Bug #73243 [Asn->Fbk]: Unable to configure trusted CA

From: Date: Thu, 06 Oct 2016 20:49:11 +0000
Subject: Bug #73243 [Asn->Fbk]: Unable to configure trusted CA
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204519@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73243&edit=1

 ID:                 73243
 Updated by:         ab@php.net
 Reported by:        petr dot maly at remotehost dot cz
 Summary:            Unable to configure trusted CA
-Status:             Assigned
+Status:             Feedback
 Type:               Bug
 Package:            LDAP related
 Operating System:   Windows 10 x86
 PHP Version:        7.0.11
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for the additional info and investigation. Now i reproduce this, indeed your snippet works on
PHP5 and doesn't in PHP7. Using ldaps://ldap.telesec.de and "TLS_REQCERT never" in
the ldap.conf

Please tell how you built openldap in the worky variant? Did you enable deprecated symbols? Which
solutions and patches did you use? In the winlibs repo, we use own VS solutions, the patch is
commited in there as well.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2016-10-06 12:53:04] petr dot maly at remotehost dot cz

I have already faced all the problems with OpenSSL in other open source projects and many different
embedded devices (because of security issues) and I can say that it is the hell. Nevertheless I use
OpenSSL 1.0.2h, which is deployed together with [2].

I tried to compile php_ldap.dll few moments ago. First of all I built it from original OpenLdap
sources (with few patches including the path to ldap.conf) and I was successfull to compile it
together with [1]. Produced binary php_ldap.dll worked (read c:\openldap\sysconf\ldap.conf and was
communicating correctly). 

Second time I compiled OpenLdap using your sources in GIT (link above). I produced openldap libs and
compiled it with php [1]. I tested final binary php_ldap.dll, and it did not worked, the
configuration was read, but it was not communicating - handshake was not initated.

I was compiling using PHP-SDK downloaded from [3]. However I thought that I would not have to touch
the content of these dependencies, but I had to. I had to updat OpenSSL to 1.0.2h and I noticed that
the old includes for openldap are used in that packages (different from your openldap sources) :-(. 

I have tested the plugin using php script from the first comment with the public
"ldaps://ldap.telesec.de" ldap server (I am testing 'ldaps' all the time, not
'ldap'). And ldap.conf contain only "TLS_REQCERT never". 

Thanks,
Petr

[1] http://windows.php.net/downloads/releases/php-7.0.11-src.zip
[2] http://windows.php.net/downloads/releases/php-7.0.11-nts-Win32-VC14-x86.zip
[3] http://windows.php.net/downloads/php-sdk/deps-7.0-vc14-x86.7z

------------------------------------------------------------------------
[2016-10-06 11:23:49] ab@php.net

Good. Which exact PHP and OpenSSL versions do you use? Please note, that recent OpenSSL versions
strengthened the behaviors by disabling many weak algorithms. It might be good the case as PHP ships
default OpenSSL builds, but could also be something on the server side.

Otherwise, I'd ask you to please provide your ldap.conf and a test server, so I could debug. If
you can't reveal your server, please point me to any public server that can reproduce the
issue.

Thanks.

------------------------------------------------------------------------
[2016-10-06 10:29:05] petr dot maly at remotehost dot cz

I have verified that the binary, you have provided to me, is reading the proper configuration file
(c:\openldsp\sysconf\ldap.conf). However as I write in previous comment, the SSL handshake is not
initiated. The configuration ldap.conf should be correct (it is working with PHP 5.6).

Thanks,
Petr

------------------------------------------------------------------------
[2016-10-05 15:07:24] ab@php.net

Thanks for checking. The issue you've reported is, that the file C:\openldap\sysconf\ldap.conf
doesn't get read in with x86 build. This is indeed due to an erroneous dependency build and
will be fixed in future releases. The extra build I made for you uses the corrected dependency, so
the config file is read in. Please verify with procmon (here https://technet.microsoft.com/de-de/sysinternals/processmonitor.aspx).
With the file read in, it is up to the actual ldap.conf what to do with SSL and other things.

Thanks.

------------------------------------------------------------------------
[2016-10-05 14:40:11] petr dot maly at remotehost dot cz

I have tried the provided library, but it is not working. I have connected to LDAP server using the
original path for the configuration (c:\openldap\sysconf\ldap.conf) and the SSL was not even
initiated. The initial SSL handshake packet was not sent by client (php_ldap.dll). 

If you are interested in wireshark captures I can provide it to you.

Thanks, 

Petr

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73243


--
Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1


Thread (18 messages)

« previous php.bugs (#204519) next »