xref: /onnv-gate/usr/src/lib/libldap4/common/open.c (revision 0:68f95e015346)
1*0Sstevel@tonic-gate /*
2*0Sstevel@tonic-gate  * Copyright (c) 1995-2001 by Sun Microsystems, Inc.
3*0Sstevel@tonic-gate  * All rights reserved.
4*0Sstevel@tonic-gate  */
5*0Sstevel@tonic-gate 
6*0Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
7*0Sstevel@tonic-gate 
8*0Sstevel@tonic-gate /*
9*0Sstevel@tonic-gate  *  Copyright (c) 1995 Regents of the University of Michigan.
10*0Sstevel@tonic-gate  *  All rights reserved.
11*0Sstevel@tonic-gate  *
12*0Sstevel@tonic-gate  *  open.c
13*0Sstevel@tonic-gate  */
14*0Sstevel@tonic-gate 
15*0Sstevel@tonic-gate #ifndef	lint
16*0Sstevel@tonic-gate static char copyright[] = "@(#) Copyright (c) 1995 Regents of the "
17*0Sstevel@tonic-gate 	"University of Michigan.\nAll rights reserved.\n";
18*0Sstevel@tonic-gate #endif
19*0Sstevel@tonic-gate 
20*0Sstevel@tonic-gate #include <stdio.h>
21*0Sstevel@tonic-gate #include <string.h>
22*0Sstevel@tonic-gate #include <stdlib.h> /* calloc(), free(), atoi() for Solaris */
23*0Sstevel@tonic-gate #include <locale.h>
24*0Sstevel@tonic-gate #include <thread.h>
25*0Sstevel@tonic-gate 
26*0Sstevel@tonic-gate #ifdef MACOS
27*0Sstevel@tonic-gate #include <stdlib.h>
28*0Sstevel@tonic-gate #include "macos.h"
29*0Sstevel@tonic-gate #endif /* MACOS */
30*0Sstevel@tonic-gate 
31*0Sstevel@tonic-gate #if defined(DOS) || defined(_WIN32)
32*0Sstevel@tonic-gate #include "msdos.h"
33*0Sstevel@tonic-gate #include <stdlib.h>
34*0Sstevel@tonic-gate #endif /* DOS */
35*0Sstevel@tonic-gate 
36*0Sstevel@tonic-gate #if !defined(MACOS) && !defined(DOS) && !defined(_WIN32)
37*0Sstevel@tonic-gate #include <sys/time.h>
38*0Sstevel@tonic-gate #include <sys/types.h>
39*0Sstevel@tonic-gate #include <sys/socket.h>
40*0Sstevel@tonic-gate #ifndef VMS
41*0Sstevel@tonic-gate #include <sys/param.h>
42*0Sstevel@tonic-gate #endif
43*0Sstevel@tonic-gate #include <netinet/in.h>
44*0Sstevel@tonic-gate #endif
45*0Sstevel@tonic-gate #include "lber.h"
46*0Sstevel@tonic-gate #include "ldap.h"
47*0Sstevel@tonic-gate #include "ldap-private.h"
48*0Sstevel@tonic-gate #include "ldap-int.h"
49*0Sstevel@tonic-gate 
50*0Sstevel@tonic-gate #ifdef LDAP_DEBUG
51*0Sstevel@tonic-gate int	ldap_debug;
52*0Sstevel@tonic-gate #endif
53*0Sstevel@tonic-gate 
54*0Sstevel@tonic-gate #ifndef INADDR_LOOPBACK
55*0Sstevel@tonic-gate #define	INADDR_LOOPBACK	((unsigned int) 0x7f000001)
56*0Sstevel@tonic-gate #endif
57*0Sstevel@tonic-gate 
58*0Sstevel@tonic-gate #ifndef MAXHOSTNAMELEN
59*0Sstevel@tonic-gate #define	MAXHOSTNAMELEN  64
60*0Sstevel@tonic-gate #endif
61*0Sstevel@tonic-gate 
62*0Sstevel@tonic-gate extern int thr_kill(thread_t, int);
63*0Sstevel@tonic-gate 
64*0Sstevel@tonic-gate /*
65*0Sstevel@tonic-gate  * ldap_open - initialize and connect to an ldap server.  A magic cookie to
66*0Sstevel@tonic-gate  * be used for future communication is returned on success, NULL on failure.
