Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Wed, 14 Mar 2018 22:41:04 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214360@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         mp at webfactory dot de
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Closed
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

I understand that this request was initially about disabling the check that the host name
you're connecting matches the CN provided in the server's X509 cert. 

In other words, what is desired is to make sure that the server is providing a cert signed by the
given CA, but ignore whatever CN it has.

We now have MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT in mysqli and the (undocumented?)
PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT. 

I am under the impression that they actually do what has been documented, namely "disables
validation of the provided SSL certificate".

So, this does NOT disable only name verification, but COMPLETELY DISABLES certificate checking.


Previous Comments:
------------------------------------------------------------------------
[2016-12-14 23:24:50] mjmetz at ualberta dot ca

I feel the PHP documentation should be clearer on what this actually does.

http://php.net/manual/en/mysqli.real-connect.php#refsect1-mysqli.real-connect-parameters

MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT 

It currently says:
    Like MYSQLI_CLIENT_SSL, but disables validation of the provided SSL certificate. This is only
for installations using MySQL Native Driver and MySQL 5.6 or later.

But it should highlight that it just disables Common Name (CN) verification but still verifies the
certificate with the CA (if a CA was given in mysqli::set_ssl()).

A better description would be:
    Like MYSQLI_CLIENT_SSL, but disables Common Name (CN) validation of the provided SSL
certificate. CA validation will still occur if a CA was specified with mysqli::set_ssl(). This is
only for installations using MySQL Native Driver and MySQL 5.6 or later.

------------------------------------------------------------------------
[2016-10-13 08:37:32] jimmmaaay at hotmail dot com

MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is missing from PHP 7

------------------------------------------------------------------------
[2015-12-02 14:12:28] arekm at maven dot pl

Ok, there is bug report already for this:

https://bugs.php.net/bug.php?id=71003

------------------------------------------------------------------------
[2015-12-02 14:02:48] andrey@php.net

yes

------------------------------------------------------------------------
[2015-12-02 13:55:49] arekm at maven dot pl

@andrey: what about mysql PDO?

I don't see these flags being usable in PDO. Should separate bug be filled?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#214360) next »