Edit report at https://bugs.php.net/bug.php?id=71003&edit=1
ID: 71003
Comment by: anrdaemon at yandex dot ru
Reported by: tmatsuo at google dot com
Summary: Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to
PDO interface
Status: Closed
Type: Feature/Change Request
Package: PDO MySQL
PHP Version: 5.6.16
Assigned To: andrey
Block user comment: N
Private report: N
New Comment:
The verification should be fixed, not avoided.
Client must verify host names against DNS: and IP: records in subjectAltName, as domain names are
not obliged to appear in CN.
Also, how would you solve a problem of connecting to the same server by multiple names, if you only
verify that CN do match?
On the top of that, why MySQLi works and verifies ok while PDO does not?
On the same host, using same credentials, in the same script, in the same running session.
Previous Comments:
------------------------------------------------------------------------
[2020-02-10 13:50:10] nj dot andreasson at gmail dot com
Related To: Bug #71845
------------------------------------------------------------------------
[2020-02-10 13:50:10] nj dot andreasson at gmail dot com
Related To: Bug #71845
------------------------------------------------------------------------
[2019-10-16 14:32:20] guir dot oliveira at hotmail dot com
I've just stumbled into this problem and still can't use it... The solution of disabling
the verification completely isn't reliable as it wouldn't be as secure as verifying the
CA.
What we need is to expose an option to not verify ONLY the hostname X CN.
In my opinion this issue should be reopened.
------------------------------------------------------------------------
[2018-07-27 13:50:31] nj dot johansson at gmail dot com
I agree with the previous commentator that just exposing PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT and
letting you set it to false isn't a good solution.
My previous comment from 2016-04-04 actually still stands.
I would like to be able to have peer verification enabled but explicitly tell which peer name I
expect, just like the 'peer_name' setting available in the SSL context options
(http://php.net/manual/en/context.ssl.php#context.ssl.verify-peer-name).
Is there a reasonable way to expose this setting?
Still to date I'm using a workaround to not be hit by the issue detailed here.
------------------------------------------------------------------------
[2018-03-14 22:59:54] mp at webfactory dot de
Take care: I am under the impression that setting PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT to false
*completely disables* peer certificate verification.
What the OP asked for was to disable *name checking*, but still verifying that the certificate is
issued by the given CA.
So make sure you are actually getting what you want: If the server cert is not checked at all, you
will still see encrypted connections and no errors due to name mismatches. But, in fact, you cannot
be sure which server you're connected to as *any* X509 cert will do!
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71003
--
Edit this bug report at https://bugs.php.net/bug.php?id=71003&edit=1