2 * Sylpheed -- a GTK+ based, lightweight, and fast e-mail client
3 * Copyright (C) 2003-2009 Match Grun and the Claws Mail team
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 3 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License
16 * along with this program. If not, see <http://www.gnu.org/licenses/>.
21 * Some utility functions to access LDAP servers.
34 #include "common/utils.h"
36 #include "ldapserver.h"
39 #define SYLDAP_TEST_FILTER "(objectclass=*)"
40 #define SYLDAP_SEARCHBASE_V2 "cn=config"
41 #define SYLDAP_SEARCHBASE_V3 ""
42 #define SYLDAP_V2_TEST_ATTR "database"
43 #define SYLDAP_V3_TEST_ATTR "namingcontexts"
46 * Attempt to discover the base DN for a server using LDAP version 3.
47 * \param ld LDAP handle for a connected server.
48 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
49 * \return List of Base DN's, or NULL if could not read. List should be
52 static GList *ldaputil_test_v3( LDAP *ld, gint tov, gint *errcode ) {
55 LDAPMessage *result = NULL, *e;
60 struct timeval timeout;
71 /* Test for LDAP version 3 */
72 attribs[0] = SYLDAP_V3_TEST_ATTR;
74 rc = ldap_search_ext_s(
75 ld, SYLDAP_SEARCHBASE_V3, LDAP_SCOPE_BASE, SYLDAP_TEST_FILTER,
76 attribs, 0, NULL, NULL, &timeout, 0, &result );
78 if( rc == LDAP_SUCCESS ) {
80 for( e = ldap_first_entry( ld, result );
82 e = ldap_next_entry( ld, e ) )
84 /* Process attributes */
85 for( attribute = ldap_first_attribute( ld, e, &ber );
87 attribute = ldap_next_attribute( ld, e, ber ) )
90 attribute, SYLDAP_V3_TEST_ATTR ) == 0 )
92 vals = ldap_get_values_len( ld, e, attribute );
94 for( i = 0; vals[i] != NULL; i++ ) {
95 baseDN = g_list_append(
96 baseDN, g_strndup( vals[i]->bv_val, vals[i]->bv_len ) );
99 ldap_value_free_len( vals );
101 ldap_memfree( attribute );
112 ldap_msgfree( result );
117 * Attempt to discover the base DN for a server using LDAP version 2.
118 * \param ld LDAP handle for a connected server.
119 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
120 * \return List of Base DN's, or NULL if could not read. List should be
121 * g_free() when done.
123 static GList *ldaputil_test_v2( LDAP *ld, gint tov ) {
124 GList *baseDN = NULL;
126 LDAPMessage *result = NULL, *e;
130 struct berval **vals;
131 struct timeval timeout;
134 timeout.tv_usec = 0L;
136 timeout.tv_sec = tov;
139 timeout.tv_sec = 30L;
143 rc = ldap_search_ext_s(
144 ld, SYLDAP_SEARCHBASE_V2, LDAP_SCOPE_BASE, SYLDAP_TEST_FILTER,
145 attribs, 0, NULL, NULL, &timeout, 0, &result );
147 if( rc == LDAP_SUCCESS ) {
148 /* Process entries */
149 for( e = ldap_first_entry( ld, result );
151 e = ldap_next_entry( ld, e ) )
153 /* Process attributes */
154 for( attribute = ldap_first_attribute( ld, e, &ber );
156 attribute = ldap_next_attribute( ld, e, ber ) )
160 SYLDAP_V2_TEST_ATTR ) == 0 ) {
161 vals = ldap_get_values_len( ld, e, attribute );
163 for( i = 0; vals[i] != NULL; i++ ) {
166 * Strip the 'ldb:' from the
167 * front of the value.
169 tmp = g_strndup( vals[i]->bv_val, vals[i]->bv_len);
170 ch = ( char * ) strchr( tmp, ':' );
172 gchar *bn = g_strdup( ++ch );
175 baseDN = g_list_append(
176 baseDN, g_strdup( bn ) );
182 ldap_value_free_len( vals );
184 ldap_memfree( attribute );
193 ldap_msgfree( result );
197 int claws_ldap_simple_bind_s( LDAP *ld, LDAP_CONST char *dn, LDAP_CONST char *passwd )
201 if ( passwd != NULL ) {
202 cred.bv_val = (char *) passwd;
203 cred.bv_len = strlen( passwd );
209 debug_print("binding: DN->%s\n", dn?dn:"null");
211 return ldap_sasl_bind_s( ld, dn, LDAP_SASL_SIMPLE, &cred,
214 return ldap_simple_bind_s(ld, dn, passwd);
219 * Attempt to discover the base DN for the server.
220 * \param host Host name.
221 * \param port Port number.
222 * \param bindDN Bind DN (optional).
223 * \param bindPW Bind PW (optional).
224 * \param tov Timeout value (seconds), or 0 for none, default 30 secs.
225 * \return List of Base DN's, or NULL if could not read. This list should be
226 * g_free() when done.
228 GList *ldaputil_read_basedn(
229 const gchar *host, const gint port, const gchar *bindDN,
230 const gchar *bindPW, const gint tov, int ssl, int tls )
232 GList *baseDN = NULL;
234 LdapControl *ctl = ldapctl_create();
242 ldapctl_set_tls(ctl, tls);
243 ldapctl_set_ssl(ctl, ssl);
244 ldapctl_set_port(ctl, port);
245 ldapctl_set_host(ctl, host);
246 ldapctl_set_timeout(ctl, tov);
247 ldapctl_set_bind_dn(ctl, bindDN);
248 ldapctl_set_bind_password(ctl, bindPW, FALSE, FALSE);
250 ld = ldapsvr_connect(ctl);
255 baseDN = ldaputil_test_v3( ld, tov, &rc );
257 debug_print("Using LDAP v3\n");
260 if( baseDN == NULL && !LDAP_API_ERROR(rc) ) {
262 if( baseDN == NULL) {
264 baseDN = ldaputil_test_v2( ld, tov );
266 debug_print("Using LDAP v2\n");
269 ldapsvr_disconnect(ld);
277 * Attempt to connect to the server.
279 * \param host Host name.
280 * \param port Port number.
281 * \return <i>TRUE</i> if connected successfully.
283 gboolean ldaputil_test_connect( const gchar *host, const gint port, int ssl, int tls, int secs ) {
284 gboolean retVal = FALSE;
285 LdapControl *ctl = ldapctl_create();
288 ldapctl_set_tls(ctl, tls);
289 ldapctl_set_ssl(ctl, ssl);
290 ldapctl_set_port(ctl, port);
291 ldapctl_set_host(ctl, host);
292 ldapctl_set_timeout(ctl, secs);
294 ld = ldapsvr_connect(ctl);
296 ldapsvr_disconnect(ld);
297 debug_print("ld != NULL\n");
306 * Test whether LDAP libraries installed.
307 * Return: TRUE if library available.
309 gboolean ldaputil_test_ldap_lib( void ) {
313 #endif /* USE_LDAP */