Doc #50270 [Opn->Wfx]: ldap_start_tls problem

From: Date: Mon, 09 Jan 2017 07:03:31 +0000
Subject: Doc #50270 [Opn->Wfx]: ldap_start_tls problem
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14316@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=50270&edit=1 ID: 50270 Updated by: heiglandreas@php.net Reported by: jcarlos at dsi dot uclm dot es Summary: ldap_start_tls problem -Status: Open +Status: Wont fix Type: Documentation Problem Package: LDAP related Operating System: windows PHP Version: 5.3.1 Block user comment: N Private report: N New Comment: This issue has been open for more than 7 years and targets a by now unsupported version of PHP. Therefore I'm closing it. Should you still have these issues with a supported version of PHP please feel free to open a new issue. Thanks Previous Comments: ------------------------------------------------------------------------ [2013-01-21 13:43:52] omar dot piani at gmail dot com I was stucked with this: https://bugs.php.net/bug.php?id=48866 the solution is move the ldap.conf to c:\ ------------------------------------------------------------------------ [2010-08-12 00:33:28] steve at maraspin dot net I am also experiencing the same problem with PHP 5.3.2, bundled in Zend Server CE. I've tried invoking following script both from the cli and apache on CentOS 5.5 64 bit and it fails on both cases. Following error message appears: Warning: ldap_start_tls(): Unable to start TLS: Not Supported in /tmp/script.php on line 7 On same machine, the same script, interpreted by a PHP 5.1.6 (cli) interpreter (obtained from CentOS yum repository, php package) works well. Both php binaries are compiled for 64 bit. <?php $ldap="ldap://myhost"; $ds=ldap_connect($ldap,389); $ldapbind=false; if(ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3)) { if(ldap_set_option($ds, LDAP_OPT_REFERRALS, 0)) { if(ldap_start_tls($ds)) { $ldapbind = ldap_bind($ds, "cn=username, dc=x, dc=y", "password" ); if ($ldapbind) { echo "ok"; } else { echo "ko tls"; } } else { echo "no tls"; } } else echo "no option"; } else { echo "no version"; } ldap_close($ds); ------------------------------------------------------------------------ [2009-12-01 11:12:34] jcarlos at dsi dot uclm dot es I have tested in linux Width PHP/5.2.10-2ubuntu and Apache/2.2.1.2 INTEGRATING ACTIVE DIRECTORY WITH PHP-LDAP AND TLS IN LINUX =========================================================== I'm not an expert, but it works. 1)I have installed ubuntu 9.10 desktop 2)Packages: apt-get install apache2 apt-get install libapache2-mod-php5 apt-get install libldap-2.4-2 apt-get install ldap-utils apt-get install libsasl2-modules-ldap apt-get install openssl apt-get install libsasl2-2 apt-get install libkrb5-3 apt-get install kbr5-config apt-get install kbr5-user apt-get install php5-ldap apt-get install php5-sasl apt-get install php5-auth-pam 3)Put the PEM certificate. cd /etc/ldap mkdir certs copy /myhome/mycert.pem /etc/ldap/certs/mycert.pem NOTE:webcert.crt rename to mycert.pem. It's the same 4)Edit the file /etc/ldap/ldap.conf and Add: TLS_REQCERT never TLS_CACERT /etc/ldap/certs/mycert.pem 5)Create file /var/www/ldaptlstest.php: <?php $ldap="ldap.myDomain.com"; $usr="user@myDomain.com"; $pwd="mypassword"; $ds=ldap_connect($ldap); $ldapbind=false; if(ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3)) if(ldap_set_option($ds, LDAP_OPT_REFERRALS, 0)) if(ldap_start_tls($ds)) $ldapbind = @ldap_bind($ds, $usr, $pwd); ldap_close($ds); if(!$ldapbind) echo "ERROR"; else echo "OK"; ?> 6)Restart the server: /etc/init.d/apache2 restart 7)Open Firefox and write: http://localhost/ldaptlstest.php ;) Works fine ------------------------------------------------------------------------ [2009-11-27 09:19:01] jcarlos at dsi dot uclm dot es In Step 1, I have downloaded the certificate the the url https://www.myDomain.com ------------------------------------------------------------------------ [2009-11-26 11:05:18] pajoye@php.net Moving to the "to be documented" state, it could be very usefull to have this info in the ldap documentation. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=50270 -- Edit this bug report at https://bugs.php.net/bug.php?id=50270&edit=1

« previous php.doc.bugs (#14316) next »