposed to PDO interface. Please provide a way to specify MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT when using the PDO interface. Expected result: ---------------- You can somehow instruct PDO that it ignores the peer name of the certificate upon establish an SSL connection. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1

« previous php.bugs (#200527) next »