Bug #79011 [Fbk->Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars
| From: | bendix dot ohlhauser at gmail dot com | Date: | Mon, 23 Dec 2019 02:07:03 +0000 |
| Subject: | Bug #79011 [Fbk->Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224484@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79011&edit=1
ID: 79011
User updated by: bendix dot ohlhauser at gmail dot com
Reported by: bendix dot ohlhauser at gmail dot com
-Summary: MySQL caching_sha2_password Authentication
inconsistency
+Summary: MySQL caching_sha2_password Access denied for
password with more than 20 chars
-Status: Feedback
+Status: Open
Type: Bug
Package: MySQLi related
Operating System: Ubuntu 18 LTS
PHP Version: 7.4.1
Block user comment: N
Private report: N
New Comment:
It actually happens with passwords with over 19 charaters. See my stackoverflow answer.
It is probably a issue with mysql, but since I'm not 100% sure, I'll leave this open.
Probably not a security issue.
Previous Comments:
------------------------------------------------------------------------
[2019-12-21 20:26:08] requinix@php.net
PHP isn't somehow running your script differently because it knows you did something with the
mysql client, so this sounds like an issue with MySQL's authentication system.
We can wait to see what they think about it.
https://bugs.mysql.com/bug.php?id=98048
------------------------------------------------------------------------
[2019-12-21 19:15:48] bendix dot ohlhauser at gmail dot com
Image showing the issue: https://imgur.com/a/AomDhtt
------------------------------------------------------------------------
[2019-12-21 03:06:48] bendix dot ohlhauser at gmail dot com
Description:
------------
--- Potential security issue, not sure though ---
--- Potentially issue with MySQL, instead of PHP, not sure though ---
Disclaimer: This might look like user error, but most certainly is not.
See: https://stackoverflow.com/questions/59432704/php-7-4-mysql-caching-sha2-password-randomly-denying-passwords
MySQL caching_sha2_password is supported by PHP7.4, but it handles the passwords incorrectly.
The following password via PHP: l0QDEptp*L6tNo28ey^8
Results in Access Denied.
Logging in to the account via mysql shell and running it again fixed the issue.
Also, removing a character fixed the issue.
Regarding php.ini: opcache is enabled.
Feel free to contact me for additional information.
Test script:
---------------
const DB_CHARSET = 'UTF8MB4';
const DB_HOST = '127.0.0.1';
const DB_USERNAME = 'test';
const DB_PASSWORD = '';
$mysqli = new mysqli(DB_HOST, DB_USERNAME, DB_PASSWORD, DB_NAME);
Expected result:
----------------
Successful login
Actual result:
--------------
PHP Warning: mysqli::__construct(): (HY000/1045): Access denied for user
'test'@'localhost' (using password: YES) in /db.php on line 5
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79011&edit=1