You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Symfony 6.4框架中使用自签名证书连接LDAPS

Symfony 6.4 LDAPS连接失败解决方案

问题说明

现有Symfony 6.4 Web应用,LDAP连接功能正常,但切换为LDAPS协议时连接失败。在旧的非Symfony应用中,执行putenv('LDAPTLS_REQCERT=never')即可解决该问题,但Symfony环境下此方法无效。应用部署在Ubuntu系统+Apache服务器环境中。

当前配置

.env.local

LDAPTLS_REQCERT=never
LDAP_CONNECTION_STRING=ldaps://192.168.15.201:636
LDAP_IP=192.168.15.201
LDAP_USERNAME=company\Administrator
LDAP_PASSWORD=strong_secret
LDAP_DOMAIN=company.local
LDAP_ENCRYPTION=tls
LDAP_VERSION=3

LdapService.php

<?php

namespace App\Service;

use Symfony\Component\Ldap\Ldap;
use Symfony\Component\Ldap\Exception\LdapException;

class LdapService
{
    private $ldap;

    public function __construct()
    {
        try {
            putenv('LDAPTLS_REQCERT=never');

            $connectToLdap = $_ENV['LDAP_CONNECTION_STRING'];
            $ldapUsername = $_ENV['LDAP_USERNAME'];
            $ldapPassword = $_ENV['LDAP_PASSWORD'];

            $this->ldap = Ldap::create('ext_ldap', ['connection_string' => $connectToLdap]);

            $this->ldap->bind($ldapUsername, $ldapPassword);
        } catch (LdapException $e) {
            echo 'LDAP Connection Error: ' . $e->getMessage();
            throw $e;
        }
    }

    public function getLdap(): Ldap
    {
        return $this->ldap;
    }
}

services.yaml

parameters:

services:
    # default configuration for services in *this* file
    _defaults:
        autowire: true      # Automatically injects dependencies in your services.
        autoconfigure: true # Automatically registers your services as commands, event subscribers, etc.
        bind:
            $ldapService: '@App\Service\LdapService'
    # makes classes in src/ available to be used as services
    # this creates a service per class whose id is the fully-qualified class name
    App\:
        resource: '../src/'
        exclude:
            - '../src/DependencyInjection/'
            - '../src/Entity/'
            - '../src/Kernel.php'
    App\Controller\:
        resource: '../src/Controller'
        tags: ['controller.service_arguments']
    # add more service definitions when explicit configuration is needed
    # please note that last definitions always *replace* previous ones
    
    # Explicitly configure the LdapService
    App\Service\LdapService:
        public: true

ExampleController.php

<?php

namespace App\Controller;

use App\Service\LdapService;

use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\Routing\Annotation\Route;
use Symfony\Component\Ldap\Exception\LdapException;

#[Route('/ldapuser', name: 'app_ldapuser.')]
class LdapUserController extends AbstractController
{
    private $ldapService;

    public function __construct(LdapService $ldapService)
    {
        $this->ldapService = $ldapService;
    }
}

解决方法

方法1:直接配置LDAP TLS选项(推荐)

Symfony的ext_ldap适配器支持直接设置TLS验证参数,替代环境变量方式,更可靠且无需依赖系统环境。修改LdapService.php中的LDAP实例创建代码:

$this->ldap = Ldap::create('ext_ldap', [
    'connection_string' => $connectToLdap,
    'tls_options' => [
        'verify_peer' => false,
        'verify_peer_name' => false,
    ],
    'version' => $_ENV['LDAP_VERSION'],
]);

同时删除.env.local中的LDAP_ENCRYPTION=tls配置项——ldaps://协议本身已自带加密,该选项用于普通LDAP连接后启动TLS,会造成逻辑冲突。

方法2:确保环境变量在Symfony启动前生效

若坚持使用环境变量方案,需保证LDAPTLS_REQCERT=never在Symfony内核初始化前加载:

  • 编辑Apache虚拟主机配置,添加SetEnv LDAPTLS_REQCERT never,随后重启Apache服务
  • 确保.env.local中的该变量在Symfony加载环境变量时被正确读取,但此方式优先级低于直接配置LDAP选项

方法3:系统级LDAP配置修改(仅测试环境使用)

编辑Ubuntu系统全局LDAP配置文件/etc/ldap/ldap.conf,添加或修改:

TLS_REQCERT never

此方式会全局禁用LDAP TLS证书验证,仅适合测试环境,生产环境不建议使用。


内容的提问来源于stack exchange,提问作者TheQuestionmark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 02:37:03