Bug #78029 [Com]: ldap_set_option doesn't always set TLS options.
| From: | master dot training365 at gmail dot com | Date: | Fri, 11 Feb 2022 07:38:57 +0000 |
| Subject: | Bug #78029 [Com]: ldap_set_option doesn't always set TLS options. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-239624@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78029&edit=1
ID: 78029
Comment by: master dot training365 at gmail dot com
Reported by: will dot skates at ntlworld dot com
Summary: ldap_set_option doesn't always set TLS options.
Status: Open
Type: Bug
Package: LDAP related
Operating System: Linux
PHP Version: 7.2.18
Block user comment: N
Private report: N
New Comment:
https://pluto-mart.net/10-best-dainty-flowers/
https://pluto-mart.net/10-best-chewbacca-onesie/
https://pluto-mart.net/10-best-twin-lounger/
https://pluto-mart.net/10-best-green-roller-skates/
https://pluto-mart.net/10-best-light-mauve/
Previous Comments:
------------------------------------------------------------------------
[2022-02-11 07:38:05] master dot training365 at gmail dot com
https://pluto-mart.net/10-best-non-carbonated-energy-drinks/
https://pluto-mart.net/10-best-above-ground-pool-size-chart/
https://pluto-mart.net/10-best-snowshoe-poles/
https://pluto-mart.net/10-best-black-dresser-with-mirror/
https://pluto-mart.net/10-best-no-neck-meme/
------------------------------------------------------------------------
[2022-02-11 07:37:33] master dot training365 at gmail dot com
https://pluto-mart.net/10-best-corduroy-blazer-women/
https://pluto-mart.net/10-best-shearling-slides/
https://pluto-mart.net/10-best-blue-tie-dye/
https://pluto-mart.net/10-best-bandai-model-kits/
------------------------------------------------------------------------
[2021-07-26 13:26:14] cmb@php.net
Related To: Bug #73558
------------------------------------------------------------------------
[2019-05-17 16:43:22] will dot skates at ntlworld dot com
Description:
------------
"ldap_set_option" doesn't behave predictably when you set TLS options. The tests for
the extension (*1) _seem_ to suggest that it should just because they pass the resource as the first
option.
The TLS context is established the first time an ldap connection is bound (2 & 3). I think that
means that if I want to change my TLS settings I have to restart php-fpm and hope I'm the first
one to ldap_bind on the box.
[1]: https://github.com/php/php-src/blob/master/ext/ldap/tests/ldap_set_option_cafiles_basic.phpt
[2]: https://github.com/openldap/openldap/blob/b06f5b0493937fc28f2cc86df1d7f464aa4504d8/libraries/libldap/open.c#L193
[3]: https://github.com/openldap/openldap/blob/b06f5b0493937fc28f2cc86df1d7f464aa4504d8/libraries/libldap/tls2.c#L368
I'm running the two scripts using "php -S" and navigating to test1.php and test2.php
respectively.
I'm not sure what the ideal solution is. OpenLDAP does provide the LDAP_OPT_X_TLS_NEWCTX and
LDAP_OPT_X_TLS_CTX options to help deal with this but they both seem to alter the global scope
around the function. The problem is just that I can't rely on "ldap_set_option" to
actually do what I tell it to. It might be better to create a new TLS context for every connection
as it gets bound so that OpenLDAP doesn't override it with the global state.
This is true if I bind using ldaps:// or StartTLS.
For testing I have slapd (2.4.47) running in a container and have generated my own CA, Client and
Server certificates.
My LDAP extension info:
ldap
LDAP Support => enabled
RCS Version => $Id: 3839f871a91c293a52322c63329c68db23a0290a $
Total Links => 0/unlimited
API Version => 3001
Vendor Name => OpenLDAP
Vendor Version => 20446
SASL Support => Enabled
Directive => Local Value => Master Value
ldap.max_links => Unlimited => Unlimited
Test script:
---------------
https://pastebin.com/n1HUjCwD
Expected result:
----------------
NULL
NULL
Actual result:
--------------
NULL
string(131) "error:1416F086:SSL routines:tls_process_server_certificate:certificate verify
failed (self signed certificate in certificate chain)"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78029&edit=1