Commit 6fb5bcd2 authored by Stefan Fritsch's avatar Stefan Fritsch
Browse files

Revert r1129808:

    Incorporate the ap_ldap incomplete API, as there is no interest or effort
    at APR to make this a complete abstraction, and it was voted 'off the island'
    with APR 2.0.  This will allow httpd 2.3 to build against either apr-2.0
    or apr+util 1.x.

This also reverts part of r1142938, which needs to be re-done.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/revert-ap-ldap@1150172 13f79535-47bb-0310-9956-ffa450edef68
parent f96669de
Loading
Loading
Loading
Loading
+0 −5
Original line number Diff line number Diff line
@@ -76,11 +76,6 @@
    OpenSSL or the operating system's platform-specific SSL facilities.
    Apache httpd currently does not use that apr-util interface.

    modules/ldap/ provides an abstract interface for SSL encrypted LDAP
    (ldaps and STARTTLS style) connections, implemented with OpenLDAP, 
    Netscape LDAP SDK, Mozilla LDAP SDK, or other platform specific ldap
    interfaces.

    Some object code distributions of Apache httpd, indicated with the
    word "crypto" in the package name, may include object code for the
    OpenSSL encryption library as distributed in open source form from

build/find_ldap.m4

deleted100644 → 0
+0 −263
Original line number Diff line number Diff line
dnl -------------------------------------------------------- -*- autoconf -*-
dnl Licensed to the Apache Software Foundation (ASF) under one or more
dnl contributor license agreements.  See the NOTICE file distributed with
dnl this work for additional information regarding copyright ownership.
dnl The ASF licenses this file to You under the Apache License, Version 2.0
dnl (the "License"); you may not use this file except in compliance with
dnl the License.  You may obtain a copy of the License at
dnl
dnl     http://www.apache.org/licenses/LICENSE-2.0
dnl
dnl Unless required by applicable law or agreed to in writing, software
dnl distributed under the License is distributed on an "AS IS" BASIS,
dnl WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
dnl See the License for the specific language governing permissions and
dnl limitations under the License.


dnl 
dnl Find a particular LDAP library
dnl
AC_DEFUN([AP_FIND_LDAPLIB], [
  if test ${ap_has_ldap} != "1"; then
    ldaplib=$1
    extralib=$2
    # Clear the cache entry for subsequent AP_FIND_LDAPLIB invocations.
    changequote(,)
    ldaplib_cache_id="`echo $ldaplib | sed -e 's/[^a-zA-Z0-9_]/_/g'`"
    changequote([,])
    unset ac_cv_lib_${ldaplib_cache_id}_ldap_init
    unset ac_cv_lib_${ldaplib_cache_id}___ldap_init
    AC_CHECK_LIB(${ldaplib}, ldap_init, 
      [
        LDADD_ldap="-l${ldaplib} ${extralib}"
        AC_CHECK_LIB(${ldaplib}, ldapssl_client_init, ap_has_ldapssl_client_init="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldapssl_client_deinit, ap_has_ldapssl_client_deinit="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldapssl_add_trusted_cert, ap_has_ldapssl_add_trusted_cert="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldap_start_tls_s, ap_has_ldap_start_tls_s="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldap_sslinit, ap_has_ldap_sslinit="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldapssl_init, ap_has_ldapssl_init="1", , ${extralib})
        AC_CHECK_LIB(${ldaplib}, ldapssl_install_routines, ap_has_ldapssl_install_routines="1", , ${extralib})
        ap_has_ldap="1";
      ], , ${extralib})
  fi
])


dnl
dnl AP_FIND_LDAP: figure out where LDAP is located
dnl
AC_DEFUN([AP_FIND_LDAP],  [

echo $ac_n "${nl}checking for ldap support..."

ap_has_ldap="0";
ap_has_ldapssl_client_init="0"
ap_has_ldapssl_client_deinit="0"
ap_has_ldapssl_add_trusted_cert="0"
ap_has_ldap_start_tls_s="0"
ap_has_ldapssl_init="0"
ap_has_ldap_sslinit="0"
ap_has_ldapssl_install_routines="0"
ap_has_ldap_openldap="0"
ap_has_ldap_solaris="0"
ap_has_ldap_novell="0"
ap_has_ldap_microsoft="0"
ap_has_ldap_netscape="0"
ap_has_ldap_mozilla="0"
ap_has_ldap_tivoli="0"
ap_has_ldap_zos="0"
ap_has_ldap_other="0"
LDADD_ldap=""

