Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory

From: Date: Tue, 05 Nov 2019 14:04:56 +0000
Subject: Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223576@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66724&edit=1

 ID:                 66724
 Comment by:         ckd159 at gmail dot com
 Reported by:        post at rolandgruber dot de
 Summary:            ldap_get_entries does not escape DN values on Active
                     Directory
 Status:             Assigned
 Type:               Bug
 Package:            LDAP related
 Operating System:   Debian Linux
 PHP Version:        5.4.25
 Assigned To:        heiglandreas
 Block user comment: N
 Private report:     N

 New Comment:

I use ADSI Edit and ldapsearch to access AD and LDS.
cn = sn, givenname
dn = CN=sn\, givenname,OU=..,DC=..


Previous Comments:
------------------------------------------------------------------------
[2019-10-31 19:36:05] post at rolandgruber dot de

This is still an issue. In addition, using the "cn=foo\, bar,dc=test" that comes back in
Active Directory case does not work for ldap_read(). Active Directory expects the comma to be
escaped as "\2C".

------------------------------------------------------------------------
[2017-01-27 17:44:13] post at rolandgruber dot de

True, on PHP 7 it is "ou=foo\2C bar,ou=test,o=test,c=de" for OpenLDAP.

------------------------------------------------------------------------
[2017-01-22 15:22:01] heiglandreas@php.net

The DN should contain EITHER '\,' OR '\2C' but NOT '\5C\2C'. IMO that
means that the value in the CN-Attribute already contains '\,' and not a simple
','. Can you please check that? 

Additionally I checked that against a third LDAP-Server:

$ldap = ldap_connect('ldap://pksldap.tttc.de');
ldap_bind($ldap);
$result = ldap_search($ldap, 'c=DE', 'sn=Jahneke');
$res = ldap_get_entries($ldap, $result);
var_Dump($res[0]['dn']);
//string(101) "cn=Jahneke\2C Ralf- ChristophSER:799945522,ou=T-TeleSec SigG Test CA
15:PN,o=Deutsche Telekom AG,c=de"
var_Dump($res[0]['cn'][0]);
string(37) "Jahneke, Ralf- ChristophSER:799945522"

Could you run that agains your OpenLDAP and ActiveDirectory (with appropriately adapted
search-filter)? Thanks!

------------------------------------------------------------------------
[2017-01-22 15:21:58] heiglandreas@php.net

The DN should contain EITHER '\,' OR '\2C' but NOT '\5C\2C'. IMO that
means that the value in the CN-Attribute already contains '\,' and not a simple
','. Can you please check that? 

Additionally I checked that against a third LDAP-Server:

$ldap = ldap_connect('ldap://pksldap.tttc.de');
ldap_bind($ldap);
$result = ldap_search($ldap, 'c=DE', 'sn=Jahneke');
$res = ldap_get_entries($ldap, $result);
var_Dump($res[0]['dn']);
//string(101) "cn=Jahneke\2C Ralf- ChristophSER:799945522,ou=T-TeleSec SigG Test CA
15:PN,o=Deutsche Telekom AG,c=de"
var_Dump($res[0]['cn'][0]);
string(37) "Jahneke, Ralf- ChristophSER:799945522"

Could you run that agains your OpenLDAP and ActiveDirectory (with appropriately adapted
search-filter)? Thanks!

------------------------------------------------------------------------
[2017-01-22 08:53:35] post at rolandgruber dot de

I verified with PHP 7.0.12 against Windows 2012 and OpenLDAP 2.4.40

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66724


--
Edit this bug report at https://bugs.php.net/bug.php?id=66724&edit=1


Thread (12 messages)

« previous php.bugs (#223576) next »