如何在Symfony 6.4框架中使用自签名证书连接LDAPS
Symfony 6.4 LDAPS连接失败解决方案
问题说明
现有Symfony 6.4 Web应用,LDAP连接功能正常,但切换为LDAPS协议时连接失败。在旧的非Symfony应用中,执行putenv('LDAPTLS_REQCERT=never')即可解决该问题,但Symfony环境下此方法无效。应用部署在Ubuntu系统+Apache服务器环境中。
当前配置
.env.local
LDAPTLS_REQCERT=never LDAP_CONNECTION_STRING=ldaps://192.168.15.201:636 LDAP_IP=192.168.15.201 LDAP_USERNAME=company\Administrator LDAP_PASSWORD=strong_secret LDAP_DOMAIN=company.local LDAP_ENCRYPTION=tls LDAP_VERSION=3
LdapService.php
<?php namespace App\Service; use Symfony\Component\Ldap\Ldap; use Symfony\Component\Ldap\Exception\LdapException; class LdapService { private $ldap; public function __construct() { try { putenv('LDAPTLS_REQCERT=never'); $connectToLdap = $_ENV['LDAP_CONNECTION_STRING']; $ldapUsername = $_ENV['LDAP_USERNAME']; $ldapPassword = $_ENV['LDAP_PASSWORD']; $this->ldap = Ldap::create('ext_ldap', ['connection_string' => $connectToLdap]); $this->ldap->bind($ldapUsername, $ldapPassword); } catch (LdapException $e) { echo 'LDAP Connection Error: ' . $e->getMessage(); throw $e; } } public function getLdap(): Ldap { return $this->ldap; } }
services.yaml
parameters: services: # default configuration for services in *this* file _defaults: autowire: true # Automatically injects dependencies in your services. autoconfigure: true # Automatically registers your services as commands, event subscribers, etc. bind: $ldapService: '@App\Service\LdapService' # makes classes in src/ available to be used as services # this creates a service per class whose id is the fully-qualified class name App\: resource: '../src/' exclude: - '../src/DependencyInjection/' - '../src/Entity/' - '../src/Kernel.php' App\Controller\: resource: '../src/Controller' tags: ['controller.service_arguments'] # add more service definitions when explicit configuration is needed # please note that last definitions always *replace* previous ones # Explicitly configure the LdapService App\Service\LdapService: public: true
ExampleController.php
<?php namespace App\Controller; use App\Service\LdapService; use Symfony\Bundle\FrameworkBundle\Controller\AbstractController; use Symfony\Component\HttpFoundation\Response; use Symfony\Component\HttpFoundation\Request; use Symfony\Component\Routing\Annotation\Route; use Symfony\Component\Ldap\Exception\LdapException; #[Route('/ldapuser', name: 'app_ldapuser.')] class LdapUserController extends AbstractController { private $ldapService; public function __construct(LdapService $ldapService) { $this->ldapService = $ldapService; } }
解决方法
方法1:直接配置LDAP TLS选项(推荐)
Symfony的ext_ldap适配器支持直接设置TLS验证参数,替代环境变量方式,更可靠且无需依赖系统环境。修改LdapService.php中的LDAP实例创建代码:
$this->ldap = Ldap::create('ext_ldap', [ 'connection_string' => $connectToLdap, 'tls_options' => [ 'verify_peer' => false, 'verify_peer_name' => false, ], 'version' => $_ENV['LDAP_VERSION'], ]);
同时删除.env.local中的LDAP_ENCRYPTION=tls配置项——ldaps://协议本身已自带加密,该选项用于普通LDAP连接后启动TLS,会造成逻辑冲突。
方法2:确保环境变量在Symfony启动前生效
若坚持使用环境变量方案,需保证LDAPTLS_REQCERT=never在Symfony内核初始化前加载:
- 编辑Apache虚拟主机配置,添加
SetEnv LDAPTLS_REQCERT never,随后重启Apache服务 - 确保
.env.local中的该变量在Symfony加载环境变量时被正确读取,但此方式优先级低于直接配置LDAP选项
方法3:系统级LDAP配置修改(仅测试环境使用)
编辑Ubuntu系统全局LDAP配置文件/etc/ldap/ldap.conf,添加或修改:
TLS_REQCERT never
此方式会全局禁用LDAP TLS证书验证,仅适合测试环境,生产环境不建议使用。
内容的提问来源于stack exchange,提问作者TheQuestionmark
相关产品推荐
相关产品推荐

