45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk/*
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * CDDL HEADER START
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk *
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * The contents of this file are subject to the terms of the
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * Common Development and Distribution License (the "License").
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * You may not use this file except in compliance with the License.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk *
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * or http://www.opensolaris.org/os/licensing.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * See the License for the specific language governing permissions
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * and limitations under the License.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk *
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * When distributing Covered Code, include this CDDL HEADER in each
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * If applicable, add the following below this CDDL HEADER, with the
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * fields enclosed by brackets "[]" replaced with your own identifying
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * information: Portions Copyright [yyyy] [name of copyright owner]
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk *
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * CDDL HEADER END
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk/*
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * Copyright 2006 Sun Microsystems, Inc. All rights reserved.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk * Use is subject to license terms.
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#pragma ident "%Z%%M% %I% %E% SMI"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <netdb.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include "ldap_common.h"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <sys/types.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <sys/socket.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <netinet/in.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <arpa/inet.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#include <sys/tsol/tndb.h>
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk/* tnrhdb attributes filters */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#define _TNRHDB_ADDR "ipTnetNumber"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#define _TNRHDB_TNAME "ipTnetTemplateName"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#define _F_GETTNDBBYADDR "(&(objectClass=ipTnetHost)(ipTnetNumber=%s))"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk#define _F_GETTNDBBYADDR_SSD "(&(%%s)(ipTnetNumber=%s))"
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpkstatic const char *tnrhdb_attrs[] = {
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _TNRHDB_ADDR,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _TNRHDB_TNAME,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk NULL
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk};
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjlstatic void
cb5caa98562cf06753163f558cbcfe30b8f4673adjlescape_colon(char *in, char *out) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl int i, j;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl for (i = 0, j = 0; in[i] != '\0'; i++) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (in[i] == ':') {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl out[j++] = '\\';
cb5caa98562cf06753163f558cbcfe30b8f4673adjl out[j++] = in[i];
cb5caa98562cf06753163f558cbcfe30b8f4673adjl } else
cb5caa98562cf06753163f558cbcfe30b8f4673adjl out[j++] = in[i];
cb5caa98562cf06753163f558cbcfe30b8f4673adjl }
cb5caa98562cf06753163f558cbcfe30b8f4673adjl out[j] = '\0';
cb5caa98562cf06753163f558cbcfe30b8f4673adjl}
cb5caa98562cf06753163f558cbcfe30b8f4673adjl
cb5caa98562cf06753163f558cbcfe30b8f4673adjl/*
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * _nss_ldap_tnrhdb2str is the data marshaling method for the tnrhdb
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * (tsol_getrhbyaddr()/tsol_getrhent()) backend processes.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * This method is called after a successful ldap search has been performed.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * This method will parse the ldap search values into the file format.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl *
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * e.g.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl *
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * 192.168.120.6:public
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * fec0\:\:a00\:20ff\:fea0\:21f7:cipso
cb5caa98562cf06753163f558cbcfe30b8f4673adjl *
cb5caa98562cf06753163f558cbcfe30b8f4673adjl */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpkstatic int
cb5caa98562cf06753163f558cbcfe30b8f4673adjl_nss_ldap_tnrhdb2str(ldap_backend_ptr be, nss_XbyY_args_t *argp)
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk{
cb5caa98562cf06753163f558cbcfe30b8f4673adjl int nss_result = NSS_STR_PARSE_SUCCESS;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk int len = 0;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk char *buffer = NULL;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl char **addr, **template, *addr_out;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk ns_ldap_result_t *result = be->result;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl char addr6[INET6_ADDRSTRLEN + 5]; /* 5 '\' for ':' at most */
cb5caa98562cf06753163f558cbcfe30b8f4673adjl
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (result == NULL)
cb5caa98562cf06753163f558cbcfe30b8f4673adjl return (NSS_STR_PARSE_PARSE);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjl addr = __ns_ldap_getAttr(result->entry, _TNRHDB_ADDR);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (addr == NULL || addr[0] == NULL || (strlen(addr[0]) < 1)) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl nss_result = NSS_STR_PARSE_PARSE;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl goto result_tnrhdb2str;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk }
cb5caa98562cf06753163f558cbcfe30b8f4673adjl
cb5caa98562cf06753163f558cbcfe30b8f4673adjl /*
