Many business applications let staff sign in with their company directory account through LDAP, for example against Active Directory or OpenLDAP. In PHP this needs the ldap extension, and it needs the web server to be able to reach your directory server over the network. This article answers plainly what works on Domain India hosting and where you should run an LDAP-connected application instead.
On our cPanel shared server, the PHP ldap extension is loaded in PHP 7.0 to 8.5 (except 8.0). On our DirectAdmin shared server it isn't installed for any PHP version. But on both servers the firewall doesn't allow outgoing connections on the LDAP ports 389 and 636, so a site on shared hosting can't reach an outside directory server anyway. For LDAP sign-in, use a VPS, where you control PHP and the firewall.
1. What LDAP authentication needs
LDAP (Lightweight Directory Access Protocol) is how applications look up users and check passwords in a directory service. A PHP application that logs users in through LDAP needs two things:
ldap_connect(), ldap_bind() and ldap_search(). Frameworks and plugins (Laravel packages, WordPress and Moodle LDAP plugins, Nextcloud) all use it underneath.Having the extension is not enough on its own. If the connection to port 389 or 636 is blocked, ldap_bind() fails with "Can't contact LDAP server", whatever the code does.
2. The answer for each Domain India plan
We checked our servers on 24 September 2026:
| Hosting | PHP ldap extension | Outgoing LDAP ports (389, 636) | LDAP sign-in practical? |
|---|---|---|---|
| cPanel shared hosting | Loaded in PHP 7.0 to 8.5, except PHP 8.0 | Not allowed by the server firewall | No |
| DirectAdmin shared hosting | Not installed for any PHP version | Not allowed by the server firewall | No |
| Webuzo shared hosting | Not checked | Not checked | Ask support |
| VPS | You install it | You open them | Yes |
On cPanel the extension appears in both the command-line PHP and the PHP-FPM builds that serve websites. It is the firewall, not PHP, that stops LDAP sign-in on shared hosting. Outgoing connections from shared servers are limited to a fixed list of ports (web, mail, FTP, SSH, DNS and a few others), and the LDAP ports are not on it. The list is set for the whole server, not per account, so ask support before you plan around an exception.
Moving your directory server to port 443 or 80 to slip through the firewall, or opening your Active Directory to the whole internet, is a serious security risk. Keep the directory private and run the LDAP-connected application somewhere that can reach it safely, such as a VPS on a restricted firewall rule or a VPN.
3. Check what your own account has
On cPanel you can confirm the extension for the PHP version your site uses. Create a small file with a hard-to-guess name, open it once in the browser, then delete it:
<?php
// ldap-check-7f3a9.php — delete after use
var_dump(extension_loaded('ldap'));bool(true) means the extension is loaded. It does not mean your directory is reachable. To see which PHP version your domain runs and to switch it, see how to change your PHP version. Note that phpinfo() is disabled on our cPanel server, which is why the check above uses extension_loaded().
4. Running LDAP sign-in on a VPS
A Domain India VPS is self-managed: you get root access and choose the software. There is no cPanel on a VPS. On a current Linux distribution, installing the extension takes one command:
# Debian / Ubuntu
sudo apt install php-ldap
# AlmaLinux / Rocky Linux (with the distribution's PHP packages)
sudo dnf install php-ldapRestart PHP-FPM (or your web server) afterwards, then allow outgoing traffic to your directory server only. Prefer LDAPS on port 636, or StartTLS on 389, so passwords never cross the network in plain text:
<?php
$conn = ldap_connect('ldaps://dc1.example.in:636');
ldap_set_option($conn, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_set_option($conn, LDAP_OPT_REFERRALS, 0);
$userDn = sprintf('uid=%s,ou=people,dc=example,dc=in', ldap_escape($username, '', LDAP_ESCAPE_DN));
if ($password !== '' && @ldap_bind($conn, $userDn, $password)) {
// signed in
}Two details matter for security. Always reject an empty password before calling ldap_bind(), because many directories treat an empty password as an anonymous bind and report success. And escape user input with ldap_escape() to prevent LDAP injection.
If your directory is on your office network, connect the VPS to it over a VPN (for example WireGuard) rather than exposing the directory publicly. For firewall and SSH basics on your own server, see the VPS security and optimisation tips.
5. Alternatives to LDAP on shared hosting
If you want company sign-in but prefer to stay on shared hosting, consider single sign-on over HTTPS instead of LDAP. Microsoft Entra ID (the former Azure AD), Google Workspace and most identity providers support OpenID Connect or SAML, which use ordinary HTTPS on port 443. Many PHP applications and WordPress plugins support these protocols, and they work through the normal outgoing web ports. Test the specific plugin on your plan before you rely on it, because some libraries need PHP functions that shared hosting disables; see PHP disabled functions on shared hosting.
6. Where Domain India fits
For an application that must talk to your directory server over LDAP, choose a VPS, where you control PHP, the firewall and the network:
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
The card shows the Domain India list price on 19 September 2026, excluding 18% GST. See all sizes on VPS servers. For a website that doesn't need LDAP, cPanel hosting remains the simpler choice.
7. Frequently asked questions
Is the PHP LDAP extension available on Domain India cPanel hosting?
Yes. On Domain India's cPanel shared server, the ldap extension is loaded in PHP 7.0 to 8.5, except PHP 8.0. However, the server firewall does not allow outgoing connections on the LDAP ports 389 and 636, so a site cannot reach an external directory server.
Is the LDAP extension available on DirectAdmin hosting?
No. On Domain India's DirectAdmin shared server, PHP is built without the ldap extension for every version, and the LDAP ports are also closed for outgoing connections.
Can support open port 389 or 636 for my account?
The outgoing port list on Domain India shared servers is set for the whole server, not per account, so an exception for one site is unlikely. Ask support if you need it; the reliable route for LDAP sign-in is a VPS, where you control the firewall.
Can I use LDAP authentication on a Domain India VPS?
Yes. A VPS is self-managed with root access, so you install the php-ldap package, allow outgoing traffic to your directory server and configure your application. Use LDAPS or StartTLS so passwords are encrypted.
What can I use instead of LDAP on shared hosting?
Single sign-on with OpenID Connect or SAML, offered by Microsoft Entra ID, Google Workspace and other identity providers. These use HTTPS on port 443, which shared hosting allows. Test the plugin or library on your plan first.
Why does ldap_bind() say "Can't contact LDAP server"?
The web server cannot open a network connection to the directory. On Domain India shared hosting this is expected, because the LDAP ports are closed for outgoing connections. On your own server, check the firewall, the hostname and the port.
Ready to build company sign-in? Compare VPS plans, or open a support ticket and tell us which application and directory you use, and we will suggest the right setup.
Tell us what your application needs, and our support team will recommend shared hosting or a VPS.
Ask our team