summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* COLLECTION Improvements to copy functionsDmitri Pal2009-09-104-51/+191
| | | | | | | | | | | | | | | | | | | | This patch adds better options for copying collections in flat mode. It allows caller of the interface to control prefixing of the fields when one collection is appended to another. It also avoids creating prefixes when the collection is simply copied in flat mode. Also for ELAPI I realized that the most efficient way to deal with the "resolved" event (event where all templeted values are actually replaced with the real values) is to add a callback capability to a copy collection function so that the callback can be used to modify the data (resolve it) while the copy operation is in progress. This approach eliminates the need for separate set of lookups after the event is already copied.
* Update manpage to reflect new syntax for enumerateStephen Gallagher2009-09-101-12/+6
|
* Check for valid min and max IDs in confdb_get_domainsStephen Gallagher2009-09-101-1/+7
|
* Add support for the EntryCacheNoWaitRefreshTimeoutStephen Gallagher2009-09-095-2/+75
| | | | | | | | This timeout specifies the lifetime of a cache entry before it is updated out-of-band. When this timeout is hit, the request will still complete from cache, but the SSSD will also go and update the cached entry in the background to extend the life of the cache entry and reduce the wait time of a future request.
* Consolidate cache lookups in the NSSStephen Gallagher2009-09-091-177/+93
| | | | | | getpwnam, getpwuid, getgrnam and getgrgid will now use a common function, check_cache, for determining whether to return a cached value or to go to the provider.
* Cleanups for library linkingsbose2009-09-091-2/+1
| | | | | - remove unused PAM_LIBS from LDAP and Kerberos provider - add OPENLDAP_LIBS to LDAP provider
* more fixes for older libpcre versionssbose2009-09-092-3/+10
| | | | | - older version of libpcre only support the Python syntax (?P<name>) for named subpatterns
* COLLECTION Copy collection flat with concatenated namesDmitri Pal2009-09-095-239/+365
| | | | | | | | | | | | | | | | | | | | | This patch addresses several issues: a) Adds capability to add or copy the collections in flattened mode but construct names of attributes in dotted notation. For example when you append collection "sub" with items "foo" and "bar" previously you could add them as "foo" and "bar" not you can flatten them and the names will be "sub.foo" and "sub.bar" this allows better processing of the attributes in the elapi message. b) Removes old implemntation of the copy collection function. c) Removes the col_set_timestamp, this functionality has been moved to ELAPI long ago. d) Updates collection unit test. e) Updates elapi to use new functionality f) Updates elapi unit test Have run under valgrind with no problems.
* ELAPI Laying foundation for the async processingDmitri Pal2009-09-086-90/+175
| | | | | | | A relatively small patch aligning headers and a small portion of code for upcoming implementation of the async event processing. Cleanup of the test config file.
* ELAPI Adding file provider and CSV formatDmitri Pal2009-09-0820-139/+2250
| | | | | | | | | | | | | | | | | | | | | This patch creates the infrastructure for logging of the event from the top of the interface to the bottom. It is a start. A lot of functionality is left aside. The attempt of this patch is pass event from caller of the ELAPI interface via targets to sinks then to providers and do serialization creating entity that is ready to be written to a file. It also implements more specific provider related configuration parameters. Also it addresses couple suggestions that were brought up against previous patch. ELAPI Correcting issues This patch addresses the issues found during the review of the previous patches and addresses ticket #166.
* ELAPI sinks and providersDmitri Pal2009-09-089-143/+1016
| | | | | | | | | This patch drills down to the next level of ELAPI functionality. I adds the creation and loading of the sinks. It also implements a skeleton for the first low level provider which will be capable of writing to a file. The configuration ini file is extended to define new configuration parameters and their meanings.
* Remove shadow-utils support from toolsJakub Hrozek2009-09-088-763/+73
| | | | | Removes the ability to proxy to shadow-utils. Also remove all the supporting functions for getting domain type, domain by id etc.
* Tools are allowed to touch only the 'local' domainSimo Sorce2009-09-088-76/+35
|
* Split database in multiple filesSimo Sorce2009-09-0826-335/+1184
| | | | | The special persistent local database retains the original name. All other backends now have their own cache-NAME.ldb file.
* Fix two possible uninitialized valuesSimo Sorce2009-09-082-4/+5
| | | | Make counter for used messages explicit.
* initialize sockaddr_in structureSumit Bose2009-09-081-0/+10
|
* fix libdbus configure checkSumit Bose2009-09-082-1/+2
| | | | | - remove unneeded CFLAGS component - do not leak LDFLAGS used by configure check to final Makefile
* configure cleanupsSumit Bose2009-09-0315-22/+31
| | | | | - replaced mailing list address - let sssd base components read version from VERSION
* Avoid crash when timestamp is NULLRalf Haferkamp2009-09-031-1/+3
| | | | | Check if the timestamp argument of sdap_save_group_recv is NULL before using it.
