1 #ifndef _INCLUDE_ADS_H_
2 #define _INCLUDE_ADS_H_
4 header for ads (active directory) library routines
6 basically this is a wrapper around ldap
9 #include "libads/ads_status.h"
14 struct ads_saslwrap_ops {
16 ADS_STATUS (*wrap)(struct ads_saslwrap *, uint8_t *buf, uint32_t len);
17 ADS_STATUS (*unwrap)(struct ads_saslwrap *);
18 void (*disconnect)(struct ads_saslwrap *);
21 enum ads_saslwrap_type {
22 ADS_SASLWRAP_TYPE_PLAIN = 1,
23 ADS_SASLWRAP_TYPE_SIGN = 2,
24 ADS_SASLWRAP_TYPE_SEAL = 4
28 /* expected SASL wrapping type */
29 enum ads_saslwrap_type wrap_type;
30 /* SASL wrapping operations */
31 const struct ads_saslwrap_ops *wrap_ops;
32 #ifdef HAVE_LDAP_SASL_WRAPPING
33 Sockbuf_IO_Desc *sbiod; /* lowlevel state for LDAP wrapping */
34 #endif /* HAVE_LDAP_SASL_WRAPPING */
36 void *wrap_private_data;
41 #define ADS_SASL_WRAPPING_IN_MAX_WRAPPED 0x0FFFFFFF
50 #define ADS_SASL_WRAPPING_OUT_MAX_WRAPPED 0x00A00000
51 uint32_t max_unwrapped;
58 typedef struct ads_struct {
59 int is_mine; /* do I own this structure's memory? */
61 /* info needed to find the server */
66 bool gc; /* Is this a global catalog server? */
67 bool no_fallback; /* Bail if the ldap_server is not available */
70 /* info needed to authenticate */
84 /* info derived from the servers config */
86 uint32_t flags; /* cldap flags identifying the services. */
89 char *ldap_server_name;
90 char *server_site_name;
91 char *client_site_name;
98 /* info about the current LDAP connection */
100 struct ads_saslwrap ldap_wrap_data;
103 struct sockaddr_storage ss; /* the ip of the active connection, if any */
104 time_t last_attempt; /* last attempt to reconnect, monotonic clock */
107 #endif /* HAVE_LDAP */
111 typedef LDAPMod **ADS_MODLIST;
113 typedef void **ADS_MODLIST;
116 /* time between reconnect attempts */
117 #define ADS_RECONNECT_TIME 5
119 /* ldap control oids */
120 #define ADS_PAGE_CTL_OID "1.2.840.113556.1.4.319"
121 #define ADS_NO_REFERRALS_OID "1.2.840.113556.1.4.1339"
122 #define ADS_SERVER_SORT_OID "1.2.840.113556.1.4.473"
123 #define ADS_PERMIT_MODIFY_OID "1.2.840.113556.1.4.1413"
124 #define ADS_ASQ_OID "1.2.840.113556.1.4.1504"
125 #define ADS_EXTENDED_DN_OID "1.2.840.113556.1.4.529"
126 #define ADS_SD_FLAGS_OID "1.2.840.113556.1.4.801"
128 /* ldap bitwise searches */
129 #define ADS_LDAP_MATCHING_RULE_BIT_AND "1.2.840.113556.1.4.803"
130 #define ADS_LDAP_MATCHING_RULE_BIT_OR "1.2.840.113556.1.4.804"
132 #define ADS_PINGS 0x0000FFFF /* Ping response */
134 enum ads_extended_dn_flags {
135 ADS_EXTENDED_DN_HEX_STRING = 0,
136 ADS_EXTENDED_DN_STRING = 1 /* not supported on win2k */
139 /* this is probably not very well suited to pass other controls generically but
140 * is good enough for the extended dn control where it is only used for atm */
148 #include "libads/ads_proto.h"
151 #include "libads/ads_ldap_protos.h"
154 #include "libads/kerberos_proto.h"
156 #endif /* _INCLUDE_ADS_H_ */