AC_ARG_WITH(lber,[  --with-lber=library     lber library to use],
  [
    if test "$withval" = "yes"; then
      ap_liblber_name="lber"
    else
      ap_liblber_name="$withval"
    fi
  ],
  [
    ap_liblber_name="lber"
  ])

AC_ARG_WITH(ldap-include,[  --with-ldap-include=path  path to ldap include files with trailing slash])
AC_ARG_WITH(ldap-lib,[  --with-ldap-lib=path    path to ldap lib file])
AC_ARG_WITH(ldap,[  --with-ldap=library     ldap library to use],
  [
    if test "$with_ldap" != "no"; then
      save_cppflags="$CPPFLAGS"
      save_ldflags="$LDFLAGS"
      save_libs="$LIBS"
      if test -n "$with_ldap_include"; then
        CPPFLAGS="$CPPFLAGS -I$with_ldap_include"
        APR_ADDTO(INCLUDES, [-I$with_ldap_include])
      fi
      if test -n "$with_ldap_lib"; then
        APR_ADDTO(LDFLAGS, [-L$with_ldap_lib])
      fi

      LIBLDAP="$withval"
      if test "$LIBLDAP" = "yes"; then
        dnl The iPlanet C SDK 5.0 is as yet untested... 
        AP_FIND_LDAPLIB("ldap50", "-lnspr4 -lplc4 -lplds4 -liutil50 -llber50 -lldif50 -lnss3 -lprldap50 -lssl3 -lssldap50")
        AP_FIND_LDAPLIB("ldapssl41", "-lnspr3 -lplc3 -lplds3")
        AP_FIND_LDAPLIB("ldapssl40")
        AP_FIND_LDAPLIB("ldapssl30")
        AP_FIND_LDAPLIB("ldapssl20")
        AP_FIND_LDAPLIB("ldapsdk", "-lldapx -lldapssl -lldapgss -lgssapi_krb5")
        AP_FIND_LDAPLIB("ldapsdk", "-lldapx -lldapssl -lldapgss -lgss -lresolv -lsocket")
        AP_FIND_LDAPLIB("ldap", "-llber")
        AP_FIND_LDAPLIB("ldap", "-llber -lresolv")
        AP_FIND_LDAPLIB("ldap", "-llber -lresolv -lsocket -lnsl")
        AP_FIND_LDAPLIB("ldap", "-ldl -lpthread")
      else
        AP_FIND_LDAPLIB($LIBLDAP)
        AP_FIND_LDAPLIB($LIBLDAP, "-lresolv")
        AP_FIND_LDAPLIB($LIBLDAP, "-lresolv -lsocket -lnsl")
        AP_FIND_LDAPLIB($LIBLDAP, "-ldl -lpthread")
      fi

      test ${ap_has_ldap} != "1" && AC_MSG_ERROR(could not find an LDAP library)
      AC_CHECK_LIB($ap_liblber_name, ber_init,
        [LDADD_ldap="${LDADD_ldap} -l${ap_liblber_name}"])

      AC_CHECK_HEADERS(lber.h, lber_h=["#include <lber.h>"])

      # Solaris has a problem in <ldap.h> which prevents it from
      # being included by itself.  Check for <ldap.h> manually,
      # including lber.h first.
      AC_CACHE_CHECK([for ldap.h], [ap_cv_hdr_ldap_h],
      [AC_TRY_CPP(
      [#ifdef HAVE_LBER_H
      #include <lber.h>
      #endif
      #include <ldap.h>
      ], [ap_cv_hdr_ldap_h=yes], [ap_cv_hdr_ldap_h=no])])
      if test "$ap_cv_hdr_ldap_h" = "yes"; then
        ldap_h=["#include <ldap.h>"]
        AC_DEFINE([HAVE_LDAP_H], 1, [Defined if ldap.h is present])
      fi