67*0Sstevel@tonic-gate  * "host" may be a space-separated list of hosts or IP addresses
68*0Sstevel@tonic-gate  *
69*0Sstevel@tonic-gate  * Example:
70*0Sstevel@tonic-gate  *	LDAP	*ld;
71*0Sstevel@tonic-gate  *	ld = ldap_open( hostname, port );
72*0Sstevel@tonic-gate  */
73*0Sstevel@tonic-gate 
74*0Sstevel@tonic-gate LDAP *
ldap_open(char * host,int port)75*0Sstevel@tonic-gate ldap_open(char *host, int port)
76*0Sstevel@tonic-gate {
77*0Sstevel@tonic-gate 	LDAP		*ld;
78*0Sstevel@tonic-gate 	int err;
79*0Sstevel@tonic-gate 
80*0Sstevel@tonic-gate 	if ((ld = ldap_init(host, port)) == NULL) {
81*0Sstevel@tonic-gate 		return (NULL);
82*0Sstevel@tonic-gate 	}
83*0Sstevel@tonic-gate 
84*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 113,
85*0Sstevel@tonic-gate 		"ldap_open (after ldap_init)\n"), 0, 0, 0);
86*0Sstevel@tonic-gate 
87*0Sstevel@tonic-gate #ifdef _REENTRANT
88*0Sstevel@tonic-gate 	LOCK_LDAP(ld);
89*0Sstevel@tonic-gate #endif
90*0Sstevel@tonic-gate 	if ((err = open_default_ldap_connection(ld)) != LDAP_SUCCESS) {
91*0Sstevel@tonic-gate #ifdef _REENTRANT
92*0Sstevel@tonic-gate 	UNLOCK_LDAP(ld);
93*0Sstevel@tonic-gate #endif
94*0Sstevel@tonic-gate 		ldap_ld_free(ld, 0);
95*0Sstevel@tonic-gate 		Debug(LDAP_DEBUG_ANY, catgets(slapdcat, 1, 1275,
96*0Sstevel@tonic-gate 			"ldap_open failed, %s\n"),
97*0Sstevel@tonic-gate 			ldap_err2string(err), 0, 0);
98*0Sstevel@tonic-gate 		return (NULL);
99*0Sstevel@tonic-gate 	}
100*0Sstevel@tonic-gate 
101*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 194,
102*0Sstevel@tonic-gate 		"ldap_open successful, ld_host is %s\n"),
103*0Sstevel@tonic-gate 		(ld->ld_host == NULL) ? "(null)" : ld->ld_host, 0, 0);
104*0Sstevel@tonic-gate #ifdef _REENTRANT
105*0Sstevel@tonic-gate 	UNLOCK_LDAP(ld);
106*0Sstevel@tonic-gate #endif
107*0Sstevel@tonic-gate 	return (ld);
108*0Sstevel@tonic-gate 
109*0Sstevel@tonic-gate }
110*0Sstevel@tonic-gate 
111*0Sstevel@tonic-gate /*
112*0Sstevel@tonic-gate  * Open the default connection
113*0Sstevel@tonic-gate  * ld->ld_defconn MUST be null when calling this function,
114*0Sstevel@tonic-gate  * ie the connection was never established
115*0Sstevel@tonic-gate  * ld should be LOCKed before calling this function
116*0Sstevel@tonic-gate  */
117*0Sstevel@tonic-gate int
open_default_ldap_connection(LDAP * ld)118*0Sstevel@tonic-gate open_default_ldap_connection(LDAP *ld)
119*0Sstevel@tonic-gate {
120*0Sstevel@tonic-gate 	LDAPServer	*srv;
121*0Sstevel@tonic-gate 	int err;
122*0Sstevel@tonic-gate 
123*0Sstevel@tonic-gate 	if ((srv = (LDAPServer *)calloc(1, sizeof (LDAPServer))) ==
124*0Sstevel@tonic-gate 	    NULL || (ld->ld_defhost != NULL && (srv->lsrv_host =
125*0Sstevel@tonic-gate 	    strdup(ld->ld_defhost)) == NULL)) {
126*0Sstevel@tonic-gate 		return (LDAP_NO_MEMORY);
