]> git.sur5r.net Git - openldap/blob - servers/slapd/sasl.c
e51de293a9cb0d4dca6ed392bd12d7e1e848f993
[openldap] / servers / slapd / sasl.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-1999 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6
7 #include "portable.h"
8
9 #include <ac/stdlib.h>
10 #include <stdio.h>
11
12 #include "slap.h"
13 #include "proto-slap.h"
14
15 #include <lber.h>
16 #include <ldap_log.h>
17
18 char **supportedSASLMechanisms = NULL;
19 char *sasl_host = NULL;
20
21 #ifdef HAVE_CYRUS_SASL
22 static void *slap_sasl_mutex_new(void)
23 {
24         ldap_pvt_thread_mutex_t *mutex;
25
26         mutex = (ldap_pvt_thread_mutex_t *) ch_malloc( sizeof(ldap_pvt_thread_mutex_t) );
27         if ( ldap_pvt_thread_mutex_init( mutex ) == 0 ) {
28                 return mutex;
29         }
30         return NULL;
31 }
32
33 static int slap_sasl_mutex_lock(void *mutex)
34 {
35         return ldap_pvt_thread_mutex_lock( (ldap_pvt_thread_mutex_t *)mutex );
36 }
37
38 static int slap_sasl_mutex_unlock(void *mutex)
39 {
40         return ldap_pvt_thread_mutex_unlock( (ldap_pvt_thread_mutex_t *)mutex );
41 }
42
43 static void slap_sasl_mutex_dispose(void *mutex)
44 {
45         (void) ldap_pvt_thread_mutex_destroy( (ldap_pvt_thread_mutex_t *)mutex );
46         free( mutex );
47 }
48
49 static int
50 slap_sasl_err2ldap( int saslerr )
51 {
52         int rc;
53
54         switch (saslerr) {
55                 case SASL_CONTINUE:
56                         rc = LDAP_SASL_BIND_IN_PROGRESS;
57                         break;
58                 case SASL_OK:
59                         rc = LDAP_SUCCESS;
60                         break;
61                 case SASL_FAIL:
62                         rc = LDAP_OTHER;
63                         break;
64                 case SASL_NOMEM:
65                         rc = LDAP_OTHER;
66                         break;
67                 case SASL_NOMECH:
68                         rc = LDAP_AUTH_METHOD_NOT_SUPPORTED;
69                         break;
70                 case SASL_BADAUTH:
71                         rc = LDAP_INVALID_CREDENTIALS;
72                         break;
73                 case SASL_NOAUTHZ:
74                         rc = LDAP_INSUFFICIENT_ACCESS;
75                         break;
76                 case SASL_TOOWEAK:
77                 case SASL_ENCRYPT:
78                         rc = LDAP_INAPPROPRIATE_AUTH;
79                         break;
80                 default:
81                         rc = LDAP_OTHER;
82                         break;
83         }
84
85         return rc;
86 }
87
88
89 int sasl_init( void )
90 {
91         int rc;
92         char *mechs;
93         sasl_conn_t *server = NULL;
94
95         sasl_set_alloc( ch_malloc, ch_calloc, ch_realloc, ch_free ); 
96
97         sasl_set_mutex(
98                 slap_sasl_mutex_new,
99                 slap_sasl_mutex_lock,
100                 slap_sasl_mutex_unlock,
101                 slap_sasl_mutex_dispose );
102
103         rc = sasl_server_init( NULL, "slapd" );
104
105         if( rc != SASL_OK ) {
106                 Debug( LDAP_DEBUG_ANY, "sasl_server_init failed\n",
107                         0, 0, 0 );
108                 return -1;
109         }
110
111         if( sasl_host == NULL ) {
112                 char hostname[MAXHOSTNAMELEN+1];
113
114                 if( gethostname( hostname, MAXHOSTNAMELEN ) == 0 ) {
115                         hostname[MAXHOSTNAMELEN] = '\0';
116                         sasl_host = hostname;
117                 }
118         }
119
120         rc = sasl_server_new( "ldap", sasl_host, NULL, NULL,
121                 SASL_SECURITY_LAYER, 
122                 &server );
123
124         if( rc != SASL_OK ) {
125                 Debug( LDAP_DEBUG_ANY, "sasl_server_new failed\n",
126                         0, 0, 0 );
127                 return -1;
128         }
129
130 #ifdef RESTRICT_SASL
131         {
132                 sasl_security_properties_t secprops;
133                 memset(&secprops, 0, sizeof(secprops));
134                 secprops.security_flags = SASL_SEC_NOPLAINTEXT | SASL_SEC_NOANONYMOUS;
135                 secprops.property_names = NULL;
136                 secprops.property_values = NULL;
137         
138                 rc = sasl_setprop( server, SASL_SEC_PROPS, &secprops );
139
140                 if( rc != SASL_OK ) {
141                         Debug( LDAP_DEBUG_ANY, "sasl_setprop failed\n",
142                                 0, 0, 0 );
143                         return -1;
144                 }
145         }
146 #endif
147
148         rc = sasl_listmech( server, NULL, NULL, ",", NULL,
149                 &mechs, NULL, NULL);
150
151         if( rc != SASL_OK ) {
152                 Debug( LDAP_DEBUG_ANY, "sasl_listmech failed: %d\n",
153                         rc, 0, 0 );
154                 return -1;
155         }
156
157         Debug( LDAP_DEBUG_TRACE, "SASL mechanisms: %s\n",
158                 mechs, 0, 0 );
159
160         supportedSASLMechanisms = str2charray( mechs, "," );
161         sasl_dispose( &server );
162
163         return 0;
164 }
165
166 int sasl_destroy( void )
167 {
168         charray_free( supportedSASLMechanisms );
169         return 0;
170 }
171
172 #ifdef HAVE_CYRUS_SASL
173 int sasl_bind(
174     Connection          *conn,
175     Operation           *op,  
176     char                *dn,  
177     char                *ndn,
178     char                *mech,
179     struct berval       *cred,
180         char                            **edn )