      AC_CHECK_HEADERS(ldap_ssl.h, ldap_ssl_h=["#include <ldap_ssl.h>"])

      if test "$ap_cv_hdr_ldap_h" = "yes"; then
        AC_CACHE_CHECK([for LDAP toolkit],
                       [ap_cv_ldap_toolkit], [
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([OpenLDAP], [$lber_h
                         $ldap_h 
                         LDAP_VENDOR_NAME], [ap_has_ldap_openldap="1"
                                             ap_cv_ldap_toolkit="OpenLDAP"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([Sun Microsystems Inc.], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_solaris="1"
                                             ap_cv_ldap_toolkit="Solaris"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([Novell], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_novell="1"
                                             ap_cv_ldap_toolkit="Novell"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([Microsoft Corporation.], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_microsoft="1"
                                             ap_cv_ldap_toolkit="Microsoft"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([Netscape Communications Corp.], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_netscape="1"
                                             ap_cv_ldap_toolkit="Netscape"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([mozilla.org], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_mozilla="1"
                                             ap_cv_ldap_toolkit="Mozilla"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            AC_EGREP_CPP([International Business Machines], [$lber_h
                         $ldap_h
                         LDAP_VENDOR_NAME], [ap_has_ldap_tivoli="1"
                                             ap_cv_ldap_toolkit="Tivoli"])
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            case "$host" in
            *-ibm-os390)
              AC_EGREP_CPP([IBM], [$lber_h
                                   $ldap_h], [ap_has_ldap_zos="1"
                                              ap_cv_ldap_toolkit="z/OS"])
              ;;
            esac
          fi
          if test "x$ap_cv_ldap_toolkit" = "x"; then
            ap_has_ldap_other="1"
            ap_cv_ldap_toolkit="unknown"
          fi
        ])
      fi

      CPPFLAGS=$save_cppflags
      LDFLAGS=$save_ldflags
      LIBS=$save_libs
    fi
  ])

if test "$ap_has_ldap_openldap" = "1"; then
    save_cppflags="$CPPFLAGS"
    save_ldflags="$LDFLAGS"
    save_libs="$LIBS"

    CPPFLAGS="$CPPFLAGS $INCLUDES"
    AC_CACHE_CHECK([style of ldap_set_rebind_proc routine], ac_cv_ldap_set_rebind_proc_style,
    APR_TRY_COMPILE_NO_WARNING([
    #ifdef HAVE_LBER_H
    #include <lber.h>
    #endif
    #ifdef HAVE_LDAP_H
    #include <ldap.h>
    #endif
    ], [
    int tmp = ldap_set_rebind_proc((LDAP *)0, (LDAP_REBIND_PROC *)0, (void *)0);
    /* use tmp to suppress the warning */
    tmp=0;
    ], ac_cv_ldap_set_rebind_proc_style=three, ac_cv_ldap_set_rebind_proc_style=two))

    if test "$ac_cv_ldap_set_rebind_proc_style" = "three"; then
        AC_DEFINE(LDAP_SET_REBIND_PROC_THREE, 1, [Define if ldap_set_rebind_proc takes three arguments])
    fi

    CPPFLAGS="$save_cppflags"
    LDFLAGS="$save_ldflags"
    LIBS="$save_libs"
fi

AC_SUBST(ldap_h)
AC_SUBST(lber_h)
AC_SUBST(ldap_ssl_h)
AC_SUBST(ap_has_ldapssl_client_init)
AC_SUBST(ap_has_ldapssl_client_deinit)
AC_SUBST(ap_has_ldapssl_add_trusted_cert)
AC_SUBST(ap_has_ldap_start_tls_s)
AC_SUBST(ap_has_ldapssl_init)
AC_SUBST(ap_has_ldap_sslinit)
AC_SUBST(ap_has_ldapssl_install_routines)
AC_SUBST(ap_has_ldap)
AC_SUBST(ap_has_ldap_openldap)
AC_SUBST(ap_has_ldap_solaris)
AC_SUBST(ap_has_ldap_novell)
AC_SUBST(ap_has_ldap_microsoft)
AC_SUBST(ap_has_ldap_netscape)
AC_SUBST(ap_has_ldap_mozilla)
AC_SUBST(ap_has_ldap_tivoli)
AC_SUBST(ap_has_ldap_zos)
AC_SUBST(ap_has_ldap_other)
AC_SUBST(LDADD_ldap)
AC_CONFIG_FILES(include/ap_ldap.h)
])
+0 −1
Original line number Diff line number Diff line
@@ -16,7 +16,6 @@ dnl #
sinclude(build/apr_common.m4)
sinclude(build/find_apr.m4)
sinclude(build/find_apu.m4)
sinclude(build/find_ldap.m4)
sinclude(acinclude.m4)

