Bug #69524 [Com]: openssl-pkey-get-public() kill mysql(i) connection with ssl

From: Date: Wed, 25 Jan 2017 14:30:28 +0000
Subject: Bug #69524 [Com]: openssl-pkey-get-public() kill mysql(i) connection with ssl
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206945@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69524&edit=1 ID: 69524 Comment by: jarkkohyvarinen at hotmail dot com Reported by: js at xim dot de Summary: openssl-pkey-get-public() kill mysql(i) connection with ssl Status: Feedback Type: Bug Package: MySQLi related Operating System: Linux Debian PHP Version: 5.6.8 Block user comment: N Private report: N New Comment: If I call openssl_error_string() after openssl_pkey_get_public() the issue does not occur and queries through PDO object works fine. But if I put an invalid string to openssl_pkey_get_public the issue still occurs even if I call openssl_error_string. Previous Comments: ------------------------------------------------------------------------ [2017-01-25 07:39:33] requinix@php.net https://bugs.php.net/bug.php?id=73978 looks like the same issue. @jarkkohyvarinen or anyone: What happens if you put openssl_error_string(); after your call to openssl_pkey_get_public or whatever other OpenSSL function? ------------------------------------------------------------------------ [2017-01-25 07:37:58] requinix@php.net Related To: Bug #73978 ------------------------------------------------------------------------ [2017-01-25 07:17:00] jarkkohyvarinen at hotmail dot com I have also experienced the same issue with pdo-mysql. PHP 5.6.28 CentOS 6.8 OpenSSL 1.0.1e ------------------------------------------------------------------------ [2016-06-10 05:33:32] samm at net-art dot cz I can confirm the issue with pdo-mysql: This is a test script: <?php $pdo = new PDO( 'mysql:host=dbhost.com;dbname=db', 'dbuser', 'dbpass', array( /* PDO::MYSQL_ATTR_SSL_KEY =>'/path/to/client-key.pem', PDO::MYSQL_ATTR_SSL_CERT=>'/path/to/client-cert.pem', */ PDO::MYSQL_ATTR_SSL_CA =>'/etc/rds-combined-ca-bundle.pem' )); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $query="SELECT 1+1"; $query = $pdo->prepare($query); $query->execute(); $row = $query->fetch(PDO::FETCH_ASSOC); var_dump($row); $openssl_pkey_get_public = openssl_pkey_get_public('-----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6ZkX4HXSiL5YPdaHeAIZ IsE+jOTdQQzl2R8geQuOB2ODtlSUzMSWEH1o4AQtdTdoQljdiUfoUQQUaMAVj4K9 QsPV8I+by3nhR2kkgjkobspnxfTbMnVkhNlAAeBOrVDO1OF32r/SWrHH1W+WnjRp g+60bAFvO06OEfVjOTlc4jJAuQq1BCuHalU88yb6wED6A9iP9FLQrQDtKUhTNXRe v/iBpCKTDGzakao6hJspNrw8sS2FsdzQ8TZdlJ4jTaT8DjMGYsu29Mrov0ybUk0D zG1Uk+os/0Bz1BnNcCIqRNuNQo5zjOOTE3DkK1Q9wse1TjEi/cCn74H9OWpSlYY3 CQIDAQAB -----END PUBLIC KEY-----'); $query="SELECT 2+2"; $query = $pdo->prepare($query); $query->execute(); $row = $query->fetch(PDO::FETCH_ASSOC); var_dump($row); ?> This is a return: # php sqltest.php array(1) { ["1+1"]=> string(1) "2" } PHP Warning: PDOStatement::execute(): SSL operation failed with code 1. OpenSSL Error messages: error:0906D06C:PEM routines:PEM_read_bio:no start line in /home/ubuntu/sqltest.php on line 31 PHP Warning: PDOStatement::execute(): MySQL server has gone away in /home/ubuntu/sqltest.php on line 31 PHP Warning: PDOStatement::execute(): Error reading result set's header in /home/ubuntu/sqltest.php on line 31 PHP Fatal error: Uncaught PDOException: SQLSTATE[HY000]: General error: 2006 MySQL server has gone away in /home/ubuntu/sqltest.php:31 Stack trace: #0 /home/ubuntu/sqltest.php(31): PDOStatement->execute() #1 {main} thrown in /home/ubuntu/sqltest.php on line 31 As you could see - second query failed, right after openssl_pkey_get_public call. root@ip-172-32-2-133:~# php -v PHP 7.0.7-4+deb.sury.org~wily+1 (cli) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies with Zend OPcache v7.0.6-dev, Copyright (c) 1999-2016, by Zend Technologies ------------------------------------------------------------------------ [2016-05-02 16:36:33] roy at chameleon dot ad I can confirm a similar issue when using openssl_public_encrypt If the mysql_conn has been opened before (and is using ssl) calling failing $mysqli->query() will fail with error PHP Warning: mysqli::query(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0906D06C:PEM routines:PEM_read_bio:no start line in XXXX on line 35\nPHP message: PHP Warning: mysqli::query(): MySQL server has gone away in XXXX on line 35\nPHP message: PHP Warning: mysqli::query(): Error reading result set's header in XXXX on line 35\n', referer: http://chameleon.ad/signup.php I am using php 5.6.18 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69524 -- Edit this bug report at https://bugs.php.net/bug.php?id=69524&edit=1

« previous php.bugs (#206945) next »