Bug->Doc #70971 [Csd->ReO]: LDAP Not Reading Config File (ldap.cfg)
| From: | ab@php.net | Date: | Wed, 09 Dec 2015 11:29:23 +0000 |
| Subject: | Bug->Doc #70971 [Csd->ReO]: LDAP Not Reading Config File (ldap.cfg) | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12920@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70971&edit=1
ID: 70971
Updated by: ab@php.net
Reported by: jspringe at gmail dot com
Summary: LDAP Not Reading Config File (ldap.cfg)
-Status: Closed
+Status: Re-Opened
-Type: Bug
+Type: Documentation Problem
Package: LDAP related
Operating System: Windows (7/8/10)
PHP Version: 7.0.0RC7
Block user comment: N
Private report: N
New Comment:
@jspringe, thanks for the further investigation. If it's a change in the OpenLDAP version, it
would make sense to document it.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-12-04 14:41:18] jspringe at gmail dot com
After looking over the source for this extension and the source for OpenLDAP itself I've found
what needs to be done in Windows - I'm not how this translates to Linux.
You need to set an environment variable of LDAPCONF that is equal to the path and filename of your
configuration. In previous versions the extension would assume C:\openldap\sysconf\ldap.conf.
------------------------------------------------------------------------
[2015-11-26 14:33:18] jspringe at gmail dot com
I removed the config file completely and the error triggered on 5.5.30, so it's definitely
reading it in previous versions. I'm fully aware that the error I'm getting is a
certificate problem. Which is why I used the directive TLS_REQCERT never. In 5.5.30 you would use
the config file to add certs as well - so again - what am I suppose to do in PHP7 when I need an
SSL/TLS connection?
------------------------------------------------------------------------
[2015-11-26 01:53:22] ab@php.net
Btw the error message you posted looks pretty much like that, certificate failure. IIRC starting
with even with OpenSSL 1.0.1, custom certificates might be deleted automatically from the Windows
storage, as they got validated with some trusted certificate checker service.
Thanks.
------------------------------------------------------------------------
[2015-11-26 01:49:30] ab@php.net
Thanks for the further info. As I've mentioned, i couldn't spot any attempts to load the
config file at the startup file. It likely could be, that the file is only getting loaded when PHP
code starts to work. I'll probably have to setup a ldap server, lets see.
But one thing I would like to ask you before - please check the event logs. 5.5 and 7 use different
OpenSSL versions. OPenSSL 1.0.2 used with 7.0 is integrated better with the Windows APIs. It could
be, that your certificate gets validated live and OpenSSL just refuses it.
Thanks.
------------------------------------------------------------------------
[2015-11-25 19:00:46] jspringe at gmail dot com
Current working configuration:
PHP 5.5.30
Config File: C:\OpenLDAP\sysconf\ldap.cfg
Contents: TLS_REQCERT never
Current failing configuration:
PHP 7.0.0RC7
Config File: C:\OpenLDAP\sysconf\ldap.cfg
Contents: TLS_REQCERT never
Code:
$ldap_identifier = ldap_connect('ldaps://activedirectory');
ldap_set_option($ldap_identifier, LDAP_OPT_REFERRALS, 0);
ldap_set_option($ldap_identifier, LDAP_OPT_PROTOCOL_VERSION, 3);
$bind = ldap_bind($ldap_identifier, 'user', 'password');
if ($bind !== true) {
ldap_get_option($ldap_identifier, LDAP_OPT_DIAGNOSTIC_MESSAGE, $extended_error);
echo $extended_error;
} else {
echo "Connected";
var_dump($bind);
}
PHP 5.5.30 Output:
Connected
boolean true
PHP 7.0.0RC7 Output:
Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in ... on line 8
error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (unable to get
local issuer certificate)
This was an error I received prior to creating the configuration file on 5.5.30. This is just a
proof-of-concept and CURRENTLY I'm not concerned with the certificate (I actually know
it's expired which is a problem I'll tackle later). Either way with the configuration file
it should work the same as before or documentation needs to be updated. Also the documentation
itself doesn't mention the configuration file - luckily a few comments do.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70971
--
Edit this bug report at https://bugs.php.net/bug.php?id=70971&edit=1