127*0Sstevel@tonic-gate 	}
128*0Sstevel@tonic-gate 	srv->lsrv_port = ld->ld_defport;
129*0Sstevel@tonic-gate 
130*0Sstevel@tonic-gate 	if ((ld->ld_defconn = new_connection(ld, &srv, 1, 1, 0)) ==
131*0Sstevel@tonic-gate 		NULL) {
132*0Sstevel@tonic-gate 		err = ld->ld_errno;
133*0Sstevel@tonic-gate 		Debug(LDAP_DEBUG_ANY, catgets(slapdcat, 1, 1276,
134*0Sstevel@tonic-gate 		"Default connection to ldap server %s couldn't be "
135*0Sstevel@tonic-gate 		"opened (%d)\n"), ld->ld_defhost, err, 0);
136*0Sstevel@tonic-gate 
137*0Sstevel@tonic-gate 		if (ld->ld_defhost != NULL)
138*0Sstevel@tonic-gate 			free(srv->lsrv_host);
139*0Sstevel@tonic-gate 		free((char *)srv);
140*0Sstevel@tonic-gate 		return (err);
141*0Sstevel@tonic-gate 	}
142*0Sstevel@tonic-gate 
143*0Sstevel@tonic-gate 	/* so it never gets closed/freed */
144*0Sstevel@tonic-gate 	++ld->ld_defconn->lconn_refcnt;
145*0Sstevel@tonic-gate 
146*0Sstevel@tonic-gate 	return (LDAP_SUCCESS);
147*0Sstevel@tonic-gate }
148*0Sstevel@tonic-gate 
149*0Sstevel@tonic-gate static pthread_mutex_t ldap_thr_index_mutex = {0};
150*0Sstevel@tonic-gate static pthread_t ldap_thr_table[MAX_THREAD_ID] = {0};
151*0Sstevel@tonic-gate 
152*0Sstevel@tonic-gate int
ldap_thr_index()153*0Sstevel@tonic-gate ldap_thr_index()
154*0Sstevel@tonic-gate {
155*0Sstevel@tonic-gate 	int i = 0;
156*0Sstevel@tonic-gate 	int free = 0;
157*0Sstevel@tonic-gate 	pthread_t cur = thr_self();
158*0Sstevel@tonic-gate 	for (i = 1; i < MAX_THREAD_ID; ++i) {
159*0Sstevel@tonic-gate 		if (ldap_thr_table[i] == cur) {
160*0Sstevel@tonic-gate 			return (i);
161*0Sstevel@tonic-gate 		} /* end if */
162*0Sstevel@tonic-gate 	} /* end for */
163*0Sstevel@tonic-gate 	/*
164*0Sstevel@tonic-gate 	 * not in the table, allocate a new entry
165*0Sstevel@tonic-gate 	 */
166*0Sstevel@tonic-gate 	pthread_mutex_lock(&ldap_thr_index_mutex);
167*0Sstevel@tonic-gate 	for (i = 1; i < MAX_THREAD_ID; ++i) {
168*0Sstevel@tonic-gate 		if (ldap_thr_table[i] == 0 ||
169*0Sstevel@tonic-gate 			thr_kill(ldap_thr_table[i], 0) != 0) {
170*0Sstevel@tonic-gate 			ldap_thr_table[i] = cur;
171*0Sstevel@tonic-gate 			pthread_mutex_unlock(&ldap_thr_index_mutex);
172*0Sstevel@tonic-gate 			return (i);
173*0Sstevel@tonic-gate 		} /* end if */
174*0Sstevel@tonic-gate 	} /* end for */
175*0Sstevel@tonic-gate 	pthread_mutex_unlock(&ldap_thr_index_mutex);
176*0Sstevel@tonic-gate 	/* if table is full, return the first entry, so that it */
177*0Sstevel@tonic-gate 	/* doesn't core dump */
178*0Sstevel@tonic-gate 	return (0);
179*0Sstevel@tonic-gate }
180*0Sstevel@tonic-gate 
181*0Sstevel@tonic-gate /*
182*0Sstevel@tonic-gate  * ldap_init - initialize the LDAP library.  A magic cookie to be used for
183*0Sstevel@tonic-gate  * future communication is returned on success, NULL on failure.
