Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface

From: Date: Wed, 16 Oct 2019 14:32:20 +0000
Subject: Req #71003 [Com]: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO interface
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223216@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71003&edit=1

 ID:                 71003
 Comment by:         guir dot oliveira at hotmail dot com
 Reported by:        tmatsuo at google dot com
 Summary:            Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
                     PDO interface
 Status:             Closed
 Type:               Feature/Change Request
 Package:            PDO MySQL
 PHP Version:        5.6.16
 Assigned To:        andrey
 Block user comment: N
 Private report:     N

 New Comment:

I've just stumbled into this problem and still can't use it... The solution of disabling
the verification completely isn't reliable as it wouldn't be as secure as verifying the
CA.

What we need is to expose an option to not verify ONLY the hostname X CN.

In my opinion this issue should be reopened.


Previous Comments:
------------------------------------------------------------------------
[2018-07-27 13:50:31] nj dot johansson at gmail dot com

I agree with the previous commentator that just exposing PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT and
letting you set it to false isn't a good solution.

My previous comment from 2016-04-04 actually still stands.
I would like to be able to have peer verification enabled but explicitly tell which peer name I
expect, just like the 'peer_name' setting available in the SSL context options
(http://php.net/manual/en/context.ssl.php#context.ssl.verify-peer-name).

Is there a reasonable way to expose this setting?
Still to date I'm using a workaround to not be hit by the issue detailed here.

------------------------------------------------------------------------
[2018-03-14 22:59:54] mp at webfactory dot de

Take care: I am under the impression that setting PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT to false
*completely disables* peer certificate verification.

What the OP asked for was to disable *name checking*, but still verifying that the certificate is
issued by the given CA.

So make sure you are actually getting what you want: If the server cert is not checked at all, you
will still see encrypted connections and no errors due to name mismatches. But, in fact, you cannot
be sure which server you're connected to as *any* X509 cert will do!

------------------------------------------------------------------------
[2017-03-09 16:32:49] nikic@php.net

Automatic comment on behalf of thomas@orozco.fr
Revision: http://git.php.net/?p=php-src.git;a=commit;h=247ce052cd0fc7d0d8ea1a0e7ea2075e9601766a
Log: Fixed bug #71003: Add PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT

------------------------------------------------------------------------
[2016-12-03 01:57:53] jeremy at boldapps dot net

I added a PR for this bug a few months ago. https://github.com/php/php-src/pull/1972
Anything else I need to do to get it considered?

------------------------------------------------------------------------
[2016-06-21 15:17:28] mrpatricktully at gmail dot com

We just ran into this same issue.  Seeing as re-compiling php with this patch is not really an
option for us (config management setup), we did try the following work around and can confirm it
works.  Assuming the CN is something like a hostname (i.e. project name or something other an an IP
address).  You can hardcode the name in the local hosts file of the client servers.  i.e. if the
CN=server and the mysql server is 192.168.2.1 putting this in your hosts file, then setting the host
to "server" in php works

192.168.2.1  server

This only works of course if you have a one to one match (i.e. won't work if you have more than
one server using the same cert).  Not really an ideal solution but it does work if you are in a
bind.  Hopefully the patch will be rolled into a release?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71003


--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1


Thread (18 messages)

« previous php.bugs (#223216) next »