2 Unix SMB/CIFS implementation.
6 Copyright (C) Andrew Tridgell 2005
7 Copyright (C) Volker Lendecke 2004
8 Copyright (C) Stefan Metzmacher 2004
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 3 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #include "lib/events/events.h"
26 #include "auth/auth.h"
27 #include "auth/credentials/credentials.h"
28 #include "librpc/gen_ndr/ndr_samr.h"
29 #include "../lib/util/dlinklist.h"
30 #include "../lib/util/asn1.h"
31 #include "ldap_server/ldap_server.h"
32 #include "smbd/service_task.h"
33 #include "smbd/service_stream.h"
34 #include "smbd/service.h"
35 #include "smbd/process_model.h"
36 #include "lib/tls/tls.h"
37 #include "lib/messaging/irpc.h"
38 #include "lib/ldb/include/ldb.h"
39 #include "lib/ldb/include/ldb_errors.h"
40 #include "libcli/ldap/ldap_proto.h"
41 #include "system/network.h"
42 #include "lib/socket/netif.h"
43 #include "dsdb/samdb/samdb.h"
44 #include "param/param.h"
46 close the socket and shutdown a server_context
48 void ldapsrv_terminate_connection(struct ldapsrv_connection
*conn
,
51 packet_recv_disable(conn
->packet
);
52 TALLOC_FREE(conn
->packet
);
53 TALLOC_FREE(conn
->sockets
.tls
);
54 stream_terminate_connection(conn
->connection
, reason
);
60 static void ldapsrv_error_handler(void *private_data
, NTSTATUS status
)
62 struct ldapsrv_connection
*conn
= talloc_get_type(private_data
,
63 struct ldapsrv_connection
);
64 ldapsrv_terminate_connection(conn
, nt_errstr(status
));
68 process a decoded ldap message
70 static void ldapsrv_process_message(struct ldapsrv_connection
*conn
,
71 struct ldap_message
*msg
)
73 struct ldapsrv_call
*call
;
77 call
= talloc(conn
, struct ldapsrv_call
);
79 ldapsrv_terminate_connection(conn
, "no memory");
83 call
->request
= talloc_steal(call
, msg
);
86 call
->send_callback
= NULL
;
87 call
->send_private
= NULL
;
90 status
= ldapsrv_do_call(call
);
91 if (!NT_STATUS_IS_OK(status
)) {
96 blob
= data_blob(NULL
, 0);
98 if (call
->replies
== NULL
) {
103 /* build all the replies into a single blob */
104 while (call
->replies
) {
108 msg
= call
->replies
->msg
;
109 if (!ldap_encode(msg
, samba_ldap_control_handlers(), &b
, call
)) {
110 DEBUG(0,("Failed to encode ldap reply of type %d\n", msg
->type
));
115 ret
= data_blob_append(call
, &blob
, b
.data
, b
.length
);
118 talloc_set_name_const(blob
.data
, "Outgoing, encoded LDAP packet");
125 DLIST_REMOVE(call
->replies
, call
->replies
);
128 packet_send_callback(conn
->packet
, blob
,
129 call
->send_callback
, call
->send_private
);
137 static NTSTATUS
ldapsrv_decode(void *private_data
, DATA_BLOB blob
)
140 struct ldapsrv_connection
*conn
= talloc_get_type(private_data
,
141 struct ldapsrv_connection
);
142 struct asn1_data
*asn1
= asn1_init(conn
);
143 struct ldap_message
*msg
= talloc(conn
, struct ldap_message
);
145 if (asn1
== NULL
|| msg
== NULL
) {
146 return NT_STATUS_NO_MEMORY
;
149 if (!asn1_load(asn1
, blob
)) {
152 return NT_STATUS_NO_MEMORY
;
155 status
= ldap_decode(asn1
, samba_ldap_control_handlers(), msg
);
156 if (!NT_STATUS_IS_OK(status
)) {
161 data_blob_free(&blob
);
162 talloc_steal(conn
, msg
);
165 ldapsrv_process_message(conn
, msg
);
172 static void ldapsrv_conn_idle_timeout(struct tevent_context
*ev
,
173 struct tevent_timer
*te
,
177 struct ldapsrv_connection
*conn
= talloc_get_type(private_data
