Bug #73558 [Asn->Opn]: LDAP_OPT_X_TLS_CACERTFILE silently ignored
Edit report at https://bugs.php.net/bug.php?id=73558&edit=1
ID: 73558
Updated by: cmb@php.net
Reported by: jmaguire at duo dot com
Summary: LDAP_OPT_X_TLS_CACERTFILE silently ignored
-Status: Assigned
+Status: Open
Type: Bug
Package: LDAP related
Operating System: Linux
PHP Version: 7.1.0RC6
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thanks for the quick feedback!
Previous Comments:
------------------------------------------------------------------------
[2016-11-18 14:51:20] jmaguire at duo dot com
root@1bee5dfaf619:/# php71 -i | grep '^ldap$' -A10
ldap
LDAP Support => enabled
RCS Version => $Id: 0f82354ac9a0aaea23809d237e9f75e99b647142 $
Total Links => 0/unlimited
API Version => 3001
Vendor Name => OpenLDAP
Vendor Version => 20442
Directive => Local Value => Master Value
ldap.max_links => Unlimited => Unlimited
------------------------------------------------------------------------
[2016-11-18 10:42:19] cmb@php.net
Form looking at the sources[1], LDAP_OPT_X_TLS_CACERTFILE is only
supported for LDAP_API_VERSION > 2000.
Which API version does phpinfo() report for you?
[1] <https://github.com/php/php-src/blob/php-7.1.0RC6/ext/ldap/ldap.c#L2238-L2245>
------------------------------------------------------------------------
[2016-11-17 21:23:21] jmaguire at duo dot com
Description:
------------
New in PHP 7.1, LDAP_OPT_X_TLS_CACERTFILE should allow you to specify a CA certificate for an LDAP
connection. However, this setting is silently ignored in lieu of the global system LDAP settings.
Test script:
---------------
<?php
$conn = ldap_connect("ldaps://svr-dc01.acme.local", 389);
var_dump($conn);
ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE, '/var/www/html/cert/ldap/acme_ad.crt');
ldap_start_tls($conn);
$ldap_bind = ldap_bind($conn, 'acme\\administrator', 'password');
var_dump($ldap_bind);
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(false)
// root@7a4887b9f003:~# cp /var/www/html/cert/ldap/acme_ad.crt /var/www/html/cert/ldap/active.crt
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(true)
//
// root@7a4887b9f003:~# cat /etc/ldap/ldap.conf
// TLS_CACERT /var/www/html/cert/ldap/active.crt
Expected result:
----------------
I expect to receive "bool(true)" in both results, as the LDAP certificate used should be
/var/www/html/cert/ldap/acme_ad.crt.
Actual result:
--------------
I receive "bool(false)" in the first result because the LDAP certificate
"/var/www/html/cert/ldap/active.crt" (set in /etc/ldap/ldap.conf) is being used instead --
as such, if the cert is copied to that path, I receive "bool(true)"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73558&edit=1
Thread (10 messages)