Bug #70971 [Fbk]: LDAP Not Reading Config File (ldap.cfg)

From: Date: Thu, 26 Nov 2015 01:53:23 +0000
Subject: Bug #70971 [Fbk]: LDAP Not Reading Config File (ldap.cfg)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197426@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70971&edit=1 ID: 70971 Updated by: ab@php.net Reported by: jspringe at gmail dot com Summary: LDAP Not Reading Config File (ldap.cfg) Status: Feedback Type: Bug Package: LDAP related Operating System: Windows (7/8/10) PHP Version: 7.0.0RC7 Block user comment: N Private report: N New Comment: Btw the error message you posted looks pretty much like that, certificate failure. IIRC starting with even with OpenSSL 1.0.1, custom certificates might be deleted automatically from the Windows storage, as they got validated with some trusted certificate checker service. Thanks. Previous Comments: ------------------------------------------------------------------------ [2015-11-26 01:49:30] ab@php.net Thanks for the further info. As I've mentioned, i couldn't spot any attempts to load the config file at the startup file. It likely could be, that the file is only getting loaded when PHP code starts to work. I'll probably have to setup a ldap server, lets see. But one thing I would like to ask you before - please check the event logs. 5.5 and 7 use different OpenSSL versions. OPenSSL 1.0.2 used with 7.0 is integrated better with the Windows APIs. It could be, that your certificate gets validated live and OpenSSL just refuses it. Thanks. ------------------------------------------------------------------------ [2015-11-25 19:00:46] jspringe at gmail dot com Current working configuration: PHP 5.5.30 Config File: C:\OpenLDAP\sysconf\ldap.cfg Contents: TLS_REQCERT never Current failing configuration: PHP 7.0.0RC7 Config File: C:\OpenLDAP\sysconf\ldap.cfg Contents: TLS_REQCERT never Code: $ldap_identifier = ldap_connect('ldaps://activedirectory'); ldap_set_option($ldap_identifier, LDAP_OPT_REFERRALS, 0); ldap_set_option($ldap_identifier, LDAP_OPT_PROTOCOL_VERSION, 3); $bind = ldap_bind($ldap_identifier, 'user', 'password'); if ($bind !== true) { ldap_get_option($ldap_identifier, LDAP_OPT_DIAGNOSTIC_MESSAGE, $extended_error); echo $extended_error; } else { echo "Connected"; var_dump($bind); } PHP 5.5.30 Output: Connected boolean true PHP 7.0.0RC7 Output: Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in ... on line 8 error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (unable to get local issuer certificate) This was an error I received prior to creating the configuration file on 5.5.30. This is just a proof-of-concept and CURRENTLY I'm not concerned with the certificate (I actually know it's expired which is a problem I'll tackle later). Either way with the configuration file it should work the same as before or documentation needs to be updated. Also the documentation itself doesn't mention the configuration file - luckily a few comments do. ------------------------------------------------------------------------ [2015-11-25 17:03:19] ab@php.net Thanks for the report. Could you please explain, how it is supposed to work. Any snippet? I've just compared 7.0 and 5.6 and the behavior is not different. OpenLDAP is always compiled with SSL support and either of versions trying to load any of config files. The build config of dependencies is in both cases the same and the sysconf is set to c:\\openldap\\sysconf. I need more tips from you to reproduce the behavior. Thanks. ------------------------------------------------------------------------ [2015-11-25 14:44:50] jspringe at gmail dot com Description: ------------ LDAP extension does not appear to be reading a configuration file. In previous versions for Windows LDAP expects the configuration file to be in C:\OpenLDAP\sysconf\ldap.conf. This does not appear to work in RC7. This means the a connection cannot be established over SSL due to not being able set configuration options such as TLS_REQCERT or TLSCACertificatePath. Most persistent changes require SSL/TLS. If this has been changed than there is no documentation expressing the change. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70971&edit=1

« previous php.bugs (#197426) next »