Thursday, March 31, 2011

Authenticating user using LDAP from PHP

Hi my project is to make an module enrollment system for our university. So I contacted the IT people in my university for details to authenticate students to the system we are developin using the existing university login. They give me some LDAP information, I don't know how I can use it in my project. For the project I'm using PHP,Mysql on an Apacha server. So how can I authenticate an user logging into my system, given his userid and password with the LDAP information.

Given below is the LDAP information(i have changed the domain name etc.)

LDAP information for blueroom.ac.uk domain


LDAP Host : ad.blueroom.ac.uk

LDAP port no: 389

BASE DN : ou=bluebird, dc=bluebird, dc=ac, dc=my

LDAP account to bind : cn = kikdap, ou=servacc, dc=bluebird,dc=ac,dc=uk

LDAP account password : stranger4

Attribute : sAMAccountName

From stackoverflow
  • You might try http://code.activestate.com/recipes/101525/ while referring to http://us3.php.net/ldap and other results from a Google search for [php ldap authentication].

  • The general procedure would be (relevant ext/ldap php commands in brackets):

    1. connect to LDAP server using the "LDAP Host" and "LDAP port no" (ldap_connect()) and set the correct connection options (ldap_set_option()), especially LDAP_OPT_PROTOCOL_VERSION and LDAP_OPT_REFERRALS

    2. bind to LDAP server using the "LDAP account to bind" and "LDAP account password" (ldap_bind()) - if you're authenticating against an Active Directory server you can directly use the username and password from the login page and skip all the following steps.

    3. search the tree for a matching user entry/object by specifing the "BASE DN" and the appropriate LDAP filter - most likely something like (&(objectClass=user)(sAMAccountName=%s)) where %s should be replaced by the username to be authenticated (ldap_search())

    4. check if the number of returned entries is 1 (if <> 1 then something has gone wrong, e.g. no user found or multiple users found)

    5. retrive the distinguished name (DN) of this single entry (ldap_get_dn())

    6. use the DN found in the last step to try to bind to the LDAP server with the password given at the authentication page (ldap_bind())

    7. if the bind succeeds then everything is OK, if not, most likely the password is wrong

    It's really not as hard as it sounds at first. Generally I'd propose to use some sort of standard library for authenticating against a LDAP server such as the Net_LDAP2 PEAR package or Zend_Ldap out of the Zend Framework. I have no experience with actually using Net_LDAP2 (although I know the code quite well) but Zend_Ldap works very well against Active Directory servers or ADAMS servers (which is obviously what you're working with).

    This will do the trick using Zend_Ldap:

    $options = array(
        'host'                 => 'ad.blueroom.ac.uk',
        'useStartTls'          => true,
        'accountDomainName'    => 'blueroom.ac.uk',
        'accountCanonicalForm' => 4,
        'baseDn'               => 'ou=bluebird,dc=bluebird,dc=ac,dc=my',
    );
    $ldap = new Zend_Ldap($options);
    try {
        $ldap->bind('user', 'password');
    } catch (Zend_Ldap_Exception $e) {
        // something failed - inspect $e
    }
    // bind successful
    $acctname = $ldap->getCanonicalAccountName('user', Zend_Ldap::ACCTNAME_FORM_DN);
    
  • you could use http://pear.php.net/package/Net_LDAP2/docs it's nice and works.

    Example of connection taken by the doc:

    // Inclusion of the Net_LDAP2 package:
    require_once 'Net/LDAP.php';
    
    // The configuration array:
    $config = array (
        'binddn'    => 'cn=admin,ou=users,dc=example,dc=org',
        'bindpw'    => 'password',
        'basedn'    => 'dc=example,dc=org',
        'host'      => 'ldap.example.org'
    );
    
    // Connecting using the configuration:
    $ldap = Net_LDAP2::connect($config);
    
    // Testing for connection error
    if (PEAR::isError($ldap)) {
        die('Could not connect to LDAP-server: '.$ldap->getMessage());
    }
    
  • If your server is a linux box, you won't be able to talk to AD without a proper server certificate. This can be a issue if you need a help from the Univerity.

0 comments:

Post a Comment