note 90303 added to function.ldap-connect

From: Date: Wed, 15 Apr 2009 16:35:44 +0000
Subject: note 90303 added to function.ldap-connect
Groups: php.notes 
Request: Send a blank email to php-notes+get-153341@lists.php.net to get a copy of this message
It bears repeating (and the examples should probably be updated) that ldap_connect() doesn't actually test the connection to the specified ldap server. This is important if you're trying to build failover into your ldap-based authentication routine. The only way to test the connection is to actually call ldap_bind( $ds, $username, $password ). But if that fails, is it because you have the wrong username/password or is it because the connection is down? As far as I can see there isn't any way to tell. It seems that if ldap_bind() fails against your primary server, you have no choice but to try ldap_bind() with the same credentials against the backup. And yet, if your organization limits failed login attempts, a single bad password counts as two failed login attempts. Not good. One possible workaround is to try an anonymous bind first: // connect to primary $ds = ldap_connect( 'ldap://10.0.0.7/' ); // note: $ds is always a resource even if primary is down // try anonymous login to test connection $anon = @ldap_bind( $ds ); if ( !$anon ) { // test failed, connect to failover host $ds = ldap_connect( 'ldap://10.0.0.8/' ); } else { // test passed, unbind anonymous and reconnect to primary ldap_unbind( $ds ); $ds = ldap_connect( 'ldap://10.0.0.7/' ); } // now try a real login $login = @ldap_bind( $ds, $username, $password ); Note that this workaround relies on anonymous login being enabled, which may not always be the case. It's a little sad that there is no other way to test the connection. Hopefully this can be remedied in some future implementation of ldap_connect(). ---- Server IP: 209.41.74.194 Probable Submitter: 74.201.167.2 ---- Manual Page -- http://www.php.net/manual/en/function.ldap-connect.php Edit -- https://master.php.net/note/edit/90303 Del: integrated -- https://master.php.net/note/delete/90303/integrated Del: useless -- https://master.php.net/note/delete/90303/useless Del: bad code -- https://master.php.net/note/delete/90303/bad+code Del: spam -- https://master.php.net/note/delete/90303/spam Del: non-english -- https://master.php.net/note/delete/90303/non-english Del: in docs -- https://master.php.net/note/delete/90303/in+docs Del: other reasons-- https://master.php.net/note/delete/90303 Reject -- https://master.php.net/note/reject/90303 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#153341) next »