Req #72235 [NEW]: PDO and certificate CN

From: Date: Wed, 18 May 2016 01:42:26 +0000
Subject: Req #72235 [NEW]: PDO and certificate CN
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201167@lists.php.net to get a copy of this message
From:             ghfjdksl at gmail dot com
Operating system: rhel 6.7
PHP version:      5.6.21
Package:          PDO MySQL
Bug Type:         Feature/Change Request
Bug description:PDO and certificate CN

Description:
------------
In php 5.6, certificate CN is verified by default. But this is
infeasible in some situation. There should be at least one attribute
that can toggle the CN verification on and off, or at least let the user
specify what the expected CN is, instead of using the connection url.
There is a flag that one can set for mysqli, but there is no such option
for PDO now.


Test script:
---------------
<?php
$attr[PDO::MYSQL_ATTR_SSL_CA] = "rootCA.pem";
//$attr[PDO::MYSQL_ATTR_SSL_SERVER_CN] = "the.real.server.cn";
try
{
    $conn = new PDO("mysql:host=server.ip.here;port=3306;","test_user",
"my_password", $attr);
}
catch (Exception $e)
{
    print "not ok\n";
    throw $e;
}
print "ok of no exception\n"
?>

Expected result:
----------------
The test script requires mysql to be correctly setup to use ssl
connection. I'm only posting the client code here. And I'm hiding my
real test ip. 
Server certificate have CN "the.real.server.cn", and connection ip is
some real ip address. Since these two are different, the connection
should fail.
After the attached patch, one can uncomment the
PDO::MYSQL_ATTR_SSL_SERVER_CN line, and the connection should succeed.


-- 
Edit bug report at https://bugs.php.net/bug.php?id=72235&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=72235&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=72235&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=72235&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=72235&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=72235&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=72235&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=72235&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=72235&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=72235&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=72235&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=72235&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=72235&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=72235&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72235&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=72235&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=72235&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=72235&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72235&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=72235&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=72235&r=mysqlcfg



Thread (2 messages)

« previous php.bugs (#201167) next »