, struct ldapsrv_connection
);
179 ldapsrv_terminate_connection(conn
, "Timeout. No requests after bind");
183 called when a LDAP socket becomes readable
185 void ldapsrv_recv(struct stream_connection
*c
, uint16_t flags
)
187 struct ldapsrv_connection
*conn
=
188 talloc_get_type(c
->private_data
, struct ldapsrv_connection
);
190 if (conn
->limits
.ite
) { /* clean initial timeout if any */
191 talloc_free(conn
->limits
.ite
);
192 conn
->limits
.ite
= NULL
;
195 if (conn
->limits
.te
) { /* clean idle timeout if any */
196 talloc_free(conn
->limits
.te
);
197 conn
->limits
.te
= NULL
;
200 packet_recv(conn
->packet
);
202 /* set idle timeout */
203 conn
->limits
.te
= event_add_timed(c
->event
.ctx
, conn
,
204 timeval_current_ofs(conn
->limits
.conn_idle_time
, 0),
205 ldapsrv_conn_idle_timeout
, conn
);
209 called when a LDAP socket becomes writable
211 static void ldapsrv_send(struct stream_connection
*c
, uint16_t flags
)
213 struct ldapsrv_connection
*conn
=
214 talloc_get_type(c
->private_data
, struct ldapsrv_connection
);
216 packet_queue_run(conn
->packet
);
219 static void ldapsrv_conn_init_timeout(struct tevent_context
*ev
,
220 struct tevent_timer
*te
,
224 struct ldapsrv_connection
*conn
= talloc_get_type(private_data
, struct ldapsrv_connection
);
226 ldapsrv_terminate_connection(conn
, "Timeout. No requests after initial connection");
229 static int ldapsrv_load_limits(struct ldapsrv_connection
*conn
)
232 const char *attrs
[] = { "configurationNamingContext", NULL
};
233 const char *attrs2
[] = { "lDAPAdminLimits", NULL
};
234 struct ldb_message_element
*el
;
235 struct ldb_result
*res
= NULL
;
236 struct ldb_dn
*basedn
;
237 struct ldb_dn
*conf_dn
;
238 struct ldb_dn
*policy_dn
;
242 /* set defaults limits in case of failure */
243 conn
->limits
.initial_timeout
= 120;
244 conn
->limits
.conn_idle_time
= 900;
245 conn
->limits
.max_page_size
= 1000;
246 conn
->limits
.search_timeout
= 120;
249 tmp_ctx
= talloc_new(conn
);
250 if (tmp_ctx
== NULL
) {
254 basedn
= ldb_dn_new(tmp_ctx
, conn
->ldb
, NULL
);
255 if ( ! ldb_dn_validate(basedn
)) {
259 ret
= ldb_search(conn
->ldb
, tmp_ctx
, &res
, basedn
, LDB_SCOPE_BASE
, attrs
, NULL
);
260 if (ret
!= LDB_SUCCESS
) {
264 if (res
->count
!= 1) {
268 conf_dn
= ldb_msg_find_attr_as_dn(conn
->ldb
, tmp_ctx
, res
->msgs
[0], "configurationNamingContext");
269 if (conf_dn
== NULL
) {
273 policy_dn
= ldb_dn_copy(tmp_ctx
, conf_dn
);
274 ldb_dn_add_child_fmt(policy_dn
, "CN=Default Query Policy,CN=Query-Policies,CN=Directory Service,CN=Windows NT,CN=Services");
275 if (policy_dn
== NULL
) {
279 ret
= ldb_search(conn
->ldb
, tmp_ctx
, &res
, policy_dn
, LDB_SCOPE_BASE
, attrs2
, NULL
);
280 if (ret
!= LDB_SUCCESS
) {
284 if (res
->count
!= 1) {
288 el
= ldb_msg_find_element(res
->msgs
[0], "lDAPAdminLimits");
293 for (i
= 0; i
< el
->num_values
; i
++) {
294 char policy_name
[256];
297 s
= sscanf((const char *)el
->values
[i
].data
, "%255[^=]=%d", policy_name
, &policy_value
);
298 if (ret
!= 2 || policy_value
== 0)
301 if (strcasecmp("InitRecvTimeout", policy_name
) == 0) {
302 conn
->limits
.initial_timeout
= policy_value
;
305 if (strcasecmp("MaxConnIdleTime", policy_name
) == 0) {
306 conn
->limits
.conn_idle_time
= policy_value
;
309 if (strcasecmp("MaxPageSize", policy_name
) == 0) {
310 conn
->limits
.max_page_size