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * Escape ':' in IPV6.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * The value is stored in LDAP directory without escape charaters.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl */
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (strchr(addr[0], ':') != NULL) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl escape_colon(addr[0], addr6);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl addr_out = addr6;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl } else
cb5caa98562cf06753163f558cbcfe30b8f4673adjl addr_out = addr[0];
cb5caa98562cf06753163f558cbcfe30b8f4673adjl
cb5caa98562cf06753163f558cbcfe30b8f4673adjl template = __ns_ldap_getAttr(result->entry, _TNRHDB_TNAME);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (template == NULL || template[0] == NULL ||
cb5caa98562cf06753163f558cbcfe30b8f4673adjl (strlen(template[0]) < 1)) {
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk nss_result = NSS_STR_PARSE_PARSE;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl goto result_tnrhdb2str;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk }
cb5caa98562cf06753163f558cbcfe30b8f4673adjl /* "addr:template" */
cb5caa98562cf06753163f558cbcfe30b8f4673adjl len = strlen(addr_out) + strlen(template[0]) + 2;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (argp->buf.result != NULL) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if ((be->buffer = calloc(1, len)) == NULL) {
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk nss_result = NSS_STR_PARSE_PARSE;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl goto result_tnrhdb2str;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk }
cb5caa98562cf06753163f558cbcfe30b8f4673adjl be->buflen = len - 1;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl buffer = be->buffer;
cb5caa98562cf06753163f558cbcfe30b8f4673adjl } else
cb5caa98562cf06753163f558cbcfe30b8f4673adjl buffer = argp->buf.buffer;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjl (void) snprintf(buffer, len, "%s:%s", addr_out, template[0]);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjlresult_tnrhdb2str:
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk (void) __ns_ldap_freeResult(&be->result);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk return (nss_result);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk}
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpkstatic nss_status_t
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpkgetbyaddr(ldap_backend_ptr be, void *a)
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk{
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk char searchfilter[SEARCHFILTERLEN];
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk char userdata[SEARCHFILTERLEN];
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk nss_XbyY_args_t *argp = (nss_XbyY_args_t *)a;
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (argp->key.hostaddr.addr == NULL ||
cb5caa98562cf06753163f558cbcfe30b8f4673adjl (argp->key.hostaddr.type != AF_INET &&
cb5caa98562cf06753163f558cbcfe30b8f4673adjl argp->key.hostaddr.type != AF_INET6))
cb5caa98562cf06753163f558cbcfe30b8f4673adjl return (NSS_NOTFOUND);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (strchr(argp->key.hostaddr.addr, ':') != NULL) {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl /* IPV6 */
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (argp->key.hostaddr.type == AF_INET)
cb5caa98562cf06753163f558cbcfe30b8f4673adjl return (NSS_NOTFOUND);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl } else {
cb5caa98562cf06753163f558cbcfe30b8f4673adjl /* IPV4 */
cb5caa98562cf06753163f558cbcfe30b8f4673adjl if (argp->key.hostaddr.type == AF_INET6)
cb5caa98562cf06753163f558cbcfe30b8f4673adjl return (NSS_NOTFOUND);
cb5caa98562cf06753163f558cbcfe30b8f4673adjl }
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
cb5caa98562cf06753163f558cbcfe30b8f4673adjl /*
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * The IPV6 addresses are saved in the directory without '\'s.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl * So don't need to escape colons in IPV6 addresses.
cb5caa98562cf06753163f558cbcfe30b8f4673adjl */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk if (snprintf(searchfilter, sizeof (searchfilter), _F_GETTNDBBYADDR,
cb5caa98562cf06753163f558cbcfe30b8f4673adjl argp->key.hostaddr.addr) < 0)
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk return ((nss_status_t)NSS_NOTFOUND);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk if (snprintf(userdata, sizeof (userdata), _F_GETTNDBBYADDR_SSD,
cb5caa98562cf06753163f558cbcfe30b8f4673adjl argp->key.hostaddr.addr) < 0)
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk return ((nss_status_t)NSS_NOTFOUND);
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk return (_nss_ldap_lookup(be, argp, _TNRHDB, searchfilter, NULL,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _merge_SSD_filter, userdata));
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk}
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpkstatic ldap_backend_op_t tnrhdb_ops[] = {
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _nss_ldap_destr,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _nss_ldap_endent,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _nss_ldap_setent,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk _nss_ldap_getent,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk getbyaddr
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk};
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk/* ARGSUSED */
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpknss_backend_t *
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk_nss_ldap_tnrhdb_constr(const char *dummy1,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk const char *dummy2,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk const char *dummy3,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk const char *dummy4,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk const char *dummy5)
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk{
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk return ((nss_backend_t *)_nss_ldap_constr(tnrhdb_ops,
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk sizeof (tnrhdb_ops)/sizeof (tnrhdb_ops[0]), _TNRHDB,
cb5caa98562cf06753163f558cbcfe30b8f4673adjl tnrhdb_attrs, _nss_ldap_tnrhdb2str));
45916cd2fec6e79bca5dee0421bd39e3c2910d1ejpk}