LDAP SSL support
| From: | Stig Venaas | Date: | Sun, 20 Aug 2000 11:12:10 +0000 |
| Subject: | LDAP SSL support | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-29897@lists.php.net to get a copy of this message | ||
Hi
A few of the LDAP SDK's support SSL. Looks like it might be completely
transparent in OpenLDAP, but it's not using Netscape or Oracle.
I want to add support for Oracle and SSL ASAP, what I'm not sure what
is the best PHP interface though.
I think the best is to have an
ldap_connect_ssl(hostname, port, sslparams...)
that one uses instead of ldap_connect when using SSL. It should give
an error if PHP can't make sure SSL is being used. If SSL is completely
transparent people must configure it outside PHP and use ldap_connect
as usual. An alternative is of course to add arguments to ldap_connect.
Another choice would be to have a separate call that turns on SSL
after the normal ldap_connect, but that doesn't work with Netscape
I think.
My main concern is that the sslparams will depend on the API being
used. It's nearly impossible to have a good generic interface that
will also be sufficient for future SSL SDK's.
Is it okay that the parameters (also the number) varies depending
on the SDK being used? Would it be better if we passed say an
associative array as last argument where the contents of the array
depends on the SDK?
In the Oracle case I think I could do either
ldap_connect_ssl(string host, string port, string wallet, string password,
int type)
or
$ssldata = array( "wallet" => "....", "password" =>
"qwerty", type=>NO_AUTH);
ldap_connect_ssl(string host, string port, array $ssldata);
And as I said above, an alternative is to extend ldap_connect. I'm
starting to think that's best.
Comments?
Stig