diff options
author | Lukas Slebodnik <lslebodn@redhat.com> | 2013-04-24 20:26:40 +0200 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2013-05-03 19:59:40 +0200 |
commit | b24e4bec819b29f1ec8e77083d4e7610c5dd9c77 (patch) | |
tree | 393b76738d8cd9cd4f5b463e37ff96421a839e74 /src/providers/ipa | |
parent | e3db994ddc8eda225c4cc3c90e9c0bd82281faf6 (diff) | |
download | sssd-b24e4bec819b29f1ec8e77083d4e7610c5dd9c77.tar.gz sssd-b24e4bec819b29f1ec8e77083d4e7610c5dd9c77.tar.bz2 sssd-b24e4bec819b29f1ec8e77083d4e7610c5dd9c77.zip |
SUDO: IPA provider
This patch added auto configuration SUDO with ipa provider and compat tree.
https://fedorahosted.org/sssd/ticket/1733
Diffstat (limited to 'src/providers/ipa')
-rw-r--r-- | src/providers/ipa/ipa_common.h | 5 | ||||
-rw-r--r-- | src/providers/ipa/ipa_init.c | 24 | ||||
-rw-r--r-- | src/providers/ipa/ipa_sudo.c | 55 |
3 files changed, 84 insertions, 0 deletions
diff --git a/src/providers/ipa/ipa_common.h b/src/providers/ipa/ipa_common.h index ae1c9173..d5c10a51 100644 --- a/src/providers/ipa/ipa_common.h +++ b/src/providers/ipa/ipa_common.h @@ -180,4 +180,9 @@ int ipa_service_init(TALLOC_CTX *memctx, struct be_ctx *ctx, struct ipa_options *options, struct ipa_service **_service); +int ipa_sudo_init(struct be_ctx *be_ctx, + struct ipa_id_ctx *id_ctx, + struct bet_ops **ops, + void **pvt_data); + #endif /* _IPA_COMMON_H_ */ diff --git a/src/providers/ipa/ipa_init.c b/src/providers/ipa/ipa_init.c index b65a6cea..0e9fe0dd 100644 --- a/src/providers/ipa/ipa_init.c +++ b/src/providers/ipa/ipa_init.c @@ -526,3 +526,27 @@ int sssm_ipa_subdomains_init(struct be_ctx *bectx, return EOK; } + +int sssm_ipa_sudo_init(struct be_ctx *bectx, + struct bet_ops **ops, + void **pvt_data) +{ +#ifdef BUILD_SUDO + struct ipa_id_ctx *id_ctx; + int ret; + + DEBUG(SSSDBG_TRACE_INTERNAL, ("Initializing IPA sudo handler\n")); + + ret = sssm_ipa_id_init(bectx, ops, (void **) &id_ctx); + if (ret != EOK) { + DEBUG(SSSDBG_CRIT_FAILURE, ("sssm_ipa_id_init failed.\n")); + return ret; + } + + return ipa_sudo_init(bectx, id_ctx, ops, pvt_data); +#else + DEBUG(SSSDBG_MINOR_FAILURE, ("Sudo init handler called but SSSD is " + "built without sudo support, ignoring\n")); + return EOK; +#endif +} diff --git a/src/providers/ipa/ipa_sudo.c b/src/providers/ipa/ipa_sudo.c new file mode 100644 index 00000000..726b1168 --- /dev/null +++ b/src/providers/ipa/ipa_sudo.c @@ -0,0 +1,55 @@ +/* + SSSD + + IPA Provider Initialization functions + + Authors: + Lukas Slebodnik <lslebodn@redhat.com> + + Copyright (C) 2013 Red Hat + + This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation; either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + You should have received a copy of the GNU General Public License + along with this program. If not, see <http://www.gnu.org/licenses/>. +*/ + +#include "providers/ipa/ipa_common.h" +#include "providers/ldap/sdap_sudo.h" + +int ipa_sudo_init(struct be_ctx *be_ctx, + struct ipa_id_ctx *id_ctx, + struct bet_ops **ops, + void **pvt_data) +{ + int ret; + struct ipa_options *ipa_options; + struct sdap_options *ldap_options; + + DEBUG(SSSDBG_TRACE_INTERNAL, ("Initializing sudo IPA back end\n")); + + /* + * SDAP_SUDO_SEARCH_BASE has already been initialized in + * function ipa_get_id_options + */ + ret = sdap_sudo_init(be_ctx, id_ctx->sdap_id_ctx, ops, pvt_data); + if (ret != EOK) { + DEBUG(SSSDBG_OP_FAILURE, ("Cannot initialize LDAP SUDO [%d]: %s\n", + ret, strerror(ret))); + return ret; + } + + ipa_options = id_ctx->ipa_options; + ldap_options = id_ctx->sdap_id_ctx->opts; + + ipa_options->id->sudorule_map = ldap_options->sudorule_map; + return EOK; +} |