* Fix initgroups search filter when using rfc2307bisRalf Haferkamp2009-09-031-2/+2
| | | | | sdap_get_initgr_process() was using the wrong sdap_id_map struct when creating the searchfilter for the initgroups() call.
* Fix proxy enumerationSimo Sorce2009-09-031-86/+123
| | | | New tevent library finally outlawed nested loops.
* Move RPM specfiles into contrib/Stephen Gallagher2009-09-023-7/+17
| | | | Support RHEL 5 in the spec file
* Honor enumerate option in ldap_idSimo Sorce2009-09-021-6/+9
| | | | | If enumerations are disabled for this domain, then do not start the enumeration task.
* remove the concept of a backend nameSumit Bose2009-09-024-31/+41
| | | | | | | | | | | The data provider backends stored a name value besides the domain name to identify themselves to the data provider. This was the name of the id provider. Currently the backends can have different providers for id, authentication etc. So the name may be missleading. Also when there are more domains with the same id provider the name is not enough to identify the backend but the domain name is. As a consequence the backend name is removed completely and only the domain name is used for identification.
* check if libpcre version is above or below 7Sumit Bose2009-09-013-2/+27
| | | | | PCRE_DUPNAMES is a new feature of libpcre 7. It is used in sssd to make the splitting of fully qualified user names more flexible.
* stop processing a domain if no provider is givenSumit Bose2009-09-011-0/+1
|
* Turn enumeration into a boolean valueSimo Sorce2009-08-314-13/+22
|
* Correctly handle DbusWatch behavior.Simo Sorce2009-08-312-37/+124
| | | | | | | It seems like DBUS always adds 2 watches for the same fd. One is for reading and the other is for writing. DBUS then keeps disabling one and enabling the other, depending on whether it is interested in reading or writing from/to the file descriptor.
* check if gid attribute is emptySumit Bose2009-08-281-0/+6
|
* send SSSD_REALM and SSSD_KDCIP environment to the clientSumit Bose2009-08-281-2/+31
| | | | | | Currently the kerberos locator plugin needs these two variables to be set to find a KDC which is configured in sssd but not in /etc/krb5.conf.
* add configure check for errno_tSumit Bose2009-08-284-0/+14
|
* fix internal order of ldap user mapping optionsSumit Bose2009-08-281-4/+4
|
* Speed-up enumerations.Simo Sorce2009-08-282-2/+167
| | | | | | | This patch reduces the time needed to enumerate groups of a midsized domain from 12 seconds to 4.4 Optimizes enumerations by doing only 2 ldb searches and some ordering instead of a number of searches proportional to the number of groups
* Make enumeration an independent taskSimo Sorce2009-08-275-68/+693
| | | | | | Always immediately return to DP, and update users/groups in the background. Also implements an optimization to retrieve only changed/new users/groups by filtering using the modifyTimestamp after the first query.
* Remove redunant function and always pass attrs.Simo Sorce2009-08-274-54/+30
|
* Upgrade database to 0.2Simo Sorce2009-08-272-5/+172
| | | | Provides also an upgrade function.
* Fix group replies when using member/memberofSimo Sorce2009-08-273-197/+180
| | | | Also remove legacy memberuid support
* Always save using member/memberOfSimo Sorce2009-08-275-216/+151
| | | | | First pass to remove the legacy option and make it just a property of the provider
* Initial support for multiple schema typesSimo Sorce2009-08-271-7/+39
|
* do not show server messages to userSumit Bose2009-08-271-5/+0
|
* removed unused header fileSumit Bose2009-08-271-18/+0
|
* Use the correct structure.Simo Sorce2009-08-271-2/+2
|
* Update version to 0.5.0sssd-0_5_0Stephen Gallagher2009-08-245-13/+507
| | | | Update gettext strings
* Do not fail enumerations if a single store failsSimo Sorce2009-08-241-40/+45
| | | | Try as hard as possible to store as much data as we can.
* Relax memberof constraints a bitSimo Sorce2009-08-241-85/+226
| | | | | | Allow to try to set members that do not actually exist. In that case simply remove them when we find out they are not real entries.
* Add debug statements to sysdb_opsSimo Sorce2009-08-241-10/+111
|
* Catch possible bad input passed in by glibcSimo Sorce2009-08-242-0/+20
| | | | Seen in tests and was leading to a segfault
* some UPN handling fixesSumit Bose2009-08-247-28/+79
| | | | | | - making the realm part upper case is now optional and done in the LDAP backend - using a username@realm UPN is now optional
* Fix accidentally forcing MPGs on for all domainsStephen Gallagher2009-08-211-1/+1
|
* extended the documentation of LDAP backendSumit Bose2009-08-212-4/+211
| | | | | Added man pages sections about user and group attribute mapping. Added an example configuration to access an AD server.