Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | LDAP: Try next failover server on any error | Stephen Gallagher | 2011-11-29 | 1 | -9/+5 | |
| | ||||||
* | Fixed logically dead code in netgroup processing | Jan Zeleny | 2011-11-28 | 1 | -1/+1 | |
| | ||||||
* | Fixed uninitialized pointer read in netgroups processing | Jan Zeleny | 2011-11-28 | 1 | -0/+6 | |
| | ||||||
* | Fix sdap_id_ctx/ipa_id_ctx mismatch in IPA provider | Jakub Hrozek | 2011-11-25 | 4 | -4/+18 | |
| | | | | | This was causing a segfault during HBAC processing and any ID lookups except for netgroups | |||||
* | Added IPA account info handler | Jan Zeleny | 2011-11-23 | 3 | -1/+373 | |
| | | | | | Currently it is only handling netgroups by itself, other requests are forwarded to LDAP provider. | |||||
* | Added support for fetching netgroups in IPA provider | Jan Zeleny | 2011-11-23 | 1 | -0/+992 | |
| | ||||||
* | New IPA ID context | Jan Zeleny | 2011-11-23 | 3 | -22/+37 | |
| | ||||||
* | Added and modified options for IPA netgroups | Jan Zeleny | 2011-11-23 | 2 | -24/+69 | |
| | ||||||
* | Modified sdap_parse_search_base() | Jan Zeleny | 2011-11-23 | 4 | -16/+14 | |
| | ||||||
* | Renamed some LDAP routines | Jan Zeleny | 2011-11-23 | 6 | -41/+49 | |
| | | | | | These were renamed just ot make sure they are not mistook for IPA netgroup functions. | |||||
* | Set more strict permissions on keyring | Simo Sorce | 2011-11-22 | 1 | -1/+1 | |
| | | | | | We want to confine access to the keyring to the current process and not let root easily peek into the keyring contents. | |||||
* | Fixed unchecked value of setenv() in check_and_export_options() | Jan Zeleny | 2011-11-22 | 1 | -2/+5 | |
| | | | | https://fedorahosted.org/sssd/ticket/1080 | |||||
* | Cleanup: Remove unused parameters | Jakub Hrozek | 2011-11-22 | 25 | -119/+38 | |
| | ||||||
* | Prevent printing NULL in several places of LDAP provider | Jakub Hrozek | 2011-11-18 | 2 | -5/+9 | |
| | ||||||
* | Use one transaction instead of two during RFC2307bis group processing | Jakub Hrozek | 2011-11-11 | 1 | -31/+55 | |
| | | | | https://fedorahosted.org/sssd/ticket/1054 | |||||
* | Squash transactions in sdap_initgr_common_store | Jakub Hrozek | 2011-11-11 | 1 | -6/+25 | |
| | | | | https://fedorahosted.org/sssd/ticket/1053 | |||||
* | LDAP: Remove redundant groups from the lookup list | Stephen Gallagher | 2011-11-08 | 1 | -23/+0 | |
| | ||||||
* | Fixed empty loginShell in proxy provider | Jan Zeleny | 2011-11-07 | 1 | -4/+32 | |
| | | | | https://fedorahosted.org/sssd/ticket/892 | |||||
* | Use correct state struct in sdap_initgr_rfc2307bis_next_base | Jakub Hrozek | 2011-11-07 | 1 | -2/+3 | |
| | ||||||
* | Fix segfault in sdap_get_initgr_user | Jakub Hrozek | 2011-11-07 | 1 | -1/+2 | |
| | ||||||
* | Support to request canonicalization in LDAP/IPA provider | Jan Zeleny | 2011-11-02 | 7 | -1/+28 | |
| | | | | https://fedorahosted.org/sssd/ticket/957 | |||||
* | Add support to request canonicalization on krb AS requests | Jan Zeleny | 2011-11-02 | 5 | -3/+28 | |
| | | | | https://fedorahosted.org/sssd/ticket/957 | |||||
* | LDAP: Add support for multiple search bases for group enumeration | Stephen Gallagher | 2011-11-02 | 4 | -24/+101 | |
| | ||||||
* | LDAP: Add support for multiple search bases for user enumeration | Stephen Gallagher | 2011-11-02 | 4 | -8/+49 | |
| | ||||||
* | LDAP: Convert ldap_*_search_filter | Stephen Gallagher | 2011-11-02 | 3 | -59/+23 | |
| | | | | | | Instead of making this a global option for all user lookups, make it only used if the search base is passed without an explicit filter. | |||||
