Bug #73558 [Opn->Fbk]: LDAP_OPT_X_TLS_CACERTFILE silently ignored
Edit report at https://bugs.php.net/bug.php?id=73558&edit=1
ID: 73558
Updated by: cmb@php.net
Reported by: jmaguire at duo dot com
Summary: LDAP_OPT_X_TLS_CACERTFILE silently ignored
-Status: Open
+Status: Feedback
Type: Bug
Package: LDAP related
Operating System: Linux
PHP Version: 7.1.0RC6
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Form looking at the sources[1], LDAP_OPT_X_TLS_CACERTFILE is only
supported for LDAP_API_VERSION > 2000.
Which API version does phpinfo() report for you?
[1] <https://github.com/php/php-src/blob/php-7.1.0RC6/ext/ldap/ldap.c#L2238-L2245>
Previous Comments:
------------------------------------------------------------------------
[2016-11-17 21:23:21] jmaguire at duo dot com
Description:
------------
New in PHP 7.1, LDAP_OPT_X_TLS_CACERTFILE should allow you to specify a CA certificate for an LDAP
connection. However, this setting is silently ignored in lieu of the global system LDAP settings.
Test script:
---------------
<?php
$conn = ldap_connect("ldaps://svr-dc01.acme.local", 389);
var_dump($conn);
ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE, '/var/www/html/cert/ldap/acme_ad.crt');
ldap_start_tls($conn);
$ldap_bind = ldap_bind($conn, 'acme\\administrator', 'password');
var_dump($ldap_bind);
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(false)
// root@7a4887b9f003:~# cp /var/www/html/cert/ldap/acme_ad.crt /var/www/html/cert/ldap/active.crt
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(true)
//
// root@7a4887b9f003:~# cat /etc/ldap/ldap.conf
// TLS_CACERT /var/www/html/cert/ldap/active.crt
Expected result:
----------------
I expect to receive "bool(true)" in both results, as the LDAP certificate used should be
/var/www/html/cert/ldap/acme_ad.crt.
Actual result:
--------------
I receive "bool(false)" in the first result because the LDAP certificate
"/var/www/html/cert/ldap/active.crt" (set in /etc/ldap/ldap.conf) is being used instead --
as such, if the cert is copied to that path, I receive "bool(true)"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73558&edit=1
Thread (10 messages)