184*0Sstevel@tonic-gate  * "defhost" may be a space-separated list of hosts or IP addresses
185*0Sstevel@tonic-gate  *
186*0Sstevel@tonic-gate  * Example:
187*0Sstevel@tonic-gate  *	LDAP	*ld;
188*0Sstevel@tonic-gate  *	ld = ldap_init( default_hostname, default_port );
189*0Sstevel@tonic-gate  */
190*0Sstevel@tonic-gate LDAP *
ldap_init(char * defhost,int defport)191*0Sstevel@tonic-gate ldap_init(char *defhost, int defport)
192*0Sstevel@tonic-gate {
193*0Sstevel@tonic-gate 	LDAP			*ld;
194*0Sstevel@tonic-gate 	char *locale;
195*0Sstevel@tonic-gate 
196*0Sstevel@tonic-gate 	locale = setlocale(LC_ALL, "");
197*0Sstevel@tonic-gate 	i18n_catopen("sdserver");
198*0Sstevel@tonic-gate 
199*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 195,
200*0Sstevel@tonic-gate 		"ldap_init\n"), 0, 0, 0);
201*0Sstevel@tonic-gate 
202*0Sstevel@tonic-gate 
203*0Sstevel@tonic-gate 	if ((ld = (LDAP *) calloc(1, sizeof (LDAP))) == NULL) {
204*0Sstevel@tonic-gate 		return (NULL);
205*0Sstevel@tonic-gate 	}
206*0Sstevel@tonic-gate 
207*0Sstevel@tonic-gate #ifdef _REENTRANT
208*0Sstevel@tonic-gate 	pthread_mutex_init(&ld->ld_ldap_mutex, DEFAULT_TYPE);
209*0Sstevel@tonic-gate 	pthread_mutex_init(&ld->ld_response_mutex, DEFAULT_TYPE);
210*0Sstevel@tonic-gate 	pthread_mutex_init(&ld->ld_poll_mutex, DEFAULT_TYPE);
211*0Sstevel@tonic-gate 	ld->ld_lockthread = 0;
212*0Sstevel@tonic-gate #endif
213*0Sstevel@tonic-gate 
214*0Sstevel@tonic-gate 	if ((ld->ld_selectinfo = new_select_info()) == NULL) {
215*0Sstevel@tonic-gate 		free((char *)ld);
216*0Sstevel@tonic-gate 		return (NULL);
217*0Sstevel@tonic-gate 	}
218*0Sstevel@tonic-gate 	ld->ld_follow_referral = 1;
219*0Sstevel@tonic-gate 
220*0Sstevel@tonic-gate 	/*
221*0Sstevel@tonic-gate 	 * default to localhost when hostname is not specified
222*0Sstevel@tonic-gate 	 * or if null string is passed as hostname
223*0Sstevel@tonic-gate 	 */
224*0Sstevel@tonic-gate 
225*0Sstevel@tonic-gate 	if ((defhost != NULL) && (*defhost != NULL) &&
226*0Sstevel@tonic-gate 		(ld->ld_defhost = strdup(defhost)) == NULL) {
227*0Sstevel@tonic-gate 		free_select_info(ld->ld_selectinfo);
228*0Sstevel@tonic-gate 		free((char *)ld);
229*0Sstevel@tonic-gate 		return (NULL);
230*0Sstevel@tonic-gate 	}
231*0Sstevel@tonic-gate 
232*0Sstevel@tonic-gate 	ld->ld_defport = (defport == 0) ? LDAP_PORT : defport;
233*0Sstevel@tonic-gate 	ld->ld_version = LDAP_VERSION;
234*0Sstevel@tonic-gate 	ld->ld_lberoptions = LBER_USE_DER;
235*0Sstevel@tonic-gate 	ld->ld_refhoplimit = LDAP_DEFAULT_REFHOPLIMIT;
236*0Sstevel@tonic-gate 	ld->ld_connect_timeout = LDAP_X_IO_TIMEOUT_NO_TIMEOUT;
237*0Sstevel@tonic-gate 
238*0Sstevel@tonic-gate #if defined(STR_TRANSLATION) && defined(LDAP_DEFAULT_CHARSET)
239*0Sstevel@tonic-gate 	ld->ld_lberoptions |= LBER_TRANSLATE_STRINGS;
240*0Sstevel@tonic-gate #if LDAP_CHARSET_8859 == LDAP_DEFAULT_CHARSET
241*0Sstevel@tonic-gate 	ldap_set_string_translators(ld, ldap_8859_to_t61,
