2 Unix SMB/CIFS implementation.
3 LDAP protocol helper functions for SAMBA
5 Copyright (C) Simo Sorce 2005
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
26 #include "../lib/util/asn1.h"
27 #include "libcli/ldap/libcli_ldap.h"
28 #include "libcli/ldap/ldap_proto.h"
29 #include "dsdb/samdb/samdb.h"
31 static bool decode_server_sort_response(void *mem_ctx
, DATA_BLOB in
, void *_out
)
35 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
36 struct ldb_sort_resp_control
*lsrc
;
38 if (!data
) return false;
40 if (!asn1_load(data
, in
)) {
44 lsrc
= talloc(mem_ctx
, struct ldb_sort_resp_control
);
49 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
53 if (!asn1_read_enumerated(data
, &(lsrc
->result
))) {
57 lsrc
->attr_desc
= NULL
;
58 if (asn1_peek_tag(data
, ASN1_OCTET_STRING
)) {
59 if (!asn1_read_OctetString(data
, mem_ctx
, &attr
)) {
62 lsrc
->attr_desc
= talloc_strndup(lsrc
, (const char *)attr
.data
, attr
.length
);
63 if (!lsrc
->attr_desc
) {
68 if (!asn1_end_tag(data
)) {
77 static bool decode_server_sort_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
82 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
83 struct ldb_server_sort_control
**lssc
;
86 if (!data
) return false;
88 if (!asn1_load(data
, in
)) {
92 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
98 for (num
= 0; asn1_peek_tag(data
, ASN1_SEQUENCE(0)); num
++) {
99 lssc
= talloc_realloc(mem_ctx
, lssc
, struct ldb_server_sort_control
*, num
+ 2);
103 lssc
[num
] = talloc_zero(lssc
, struct ldb_server_sort_control
);
108 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
112 if (!asn1_read_OctetString(data
, mem_ctx
, &attr
)) {
116 lssc
[num
]->attributeName
= talloc_strndup(lssc
[num
], (const char *)attr
.data
, attr
.length
);
117 if (!lssc
[num
]->attributeName
) {
121 if (asn1_peek_tag(data
, ASN1_CONTEXT_SIMPLE(0))) {
122 if (!asn1_read_ContextSimple(data
, mem_ctx
, 0, &rule
)) {
125 lssc
[num
]->orderingRule
= talloc_strndup(lssc
[num
], (const char *)rule
.data
, rule
.length
);
126 if (!lssc
[num
]->orderingRule
) {
131 if (asn1_peek_tag(data
, ASN1_CONTEXT_SIMPLE(1))) {
133 if (!asn1_read_BOOLEAN_context(data
, &reverse
, 1)) {
136 lssc
[num
]->reverse
= reverse
;
139 if (!asn1_end_tag(data
)) {
148 if (!asn1_end_tag(data
)) {
157 static bool decode_extended_dn_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
160 struct asn1_data
*data
;
161 struct ldb_extended_dn_control
*ledc
;
163 /* The content of this control is optional */
164 if (in
.length
== 0) {
169 data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
170 if (!data
) return false;
172 if (!asn1_load(data
, in
)) {
176 ledc
= talloc(mem_ctx
, struct ldb_extended_dn_control
);
181 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
185 if (!asn1_read_Integer(data
, &(ledc
->type
))) {
189 if (!asn1_end_tag(data
)) {
198 static bool decode_sd_flags_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
201 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
202 struct ldb_sd_flags_control
*lsdfc
;
204 if (!data
) return false;
206 if (!asn1_load(data
, in
)) {
210 lsdfc
= talloc(mem_ctx
, struct ldb_sd_flags_control
);
215 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
219 if (!asn1_read_Integer(data
, (int *) &(lsdfc
->secinfo_flags
))) {
223 if (!asn1_end_tag(data
)) {
232 static bool decode_search_options_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
235 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
236 struct ldb_search_options_control
*lsoc
;
238 if (!data
) return false;