dnl Later versions of autoconf (>= 2.62) by default cause the produced
+4 −5
Original line number Diff line number Diff line
@@ -51,13 +51,12 @@ PREDEFINED="APR_DECLARE(x)=x" \
	APR_HAS_USER \
	APR_HAS_LARGE_FILES \
	APR_HAS_XTHREAD_FILES \
	DOXYGEN \
	APU_DECLARE_DATA \
	__pre_nw__ \
	DOXYGEN= \
	APU_DECLARE_DATA= \
	__pre_nw__= \
	"APU_DECLARE(x)=x" \
	"CACHE_DECLARE(x)=x" \
	"PROXY_DECLARE(x)=x" \
	"MODLDAP_DECLARE(x)=x"
	"PROXY_DECLARE(x)=x"
	

OPTIMIZE_OUTPUT_FOR_C=YES

include/ap_ldap.h.in

deleted100644 → 0
+0 −193
Original line number Diff line number Diff line
/* Licensed to the Apache Software Foundation (ASF) under one or more
 * contributor license agreements.  See the NOTICE file distributed with
 * this work for additional information regarding copyright ownership.
 * The ASF licenses this file to You under the Apache License, Version 2.0
 * (the "License"); you may not use this file except in compliance with
 * the License.  You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

/*
 * ap_ldap.h is generated from ap_ldap.h.in by configure -- do not edit ap_ldap.h
 */
/**
 * @file ap_ldap.h
 * @brief  MODLDAP 
 */
#ifndef AP_LDAP_H
#define AP_LDAP_H

/**
 * @defgroup AP_Util_LDAP LDAP
 * @ingroup APR_Util
 * @{
 */

#if !defined(WIN32)
#define MODLDAP_DECLARE(type)            type
#define MODLDAP_DECLARE_NONSTD(type)     type
#define MODLDAP_DECLARE_DATA
#elif defined(MODLDAP_DECLARE_STATIC)
#define MODLDAP_DECLARE(type)            type __stdcall
#define MODLDAP_DECLARE_NONSTD(type)     type
#define MODLDAP_DECLARE_DATA
#elif defined(MODLDAP_DECLARE_EXPORT)
#define MODLDAP_DECLARE(type)            __declspec(dllexport) type __stdcall
#define MODLDAP_DECLARE_NONSTD(type)     __declspec(dllexport) type
#define MODLDAP_DECLARE_DATA             __declspec(dllexport)
#else
#define MODLDAP_DECLARE(type)            __declspec(dllimport) type __stdcall
#define MODLDAP_DECLARE_NONSTD(type)     __declspec(dllimport) type
#define MODLDAP_DECLARE_DATA             __declspec(dllimport)
#endif
/* this will be defined if LDAP support was compiled into apr-util */
#define AP_HAS_LDAP		  @ap_has_ldap@

/* identify the LDAP toolkit used */
#define AP_HAS_NETSCAPE_LDAPSDK  @ap_has_ldap_netscape@
#define AP_HAS_SOLARIS_LDAPSDK   @ap_has_ldap_solaris@
#define AP_HAS_NOVELL_LDAPSDK    @ap_has_ldap_novell@
#define AP_HAS_MOZILLA_LDAPSDK   @ap_has_ldap_mozilla@
#define AP_HAS_OPENLDAP_LDAPSDK  @ap_has_ldap_openldap@
#define AP_HAS_MICROSOFT_LDAPSDK @ap_has_ldap_microsoft@
#define AP_HAS_TIVOLI_LDAPSDK    @ap_has_ldap_tivoli@
#define AP_HAS_ZOS_LDAPSDK       @ap_has_ldap_zos@
#define AP_HAS_OTHER_LDAPSDK     @ap_has_ldap_other@


/*
 * Handle the case when LDAP is enabled
 */
#if AP_HAS_LDAP

/*
 * The following #defines are DEPRECATED and should not be used for
 * anything. They remain to maintain binary compatibility.
 * The original code defined the OPENLDAP SDK as present regardless
 * of what really was there, which was way bogus. In addition, the
 * ap_ldap_url_parse*() functions have been rewritten specifically for
 * APR, so the AP_HAS_LDAP_URL_PARSE macro is forced to zero.
 */
#if AP_HAS_TIVOLI_LDAPSDK
#define AP_HAS_LDAP_SSL 0
#else
#define AP_HAS_LDAP_SSL 1
#endif
#define AP_HAS_LDAP_URL_PARSE      0

