README 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129
  1. # BEGIN COPYRIGHT BLOCK
  2. # This Program is free software; you can redistribute it and/or modify it under
  3. # the terms of the GNU General Public License as published by the Free Software
  4. # Foundation; version 2 of the License.
  5. #
  6. # This Program is distributed in the hope that it will be useful, but WITHOUT
  7. # ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. # FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. #
  10. # You should have received a copy of the GNU General Public License along with
  11. # this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. # Place, Suite 330, Boston, MA 02111-1307 USA.
  13. #
  14. # In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. # right to link the code of this Program with code not covered under the GNU
  16. # General Public License ("Non-GPL Code") and to distribute linked combinations
  17. # including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. # permitted under this exception must only link to the code of this Program
  19. # through those well defined interfaces identified in the file named EXCEPTION
  20. # found in the source code files (the "Approved Interfaces"). The files of
  21. # Non-GPL Code may instantiate templates or use macros or inline functions from
  22. # the Approved Interfaces without causing the resulting work to be covered by
  23. # the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. # additions to the list of Approved Interfaces. You must obey the GNU General
  25. # Public License in all respects for all of the Program code and other code used
  26. # in conjunction with the Program except the Non-GPL Code covered by this
  27. # exception. If you modify this file, you may extend this exception to your
  28. # version of the file, but you are not obligated to do so. If you do not wish to
  29. # provide this exception without modification, you must delete this exception
  30. # statement from your version and license this file solely under the GPL without
  31. # exception.
  32. #
  33. #
  34. # Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
  35. # Copyright (C) 2005 Red Hat, Inc.
  36. # All rights reserved.
  37. # END COPYRIGHT BLOCK
  38. #
  39. This directory contains an example program to demonstrate
  40. writing plugins using the "Certificate to LDAP Mapping" API.
  41. Please read the "Managing Servers" manual to find out
  42. about how certificate to ldap mapping can be configured using
  43. the <ServerRoot>/userdb/certmap.conf file. Also refer to the
  44. "Certificate to LDAP Mapping API" documentation to find out
  45. about the various API functions and how you can write your
  46. plugin.
  47. This example demonstrate use of most of the API functions. It
  48. defines a mapping function, a search function, and a verify
  49. function. Read the API doc to learn about these functions.
  50. The init.c file also contains an init function which sets the
  51. mapping, search and verify functions.
  52. The Mapping Function
  53. --------------------
  54. The mapping function extracts the attributes "CN", "E", "O" and
  55. "C" from the certificate's subject DN using the function
  56. ldapu_get_cert_ava_val. If the attributes "C" doesn't exists
  57. then it defaults to "US". It then gets the value of a custom
  58. certmap.conf property "defaultOU" using the function
  59. ldapu_certmap_info_attrval. This demonstrates how you can have
  60. your own custom properties defined in the certmap.conf file.
  61. The mapping function then returns an ldapdn of the form:
  62. "cn=<name>, ou=<defaultOU>, o=<o>, c=<c>".
  63. If the "E" attribute has a value, it returns a filter
  64. "mail=<e>". Finally, the mapping function frees the structures
  65. returned by some of the API functions it called.
  66. The Search Function
  67. -------------------
  68. The search function calls a dummy function to get the
  69. certificate's serial number. It then does a subtree search in
  70. the entire directory for the filter
  71. "certSerialNumber=<serial No.>". If this fails, it calls the
  72. default search function. This demonstrates how you can use the
  73. default functions in your custom functions.
  74. The Verify Function
  75. -------------------
  76. The verify function returns LDAPU_SUCCESS if only one entry was
  77. returned by the search function. Otherwise, it returns
  78. LDAPU_CERT_VERIFY_FUNCTION_FAILED.
  79. Error Reporting
  80. ---------------
  81. To report errors/warning, there is a function defined called
  82. plugin_ereport. This function demonstrates how to get the
  83. subject DN and the issuer DN from the certificate.
  84. Build Procedure
  85. ---------------
  86. On UNIX: Edit the Makefile, and set the variables ARCH & SROOT
  87. according to the comments in the Makefile. Download LDAP C SDK
  88. from the mozilla.org site and make the ldap include
  89. files available in <SROOT>/include. Copy the
  90. ../include/certmap.h file to the <SROOT>/include directory.
  91. Use 'gmake' to build the plugin. A shared library plugin.so
  92. (plugin.sl on HP) will be created in the current directory.
  93. On NT: Execute the following command:
  94. NMAKE /f "Certmap.mak" CFG="Certmap - Win32 Debug"
  95. Certmap.dll will be created in the Debug subdirectory.
  96. Certmap.conf Configuration
  97. --------------------------
  98. Save a copy of certmap.conf file.
  99. Change the certmap.conf file as follows:
  100. certmap default default
  101. default:defaultOU marketing
  102. default:library <path to the shared library>
  103. default:InitFn plugin_init_fn
  104. After experimenting with this example, restore the old copy of
  105. certmap.conf file. Or else, set the certmap.conf file as follows:
  106. certmap default default
  107. default:DNComps
  108. default:FilterComps e, mail, uid
  109. default:VerifyCert on