Bug #78029 [NEW]: ldap_set_option doesn't always set TLS options.
| From: | will dot skates at ntlworld dot com | Date: | Fri, 17 May 2019 16:43:23 +0000 |
| Subject: | Bug #78029 [NEW]: ldap_set_option doesn't always set TLS options. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-220887@lists.php.net to get a copy of this message | ||
From: will dot skates at ntlworld dot com
Operating system: Linux
PHP version: 7.2.18
Package: LDAP related
Bug Type: Bug
Bug description:ldap_set_option doesn't always set TLS options.
Description:
------------
"ldap_set_option" doesn't behave predictably when you set TLS options.
The tests for the extension (*1) _seem_ to suggest that it should just
because they pass the resource as the first option.
The TLS context is established the first time an ldap connection is
bound (2 & 3). I think that means that if I want to change my TLS
settings I have to restart php-fpm and hope I'm the first one to
ldap_bind on the box.
[1]:
https://github.com/php/php-src/blob/master/ext/ldap/tests/ldap_set_option_cafiles_basic.phpt
[2]:
https://github.com/openldap/openldap/blob/b06f5b0493937fc28f2cc86df1d7f464aa4504d8/libraries/libldap/open.c#L193
[3]:
https://github.com/openldap/openldap/blob/b06f5b0493937fc28f2cc86df1d7f464aa4504d8/libraries/libldap/tls2.c#L368
I'm running the two scripts using "php -S" and navigating to test1.php
and test2.php respectively.
I'm not sure what the ideal solution is. OpenLDAP does provide the
LDAP_OPT_X_TLS_NEWCTX and LDAP_OPT_X_TLS_CTX options to help deal with
this but they both seem to alter the global scope around the function.
The problem is just that I can't rely on "ldap_set_option" to actually
do what I tell it to. It might be better to create a new TLS context for
every connection as it gets bound so that OpenLDAP doesn't override it
with the global state.
This is true if I bind using ldaps:// or StartTLS.
For testing I have slapd (2.4.47) running in a container and have
generated my own CA, Client and Server certificates.
My LDAP extension info:
ldap
LDAP Support => enabled
RCS Version => $Id: 3839f871a91c293a52322c63329c68db23a0290a $
Total Links => 0/unlimited
API Version => 3001
Vendor Name => OpenLDAP
Vendor Version => 20446
SASL Support => Enabled
Directive => Local Value => Master Value
ldap.max_links => Unlimited => Unlimited
Test script:
---------------
https://pastebin.com/n1HUjCwD
Expected result:
----------------
NULL
NULL
Actual result:
--------------
NULL
string(131) "error:1416F086:SSL
routines:tls_process_server_certificate:certificate verify failed (self
signed certificate in certificate chain)"
--
Edit bug report at https://bugs.php.net/bug.php?id=78029&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=78029&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=78029&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=78029&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=78029&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78029&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78029&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78029&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78029&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78029&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78029&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78029&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78029&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78029&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=78029&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=78029&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78029&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78029&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78029&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78029&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78029&r=mysqlcfg