#if AP_HAS_OPENLDAP_LDAPSDK && !defined(LDAP_DEPRECATED) 
/* Ensure that the "deprecated" interfaces are still exposed
 * with OpenLDAP >= 2.3; these were exposed by default in earlier
 * releases. */
#define LDAP_DEPRECATED 1
#endif

/*
 * Include the standard LDAP header files.
 */

@lber_h@
@ldap_h@
@ldap_ssl_h@


/*
 * Detected standard functions
 */
#define AP_HAS_LDAPSSL_CLIENT_INIT @ap_has_ldapssl_client_init@
#define AP_HAS_LDAPSSL_CLIENT_DEINIT @ap_has_ldapssl_client_deinit@
#define AP_HAS_LDAPSSL_ADD_TRUSTED_CERT @ap_has_ldapssl_add_trusted_cert@
#define AP_HAS_LDAP_START_TLS_S @ap_has_ldap_start_tls_s@
#define AP_HAS_LDAP_SSLINIT @ap_has_ldap_sslinit@
#define AP_HAS_LDAPSSL_INIT @ap_has_ldapssl_init@
#define AP_HAS_LDAPSSL_INSTALL_ROUTINES @ap_has_ldapssl_install_routines@

/*
 * Make sure the secure LDAP port is defined
 */
#ifndef LDAPS_PORT
#define LDAPS_PORT 636  /* ldaps:/// default LDAP over TLS port */
#endif

/*
 * For ldap function calls that input a size limit on the number of returned elements
 * Some SDKs do not have the define for LDAP_DEFAULT_LIMIT (-1) or LDAP_NO_LIMIT (0)
 * LDAP_DEFAULT_LIMIT is preferred as it allows inheritance from whatever the SDK
 * or process is configured for.
 */
#ifdef LDAP_DEFAULT_LIMIT
#define AP_LDAP_SIZELIMIT LDAP_DEFAULT_LIMIT
#else
#ifdef LDAP_NO_LIMIT
#define AP_LDAP_SIZELIMIT LDAP_NO_LIMIT
#endif
#endif

#ifndef AP_LDAP_SIZELIMIT
#define AP_LDAP_SIZELIMIT 0 /* equivalent to LDAP_NO_LIMIT, and what goes on the wire */
#endif

/*
 * z/OS is missing some defines
 */
#ifndef LDAP_VERSION_MAX
#define LDAP_VERSION_MAX  LDAP_VERSION
#endif
#if AP_HAS_ZOS_LDAPSDK
#define LDAP_VENDOR_NAME "IBM z/OS"
#endif

/* Note: Macros defining const casting has been removed in APR v1.0,
 * pending real support for LDAP v2.0 toolkits.
 *
 * In the mean time, please use an LDAP v3.0 toolkit.
 */
#if LDAP_VERSION_MAX <= 2
#error Support for LDAP v2.0 toolkits has been removed from apr-util. Please use an LDAP v3.0 toolkit.
#endif 

#ifdef __cplusplus
extern "C" {
#endif /* __cplusplus */

/**
 * This structure allows the C LDAP API error codes to be returned
 * along with plain text error messages that explain to us mere mortals
 * what really happened.
 */
typedef struct ap_ldap_err_t {
    const char *reason;
    const char *msg;
    int rc;
} ap_ldap_err_t;

#ifdef __cplusplus
}
#endif

/* The MS SDK returns LDAP_UNAVAILABLE when the backend has closed the connection
 * between LDAP calls. Protect with AP_HAS_MICROSOFT_LDAPSDK in case someone 
 * manually chooses another SDK on Windows 
 */
#if AP_HAS_MICROSOFT_LDAPSDK
#define AP_LDAP_IS_SERVER_DOWN(s)    ((s) == LDAP_SERVER_DOWN \
                                   || (s) == LDAP_UNAVAILABLE)
#else
#define AP_LDAP_IS_SERVER_DOWN(s)    ((s) == LDAP_SERVER_DOWN)
#endif

#include "ap_ldap_url.h"
#include "ap_ldap_init.h"
#include "ap_ldap_option.h"
#include "ap_ldap_rebind.h"

#endif /* AP_HAS_LDAP */
/** @} */
#endif /* AP_LDAP_H */
Loading