= policy_value
;
313 if (strcasecmp("MaxQueryDuration", policy_name
) == 0) {
314 conn
->limits
.search_timeout
= policy_value
;
322 DEBUG(0, ("Failed to load ldap server query policies\n"));
323 talloc_free(tmp_ctx
);
328 initialise a server_context from a open socket and register a event handler
329 for reading from that socket
331 static void ldapsrv_accept(struct stream_connection
*c
,
332 struct auth_session_info
*session_info
)
334 struct ldapsrv_service
*ldapsrv_service
=
335 talloc_get_type(c
->private_data
, struct ldapsrv_service
);
336 struct ldapsrv_connection
*conn
;
337 struct cli_credentials
*server_credentials
;
338 struct socket_address
*socket_address
;
342 conn
= talloc_zero(c
, struct ldapsrv_connection
);
344 stream_terminate_connection(c
, "ldapsrv_accept: out of memory");
349 conn
->connection
= c
;
350 conn
->service
= ldapsrv_service
;
351 conn
->sockets
.raw
= c
->socket
;
352 conn
->lp_ctx
= ldapsrv_service
->task
->lp_ctx
;
354 c
->private_data
= conn
;
356 socket_address
= socket_get_my_addr(c
->socket
, conn
);
357 if (!socket_address
) {
358 ldapsrv_terminate_connection(conn
, "ldapsrv_accept: failed to obtain local socket address!");
361 port
= socket_address
->port
;
362 talloc_free(socket_address
);
365 struct socket_context
*tls_socket
= tls_init_server(ldapsrv_service
->tls_params
, c
->socket
,
368 ldapsrv_terminate_connection(conn
, "ldapsrv_accept: tls_init_server() failed");
371 talloc_steal(c
, tls_socket
);
372 c
->socket
= tls_socket
;
373 conn
->sockets
.tls
= tls_socket
;
375 } else if (port
== 3268) /* Global catalog */ {
376 conn
->global_catalog
= true;
378 conn
->packet
= packet_init(conn
);
379 if (conn
->packet
== NULL
) {
380 ldapsrv_terminate_connection(conn
, "out of memory");
384 packet_set_private(conn
->packet
, conn
);
385 packet_set_socket(conn
->packet
, c
->socket
);
386 packet_set_callback(conn
->packet
, ldapsrv_decode
);
387 packet_set_full_request(conn
->packet
, ldap_full_packet
);
388 packet_set_error_handler(conn
->packet
, ldapsrv_error_handler
);
389 packet_set_event_context(conn
->packet
, c
->event
.ctx
);
390 packet_set_fde(conn
->packet
, c
->event
.fde
);
391 packet_set_serialise(conn
->packet
);
393 if (conn
->sockets
.tls
) {
394 packet_set_unreliable_select(conn
->packet
);
397 /* Ensure we don't get packets until the database is ready below */
398 packet_recv_disable(conn
->packet
);
400 server_credentials
= cli_credentials_init(conn
);
401 if (!server_credentials
) {
402 stream_terminate_connection(c
, "Failed to init server credentials\n");
406 cli_credentials_set_conf(server_credentials
, conn
->lp_ctx
);
407 status
= cli_credentials_set_machine_account(server_credentials
, conn
->lp_ctx
);
408 if (!NT_STATUS_IS_OK(status
)) {
409 stream_terminate_connection(c
, talloc_asprintf(conn
, "Failed to obtain server credentials, perhaps a standalone server?: %s\n", nt_errstr(status
)));
412 conn
->server_credentials
= server_credentials
;
414 conn
->session_info
= talloc_move(conn
, &session_info
);
416 if (!NT_STATUS_IS_OK(ldapsrv_backend_Init(conn
))) {
417 ldapsrv_terminate_connection(conn
, "backend Init failed");
421 /* load limits from the conf partition */
422 ldapsrv_load_limits(conn
); /* should we fail on error ? */
424 /* register the server */
425 irpc_add_name(c
->msg_ctx
, "ldap_server");
