Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory

From: Date: Wed, 11 Jan 2017 19:28:43 +0000
Subject: Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206538@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66724&edit=1

 ID:                 66724
 Comment by:         post at rolandgruber dot de
 Reported by:        post at rolandgruber dot de
 Summary:            ldap_get_entries does not escape DN values on Active
                     Directory
 Status:             Feedback
 Type:               Bug
 Package:            LDAP related
 Operating System:   Debian Linux
 PHP Version:        5.4.25
 Assigned To:        heiglandreas
 Block user comment: N
 Private report:     N

 New Comment:

Verified with PHP 7.0.12 against Windows 2012 and OpenLDAP 2.4.40


Previous Comments:
------------------------------------------------------------------------
[2017-01-10 07:58:54] heiglandreas@php.net

This issue targets an unsupported version of PHP. Is this still a reproducible issue? And if so,
what version of OpenLDAP and ActiveDirectory are involved in the test?

Thanks for your feedback!

------------------------------------------------------------------------
[2014-02-27 06:16:55] chrispmaiden at gmail dot com

I was hoping to test this but fell short, I found the OpenLDAP project host a public LDAP server
(http://www.openldap.org/faq/data/cache/1360.html) with the clause, "This service is often
unavailable for one reason or another." which I found to be the case.

Is anyone aware of alternative public LDAP servers to test against?

Failing that I'll set up instances locally.

Thanks.

------------------------------------------------------------------------
[2014-02-16 19:10:19] post at rolandgruber dot de

Description:
------------
A search with ldap_search() and then getting the entries with ldap_get_entries() returns different
search results on OpenLDAP and ActiveDirectory.

Example DN of a search result entry: cn=foo\, bar,dc=test

Active Directory: cn=foo\, bar,dc=test
OpenLDAP: cn=foo\5C\2C bar,dc=test

So for OpenLDAP special chars in the DN are escaped and for Active Directory they are not.



Expected result:
----------------
The returned DNs should be the same for all LDAP servers.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=66724&edit=1


Thread (12 messages)

« previous php.bugs (#206538) next »