Bug #73558 [Asn->Opn]: LDAP_OPT_X_TLS_CACERTFILE silently ignored

From: Date: Fri, 18 Nov 2016 15:19:13 +0000
Subject: Bug #73558 [Asn->Opn]: LDAP_OPT_X_TLS_CACERTFILE silently ignored
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205463@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73558&edit=1

 ID:                 73558
 Updated by:         cmb@php.net
 Reported by:        jmaguire at duo dot com
 Summary:            LDAP_OPT_X_TLS_CACERTFILE silently ignored
-Status:             Assigned
+Status:             Open
 Type:               Bug
 Package:            LDAP related
 Operating System:   Linux
 PHP Version:        7.1.0RC6
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for the quick feedback!


Previous Comments:
------------------------------------------------------------------------
[2016-11-18 14:51:20] jmaguire at duo dot com

root@1bee5dfaf619:/# php71 -i | grep '^ldap$' -A10
ldap

LDAP Support => enabled
RCS Version => $Id: 0f82354ac9a0aaea23809d237e9f75e99b647142 $
Total Links => 0/unlimited
API Version => 3001
Vendor Name => OpenLDAP
Vendor Version => 20442

Directive => Local Value => Master Value
ldap.max_links => Unlimited => Unlimited

------------------------------------------------------------------------
[2016-11-18 10:42:19] cmb@php.net

Form looking at the sources[1], LDAP_OPT_X_TLS_CACERTFILE is only
supported for LDAP_API_VERSION > 2000.

Which API version does phpinfo() report for you?

[1] <https://github.com/php/php-src/blob/php-7.1.0RC6/ext/ldap/ldap.c#L2238-L2245>

------------------------------------------------------------------------
[2016-11-17 21:23:21] jmaguire at duo dot com

Description:
------------
New in PHP 7.1, LDAP_OPT_X_TLS_CACERTFILE should allow you to specify a CA certificate for an LDAP
connection. However, this setting is silently ignored in lieu of the global system LDAP settings.

Test script:
---------------
<?php

$conn = ldap_connect("ldaps://svr-dc01.acme.local", 389);
var_dump($conn);
ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE, '/var/www/html/cert/ldap/acme_ad.crt');
ldap_start_tls($conn);
$ldap_bind = ldap_bind($conn, 'acme\\administrator', 'password');
var_dump($ldap_bind);

// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(false)

// root@7a4887b9f003:~# cp /var/www/html/cert/ldap/acme_ad.crt /var/www/html/cert/ldap/active.crt
// root@7a4887b9f003:~# php ldap.php
// resource(4) of type (ldap link)
// bool(true)
//
// root@7a4887b9f003:~# cat /etc/ldap/ldap.conf
// TLS_CACERT /var/www/html/cert/ldap/active.crt

Expected result:
----------------
I expect to receive "bool(true)" in both results, as the LDAP certificate used should be
/var/www/html/cert/ldap/acme_ad.crt.

Actual result:
--------------
I receive "bool(false)" in the first result because the LDAP certificate
"/var/www/html/cert/ldap/active.crt" (set in /etc/ldap/ldap.conf) is being used instead --
as such, if the cert is copied to that path, I receive "bool(true)"


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73558&edit=1


Thread (10 messages)

« previous php.bugs (#205463) next »