Is it possible instead to add a new directive to the configuration file to set the protocol version, using ldap_set_option and LDAP_OPT_PROTOCOL_VERSION , LDAP_VERSION3 ?
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
diff -r -U 2 cpu-1.3.100/doc/man/cpu.conf.5 cpu-1.3.100-protversion/doc/man/cpu.conf.5
--- cpu-1.3.100/doc/man/cpu.conf.5 Sun Mar 9 20:25:56 2003
+++ cpu-1.3.100-protversion/doc/man/cpu.conf.5 Sat Aug 9 01:15:39 2003
@@ -37,4 +37,9 @@
listening on. This value must be non negative. This can be overridden by the
\fB-P\fR command line switch.
+.IP "\fBPROTOCOL_VERSION\fR = \fIversion\fR"
+\fIversion\fR is the version to use when connecting to the LDAP server
+specified by \fBLDAP_HOST\fR and \fBLDAP_PORT\fR. The valid values
+are 2 (default) and 3. Note that by default the OpenLDAP slapd server
+only uses the protocol version 3, and that TLS automatically uses version 3.
.IP "\fBBIND_DN\fR = \fIdn\fR"
\fIdn\fR should be the fully qualified DN of an LDAP entity with appropriate
diff -r -U 2 cpu-1.3.100/src/include/plugins/ldap/ldap.h cpu-1.3.100-protversion/src/include/plugins/ldap/ldap.h
--- cpu-1.3.100/src/include/plugins/ldap/ldap.h Wed Apr 30 01:02:12 2003
+++ cpu-1.3.100-protversion/src/include/plugins/ldap/ldap.h Sat Aug 9 00:51:28 2003
@@ -86,4 +86,5 @@
int port; /* required. LDAP_PORT or -P (pg) */
int usetls;
+ int protocolVersion;
bool remove_home_directory;
bool assume_yes;
Only in cpu-1.3.100-protversion/src/plugins/ldap: .libs
diff -r -U 2 cpu-1.3.100/src/plugins/ldap/commandline.c cpu-1.3.100-protversion/src/plugins/ldap/commandline.c
--- cpu-1.3.100/src/plugins/ldap/commandline.c Thu May 1 22:20:36 2003
+++ cpu-1.3.100-protversion/src/plugins/ldap/commandline.c Sat Aug 9 00:54:09 2003
@@ -391,4 +391,5 @@
globalLdap->assume_yes = false;
globalLdap->port = -1;
+ globalLdap->protocolVersion=-10;
globalLdap->timeout.tv_sec = -10;
return 0;
@@ -468,4 +469,12 @@
/* end of required fields */
+
+ if (globalLdap->protocolVersion == -10)
+ {
+ if ((globalLdap->protocolVersion = cfg_get_int ("LDAP","PROTOCOL_VERSION")) == -10)
+ {
+ globalLdap->protocolVersion=2;
+ }
+ }
if ( operation == USERADD && globalLdap->password_file != NULL )
diff -r -U 2 cpu-1.3.100/src/plugins/ldap/ld.c cpu-1.3.100-protversion/src/plugins/ldap/ld.c
--- cpu-1.3.100/src/plugins/ldap/ld.c Wed Apr 30 01:17:42 2003
+++ cpu-1.3.100-protversion/src/plugins/ldap/ld.c Sat Aug 9 01:14:20 2003
@@ -46,5 +46,22 @@
{
LDAP * ld;
- int version = LDAP_VERSION3;
+ int version;
+
+ if (! (int)globalLdap->usetls)
+ {
+ switch(globalLdap->protocolVersion)
+ {
+ case 2:
+ version=LDAP_VERSION2;
+ break;
+ case 3:
+ version=LDAP_VERSION3;
+ break;
+ default:
+ fprintf(stderr, "ldap: ldapOperation: unknown protocol version\n");
+ return -1;
+ }
+ }
+ else version=LDAP_VERSION3;
Hi !
I'm trying to use CPU on FreeBSD-CURRENT with openldap 2.1. When I try to add a group for example I get :
ldap: ldapOperation: ldap_bind_s: Protocol error (2)
additional info: requested protocol version not allowed
ldap: CPU_init: Error in ldapOperation.
Any clue ?
http://www.openldap.org/lists/openldap-software/200305/msg00431.html
Is it possible instead to add a new directive to the configuration file to set the protocol version, using ldap_set_option and LDAP_OPT_PROTOCOL_VERSION , LDAP_VERSION3 ?
Sure. I'll get to it when I'm on vacation next week. I've got finals this week.