240 if (!asn1_load(data
, in
)) {
244 lsoc
= talloc(mem_ctx
, struct ldb_search_options_control
);
249 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
253 if (!asn1_read_Integer(data
, (int *) &(lsoc
->search_options
))) {
257 if (!asn1_end_tag(data
)) {
266 static bool decode_paged_results_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
270 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
271 struct ldb_paged_control
*lprc
;
273 if (!data
) return false;
275 if (!asn1_load(data
, in
)) {
279 lprc
= talloc(mem_ctx
, struct ldb_paged_control
);
284 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
288 if (!asn1_read_Integer(data
, &(lprc
->size
))) {
292 if (!asn1_read_OctetString(data
, mem_ctx
, &cookie
)) {
295 lprc
->cookie_len
= cookie
.length
;
296 if (lprc
->cookie_len
) {
297 lprc
->cookie
= talloc_memdup(lprc
, cookie
.data
, cookie
.length
);
299 if (!(lprc
->cookie
)) {
306 if (!asn1_end_tag(data
)) {
315 static bool decode_dirsync_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
319 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
320 struct ldb_dirsync_control
*ldc
;
322 if (!data
) return false;
324 if (!asn1_load(data
, in
)) {
328 ldc
= talloc(mem_ctx
, struct ldb_dirsync_control
);
333 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
337 if (!asn1_read_Integer(data
, &(ldc
->flags
))) {
341 if (!asn1_read_Integer(data
, &(ldc
->max_attributes
))) {
345 if (!asn1_read_OctetString(data
, mem_ctx
, &cookie
)) {
348 ldc
->cookie_len
= cookie
.length
;
349 if (ldc
->cookie_len
) {
350 ldc
->cookie
= talloc_memdup(ldc
, cookie
.data
, cookie
.length
);
352 if (!(ldc
->cookie
)) {
359 if (!asn1_end_tag(data
)) {
368 /* seem that this controls has 2 forms one in case it is used with
369 * a Search Request and another when used in a Search Response
371 static bool decode_asq_control(void *mem_ctx
, DATA_BLOB in
, void *_out
)
374 DATA_BLOB source_attribute
;
375 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
376 struct ldb_asq_control
*lac
;
378 if (!data
) return false;
380 if (!asn1_load(data
, in
)) {
384 lac
= talloc(mem_ctx
, struct ldb_asq_control
);
389 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
393 if (asn1_peek_tag(data
, ASN1_OCTET_STRING
)) {
395 if (!asn1_read_OctetString(data
, mem_ctx
, &source_attribute
)) {
398 lac
->src_attr_len
= source_attribute
.length
;
399 if (lac
->src_attr_len
) {
400 lac
->source_attribute
= talloc_strndup(lac
, (const char *)source_attribute
.data
, source_attribute
.length
);
402 if (!(lac
->source_attribute
)) {
406 lac
->source_attribute
= NULL
;
411 } else if (asn1_peek_tag(data
, ASN1_ENUMERATED
)) {
413 if (!asn1_read_enumerated(data
, &(lac
->result
))) {
423 if (!asn1_end_tag(data
)) {
432 static bool decode_verify_name_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
436 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
437 struct ldb_verify_name_control
*lvnc
;
440 if (!data
) return false;
442 if (!asn1_load(data
, in
)) {
446 lvnc
= talloc(mem_ctx
, struct ldb_verify_name_control
);
451 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
455 if (!asn1_read_Integer(data
, &(lvnc
->flags
))) {
459 if (!asn1_read_OctetString(data
, mem_ctx
, &name
)) {
464 len
= utf16_null_terminated_len_n(name
.data
, name
.length
);
465 convert_string_talloc(mem_ctx
, CH_UTF16
, CH_UNIX
,
467 &lvnc
->gc
, &lvnc
->gc_len
);
477 if (!asn1_end_tag(data
)) {
485 static bool encode_verify_name_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
487 struct ldb_verify_name_control
*lvnc