* | LDAP: Add multiple search bases for initgroups (RFC2307bis groups) | Stephen Gallagher | 2011-11-02 | 1 | -77/+225 | |
| | ||||||
* | LDAP: Add multiple search bases for initgroups (RFC2307 groups) | Stephen Gallagher | 2011-11-02 | 1 | -17/+99 | |
| | ||||||
* | LDAP: Add multiple search bases for initgroups (users) | Stephen Gallagher | 2011-11-02 | 1 | -30/+72 | |
| | ||||||
* | LDAP: Support multiple group search bases (non-enumeration, RFC2307) | Stephen Gallagher | 2011-11-02 | 4 | -16/+74 | |
| | ||||||
* | LDAP: Support multiple netgroup search bases | Stephen Gallagher | 2011-11-02 | 3 | -14/+65 | |
| | ||||||
* | LDAP: Support multiple user search bases (non-enumeration) | Stephen Gallagher | 2011-11-02 | 4 | -14/+70 | |
| | ||||||
* | LDAP: Add parser for multiple search bases | Stephen Gallagher | 2011-11-02 | 5 | -26/+380 | |
| | ||||||
* | Make sdap_get_id_specific_filter() more strict | Stephen Gallagher | 2011-11-02 | 2 | -4/+4 | |
| | ||||||
* | Fix size return for split_on_separator() | Stephen Gallagher | 2011-11-02 | 1 | -5/+5 | |
| | | | | | | | It was returning the size of the array, rather than the number of elements. (The array was NULL-terminated). This argument was only used in one place that was actually working around this odd return value. | |||||
* | Remove unused sdap_options attributes | Stephen Gallagher | 2011-11-02 | 1 | -3/+0 | |
| | | | | These DNs were never assigned or referenced anywhere. | |||||
* | Cleanup of unused function in ldap access provider | Jan Zeleny | 2011-11-02 | 1 | -2/+0 | |
| | ||||||
* | Remove confusing do-while loop | Jakub Hrozek | 2011-11-02 | 1 | -35/+36 | |
| | | | | | The deref processing would return a single control back. The do-while loop was harmless but confusing. | |||||
* | Use LDAPDerefSpec properly | Jakub Hrozek | 2011-11-02 | 1 | -4/+6 | |
| | | | | | | | | ldap_create_deref_control_value expects an array of LDAPDerefSpec structures with LDAPDerefSpec.derefAttr == NULL as a sentinel. We were passing a single instance of a LDAPDerefSpec structure. https://fedorahosted.org/sssd/ticket/1050 | |||||
* | Steal result onto mem_ctx in sdap_initgr_nested_get_direct_parents | Jakub Hrozek | 2011-10-31 | 1 | -2/+1 | |
| | ||||||
* | RFC2307bis initgroups: fix nested groups processing | Jakub Hrozek | 2011-10-31 | 1 | -20/+33 | |
| | | | | | Due to incorrectly written loop, SSSD would go into infitite loop if it processed the same group on two different levels of membership. | |||||
* | Do not leak hash table iterator during proxy auth | Jakub Hrozek | 2011-10-31 | 1 | -0/+1 | |
| | ||||||
* | Plug memory leaks in LDAP provider | Jakub Hrozek | 2011-10-25 | 1 | -0/+3 | |
| | ||||||
* | Cancel transactions correctly during initgroups | Jakub Hrozek | 2011-10-17 | 1 | -13/+31 | |
| | ||||||
* | Use fewer transactions during IPA initgroups | Jakub Hrozek | 2011-10-17 | 1 | -171/+273 | |
| | ||||||
* | Use fewer transactions during RFC2307bis initgroups | Jakub Hrozek | 2011-10-17 | 1 | -346/+366 | |
| | ||||||
* | Utility functions for LDAP nested schema initgroups | Jakub Hrozek | 2011-10-17 | 1 | -0/+119 | |
| | ||||||
* | Add a missing break | Jakub Hrozek | 2011-10-17 | 1 | -0/+1 | |
| | ||||||
* | HBAC: Use originalMember for identifying hostgroups | Stephen Gallagher | 2011-10-14 | 3 | -45/+165 | |
| | ||||||
* | HBAC: Use originalMember for identifying servicegroups | Stephen Gallagher | 2011-10-14 | 3 | -41/+169 | |
| | ||||||
* | HBAC: Do not save member/memberOf links | Stephen Gallagher | 2011-10-14 | 1 | -120/+0 | |
| | | | | We can just trust the values from the FreeIPA server |