242*0Sstevel@tonic-gate 		ldap_t61_to_8859);
243*0Sstevel@tonic-gate #endif /* LDAP_CHARSET_8859 == LDAP_DEFAULT_CHARSET */
244*0Sstevel@tonic-gate #endif /* STR_TRANSLATION && LDAP_DEFAULT_CHARSET */
245*0Sstevel@tonic-gate 
246*0Sstevel@tonic-gate 	return (ld);
247*0Sstevel@tonic-gate }
248*0Sstevel@tonic-gate 
249*0Sstevel@tonic-gate 
250*0Sstevel@tonic-gate /* ARGSUSED */
251*0Sstevel@tonic-gate int
open_ldap_connection(LDAP * ld,Sockbuf * sb,char * host,int defport,char ** krbinstancep,int async)252*0Sstevel@tonic-gate open_ldap_connection(LDAP *ld, Sockbuf *sb, char *host, int defport,
253*0Sstevel@tonic-gate 	char **krbinstancep, int async)
254*0Sstevel@tonic-gate {
255*0Sstevel@tonic-gate 	int 			rc, port;
256*0Sstevel@tonic-gate 	char			*p, *q, *r;
257*0Sstevel@tonic-gate 	char			*curhost, hostname[ 2*MAXHOSTNAMELEN ];
258*0Sstevel@tonic-gate 	int			bindTimeout;
259*0Sstevel@tonic-gate 
260*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 196,
261*0Sstevel@tonic-gate 		"open_ldap_connection\n"), 0, 0, 0);
262*0Sstevel@tonic-gate 
263*0Sstevel@tonic-gate 	defport = htons(defport);
264*0Sstevel@tonic-gate 	bindTimeout = ld->ld_connect_timeout;
265*0Sstevel@tonic-gate 
266*0Sstevel@tonic-gate 	if (host != NULL) {
267*0Sstevel@tonic-gate 		for (p = host; p != NULL && *p != '\0'; p = q) {
268*0Sstevel@tonic-gate 			if ((q = strchr(p, ' ')) != NULL) {
269*0Sstevel@tonic-gate 				(void) strncpy(hostname, p, q - p);
270*0Sstevel@tonic-gate 				hostname[ q - p ] = '\0';
271*0Sstevel@tonic-gate 				curhost = hostname;
272*0Sstevel@tonic-gate 				while (*q == ' ') {
273*0Sstevel@tonic-gate 					++q;
274*0Sstevel@tonic-gate 				}
275*0Sstevel@tonic-gate 			} else {
276*0Sstevel@tonic-gate 				/* avoid copy if possible */
277*0Sstevel@tonic-gate 				curhost = p;
278*0Sstevel@tonic-gate 				q = NULL;
279*0Sstevel@tonic-gate 			}
280*0Sstevel@tonic-gate 
281*0Sstevel@tonic-gate 			if ((r = strchr(curhost, ':')) != NULL) {
282*0Sstevel@tonic-gate 			    if (curhost != hostname) {
283*0Sstevel@tonic-gate 				/* now copy */
284*0Sstevel@tonic-gate 				(void) strcpy(hostname, curhost);
285*0Sstevel@tonic-gate 				r = hostname + (r - curhost);
286*0Sstevel@tonic-gate 				curhost = hostname;
287*0Sstevel@tonic-gate 			    }
288*0Sstevel@tonic-gate 			    *r++ = '\0';
289*0Sstevel@tonic-gate 			    port = htons((short)atoi(r));
290*0Sstevel@tonic-gate 			} else {
291*0Sstevel@tonic-gate 			    port = defport;
292*0Sstevel@tonic-gate 			}
293*0Sstevel@tonic-gate 
294*0Sstevel@tonic-gate 			if ((rc = connect_to_host(sb, curhost, 0,
295*0Sstevel@tonic-gate 			    port, async, bindTimeout)) != -1) {
296*0Sstevel@tonic-gate 				break;
297*0Sstevel@tonic-gate 			}
298*0Sstevel@tonic-gate 		}
299*0Sstevel@tonic-gate 	} else {
300*0Sstevel@tonic-gate 		rc = connect_to_host(sb, NULL, htonl(INADDR_LOOPBACK),
301*0Sstevel@tonic-gate 			defport, async, bindTimeout);
302*0Sstevel@tonic-gate 	}
303*0Sstevel@tonic-gate 
304*0Sstevel@tonic-gate 	if (rc == -1) {
