]> git.sur5r.net Git - openldap/blob - servers/slapd/sasl.c
Change reporting of SASL username
[openldap] / servers / slapd / sasl.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6
7 #include "portable.h"
8
9 #include <ac/stdlib.h>
10 #include <stdio.h>
11
12 #include "slap.h"
13 #include "proto-slap.h"
14
15 #include <lber.h>
16 #include <ldap_log.h>
17
18 char **supportedSASLMechanisms = NULL;
19 char *sasl_host = NULL;
20
21 #ifdef HAVE_CYRUS_SASL
22
23 #ifdef SLAPD_SPASSWD
24 #include <lutil.h>
25 #endif
26
27 static void *slap_sasl_mutex_new(void)
28 {
29         ldap_pvt_thread_mutex_t *mutex;
30
31         mutex = (ldap_pvt_thread_mutex_t *) ch_malloc( sizeof(ldap_pvt_thread_mutex_t) );
32         if ( ldap_pvt_thread_mutex_init( mutex ) == 0 ) {
33                 return mutex;
34         }
35         return NULL;
36 }
37
38 static int slap_sasl_mutex_lock(void *mutex)
39 {
40         return ldap_pvt_thread_mutex_lock( (ldap_pvt_thread_mutex_t *)mutex );
41 }
42
43 static int slap_sasl_mutex_unlock(void *mutex)
44 {
45         return ldap_pvt_thread_mutex_unlock( (ldap_pvt_thread_mutex_t *)mutex );
46 }
47
48 static void slap_sasl_mutex_dispose(void *mutex)
49 {
50         (void) ldap_pvt_thread_mutex_destroy( (ldap_pvt_thread_mutex_t *)mutex );
51         free( mutex );
52 }
53
54 static int
55 slap_sasl_err2ldap( int saslerr )
56 {
57         int rc;
58
59         switch (saslerr) {
60                 case SASL_CONTINUE:
61                         rc = LDAP_SASL_BIND_IN_PROGRESS;
62                         break;
63                 case SASL_OK:
64                         rc = LDAP_SUCCESS;
65                         break;
66                 case SASL_FAIL:
67                         rc = LDAP_OTHER;
68                         break;
69                 case SASL_NOMEM:
70                         rc = LDAP_OTHER;
71                         break;
72                 case SASL_NOMECH:
73                         rc = LDAP_AUTH_METHOD_NOT_SUPPORTED;
74                         break;
75                 case SASL_BADAUTH:
76                         rc = LDAP_INVALID_CREDENTIALS;
77                         break;
78                 case SASL_NOAUTHZ:
79                         rc = LDAP_INSUFFICIENT_ACCESS;
80                         break;
81                 case SASL_TOOWEAK:
82                 case SASL_ENCRYPT:
83                         rc = LDAP_INAPPROPRIATE_AUTH;
84                         break;
85                 default:
86                         rc = LDAP_OTHER;
87                         break;
88         }
89
90         return rc;
91 }
92
93
94 int sasl_init( void )
95 {
96         int rc;
97         char *mechs;
98         sasl_conn_t *server = NULL;
99
100         sasl_set_alloc( ch_malloc, ch_calloc, ch_realloc, ch_free ); 
101
102         sasl_set_mutex(
103                 slap_sasl_mutex_new,
104                 slap_sasl_mutex_lock,
105                 slap_sasl_mutex_unlock,
106                 slap_sasl_mutex_dispose );
107
108         /* server name should be configurable */
109         rc = sasl_server_init( NULL, "slapd" );
110
111         if( rc != SASL_OK ) {
112                 Debug( LDAP_DEBUG_ANY, "sasl_server_init failed\n",
113                         0, 0, 0 );
114                 return -1;
115         }
116
117         if( sasl_host == NULL ) {
118                 static char hostname[MAXHOSTNAMELEN+1];
119
120                 if( gethostname( hostname, MAXHOSTNAMELEN ) == 0 ) {
121                         hostname[MAXHOSTNAMELEN] = '\0';
122                         sasl_host = hostname;
123                 }
124         }
125
126         rc = sasl_server_new( "ldap", sasl_host, NULL, NULL,
127                 SASL_SECURITY_LAYER, 
128                 &server );
129
130         if( rc != SASL_OK ) {
131                 Debug( LDAP_DEBUG_ANY, "sasl_server_new failed\n",
132                         0, 0, 0 );
133                 return -1;
134         }
135
136 #ifndef SLAPD_IGNORE_RFC2829
137         {
