2 * Sylpheed -- a GTK+ based, lightweight, and fast e-mail client
3 * Copyright (C) 2003-2007 Match Grun and the Claws Mail team
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 3 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License
16 * along with this program. If not, see <http://www.gnu.org/licenses/>.
21 * Some utility functions to access LDAP servers.
36 #include "common/utils.h"
38 #define SYLDAP_TEST_FILTER "(objectclass=*)"
39 #define SYLDAP_SEARCHBASE_V2 "cn=config"
40 #define SYLDAP_SEARCHBASE_V3 ""
41 #define SYLDAP_V2_TEST_ATTR "database"
42 #define SYLDAP_V3_TEST_ATTR "namingcontexts"
45 * Attempt to discover the base DN for a server using LDAP version 3.
46 * \param ld LDAP handle for a connected server.
47 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
48 * \return List of Base DN's, or NULL if could not read. List should be
51 static GList *ldaputil_test_v3( LDAP *ld, gint tov, gint *errcode ) {
54 LDAPMessage *result = NULL, *e;
59 struct timeval timeout;
70 /* Test for LDAP version 3 */
71 attribs[0] = SYLDAP_V3_TEST_ATTR;
73 rc = ldap_search_ext_s(
74 ld, SYLDAP_SEARCHBASE_V3, LDAP_SCOPE_BASE, SYLDAP_TEST_FILTER,
75 attribs, 0, NULL, NULL, &timeout, 0, &result );
77 if( rc == LDAP_SUCCESS ) {
79 for( e = ldap_first_entry( ld, result );
81 e = ldap_next_entry( ld, e ) )
83 /* Process attributes */
84 for( attribute = ldap_first_attribute( ld, e, &ber );
86 attribute = ldap_next_attribute( ld, e, ber ) )
89 attribute, SYLDAP_V3_TEST_ATTR ) == 0 )
91 vals = ldap_get_values_len( ld, e, attribute );
93 for( i = 0; vals[i] != NULL; i++ ) {
94 baseDN = g_list_append(
95 baseDN, g_strndup( vals[i]->bv_val, vals[i]->bv_len ) );
98 ldap_value_free_len( vals );
100 ldap_memfree( attribute );
111 ldap_msgfree( result );
116 * Attempt to discover the base DN for a server using LDAP version 2.
117 * \param ld LDAP handle for a connected server.
118 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
119 * \return List of Base DN's, or NULL if could not read. List should be
120 * g_free() when done.
122 static GList *ldaputil_test_v2( LDAP *ld, gint tov ) {
123 GList *baseDN = NULL;
125 LDAPMessage *result = NULL, *e;
129 struct berval **vals;
130 struct timeval timeout;
133 timeout.tv_usec = 0L;
135 timeout.tv_sec = tov;
138 timeout.tv_sec = 30L;
142 rc = ldap_search_ext_s(
143 ld, SYLDAP_SEARCHBASE_V2, LDAP_SCOPE_BASE, SYLDAP_TEST_FILTER,
144 attribs, 0, NULL, NULL, &timeout, 0, &result );
146 if( rc == LDAP_SUCCESS ) {
147 /* Process entries */
148 for( e = ldap_first_entry( ld, result );
150 e = ldap_next_entry( ld, e ) )
152 /* Process attributes */
153 for( attribute = ldap_first_attribute( ld, e, &ber );
155 attribute = ldap_next_attribute( ld, e, ber ) )
159 SYLDAP_V2_TEST_ATTR ) == 0 ) {
160 vals = ldap_get_values_len( ld, e, attribute );
162 for( i = 0; vals[i] != NULL; i++ ) {
165 * Strip the 'ldb:' from the
166 * front of the value.
