From 87f3fa68e8223111bd53e4bc7a4842b1a35f0ee7 Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Tue, 5 Jul 2011 11:37:45 +0200 Subject: Call ldap_install_tls() on ldaps connections --- src/util/sss_ldap.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/src/util/sss_ldap.c b/src/util/sss_ldap.c index e24ae82b..1394b4d6 100644 --- a/src/util/sss_ldap.c +++ b/src/util/sss_ldap.c @@ -422,6 +422,21 @@ static void sss_ldap_init_sys_connect_done(struct tevent_req *subreq) return; } + if (ldap_is_ldaps_url(state->uri)) { + lret = ldap_install_tls(state->ldap); + if (lret != LDAP_SUCCESS) { + if (lret == LDAP_LOCAL_ERROR) { + DEBUG(5, ("TLS/SSL already in place.\n")); + } else { + DEBUG(1, ("ldap_install_tls failed: %s\n", + ldap_err2string(lret))); + + tevent_req_error(req, EIO); + return; + } + } + } + tevent_req_done(req); return; } -- cgit