PHP LDAP 连接无法联系 LDAP 服务器
PHP LDAP Connection Can't Contact LDAP Server
我有一个正在迁移的外部 Web 服务器。我正在尝试通过 LDAP 对内部服务器上的 Active Directory 进行身份验证。我可以使用相同的代码从旧服务器 (Ubuntu 8) 进行连接和身份验证,但无法在新服务器 (Redhat 7) 上进行身份验证。
外部服务器当前是 运行 Redhat 7 运行 PHP 5.4.16,启用了 LDAP 支持 (php-ldap)。
内部服务器目前是一个 Windows Server 2008 box with LDAP and Active Directory。
下面的代码是当前 PHP 我正在使用的代码,它能够在旧服务器上连接,但在新服务器上出现问题。它基本上使用 PHP LDAP 连接字符串并尝试绑定。我已经用标识符替换了一些个人信息。 (用户名、子域等)
<?php
$adServer = "ldaps://subdomain.domain.edu";
$ldap = ldap_connect($adServer);
$username = 'USERNAME';
$password = 'PASS';
$ldaprdn = 'DOMAIN' . "\" . $username;
ldap_set_option($ldap, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_set_option($ldap, LDAP_OPT_REFERRALS, 0);
$bind = @ldap_bind($ldap, $ldaprdn, $password);
if ($bind) {
$filter="(sAMAccountName=$username)";
$result = ldap_search($ldap,"dc=subdomain,dc=domain,dc=edu",$filter);
ldap_sort($ldap,$result,"sn");
$info = ldap_get_entries($ldap, $result);
for ($i=0; $i<$info["count"]; $i++)
{
if($info['count'] > 1)
break;
echo "<p>You are accessing <strong> ". $info[$i]["sn"][0] .", " . $info[$i]["givenname"][0] ."</strong><br /> (" . $info[$i]["samaccountname"][0] .")</p>\n";
echo '<pre>';
var_dump($info);
echo '</pre>';
$userDn = $info[$i]["distinguishedname"][0];
}
@ldap_close($ldap);
} else {
$msg = "Invalid email address / password";
echo $msg;
}
?>
在新服务器上,我可以使用以下 ldapsearch 命令连接到 ldap 服务器:
ldapsearch -x -LLL -h sub-domain.domain.edu -D 'CN=DOMAIN\USERNAME' -w 'PASS' -b "dc=subdomain,dc=domain,dc=edu" -s sub "(objectClass=user)" givenName
这是我的 ldap.conf 文件(/etc/openldap/ldap.conf
,新服务器)
#
# LDAP Defaults
#
# See ldap.conf(5) for details
# This file should be world readable but not world writable.
#BASE dc=example,dc=com
#URI ldap://ldap.example.com ldap://ldap-master.example.com:666
#SIZELIMIT 12
#TIMELIMIT 15
#DEREF never
#TLS_CACERTDIR /etc/openldap/certs
# Turning this off breaks GSSAPI used with krb5 when rdns = false
SASL_NOCANON on
TLS_REQCERT never
这是我在错误日志中得到的(新服务器):
ldap_create
ldap_url_parse_ext(ldaps://subdomain.domain.edu)
ldap_bind_s
ldap_simple_bind_s
ldap_sasl_bind_s
ldap_sasl_bind
ldap_send_initial_request
ldap_new_connection 1 1 0
ldap_int_open_connection
ldap_connect_to_host: TCP subdomain.domain.edu:636
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.19:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.24:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.41:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying 2002:XXXX:XXXX::XXXX:XXXX 636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_err2string
[Mon Feb 23 15:20:28.689775 2015] [:error] [pid 12299] [client 10.25.XX.XX:53630] PHP Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in /var/www/html/index2.php on line 19
又找了几天,终于有了答案。 SELinux。更具体地说,设置的SELinux Booleans。 httpd_can_network_connect 是我们正在看的那个:
httpd_can_network_connect (HTTPD Service):: Allow HTTPD scripts and modules to connect to the network.
