LDAP SSL support

From: Date: Sun, 20 Aug 2000 11:12:10 +0000
Subject: LDAP SSL support
Groups: php.dev 
Request: Send a blank email to php-dev+get-29897@lists.php.net to get a copy of this message
Hi A few of the LDAP SDK's support SSL. Looks like it might be completely transparent in OpenLDAP, but it's not using Netscape or Oracle. I want to add support for Oracle and SSL ASAP, what I'm not sure what is the best PHP interface though. I think the best is to have an ldap_connect_ssl(hostname, port, sslparams...) that one uses instead of ldap_connect when using SSL. It should give an error if PHP can't make sure SSL is being used. If SSL is completely transparent people must configure it outside PHP and use ldap_connect as usual. An alternative is of course to add arguments to ldap_connect. Another choice would be to have a separate call that turns on SSL after the normal ldap_connect, but that doesn't work with Netscape I think. My main concern is that the sslparams will depend on the API being used. It's nearly impossible to have a good generic interface that will also be sufficient for future SSL SDK's. Is it okay that the parameters (also the number) varies depending on the SDK being used? Would it be better if we passed say an associative array as last argument where the contents of the array depends on the SDK? In the Oracle case I think I could do either ldap_connect_ssl(string host, string port, string wallet, string password, int type) or $ssldata = array( "wallet" => "....", "password" => "qwerty", type=>NO_AUTH); ldap_connect_ssl(string host, string port, array $ssldata); And as I said above, an alternative is to extend ldap_connect. I'm starting to think that's best. Comments? Stig

« previous php.dev (#29897) next »