Bug #74445 [NEW]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2
| From: | jball at jball dot org | Date: | Fri, 14 Apr 2017 21:31:56 +0000 |
| Subject: | Bug #74445 [NEW]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-208571@lists.php.net to get a copy of this message | ||
From: jball at jball dot org
Operating system: CentOS 7
PHP version: 7.1.4
Package: MySQLi related
Bug Type: Bug
Bug description:The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2
Description:
------------
In regards to: MySQL native driver for PHP - mysqlnd (ext/mysqli)
The PHP/mysqli connector fails to create an SSL connection with the
TLSv1.2 protocol to a MySQL server.
For example, in the following PHP script, we create a connection to a
MySQL database. Our MySQL database is setup with SSL=On and generates
its own certificates. Additionally, MySQL users are created/altered with
"REQUIRE SSL". The PHP script always connects to MySQL with the TLSv1.0
protocol no matter which CIPHER is selected in the php scripts's ssl_set
method. If we set tls_version=v1.2 or tls_version=v1.1,v1.2 in our
MySQLâs my.cnf file (in tandem with REQUIRE SSL for the user), then
our PHP script will not connect at all to our MySQL database.
Test script:
---------------
1) Compile and install MySQL server with OpenSSL 1.0.1 or greater
2) Edit the configuration of the MySQL server, set
"tls_version=TLSv1.2"
3) Create a user in MySQL with "REQUIRE SSL"
4) Compile PHP 7.1.1, 7.0.15, or 5.6.30 with the same version of OpenSSL
as MySQL
5) Run the following script on PHP (try the script with the MySQL server
variable set to (tls_version=TLSv1.2 and
tls_version=TLSv1,TLSv1.1,TLSv1.2):
Note, in the script below, "TRY-ANY-CIPHER" means we tried all of the
available ciphers and none of them would connect with anything higher
than TLS 1.0.
<?php
echo 'hello';
$mysqli = new mysqli();
$mysqli->init();
# replace TRY-ANY-CIPER with the CIPHER of your choice, or NULL
$mysqli->ssl_set('/etc/ssl/mysql/client-key.pem',
'/etc/ssl/mysql/client-cert.pem', '/etc/ssl/mysql/ca-cert.pem', NULL,
TRY-ANY-CIPHER);
$mysqli->real_connect('hostname.abc', 'ssluser', 'password',
'db', 3306,
null, MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT);
sleep(10);
echo 'goodbye';
?>
6) SSL Test; while the PHP script above is running (in sleep(10)),
verify the SSL protocol of the connection in MySQL with the following
query:
SELECT sbt.variable_value AS tls_version, t2.variable_value AS cipher,
processlist_user AS user, processlist_host AS host
FROM performance_schema.status_by_thread AS sbt
JOIN performance_schema.threads AS t ON t.thread_id = sbt.thread_id
JOIN performance_schema.status_by_thread AS t2 ON t2.thread_id =
t.thread_id
WHERE sbt.variable_name = 'Ssl_version' and t2.variable_name =
'Ssl_cipher' ORDER BY tls_version;
7) The above script will not even connect with this setting:
tls_version=TLSv1.2 The script will connect but only at TLSv1.0 with
this setting: tls_version=TLSv1,TLSv1.1,TLSv1.2
Expected result:
----------------
The script should connect.
7) The above script will not even connect with this setting:
tls_version=TLSv1.2 The script will connect but only at TLSv1.0 with
this setting: tls_version=TLSv1,TLSv1.1,TLSv1.2
Actual result:
--------------
The script fails to connect.
7) The above script will not even connect with this setting:
tls_version=TLSv1.2 The script will connect but only at TLSv1.0 with
this setting: tls_version=TLSv1,TLSv1.1,TLSv1.2
--
Edit bug report at https://bugs.php.net/bug.php?id=74445&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74445&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74445&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74445&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74445&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74445&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74445&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74445&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74445&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74445&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74445&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74445&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74445&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74445&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74445&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74445&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74445&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74445&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74445&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74445&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74445&r=mysqlcfg