此命令可用于打开它:
setsebool -P httpd_can_network_connect on
我通过找到这个答案解决了这个问题:
LDAP works with PHP CLI but not through apache
我有一个正在迁移的外部 Web 服务器。我正在尝试通过 LDAP 对内部服务器上的 Active Directory 进行身份验证。我可以使用相同的代码从旧服务器 (Ubuntu 8) 进行连接和身份验证,但无法在新服务器 (Redhat 7) 上进行身份验证。
外部服务器当前是 运行 Redhat 7 运行 PHP 5.4.16,启用了 LDAP 支持 (php-ldap)。
内部服务器目前是一个 Windows Server 2008 box with LDAP and Active Directory。
下面的代码是当前 PHP 我正在使用的代码,它能够在旧服务器上连接,但在新服务器上出现问题。它基本上使用 PHP LDAP 连接字符串并尝试绑定。我已经用标识符替换了一些个人信息。 (用户名、子域等)
<?php
$adServer = "ldaps://subdomain.domain.edu";
$ldap = ldap_connect($adServer);
$username = 'USERNAME';
$password = 'PASS';
$ldaprdn = 'DOMAIN' . "\" . $username;
ldap_set_option($ldap, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_set_option($ldap, LDAP_OPT_REFERRALS, 0);
$bind = @ldap_bind($ldap, $ldaprdn, $password);
if ($bind) {
$filter="(sAMAccountName=$username)";
$result = ldap_search($ldap,"dc=subdomain,dc=domain,dc=edu",$filter);
ldap_sort($ldap,$result,"sn");
$info = ldap_get_entries($ldap, $result);
for ($i=0; $i<$info["count"]; $i++)
{
if($info['count'] > 1)
break;
echo "<p>You are accessing <strong> ". $info[$i]["sn"][0] .", " . $info[$i]["givenname"][0] ."</strong><br /> (" . $info[$i]["samaccountname"][0] .")</p>\n";
echo '<pre>';
var_dump($info);
echo '</pre>';
$userDn = $info[$i]["distinguishedname"][0];
}
@ldap_close($ldap);
} else {
$msg = "Invalid email address / password";
echo $msg;
}
?>
在新服务器上,我可以使用以下 ldapsearch 命令连接到 ldap 服务器:
ldapsearch -x -LLL -h sub-domain.domain.edu -D 'CN=DOMAIN\USERNAME' -w 'PASS' -b "dc=subdomain,dc=domain,dc=edu" -s sub "(objectClass=user)" givenName
这是我的 ldap.conf 文件(/etc/openldap/ldap.conf
,新服务器)
#
# LDAP Defaults
#
# See ldap.conf(5) for details
# This file should be world readable but not world writable.
#BASE dc=example,dc=com
#URI ldap://ldap.example.com ldap://ldap-master.example.com:666
#SIZELIMIT 12
#TIMELIMIT 15
#DEREF never
#TLS_CACERTDIR /etc/openldap/certs
# Turning this off breaks GSSAPI used with krb5 when rdns = false
SASL_NOCANON on
TLS_REQCERT never
这是我在错误日志中得到的(新服务器):
ldap_create
ldap_url_parse_ext(ldaps://subdomain.domain.edu)
ldap_bind_s
ldap_simple_bind_s
ldap_sasl_bind_s
ldap_sasl_bind
ldap_send_initial_request
ldap_new_connection 1 1 0
ldap_int_open_connection
ldap_connect_to_host: TCP subdomain.domain.edu:636
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.19:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.24:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying XXX.18X.XX.41:636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_new_socket: 10
ldap_prepare_socket: 10
ldap_connect_to_host: Trying 2002:XXXX:XXXX::XXXX:XXXX 636
ldap_pvt_connect: fd: 10 tm: -1 async: 0
attempting to connect:
connect errno: 13
ldap_close_socket: 10
ldap_err2string
[Mon Feb 23 15:20:28.689775 2015] [:error] [pid 12299] [client 10.25.XX.XX:53630] PHP Warning: ldap_bind(): Unable to bind to server: Can't contact LDAP server in /var/www/html/index2.php on line 19
又找了几天,终于有了答案。 SELinux。更具体地说,设置的SELinux Booleans。 httpd_can_network_connect 是我们正在看的那个:
httpd_can_network_connect (HTTPD Service):: Allow HTTPD scripts and modules to connect to the network.
此命令可用于打开它:
setsebool -P httpd_can_network_connect on
我通过找到这个答案解决了这个问题:
LDAP works with PHP CLI but not through apache