= talloc_get_type(in
, struct ldb_verify_name_control
);
488 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
491 if (!data
) return false;
493 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
497 if (!asn1_write_Integer(data
, lvnc
->flags
)) {
504 ok
= convert_string_talloc(mem_ctx
, CH_UNIX
, CH_UTF16
,
505 lvnc
->gc
, lvnc
->gc_len
,
506 &gc_utf16
.data
, &gc_utf16
.length
);
510 if (!asn1_write_OctetString(data
, gc_utf16
.data
, gc_utf16
.length
)) {
514 if (!asn1_write_OctetString(data
, NULL
, 0)) {
519 if (!asn1_pop_tag(data
)) {
523 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
532 static bool decode_vlv_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
535 DATA_BLOB assertion_value
, context_id
;
536 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
537 struct ldb_vlv_req_control
*lvrc
;
539 if (!data
) return false;
541 if (!asn1_load(data
, in
)) {
545 lvrc
= talloc(mem_ctx
, struct ldb_vlv_req_control
);
550 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
554 if (!asn1_read_Integer(data
, &(lvrc
->beforeCount
))) {
558 if (!asn1_read_Integer(data
, &(lvrc
->afterCount
))) {
562 if (asn1_peek_tag(data
, ASN1_CONTEXT(0))) {
566 if (!asn1_start_tag(data
, ASN1_CONTEXT(0))) {
570 if (!asn1_read_Integer(data
, &(lvrc
->match
.byOffset
.offset
))) {
574 if (!asn1_read_Integer(data
, &(lvrc
->match
.byOffset
.contentCount
))) {
578 if (!asn1_end_tag(data
)) { /*CONTEXT*/
586 if (!asn1_read_ContextSimple(data
, mem_ctx
, 1, &assertion_value
)){
590 lvrc
->match
.gtOrEq
.value_len
= assertion_value
.length
;
591 if (lvrc
->match
.gtOrEq
.value_len
) {
592 lvrc
->match
.gtOrEq
.value
= talloc_memdup(lvrc
, assertion_value
.data
, assertion_value
.length
);
594 if (!(lvrc
->match
.gtOrEq
.value
)) {
598 lvrc
->match
.gtOrEq
.value
= NULL
;
602 if (asn1_peek_tag(data
, ASN1_OCTET_STRING
)) {
603 if (!asn1_read_OctetString(data
, mem_ctx
, &context_id
)) {
606 lvrc
->ctxid_len
= context_id
.length
;
607 if (lvrc
->ctxid_len
) {
608 lvrc
->contextId
= talloc_memdup(lvrc
, context_id
.data
, context_id
.length
);
610 if (!(lvrc
->contextId
)) {
614 lvrc
->contextId
= NULL
;
617 lvrc
->contextId
= NULL
;
621 if (!asn1_end_tag(data
)) {
630 static bool decode_vlv_response(void *mem_ctx
, DATA_BLOB in
, void *_out
)
633 DATA_BLOB context_id
;
634 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
635 struct ldb_vlv_resp_control
*lvrc
;
637 if (!data
) return false;
639 if (!asn1_load(data
, in
)) {
643 lvrc
= talloc(mem_ctx
, struct ldb_vlv_resp_control
);
648 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
652 if (!asn1_read_Integer(data
, &(lvrc
->targetPosition
))) {
656 if (!asn1_read_Integer(data
, &(lvrc
->contentCount
))) {
660 if (!asn1_read_enumerated(data
, &(lvrc
->vlv_result
))) {
664 if (asn1_peek_tag(data
, ASN1_OCTET_STRING
)) {
665 if (!asn1_read_OctetString(data
, mem_ctx
, &context_id
)) {
668 lvrc
->contextId
= talloc_memdup(lvrc
, (const char *)context_id
.data
, context_id
.length
);
669 if (!lvrc
->contextId
) {
672 lvrc
->ctxid_len
= context_id
.length
;
674 lvrc
->contextId
= NULL
;
678 if (!asn1_end_tag(data
)) {
687 static bool encode_server_sort_response(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
689 struct ldb_sort_resp_control
*lsrc
= talloc_get_type(in
, struct ldb_sort_resp_control
);
690 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
692 if (!data
) return false;
694 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
698 if (!asn1_write_enumerated(data
, lsrc
->result
)) {
702 if (lsrc
->attr_desc
) {
