Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars
| From: | nikic@php.net | Date: | Fri, 27 Dec 2019 15:44:23 +0000 |
| Subject: | Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224558@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79011&edit=1
ID: 79011
Updated by: nikic@php.net
Reported by: bendix dot ohlhauser at gmail dot com
Summary: MySQL caching_sha2_password Access denied for
password with more than 20 chars
Status: Open
Type: Bug
Package: MySQLi related
Operating System: Ubuntu 18 LTS
PHP Version: 7.4.1
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
As you mention that logging in via shell fixes the issue, it seems unlikely that this is related to
the password length. caching_sha2_password uses a cache (as the name implies) and has a different
handshake depending on whether the cache is hit or not.
Most likely you are running into an issue where you specify a default socket, but the actual
connection uses TCP, resulting in mysqlnd mistakenly classifying it as a secure transport. This
should be fixed once https://github.com/php/php-src/pull/5034 lands.
Previous Comments:
------------------------------------------------------------------------
[2019-12-27 15:24:47] bendix dot ohlhauser at gmail dot com
A developer at Oracle said that this is a PHP issue. Not sure if he really looked into it.
I personally would rather say it has probably something to do with MySQL, but I have very little
understanding of the internals.
@cmb
Thanks for the hint, but there are 2 possible issues with it:
- Why does it work after logging into MySQL CLI?
- Is the error later 'converted' to "Access Denied"? I'd expect a
different exception for that.
Since I'm a unnecessary middle man, I'd suggest you should talk to the assignee at Oracle.
I will say the same to him.
I'd appreciate an update if you know the underlying issue or the issue has been fixed.
------------------------------------------------------------------------
[2019-12-23 09:05:31] cmb@php.net
You might be hitting
<https://github.com/php/php-src/blob/php-7.4.1/ext/mysqlnd/mysqlnd_auth.c#L798-L808>.
------------------------------------------------------------------------
[2019-12-23 02:23:35] requinix@php.net
It's *potentially* a security issue because the authentication system (<- important)
doesn't seem to be working correctly. Don't know exactly how it's malfunctioning,
which means don't know exactly what is wrong or whether it can be abused.
------------------------------------------------------------------------
[2019-12-23 02:16:58] bugreports at gmail dot com
> --- Potential security issue, not sure though ---
how could "Access denied" be a security issue to begin with?
if you get access with a random wrong password it would be
------------------------------------------------------------------------
[2019-12-23 02:07:02] bendix dot ohlhauser at gmail dot com
It actually happens with passwords with over 19 charaters. See my stackoverflow answer.
It is probably a issue with mysql, but since I'm not 100% sure, I'll leave this open.
Probably not a security issue.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79011
--
Edit this bug report at https://bugs.php.net/bug.php?id=79011&edit=1