summaryrefslogtreecommitdiffstats
path: root/dirmngr/t-ldap-misc.c
diff options
context:
space:
mode:
authorWerner Koch <wk@gnupg.org>2021-06-08 08:46:59 +0200
committerWerner Koch <wk@gnupg.org>2021-06-16 12:58:32 +0200
commit864ea251983977b91a7f6ff5964e497cf4b208dc (patch)
tree1449aece313b92b3d06bf174928cf2dd080f5bdd /dirmngr/t-ldap-misc.c
parentdirmngr: Remove useless code. (diff)
downloadgnupg2-864ea251983977b91a7f6ff5964e497cf4b208dc.tar.xz
gnupg2-864ea251983977b91a7f6ff5964e497cf4b208dc.zip
dirmngr: Rewrite the LDAP wrapper tool
* dirmngr/ldap-misc.c: New. * dirmngr/ldap-misc.h: New. * dirmngr/ks-engine-ldap.c: Include ldap-misc.h. (ldap_err_to_gpg_err, ldap_to_gpg_err): Move to ldap-misc.c. * dirmngr/ldap-wrapper.c (ldap_wrapper): Print list of args in debug mode. * dirmngr/server.c (lookup_cert_by_pattern): Handle GPG_ERR_NOT_FOUND the saqme as GPG_ERR_NO_DATA. * dirmngr/ldap.c (run_ldap_wrapper): Add args tls_mode and ntds. Remove arg url. Adjust for changes in dirmngr_ldap. (url_fetch_ldap): Remove args host and port. Parse the URL and use these values to call run_ldap_wrapper. (attr_fetch_ldap): Pass tls flags to run_ldap_wrapper. (rfc2254_need_escape, rfc2254_escape): New. (extfilt_need_escape, extfilt_escape): New. (parse_one_pattern): Rename to ... (make_one_filter): this. Change for new dirmngr_ldap calling convention. Make issuer DN searching partly work. (escape4url, make_url): Remove. (start_cert_fetch_ldap): Change for new dirmngr_ldap calling convention. * dirmngr/dirmngr_ldap.c: Major rewrite. * dirmngr/t-ldap-misc.c: New. * dirmngr/t-support.h (DIM, DIMof): New. * dirmngr/Makefile.am (dirmngr_ldap_SOURCES): Add ldap-misc.c (module_tests) [USE_LDAP]: Add t-ldap-misc. (t_ldap_parse_uri_SOURCES): Ditto. (t_ldap_misc_SOURCES): New. -- This rewrite allows to properly handle TLS and avoids some code duplication. Signed-off-by: Werner Koch <wk@gnupg.org> (cherry picked from commit 39815c023f0371dea01f7c51469b19c06ad18718)
Diffstat (limited to 'dirmngr/t-ldap-misc.c')
-rw-r--r--dirmngr/t-ldap-misc.c158
1 files changed, 158 insertions, 0 deletions
diff --git a/dirmngr/t-ldap-misc.c b/dirmngr/t-ldap-misc.c
new file mode 100644
index 000000000..afba1025f
--- /dev/null
+++ b/dirmngr/t-ldap-misc.c
@@ -0,0 +1,158 @@
+/* t-ldap-parse-uri.c - Tests for ldap-parse-uri.c and ldap-misc.c
+ * Copyright (C) 2015 g10 Code GmbH
+ *
+ * This file is part of GnuPG.
