Bug #78824 [NEW]: SSL verification fails on Debian Buster
| From: | markus dot fasselt at gmail dot com | Date: | Sat, 16 Nov 2019 23:11:41 +0000 |
| Subject: | Bug #78824 [NEW]: SSL verification fails on Debian Buster | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-223747@lists.php.net to get a copy of this message | ||
From: markus dot fasselt at gmail dot com
Operating system: Debian Buster
PHP version: 7.3.11
Package: PDO MySQL
Bug Type: Bug
Bug description:SSL verification fails on Debian Buster
Description:
------------
Trying to connect to an AWS RDS MySQL Instance with PDO using an
encrypted SSL connection using the combined CA bundle provided here:
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.IntermediateCertificates
results in the following error:
Fatal error: Uncaught PDOException: PDO::__construct(): SSL operation
failed with code 1. OpenSSL Error messages:
error:1416F086:SSL routines:tls_process_server_certificate:certificate
verify failed in /ssl/test.php:4
I tested this with the official PHP Docker images and using a native
Debian Buster installation.
I tried to find out when this broke and pinned it to version 7.3.7. In
7.3.6 everything worked fine.
In the changelog I found this change:
Fixed bug #78079 (openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c).
This change was also included in 7.2.20 and I was able to confirm the
issue there as well. With 7.2.19 it works fine.
In the Docker images, PHP 7.3.6 and 7.2.19 use OpenSSL version 1.1.0k,
7.3.7 and 7.2.20 use 1.1.1c.
The native Buster installation was using PHP 7.3.11 with OpenSSL
1.1.1d.
Using the Alpine Docker build or an Ubuntu installation works fine. So I
guess this is related to the Debian Buster environment.
The test script tries to connect to an RDS instance. However, I think
you can use any MySQL instance as the certificate validation fails
locally. I do not assume that the CA bundle is invalid, as it works on
several other environments.
Test script:
---------------
# Dockerfile
FROM php:7.3.7-cli
RUN docker-php-ext-install pdo_mysql
# test.php
<?php
$pdo = new PDO('mysql:host=foobar.abc-central-1.rds.amazonaws.com',
'admin', 'egal', [
PDO::MYSQL_ATTR_SSL_CA => './rds-combined-ca-bundle.pem',
PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT => true,
]);
--
Edit bug report at https://bugs.php.net/bug.php?id=78824&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78824&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78824&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78824&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78824&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78824&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78824&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78824&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78824&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78824&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78824&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78824&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78824&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78824&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78824&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78824&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78824&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78824&r=mysqlcfg