Bug #69574 [Com]: ldap connection timeouts not enforced
| From: | tanjh58 at hotmail dot com | Date: | Fri, 12 Aug 2022 03:04:56 +0000 |
| Subject: | Bug #69574 [Com]: ldap connection timeouts not enforced | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-242188@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69574&edit=1
ID: 69574
Comment by: tanjh58 at hotmail dot com
Reported by: ryan dot brothers at gmail dot com
Summary: ldap connection timeouts not enforced
Status: Closed
Type: Bug
Package: LDAP related
Operating System: Linux
PHP Version: 5.6.8
Assigned To: mcmic
Block user comment: N
Private report: N
New Comment:
For ldap protocol, I did the similar code:
<?php
$ldap = ldap_connect('ldap://127.0.0.1:389');
ldap_set_option($ldap, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMELIMIT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMEOUT, 3);
ldap_bind($ldap);
?>
This times out in 3 seconds.
How could you set timeout before ldap_connect, if $ldap is not set by ldap_connect call?
Previous Comments:
------------------------------------------------------------------------
[2022-08-11 19:40:56] heiglandreas@php.net
As ldap_connect doesn't actually "connect", the logic is quite flawed here as the
first command actually connecting to the server in the example is the ldap_bind.
But in the end that's nitpicking. The TIMEOUT needs to be set before the ldap_connect, so the
ldap_set_option gets NULL as connection parameter.
------------------------------------------------------------------------
[2022-08-11 18:38:16] requinix@php.net
Connection timeouts must be set before connecting. Set LDAP_OPT_NETWORK_TIMEOUT globally before
calling ldap_connect() by passing null in place of a connection.
ldap_set_option(null, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_connect('127.0.0.1:1234');
Meanwhile ldap_bind() is something else.
------------------------------------------------------------------------
[2022-08-11 18:10:10] tanjh58 at hotmail dot com
This doesn't work for ldaps protocol. Here is my code:
<?php
$ldap = ldap_connect('ldaps://127.0.0.1:636');
ldap_set_option($ldap, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMELIMIT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMEOUT, 3);
ldap_bind($ldap);
?>
This never timeout.
------------------------------------------------------------------------
[2015-09-10 10:00:43] mcmic@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
I added support for LDAP_OPT_TIMEOUT, please check that it fixes your problem.
------------------------------------------------------------------------
[2015-09-09 15:24:21] mcmic@php.net
Ok, so the problem is:
LDAP_OPT_TIMELIMIT is only for searches, not bind operations
LDAP_OPT_NETWORK_TIMEOUT is for socket level timeout, in your test there is no such thing as the nc
is indeed listening on the socket.
What you need is LDAP_OPT_TIMEOUT from openldap, which is not available yet in PHP.
So Iâm gonna add this to php-ldap as it seems usefull.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69574
--
Edit this bug report at https://bugs.php.net/bug.php?id=69574&edit=1