Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Comment by: highmind63 at gmail dot com
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Open
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Block user comment: N
Private report: N
New Comment:
For all those trying to get this to work, don't. There is no possible way to make this work, in
all of my tests. You MUST have a valid commercial certificate and it MUST match the name of the
host. I've tried the following to no avail:
set PDO::MYSQL_ATTR_SSL_CAPATH option to a properly hashed dir (one that I tested and works with
CURLOPT_CAPATH). No go
set openssl.capath to the same properly hashed dir. No go, completely ignored.
I tried fiddling around a bit with openssl's internal cert store, but I couldn't get that
to work. That should work, but at the expense of changing all the openssl cert store data
system-wide.
This is a big defect in PHP's PDO currently, PDO over SSL is barely useable as-is.
Previous Comments:
------------------------------------------------------------------------
[2016-05-18 02:05:16] requinix@php.net
See also bug #71845 about the general CN mismatch problem.
------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net
Related To: Bug #71845
------------------------------------------------------------------------
[2016-05-18 02:02:50] requinix@php.net
Related To: Bug #72235
------------------------------------------------------------------------
[2016-05-15 20:28:57] zhil dot mobile at gmail dot com
Any news regarding this bug?
------------------------------------------------------------------------
[2016-04-13 15:13:21] phpbugs at bazoink dot com
I'm still working on getting PDO to support CLIENT_SSL_DONT_VERIFY_SERVER_CERT, in the
meantime, if you want to change the default for PDO (and it's set to use mysqlnd, which it
probably is, change this line and recompile:
php-5.6.20/ext/mysqlnd/mysqlnd_structs.h line 215
change
#define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_VERIFY
to
#define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_DONT_VERIFY
That will give you the pre-5.6 behavior of not verifying the CN.
I hope to have a working patch to add the option to PDO this weekend. I'm close, but not
complete.
Mark
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71003
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1