Bug #76651 [Com]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8

From: Date: Fri, 14 Sep 2018 18:53:08 +0000
Subject: Bug #76651 [Com]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217058@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76651&edit=1 ID: 76651 Comment by: no at mail dot here Reported by: itaylorswift365 at gmail dot com Summary: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8 Status: Closed Type: Bug Package: MySQLi related Operating System: Debian 9.5 x64 PHP Version: 7.2.8 Assigned To: mysql Block user comment: N Private report: N New Comment: This bug is still in PHP 7.2.10 (cli) (built: Sep 13 2018 00:47:25) ( NTS MSVC15 (Visual C++ 2017) x64 ). Previous Comments: ------------------------------------------------------------------------ [2018-09-10 18:11:42] cmb@php.net This bug should be fixed with commit 03740ef[1]. [1] <http://git.php.net/?p=php-src.git;a=commit;h=03740ef7dffcc80530a89ebde3ccf5464f7f18e6> ------------------------------------------------------------------------ [2018-09-06 08:06:28] no at mail dot her Niki, You're right. Using phpMyAdmin and MySql 8.0.12 for testing, depending on the db user's auth type, the following error messages are returned: PHP 7.2.7: Auth type Standard: Works, no errors. Auth type caching_sha2_password: mysqli_real_connect(): The server requested authentication method unknown to the client [caching_sha2_password] mysqli_real_connect(): (HY000/2054): The server requested authentication method unknown to the client PHP 7.2.8: Auth type Standard: mysqli_real_connect(): Unexpected server respose while doing caching_sha2 auth: 109 mysqli_real_connect(): MySQL server has gone away mysqli_real_connect(): (HY000/2006): MySQL server has gone away Auth type caching_sha2_password: mysqli_real_connect(): PHP was built without openssl extension, can't send password encrypted mysqli_real_connect(): (HY000/1045): Access denied for user 'user123'@'localhost' (using password: YES) ------------------------------------------------------------------------ [2018-09-04 13:29:41] nikic@php.net @johannes: Maybe I misunderstood the issue. The way I'm reading this bug report is that PHP 7.2.8 *regressed* MySQL authentication for a case that was previously working correctly. That is, a MySQL setup that worked with PHP 7.2.7 no longer works with PHP 7.2.8. Is that wrong? ------------------------------------------------------------------------ [2018-09-04 09:33:54] johannes@php.net Reverting doesn't make a thing better. Root cause: MySQL 8.0 added a new authentication scheme and made it default. PHP builds without this patch can't use that scheme at all and have to switch to a different older, less secure, mechanism. The issues with this change are the dependencies. This new machanism requires OpenSSL and ext/hash to be available. Without those statically compiled in (we can't do proper runtime guessing for C symbols) we can't use them and have a compile-time decision to make. The proper fix would be to enforce OpenSSL and ext/Hash similar to ext/date. It's 2018 and basic security routines should be a thing users can rely on to be there ... Reverting this change means that nobody can use the new authentication mechanism. ------------------------------------------------------------------------ [2018-09-04 04:05:40] nikic@php.net I've reverted the MySQL auth changes via https://github.com/php/php-src/commit/03740ef7dffcc80530a89ebde3ccf5464f7f18e6 in all branches, which will hopefully resolve this issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76651 -- Edit this bug report at https://bugs.php.net/bug.php?id=76651&edit=1

« previous php.bugs (#217058) next »