[php-src] Issue #8577: PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT still checking CN
| From: | drewwynne0 | Date: | Wed, 18 May 2022 17:55:37 +0000 |
| Subject: | [php-src] Issue #8577: PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT still checking CN | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-241535@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8577
Author: drewwynne0
### Description
Apologies, may not be a bug but cannot seems to find anything after extensive research.
The following code:
```php
PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT => false,
```
Resulted in this output:
```
Peer certificate CN=
*.proxy-~~~.eu-west-2.rds.amazonaws.com' did not match expected
CN=~~~.**endpoint**.proxy-~~~.eu-west-2.rds.amazonaws.com'
```
~~~ used for masking
But I expected this output instead:
```
Successful mysql connection
```
There doesn't seem to be a specific way to force ``--ssl-mode=VERIFY_CA``
mysql cli connection works fine with this flag
Scenario - I am utilising AWS RDS Proxy with a Read/Write endpoint and a Read endpoint. Read/write
connects for, but when trying to connect to the read only endpoint, receive the above error,
assuming that the read only is within the subdomain **.endpoint.proxy-** whereas the read/write is
with **.proxy-**
### PHP Version
PHP 8.1.6
### Operating System
Windows 11 // Ubuntu 20.04