From 4848bc7529bc24da71d914256d50b04748d77b13 Mon Sep 17 00:00:00 2001 From: Scott Ullrich Date: Sun, 30 Dec 2007 23:18:36 +0000 Subject: [PATCH] Add LDAP test functions to verify that the LDAP settings are correct. Return the OU's and show to the user after test completion. --- etc/inc/auth.inc | 46 +++++++++++- usr/local/www/system_usermanager_settings.php | 27 ++++--- .../www/system_usermanager_settings_test.php | 73 +++++++++++++++++++ 3 files changed, 133 insertions(+), 13 deletions(-) create mode 100755 usr/local/www/system_usermanager_settings_test.php diff --git a/etc/inc/auth.inc b/etc/inc/auth.inc index 73c9a719d0..67b15661d0 100644 --- a/etc/inc/auth.inc +++ b/etc/inc/auth.inc @@ -608,7 +608,42 @@ function passwd_backed($username, $passwd) { return false; } -function ldap_get_user_ous() { +function ldap_test_connection() { + global $config, $g; + + $ldapserver = $config['system']['webgui']['ldapserver']; + $ldapbindun = $config['system']['webgui']['ldapbindun']; + $ldapbindpw = $config['system']['webgui']['ldapbindpw']; + + if (!($ldap = ldap_connect($ldapserver))) { + return false; + } + + return true; +} + +function ldap_test_bind() { + global $config, $g; + + $ldapserver = $config['system']['webgui']['ldapserver']; + $ldapbindun = $config['system']['webgui']['ldapbindun']; + $ldapbindpw = $config['system']['webgui']['ldapbindpw']; + + if (!($ldap = ldap_connect($ldapserver))) { + return false; + } + + ldap_set_option($ldap, LDAP_OPT_REFERRALS, 0); + ldap_set_option($ldap, LDAP_OPT_PROTOCOL_VERSION, 3); + + if (!($res = @ldap_bind($ldap, $ldapbindun, $ldapbindpw))) { + return false; + } + + return true; +} + +function ldap_get_user_ous($show_complete_ou=false) { global $config, $g; $ldapserver = $config['system']['webgui']['ldapserver']; @@ -640,11 +675,16 @@ function ldap_get_user_ous() { $ous = array(); foreach($info as $inf) { + if(!$show_complete_ou) { $inf_split = split(",", $inf['dn']); $ou = $inf_split[0]; $ou = str_replace("OU=","", $ou); - if($ou) - $ous[] = $ou; + } else { + if($inf) + $ou = $inf['dn']; + } + if($ou) + $ous[] = $ou; } return $ous; diff --git a/usr/local/www/system_usermanager_settings.php b/usr/local/www/system_usermanager_settings.php index 6b93754f9f..c34bd8ec54 100755 --- a/usr/local/www/system_usermanager_settings.php +++ b/usr/local/www/system_usermanager_settings.php @@ -31,6 +31,9 @@ POSSIBILITY OF SUCH DAMAGE. */ +if($_POST['savetest']) + $save_and_test = true; + require("guiconfig.inc"); $pconfig['session_timeout'] = &$config['system']['webgui']['session_timeout']; @@ -46,7 +49,7 @@ $pgtitle = array("System","User manager settings"); if ($_POST) { unset($input_errors); - + /* input validation */ $reqdfields = explode(" ", "session_timeout"); $reqdfieldsn = explode(",", "Session Timeout"); @@ -63,12 +66,6 @@ if ($_POST) { if ($timeout > 999) $input_errors[] = gettext("Session timeout must be an integer with value 1 or greater."); - /* if this is an AJAX caller then handle via JSON */ - if (isAjax() && is_array($input_errors)) { - input_errors2Ajax($input_errors); - exit; - } - if (!$input_errors) { @@ -112,7 +109,6 @@ if ($_POST) { $retval = system_password_configure(); sync_webgui_passwords(); - pfSenseHeader("system_usermanager_settings.php"); } } @@ -123,6 +119,16 @@ include("head.inc"); + +\n"; + echo "myRef = window.open('system_usermanager_settings_test.php','mywin', "; + echo "'left=20,top=20,width=500,height=500,toolbar=1,resizable=0');\n"; + echo "\n"; + } +?> + -
@@ -199,7 +205,9 @@ if(!$pconfig['backend'])
  " /> + + " /> + " />
@@ -208,7 +216,6 @@ if(!$pconfig['backend']) - diff --git a/usr/local/www/system_usermanager_settings_test.php b/usr/local/www/system_usermanager_settings_test.php new file mode 100755 index 0000000000..2e11c213c2 --- /dev/null +++ b/usr/local/www/system_usermanager_settings_test.php @@ -0,0 +1,73 @@ + + All rights reserved. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions are met: + + 1. Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. + + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, + INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY + AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE + AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, + OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + POSSIBILITY OF SUCH DAMAGE. +*/ + +require("guiconfig.inc"); + +$ldapserver = $config['system']['webgui']['ldapserver']; +$ldapbindun = $config['system']['webgui']['ldapbindun']; +$ldapbindpw = $config['system']['webgui']['ldapbindpw']; + +$ldapfilter = $config['system']['webgui']['ldapfilter']; + +echo "Testing pfSense LDAP settings... One moment please...

"; + +echo ""; + +echo ""; +else + echo ""; + +echo ""; +else + echo ""; + +echo ""; +else + echo ""; + +echo "
Attempting connection to {$ldapserver}"; +if(ldap_test_connection()) + echo "OK
failed
Attempting bind to {$ldapserver}"; +if(ldap_test_bind()) + echo "OK
failed
Attempting to fetch Organizational Units from {$ldapserver}"; +$ous = ldap_get_user_ous(true); +if(count($ous)>1) + echo "OK
failed

"; + +if(is_array($ous)) { + echo "Organization units found:

"; + echo ""; + foreach($ous as $ou) { + echo ""; + } + echo "
" . $ou . "
"; +} + +?> \ No newline at end of file