|
|
96373c |
From 656b141630c5f37a953a75ff05d3a1a30b14eef1 Mon Sep 17 00:00:00 2001
|
|
|
96373c |
From: Mark Reynolds <mreynolds@redhat.com>
|
|
|
96373c |
Date: Thu, 1 Feb 2018 14:28:24 -0500
|
|
|
96373c |
Subject: [PATCH] Ticket 49557 - Add config option for checking CRL on outbound
|
|
|
96373c |
SSL Connections
|
|
|
96373c |
|
|
|
96373c |
Bug Description: There are cases where a CRL is not available during an outbound
|
|
|
96373c |
replication connection. This is seen as an error by openldap,
|
|
|
96373c |
and the connection fails.
|
|
|
96373c |
|
|
|
96373c |
Fix Description: Add on/off option for checking the CRL. The default is not to
|
|
|
96373c |
check the CRL.
|
|
|
96373c |
|
|
|
96373c |
https://pagure.io/389-ds-base/issue/49557
|
|
|
96373c |
|
|
|
96373c |
Reviewed by: wibrown, Ludwig Krispenz, Thierry Bordaz
|
|
|
96373c |
---
|
|
|
96373c |
dirsrvtests/tests/suites/{ssl => tls}/__init__.py | 0
|
|
|
96373c |
dirsrvtests/tests/suites/tls/tls_check_crl_test.py | 52 +++++++++++++++++
|
|
|
96373c |
ldap/schema/01core389.ldif | 1 +
|
|
|
96373c |
ldap/servers/slapd/ldaputil.c | 9 ++-
|
|
|
96373c |
ldap/servers/slapd/libglobs.c | 66 +++++++++++++++++++++-
|
|
|
96373c |
ldap/servers/slapd/proto-slap.h | 2 +
|
|
|
96373c |
ldap/servers/slapd/slap.h | 10 +++-
|
|
|
96373c |
7 files changed, 135 insertions(+), 5 deletions(-)
|
|
|
96373c |
rename dirsrvtests/tests/suites/{ssl => tls}/__init__.py (100%)
|
|
|
96373c |
create mode 100644 dirsrvtests/tests/suites/tls/tls_check_crl_test.py
|
|
|
96373c |
|
|
|
96373c |
diff --git a/dirsrvtests/tests/suites/ssl/__init__.py b/dirsrvtests/tests/suites/tls/__init__.py
|
|
|
96373c |
similarity index 100%
|
|
|
96373c |
rename from dirsrvtests/tests/suites/ssl/__init__.py
|
|
|
96373c |
rename to dirsrvtests/tests/suites/tls/__init__.py
|
|
|
96373c |
diff --git a/dirsrvtests/tests/suites/tls/tls_check_crl_test.py b/dirsrvtests/tests/suites/tls/tls_check_crl_test.py
|
|
|
96373c |
new file mode 100644
|
|
|
96373c |
index 000000000..8b4d07f94
|
|
|
96373c |
--- /dev/null
|
|
|
96373c |
+++ b/dirsrvtests/tests/suites/tls/tls_check_crl_test.py
|
|
|
96373c |
@@ -0,0 +1,52 @@
|
|
|
96373c |
+# --- BEGIN COPYRIGHT BLOCK ---
|
|
|
96373c |
+# Copyright (C) 2018 Red Hat, Inc.
|
|
|
96373c |
+# All rights reserved.
|
|
|
96373c |
+#
|
|
|
96373c |
+# License: GPL (version 3 or any later version).
|
|
|
96373c |
+# See LICENSE for details.
|
|
|
96373c |
+# --- END COPYRIGHT BLOCK ---
|
|
|
96373c |
+#
|
|
|
96373c |
+
|
|
|
96373c |
+
|
|
|
96373c |
+import pytest
|
|
|
96373c |
+import ldap
|
|
|
96373c |
+from lib389.topologies import topology_st
|
|
|
96373c |
+
|
|
|
96373c |
+def test_tls_check_crl(topology_st):
|
|
|
96373c |
+ """Test that TLS check_crl configurations work as expected.
|
|
|
96373c |
+
|
|
|
96373c |
+ :id:
|
|
|
96373c |
+ :steps:
|
|
|
96373c |
+ 1. Enable TLS
|
|
|
96373c |
+ 2. Set invalid value
|
|
|
96373c |
+ 3. Set valid values
|
|
|
96373c |
+ 4. Check config reset
|
|
|
96373c |
+ :expectedresults:
|
|
|
96373c |
+ 1. TlS is setup
|
|
|
96373c |
+ 2. The invalid value is rejected
|
|
|
96373c |
+ 3. The valid values are used
|
|
|
96373c |
+ 4. The value can be reset
|
|
|
96373c |
+ """
|
|
|
96373c |
+ standalone = topology_st.standalone
|
|
|
96373c |
+ # Enable TLS
|
|
|
96373c |
+ standalone.enable_tls()
|
|
|
96373c |
+ # Check all the valid values.
