Bug #76651 [Csd]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8

From: Date: Sun, 16 Sep 2018 06:44:05 +0000
Subject: Bug #76651 [Csd]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217072@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76651&edit=1 ID: 76651 Updated by: nikic@php.net Reported by: itaylorswift365 at gmail dot com Summary: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8 Status: Closed Type: Bug Package: MySQLi related Operating System: Debian 9.5 x64 PHP Version: 7.2.8 Assigned To: mysql Block user comment: N Private report: N New Comment: PHP 7.2.10 does not yet include the revert (the only released version that does is PHP 7.3.0 RC1). The fix will be part of the next set of releases. Previous Comments: ------------------------------------------------------------------------ [2018-09-14 18:53:08] no at mail dot here This bug is still in PHP 7.2.10 (cli) (built: Sep 13 2018 00:47:25) ( NTS MSVC15 (Visual C++ 2017) x64 ). ------------------------------------------------------------------------ [2018-09-10 18:11:42] cmb@php.net This bug should be fixed with commit 03740ef[1]. [1] <http://git.php.net/?p=php-src.git;a=commit;h=03740ef7dffcc80530a89ebde3ccf5464f7f18e6> ------------------------------------------------------------------------ [2018-09-06 08:06:28] no at mail dot her Niki, You're right. Using phpMyAdmin and MySql 8.0.12 for testing, depending on the db user's auth type, the following error messages are returned: PHP 7.2.7: Auth type Standard: Works, no errors. Auth type caching_sha2_password: mysqli_real_connect(): The server requested authentication method unknown to the client [caching_sha2_password] mysqli_real_connect(): (HY000/2054): The server requested authentication method unknown to the client PHP 7.2.8: Auth type Standard: mysqli_real_connect(): Unexpected server respose while doing caching_sha2 auth: 109 mysqli_real_connect(): MySQL server has gone away mysqli_real_connect(): (HY000/2006): MySQL server has gone away Auth type caching_sha2_password: mysqli_real_connect(): PHP was built without openssl extension, can't send password encrypted mysqli_real_connect(): (HY000/1045): Access denied for user 'user123'@'localhost' (using password: YES) ------------------------------------------------------------------------ [2018-09-04 13:29:41] nikic@php.net @johannes: Maybe I misunderstood the issue. The way I'm reading this bug report is that PHP 7.2.8 *regressed* MySQL authentication for a case that was previously working correctly. That is, a MySQL setup that worked with PHP 7.2.7 no longer works with PHP 7.2.8. Is that wrong? ------------------------------------------------------------------------ [2018-09-04 09:33:54] johannes@php.net Reverting doesn't make a thing better. Root cause: MySQL 8.0 added a new authentication scheme and made it default. PHP builds without this patch can't use that scheme at all and have to switch to a different older, less secure, mechanism. The issues with this change are the dependencies. This new machanism requires OpenSSL and ext/hash to be available. Without those statically compiled in (we can't do proper runtime guessing for C symbols) we can't use them and have a compile-time decision to make. The proper fix would be to enforce OpenSSL and ext/Hash similar to ext/date. It's 2018 and basic security routines should be a thing users can rely on to be there ... Reverting this change means that nobody can use the new authentication mechanism. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76651 -- Edit this bug report at https://bugs.php.net/bug.php?id=76651&edit=1

« previous php.bugs (#217072) next »