Edit report at https://bugs.php.net/bug.php?id=73243&edit=1
ID: 73243
User updated by: petr dot maly at remotehost dot cz
Reported by: petr dot maly at remotehost dot cz
Summary: Unable to configure trusted CA
Status: Closed
Type: Bug
Package: LDAP related
Operating System: Windows 10 x86
PHP Version: 7.0.11
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
I have just checked the new binaries and recompiled the extension and it is working :-). Thanks a
lot.
Petr
PS:
A little bit outdated information about my build:
I used official openldap sources + windows makefile for VS [1] + few small patches to get working
with the newest VS. I checked your fix and macros of my build and it is same.
[1] https://github.com/mbooth101/openldap
Previous Comments:
------------------------------------------------------------------------
[2016-10-07 20:56:07] ab@php.net
This issue should be fixed now. I've retagged openldap-2.4.4 with an updated patch. You can
either use it or the prepared binaries
http://windows.php.net/downloads/php-sdk/deps/vc14/x64/openldap-2.4.44-vc14-x64.ziphttp://windows.php.net/downloads/php-sdk/deps/vc14/x86/openldap-2.4.44-vc14-x86.zip
The dependency packages will be updated anytime soon.
Thanks.
------------------------------------------------------------------------
[2016-10-06 20:49:08] ab@php.net
Thanks for the additional info and investigation. Now i reproduce this, indeed your snippet works on
PHP5 and doesn't in PHP7. Using ldaps://ldap.telesec.de and "TLS_REQCERT never" in
the ldap.conf
Please tell how you built openldap in the worky variant? Did you enable deprecated symbols? Which
solutions and patches did you use? In the winlibs repo, we use own VS solutions, the patch is
commited in there as well.
Thanks.
------------------------------------------------------------------------
[2016-10-06 12:53:04] petr dot maly at remotehost dot cz
I have already faced all the problems with OpenSSL in other open source projects and many different
embedded devices (because of security issues) and I can say that it is the hell. Nevertheless I use
OpenSSL 1.0.2h, which is deployed together with [2].
I tried to compile php_ldap.dll few moments ago. First of all I built it from original OpenLdap
sources (with few patches including the path to ldap.conf) and I was successfull to compile it
together with [1]. Produced binary php_ldap.dll worked (read c:\openldap\sysconf\ldap.conf and was
communicating correctly).
Second time I compiled OpenLdap using your sources in GIT (link above). I produced openldap libs and
compiled it with php [1]. I tested final binary php_ldap.dll, and it did not worked, the
configuration was read, but it was not communicating - handshake was not initated.
I was compiling using PHP-SDK downloaded from [3]. However I thought that I would not have to touch
the content of these dependencies, but I had to. I had to updat OpenSSL to 1.0.2h and I noticed that
the old includes for openldap are used in that packages (different from your openldap sources) :-(.
I have tested the plugin using php script from the first comment with the public
"ldaps://ldap.telesec.de" ldap server (I am testing 'ldaps' all the time, not
'ldap'). And ldap.conf contain only "TLS_REQCERT never".
Thanks,
Petr
[1] http://windows.php.net/downloads/releases/php-7.0.11-src.zip
[2] http://windows.php.net/downloads/releases/php-7.0.11-nts-Win32-VC14-x86.zip
[3] http://windows.php.net/downloads/php-sdk/deps-7.0-vc14-x86.7z
------------------------------------------------------------------------
[2016-10-06 11:23:49] ab@php.net
Good. Which exact PHP and OpenSSL versions do you use? Please note, that recent OpenSSL versions
strengthened the behaviors by disabling many weak algorithms. It might be good the case as PHP ships
default OpenSSL builds, but could also be something on the server side.
Otherwise, I'd ask you to please provide your ldap.conf and a test server, so I could debug. If
you can't reveal your server, please point me to any public server that can reproduce the
issue.
Thanks.
------------------------------------------------------------------------
[2016-10-06 10:29:05] petr dot maly at remotehost dot cz
I have verified that the binary, you have provided to me, is reading the proper configuration file
(c:\openldsp\sysconf\ldap.conf). However as I write in previous comment, the SSL handshake is not
initiated. The configuration ldap.conf should be correct (it is working with PHP 5.6).
Thanks,
Petr
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73243
--
Edit this bug report at https://bugs.php.net/bug.php?id=73243&edit=1