fixed TLS support in ldap, thanks backseat

This commit is contained in:
mdipierro
2015-08-01 00:21:56 -05:00
parent d7caaf04cc
commit 048f275076
3 changed files with 12 additions and 2 deletions
+1 -1
View File
@@ -32,7 +32,7 @@ update:
echo "remember that pymysql was tweaked" echo "remember that pymysql was tweaked"
src: src:
### Use semantic versioning ### Use semantic versioning
echo 'Version 2.12.0-stable+timestamp.'`date +%Y.%m.%d.%H.%M.%S` > VERSION echo 'Version 2.12.0-beta+timestamp.'`date +%Y.%m.%d.%H.%M.%S` > VERSION
### rm -f all junk files ### rm -f all junk files
make clean make clean
### clean up baisc apps ### clean up baisc apps
+1 -1
View File
@@ -1 +1 @@
Version 2.12.0-stable+timestamp.2015.07.20.01.19.51 Version 2.12.0-stable+timestamp.2015.07.30.10.03.50
+10
View File
@@ -33,6 +33,7 @@ def ldap_auth(server='ldap', port=None,
group_name_attrib='cn', group_name_attrib='cn',
group_member_attrib='memberUid', group_member_attrib='memberUid',
group_filterstr='objectClass=*', group_filterstr='objectClass=*',
tls=False,
logging_level='error'): logging_level='error'):
""" """
@@ -80,6 +81,13 @@ def ldap_auth(server='ldap', port=None,
If ldap is using GnuTLS then you need cert_file="..." instead cert_path If ldap is using GnuTLS then you need cert_file="..." instead cert_path
because cert_path isn't implemented in GnuTLS :( because cert_path isn't implemented in GnuTLS :(
To enable TLS, set tls=True:
auth.settings.login_methods.append(ldap_auth(
server='my.ldap.server',
base_dn='ou=Users,dc=domain,dc=com',
tls=True))
If you need to bind to the directory with an admin account in order to If you need to bind to the directory with an admin account in order to
search it then specify bind_dn & bind_pw to use for this. search it then specify bind_dn & bind_pw to use for this.
- currently only implemented for Active Directory - currently only implemented for Active Directory
@@ -610,6 +618,8 @@ def ldap_auth(server='ldap', port=None,
ldap_port = 389 ldap_port = 389
con = ldap.initialize( con = ldap.initialize(
"ldap://" + ldap_server + ":" + str(ldap_port)) "ldap://" + ldap_server + ":" + str(ldap_port))
if tls:
con.start_tls_s()
return con return con
def get_user_groups_from_ldap(username, def get_user_groups_from_ldap(username,