Bug #78824 [NEW]: SSL verification fails on Debian Buster

From: Date: Sat, 16 Nov 2019 23:11:41 +0000
Subject: Bug #78824 [NEW]: SSL verification fails on Debian Buster
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223747@lists.php.net to get a copy of this message
From: markus dot fasselt at gmail dot com Operating system: Debian Buster PHP version: 7.3.11 Package: PDO MySQL Bug Type: Bug Bug description:SSL verification fails on Debian Buster Description: ------------ Trying to connect to an AWS RDS MySQL Instance with PDO using an encrypted SSL connection using the combined CA bundle provided here: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.IntermediateCertificates results in the following error: Fatal error: Uncaught PDOException: PDO::__construct(): SSL operation failed with code 1. OpenSSL Error messages: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed in /ssl/test.php:4 I tested this with the official PHP Docker images and using a native Debian Buster installation. I tried to find out when this broke and pinned it to version 7.3.7. In 7.3.6 everything worked fine. In the changelog I found this change: Fixed bug #78079 (openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c). This change was also included in 7.2.20 and I was able to confirm the issue there as well. With 7.2.19 it works fine. In the Docker images, PHP 7.3.6 and 7.2.19 use OpenSSL version 1.1.0k, 7.3.7 and 7.2.20 use 1.1.1c. The native Buster installation was using PHP 7.3.11 with OpenSSL 1.1.1d. Using the Alpine Docker build or an Ubuntu installation works fine. So I guess this is related to the Debian Buster environment. The test script tries to connect to an RDS instance. However, I think you can use any MySQL instance as the certificate validation fails locally. I do not assume that the CA bundle is invalid, as it works on several other environments. Test script: --------------- # Dockerfile FROM php:7.3.7-cli RUN docker-php-ext-install pdo_mysql # test.php <?php $pdo = new PDO('mysql:host=foobar.abc-central-1.rds.amazonaws.com', 'admin', 'egal', [ PDO::MYSQL_ATTR_SSL_CA => './rds-combined-ca-bundle.pem', PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT => true, ]); -- Edit bug report at https://bugs.php.net/bug.php?id=78824&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78824&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78824&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78824&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78824&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78824&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78824&r=support Expected behavior: https://bugs.php.net/fix.php?id=78824&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78824&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78824&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78824&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78824&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78824&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78824&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78824&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78824&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78824&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78824&r=mysqlcfg

« previous php.bugs (#223747) next »