Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Comment by: thomas at orozco dot fr
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Assigned
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Assigned To: andrey
Block user comment: N
Private report: N
New Comment:
Hi there,
The following patch seems to work for me with some limited testing (it just sets
CLIENT_SSL_VERIFY_SERVER_CERT and the heavy lifting is done by the code from https://bugs.php.net/bug.php?id=68344).
Is this worth submitting as a PR https://github.com/php/php-src? Is there anything I can
do to help move this forward?
---
From ff2c31450a7f5ca2c32b49873c5d6e1a0de67674 Mon Sep 17 00:00:00 2001
From: Thomas Orozco <thomas@orozco.fr>
Date: Thu, 9 Jun 2016 10:45:40 +0200
Subject: [PATCH] Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT
---
ext/pdo_mysql/mysql_driver.c | 12 ++++++++++++
ext/pdo_mysql/pdo_mysql.c | 3 +++
ext/pdo_mysql/php_pdo_mysql_int.h | 3 +++
ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt | 1 +
4 files changed, 19 insertions(+)
diff --git a/ext/pdo_mysql/mysql_driver.c b/ext/pdo_mysql/mysql_driver.c
index 1b1d1ab..20ae458 100644
--- a/ext/pdo_mysql/mysql_driver.c
+++ b/ext/pdo_mysql/mysql_driver.c
@@ -731,6 +731,18 @@ static int pdo_mysql_handle_factory(pdo_dbh_t *dbh, zval *driver_options)
}
}
#endif
+
+#ifdef PDO_USE_MYSQLND
+ {
+ zend_long ssl_verify_cert = pdo_attr_lval(driver_options,
+ PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT, -1);
+ if (ssl_verify_cert != -1) {
+ connect_opts |= ssl_verify_cert ?
+ CLIENT_SSL_VERIFY_SERVER_CERT:
+ CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
+ }
+ }
+#endif
}
#ifdef PDO_MYSQL_HAS_CHARSET
diff --git a/ext/pdo_mysql/pdo_mysql.c b/ext/pdo_mysql/pdo_mysql.c
index fdf7062..79efb21 100644
--- a/ext/pdo_mysql/pdo_mysql.c
+++ b/ext/pdo_mysql/pdo_mysql.c
@@ -130,6 +130,9 @@ static PHP_MINIT_FUNCTION(pdo_mysql)
REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SERVER_PUBLIC_KEY",
(zend_long)PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY);
#endif
REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_MULTI_STATEMENTS",
(zend_long)PDO_MYSQL_ATTR_MULTI_STATEMENTS);
+#ifdef PDO_USE_MYSQLND
+ REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SSL_VERIFY_SERVER_CERT",
(zend_long)PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT);
+#endif
#ifdef PDO_USE_MYSQLND
mysqlnd_reverse_api_register_api(&pdo_mysql_reverse_api);
diff --git a/ext/pdo_mysql/php_pdo_mysql_int.h b/ext/pdo_mysql/php_pdo_mysql_int.h
index 20d640c..08eb731 100644
--- a/ext/pdo_mysql/php_pdo_mysql_int.h
+++ b/ext/pdo_mysql/php_pdo_mysql_int.h
@@ -179,6 +179,9 @@ enum {
PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY,
#endif
PDO_MYSQL_ATTR_MULTI_STATEMENTS,
+#ifdef PDO_USE_MYSQLND
+ PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT,
+#endif
};
#endif
diff --git a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
index f3d0fa6..fba1c24 100644
--- a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
+++ b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
@@ -27,6 +27,7 @@ if (!extension_loaded('mysqli') &&
!extension_loaded('mysqlnd')) {
"MYSQL_ATTR_SSL_CIPHER" => true,
"MYSQL_ATTR_COMPRESS" => true,
"MYSQL_ATTR_MULTI_STATEMENTS" => true,
+ "MYSQL_ATTR_SSL_VERIFY_SERVER_CERT" => true,
);
if (!MySQLPDOTest::isPDOMySQLnd()) {
--
2.7.4
Previous Comments:
------------------------------------------------------------------------
[2016-05-22 17:58:22] zhil dot mobile at gmail dot com
I have setuped free SSL sertificate from http://buy.wosign.com/free/
It works on SSH console using mysql command like
mysql -h myhost.com --ssl --ssl-ca=/.../wosign/root_bundle.crt --ssl-verify-server-cert
--ssl-mode=REQUIRED DBNAME -u USERNAME -pPASS
But I failed to make it work using php PDO mysql.
I am considering creating SSH tunel for remote mysql instead of spending more time on this issue.
Do anybody have any ideas how could it be fixed?
------------------------------------------------------------------------
[2016-05-18 17:52:51] nikic@php.net
@andrey: You implemented the mysqli fix for this issue, could you maybe take a look at PDO mysql as
well?
------------------------------------------------------------------------
[2016-05-18 16:55:31] highmind63 at gmail dot com
For all those trying to get this to work, don't. There is no possible way to make this work, in
all of my tests. You MUST have a valid commercial certificate and it MUST match the name of the
host. I've tried the following to no avail:
set PDO::MYSQL_ATTR_SSL_CAPATH option to a properly hashed dir (one that I tested and works with
CURLOPT_CAPATH). No go
set openssl.capath to the same properly hashed dir. No go, completely ignored.
I tried fiddling around a bit with openssl's internal cert store, but I couldn't get that
to work. That should work, but at the expense of changing all the openssl cert store data
system-wide.
This is a big defect in PHP's PDO currently, PDO over SSL is barely useable as-is.
------------------------------------------------------------------------
[2016-05-18 02:05:16] requinix@php.net
See also bug #71845 about the general CN mismatch problem.
------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net
Related To: Bug #71845
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71003
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1