diff options
author | Werner Koch <wk@gnupg.org> | 2021-02-17 17:31:36 +0100 |
---|---|---|
committer | Werner Koch <wk@gnupg.org> | 2021-02-17 17:40:02 +0100 |
commit | ab7dc4b524c3e2ad5153acfdbfa879a9e62d2dbe (patch) | |
tree | 91e80e544bfc2169524614dc5772d06dae792ecd /doc/DETAILS | |
parent | build: Update gpg-error.m4 again. (diff) | |
download | gnupg2-ab7dc4b524c3e2ad5153acfdbfa879a9e62d2dbe.tar.xz gnupg2-ab7dc4b524c3e2ad5153acfdbfa879a9e62d2dbe.zip |
dirmngr: Support new gpgNtds parameter in LDAP keyserver URLs.
* dirmngr/ldap-parse-uri.c (ldap_parse_uri): Support a new gpgNtds
extension.
* dirmngr/ks-engine-ldap.c (my_ldap_connect): Do ldap_init always with
hostname - which is NULL and thus the same if not given. Fix minor
error in error code handling.
--
Note that "gpgNtds" is per RFC-4512 case insensitive and has not yet
been officially regisetered. Thus for correctness the OID can be
used:
1.3.6.1.4.1.11591.2.5 LDAP URL extensions
1.3.6.1.4.1.11591.2.5.1 gpgNtds=1 (auth. with current user)
Note that the value must be 1; all other values won't enable AD
authentication and are resevered for future use.
This has been cherry-picked from the 2.2 branch,
commit 55f46b33df08e8e0ea520ade5f73b321bc01d705
Signed-off-by: Werner Koch <wk@gnupg.org>
Diffstat (limited to 'doc/DETAILS')
-rw-r--r-- | doc/DETAILS | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/doc/DETAILS b/doc/DETAILS index 44bee32ad..bec42a454 100644 --- a/doc/DETAILS +++ b/doc/DETAILS @@ -541,7 +541,7 @@ pkd:0:1024:B665B1435F4C2 .... FF26ABB: Mark the start of the actual decryption process. This is also emitted when in --list-only mode. *** END_DECRYPTION - Mark the end of the actual decryption process. This are also + Mark the end of the actual decryption process. This is also emitted when in --list-only mode. *** DECRYPTION_KEY <fpr> <fpr2> <otrust> This line is emitted when a public key decryption succeeded in @@ -1167,6 +1167,11 @@ pkd:0:1024:B665B1435F4C2 .... FF26ABB: These were used for the ancient shared memory based co-processing. *** BEGIN_STREAM, END_STREAM Used to issued by the experimental pipemode. +*** GOODMDC + This is not anymore needed. Checking the DECRYPTION_OKAY status is + sufficient. +*** BADMDC + This is not anymore needed. ** Inter-component codes Status codes are also used between the components of the GnuPG @@ -1555,6 +1560,8 @@ Status codes are: 1.3.6.1.4.1.11591.2.4.1.2 gpgSubFingerprint attribute 1.3.6.1.4.1.11591.2.4.1.3 gpgMailbox attribute 1.3.6.1.4.1.11591.2.4.1.4 gpgSubCertID attribute + 1.3.6.1.4.1.11591.2.5 LDAP URL extensions + 1.3.6.1.4.1.11591.2.5.1 gpgNtds=1 (auth. with current AD user) 1.3.6.1.4.1.11591.2.12242973 invalid encoded OID #+end_example |