db-ldap.h revision 43d3ea2780b5f8557ede7b4c039e8f56cb8d357d
c25356d5978632df6203437e1953bcb29e0c736fTimo Sirainen#ifndef DB_LDAP_H
c25356d5978632df6203437e1953bcb29e0c736fTimo Sirainen#define DB_LDAP_H
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
cfdaa223525f87c9c980a25cc7bb6770a248d76aTimo Sirainen/* Functions like ldap_bind() have been deprecated in OpenLDAP 2.3
cfdaa223525f87c9c980a25cc7bb6770a248d76aTimo Sirainen This define enables them until the code here can be refactored */
cfdaa223525f87c9c980a25cc7bb6770a248d76aTimo Sirainen#define LDAP_DEPRECATED 1
cfdaa223525f87c9c980a25cc7bb6770a248d76aTimo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* Maximum number of requests in queue. After this new requests are dropped. */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen#define DB_LDAP_MAX_QUEUE_SIZE 1024
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* Maximum number of pending requests before delaying new requests. */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen#define DB_LDAP_MAX_PENDING_REQUESTS 128
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* If LDAP connection is down, fail requests after waiting for this long. */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen#define DB_LDAP_REQUEST_DISCONNECT_TIMEOUT_SECS 4
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* If request is still in queue after this many seconds and other requests
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen have been replied, assume the request was lost and abort it. */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen#define DB_LDAP_REQUEST_LOST_TIMEOUT_SECS 60
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* If server disconnects us, don't reconnect if no requests have been sent
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen for this many seconds. */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen#define DB_LDAP_IDLE_RECONNECT_SECS 60
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen#include <ldap.h>
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
3c9783956dea385b322cd7fa6bf8c98c17a907a0Timo Sirainenstruct auth_request;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainenstruct ldap_connection;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainenstruct ldap_request;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainentypedef void db_search_callback_t(struct ldap_connection *conn,
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen struct ldap_request *request,
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen LDAPMessage *res);
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainenstruct ldap_settings {
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen const char *hosts;
e65cc79f80577e83c706f0678c78e2c0bd91434fTimo Sirainen const char *uris;
7d6389e4053c2dac1fb37180b5756b00785983dcTimo Sirainen const char *dn;
7d6389e4053c2dac1fb37180b5756b00785983dcTimo Sirainen const char *dnpass;
6ef7e31619edfaa17ed044b45861d106a86191efTimo Sirainen bool auth_bind;
f1ddb98e6b639394ae205b305be1ddcfab102578Timo Sirainen const char *auth_bind_userdn;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen
40992309053d51192ae1b36d1dd6c057f2d37257Timo Sirainen bool tls;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen bool sasl_bind;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen const char *sasl_mech;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen const char *sasl_realm;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen const char *sasl_authz_id;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_ca_cert_file;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_ca_cert_dir;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_cert_file;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_key_file;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_cipher_suite;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen const char *tls_require_cert;
b96dcd982888d89e6f2508258d6d9588d79c7a26Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen const char *deref;
e82af44fe25ca9b88210f313548dc08538e4a677Timo Sirainen const char *scope;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen const char *base;
b567e0172c73dcf7642462e86962060358dd5f28Timo Sirainen unsigned int ldap_version;
b567e0172c73dcf7642462e86962060358dd5f28Timo Sirainen
f8464772990b52cb8de4553bc1135adcf72813b8Timo Sirainen const char *ldaprc_path;
f4a19b0cf11cdff437571708d9d788d02a906a00Timo Sirainen const char *debug_level;
f4a19b0cf11cdff437571708d9d788d02a906a00Timo Sirainen
10c5fd417af4ee30b68c967f5e7d5a49f4f149b5Timo Sirainen const char *user_attrs;
10c5fd417af4ee30b68c967f5e7d5a49f4f149b5Timo Sirainen const char *user_filter;
10c5fd417af4ee30b68c967f5e7d5a49f4f149b5Timo Sirainen const char *pass_attrs;
10c5fd417af4ee30b68c967f5e7d5a49f4f149b5Timo Sirainen const char *pass_filter;
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen const char *iterate_attrs;
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen const char *iterate_filter;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
473080c7c0d25ddfdf77e7dfa0ba8f73c6c669d5Timo Sirainen const char *default_pass_scheme;
1f18053d463f0294387b5e4dd11f9010bda9a24eTimo Sirainen
6ef7e31619edfaa17ed044b45861d106a86191efTimo Sirainen /* ... */
e82af44fe25ca9b88210f313548dc08538e4a677Timo Sirainen int ldap_deref, ldap_scope;
e714eed72515794c46c6712a611e5ab924d903daTimo Sirainen uid_t uid;
e714eed72515794c46c6712a611e5ab924d903daTimo Sirainen gid_t gid;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen};
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenenum ldap_request_type {
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_REQUEST_TYPE_SEARCH,
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_REQUEST_TYPE_BIND
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen};
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenstruct ldap_request {
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen enum ldap_request_type type;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* msgid for sent requests, -1 if not sent */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen int msgid;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* timestamp when request was created */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen time_t create_time;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen db_search_callback_t *callback;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen struct auth_request *auth_request;
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen /* If expect_one_reply=TRUE, this contains the first LDAP entry.
