Bug #62195 [Com]: NTLM authentication of current user on different host fails
| From: | alexanderlutsky at gmail dot com | Date: | Fri, 06 Jul 2018 15:14:42 +0000 |
| Subject: | Bug #62195 [Com]: NTLM authentication of current user on different host fails | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216178@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62195&edit=1
ID: 62195
Comment by: alexanderlutsky at gmail dot com
Reported by: a dot schilder at gmx dot de
Summary: NTLM authentication of current user on different
host fails
Status: Not a bug
Type: Bug
Package: cURL related
Operating System: Windows Server 2008R2
PHP Version: 5.4.3
Block user comment: N
Private report: N
New Comment:
Still experiencing this in PHP 7.1.7, cURL version 7.54.1
When I explicitly specify my own username and password (which are the same for both source and
destination servers) under CURLOPT_USERPWD it works perfectly, but with just ":" -
authentication fails, error 401
The code is as follows:
...
function file_get_contents_curl($url) {
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, $url);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($curl, CURLOPT_HTTPAUTH, CURLAUTH_NTLM);
curl_setopt($curl, CURLOPT_UNRESTRICTED_AUTH, TRUE);
curl_setopt($curl, CURLOPT_USERPWD, ":");
$data = curl_exec($curl);
curl_close($curl);
return $data;
}
...
Can you please advise?
Previous Comments:
------------------------------------------------------------------------
[2014-04-25 09:37:09] mike@php.net
man curl_easy_setopt says:
"libcurl will only send this user and password information to hosts using the initial host name
(unless CURLOPT_UNRESTRICTED_AUTH is set)"
Did you try CURLOPT_UNRESTRICTED_AUTH?
------------------------------------------------------------------------
[2012-06-11 13:22:55] a dot schilder at gmx dot de
Typo in summary corrected
------------------------------------------------------------------------
[2012-05-31 10:15:50] a dot schilder at gmx dot de
Description:
------------
A request with NTML authentication using the current, authenticated user (CURLOPT_USERPWD
":") doesn't work, when doing a request to another host in the same domain. Settings
the same credentials directly for CURLOPT_USERPWD works as expected.
Test script:
---------------
Script on "server1.domainXYZ", user already authenicated.
Curl requests to "server1.domainXYZ" and "server2.domainXYZ".
Version 1 (Server 1, explicitly setting the credentials of the current user):
...
curl_setopt($ch, CURLOPT_URL, 'http://server1.domainXYZ/file.php');
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, "domainXYZ\\userX:passwordY");
...
Version 2 (Server 1, using current user):
...
curl_setopt($ch, CURLOPT_URL, 'http://server1.domainXYZ/file.php');
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, ":");
...
Version 3 (Server 2, explicitly setting the credentials of the current user):
...
curl_setopt($ch, CURLOPT_URL, 'http://server2.domainXYZ/file.php');
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, "domainXYZ\\userX:passwordY");
...
Version 4 (Server 2, using current user):
...
curl_setopt($ch, CURLOPT_URL, 'http://server2.domainXYZ/file.php');
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, ":");
...
Expected result:
----------------
Version 1: works
Version 2: works
Version 3: works
Version 4: works
Actual result:
--------------
Version 1: works
Version 2: works
Version 3: works
Version 4: doesn't work
In Version 1-3 the user name is correctly sent and logged in the IIS logs ("cs-username").
In Version 4, the user name in the IIS logs is empty ("-"), so no user name is sent by
cURL.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62195&edit=1