Bug #71845 [Com]: Impossible to use PDO with ssl connections

From: Date: Mon, 10 Feb 2020 13:50:10 +0000
Subject: Bug #71845 [Com]: Impossible to use PDO with ssl connections
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225477@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71845&edit=1

 ID:                 71845
 Comment by:         nj dot andreasson at gmail dot com
 Reported by:        source dot spider at gmail dot com
 Summary:            Impossible to use PDO with ssl connections
 Status:             Open
 Type:               Bug
 Package:            PDO MySQL
 Operating System:   centos 7
 PHP Version:        7.0.4
 Block user comment: N
 Private report:     N

 New Comment:

I was yet again hit with this issue in an AWS environment.
I first commented on this issue almost 4 years ago in bug #71003 but it was sadly closed further
down the line (not sure why?).
As explained in bug 71003, I still see that the best solution would be to expose a
"verify_peer_name" directive that you could populate with the expected peer name to
verify.
Thanks for considering it!


Previous Comments:
------------------------------------------------------------------------
[2020-01-27 12:50:19] cmb@php.net

Related To: Bug #72878

------------------------------------------------------------------------
[2016-05-18 02:05:16] requinix@php.net

Related To: Bug #71003

------------------------------------------------------------------------
[2016-05-18 02:04:09] requinix@php.net

See also request #71003 to expose the mysqli flag to PDO.

------------------------------------------------------------------------
[2016-05-18 02:02:50] requinix@php.net

Related To: Bug #72235

------------------------------------------------------------------------
[2016-03-17 15:47:10] source dot spider at gmail dot com

Description:
------------
Services such as Google Cloud SQL have SSL certificates signed as CN=`project:instance-name'
(literally). However to connect to them IPs are required. In some cases you may also need to connect
to multiple servers, but the certificate remains unchanged (the service in question provide only one
set of certificates). As such the verification done by php (or mysqlnd?) is pointless and simply
serves to break the application establishing a secure connection[1].

The error will manifest as "PDO::__construct(): Peer certificate
CN=project:instance-name' did not match expected CN=123.456.78.9' in
/path/to/script.php"

None of the mechanisms that would disable the verification, such as stream_context_set_default[2],
actually affect the connection in any way.

There appears to be a MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT (which was introduced to fix the
same mistake on mysqli apparently) however the functionality wasn't ported to any of the other
interfaces even though it's clearly just as broken everywhere else.

___________

[1] many applications require the connection to be secure to ensure sensitive information isn't
just traveling in plain text over pipes to and from the database

[2] full example of stream_context_set_default

stream_context_set_default([
    'ssl' => [
	'verify_peer_name' => false,
        'verify_peer' => false
    ]
]);

Test script:
---------------
<?php

#
# The following parameters will need to be filled in and the certificate
# must not match the dbhost parameter. Ideally we wouldn't need to modify
# the default context and could customize via $options instead
#

$dbhost = '';
$dbname = '';
$dbuser = '';
$dbpass = '';

stream_context_set_default([
    'ssl' => [
	'verify_peer_name' => false,
        'verify_peer' => false
    ]
]);

$options = [
	\PDO::MYSQL_ATTR_SSL_KEY  => __DIR__.'/client-key.pem',
	\PDO::MYSQL_ATTR_SSL_CERT => __DIR__.'/client-cert.pem',
	\PDO::MYSQL_ATTR_SSL_CA   => __DIR__.'/server-ca.pem'
];



$dsn = 'mysql:host='.$dbhost.';dbname='.$dbname.';charset=utf8';

try {
	$pdo = new \PDO($dsn, $dbuser, $dbpass, $options);
	echo "SUCCESS!\n\n";
}
catch (\Exception $e) {
	echo "FAILED!\n\n";
	throw $e;
}

Expected result:
----------------
The script should print "SUCCESS!"

Actual result:
--------------
The script prints "FAILED!" and throws the error saying "PDO::__construct(): Peer
certificate CN=project:instance-name' did not match expected CN=123.456.78.9'
in /path/to/script.php"


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71845&edit=1


Thread (7 messages)

« previous php.bugs (#225477) next »