note 46054 added to function.ldap-connect
| From: | blizzards at libero dot it | Date: | Tue, 28 Sep 2004 10:23:54 +0000 |
| Subject: | note 46054 added to function.ldap-connect | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-77473@lists.php.net to get a copy of this message | ||
To complete questions about how to connect to a LDAP ACTIVE DIRECTORY 2000/2003 server with SASL on
port 636, you can refer to prevous notes, and the following directives:
A)Create CA certificates from AD;
B)Export in .pem (DER) format;
C)Install OPENSSL,CYRUS SASL,OPENLDAP,KERBEROS 5;
D)Copy exported AD ca cert into openssl certs dir on your unix system;
E)Reash with c_reash command;
F)Get a kerberos ticket form AD for your user;
G)Compile PHP with SSL and LDAP support;
H)Test with ldapsearch -D <binddn> -W -H ldaps://ad.secure.com:636 -x
If all works right, create your php script.
Note: For writing parameters to AD you need to renew ticket each 10 hours or less (AD default
lifetime ticket), for reading pourpose you can maintain expired ticket.
When querying a windows 2000/2003 AD you MUST use only SASL and not TLS (non supported).
----
Manual Page -- http://www.php.net/manual/en/function.ldap-connect.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+46054
Delete -- http://master.php.net/manage/user-notes.php?action=delete+46054&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+46054&report=yes
Search -- http://master.php.net/manage/user-notes.php