Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface

From: Date: Thu, 09 Jun 2016 10:38:21 +0000
Subject: Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201508@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1

 ID:                 71003
 Comment by:         thomas at orozco dot fr
 Reported by:        tmatsuo at google dot com
 Summary:            Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
                     PDO interface
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            PDO MySQL
 PHP Version:        5.6.16
 Assigned To:        andrey
 Block user comment: N
 Private report:     N

 New Comment:

Hi there,

The following patch seems to work for me with some limited testing (it just sets
CLIENT_SSL_VERIFY_SERVER_CERT and the heavy lifting is done by the code from https://bugs.php.net/bug.php?id=68344).

Is this worth submitting as a PR https://github.com/php/php-src? Is there anything I can
do to help move this forward?

---

From ff2c31450a7f5ca2c32b49873c5d6e1a0de67674 Mon Sep 17 00:00:00 2001
From: Thomas Orozco <thomas@orozco.fr>
Date: Thu, 9 Jun 2016 10:45:40 +0200
Subject: [PATCH] Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT

---
 ext/pdo_mysql/mysql_driver.c                       | 12 ++++++++++++
 ext/pdo_mysql/pdo_mysql.c                          |  3 +++
 ext/pdo_mysql/php_pdo_mysql_int.h                  |  3 +++
 ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt |  1 +
 4 files changed, 19 insertions(+)

diff --git a/ext/pdo_mysql/mysql_driver.c b/ext/pdo_mysql/mysql_driver.c
index 1b1d1ab..20ae458 100644
--- a/ext/pdo_mysql/mysql_driver.c
+++ b/ext/pdo_mysql/mysql_driver.c
@@ -731,6 +731,18 @@ static int pdo_mysql_handle_factory(pdo_dbh_t *dbh, zval *driver_options)
 			}
 		}
 #endif
+
+#ifdef PDO_USE_MYSQLND
+		{
+			zend_long ssl_verify_cert = pdo_attr_lval(driver_options,
+					PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT, -1);
+			if (ssl_verify_cert != -1) {
+				connect_opts |= ssl_verify_cert ?
+					CLIENT_SSL_VERIFY_SERVER_CERT:
+					CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
+			}
+		}
+#endif
 	}
 
 #ifdef PDO_MYSQL_HAS_CHARSET
diff --git a/ext/pdo_mysql/pdo_mysql.c b/ext/pdo_mysql/pdo_mysql.c
index fdf7062..79efb21 100644
--- a/ext/pdo_mysql/pdo_mysql.c
+++ b/ext/pdo_mysql/pdo_mysql.c
@@ -130,6 +130,9 @@ static PHP_MINIT_FUNCTION(pdo_mysql)
 	 REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SERVER_PUBLIC_KEY",
(zend_long)PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY);
 #endif
 	REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_MULTI_STATEMENTS",
(zend_long)PDO_MYSQL_ATTR_MULTI_STATEMENTS);
+#ifdef PDO_USE_MYSQLND
+	 REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SSL_VERIFY_SERVER_CERT",
(zend_long)PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT);
+#endif
 
 #ifdef PDO_USE_MYSQLND
 	mysqlnd_reverse_api_register_api(&pdo_mysql_reverse_api);
diff --git a/ext/pdo_mysql/php_pdo_mysql_int.h b/ext/pdo_mysql/php_pdo_mysql_int.h
index 20d640c..08eb731 100644
--- a/ext/pdo_mysql/php_pdo_mysql_int.h
+++ b/ext/pdo_mysql/php_pdo_mysql_int.h
@@ -179,6 +179,9 @@ enum {
 	PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY,
 #endif
 	PDO_MYSQL_ATTR_MULTI_STATEMENTS,
+#ifdef PDO_USE_MYSQLND
+	PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT,
+#endif
 };
 
 #endif
diff --git a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
index f3d0fa6..fba1c24 100644
--- a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
+++ b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
@@ -27,6 +27,7 @@ if (!extension_loaded('mysqli') &&
!extension_loaded('mysqlnd')) {
 		"MYSQL_ATTR_SSL_CIPHER"						=> true,
 		"MYSQL_ATTR_COMPRESS"						=> true,
 		"MYSQL_ATTR_MULTI_STATEMENTS"					=> true,
+		"MYSQL_ATTR_SSL_VERIFY_SERVER_CERT"				=> true,
 	);
 
 	if (!MySQLPDOTest::isPDOMySQLnd()) {
-- 
2.7.4


Previous Comments:
------------------------------------------------------------------------
[2016-05-22 17:58:22] zhil dot mobile at gmail dot com

I have setuped free SSL sertificate from http://buy.wosign.com/free/
It works on SSH console using mysql command like

mysql -h myhost.com --ssl --ssl-ca=/.../wosign/root_bundle.crt --ssl-verify-server-cert
--ssl-mode=REQUIRED DBNAME -u USERNAME -pPASS

But I failed to make it work using php PDO mysql.
I am considering creating SSH tunel for remote mysql instead of spending more time on this issue.

Do anybody have any ideas how could it be fixed?

------------------------------------------------------------------------
[2016-05-18 17:52:51] nikic@php.net

@andrey: You implemented the mysqli fix for this issue, could you maybe take a look at PDO mysql as
well?

------------------------------------------------------------------------
[2016-05-18 16:55:31] highmind63 at gmail dot com

For all those trying to get this to work, don't. There is no possible way to make this work, in
all of my tests. You MUST have a valid commercial certificate and it MUST match the name of the
host. I've tried the following to no avail:

set PDO::MYSQL_ATTR_SSL_CAPATH option to a properly hashed dir (one that I tested and works with
CURLOPT_CAPATH). No go

set openssl.capath to the same properly hashed dir. No go, completely ignored.

I tried fiddling around a bit with openssl's internal cert store, but I couldn't get that
to work. That should work, but at the expense of changing all the openssl cert store data
system-wide.

This is a big defect in PHP's PDO currently, PDO over SSL is barely useable as-is.

------------------------------------------------------------------------
[2016-05-18 02:05:16] requinix@php.net

See also bug #71845 about the general CN mismatch problem.

------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net

Related To: Bug #71845

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71003


--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1


Thread (18 messages)

« previous php.bugs (#201508) next »