And actually, I'll just set it as a configuration option in cpu.conf.
Actually I've just implemented it ;)
diff -r -U 2 cpu-1.3.100/doc/man/cpu.conf.5 cpu-1.3.100-protversion/doc/man/cpu.conf.5
--- cpu-1.3.100/doc/man/cpu.conf.5 Sun Mar 9 20:25:56 2003
+++ cpu-1.3.100-protversion/doc/man/cpu.conf.5 Sat Aug 9 01:15:39 2003
@@ -37,4 +37,9 @@
listening on. This value must be non negative. This can be overridden by the
\fB-P\fR command line switch.
+.IP "\fBPROTOCOL_VERSION\fR = \fIversion\fR"
+\fIversion\fR is the version to use when connecting to the LDAP server
+specified by \fBLDAP_HOST\fR and \fBLDAP_PORT\fR. The valid values
+are 2 (default) and 3. Note that by default the OpenLDAP slapd server
+only uses the protocol version 3, and that TLS automatically uses version 3.
.IP "\fBBIND_DN\fR = \fIdn\fR"
\fIdn\fR should be the fully qualified DN of an LDAP entity with appropriate
diff -r -U 2 cpu-1.3.100/src/include/plugins/ldap/ldap.h cpu-1.3.100-protversion/src/include/plugins/ldap/ldap.h
--- cpu-1.3.100/src/include/plugins/ldap/ldap.h Wed Apr 30 01:02:12 2003
+++ cpu-1.3.100-protversion/src/include/plugins/ldap/ldap.h Sat Aug 9 00:51:28 2003
@@ -86,4 +86,5 @@
int port; /* required. LDAP_PORT or -P (pg) */
int usetls;
+ int protocolVersion;
bool remove_home_directory;
bool assume_yes;
Only in cpu-1.3.100-protversion/src/plugins/ldap: .libs
diff -r -U 2 cpu-1.3.100/src/plugins/ldap/commandline.c cpu-1.3.100-protversion/src/plugins/ldap/commandline.c
--- cpu-1.3.100/src/plugins/ldap/commandline.c Thu May 1 22:20:36 2003
+++ cpu-1.3.100-protversion/src/plugins/ldap/commandline.c Sat Aug 9 00:54:09 2003
@@ -391,4 +391,5 @@
globalLdap->assume_yes = false;
globalLdap->port = -1;
+ globalLdap->protocolVersion=-10;
globalLdap->timeout.tv_sec = -10;
return 0;
@@ -468,4 +469,12 @@
/* end of required fields */
+
+ if (globalLdap->protocolVersion == -10)
+ {
+ if ((globalLdap->protocolVersion = cfg_get_int ("LDAP","PROTOCOL_VERSION")) == -10)
+ {
+ globalLdap->protocolVersion=2;
+ }
+ }
if ( operation == USERADD && globalLdap->password_file != NULL )
diff -r -U 2 cpu-1.3.100/src/plugins/ldap/ld.c cpu-1.3.100-protversion/src/plugins/ldap/ld.c
--- cpu-1.3.100/src/plugins/ldap/ld.c Wed Apr 30 01:17:42 2003
+++ cpu-1.3.100-protversion/src/plugins/ldap/ld.c Sat Aug 9 01:14:20 2003
@@ -46,5 +46,22 @@
{
LDAP * ld;
- int version = LDAP_VERSION3;
+ int version;
+
+ if (! (int)globalLdap->usetls)
+ {
+ switch(globalLdap->protocolVersion)
+ {
+ case 2:
+ version=LDAP_VERSION2;
+ break;
+ case 3:
+ version=LDAP_VERSION3;
+ break;
+ default:
+ fprintf(stderr, "ldap: ldapOperation: unknown protocol version\n");
+ return -1;
+ }
+ }
+ else version=LDAP_VERSION3;
if ( ((char*)globalLdap->hostname != NULL || (int)globalLdap->port) &&
@@ -68,13 +85,14 @@
}
}
+
+ if ( ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION, &version ) !=
+ LDAP_OPT_SUCCESS )
+ {
+ ldap_perror(ld, "ldap: ldapOperation: ldap_set_option");
+ return -1;
+ }
if ( (int)globalLdap->usetls )
{
- if ( ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION, &version ) !=
- LDAP_OPT_SUCCESS )
- {
- ldap_perror(ld, "ldap: ldapOperation: ldap_set_option");
- return -1;
- }
if ( ldap_start_tls_s( ld, NULL, NULL ) != LDAP_SUCCESS )
{