305*0Sstevel@tonic-gate 		return (rc);
306*0Sstevel@tonic-gate 	}
307*0Sstevel@tonic-gate 
308*0Sstevel@tonic-gate 	if (krbinstancep != NULL) {
309*0Sstevel@tonic-gate #ifdef KERBEROS
310*0Sstevel@tonic-gate 		if ((*krbinstancep = host_connected_to(sb)) != NULL &&
311*0Sstevel@tonic-gate 			(p = strchr(*krbinstancep, '.')) != NULL) {
312*0Sstevel@tonic-gate 			*p = '\0';
313*0Sstevel@tonic-gate 		}
314*0Sstevel@tonic-gate #else /* KERBEROS */
315*0Sstevel@tonic-gate 		krbinstancep = NULL;
316*0Sstevel@tonic-gate #endif /* KERBEROS */
317*0Sstevel@tonic-gate 	}
318*0Sstevel@tonic-gate 
319*0Sstevel@tonic-gate 	return (0);
320*0Sstevel@tonic-gate }
321*0Sstevel@tonic-gate 
322*0Sstevel@tonic-gate /*
323*0Sstevel@tonic-gate  * ldap_ssl_open - initialize and connect to an ssl secured ldap
324*0Sstevel@tonic-gate  * server.  First ldap_open() is called and then ssl is layered on top
325*0Sstevel@tonic-gate  * of the socket.  A magic cookie to be used for future communication
326*0Sstevel@tonic-gate  * is returned on success, NULL on failure.  "host" may be a
327*0Sstevel@tonic-gate  * space-separated list of hosts or IP addresses.  CAfile and CApath
328*0Sstevel@tonic-gate  * are used first time through, subsequent calls are ignored and can
329*0Sstevel@tonic-gate  * be NULL.
330*0Sstevel@tonic-gate  *
331*0Sstevel@tonic-gate  * Example:
332*0Sstevel@tonic-gate  *	LDAP	*ld;
333*0Sstevel@tonic-gate  * ld = ldap_ssl_open( hostname, port, key );
334*0Sstevel@tonic-gate  */
335*0Sstevel@tonic-gate 
336*0Sstevel@tonic-gate #ifdef LDAP_SSL
337*0Sstevel@tonic-gate 
338*0Sstevel@tonic-gate #include "security/ssl.h"
339*0Sstevel@tonic-gate 
340*0Sstevel@tonic-gate int
establish_ssl_connection(LDAP * ld)341*0Sstevel@tonic-gate establish_ssl_connection(LDAP *ld)
342*0Sstevel@tonic-gate {
343*0Sstevel@tonic-gate 	SSL *ssl = NULL;	/* The Client's SSL connection */
344*0Sstevel@tonic-gate 
345*0Sstevel@tonic-gate 	/*
346*0Sstevel@tonic-gate 	 * Creates a new SSL connection.  This holds information
347*0Sstevel@tonic-gate 	 * pertinent to this
348*0Sstevel@tonic-gate 	 * connection.
349*0Sstevel@tonic-gate 	 */
350*0Sstevel@tonic-gate 	if ((ssl = SSL_new()) == NULL) {
351*0Sstevel@tonic-gate 		Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 198,
352*0Sstevel@tonic-gate 			"SSL_new() failed: %s\n"),
353*0Sstevel@tonic-gate 			SSL_strerr(SSL_errno(ssl)), 0, 0);
354*0Sstevel@tonic-gate 		return (-1);
355*0Sstevel@tonic-gate 	}
356*0Sstevel@tonic-gate 
357*0Sstevel@tonic-gate 	/* if keyname is non-null, set ssl keypackage name from it */
358*0Sstevel@tonic-gate 	if (ld->ld_ssl_key != NULL) {
359*0Sstevel@tonic-gate 		if (SSL_set_userid(ssl, ld->ld_ssl_key, 0) == NULL) {
360*0Sstevel@tonic-gate 			Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1,
361*0Sstevel@tonic-gate 				199, "SSL_set_userid() failed: %s\n"),
362*0Sstevel@tonic-gate 				SSL_strerr(SSL_errno(ssl)), 0, 0);