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen If another one comes, we'll return an error. */
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen LDAPMessage *first_entry;
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen unsigned int expect_one_reply:1;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen};
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenstruct ldap_request_search {
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen struct ldap_request request;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen const char *base;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen const char *filter;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen char **attributes; /* points to pass_attr_names / user_attr_names */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen};
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenstruct ldap_request_bind {
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen struct ldap_request request;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen const char *dn;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen};
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenenum ldap_connection_state {
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Not connected */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_CONN_STATE_DISCONNECTED,
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Binding - either to default dn or doing auth bind */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_CONN_STATE_BINDING,
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Bound to auth dn */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_CONN_STATE_BOUND_AUTH,
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Bound to default dn */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen LDAP_CONN_STATE_BOUND_DEFAULT
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen};
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainenstruct ldap_connection {
c4457e497e01b57565d24da624968699b166e02aTimo Sirainen struct ldap_connection *next;
c4457e497e01b57565d24da624968699b166e02aTimo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen pool_t pool;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen int refcount;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen char *config_path;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen struct ldap_settings set;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen LDAP *ld;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen enum ldap_connection_state conn_state;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen int default_bind_msgid;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen int fd;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen struct io *io;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen struct timeout *to;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Request queue contains sent requests at tail (msgid != -1) and
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen queued requests at head (msgid == -1). */
63cde222abaaa2a9bdaa9a143698dbc8b23bd742Timo Sirainen struct aqueue *request_queue;
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen ARRAY_DEFINE(request_array, struct ldap_request *);
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Number of messages in queue with msgid != -1 */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen unsigned int pending_count;
e023e3c2677ab66d7a7445eae9caf3d739e199cbTimo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen /* Timestamp when we last received a reply */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen time_t last_reply_stamp;
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen char **pass_attr_names, **user_attr_names, **iterate_attr_names;
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen struct hash_table *pass_attr_map, *user_attr_map, *iterate_attr_map;
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen};
a399486f2d8d5bed51bc6344baba61a7f2b0dcdbTimo Sirainen
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen/* Send/queue request */
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainenvoid db_ldap_request(struct ldap_connection *conn,
fc4ff2356fee6389d4cf2b3f12f4098a436f0502Timo Sirainen struct ldap_request *request);
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
9f431ccfb6932746db56245c8a3d3415717ef545Timo Sirainenvoid db_ldap_set_attrs(struct ldap_connection *conn, const char *attrlist,
0d7d27765267594a5870892268ab345148306d49Timo Sirainen char ***attr_names_r, struct hash_table *attr_map,
16133a719ce8b6a5b8cedd721340cc1607c43433Timo Sirainen const char *skip_attr);
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainenstruct ldap_connection *db_ldap_init(const char *config_path);
d5cebe7f98e63d4e2822863ef2faa4971e8b3a5dTimo Sirainenvoid db_ldap_unref(struct ldap_connection **conn);
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen
16133a719ce8b6a5b8cedd721340cc1607c43433Timo Sirainenint db_ldap_connect(struct ldap_connection *conn);
08aea01ef9a9d20703e0fcf8618e6195c0037a44Timo Sirainen
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainenvoid db_ldap_enable_input(struct ldap_connection *conn, bool enable);
43d3ea2780b5f8557ede7b4c039e8f56cb8d357dTimo Sirainen
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainenstruct var_expand_table *
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainendb_ldap_value_get_var_expand_table(struct auth_request *auth_request);
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen
3c9783956dea385b322cd7fa6bf8c98c17a907a0Timo Sirainenconst char *ldap_escape(const char *str,
3c9783956dea385b322cd7fa6bf8c98c17a907a0Timo Sirainen const struct auth_request *auth_request);
ebfcfd258acc89633c47d9c3b0b40a1a3f75cdcbTimo Sirainenconst char *ldap_get_error(struct ldap_connection *conn);
d1f0acc7fc722e13e8296228703adfe8a884d59eTimo Sirainen
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainenstruct db_ldap_result_iterate_context *
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainendb_ldap_result_iterate_init(struct ldap_connection *conn, LDAPMessage *entry,
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen struct auth_request *auth_request,
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen struct hash_table *attr_map);
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainenbool db_ldap_result_iterate_next(struct db_ldap_result_iterate_context *ctx,
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen const char **name_r, const char **value_r);
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainenbool db_ldap_result_iterate_next_all(struct db_ldap_result_iterate_context *ctx,
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen const char **name_r,
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen const char *const **values_r);
4261a8b43792dc4db4b39e6910319835b7450e84Timo Sirainen
965ed6ea3fc8f7637bd0d159d2fdb283a191ce34Timo Sirainen#endif