Bug #69524 [Com]: openssl-pkey-get-public() kill mysql(i) connection with ssl
| From: | jarkkohyvarinen at hotmail dot com | Date: | Wed, 25 Jan 2017 14:30:28 +0000 |
| Subject: | Bug #69524 [Com]: openssl-pkey-get-public() kill mysql(i) connection with ssl | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206945@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69524&edit=1
ID: 69524
Comment by: jarkkohyvarinen at hotmail dot com
Reported by: js at xim dot de
Summary: openssl-pkey-get-public() kill mysql(i) connection
with ssl
Status: Feedback
Type: Bug
Package: MySQLi related
Operating System: Linux Debian
PHP Version: 5.6.8
Block user comment: N
Private report: N
New Comment:
If I call openssl_error_string() after openssl_pkey_get_public() the issue does not occur and
queries through PDO object works fine. But if I put an invalid string to openssl_pkey_get_public the
issue still occurs even if I call openssl_error_string.
Previous Comments:
------------------------------------------------------------------------
[2017-01-25 07:39:33] requinix@php.net
https://bugs.php.net/bug.php?id=73978 looks like
the same issue.
@jarkkohyvarinen or anyone: What happens if you put
openssl_error_string();
after your call to openssl_pkey_get_public or whatever other OpenSSL function?
------------------------------------------------------------------------
[2017-01-25 07:37:58] requinix@php.net
Related To: Bug #73978
------------------------------------------------------------------------
[2017-01-25 07:17:00] jarkkohyvarinen at hotmail dot com
I have also experienced the same issue with pdo-mysql.
PHP 5.6.28
CentOS 6.8
OpenSSL 1.0.1e
------------------------------------------------------------------------
[2016-06-10 05:33:32] samm at net-art dot cz
I can confirm the issue with pdo-mysql:
This is a test script:
<?php
$pdo = new PDO(
'mysql:host=dbhost.com;dbname=db',
'dbuser',
'dbpass',
array(
/* PDO::MYSQL_ATTR_SSL_KEY =>'/path/to/client-key.pem',
PDO::MYSQL_ATTR_SSL_CERT=>'/path/to/client-cert.pem', */
PDO::MYSQL_ATTR_SSL_CA =>'/etc/rds-combined-ca-bundle.pem'
));
$pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$query="SELECT 1+1";
$query = $pdo->prepare($query);
$query->execute();
$row = $query->fetch(PDO::FETCH_ASSOC);
var_dump($row);
$openssl_pkey_get_public = openssl_pkey_get_public('-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6ZkX4HXSiL5YPdaHeAIZ
IsE+jOTdQQzl2R8geQuOB2ODtlSUzMSWEH1o4AQtdTdoQljdiUfoUQQUaMAVj4K9
QsPV8I+by3nhR2kkgjkobspnxfTbMnVkhNlAAeBOrVDO1OF32r/SWrHH1W+WnjRp
g+60bAFvO06OEfVjOTlc4jJAuQq1BCuHalU88yb6wED6A9iP9FLQrQDtKUhTNXRe
v/iBpCKTDGzakao6hJspNrw8sS2FsdzQ8TZdlJ4jTaT8DjMGYsu29Mrov0ybUk0D
zG1Uk+os/0Bz1BnNcCIqRNuNQo5zjOOTE3DkK1Q9wse1TjEi/cCn74H9OWpSlYY3
CQIDAQAB
-----END PUBLIC KEY-----');
$query="SELECT 2+2";
$query = $pdo->prepare($query);
$query->execute();
$row = $query->fetch(PDO::FETCH_ASSOC);
var_dump($row);
?>
This is a return:
# php sqltest.php
array(1) {
["1+1"]=>
string(1) "2"
}
PHP Warning: PDOStatement::execute(): SSL operation failed with code 1. OpenSSL Error messages:
error:0906D06C:PEM routines:PEM_read_bio:no start line in /home/ubuntu/sqltest.php on line 31
PHP Warning: PDOStatement::execute(): MySQL server has gone away in /home/ubuntu/sqltest.php on
line 31
PHP Warning: PDOStatement::execute(): Error reading result set's header in
/home/ubuntu/sqltest.php on line 31
PHP Fatal error: Uncaught PDOException: SQLSTATE[HY000]: General error: 2006 MySQL server has gone
away in /home/ubuntu/sqltest.php:31
Stack trace:
#0 /home/ubuntu/sqltest.php(31): PDOStatement->execute()
#1 {main}
thrown in /home/ubuntu/sqltest.php on line 31
As you could see - second query failed, right after openssl_pkey_get_public call.
root@ip-172-32-2-133:~# php -v
PHP 7.0.7-4+deb.sury.org~wily+1 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.6-dev, Copyright (c) 1999-2016, by Zend Technologies
------------------------------------------------------------------------
[2016-05-02 16:36:33] roy at chameleon dot ad
I can confirm a similar issue when using openssl_public_encrypt
If the mysql_conn has been opened before (and is using ssl) calling failing $mysqli->query() will
fail with error
PHP Warning: mysqli::query(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:0906D06C:PEM routines:PEM_read_bio:no start line in XXXX on line 35\nPHP message:
PHP Warning: mysqli::query(): MySQL server has gone away in XXXX on line 35\nPHP message: PHP
Warning: mysqli::query(): Error reading result set's header in XXXX on line 35\n',
referer: http://chameleon.ad/signup.php
I am using php 5.6.18
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69524
--
Edit this bug report at https://bugs.php.net/bug.php?id=69524&edit=1