Bug #73558 [NEW]: LDAP_OPT_X_TLS_CACERTFILE silently ignored
| From: | jmaguire at duo dot com | Date: | Thu, 17 Nov 2016 21:23:24 +0000 |
| Subject: | Bug #73558 [NEW]: LDAP_OPT_X_TLS_CACERTFILE silently ignored | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205438@lists.php.net to get a copy of this message | ||
From: jmaguire at duo dot com
Operating system: Linux
PHP version: 7.1.0RC6
Package: LDAP related
Bug Type: Bug
Bug description:LDAP_OPT_X_TLS_CACERTFILE silently ignored
Description:
------------
New in PHP 7.1, LDAP_OPT_X_TLS_CACERTFILE should allow you to specify a
CA certificate for an LDAP connection. However, this setting is silently
ignored in lieu of the global system LDAP settings.
Test script:
---------------
<?php
$conn = ldap_connect("ldaps://svr-dc01.acme.local", 389);
var_dump($conn);
ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE,
'/var/www/html/cert/ldap/acme_ad.crt');
ldap_start_tls($conn);
$ldap_bind = ldap_bind($conn, 'acme\\administrator', 'password');
var_dump($ldap_bind);
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(false)
// root@7a4887b9f003:~# cp /var/www/html/cert/ldap/acme_ad.crt
/var/www/html/cert/ldap/active.crt
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(true)
//
// root@7a4887b9f003:~# cat /etc/ldap/ldap.conf
// TLS_CACERT /var/www/html/cert/ldap/active.crt
Expected result:
----------------
I expect to receive "bool(true)" in both results, as the LDAP
certificate used should be /var/www/html/cert/ldap/acme_ad.crt.
Actual result:
--------------
I receive "bool(false)" in the first result because the LDAP certificate
"/var/www/html/cert/ldap/active.crt" (set in /etc/ldap/ldap.conf) is
being used instead -- as such, if the cert is copied to that path, I
receive "bool(true)"
--
Edit bug report at https://bugs.php.net/bug.php?id=73558&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73558&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73558&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73558&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73558&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73558&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73558&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73558&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73558&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73558&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73558&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73558&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73558&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73558&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73558&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73558&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73558&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73558&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73558&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73558&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73558&r=mysqlcfg