1 #ifndef _INCLUDE_ADS_H_
2 #define _INCLUDE_ADS_H_
4 header for ads (active directory) library routines
6 basically this is a wrapper around ldap
11 struct ads_saslwrap_ops {
13 ADS_STATUS (*wrap)(struct ads_struct *, uint8 *buf, uint32 len);
14 ADS_STATUS (*unwrap)(struct ads_struct *);
15 void (*disconnect)(struct ads_struct *);
18 enum ads_saslwrap_type {
19 ADS_SASLWRAP_TYPE_PLAIN = 1,
20 ADS_SASLWRAP_TYPE_SIGN = 2,
21 ADS_SASLWRAP_TYPE_SEAL = 4
24 typedef struct ads_struct {
25 int is_mine; /* do I own this structure's memory? */
27 /* info needed to find the server */
32 int foreign; /* set to 1 if connecting to a foreign
34 bool gc; /* Is this a global catalog server? */
37 /* info needed to authenticate */
50 /* info derived from the servers config */
52 uint32 flags; /* cldap flags identifying the services. */
55 char *ldap_server_name;
56 char *server_site_name;
57 char *client_site_name;
63 /* info about the current LDAP connection */
67 struct sockaddr_storage ss; /* the ip of the active connection, if any */
68 time_t last_attempt; /* last attempt to reconnect */
71 enum ads_saslwrap_type wrap_type;
73 #ifdef HAVE_LDAP_SASL_WRAPPING
74 Sockbuf_IO_Desc *sbiod; /* lowlevel state for LDAP wrapping */
75 #endif /* HAVE_LDAP_SASL_WRAPPING */
77 const struct ads_saslwrap_ops *wrap_ops;
78 void *wrap_private_data;
83 #define ADS_SASL_WRAPPING_IN_MAX_WRAPPED 0x0FFFFFFF
92 #define ADS_SASL_WRAPPING_OUT_MAX_WRAPPED 0x00A00000
99 #endif /* HAVE_LDAP */
103 typedef LDAPMod **ADS_MODLIST;
105 typedef void **ADS_MODLIST;
108 /* time between reconnect attempts */
109 #define ADS_RECONNECT_TIME 5
111 /* ldap control oids */
112 #define ADS_PAGE_CTL_OID "1.2.840.113556.1.4.319"
113 #define ADS_NO_REFERRALS_OID "1.2.840.113556.1.4.1339"
114 #define ADS_SERVER_SORT_OID "1.2.840.113556.1.4.473"
115 #define ADS_PERMIT_MODIFY_OID "1.2.840.113556.1.4.1413"
116 #define ADS_ASQ_OID "1.2.840.113556.1.4.1504"
117 #define ADS_EXTENDED_DN_OID "1.2.840.113556.1.4.529"
118 #define ADS_SD_FLAGS_OID "1.2.840.113556.1.4.801"
120 /* ldap bitwise searches */
121 #define ADS_LDAP_MATCHING_RULE_BIT_AND "1.2.840.113556.1.4.803"
122 #define ADS_LDAP_MATCHING_RULE_BIT_OR "1.2.840.113556.1.4.804"
124 #define ADS_PINGS 0x0000FFFF /* Ping response */
126 /* ads auth control flags */
127 #define ADS_AUTH_DISABLE_KERBEROS 0x0001
128 #define ADS_AUTH_NO_BIND 0x0002
129 #define ADS_AUTH_ANON_BIND 0x0004
130 #define ADS_AUTH_SIMPLE_BIND 0x0008
131 #define ADS_AUTH_ALLOW_NTLMSSP 0x0010
132 #define ADS_AUTH_SASL_SIGN 0x0020
133 #define ADS_AUTH_SASL_SEAL 0x0040
134 #define ADS_AUTH_SASL_FORCE 0x0080
135 #define ADS_AUTH_USER_CREDS 0x0100
137 enum ads_extended_dn_flags {
138 ADS_EXTENDED_DN_HEX_STRING = 0,
139 ADS_EXTENDED_DN_STRING = 1 /* not supported on win2k */
142 /* this is probably not very well suited to pass other controls generically but
143 * is good enough for the extended dn control where it is only used for atm */
151 #include "libads/ads_proto.h"
154 #include "libads/ads_ldap_protos.h"
157 #include "libads/kerberos_proto.h"
159 #endif /* _INCLUDE_ADS_H_ */