Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface

From: Date: Wed, 18 May 2016 16:55:35 +0000
Subject: Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201183@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1

 ID:                 71003
 Comment by:         highmind63 at gmail dot com
 Reported by:        tmatsuo at google dot com
 Summary:            Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
                     PDO interface
 Status:             Open
 Type:               Feature/Change Request
 Package:            PDO MySQL
 PHP Version:        5.6.16
 Block user comment: N
 Private report:     N

 New Comment:

For all those trying to get this to work, don't. There is no possible way to make this work, in
all of my tests. You MUST have a valid commercial certificate and it MUST match the name of the
host. I've tried the following to no avail:

set PDO::MYSQL_ATTR_SSL_CAPATH option to a properly hashed dir (one that I tested and works with
CURLOPT_CAPATH). No go

set openssl.capath to the same properly hashed dir. No go, completely ignored.

I tried fiddling around a bit with openssl's internal cert store, but I couldn't get that
to work. That should work, but at the expense of changing all the openssl cert store data
system-wide.

This is a big defect in PHP's PDO currently, PDO over SSL is barely useable as-is.


Previous Comments:
------------------------------------------------------------------------
[2016-05-18 02:05:16] requinix@php.net

See also bug #71845 about the general CN mismatch problem.

------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net

Related To: Bug #71845

------------------------------------------------------------------------
[2016-05-18 02:02:50] requinix@php.net

Related To: Bug #72235

------------------------------------------------------------------------
[2016-05-15 20:28:57] zhil dot mobile at gmail dot com

Any news regarding this bug?

------------------------------------------------------------------------
[2016-04-13 15:13:21] phpbugs at bazoink dot com

I'm still working on getting PDO to support CLIENT_SSL_DONT_VERIFY_SERVER_CERT, in the
meantime, if you want to change the default for PDO (and it's set to use mysqlnd, which it
probably is, change this line and recompile:

php-5.6.20/ext/mysqlnd/mysqlnd_structs.h line 215 
change 
#define MYSQLND_SSL_PEER_DEFAULT_ACTION  MYSQLND_SSL_PEER_VERIFY
to
#define MYSQLND_SSL_PEER_DEFAULT_ACTION MYSQLND_SSL_PEER_DONT_VERIFY

That will give you the pre-5.6 behavior of not verifying the CN.

I hope to have a working patch to add the option to PDO this weekend. I'm close, but not
complete.

Mark

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71003


--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1


Thread (18 messages)

« previous php.bugs (#201183) next »