1 /* bind.c - ldap backend bind function */
5 * Copyright 1999, Howard Chu, All rights reserved. <hyc@highlandsun.com>
7 * Permission is granted to anyone to use this software for any purpose
8 * on any computer system, and to alter it and redistribute it, subject
9 * to the following restrictions:
11 * 1. The author is not responsible for the consequences of use of this
12 * software, no matter how awful, even if they arise from flaws in it.
14 * 2. The origin of this software must not be misrepresented, either by
15 * explicit claim or by omission. Since few users ever read sources,
16 * credits should appear in the documentation.
18 * 3. Altered versions must be plainly marked as such, and must not be
19 * misrepresented as being the original software. Since few users
20 * ever read sources, credits should appear in the documentation.
22 * 4. This notice may not be removed or altered.
29 #include <ac/socket.h>
30 #include <ac/string.h>
33 #include "back-ldap.h"
47 struct ldapinfo *li = (struct ldapinfo *) be->be_private;
52 lc = ldap_back_getconn(li, conn, op);
56 if (ldap_bind_s(lc->ld, dn, cred->bv_val, method) != LDAP_SUCCESS)
57 return( ldap_back_op_result(lc, op) );
64 ldap_back_getconn(struct ldapinfo *li, Connection *conn, Operation *op)
69 ldap_pvt_thread_mutex_lock( &li->conn_mutex );
70 for (lc = li->lcs; lc; lc=lc->next)
73 ldap_pvt_thread_mutex_unlock( &li->conn_mutex );
75 /* Looks like we didn't get a bind. Open a new session... */
77 int vers = conn->c_protocol;
78 int err = ldap_initialize(&ld, li->url);
79 if (err != LDAP_SUCCESS) {
80 err = ldap_back_map_result(err);
81 send_ldap_result( conn, op, err,
82 NULL, "ldap_init failed", NULL, NULL );
85 /* Set LDAP version. This will always succeed: If the client
86 * bound with a particular version, then so can we.
88 ldap_set_option(ld, LDAP_OPT_PROTOCOL_VERSION, &vers);
90 lc = (struct ldapconn *)ch_malloc(sizeof(struct ldapconn));
94 ldap_pvt_thread_mutex_lock( &li->conn_mutex );
97 ldap_pvt_thread_mutex_unlock( &li->conn_mutex );
103 ldap_back_dobind(struct ldapconn *lc, Operation *op)
108 if (ldap_bind_s(lc->ld, lc->conn->c_cdn, NULL, LDAP_AUTH_SIMPLE) !=
110 ldap_back_op_result(lc, op);
115 /* Map API errors to protocol errors... */
118 ldap_back_map_result(int err)
122 case LDAP_SERVER_DOWN:
123 return LDAP_UNAVAILABLE;
124 case LDAP_LOCAL_ERROR:
125 return LDAP_OPERATIONS_ERROR;
126 case LDAP_ENCODING_ERROR:
127 case LDAP_DECODING_ERROR:
128 return LDAP_PROTOCOL_ERROR;
130 return LDAP_UNAVAILABLE;
131 case LDAP_AUTH_UNKNOWN:
132 return LDAP_AUTH_METHOD_NOT_SUPPORTED;
133 case LDAP_FILTER_ERROR:
134 return LDAP_OPERATIONS_ERROR;
135 case LDAP_USER_CANCELLED:
136 return LDAP_OPERATIONS_ERROR;
137 case LDAP_PARAM_ERROR:
138 return LDAP_PROTOCOL_ERROR;
140 return LDAP_OPERATIONS_ERROR;
141 case LDAP_CONNECT_ERROR:
142 return LDAP_UNAVAILABLE;
143 case LDAP_NOT_SUPPORTED:
144 return LDAP_UNWILLING_TO_PERFORM;
145 case LDAP_CONTROL_NOT_FOUND:
146 return LDAP_PROTOCOL_ERROR;
147 case LDAP_NO_RESULTS_RETURNED:
148 return LDAP_NO_SUCH_OBJECT;
149 case LDAP_MORE_RESULTS_TO_RETURN:
151 case LDAP_CLIENT_LOOP:
152 case LDAP_REFERRAL_LIMIT_EXCEEDED:
153 return LDAP_LOOP_DETECT;
155 if LDAP_API_ERROR(err)
163 ldap_back_op_result(struct ldapconn *lc, Operation *op)
169 ldap_get_option(lc->ld, LDAP_OPT_ERROR_NUMBER, &err);
170 ldap_get_option(lc->ld, LDAP_OPT_ERROR_STRING, &msg);
171 ldap_get_option(lc->ld, LDAP_OPT_MATCHED_DN, &match);
172 err = ldap_back_map_result(err);
173 send_ldap_result( lc->conn, op, err, match, msg, NULL, NULL );
176 return( (err==LDAP_SUCCESS) ? 0 : -1 );