Doc #80436 [NEW]: MYSQL_ATTR_SSL_CAPATH Prevails on MYSQL_ATTR_SSL_VERIFY_SERVER_CERT

From: Date: Sat, 28 Nov 2020 11:09:40 +0000
Subject: Doc #80436 [NEW]: MYSQL_ATTR_SSL_CAPATH Prevails on MYSQL_ATTR_SSL_VERIFY_SERVER_CERT
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18164@lists.php.net to get a copy of this message
From: Patrick dot Messier at canada dot ca Operating system: debian buster PHP version: 7.4.13 Package: PDO MySQL Bug Type: Documentation Problem Bug description:MYSQL_ATTR_SSL_CAPATH Prevails on MYSQL_ATTR_SSL_VERIFY_SERVER_CERT Description: ------------ It seams that whenever PDO::MYSQL_ATTR_SSL_CERT is set to something, PHP will try to validate the database certificate, regardless of the PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT value. Test script: --------------- I've successfully used the following value combination when connecting to MySQL servers that uses a certificate signed by a trusted Certificate Authority (CA). PDO::MYSQL_ATTR_SSL_CAPATH=/etc/ssl/certs PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT=true Based on PHP documentation (https://www.php.net/manual/en/ref.pdo-mysql.php), I thought I could simply toggle MYSQL_ATTR_SSL_VERIFY_SERVER_CERT to false to allow connections to database servers that use self-signed certificate (i.e. for which the CA certificate is absent from /etc/ssl/certs). PDO::MYSQL_ATTR_SSL_CAPATH=/etc/ssl/certs PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT=false Expected result: ---------------- PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT set to false would prevent PHP from validating the database certificate regardless of the MYSQL_ATTR_SSL_CAPATH value. Actual result: -------------- Doing so constantly leads to the following error: PDO::__construct(): SSL operation failed with code 1. OpenSSL Error messages: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed Surpringly, the following combinations works: PDO::MYSQL_ATTR_SSL_CAPATH=null PDO::MYSQL_ATTR_SSL_VERIFY_SERVER_CERT=[false|true] In which case I believe the database server switches to unencrypted protocol, if it allows it, which is not what we want. -- Edit bug report at https://bugs.php.net/bug.php?id=80436&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=80436&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=80436&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=80436&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=80436&r=needscript Try newer version: https://bugs.php.net/fix.php?id=80436&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=80436&r=support Expected behavior: https://bugs.php.net/fix.php?id=80436&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=80436&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=80436&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=80436&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=80436&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=80436&r=dst IIS Stability: https://bugs.php.net/fix.php?id=80436&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=80436&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=80436&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=80436&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=80436&r=mysqlcfg

« previous php.doc.bugs (#18164) next »