Bug #73243 [Fbk->Asn]: Unable to configure trusted CA

From: Date: Thu, 06 Oct 2016 12:53:10 +0000
Subject: Bug #73243 [Fbk->Asn]: Unable to configure trusted CA
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204512@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73243&edit=1 ID: 73243 User updated by: petr dot maly at remotehost dot cz Reported by: petr dot maly at remotehost dot cz Summary: Unable to configure trusted CA -Status: Feedback +Status: Assigned Type: Bug Package: LDAP related Operating System: Windows 10 x86 PHP Version: 7.0.11 Assigned To: ab Block user comment: N Private report: N New Comment: I have already faced all the problems with OpenSSL in other open source projects and many different embedded devices (because of security issues) and I can say that it is the hell. Nevertheless I use OpenSSL 1.0.2h, which is deployed together with [2]. I tried to compile php_ldap.dll few moments ago. First of all I built it from original OpenLdap sources (with few patches including the path to ldap.conf) and I was successfull to compile it together with [1]. Produced binary php_ldap.dll worked (read c:\openldap\sysconf\ldap.conf and was communicating correctly). Second time I compiled OpenLdap using your sources in GIT (link above). I produced openldap libs and compiled it with php [1]. I tested final binary php_ldap.dll, and it did not worked, the configuration was read, but it was not communicating - handshake was not initated. I was compiling using PHP-SDK downloaded from [3]. However I thought that I would not have to touch the content of these dependencies, but I had to. I had to updat OpenSSL to 1.0.2h and I noticed that the old includes for openldap are used in that packages (different from your openldap sources) :-(. I have tested the plugin using php script from the first comment with the public "ldaps://ldap.telesec.de" ldap server (I am testing 'ldaps' all the time, not 'ldap'). And ldap.conf contain only "TLS_REQCERT never". Thanks, Petr [1] http://windows.php.net/downloads/releases/php-7.0.11-src.zip [2] http://windows.php.net/downloads/releases/php-7.0.11-nts-Win32-VC14-x86.zip [3] http://windows.php.net/downloads/php-sdk/deps-7.0-vc14-x86.7z Previous Comments: ------------------------------------------------------------------------ [2016-10-06 11:23:49] ab@php.net Good. Which exact PHP and OpenSSL versions do you use? Please note, that recent OpenSSL versions strengthened the behaviors by disabling many weak algorithms. It might be good the case as PHP ships default OpenSSL builds, but could also be something on the server side. Otherwise, I'd ask you to please provide your ldap.conf and a test server, so I could debug. If you can't reveal your server, please point me to any public server that can reproduce the issue. Thanks. ------------------------------------------------------------------------ [2016-10-06 10:29:05] petr dot maly at remotehost dot cz I have verified that the binary, you have provided to me, is reading the proper configuration file (c:\openldsp\sysconf\ldap.conf). However as I write in previous comment, the SSL handshake is not initiated. The configuration ldap.conf should be correct (it is working with PHP 5.6). Thanks, Petr ------------------------------------------------------------------------ [2016-10-05 15:07:24] ab@php.net Thanks for checking. The issue you've reported is, that the file C:\openldap\sysconf\ldap.conf doesn't get read in with x86 build. This is indeed due to an erroneous dependency build and will be fixed in future releases. The extra build I made for you uses the corrected dependency, so the config file is read in. Please verify with procmon (here https://technet.microsoft.com/de-de/sysinternals/processmonitor.aspx). With the file read in, it is up to the actual ldap.conf what to do with SSL and other things. Thanks. ------------------------------------------------------------------------ [2016-10-05 14:40:11] petr dot maly at remotehost dot cz I have tried the provided library, but it is not working. I have connected to LDAP server using the original path for the configuration (c:\openldap\sysconf\ldap.conf) and the SSL was not even initiated. The initial SSL handshake packet was not sent by client (php_ldap.dll). If you are interested in wireshark captures I can provide it to you. Thanks, Petr ------------------------------------------------------------------------ [2016-10-05 14:13:46] ab@php.net Thanks Christoph, you nailed it. My bad paying more attention to 64-bit builds :) Seems bug #70971 is about same issue, whereby it was not obvious it's 32-bit only. @petr dot maly at remotehost dot cz, please check whether this build is correct http://windows.php.net/downloads/snaps/ostc/73243/vc14/7.0/x86/nts/php_ldap.dll Thanks. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73243 -- Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1

« previous php.bugs (#204512) next »