Req #74445 [Ana->Csd]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2

From: Date: Tue, 04 Jul 2017 11:56:34 +0000
Subject: Req #74445 [Ana->Csd]: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209802@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74445&edit=1 ID: 74445 User updated by: a at b dot com Reported by: a at b dot com Summary: The PHP (mysqli) driver only connects with TLS 1.0 and never TLS 1.2 -Status: Analyzed +Status: Closed Type: Feature/Change Request Package: MySQLi related Operating System: CentOS 7 PHP Version: 7.1.4 Assigned To: mysql Block user comment: N Private report: N New Comment: Fixed in PHP 7.2 Previous Comments: ------------------------------------------------------------------------ [2017-06-23 12:07:46] a at b dot com Is it possible to add a patch for STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT to PHP 7.2 as PHP 7.2 will contain other TLS changes (ie. Use TLS_ANY for default ssl:// and tls:// negotiation). ------------------------------------------------------------------------ [2017-05-17 12:06:40] johannes@php.net So maybe changing the constant to STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT is enough. We'll test and research. Thanks for the pointer. ------------------------------------------------------------------------ [2017-05-17 11:53:25] spam2 at rhsoft dot net please look at http://marc.info/?t=149434415400003&r=1&w=2 especially http://marc.info/?l=php-internals&m=149450566923540&w=2 there is no need for params - any TLS capable client these days has to handover the encryption handshake to the underlying TLS library and connect with the best cipher both sides agree ------------------------------------------------------------------------ [2017-05-17 11:49:19] johannes@php.net The following patch has been added/updated: Patch Name: mysqlnd_tls_1_2_workaround.diff Revision: 1495021758 URL: https://bugs.php.net/patch-display.php?bug=74445&patch=mysqlnd_tls_1_2_workaround.diff&revision=1495021758 ------------------------------------------------------------------------ [2017-05-17 11:48:28] johannes@php.net Currently there is no way to change the crypto method being used. One can pick a cipher, but not the method. A new API has to be added for setting this and we need a good way for that. Adding yet another argument for mysqli_ssl_set() isn't nice. Probably we have to refactor the SSL setup in a larger way. As a work-around I'm adding a patch to this bug, which switches to TLSv1.2 in a hard-coded way. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74445 -- Edit this bug report at https://bugs.php.net/bug.php?id=74445&edit=1

« previous php.bugs (#209802) next »