703 if (!asn1_write_OctetString(data
, lsrc
->attr_desc
, strlen(lsrc
->attr_desc
))) {
708 if (!asn1_pop_tag(data
)) {
712 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
721 static bool encode_server_sort_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
723 struct ldb_server_sort_control
**lssc
= talloc_get_type(in
, struct ldb_server_sort_control
*);
724 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
727 if (!data
) return false;
729 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
735 SortKeyList ::= SEQUENCE OF SEQUENCE {
736 attributeType AttributeDescription,
737 orderingRule [0] MatchingRuleId OPTIONAL,
738 reverseOrder [1] BOOLEAN DEFAULT FALSE }
740 for (num
= 0; lssc
[num
]; num
++) {
741 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
745 if (!asn1_write_OctetString(data
, lssc
[num
]->attributeName
, strlen(lssc
[num
]->attributeName
))) {
749 if (lssc
[num
]->orderingRule
) {
750 DATA_BLOB order
= data_blob_string_const(lssc
[num
]->orderingRule
);
751 if (!asn1_write_ContextSimple(data
, 0, &order
)) {
756 if (lssc
[num
]->reverse
) {
757 if (!asn1_write_BOOLEAN_context(data
, lssc
[num
]->reverse
, 1)) {
762 if (!asn1_pop_tag(data
)) {
767 if (!asn1_pop_tag(data
)) {
771 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
780 static bool encode_extended_dn_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
782 struct ldb_extended_dn_control
*ledc
= talloc_get_type(in
, struct ldb_extended_dn_control
);
783 struct asn1_data
*data
;
786 *out
= data_blob(NULL
, 0);
790 data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
792 if (!data
) return false;
794 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
798 if (!asn1_write_Integer(data
, ledc
->type
)) {
802 if (!asn1_pop_tag(data
)) {
806 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
815 static bool encode_sd_flags_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
817 struct ldb_sd_flags_control
*lsdfc
= talloc_get_type(in
, struct ldb_sd_flags_control
);
818 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
820 if (!data
) return false;
822 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
826 if (!asn1_write_Integer(data
, lsdfc
->secinfo_flags
)) {
830 if (!asn1_pop_tag(data
)) {
834 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
843 static bool encode_search_options_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
845 struct ldb_search_options_control
*lsoc
= talloc_get_type(in
, struct ldb_search_options_control
);
846 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
848 if (!data
) return false;
850 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
854 if (!asn1_write_Integer(data
, lsoc
->search_options
)) {
858 if (!asn1_pop_tag(data
)) {
862 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
871 static bool encode_paged_results_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
873 struct ldb_paged_control
*lprc
= talloc_get_type(in
, struct ldb_paged_control
);
874 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
876 if (!data
) return false;
878 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
882 if (!asn1_write_Integer(data
, lprc
->size
)) {
886 if (!asn1_write_OctetString(data
, lprc
->cookie
, lprc
->cookie_len
)) {
890 if (!asn1_pop_tag(data
)) {
894 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
903 /* seem that this controls has 2 forms one in case it is used with
904 * a Search Request and another when used in a Search Response
906 static bool encode_asq_control(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
