Req #71003 [Opn]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
| From: | requinix@php.net | Date: | Wed, 18 May 2016 02:05:20 +0000 |
| Subject: | Req #71003 [Opn]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201170@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Updated by: requinix@php.net
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Open
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Block user comment: N
Private report: N
New Comment:
See also bug #71845 about the general CN mismatch problem.
Previous Comments:
------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net
Related To: Bug #71845
------------------------------------------------------------------------
[2016-05-18 02:02:50] requinix@php.net
Related To: Bug #72235
------------------------------------------------------------------------
[2016-05-15 20:28:57] zhil dot mobile at gmail dot com
Any news regarding this bug?
------------------------------------------------------------------------
[2016-04-13 15:13:21] phpbugs at bazoink dot com
I'm still working on getting PDO to support CLIENT_SSL_DONT_VERIFY_SERVER_CERT, in the
meantime, if you want to change the default for PDO (and it's set to use mysqlnd, which it
probably is, change this line and recompile:
php-5.6.20/ext/mysqlnd/mysqlnd_structs.h line 215
change
#define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_VERIFY
to
#define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_DONT_VERIFY
That will give you the pre-5.6 behavior of not verifying the CN.
I hope to have a working patch to add the option to PDO this weekend. I'm close, but not
complete.
Mark
------------------------------------------------------------------------
[2016-04-04 09:23:14] nj dot johansson at gmail dot com
A nice solution would be to be able to explicitly pass a peer name that should be expected using http://php.net/manual/en/context.ssl.php#context.ssl.verify-peer-name
My use case is that we have a CNAME record pointing at an AWS RDS instance (*.rds.amazonaws.com) to
be able to easily switch the underlying instance. However, lacking other information PHP will since
5.6 try to guess the peer name using the hostname provided and peer name verification will as such
fail.
I also understand that for some use cases (see http://stackoverflow.com/questions/29260464/google-cloud-sql-ssl-fails-peer-certificate-validation)
it is out of the developer's control what the Common Name (CN) for the remote database will be
assigned to, however, given the same option as suggested above it would still be possible to
connect.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71003
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1