Bug #73558 [NEW]: LDAP_OPT_X_TLS_CACERTFILE silently ignored

From: Date: Thu, 17 Nov 2016 21:23:24 +0000
Subject: Bug #73558 [NEW]: LDAP_OPT_X_TLS_CACERTFILE silently ignored
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205438@lists.php.net to get a copy of this message
From: jmaguire at duo dot com Operating system: Linux PHP version: 7.1.0RC6 Package: LDAP related Bug Type: Bug Bug description:LDAP_OPT_X_TLS_CACERTFILE silently ignored Description: ------------ New in PHP 7.1, LDAP_OPT_X_TLS_CACERTFILE should allow you to specify a CA certificate for an LDAP connection. However, this setting is silently ignored in lieu of the global system LDAP settings. Test script: --------------- <?php $conn = ldap_connect("ldaps://svr-dc01.acme.local", 389); var_dump($conn); ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE, '/var/www/html/cert/ldap/acme_ad.crt'); ldap_start_tls($conn); $ldap_bind = ldap_bind($conn, 'acme\\administrator', 'password'); var_dump($ldap_bind); // root@7a4887b9f003:~# php ldap.php // resource(4) of type (ldap link) // bool(false) // root@7a4887b9f003:~# cp /var/www/html/cert/ldap/acme_ad.crt /var/www/html/cert/ldap/active.crt // root@7a4887b9f003:~# php ldap.php // resource(4) of type (ldap link) // bool(true) // // root@7a4887b9f003:~# cat /etc/ldap/ldap.conf // TLS_CACERT /var/www/html/cert/ldap/active.crt Expected result: ---------------- I expect to receive "bool(true)" in both results, as the LDAP certificate used should be /var/www/html/cert/ldap/acme_ad.crt. Actual result: -------------- I receive "bool(false)" in the first result because the LDAP certificate "/var/www/html/cert/ldap/active.crt" (set in /etc/ldap/ldap.conf) is being used instead -- as such, if the cert is copied to that path, I receive "bool(true)" -- Edit bug report at https://bugs.php.net/bug.php?id=73558&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73558&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73558&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73558&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73558&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73558&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73558&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73558&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73558&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73558&r=support Expected behavior: https://bugs.php.net/fix.php?id=73558&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73558&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73558&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73558&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73558&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73558&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73558&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73558&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73558&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73558&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73558&r=mysqlcfg

« previous php.bugs (#205438) next »