Bug #73243 [Fbk->Opn]: Unable to configure trusted CA

From: Date: Tue, 04 Oct 2016 23:36:20 +0000
Subject: Bug #73243 [Fbk->Opn]: Unable to configure trusted CA
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204456@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73243&edit=1

 ID:                 73243
 User updated by:    petr dot maly at remotehost dot cz
 Reported by:        petr dot maly at remotehost dot cz
 Summary:            Unable to configure trusted CA
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            LDAP related
 Operating System:   Windows 10
 PHP Version:        7.0.11
 Block user comment: N
 Private report:     N

 New Comment:

Thank you for your responses. 

I have spotted the '%SYSCONFDIR%' constant only in the binary (I cannot found the source
code, from which this binary was build) which I have downloaded from [1] (the file
"php_ldap.dll"). The releases [2] [3] suffers same issue.

Thanks for clarification of '%SYSCONFDIR%' expression. However I have already tried to set
LDAPCONF environment variable and I was not successful to setup the CA.

Thanks,
Petr Maly

[1] http://windows.php.net/downloads/releases/php-7.0.11-nts-Win32-VC14-x86.zip
[2] http://windows.php.net/downloads/qa/php-7.1.0RC3-nts-Win32-VC14-x86.zip
[3] http://windows.php.net/downloads/snaps/php-7.1/r805580d/php-7.1-nts-windows-vc14-x86-r805580d.zip


Previous Comments:
------------------------------------------------------------------------
[2016-10-04 17:28:08] cmb@php.net

According to a message on the OpenLDAP mailing list[1]:

> Also, this [%SYSCONFDIR%) is not an environment variable (you're
> on the unfortunate platform that makes this non-obvious), but a
> macro which should be replaced at 'make install' time.

So if there's %SYSCONFDIR% in the PHP binaries, there might be a
build problem.

Anyhow, setting the environment variable LDAPCONF should solve the
problem[2].

[1] <http://www.openldap.org/lists/openldap-software/200706/msg00121.html>
[2] <http://www.openldap.org/software/man.cgi?query=ldap.conf>

------------------------------------------------------------------------
[2016-10-04 16:31:46] ab@php.net

Thanks for the report. Could you please link to the exact place you've spotted? The PHP
dependencies use same patch as before, see https://github.com/winlibs/openldap/blob/master/include/ldap_config.h#L57
. Otherwise it looks same as #70971 which was turned to the doc issue, still not closed.

Thanks.

------------------------------------------------------------------------
[2016-10-04 14:48:56] petr dot maly at remotehost dot cz

Description:
------------
I have just migrated from PHP 5.6 to PHP 7 and I am unable to connect to LDAP server using SSL. I am
using openldap configuration, which was placed at C:\openldap\sysconf\ldap.conf, to set trustworthy
CA (PHP 5.6). This configuration file is ignored in PHP 7. 

I have been inspecting php_ldap.dll binaries and I have discovered that, in php 7 was the original
hardcoded constant 'c:\openldap\sysconf\ldap.conf' replaced with
'%SYSCONFDIR%\ldap.conf'. I have tried to set SYSCONFDIR environment variable, but it is
not interpreted by the extension.

Could you fix the problem with loading of configuration file, please ? 

Thanks, 
Petr Maly

PS: Drew is facing the same problem:
http://stackoverflow.com/questions/35018674/php-ldap-connect-using-ldaps-to-connect-to-active-directory-getting-unknown-ca-e

Test script:
---------------
<?php
$a = ldap_connect("ldaps://adrien:636");
ldap_set_option($a, LDAP_OPT_NETWORK_TIMEOUT, 5);
ldap_set_option($a, LDAP_OPT_PROTOCOL_VERSION, 3);  // v3 = UTF8 encoding
ldap_set_option($a, LDAP_OPT_REFERRALS, 0);
$r=ldap_bind($a);

echo "-$r-";

Expected result:
----------------
-1-

Actual result:
--------------
PHP Warning:  ldap_bind(): Unable to bind to server: Can't contact LDAP server in
C:\Temp\ldap\test.php on line 9
--


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1


Thread (18 messages)

« previous php.bugs (#204456) next »