[php-src] Issue #12081: LDAPS client certificate authentication does not work

From: Date: Wed, 30 Aug 2023 09:16:59 +0000
Subject: [php-src] Issue #12081: LDAPS client certificate authentication does not work
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245291@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/12081 Author: fkooman ### Description The following code: ```php <?php // Test case for PHP bug: https://bugs.php.net/bug.php?id=73558 // // The two commands below work totally fine: // // OpenSSL: // $ openssl s_client -verifyCAfile ca.crt -cert ldap-client.crt -key ldap-client.key -connect ldap.home.arpa:636 // // ldapsearch: // $ LDAPTLS_CACERT=ca.crt LDAPTLS_CERT=ldap-client.crt LDAPTLS_KEY=ldap-client.key ldapwhoami -H ldaps://ldap.home.arpa -x // anonymous $ldapUri = 'ldaps://ldap.home.arpa'; $caFile = __DIR__.'/ca.crt'; $certFile = __DIR__.'/ldap-client.crt'; $keyFile = __DIR__.'/ldap-client.key'; //putenv(sprintf('LDAPTLS_CACERT=%s', $caFile)); //putenv(sprintf('LDAPTLS_CERT=%s', $certFile)); //putenv(sprintf('LDAPTLS_KEY=%s', $keyFile)); $ldapResource = ldap_connect($ldapUri); $ldapOptions = [ LDAP_OPT_PROTOCOL_VERSION => 3, LDAP_OPT_REFERRALS => 0, LDAP_OPT_X_TLS_CACERTFILE => $caFile, LDAP_OPT_X_TLS_CERTFILE => $certFile, LDAP_OPT_X_TLS_KEYFILE => $keyFile, ]; foreach($ldapOptions as $k => $v) { ldap_set_option($ldapResource, $k, $v); } if(false === ldap_bind($ldapResource)) { ldap_get_option($ldapResource, LDAP_OPT_DIAGNOSTIC_MESSAGE, $errMsg); echo sprintf( "%s (%d): %s\n", ldap_error($ldapResource), ldap_errno($ldapResource), $errMsg ); } var_dump( ldap_exop_whoami($ldapResource) ); ``` Resulted in this output: ``` PHP Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in /home/fkooman/ldap.home.arpa/ldap_test.php on line 36 Can't contact LDAP server (-1): error:0A000086:SSL routines::certificate verify failed (self-signed certificate in certificate chain) PHP Warning: ldap_exop_whoami(): Whoami extended operation failed: Can't contact LDAP server (-1) in /home/fkooman/ldap.home.arpa/ldap_test.php on line 47 bool(false) ``` But I expected this output instead (anonymous bind): ``` string(0) "" ``` ## Workaround When you enable the three putenv lines, things start working, but this probably not how it should be :) ## Additional details It seems the options LDAP_OPT_X_TLS_CACERTFILE, LDAP_OPT_X_TLS_CERTFILE and LDAP_OPT_X_TLS_KEYFILE are somehow ignored. We tested this on Fedora 38 (PHP 8.2.9 (cli) (built: Aug 3 2023 11:39:08) (NTS gcc x86_64)): ``` LDAP Support => enabled Total Links => 0/unlimited API Version => 3001 Vendor Name => OpenLDAP Vendor Version => 20604 SASL Support => Enabled Directive => Local Value => Master Value ldap.max_links => Unlimited => Unlimited ``` And on Debian 12 (PHP 8.2.7 (cli) (built: Jun 9 2023 19:37:27) (NTS)): ``` LDAP Support => enabled Total Links => 0/unlimited API Version => 3001 Vendor Name => OpenLDAP Vendor Version => 20513 SASL Support => Enabled Directive => Local Value => Master Value ldap.max_links => Unlimited => Unlimited ``` See also: https://bugs.php.net/bug.php?id=73558 ### PHP Version PHP 8.2.9 / 8.2.7 ### Operating System Fedora 38 / Debian 12

« previous php.bugs (#245291) next »