Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.7k
[Ldap] Fix LDAP connection options#46325
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Conversation
carsonbot commentedMay 11, 2022
Hey! I see that this is your first PR. That is great! Welcome! Symfony has acontribution guide which I suggest you to read. In short:
Review the GitHub status checks of your pull request and try to solve the reported issues. If some tests are failing, try to see if they are failing because of this change. When two Symfony core team members approve this change, it will be merged and you will become an official Symfony contributor! I am going to sit back now and wait for the reviews. Cheers! Carsonbot |
carsonbot commentedMay 12, 2022
Hey! I think @arekzb has recently worked with this code. Maybe they can help review this? Cheers! Carsonbot |
Uh oh!
There was an error while loading.Please reload this page.
nicolas-grekas commentedMay 14, 2022
Thank you@buffcode. |
Uh oh!
There was an error while loading.Please reload this page.
This PR adds support for the
LDAP_OPT_X_TLS_CACERTFILEoption in order to specify a CA file which should be used. It is available since the same PHP versionas the other options and may just have been forgotten.Furthermore the connection options need to be applied at different stages in order to be effective.
Connection options are tagged to be preconnect-options and are executed before
ldap_connect, all other options continue to be applied betweenldap_connectandldap_bind.Be aware thatthere is no LDAP documentation about which option is global and thus not requiring a connection and which needs one.
The preconnect options from this PR come from trial-and-error testing and mailing list entries at OpenLDAP.
Maybe also relevant: