Doc #50270 [Opn->Wfx]: ldap_start_tls problem
| From: | heiglandreas@php.net | Date: | Mon, 09 Jan 2017 07:03:31 +0000 |
| Subject: | Doc #50270 [Opn->Wfx]: ldap_start_tls problem | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14316@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=50270&edit=1
ID: 50270
Updated by: heiglandreas@php.net
Reported by: jcarlos at dsi dot uclm dot es
Summary: ldap_start_tls problem
-Status: Open
+Status: Wont fix
Type: Documentation Problem
Package: LDAP related
Operating System: windows
PHP Version: 5.3.1
Block user comment: N
Private report: N
New Comment:
This issue has been open for more than 7 years and targets a by now unsupported version of PHP.
Therefore I'm closing it.
Should you still have these issues with a supported version of PHP please feel free to open a new
issue.
Thanks
Previous Comments:
------------------------------------------------------------------------
[2013-01-21 13:43:52] omar dot piani at gmail dot com
I was stucked with this: https://bugs.php.net/bug.php?id=48866
the solution is move the ldap.conf to c:\
------------------------------------------------------------------------
[2010-08-12 00:33:28] steve at maraspin dot net
I am also experiencing the same problem with PHP 5.3.2, bundled in Zend Server CE. I've tried
invoking following script both from the cli and apache on CentOS 5.5 64 bit and it fails on both
cases. Following error message appears:
Warning: ldap_start_tls(): Unable to start TLS: Not Supported in /tmp/script.php on line 7
On same machine, the same script, interpreted by a PHP 5.1.6 (cli) interpreter (obtained from CentOS
yum repository, php package) works well. Both php binaries are compiled for 64 bit.
<?php
$ldap="ldap://myhost";
$ds=ldap_connect($ldap,389);
$ldapbind=false;
if(ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3)) {
if(ldap_set_option($ds, LDAP_OPT_REFERRALS, 0)) {
if(ldap_start_tls($ds)) {
$ldapbind = ldap_bind($ds,
"cn=username,
dc=x,
dc=y",
"password"
);
if ($ldapbind) {
echo "ok";
} else {
echo "ko tls";
}
} else {
echo "no tls";
}
} else echo "no option";
} else {
echo "no version";
}
ldap_close($ds);
------------------------------------------------------------------------
[2009-12-01 11:12:34] jcarlos at dsi dot uclm dot es
I have tested in linux
Width PHP/5.2.10-2ubuntu and Apache/2.2.1.2
INTEGRATING ACTIVE DIRECTORY WITH PHP-LDAP AND TLS IN LINUX
===========================================================
I'm not an expert, but it works.
1)I have installed ubuntu 9.10 desktop
2)Packages:
apt-get install apache2
apt-get install libapache2-mod-php5
apt-get install libldap-2.4-2
apt-get install ldap-utils
apt-get install libsasl2-modules-ldap
apt-get install openssl
apt-get install libsasl2-2
apt-get install libkrb5-3
apt-get install kbr5-config
apt-get install kbr5-user
apt-get install php5-ldap
apt-get install php5-sasl
apt-get install php5-auth-pam
3)Put the PEM certificate.
cd /etc/ldap
mkdir certs
copy /myhome/mycert.pem /etc/ldap/certs/mycert.pem
NOTE:webcert.crt rename to mycert.pem. It's the same
4)Edit the file /etc/ldap/ldap.conf and Add:
TLS_REQCERT never
TLS_CACERT /etc/ldap/certs/mycert.pem
5)Create file /var/www/ldaptlstest.php:
<?php
$ldap="ldap.myDomain.com";
$usr="user@myDomain.com";
$pwd="mypassword";
$ds=ldap_connect($ldap);
$ldapbind=false;
if(ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3))
if(ldap_set_option($ds, LDAP_OPT_REFERRALS, 0))
if(ldap_start_tls($ds))
$ldapbind = @ldap_bind($ds, $usr, $pwd);
ldap_close($ds);
if(!$ldapbind)
echo "ERROR";
else
echo "OK";
?>
6)Restart the server: /etc/init.d/apache2 restart
7)Open Firefox and write: http://localhost/ldaptlstest.php
;) Works fine
------------------------------------------------------------------------
[2009-11-27 09:19:01] jcarlos at dsi dot uclm dot es
In Step 1, I have downloaded the certificate the the url https://www.myDomain.com
------------------------------------------------------------------------
[2009-11-26 11:05:18] pajoye@php.net
Moving to the "to be documented" state, it could be very usefull to have this info in the
ldap documentation.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=50270
--
Edit this bug report at https://bugs.php.net/bug.php?id=50270&edit=1