908 struct ldb_asq_control
*lac
= talloc_get_type(in
, struct ldb_asq_control
);
909 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
911 if (!data
) return false;
913 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
919 if (!asn1_write_OctetString(data
, lac
->source_attribute
, lac
->src_attr_len
)) {
923 if (!asn1_write_enumerated(data
, lac
->result
)) {
928 if (!asn1_pop_tag(data
)) {
932 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
941 static bool encode_dirsync_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
943 struct ldb_dirsync_control
*ldc
= talloc_get_type(in
, struct ldb_dirsync_control
);
944 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
946 if (!data
) return false;
948 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
952 if (!asn1_write_Integer(data
, ldc
->flags
)) {
956 if (!asn1_write_Integer(data
, ldc
->max_attributes
)) {
960 if (!asn1_write_OctetString(data
, ldc
->cookie
, ldc
->cookie_len
)) {
964 if (!asn1_pop_tag(data
)) {
968 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
977 static bool encode_vlv_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
979 struct ldb_vlv_req_control
*lvrc
= talloc_get_type(in
, struct ldb_vlv_req_control
);
980 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
982 if (!data
) return false;
984 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
988 if (!asn1_write_Integer(data
, lvrc
->beforeCount
)) {
992 if (!asn1_write_Integer(data
, lvrc
->afterCount
)) {
996 if (lvrc
->type
== 0) {
997 if (!asn1_push_tag(data
, ASN1_CONTEXT(0))) {
1001 if (!asn1_write_Integer(data
, lvrc
->match
.byOffset
.offset
)) {
1005 if (!asn1_write_Integer(data
, lvrc
->match
.byOffset
.contentCount
)) {
1009 if (!asn1_pop_tag(data
)) { /*CONTEXT*/
1013 if (!asn1_push_tag(data
, ASN1_CONTEXT_SIMPLE(1))) {
1017 if (!asn1_write(data
, lvrc
->match
.gtOrEq
.value
, lvrc
->match
.gtOrEq
.value_len
)) {
1021 if (!asn1_pop_tag(data
)) { /*CONTEXT*/
1026 if (lvrc
->ctxid_len
) {
1027 if (!asn1_write_OctetString(data
, lvrc
->contextId
, lvrc
->ctxid_len
)) {
1032 if (!asn1_pop_tag(data
)) {
1036 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
1045 static bool encode_vlv_response(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
1047 struct ldb_vlv_resp_control
*lvrc
= talloc_get_type(in
, struct ldb_vlv_resp_control
);
1048 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
1050 if (!data
) return false;
1052 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
1056 if (!asn1_write_Integer(data
, lvrc
->targetPosition
)) {
1060 if (!asn1_write_Integer(data
, lvrc
->contentCount
)) {
1064 if (!asn1_write_enumerated(data
, lvrc
->vlv_result
)) {
1068 if (lvrc
->ctxid_len
) {
1069 if (!asn1_write_OctetString(data
, lvrc
->contextId
, lvrc
->ctxid_len
)) {
1074 if (!asn1_pop_tag(data
)) {
1078 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
1087 static bool encode_openldap_dereference(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
1089 struct dsdb_openldap_dereference_control
*control
= talloc_get_type(in
, struct dsdb_openldap_dereference_control
);
1091 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
1093 if (!data
) return false;
1095 if (!control
) return false;
1097 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
1101 for (i
=0; control
->dereference
&& control
->dereference
[i
]; i
++) {
1102 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
1105 if (!asn1_write_OctetString(data
, control
->dereference
[i
]->source_attribute
, strlen(control
->dereference