138                 /* security flags should be configurable */
139                 sasl_security_properties_t secprops;
140                 memset(&secprops, '\0', sizeof(secprops));
141                 secprops.security_flags = SASL_SEC_NOPLAINTEXT | SASL_SEC_NOANONYMOUS;
142                 secprops.property_names = NULL;
143                 secprops.property_values = NULL;
144         
145                 rc = sasl_setprop( server, SASL_SEC_PROPS, &secprops );
146
147                 if( rc != SASL_OK ) {
148                         Debug( LDAP_DEBUG_ANY, "sasl_setprop failed\n",
149                                 0, 0, 0 );
150                         return -1;
151                 }
152         }
153 #endif
154
155         rc = sasl_listmech( server, NULL, NULL, ",", NULL,
156                 &mechs, NULL, NULL);
157
158         if( rc != SASL_OK ) {
159                 Debug( LDAP_DEBUG_ANY, "sasl_listmech failed: %d\n",
160                         rc, 0, 0 );
161                 return -1;
162         }
163
164         Debug( LDAP_DEBUG_TRACE, "SASL mechanisms: %s\n",
165                 mechs, 0, 0 );
166
167         supportedSASLMechanisms = str2charray( mechs, "," );
168
169 #ifdef SLAPD_SPASSWD
170         lutil_passwd_sasl_conn = server;
171 #else
172         sasl_dispose( &server );
173 #endif
174
175         return 0;
176 }
177
178 int sasl_destroy( void )
179 {
180 #ifdef SLAPD_SPASSWD
181         sasl_dispose( &lutil_passwd_sasl_conn );
182 #endif
183         charray_free( supportedSASLMechanisms );
184         return 0;
185 }
186
187 #ifdef HAVE_CYRUS_SASL
188 int sasl_bind(
189     Connection          *conn,
190     Operation           *op,  
191     const char          *dn,  
192     const char          *ndn,
193     const char          *mech,
194     struct berval       *cred,
195         char                            **edn )
196 {
197         struct berval response;
198         const char *errstr;
199         int sc;
200         int rc = 1;
201
202         Debug(LDAP_DEBUG_ARGS,
203                 "==> sasl_bind: dn=\"%s\" mech=%s cred->bv_len=%d\n",
204                 dn, mech, cred ? cred->bv_len : 0 );
205
206         if ( conn->c_sasl_bind_context == NULL ) {
207                 sasl_callback_t callbacks[4];
208                 int cbnum = 0;
209
210 #if 0
211                 if (be->be_sasl_authorize) {
212                         callbacks[cbnum].id = SASL_CB_PROXY_POLICY;
213                         callbacks[cbnum].proc = be->be_sasl_authorize;
214                         callbacks[cbnum].context = be;
215                         ++cbnum;
216                 }
217
218                 if (be->be_sasl_getsecret) {
219                         callbacks[cbnum].id = SASL_CB_SERVER_GETSECRET;
220                         callbacks[cbnum].proc = be->be_sasl_getsecret;
221                         callbacks[cbnum].context = be;
222                         ++cbnum;
223                 }
224
225                 if (be->be_sasl_putsecret) {
226                         callbacks[cbnum].id = SASL_CB_SERVER_PUTSECRET;
227                         callbacks[cbnum].proc = be->be_sasl_putsecret;
228                         callbacks[cbnum].context = be;
229                         ++cbnum;
230                 }
231 #endif
232
233                 callbacks[cbnum].id = SASL_CB_LIST_END;
234                 callbacks[cbnum].proc = NULL;
235                 callbacks[cbnum].context = NULL;
236
237                 /* create new SASL context */
238                 sc = sasl_server_new( "ldap", sasl_host, global_realm,
239                         callbacks, SASL_SECURITY_LAYER, &conn->c_sasl_bind_context );
240
241                 if( sc != SASL_OK ) {
242                         send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
243                                 NULL, "could not create new SASL context", NULL, NULL );
244
245                 } else {
246                         unsigned reslen;
247                         conn->c_authmech = ch_strdup( mech );
248