363*0Sstevel@tonic-gate 			return (-1);
364*0Sstevel@tonic-gate 		}
365*0Sstevel@tonic-gate 	}
366*0Sstevel@tonic-gate 
367*0Sstevel@tonic-gate 	/* Start the SSL connection */
368*0Sstevel@tonic-gate 	if (SSL_connect(ssl, ld->ld_sb.sb_sd) < 1) {
369*0Sstevel@tonic-gate 		Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 200,
370*0Sstevel@tonic-gate 			"SSL_connect() failed: %s\n"),
371*0Sstevel@tonic-gate 			SSL_strerr(SSL_errno(ssl)), 0, 0);
372*0Sstevel@tonic-gate 		return (-1);
373*0Sstevel@tonic-gate 	}
374*0Sstevel@tonic-gate 
375*0Sstevel@tonic-gate 	ld->ld_sb.sb_ssl = ssl;
376*0Sstevel@tonic-gate 	return (0);
377*0Sstevel@tonic-gate }
378*0Sstevel@tonic-gate 
379*0Sstevel@tonic-gate 
380*0Sstevel@tonic-gate LDAP *
ldap_ssl_open(char * host,int port,char * keyname)381*0Sstevel@tonic-gate ldap_ssl_open(char *host, int port, char *keyname)
382*0Sstevel@tonic-gate {
383*0Sstevel@tonic-gate 	LDAP		*ld;
384*0Sstevel@tonic-gate 	int rval;
385*0Sstevel@tonic-gate 
386*0Sstevel@tonic-gate 
387*0Sstevel@tonic-gate 	if (port == 0)
388*0Sstevel@tonic-gate 		port = SSL_LDAP_PORT;
389*0Sstevel@tonic-gate 
390*0Sstevel@tonic-gate 	ld = ldap_open(host, port);
391*0Sstevel@tonic-gate 
392*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 197,
393*0Sstevel@tonic-gate 		"ldap_ssl_open (after ldap_open)\n"), 0, 0, 0);
394*0Sstevel@tonic-gate 
395*0Sstevel@tonic-gate 	if (ld == NULL)
396*0Sstevel@tonic-gate 		return (NULL);
397*0Sstevel@tonic-gate 
398*0Sstevel@tonic-gate 	ld->ld_use_ssl = 1;
399*0Sstevel@tonic-gate 	if (keyname)
400*0Sstevel@tonic-gate 		ld->ld_ssl_key = strdup(keyname);
401*0Sstevel@tonic-gate 
402*0Sstevel@tonic-gate 	if (establish_ssl_connection(ld) != 0) {
403*0Sstevel@tonic-gate 		ldap_ld_free(ld, 1);
404*0Sstevel@tonic-gate 		return (NULL);
405*0Sstevel@tonic-gate 	}
406*0Sstevel@tonic-gate 
407*0Sstevel@tonic-gate 	return (ld);
408*0Sstevel@tonic-gate }
409*0Sstevel@tonic-gate 
410*0Sstevel@tonic-gate LDAP *
ldap_ssl_init(char * defhost,int defport,char * keyname)411*0Sstevel@tonic-gate ldap_ssl_init(char *defhost, int defport, char *keyname)
412*0Sstevel@tonic-gate {
413*0Sstevel@tonic-gate 	LDAP		*ld;
414*0Sstevel@tonic-gate 	int rval;
415*0Sstevel@tonic-gate 
416*0Sstevel@tonic-gate 
417*0Sstevel@tonic-gate 	if (defport == 0)
418*0Sstevel@tonic-gate 		defport = SSL_LDAP_PORT;
419*0Sstevel@tonic-gate 
420*0Sstevel@tonic-gate 	ld = ldap_init(defhost, defport);
421*0Sstevel@tonic-gate 
422*0Sstevel@tonic-gate 	Debug(LDAP_DEBUG_TRACE, catgets(slapdcat, 1, 197,
423*0Sstevel@tonic-gate 		"ldap_ssl_open (after ldap_open)\n"), 0, 0, 0);
424*0Sstevel@tonic-gate 
425*0Sstevel@tonic-gate 	if (ld == NULL)
426*0Sstevel@tonic-gate 		return (NULL);
427*0Sstevel@tonic-gate 	ld->ld_use_ssl = 1;
428*0Sstevel@tonic-gate 	ld->ld_ssl_key = strdup(keyname);
429*0Sstevel@tonic-gate 
430*0Sstevel@tonic-gate 	return (ld);
431*0Sstevel@tonic-gate }
432*0Sstevel@tonic-gate 
433*0Sstevel@tonic-gate #endif /* LDAP_SSL */
434