[i
]->source_attribute
))) {
1108 if (!asn1_push_tag(data
, ASN1_SEQUENCE(0))) {
1111 for (j
=0; control
->dereference
&& control
->dereference
[i
]->dereference_attribute
[j
]; j
++) {
1112 if (!asn1_write_OctetString(data
, control
->dereference
[i
]->dereference_attribute
[j
],
1113 strlen(control
->dereference
[i
]->dereference_attribute
[j
]))) {
1118 if (!asn1_pop_tag(data
)) {
1121 if (!asn1_pop_tag(data
)) {
1125 if (!asn1_pop_tag(data
)) {
1129 if (!asn1_extract_blob(data
, mem_ctx
, out
)) {
1137 static bool decode_openldap_dereference(void *mem_ctx
, DATA_BLOB in
, void *_out
)
1140 struct asn1_data
*data
= asn1_init(mem_ctx
, ASN1_MAX_TREE_DEPTH
);
1141 struct dsdb_openldap_dereference_result_control
*control
;
1142 struct dsdb_openldap_dereference_result
**r
= NULL
;
1144 if (!data
) return false;
1146 control
= talloc(mem_ctx
, struct dsdb_openldap_dereference_result_control
);
1147 if (!control
) return false;
1149 if (!asn1_load(data
, in
)) {
1153 control
= talloc(mem_ctx
, struct dsdb_openldap_dereference_result_control
);
1158 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
1162 while (asn1_tag_remaining(data
) > 0) {
1163 r
= talloc_realloc(control
, r
, struct dsdb_openldap_dereference_result
*, i
+ 2);
1167 r
[i
] = talloc_zero(r
, struct dsdb_openldap_dereference_result
);
1172 if (!asn1_start_tag(data
, ASN1_SEQUENCE(0))) {
1176 if (!asn1_read_OctetString_talloc(r
[i
], data
, &r
[i
]->source_attribute
)) {
1179 if (!asn1_read_OctetString_talloc(r
[i
], data
, &r
[i
]->dereferenced_dn
)) {
1182 if (asn1_peek_tag(data
, ASN1_CONTEXT(0))) {
1183 if (!asn1_start_tag(data
, ASN1_CONTEXT(0))) {
1186 if (!ldap_decode_attribs_bare(r
, data
, &r
[i
]->attributes
,
1187 &r
[i
]->num_attributes
)) {
1190 if (!asn1_end_tag(data
)) {
1194 if (!asn1_end_tag(data
)) {
1201 if (!asn1_end_tag(data
)) {
1205 control
->attributes
= r
;
1211 static bool encode_flag_request(void *mem_ctx
, void *in
, DATA_BLOB
*out
)
1217 *out
= data_blob(NULL
, 0);
1221 static bool decode_flag_request(void *mem_ctx
, DATA_BLOB in
, void *_out
)
1223 if (in
.length
!= 0) {
1230 static const struct ldap_control_handler ldap_known_controls
[] = {
1231 { LDB_CONTROL_PAGED_RESULTS_OID
, decode_paged_results_request
, encode_paged_results_request
},
1232 { LDB_CONTROL_SD_FLAGS_OID
, decode_sd_flags_request
, encode_sd_flags_request
},
1233 { LDB_CONTROL_DOMAIN_SCOPE_OID
, decode_flag_request
, encode_flag_request
},
1234 { LDB_CONTROL_SEARCH_OPTIONS_OID
, decode_search_options_request
, encode_search_options_request
},
1235 { LDB_CONTROL_NOTIFICATION_OID
, decode_flag_request
, encode_flag_request
},
1236 { LDB_CONTROL_TREE_DELETE_OID
, decode_flag_request
, encode_flag_request
},
1237 { LDB_CONTROL_SHOW_DELETED_OID
, decode_flag_request
, encode_flag_request
},
1238 { LDB_CONTROL_SHOW_RECYCLED_OID
, decode_flag_request
, encode_flag_request
},
1239 { LDB_CONTROL_SHOW_DEACTIVATED_LINK_OID
, decode_flag_request
, encode_flag_request
},
1240 { LDB_CONTROL_EXTENDED_DN_OID
, decode_extended_dn_request
, encode_extended_dn_request
},
1241 { LDB_CONTROL_SERVER_SORT_OID
, decode_server_sort_request
, encode_server_sort_request
},
1242 { LDB_CONTROL_SORT_RESP_OID
, decode_server_sort_response
, encode_server_sort_response
},
1243 { LDB_CONTROL_ASQ_OID
, decode_asq_control
, encode_asq_control
},
1244 { LDB_CONTROL_DIRSYNC_OID
, decode_dirsync_request
, encode_dirsync_request
},
1245 { LDB_CONTROL_DIRSYNC_EX_OID
, decode_dirsync_request
, encode_dirsync_request
},
1246 { LDB_CONTROL_VLV_REQ_OID
, decode_vlv_request
