Re: back-sock and Proxy Authz or SASL Authz-Name

Howard Chu <[email protected]>
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
Michael Ströder wrote:
> HI!
>
> We a currently testing a custom OpenLDAP setup where specific modify requests
> are handled via back-sock (redirected via slapo-rwm) by a handler implemented
> in Python. These modify requests are checked and then passed to the real
> database backend (back-hdb) on behalf of the user bound to slapd. This works
> by looking at the line (binddn: ) passed to the handler by back-sock.
>
> But now there's requirement for proxy authorization. The web application binds
> via SASL bind DIGEST-MD5 and explicitly sets the authzid in the SASL bind
> request which is mapped via authz-regexp to an authz-DN. This setup seems to
> work (tested with commandline-tool ldapwhoami -X authzid) but the authz-DN is
> not passed to the back-sock handler. binddn: still contains the bind-DN of the
> web application.
>
> Is this feasible at all? If not which parts of back-sock would have to be
> patched to make that work?

Look at sock_print_conn() in result.c. You'll have to add appropriate flags 
and keywords in the config and header files as well.

-- 
   -- Howard Chu
   CTO, Symas Corp.           http://www.symas.com
   Director, Highland Sun     http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP  http://www.openldap.org/project/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.