181 {
182         struct berval response;
183         const char *errstr;
184         int sc;
185         int rc = 1;
186
187         Debug(LDAP_DEBUG_ARGS, "==> sasl_bind: dn=%s, mech=%s, cred->bv_len=%d\n",
188                 dn, mech, cred ? cred->bv_len : 0 );
189
190         if ( conn->c_sasl_bind_context == NULL ) {
191                 sasl_callback_t callbacks[4];
192                 int cbnum = 0;
193
194 #if 0
195                 if (be->be_sasl_authorize) {
196                         callbacks[cbnum].id = SASL_CB_PROXY_POLICY;
197                         callbacks[cbnum].proc = be->be_sasl_authorize;
198                         callbacks[cbnum].context = be;
199                         ++cbnum;
200                 }
201
202                 if (be->be_sasl_getsecret) {
203                         callbacks[cbnum].id = SASL_CB_SERVER_GETSECRET;
204                         callbacks[cbnum].proc = be->be_sasl_getsecret;
205                         callbacks[cbnum].context = be;
206                         ++cbnum;
207                 }
208
209                 if (be->be_sasl_putsecret) {
210                         callbacks[cbnum].id = SASL_CB_SERVER_PUTSECRET;
211                         callbacks[cbnum].proc = be->be_sasl_putsecret;
212                         callbacks[cbnum].context = be;
213                         ++cbnum;
214                 }
215 #endif
216
217                 callbacks[cbnum].id = SASL_CB_LIST_END;
218                 callbacks[cbnum].proc = NULL;
219                 callbacks[cbnum].context = NULL;
220
221                 /* create new SASL context */
222                 sc = sasl_server_new( "ldap", sasl_host, global_realm,
223                         callbacks, SASL_SECURITY_LAYER, &conn->c_sasl_bind_context );
224
225                 if( sc != SASL_OK ) {
226                         send_ldap_result( conn, op, rc = LDAP_AUTH_METHOD_NOT_SUPPORTED,
227                                 NULL, NULL, NULL, NULL );
228                 } else {
229                         conn->c_authmech = ch_strdup( mech );
230                         sc = sasl_server_start( conn->c_sasl_bind_context, conn->c_authmech,
231                                 cred->bv_val, cred->bv_len, (char **)&response.bv_val,
232                                 (unsigned *)&response.bv_len, &errstr );
233                         if ( (sc != SASL_OK) && (sc != SASL_CONTINUE) ) {
234                                 send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
235                                         NULL, errstr, NULL, NULL );
236                         }
237                 }
238         } else {
239                 sc = sasl_server_step( conn->c_sasl_bind_context, cred->bv_val, cred->bv_len,
240                         (char **)&response.bv_val, (unsigned *)&response.bv_len, &errstr );
241                 if ( (sc != SASL_OK) && (sc != SASL_CONTINUE) ) {
242                         send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
243                                 NULL, errstr, NULL, NULL );
244                 }
245         }
246
247         if ( sc == SASL_OK ) {
248                 char *authzid;
249
250                 if ( ( sc = sasl_getprop( conn->c_sasl_bind_context, SASL_USERNAME,
251                         (void **)&authzid ) ) != SASL_OK ) {
252                         send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
253                                 NULL, NULL, NULL, NULL );
254
255                 } else {
256                         Debug(LDAP_DEBUG_TRACE, "<== sasl_bind: username=%s\n",
257                                 authzid, 0, 0);
258
259                         if( strncasecmp( authzid, "anonymous", sizeof("anonyous")-1 ) &&
260                                 ( ( authzid[sizeof("anonymous")] == '\0' ) ||
261                                 ( authzid[sizeof("anonymous")] == '@' ) ) )
262                         {
263                                 *edn = ch_malloc( sizeof( "authzid=" ) + strlen( authzid ) );
264                                 strcpy( *edn, "authzid=" );
265                                 strcat( *edn, authzid );
266                         }
267
268                         send_ldap_result( conn, op, rc = LDAP_SUCCESS,
269                                 NULL, NULL, NULL, NULL );
270                 }
271
272         } else if ( sc == SASL_CONTINUE ) {
273                 send_ldap_sasl( conn, op, rc = LDAP_SASL_BIND_IN_PROGRESS,
274                         NULL, NULL, NULL, NULL,  &response );
275         } 
276
277         if ( sc != SASL_CONTINUE && conn->c_sasl_bind_context != NULL ) {
278                 sasl_dispose( &conn->c_sasl_bind_context );
279                 conn->c_sasl_bind_context = NULL;
280         }
281
282         Debug(LDAP_DEBUG_TRACE, "<== sasl_bind: rc=%d\n", rc, 0, 0);
283
284         return rc;
285 }
286 #endif /* HAVE_CYRUS_SASL */
287
288 #else
289 /* no SASL support */
290 int sasl_bind(
291     Connection          *conn,
292     Operation           *op,  
293     char                *dn,  
294     char                *ndn,
295     char                *mech,
296     struct berval       *cred,
297         char                            **edn )
298 {
299         int rc;
300
301         send_ldap_result( conn, op, rc = LDAP_UNWILLING_TO_PERFORM,
302                 NULL, "SASL unavailable", NULL, NULL );
303
304         return rc;
305 }
306
307 int sasl_init( void ) { return 0; }
308 int sasl_destroy( void ) { return 0; }
309 #endif