Req #74445 [Ana->Csd]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2
| From: | a at b dot com | Date: | Tue, 04 Jul 2017 11:56:34 +0000 |
| Subject: | Req #74445 [Ana->Csd]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209802@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74445&edit=1
ID: 74445
User updated by: a at b dot com
Reported by: a at b dot com
Summary: The PHP (mysqli) driver only connects with TLS 1.0
and never TLS 1.2
-Status: Analyzed
+Status: Closed
Type: Feature/Change Request
Package: MySQLi related
Operating System: CentOS 7
PHP Version: 7.1.4
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
Fixed in PHP 7.2
Previous Comments:
------------------------------------------------------------------------
[2017-06-23 12:07:46] a at b dot com
Is it possible to add a patch for STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT to PHP 7.2 as PHP 7.2 will
contain other TLS changes (ie. Use TLS_ANY for default ssl:// and tls:// negotiation).
------------------------------------------------------------------------
[2017-05-17 12:06:40] johannes@php.net
So maybe changing the constant to STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT is enough. We'll test and
research. Thanks for the pointer.
------------------------------------------------------------------------
[2017-05-17 11:53:25] spam2 at rhsoft dot net
please look at http://marc.info/?t=149434415400003&r=1&w=2
especially http://marc.info/?l=php-internals&m=149450566923540&w=2
there is no need for params - any TLS capable client these days has to handover the encryption
handshake to the underlying TLS library and connect with the best cipher both sides agree
------------------------------------------------------------------------
[2017-05-17 11:49:19] johannes@php.net
The following patch has been added/updated:
Patch Name: mysqlnd_tls_1_2_workaround.diff
Revision: 1495021758
URL: https://bugs.php.net/patch-display.php?bug=74445&patch=mysqlnd_tls_1_2_workaround.diff&revision=1495021758
------------------------------------------------------------------------
[2017-05-17 11:48:28] johannes@php.net
Currently there is no way to change the crypto method being used. One can pick a cipher, but not the
method. A new API has to be added for setting this and we need a good way for that. Adding yet
another argument for mysqli_ssl_set() isn't nice. Probably we have to refactor the SSL setup in
a larger way.
As a work-around I'm adding a patch to this bug, which switches to TLSv1.2 in a hard-coded way.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74445
--
Edit this bug report at https://bugs.php.net/bug.php?id=74445&edit=1