Bug #78824 [Com]: SSL verification fails on Debian Buster

From: Date: Thu, 21 Nov 2019 12:28:44 +0000
Subject: Bug #78824 [Com]: SSL verification fails on Debian Buster
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223833@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78824&edit=1 ID: 78824 Comment by: gilperon at gmail dot com Reported by: markus dot fasselt at gmail dot com Summary: SSL verification fails on Debian Buster Status: Open Type: Bug Package: PDO MySQL Operating System: Debian Buster PHP Version: 7.3.11 Block user comment: N Private report: N New Comment: Hey, I think I found an easier way to reproduce this bug you are reporting too! Check the code below: <?php $conn = mysqli_connect("localhost","root","password"); $curl = curl_init(); $opts = array(); //If you use https://www.sitepor500.com.br below (or any domain that has SSL) the bug will happen and nothing will be echoed below, but if you change that domain to anyone that DOES NOT have SSL, the bug goes away. $opts[CURLOPT_URL] = "https://www.sitepor500.com.br"; //$opts[CURLOPT_URL] = "http://anydomainwihoutssl.com"; curl_setopt_array($curl,$opts); echo curl_exec($curl); ?> NOTE: this bug does not happen with file_get_contents only with CURL. Previous Comments: ------------------------------------------------------------------------ [2019-11-20 22:45:29] cmb@php.net Related To: Bug #78845 ------------------------------------------------------------------------ [2019-11-16 23:11:41] markus dot fasselt at gmail dot com Description: ------------ Trying to connect to an AWS RDS MySQL Instance with PDO using an encrypted SSL connection using the combined CA bundle provided here: https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.IntermediateCertificates results in the following error: Fatal error: Uncaught PDOException: PDO::__construct(): SSL operation failed with code 1. OpenSSL Error messages: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed in /ssl/test.php:4 I tested this with the official PHP Docker images and using a native Debian Buster installation. I tried to find out when this broke and pinned it to version 7.3.7. In 7.3.6 everything worked fine. In the changelog I found this change: Fixed bug #78079 (openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c). This change was also included in 7.2.20 and I was able to confirm the issue there as well. With 7.2.19 it works fine. In the Docker images, PHP 7.3.6 and 7.2.19 use OpenSSL version 1.1.0k, 7.3.7 and 7.2.20 use 1.1.1c. The native Buster installation was using PHP 7.3.11 with OpenSSL 1.1.1d. Using the Alpine Docker build or an Ubuntu installation works fine. So I guess this is related to the Debian Buster environment. The test script tries to connect to an RDS instance. However, I think you can use any MySQL instance as the certificate validation fails locally. I do not assume that the CA bundle is invalid, as it works on several other environments. Test script: --------------- # Dockerfile FROM php:7.3.7-cli RUN docker-php-ext-install pdo_mysql # test.php <?php $pdo = new PDO('mysql:host=foobar.abc-central-1.rds.amazonaws.com', 'admin', 'egal', [ PDO::MYSQL_ATTR_SSL_CA => './rds-combined-ca-bundle.pem', PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT => true, ]); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78824&edit=1

« previous php.bugs (#223833) next »