Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation

From: Date: Wed, 14 Mar 2018 22:55:20 +0000
Subject: Bug #68344 [Com]: MySQLi does not provide way to disable peer certificate validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214361@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68344&edit=1

 ID:                 68344
 Comment by:         spam2 at rhsoft dot net
 Reported by:        james at jamesreno dot com
 Summary:            MySQLi does not provide way to disable peer
                     certificate validation
 Status:             Closed
 Type:               Bug
 Package:            MySQLi related
 Operating System:   NA
 PHP Version:        5.6.2
 Assigned To:        mysql
 Block user comment: N
 Private report:     N

 New Comment:

no it does not, when i deploy new ca/cert/keys pairs and mysqld did not get started no connection is
possible at all until both sides have a certificate from the new self signed CA


Previous Comments:
------------------------------------------------------------------------
[2018-03-14 22:40:59] mp at webfactory dot de

I understand that this request was initially about disabling the check that the host name
you're connecting matches the CN provided in the server's X509 cert. 

In other words, what is desired is to make sure that the server is providing a cert signed by the
given CA, but ignore whatever CN it has.

We now have MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT in mysqli and the (undocumented?)
PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT. 

I am under the impression that they actually do what has been documented, namely "disables
validation of the provided SSL certificate".

So, this does NOT disable only name verification, but COMPLETELY DISABLES certificate checking.

------------------------------------------------------------------------
[2016-12-14 23:24:50] mjmetz at ualberta dot ca

I feel the PHP documentation should be clearer on what this actually does.

http://php.net/manual/en/mysqli.real-connect.php#refsect1-mysqli.real-connect-parameters

MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT 

It currently says:
    Like MYSQLI_CLIENT_SSL, but disables validation of the provided SSL certificate. This is only
for installations using MySQL Native Driver and MySQL 5.6 or later.

But it should highlight that it just disables Common Name (CN) verification but still verifies the
certificate with the CA (if a CA was given in mysqli::set_ssl()).

A better description would be:
    Like MYSQLI_CLIENT_SSL, but disables Common Name (CN) validation of the provided SSL
certificate. CA validation will still occur if a CA was specified with mysqli::set_ssl(). This is
only for installations using MySQL Native Driver and MySQL 5.6 or later.

------------------------------------------------------------------------
[2016-10-13 08:37:32] jimmmaaay at hotmail dot com

MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT is missing from PHP 7

------------------------------------------------------------------------
[2015-12-02 14:12:28] arekm at maven dot pl

Ok, there is bug report already for this:

https://bugs.php.net/bug.php?id=71003

------------------------------------------------------------------------
[2015-12-02 14:02:48] andrey@php.net

yes

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68344


--
Edit this bug report at https://bugs.php.net/bug.php?id=68344&edit=1


Thread (57 messages)

« previous php.bugs (#214361) next »