Bug #76651 [Csd]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8
| From: | nikic@php.net | Date: | Sun, 16 Sep 2018 06:44:05 +0000 |
| Subject: | Bug #76651 [Csd]: Can't establish a connection to MySQL after upgrading PHP from 7.2.7 to 7.2.8 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217072@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76651&edit=1
ID: 76651
Updated by: nikic@php.net
Reported by: itaylorswift365 at gmail dot com
Summary: Can't establish a connection to MySQL after
upgrading PHP from 7.2.7 to 7.2.8
Status: Closed
Type: Bug
Package: MySQLi related
Operating System: Debian 9.5 x64
PHP Version: 7.2.8
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
PHP 7.2.10 does not yet include the revert (the only released version that does is PHP 7.3.0 RC1).
The fix will be part of the next set of releases.
Previous Comments:
------------------------------------------------------------------------
[2018-09-14 18:53:08] no at mail dot here
This bug is still in PHP 7.2.10 (cli) (built: Sep 13 2018 00:47:25) ( NTS MSVC15 (Visual C++ 2017)
x64 ).
------------------------------------------------------------------------
[2018-09-10 18:11:42] cmb@php.net
This bug should be fixed with commit 03740ef[1].
[1] <http://git.php.net/?p=php-src.git;a=commit;h=03740ef7dffcc80530a89ebde3ccf5464f7f18e6>
------------------------------------------------------------------------
[2018-09-06 08:06:28] no at mail dot her
Niki, You're right.
Using phpMyAdmin and MySql 8.0.12 for testing, depending on the db user's auth type, the
following error messages are returned:
PHP 7.2.7:
Auth type Standard:
Works, no errors.
Auth type caching_sha2_password:
mysqli_real_connect(): The server requested authentication method unknown to the client
[caching_sha2_password]
mysqli_real_connect(): (HY000/2054): The server requested authentication method unknown to the
client
PHP 7.2.8:
Auth type Standard:
mysqli_real_connect(): Unexpected server respose while doing caching_sha2 auth: 109
mysqli_real_connect(): MySQL server has gone away
mysqli_real_connect(): (HY000/2006): MySQL server has gone away
Auth type caching_sha2_password:
mysqli_real_connect(): PHP was built without openssl extension, can't send password encrypted
mysqli_real_connect(): (HY000/1045): Access denied for user
'user123'@'localhost' (using password: YES)
------------------------------------------------------------------------
[2018-09-04 13:29:41] nikic@php.net
@johannes: Maybe I misunderstood the issue. The way I'm reading this bug report is that PHP
7.2.8 *regressed* MySQL authentication for a case that was previously working correctly. That is, a
MySQL setup that worked with PHP 7.2.7 no longer works with PHP 7.2.8. Is that wrong?
------------------------------------------------------------------------
[2018-09-04 09:33:54] johannes@php.net
Reverting doesn't make a thing better.
Root cause: MySQL 8.0 added a new authentication scheme and made it default. PHP builds without this
patch can't use that scheme at all and have to switch to a different older, less secure,
mechanism.
The issues with this change are the dependencies. This new machanism requires OpenSSL and ext/hash
to be available. Without those statically compiled in (we can't do proper runtime guessing for
C symbols) we can't use them and have a compile-time decision to make.
The proper fix would be to enforce OpenSSL and ext/Hash similar to ext/date. It's 2018 and
basic security routines should be a thing users can rely on to be there ...
Reverting this change means that nobody can use the new authentication mechanism.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76651
--
Edit this bug report at https://bugs.php.net/bug.php?id=76651&edit=1