Solved

Using LDAP in PHP to get Active Directory info always returns Invalid credentials

Posted on 2008-10-06
5
1,494 Views
Last Modified: 2013-12-19
Let me preface this question with, I am not a sys admin by any means.  I am a LAMP developer attempting to use PHP's LDAP extension to authenticate users of a PHP application against my client's Active Directory accounts.

Setup:
    Box 1:
        Windows 2003 running Apache 2.2 and PHP 5.2
    Box 2:
        Windows box running Active Directory

The sys admin send me a screenshot of the Active Directory tree.  My account was located on:
domain: area1.area2.local
ad host machine: box2

My account is in the Our Users -> Our Department -> Our Team folder.

$connection = ldap_connect('box2');    <------- works
ldap_bind($connection,'cn=billybob,ou=Our Users,ou=Our Department,ou=Our Team,dc=area1,dc=area2,dc=local','mypassword');    <------- throws 'Unable to bind to server: Invalid credentials'

Any ideas?  

0
Comment
Question by:mhmservices
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 40

Expert Comment

by:Richard Quadling
ID: 22654747
Can you take a look through the user notes on http://docs.php.net/ldap_bind

The code ...

if (ldap_set_option($ldapLink,LDAP_OPT_PROTOCOL_VERSION,3))
{
    echo "Using LDAP v3";
}else{
    echo "Failed to set version to protocol 3";
}

May be required for you as well as other settings.
0
 

Author Comment

by:mhmservices
ID: 22671915
Thanks for the idea, but unfortunately that piece is already in our code.
0
 
LVL 40

Expert Comment

by:Richard Quadling
ID: 22673504
Are you sure the password is correct? Case sensitivity and all that.
0
 

Author Comment

by:mhmservices
ID: 22684684
I am sure the info is correct because I am using it to login to the VPN.  Thanks for the shot though.
0
 
LVL 40

Accepted Solution

by:
Richard Quadling earned 125 total points
ID: 22684987
I've only done a little playing with LDAP.

Here is the code I used as my first test.

I'm using this from the command line.


Usage :

ldap_search <username> <password> <searchElement> <seachValue>

e.g.

ldap_search RQuadling blahblahblah sn Q*

will use my credentials to look for all entities that have a SN (surname) element that starts with Q.




If you change LDAP_Server to the server name and DOMAIN to the domain.





<?php
$ds=ldap_connect('LDAP_Server.DOMAIN');  // must be a valid LDAP server!
$dn="DC=DOMAIN";
 
if ($ds)
	{ 
	$r=ldap_bind($ds, 'DOMAIN\\' . $argv[1], $argv[2]);
	$sr = ldap_search($ds, $dn, $argv[3] . '=' . $argv[4]);
 
	if (0 == $sr)
		{
		echo ldap_errno($ds), ':', ldap_error($ds), ':';
		}
	else
		{
		$info = ldap_get_entries($ds, $sr);
		print_r($info);
		}
 
	ldap_close($ds);
	var_dump($ds);
	}

Open in new window

0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many old projects have bad code, but the budget doesn't exist to rewrite the codebase. You can update this code to be safer by introducing contemporary input validation, sanitation, and safer database queries.
This article shows the steps required to install WordPress on Azure. Web Apps, Mobile Apps, API Apps, or Functions, in Azure all these run in an App Service plan. WordPress is no exception and requires an App Service Plan and Database to install
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question