LDAP Client x509 Certificate Authentication

Open
#3 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
php

Research direction

Start with the SimpleSAMLphp LDAP documentation and PHP's ldap_set_option reference linked in the issue. Determine how client certificates and keys should be configured alongside username/password authentication, including the supported PHP versions. Done means LDAP authentication can use the certificate-based flow without removing the existing credential-based flow.

Written by the indexing model from the issue text.

Description

Google announced their LDAP service: https://support.google.com/cloudidentity/answer/9089736 and we wanted to see if we could get it working for our users.

However, it requires a client certificate to authenticate to the server, which SimpleSAMLphp doesn't support: https://simplesamlphp.org/docs/stable/ldap:ldap . It seems to only support username/password for client authentication.

It would be nice to be able to support client cert/key for authentication in addition to username/password. OpenLDAP supports it using TLS_CERT and TLS_KEY.

It seems that support for this may have only come into PHP in version 7.1: http://php.net/manual/en/function.ldap-set-option.php

Dominant language
PHP
Stars
5
Forks
14
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from simplesamlphp/simplesamlphp-module-ldap

All issues in simplesamlphp/simplesamlphp-module-ldap

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.