427 /* set connections limits */
428 conn
->limits
.ite
= event_add_timed(c
->event
.ctx
, conn
,
429 timeval_current_ofs(conn
->limits
.initial_timeout
, 0),
430 ldapsrv_conn_init_timeout
, conn
);
432 packet_recv_enable(conn
->packet
);
436 static void ldapsrv_accept_nonpriv(struct stream_connection
*c
)
438 struct ldapsrv_service
*ldapsrv_service
= talloc_get_type_abort(
439 c
->private_data
, struct ldapsrv_service
);
440 struct auth_session_info
*session_info
;
443 status
= auth_anonymous_session_info(
444 c
, ldapsrv_service
->task
->lp_ctx
, &session_info
);
445 if (!NT_STATUS_IS_OK(status
)) {
446 stream_terminate_connection(c
, "failed to setup anonymous "
450 ldapsrv_accept(c
, session_info
);
453 static const struct stream_server_ops ldap_stream_nonpriv_ops
= {
455 .accept_connection
= ldapsrv_accept_nonpriv
,
456 .recv_handler
= ldapsrv_recv
,
457 .send_handler
= ldapsrv_send
,
460 /* The feature removed behind an #ifdef until we can do it properly
461 * with an EXTERNAL bind. */
463 #define WITH_LDAPI_PRIV_SOCKET
465 #ifdef WITH_LDAPI_PRIV_SOCKET
466 static void ldapsrv_accept_priv(struct stream_connection
*c
)
468 struct ldapsrv_service
*ldapsrv_service
= talloc_get_type_abort(
469 c
->private_data
, struct ldapsrv_service
);
470 struct auth_session_info
*session_info
;
472 session_info
= system_session(ldapsrv_service
->task
->lp_ctx
);
474 stream_terminate_connection(c
, "failed to setup system "
478 ldapsrv_accept(c
, session_info
);
481 static const struct stream_server_ops ldap_stream_priv_ops
= {
483 .accept_connection
= ldapsrv_accept_priv
,
484 .recv_handler
= ldapsrv_recv
,
485 .send_handler
= ldapsrv_send
,
490 add a socket address to the list of events, one event per port
492 static NTSTATUS
add_socket(struct tevent_context
*event_context
,
493 struct loadparm_context
*lp_ctx
,
494 const struct model_ops
*model_ops
,
495 const char *address
, struct ldapsrv_service
*ldap_service
)
499 struct ldb_context
*ldb
;
501 status
= stream_setup_socket(event_context
, lp_ctx
,
502 model_ops
, &ldap_stream_nonpriv_ops
,
503 "ipv4", address
, &port
,
504 lp_socket_options(lp_ctx
),
506 if (!NT_STATUS_IS_OK(status
)) {
507 DEBUG(0,("ldapsrv failed to bind to %s:%u - %s\n",
508 address
, port
, nt_errstr(status
)));
511 if (tls_support(ldap_service
->tls_params
)) {
512 /* add ldaps server */
514 status
= stream_setup_socket(event_context
, lp_ctx
,
516 &ldap_stream_nonpriv_ops
,
517 "ipv4", address
, &port
,
518 lp_socket_options(lp_ctx
),
520 if (!NT_STATUS_IS_OK(status
)) {
521 DEBUG(0,("ldapsrv failed to bind to %s:%u - %s\n",
522 address
, port
, nt_errstr(status
)));
526 /* Load LDAP database, but only to read our settings */
527 ldb
= samdb_connect(ldap_service
, ldap_service
->task
->event_ctx
,
528 lp_ctx
, system_session(lp_ctx
));
530 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
533 if (samdb_is_gc(ldb
)) {
535 status
= stream_setup_socket(event_context
, lp_ctx
,
537 &ldap_stream_nonpriv_ops
,
538 "ipv4", address
, &port
,
539 lp_socket_options(lp_ctx
),
541 if (!NT_STATUS_IS_OK(status
)) {
542 DEBUG(0,("ldapsrv failed to bind to %s:%u - %s\n",
543 address
, port
, nt_errstr(status
)));
547 /* And once we are bound, free the tempoary ldb, it will
548 * connect again on each incoming LDAP connection */
549 talloc_unlink(ldap_service
, ldb
);
