Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars

From: Date: Fri, 27 Dec 2019 15:44:23 +0000
Subject: Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224558@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79011&edit=1 ID: 79011 Updated by: nikic@php.net Reported by: bendix dot ohlhauser at gmail dot com Summary: MySQL caching_sha2_password Access denied for password with more than 20 chars Status: Open Type: Bug Package: MySQLi related Operating System: Ubuntu 18 LTS PHP Version: 7.4.1 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: As you mention that logging in via shell fixes the issue, it seems unlikely that this is related to the password length. caching_sha2_password uses a cache (as the name implies) and has a different handshake depending on whether the cache is hit or not. Most likely you are running into an issue where you specify a default socket, but the actual connection uses TCP, resulting in mysqlnd mistakenly classifying it as a secure transport. This should be fixed once https://github.com/php/php-src/pull/5034 lands. Previous Comments: ------------------------------------------------------------------------ [2019-12-27 15:24:47] bendix dot ohlhauser at gmail dot com A developer at Oracle said that this is a PHP issue. Not sure if he really looked into it. I personally would rather say it has probably something to do with MySQL, but I have very little understanding of the internals. @cmb Thanks for the hint, but there are 2 possible issues with it: - Why does it work after logging into MySQL CLI? - Is the error later 'converted' to "Access Denied"? I'd expect a different exception for that. Since I'm a unnecessary middle man, I'd suggest you should talk to the assignee at Oracle. I will say the same to him. I'd appreciate an update if you know the underlying issue or the issue has been fixed. ------------------------------------------------------------------------ [2019-12-23 09:05:31] cmb@php.net You might be hitting <https://github.com/php/php-src/blob/php-7.4.1/ext/mysqlnd/mysqlnd_auth.c#L798-L808>. ------------------------------------------------------------------------ [2019-12-23 02:23:35] requinix@php.net It's *potentially* a security issue because the authentication system (<- important) doesn't seem to be working correctly. Don't know exactly how it's malfunctioning, which means don't know exactly what is wrong or whether it can be abused. ------------------------------------------------------------------------ [2019-12-23 02:16:58] bugreports at gmail dot com > --- Potential security issue, not sure though --- how could "Access denied" be a security issue to begin with? if you get access with a random wrong password it would be ------------------------------------------------------------------------ [2019-12-23 02:07:02] bendix dot ohlhauser at gmail dot com It actually happens with passwords with over 19 charaters. See my stackoverflow answer. It is probably a issue with mysql, but since I'm not 100% sure, I'll leave this open. Probably not a security issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79011 -- Edit this bug report at https://bugs.php.net/bug.php?id=79011&edit=1

« previous php.bugs (#224558) next »