+ *
+ * GnuPG is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * GnuPG is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
+ */
+
+#include <config.h>
+
+#include <stdio.h>
+#include <stdlib.h>
+#include <gpg-error.h>
+
+#include "../common/util.h"
+#include "t-support.h"
+#include "ldap-misc.h"
+
+
+static void
+test_ldap_parse_extfilter (void)
+{
+ struct {
+ const char *string;
+ const char *base;
+ const char *filter;
+ int scope;
+ gpg_err_code_t ec;
+ } tests[] =
+ {
+ { "^CN=foo, OU=My Users&(objectClasses=*)",
+ "CN=foo, OU=My Users", "(objectClasses=*)",
+ -1 },
+ { "^CN=foo, OU=My Users&base&(objectClasses=*)",
+ "CN=foo, OU=My Users", "(objectClasses=*)",
+ LDAP_SCOPE_BASE },
+ { "^CN=foo, OU=My Users&one&(objectClasses=*)",
+ "CN=foo, OU=My Users", "(objectClasses=*)",
+ LDAP_SCOPE_ONELEVEL },
+ { "^CN=foo, OU=My Users&sub&(objectClasses=*)",
+ "CN=foo, OU=My Users", "(objectClasses=*)",
+ LDAP_SCOPE_SUBTREE },
+ /* { "^CN=foo, OU=My Users&children&(objectClasses=*)", */
+ /* "CN=foo, OU=My Users", "(objectClasses=*)", */
+ /* LDAP_SCOPE_CHILDREN }, */
+ { "^CN=foo, OU=My Users&",
+ "CN=foo, OU=My Users", NULL,
+ -1 },
+ { "^CN=foo, OU=My Users&sub&",
+ "CN=foo, OU=My Users", NULL,
+ LDAP_SCOPE_SUBTREE },
+ /* { "^&children&(objectClasses=*)", */
+ /* "", "(objectClasses=*)", */
+ /* LDAP_SCOPE_CHILDREN }, */
+ { "^CN=foo, OU=My &&Users&base&(objectClasses=*)",
+ "CN=foo, OU=My &Users", "(objectClasses=*)",
+ LDAP_SCOPE_BASE },
+ { "^CN=foo, OU=My Users&&&base&(objectClasses=*)",
+ "CN=foo, OU=My Users&", "(objectClasses=*)",
+ LDAP_SCOPE_BASE },
+ { "^CN=foo, OU=My Users",
+ NULL, NULL,
+ LDAP_SCOPE_BASE, GPG_ERR_SYNTAX },
+ { "^CN=foo, OU=My Users&base(objectClasses=*)",
+ NULL, NULL,
+ LDAP_SCOPE_BASE, GPG_ERR_SYNTAX },
+ { "^CN=foo, OU=My Users&base&objectClasses=*)",
+ NULL, NULL,
+ LDAP_SCOPE_BASE, GPG_ERR_SYNTAX },
+ { "^CN=foo, OU=My Users&base&(objectClasses=*",
+ NULL, NULL,
+ LDAP_SCOPE_BASE, GPG_ERR_SYNTAX }
+ };
+ int idx;
+ gpg_error_t err;
+ int errcount = 0;
+ char *base, *filter;
+ int scope;
+
+ for (idx= 0; idx < DIM (tests); idx++)
+ {
+ scope = -1;
+ err = ldap_parse_extfilter (tests[idx].string, 1, &base, &scope, &filter);
+ if (err && tests[idx].ec)
+ {
+ if (gpg_err_code (err) != tests[idx].ec)
+ {
+ fprintf (stderr, "%s: test %d failed: wrong error code %d\n",
+ __func__, idx, err);
+ errcount++;
+ }
+ continue;
+ }
+ if (err)
+ {
+ fprintf (stderr, "%s: test %d failed: %s\n",
+ __func__, idx, gpg_strerror (err));
+ errcount++;
+ continue;
+ }
+ if (tests[idx].ec)
+ {
+ fprintf (stderr, "%s: test %d failed: error not detected\n",
+ __func__, idx);
+ errcount++;
+ continue;
+ }
+ if ((!tests[idx].base ^ !base)
+ || (tests[idx].base && strcmp (tests[idx].base, base)))
+ {
+ fprintf (stderr, "%s: test %d failed: base mismatch ('%s')\n",
+ __func__, idx, base? base : "(null");
+ errcount++;
+ }
+ if ((!tests[idx].filter ^ !filter)
+ || (tests[idx].filter && strcmp (tests[idx].filter, filter)))
+ {
+ fprintf (stderr, "%s: test %d failed: filter mismatch ('%s')\n",
+ __func__, idx, filter? filter : "(null");
+ errcount++;
+ }
+ if (tests[idx].scope != scope)
+ {
+ fprintf (stderr, "%s: test %d failed: scope mismatch (%d)\n",
+ __func__, idx, scope);
+ errcount++;
+ }
+ xfree (base);
+ xfree (filter);
+ }
+ if (errcount)
+ exit (1);
+}
+
+
+
+
+int
+main (int argc, char **argv)
+{
+ (void)argc;
+ (void)argv;
+
+ test_ldap_parse_extfilter ();
+
+ return 0;
+}