, encode_vlv_request
},
1247 { LDB_CONTROL_VLV_RESP_OID
, decode_vlv_response
, encode_vlv_response
},
1248 { LDB_CONTROL_PERMISSIVE_MODIFY_OID
, decode_flag_request
, encode_flag_request
},
1249 { LDB_CONTROL_SERVER_LAZY_COMMIT
, decode_flag_request
, encode_flag_request
},
1250 { LDB_CONTROL_RODC_DCPROMO_OID
, decode_flag_request
, encode_flag_request
},
1251 { LDB_CONTROL_RELAX_OID
, decode_flag_request
, encode_flag_request
},
1252 { DSDB_OPENLDAP_DEREFERENCE_CONTROL
, decode_openldap_dereference
, encode_openldap_dereference
},
1253 { LDB_CONTROL_VERIFY_NAME_OID
, decode_verify_name_request
, encode_verify_name_request
},
1255 /* the following are internal only, with a network
1257 { DSDB_CONTROL_BYPASS_PASSWORD_HASH_OID
, decode_flag_request
, encode_flag_request
},
1259 /* all the ones below are internal only, and have no network
1261 { DSDB_CONTROL_CURRENT_PARTITION_OID
, NULL
, NULL
},
1262 { DSDB_CONTROL_REPLICATED_UPDATE_OID
, NULL
, NULL
},
1263 { DSDB_CONTROL_DN_STORAGE_FORMAT_OID
, NULL
, NULL
},
1264 { LDB_CONTROL_RECALCULATE_SD_OID
, NULL
, NULL
},
1265 { LDB_CONTROL_REVEAL_INTERNALS
, NULL
, NULL
},
1266 { LDB_CONTROL_AS_SYSTEM_OID
, NULL
, NULL
},
1267 { DSDB_CONTROL_PASSWORD_CHANGE_STATUS_OID
, NULL
, NULL
},
1268 { DSDB_CONTROL_PASSWORD_HASH_VALUES_OID
, NULL
, NULL
},
1269 { DSDB_CONTROL_PASSWORD_CHANGE_OLD_PW_CHECKED_OID
, NULL
, NULL
},
1270 { DSDB_CONTROL_PASSWORD_ACL_VALIDATION_OID
, NULL
, NULL
},
1271 { DSDB_CONTROL_APPLY_LINKS
, NULL
, NULL
},
1272 { LDB_CONTROL_BYPASS_OPERATIONAL_OID
, NULL
, NULL
},
1273 { DSDB_CONTROL_CHANGEREPLMETADATA_OID
, NULL
, NULL
},
1274 { LDB_CONTROL_PROVISION_OID
, NULL
, NULL
},
1275 { DSDB_EXTENDED_REPLICATED_OBJECTS_OID
, NULL
, NULL
},
1276 { DSDB_EXTENDED_SCHEMA_UPDATE_NOW_OID
, NULL
, NULL
},
1277 { DSDB_EXTENDED_ALLOCATE_RID_POOL
, NULL
, NULL
},
1278 { DSDB_CONTROL_NO_GLOBAL_CATALOG
, NULL
, NULL
},
1279 { DSDB_CONTROL_PARTIAL_REPLICA
, NULL
, NULL
},
1280 { DSDB_CONTROL_DBCHECK
, NULL
, NULL
},
1281 { DSDB_CONTROL_DBCHECK_MODIFY_RO_REPLICA
, NULL
, NULL
},
1282 { DSDB_CONTROL_DBCHECK_FIX_DUPLICATE_LINKS
, NULL
, NULL
},
1283 { DSDB_CONTROL_DBCHECK_FIX_LINK_DN_NAME
, NULL
, NULL
},
1284 { DSDB_CONTROL_DBCHECK_FIX_LINK_DN_SID
, NULL
, NULL
},
1285 { DSDB_CONTROL_PASSWORD_BYPASS_LAST_SET_OID
, NULL
, NULL
},
1286 { DSDB_CONTROL_SEC_DESC_PROPAGATION_OID
, NULL
, NULL
},
1287 { DSDB_CONTROL_PERMIT_INTERDOMAIN_TRUST_UAC_OID
, NULL
, NULL
},
1288 { DSDB_CONTROL_RESTORE_TOMBSTONE_OID
, NULL
, NULL
},
1289 { DSDB_CONTROL_CHANGEREPLMETADATA_RESORT_OID
, NULL
, NULL
},
1290 { DSDB_CONTROL_PASSWORD_DEFAULT_LAST_SET_OID
, NULL
, NULL
},
1291 { DSDB_CONTROL_PASSWORD_USER_ACCOUNT_CONTROL_OID
, NULL
, NULL
},
1292 { DSDB_CONTROL_SKIP_DUPLICATES_CHECK_OID
, NULL
, NULL
},
1293 { DSDB_CONTROL_REPLMD_VANISH_LINKS
, NULL
, NULL
},
1294 { LDB_CONTROL_RECALCULATE_RDN_OID
, NULL
, NULL
},
1295 { DSDB_CONTROL_FORCE_RODC_LOCAL_CHANGE
, NULL
, NULL
},
1296 { DSDB_CONTROL_FORCE_ALLOW_VALIDATED_DNS_HOSTNAME_SPN_WRITE_OID
, NULL
, NULL
},
1297 { DSDB_CONTROL_ACL_READ_OID
, NULL
, NULL
},
1298 { DSDB_CONTROL_GMSA_UPDATE_OID
, NULL
, NULL
},
1299 { DSDB_CONTROL_PASSWORD_KDC_RESET_SMARTCARD_ACCOUNT_PASSWORD
, NULL
, NULL
},
1300 { DSDB_EXTENDED_SCHEMA_UPGRADE_IN_PROGRESS_OID
, NULL
, NULL
},
1301 { DSDB_CONTROL_TRANSACTION_IDENTIFIER_OID
, NULL
, NULL
},
1302 { DSDB_CONTROL_CALCULATED_DEFAULT_SD_OID
, NULL
, NULL
},
1303 { NULL
, NULL
, NULL
}
1306 const struct ldap_control_handler
*samba_ldap_control_handlers(void)
1308 return ldap_known_controls
;