Edit report at https://bugs.php.net/bug.php?id=73243&edit=1
ID: 73243
Updated by: cmb@php.net
Reported by: petr dot maly at remotehost dot cz
Summary: Unable to configure trusted CA
-Status: Open
+Status: Verified
Type: Bug
Package: LDAP related
-Operating System: Windows 10
+Operating System: Windows 10 x86
PHP Version: 7.0.11
Block user comment: N
Private report: N
New Comment:
I can confirm the issue for x86 builds (checked PHP 7.0.10 and
7.0.11), but not for x64.
Previous Comments:
------------------------------------------------------------------------
[2016-10-04 23:36:18] petr dot maly at remotehost dot cz
Thank you for your responses.
I have spotted the '%SYSCONFDIR%' constant only in the binary (I cannot found the source
code, from which this binary was build) which I have downloaded from [1] (the file
"php_ldap.dll"). The releases [2] [3] suffers same issue.
Thanks for clarification of '%SYSCONFDIR%' expression. However I have already tried to set
LDAPCONF environment variable and I was not successful to setup the CA.
Thanks,
Petr Maly
[1] http://windows.php.net/downloads/releases/php-7.0.11-nts-Win32-VC14-x86.zip
[2] http://windows.php.net/downloads/qa/php-7.1.0RC3-nts-Win32-VC14-x86.zip
[3] http://windows.php.net/downloads/snaps/php-7.1/r805580d/php-7.1-nts-windows-vc14-x86-r805580d.zip
------------------------------------------------------------------------
[2016-10-04 17:28:08] cmb@php.net
According to a message on the OpenLDAP mailing list[1]:
> Also, this [%SYSCONFDIR%) is not an environment variable (you're
> on the unfortunate platform that makes this non-obvious), but a
> macro which should be replaced at 'make install' time.
So if there's %SYSCONFDIR% in the PHP binaries, there might be a
build problem.
Anyhow, setting the environment variable LDAPCONF should solve the
problem[2].
[1] <http://www.openldap.org/lists/openldap-software/200706/msg00121.html>
[2] <http://www.openldap.org/software/man.cgi?query=ldap.conf>
------------------------------------------------------------------------
[2016-10-04 16:31:46] ab@php.net
Thanks for the report. Could you please link to the exact place you've spotted? The PHP
dependencies use same patch as before, see https://github.com/winlibs/openldap/blob/master/include/ldap_config.h#L57
. Otherwise it looks same as #70971 which was turned to the doc issue, still not closed.
Thanks.
------------------------------------------------------------------------
[2016-10-04 14:48:56] petr dot maly at remotehost dot cz
Description:
------------
I have just migrated from PHP 5.6 to PHP 7 and I am unable to connect to LDAP server using SSL. I am
using openldap configuration, which was placed at C:\openldap\sysconf\ldap.conf, to set trustworthy
CA (PHP 5.6). This configuration file is ignored in PHP 7.
I have been inspecting php_ldap.dll binaries and I have discovered that, in php 7 was the original
hardcoded constant 'c:\openldap\sysconf\ldap.conf' replaced with
'%SYSCONFDIR%\ldap.conf'. I have tried to set SYSCONFDIR environment variable, but it is
not interpreted by the extension.
Could you fix the problem with loading of configuration file, please ?
Thanks,
Petr Maly
PS: Drew is facing the same problem:
http://stackoverflow.com/questions/35018674/php-ldap-connect-using-ldaps-to-connect-to-active-directory-getting-unknown-ca-e
Test script:
---------------
<?php
$a = ldap_connect("ldaps://adrien:636");
ldap_set_option($a, LDAP_OPT_NETWORK_TIMEOUT, 5);
ldap_set_option($a, LDAP_OPT_PROTOCOL_VERSION, 3); // v3 = UTF8 encoding
ldap_set_option($a, LDAP_OPT_REFERRALS, 0);
$r=ldap_bind($a);
echo "-$r-";
Expected result:
----------------
-1-
Actual result:
--------------
PHP Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in
C:\Temp\ldap\test.php on line 9
--
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1