Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Comment by: mp at webfactory dot de
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Closed
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Assigned To: andrey
Block user comment: N
Private report: N
New Comment:
Take care: I am under the impression that setting PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT to false
*completely disables* peer certificate verification.
What the OP asked for was to disable *name checking*, but still verifying that the certificate is
issued by the given CA.
So make sure you are actually getting what you want: If the server cert is not checked at all, you
will still see encrypted connections and no errors due to name mismatches. But, in fact, you cannot
be sure which server you're connected to as *any* X509 cert will do!
Previous Comments:
------------------------------------------------------------------------
[2017-03-09 16:32:49] nikic@php.net
Automatic comment on behalf of thomas@orozco.fr
Revision: http://git.php.net/?p=php-src.git;a=commit;h=247ce052cd0fc7d0d8ea1a0e7ea2075e9601766a
Log: Fixed bug #71003: Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT
------------------------------------------------------------------------
[2016-12-03 01:57:53] jeremy at boldapps dot net
I added a PR for this bug a few months ago. https://github.com/php/php-src/pull/1972
Anything else I need to do to get it considered?
------------------------------------------------------------------------
[2016-06-21 15:17:28] mrpatricktully at gmail dot com
We just ran into this same issue. Seeing as re-compiling php with this patch is not really an
option for us (config management setup), we did try the following work around and can confirm it
works. Assuming the CN is something like a hostname (i.e. project name or something other an an IP
address). You can hardcode the name in the local hosts file of the client servers. i.e. if the
CN=server and the mysql server is 192.168.2.1 putting this in your hosts file, then setting the host
to "server" in php works
192.168.2.1 server
This only works of course if you have a one to one match (i.e. won't work if you have more than
one server using the same cert). Not really an ideal solution but it does work if you are in a
bind. Hopefully the patch will be rolled into a release?
------------------------------------------------------------------------
[2016-06-09 11:13:32] thomas at orozco dot fr
(I should mention that the above patch is for the master branch of php-src, but adjusting the
zend_longs to be longs instead makes it work just fine on PHP 5.6.22)
------------------------------------------------------------------------
[2016-06-09 10:38:12] thomas at orozco dot fr
Hi there,
The following patch seems to work for me with some limited testing (it just sets
CLIENT_SSL_VERIFY_SERVER_CERT and the heavy lifting is done by the code from https://bugs.php.net/bug.php?id=68344).
Is this worth submitting as a PR https://github.com/php/php-src? Is there anything I can
do to help move this forward?
---
From ff2c31450a7f5ca2c32b49873c5d6e1a0de67674 Mon Sep 17 00:00:00 2001
From: Thomas Orozco <thomas@orozco.fr>
Date: Thu, 9 Jun 2016 10:45:40 +0200
Subject: [PATCH] Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT
---
ext/pdo_mysql/mysql_driver.c | 12 ++++++++++++
ext/pdo_mysql/pdo_mysql.c | 3 +++
ext/pdo_mysql/php_pdo_mysql_int.h | 3 +++
ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt | 1 +
4 files changed, 19 insertions(+)
diff --git a/ext/pdo_mysql/mysql_driver.c b/ext/pdo_mysql/mysql_driver.c
index 1b1d1ab..20ae458 100644
--- a/ext/pdo_mysql/mysql_driver.c
+++ b/ext/pdo_mysql/mysql_driver.c
@@ -731,6 +731,18 @@ static int pdo_mysql_handle_factory(pdo_dbh_t *dbh, zval *driver_options)
}
}
#endif
+
+#ifdef PDO_USE_MYSQLND
+ {
+ zend_long ssl_verify_cert = pdo_attr_lval(driver_options,
+ PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT, -1);
+ if (ssl_verify_cert != -1) {
+ connect_opts |= ssl_verify_cert ?
+ CLIENT_SSL_VERIFY_SERVER_CERT:
+ CLIENT_SSL_DONT_VERIFY_SERVER_CERT;
+ }
+ }
+#endif
}
#ifdef PDO_MYSQL_HAS_CHARSET
diff --git a/ext/pdo_mysql/pdo_mysql.c b/ext/pdo_mysql/pdo_mysql.c
index fdf7062..79efb21 100644
--- a/ext/pdo_mysql/pdo_mysql.c
+++ b/ext/pdo_mysql/pdo_mysql.c
@@ -130,6 +130,9 @@ static PHP_MINIT_FUNCTION(pdo_mysql)
REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SERVER_PUBLIC_KEY",
(zend_long)PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY);
#endif
REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_MULTI_STATEMENTS",
(zend_long)PDO_MYSQL_ATTR_MULTI_STATEMENTS);
+#ifdef PDO_USE_MYSQLND
+ REGISTER_PDO_CLASS_CONST_LONG("MYSQL_ATTR_SSL_VERIFY_SERVER_CERT",
(zend_long)PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT);
+#endif
#ifdef PDO_USE_MYSQLND
mysqlnd_reverse_api_register_api(&pdo_mysql_reverse_api);
diff --git a/ext/pdo_mysql/php_pdo_mysql_int.h b/ext/pdo_mysql/php_pdo_mysql_int.h
index 20d640c..08eb731 100644
--- a/ext/pdo_mysql/php_pdo_mysql_int.h
+++ b/ext/pdo_mysql/php_pdo_mysql_int.h
@@ -179,6 +179,9 @@ enum {
PDO_MYSQL_ATTR_SERVER_PUBLIC_KEY,
#endif
PDO_MYSQL_ATTR_MULTI_STATEMENTS,
+#ifdef PDO_USE_MYSQLND
+ PDO_MYSQL_ATTR_SSL_VERIFY_SERVER_CERT,
+#endif
};
#endif
diff --git a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
index f3d0fa6..fba1c24 100644
--- a/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
+++ b/ext/pdo_mysql/tests/pdo_mysql_class_constants.phpt
@@ -27,6 +27,7 @@ if (!extension_loaded('mysqli') &&
!extension_loaded('mysqlnd')) {
"MYSQL_ATTR_SSL_CIPHER" => true,
"MYSQL_ATTR_COMPRESS" => true,
"MYSQL_ATTR_MULTI_STATEMENTS" => true,
+ "MYSQL_ATTR_SSL_VERIFY_SERVER_CERT" => true,
);
if (!MySQLPDOTest::isPDOMySQLnd()) {
--
2.7.4
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71003
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1