Bug #72048 [Com]: No way to disable peer name verification

From: Date: Sun, 03 Oct 2021 18:09:37 +0000
Subject: Bug #72048 [Com]: No way to disable peer name verification
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237003@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72048&edit=1 ID: 72048 Comment by: php5443 at gmail dot com Reported by: michal at cihar dot com Summary: No way to disable peer name verification Status: Open Type: Bug Package: MySQLi related PHP Version: 7.0Git-2016-04-18 (Git) Block user comment: N Private report: N New Comment: https://images.google.co.uk/url?q=https%3A%2F%2Fa.tvfun.me%2Fhabibati-man-takoun%2F Previous Comments: ------------------------------------------------------------------------ [2020-03-05 06:01:20] alivai1976 at gmail dot com The following pull request has been associated: Patch Name: Fix #79133 - Replace <literal> with <code> On GitHub: https://github.com/php/doc-en/pull/23 Patch: https://github.com/php/doc-en/pull/23.patch ------------------------------------------------------------------------ [2016-04-18 14:11:11] michal at cihar dot com Description: ------------ Currently the MySQLi driver only allows to validate SSL certificate and whether it matches provided CN or skip both of these. This leads to insecure setup in many cases as you have to disable SSL verification in order to workaround CN/hostname mismatch (which is quite usual with cloud providers as CN contains name of the instance and you connect using IP address, this is true for example for Google Cloud SQL), what makes using SSL pretty much useless as you're open to MITM attacks. What is missing is separate control to disable only ssl.verify_peer_name as you still want to verify the server certificate. See also https://bugs.php.net/bug.php?id=68344 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72048&edit=1

« previous php.bugs (#237003) next »