Bug #69574 [Csd]: ldap connection timeouts not enforced

From: Date: Thu, 11 Aug 2022 19:40:56 +0000
Subject: Bug #69574 [Csd]: ldap connection timeouts not enforced
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242183@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69574&edit=1

 ID:                 69574
 Updated by:         heiglandreas@php.net
 Reported by:        ryan dot brothers at gmail dot com
 Summary:            ldap connection timeouts not enforced
 Status:             Closed
 Type:               Bug
 Package:            LDAP related
 Operating System:   Linux
 PHP Version:        5.6.8
 Assigned To:        mcmic
 Block user comment: N
 Private report:     N

 New Comment:

As ldap_connect doesn't actually "connect", the logic is quite flawed here as the
first command actually connecting to the server in the example is the ldap_bind.

But in the end that's nitpicking. The TIMEOUT needs to be set before the ldap_connect, so the
ldap_set_option gets NULL as connection parameter.


Previous Comments:
------------------------------------------------------------------------
[2022-08-11 18:38:16] requinix@php.net

Connection timeouts must be set before connecting. Set LDAP_OPT_NETWORK_TIMEOUT globally before
calling ldap_connect() by passing null in place of a connection.


ldap_set_option(null, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_connect('127.0.0.1:1234');


Meanwhile ldap_bind() is something else.

------------------------------------------------------------------------
[2022-08-11 18:10:10] tanjh58 at hotmail dot com

This doesn't work for ldaps protocol. Here is my code: 

<?php
$ldap = ldap_connect('ldaps://127.0.0.1:636');

ldap_set_option($ldap, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMELIMIT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMEOUT, 3);

ldap_bind($ldap);
?>

This never timeout.

------------------------------------------------------------------------
[2015-09-10 10:00:43] mcmic@php.net

The fix for this bug has been committed.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.

 For Windows:

http://windows.php.net/snapshots/
 
Thank you for the report, and for helping us make PHP better.

I added support for LDAP_OPT_TIMEOUT, please check that it fixes your problem.

------------------------------------------------------------------------
[2015-09-09 15:24:21] mcmic@php.net

Ok, so the problem is:

LDAP_OPT_TIMELIMIT is only for searches, not bind operations
LDAP_OPT_NETWORK_TIMEOUT is for socket level timeout, in your test there is no such thing as the nc
is indeed listening on the socket.

What you need is LDAP_OPT_TIMEOUT from openldap, which is not available yet in PHP.
So I’m gonna add this to php-ldap as it seems usefull.

------------------------------------------------------------------------
[2015-09-09 13:51:38] mcmic@php.net

Ok, got it, I had to do «nc -l -p 1234» instead of «nc -l 1234».
I can reproduce the bug.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69574


--
Edit this bug report at https://bugs.php.net/bug.php?id=69574&edit=1


Thread (12 messages)

« previous php.bugs (#242183) next »