168 tmp = g_strndup( vals[i]->bv_val, vals[i]->bv_len);
169 ch = ( char * ) strchr( tmp, ':' );
171 gchar *bn = g_strdup( ++ch );
174 baseDN = g_list_append(
175 baseDN, g_strdup( bn ) );
181 ldap_value_free_len( vals );
183 ldap_memfree( attribute );
192 ldap_msgfree( result );
196 int claws_ldap_simple_bind_s( LDAP *ld, LDAP_CONST char *dn, LDAP_CONST char *passwd )
200 if ( passwd != NULL ) {
201 cred.bv_val = (char *) passwd;
202 cred.bv_len = strlen( passwd );
208 debug_print("binding: DN->%s\n", dn?dn:"null");
209 return ldap_sasl_bind_s( ld, dn, LDAP_SASL_SIMPLE, &cred,
214 void ldapsrv_set_options (gint secs, LDAP *ld);
217 * Attempt to discover the base DN for the server.
218 * \param host Host name.
219 * \param port Port number.
220 * \param bindDN Bind DN (optional).
221 * \param bindPW Bind PW (optional).
222 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
223 * \return List of Base DN's, or NULL if could not read. This list should be
224 * g_free() when done.
226 GList *ldaputil_read_basedn(
227 const gchar *host, const gint port, const gchar *bindDN,
228 const gchar *bindPW, const gint tov, int ssl, int tls )
230 GList *baseDN = NULL;
236 if( host == NULL ) return baseDN;
237 if( port < 1 ) return baseDN;
239 /* Connect to server. */
241 ldapsrv_set_options (tov, NULL);
243 uri = g_strdup_printf("ldap%s://%s:%d",
246 debug_print("URI: %s\n", uri);
247 rc = ldap_initialize(&ld, uri);
254 if ((bindDN && *bindDN)
259 version = LDAP_VERSION3;
260 rc = ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION, &version );
266 if( rc != LDAP_OPT_SUCCESS ) {
267 ldap_unbind_ext( ld, NULL, NULL );
270 rc = ldap_start_tls_s( ld, NULL, NULL );
272 ldap_unbind_ext( ld, NULL, NULL );
278 /* Bind to the server, if required */
280 if( *bindDN != '\0' ) {
281 rc = claws_ldap_simple_bind_s( ld, bindDN, bindPW );
282 if( rc != LDAP_SUCCESS ) {
283 g_printerr("LDAP: %s\n", ldap_err2string(rc));
284 ldap_unbind_ext( ld, NULL, NULL );
290 /* Test for LDAP version 3 */
291 baseDN = ldaputil_test_v3( ld, tov, &rc );
293 debug_print("Using LDAP v3\n");
296 if( baseDN == NULL && !LDAP_API_ERROR(rc) ) {
297 baseDN = ldaputil_test_v2( ld, tov );
299 debug_print("Using LDAP v2\n");
302 if (ld && !LDAP_API_ERROR(rc))
303 ldap_unbind_ext( ld, NULL, NULL );
309 * Attempt to connect to the server.
311 * \param host Host name.
312 * \param port Port number.
313 * \return <i>TRUE</i> if connected successfully.
315 gboolean ldaputil_test_connect( const gchar *host, const gint port, int ssl, int tls, int secs ) {
316 gboolean retVal = FALSE;
324 if( host == NULL ) return retVal;
325 if( port < 1 ) return retVal;
327 ldapsrv_set_options (secs, NULL);
328 uri = g_strdup_printf("ldap%s://%s:%d",
331 debug_print("URI: %s\n", uri);
332 ldap_initialize(&ld, uri);
339 GList *dummy = ldaputil_test_v3( ld, secs, &rc );
342 if (LDAP_API_ERROR(rc))
348 version = LDAP_VERSION3;
349 rc = ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION, &version );
350 if( rc != LDAP_OPT_SUCCESS ) {
351 ldap_unbind_ext( ld, NULL, NULL );
355 rc = ldap_start_tls_s( ld, NULL, NULL );
357 ldap_unbind_ext( ld, NULL, NULL );
363 ldap_unbind_ext( ld, NULL, NULL );
364 debug_print("ld != NULL\n");
371 * Test whether LDAP libraries installed.
372 * Return: TRUE if library available.
374 gboolean ldaputil_test_ldap_lib( void ) {
378 #endif /* USE_LDAP */