Edit report at https://bugs.php.net/bug.php?id=73243&edit=1
ID: 73243
Updated by: ab@php.net
Reported by: petr dot maly at remotehost dot cz
Summary: Unable to configure trusted CA
-Status: Assigned
+Status: Feedback
Type: Bug
Package: LDAP related
Operating System: Windows 10 x86
PHP Version: 7.0.11
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Good. Which exact PHP and OpenSSL versions do you use? Please note, that recent OpenSSL versions
strengthened the behaviors by disabling many weak algorithms. It might be good the case as PHP ships
default OpenSSL builds, but could also be something on the server side.
Otherwise, I'd ask you to please provide your ldap.conf and a test server, so I could debug. If
you can't reveal your server, please point me to any public server that can reproduce the
issue.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2016-10-06 10:29:05] petr dot maly at remotehost dot cz
I have verified that the binary, you have provided to me, is reading the proper configuration file
(c:\openldsp\sysconf\ldap.conf). However as I write in previous comment, the SSL handshake is not
initiated. The configuration ldap.conf should be correct (it is working with PHP 5.6).
Thanks,
Petr
------------------------------------------------------------------------
[2016-10-05 15:07:24] ab@php.net
Thanks for checking. The issue you've reported is, that the file C:\openldap\sysconf\ldap.conf
doesn't get read in with x86 build. This is indeed due to an erroneous dependency build and
will be fixed in future releases. The extra build I made for you uses the corrected dependency, so
the config file is read in. Please verify with procmon (here https://technet.microsoft.com/de-de/sysinternals/processmonitor.aspx).
With the file read in, it is up to the actual ldap.conf what to do with SSL and other things.
Thanks.
------------------------------------------------------------------------
[2016-10-05 14:40:11] petr dot maly at remotehost dot cz
I have tried the provided library, but it is not working. I have connected to LDAP server using the
original path for the configuration (c:\openldap\sysconf\ldap.conf) and the SSL was not even
initiated. The initial SSL handshake packet was not sent by client (php_ldap.dll).
If you are interested in wireshark captures I can provide it to you.
Thanks,
Petr
------------------------------------------------------------------------
[2016-10-05 14:13:46] ab@php.net
Thanks Christoph, you nailed it. My bad paying more attention to 64-bit builds :) Seems bug #70971
is about same issue, whereby it was not obvious it's 32-bit only.
@petr dot maly at remotehost dot cz, please check whether this build is correct http://windows.php.net/downloads/snaps/ostc/73243/vc14/7.0/x86/nts/php_ldap.dll
Thanks.
------------------------------------------------------------------------
[2016-10-05 09:18:52] cmb@php.net
There appears to be a bad build of oldap32_a(_debug).lib. In
deps-7.1-vc14-x64.7z (2016-09-26) the lib contains
c:\openldap\sysconf\ldap.conf, in deps-7.1-vc14-x86.7z
(2016-09.26) it contains %SYSCONFDIR%\ldap.conf. If I build from
winlibs/openldap, in both x86 and x64 %SYSCONFDIR% is resolved.
Anatol, can you please have a look at this issue.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73243
--
Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1