Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface

From: Date: Sat, 03 Dec 2016 01:57:56 +0000
Subject: Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205745@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1

 ID:                 71003
 Comment by:         jeremy at boldapps dot net
 Reported by:        tmatsuo at google dot com
 Summary:            Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
                     PDO interface
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            PDO MySQL
 PHP Version:        5.6.16
 Assigned To:        andrey
 Block user comment: N
 Private report:     N

 New Comment:

I added a PR for this bug a few months ago. https://github.com/php/php-src/pull/1972
Anything else I need to do to get it considered?


Previous Comments:
------------------------------------------------------------------------
[2016-06-21 15:17:28] mrpatricktully at gmail dot com

We just ran into this same issue.  Seeing as re-compiling php with this patch is not really an
option for us (config management setup), we did try the following work around and can confirm it
works.  Assuming the CN is something like a hostname (i.e. project name or something other an an IP
address).  You can hardcode the name in the local hosts file of the client servers.  i.e. if the
CN=server and the mysql server is 192.168.2.1 putting this in your hosts file, then setting the host
to "server" in php works

192.168.2.1  server

This only works of course if you have a one to one match (i.e. won't work if you have more than
one server using the same cert).  Not really an ideal solution but it does work if you are in a
bind.  Hopefully the patch will be rolled into a release?

------------------------------------------------------------------------
[2016-06-09 11:13:32] thomas at orozco dot fr

(I should mention that the above patch is for the master branch of php-src, but adjusting the
zend_longs to be longs instead makes it work just fine on PHP 5.6.22)

------------------------------------------------------------------------
[2016-06-09 10:38:12] thomas at orozco dot fr

Hi there,

The following patch seems to work for me with some limited testing (it just sets
CLIENT_SSL_VERIFY_SERVER_CERT and the heavy lifting is done by the code from https://bugs.php.net/bug.php?id=68344).

Is this worth submitting as a PR https://github.com/php/php-src? Is there anything I can
do to help move this forward?

---

From ff2c31450a7f5ca2c32b49873c5d6e1a0de67674 Mon Sep 17 00:00:00 2001
From: Thomas Orozco <thomas@orozco.fr>
Date: Thu, 9 Jun 2016 10:45:40 +0200
Subject: [PATCH] Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT

---
 ext/pdo_mysql/mysql_driver.c                       | 12 ++++++++++++
 ext/pdo_mysql/pdo_mysql.c                          |  3 +++
 ext/pdo_mysql/php_pdo_mysql_int.h                  |  3 +++
 ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt |  1 +
 4 files changed, 19 insertions(+)

diff --git a/ext/pdo_mysql/mysql_driver.c b/ext/pdo_mysql/mysql_driver.c
index 1b1d1ab..20ae458 100644
--- a/ext/pdo_mysql/mysql_driver.c
+++ b/ext/pdo_mysql/mysql_driver.c
@@ -731,6 +731,18 @@ static int pdo_mysql_handle_factory(pdo_dbh_t *dbh, zval *driver_options)
 			}
 		}
 #endif
+
+#ifdef PDO_USE_MYSQLND
+		{
+			zend_long ssl_verify_cert = pdo_attr_lval(driver_options,
+					PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT, -1);
+			if (ssl_verify_cert != -1) {
+				connect_opts |= ssl_verify_cert ?
+					CLIENT_SSL_VERIFY_SERVER_CERT:
+					CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
+			}
+		}
+#endif
 	}
 
 #ifdef PDO_MYSQL_HAS_CHARSET
diff --git a/ext/pdo_mysql/pdo_mysql.c b/ext/pdo_mysql/pdo_mysql.c
index fdf7062..79efb21 100644
--- a/ext/pdo_mysql/pdo_mysql.c
+++ b/ext/pdo_mysql/pdo_mysql.c
@@ -130,6 +130,9 @@ static PHP_MINIT_FUNCTION(pdo_mysql)
 	 REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SERVER_PUBLIC_KEY",
(zend_long)PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY);
 #endif
 	REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_MULTI_STATEMENTS",
(zend_long)PDO_MYSQL_ATTR_MULTI_STATEMENTS);
+#ifdef PDO_USE_MYSQLND
+	 REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SSL_VERIFY_SERVER_CERT",
(zend_long)PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT);
+#endif
 
 #ifdef PDO_USE_MYSQLND
 	mysqlnd_reverse_api_register_api(&pdo_mysql_reverse_api);
diff --git a/ext/pdo_mysql/php_pdo_mysql_int.h b/ext/pdo_mysql/php_pdo_mysql_int.h
index 20d640c..08eb731 100644
--- a/ext/pdo_mysql/php_pdo_mysql_int.h
+++ b/ext/pdo_mysql/php_pdo_mysql_int.h
@@ -179,6 +179,9 @@ enum {
 	PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY,
 #endif
 	PDO_MYSQL_ATTR_MULTI_STATEMENTS,
+#ifdef PDO_USE_MYSQLND
+	PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT,
+#endif
 };
 
 #endif
diff --git a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
index f3d0fa6..fba1c24 100644
--- a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
+++ b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
@@ -27,6 +27,7 @@ if (!extension_loaded('mysqli') &&
!extension_loaded('mysqlnd')) {
 		"MYSQL_ATTR_SSL_CIPHER"						=> true,
 		"MYSQL_ATTR_COMPRESS"						=> true,
 		"MYSQL_ATTR_MULTI_STATEMENTS"					=> true,
+		"MYSQL_ATTR_SSL_VERIFY_SERVER_CERT"				=> true,
 	);
 
 	if (!MySQLPDOTest::isPDOMySQLnd()) {
-- 
2.7.4

------------------------------------------------------------------------
[2016-05-22 17:58:22] zhil dot mobile at gmail dot com

I have setuped free SSL sertificate from http://buy.wosign.com/free/
It works on SSH console using mysql command like

mysql -h myhost.com --ssl --ssl-ca=/.../wosign/root_bundle.crt --ssl-verify-server-cert
--ssl-mode=REQUIRED DBNAME -u USERNAME -pPASS

But I failed to make it work using php PDO mysql.
I am considering creating SSH tunel for remote mysql instead of spending more time on this issue.

Do anybody have any ideas how could it be fixed?

------------------------------------------------------------------------
[2016-05-18 17:52:51] nikic@php.net

@andrey: You implemented the mysqli fix for this issue, could you maybe take a look at PDO mysql as
well?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71003


--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1


Thread (18 messages)

« previous php.bugs (#205745) next »