249                         sc = sasl_server_start( conn->c_sasl_bind_context,
250                                 conn->c_authmech,
251                                 cred->bv_val, cred->bv_len,
252                                 (char **)&response.bv_val, &reslen, &errstr );
253
254                         response.bv_len = reslen;
255                         
256                         if ( (sc != SASL_OK) && (sc != SASL_CONTINUE) ) {
257                                 send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
258                                         NULL, errstr, NULL, NULL );
259                         }
260                 }
261
262         } else {
263                 unsigned reslen;
264                 sc = sasl_server_step( conn->c_sasl_bind_context,
265                         cred->bv_val, cred->bv_len,
266                         (char **)&response.bv_val, &reslen, &errstr );
267
268                 response.bv_len = reslen;
269         
270                 if ( (sc != SASL_OK) && (sc != SASL_CONTINUE) ) {
271                         send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
272                                 NULL, errstr, NULL, NULL );
273                 }
274         }
275
276         if ( sc == SASL_OK ) {
277                 char *authzid;
278
279                 sc = sasl_getprop( conn->c_sasl_bind_context, SASL_USERNAME,
280                         (void **)&authzid );
281
282                 if ( sc != SASL_OK ) {
283                         send_ldap_result( conn, op, rc = slap_sasl_err2ldap( sc ),
284                                 NULL, "no SASL username", NULL, NULL );
285
286                 } else {
287                         Debug(LDAP_DEBUG_TRACE, "sasl_bind: username=%s\n",
288                                 authzid, 0, 0);
289
290                         if( !strncasecmp( authzid, "anonymous", sizeof("anonyous")-1 ) &&
291                                 ( ( authzid[sizeof("anonymous")] == '\0' ) ||
292                                   ( authzid[sizeof("anonymous")] == '@' ) ) )
293                         {
294                                 Debug(LDAP_DEBUG_TRACE, "<== sasl_bind: anonymous\n",
295                                         0, 0, 0);
296
297                         } else {
298                                 *edn = ch_malloc( sizeof( "authzid=" ) + strlen( authzid ) );
299                                 strcpy( *edn, "authzid=" );
300                                 strcat( *edn, authzid );
301
302                                 Debug(LDAP_DEBUG_TRACE, "<== sasl_bind: authzdn: \"%s\"\n",
303                                         *edn, 0, 0);
304                         }
305
306                         send_ldap_sasl( conn, op, rc = LDAP_SUCCESS,
307                                 NULL, NULL, NULL, NULL, &response );
308                 }
309
310         } else if ( sc == SASL_CONTINUE ) {
311                 send_ldap_sasl( conn, op, rc = LDAP_SASL_BIND_IN_PROGRESS,
312                         NULL, NULL, NULL, NULL,  &response );
313         } 
314
315         if ( sc != SASL_CONTINUE && conn->c_sasl_bind_context != NULL ) {
316                 sasl_dispose( &conn->c_sasl_bind_context );
317                 conn->c_sasl_bind_context = NULL;
318         }
319
320         Debug(LDAP_DEBUG_TRACE, "<== sasl_bind: rc=%d\n", rc, 0, 0);
321
322         return rc;
323 }
324 #endif /* HAVE_CYRUS_SASL */
325
326 #else
327 /* no SASL support */
328 int sasl_bind(
329     Connection          *conn,
330     Operation           *op,  
331     const char          *dn,  
332     const char          *ndn,
333     const char          *mech,
334     struct berval       *cred,
335         char                            **edn )
336 {
337         int rc;
338
339         send_ldap_result( conn, op, rc = LDAP_UNWILLING_TO_PERFORM,
340                 NULL, "SASL unavailable", NULL, NULL );
341
342         return rc;
343 }
344
345 int sasl_init( void ) { return 0; }
346 int sasl_destroy( void ) { return 0; }
347 #endif