555 open the ldap server sockets
557 static void ldapsrv_task_init(struct task_server
*task
)
560 #ifdef WITH_LDAPI_PRIV_SOCKET
563 struct ldapsrv_service
*ldap_service
;
565 const struct model_ops
*model_ops
;
567 switch (lp_server_role(task
->lp_ctx
)) {
568 case ROLE_STANDALONE
:
569 task_server_terminate(task
, "ldap_server: no LDAP server required in standalone configuration",
572 case ROLE_DOMAIN_MEMBER
:
573 task_server_terminate(task
, "ldap_server: no LDAP server required in member server configuration",
576 case ROLE_DOMAIN_CONTROLLER
:
577 /* Yes, we want an LDAP server */
581 task_server_set_title(task
, "task[ldapsrv]");
583 /* run the ldap server as a single process */
584 model_ops
= process_model_startup(task
->event_ctx
, "single");
585 if (!model_ops
) goto failed
;
587 ldap_service
= talloc_zero(task
, struct ldapsrv_service
);
588 if (ldap_service
== NULL
) goto failed
;
590 ldap_service
->task
= task
;
592 ldap_service
->tls_params
= tls_initialise(ldap_service
, task
->lp_ctx
);
593 if (ldap_service
->tls_params
== NULL
) goto failed
;
595 if (lp_interfaces(task
->lp_ctx
) && lp_bind_interfaces_only(task
->lp_ctx
)) {
596 struct interface
*ifaces
;
600 load_interfaces(task
, lp_interfaces(task
->lp_ctx
), &ifaces
);
601 num_interfaces
= iface_count(ifaces
);
603 /* We have been given an interfaces line, and been
604 told to only bind to those interfaces. Create a
605 socket per interface and bind to only these.
607 for(i
= 0; i
< num_interfaces
; i
++) {
608 const char *address
= iface_n_ip(ifaces
, i
);
609 status
= add_socket(task
->event_ctx
, task
->lp_ctx
, model_ops
, address
, ldap_service
);
610 if (!NT_STATUS_IS_OK(status
)) goto failed
;
613 status
= add_socket(task
->event_ctx
, task
->lp_ctx
, model_ops
,
614 lp_socket_address(task
->lp_ctx
), ldap_service
);
615 if (!NT_STATUS_IS_OK(status
)) goto failed
;
618 ldapi_path
= private_path(ldap_service
, task
->lp_ctx
, "ldapi");
623 status
= stream_setup_socket(task
->event_ctx
, task
->lp_ctx
,
624 model_ops
, &ldap_stream_nonpriv_ops
,
625 "unix", ldapi_path
, NULL
,
626 lp_socket_options(task
->lp_ctx
),
628 talloc_free(ldapi_path
);
629 if (!NT_STATUS_IS_OK(status
)) {
630 DEBUG(0,("ldapsrv failed to bind to %s - %s\n",
631 ldapi_path
, nt_errstr(status
)));
634 #ifdef WITH_LDAPI_PRIV_SOCKET
635 priv_dir
= private_path(ldap_service
, task
->lp_ctx
, "ldap_priv");
636 if (priv_dir
== NULL
) {
640 * Make sure the directory for the privileged ldapi socket exists, and
641 * is of the correct permissions
643 if (!directory_create_or_exist(priv_dir
, geteuid(), 0750)) {
644 task_server_terminate(task
, "Cannot create ldap "
645 "privileged ldapi directory", true);
648 ldapi_path
= talloc_asprintf(ldap_service
, "%s/ldapi", priv_dir
);
649 talloc_free(priv_dir
);
650 if (ldapi_path
== NULL
) {
654 status
= stream_setup_socket(task
->event_ctx
, task
->lp_ctx
,
655 model_ops
, &ldap_stream_priv_ops
,
656 "unix", ldapi_path
, NULL
,
657 lp_socket_options(task
->lp_ctx
),
659 talloc_free(ldapi_path
);
660 if (!NT_STATUS_IS_OK(status
)) {
661 DEBUG(0,("ldapsrv failed to bind to %s - %s\n",
662 ldapi_path
, nt_errstr(status
)));
669 task_server_terminate(task
, "Failed to startup ldap server task", true);
673 NTSTATUS
server_service_ldap_init(void)
675 return register_server_service("ldap", ldapsrv_task_init
);