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'none')
|
|
|
96373c |
+ with pytest.raises(ldap.OPERATIONS_ERROR):
|
|
|
96373c |
+ standalone.config.set('nsslapd-tls-check-crl', 'tnhoeutnoeutn')
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'none')
|
|
|
96373c |
+
|
|
|
96373c |
+ standalone.config.set('nsslapd-tls-check-crl', 'peer')
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'peer')
|
|
|
96373c |
+
|
|
|
96373c |
+ standalone.config.set('nsslapd-tls-check-crl', 'none')
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'none')
|
|
|
96373c |
+
|
|
|
96373c |
+ standalone.config.set('nsslapd-tls-check-crl', 'all')
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'all')
|
|
|
96373c |
+
|
|
|
96373c |
+ standalone.config.remove_all('nsslapd-tls-check-crl')
|
|
|
96373c |
+ assert(standalone.config.get_attr_val_utf8('nsslapd-tls-check-crl') == 'none')
|
|
|
96373c |
+
|
|
|
96373c |
+
|
|
|
96373c |
+
|
|
|
96373c |
diff --git a/ldap/schema/01core389.ldif b/ldap/schema/01core389.ldif
|
|
|
96373c |
index ab124c86c..c7f9fef2b 100644
|
|
|
96373c |
--- a/ldap/schema/01core389.ldif
|
|
|
96373c |
+++ b/ldap/schema/01core389.ldif
|
|
|
96373c |
@@ -304,6 +304,7 @@ attributeTypes: ( 2.16.840.1.113730.3.1.2332 NAME 'allowWeakDHParam' DESC 'Netsc
|
|
|
96373c |
attributeTypes: ( 2.16.840.1.113730.3.1.2333 NAME 'nsds5ReplicaReleaseTimeout' DESC 'Netscape defined attribute type' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'Netscape Directory Server' )
|
|
|
96373c |
attributeTypes: ( 2.16.840.1.113730.3.1.2335 NAME 'nsds5ReplicaIgnoreMissingChange' DESC 'Netscape defined attribute type' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'Netscape Directory Server' )
|
|
|
96373c |
attributeTypes: ( 2.16.840.1.113730.3.1.2336 NAME 'nsDS5ReplicaBindDnGroupCheckInterval' DESC 'Replication configuration setting for controlling the bind dn group check interval' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'Netscape Directory Server' )
|
|
|
96373c |
+attributeTypes: ( 2.16.840.1.113730.3.1.2344 NAME 'nsslapd-tls-check-crl' DESC 'Check CRL when opening outbound TLS connections. Valid options are none, peer, all.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN '389 Directory Server' )
|
|
|
96373c |
#
|
|
|
96373c |
# objectclasses
|
|
|
96373c |
#
|
|
|
96373c |
diff --git a/ldap/servers/slapd/ldaputil.c b/ldap/servers/slapd/ldaputil.c
|
|
|
96373c |
index fa9d276a3..2fc2f0615 100644
|
|
|
96373c |
--- a/ldap/servers/slapd/ldaputil.c
|
|
|
96373c |
+++ b/ldap/servers/slapd/ldaputil.c
|
|
|
96373c |
@@ -570,6 +570,7 @@ slapi_ldif_parse_line(
|
|
|
96373c |
}
|
|
|
96373c |
|
|
|
96373c |
#if defined(USE_OPENLDAP)
|
|
|
96373c |
+
|
|
|
96373c |
static int
|
|
|
96373c |
setup_ol_tls_conn(LDAP *ld, int clientauth)
|
|
|
96373c |
{
|
|
|
96373c |
@@ -602,7 +603,13 @@ setup_ol_tls_conn(LDAP *ld, int clientauth)
|
|
|
96373c |
}
|
|
|
96373c |
}
|
|
|
96373c |
if (slapi_client_uses_openssl(ld)) {
|
|
|
96373c |
- const int crlcheck = LDAP_OPT_X_TLS_CRL_ALL;
|
|
|
96373c |
+ int32_t crlcheck = LDAP_OPT_X_TLS_CRL_NONE;
|
|
|
96373c |
+ tls_check_crl_t tls_check_state = config_get_tls_check_crl();
|
|
|
96373c |
+ if (tls_check_state == TLS_CHECK_PEER) {
|
|
|
96373c |
+ crlcheck = LDAP_OPT_X_TLS_CRL_PEER;
|
|
|
96373c |
+ } else if (tls_check_state == TLS_CHECK_ALL) {
|
|
|
96373c |
+ crlcheck = LDAP_OPT_X_TLS_CRL_ALL;
|
|
|
96373c |
+ }
|
|
|
96373c |
/* Sets the CRL evaluation strategy. */
|
|
|
96373c |
rc = ldap_set_option(ld, LDAP_OPT_X_TLS_CRLCHECK, &crlcheck);
|
|
|
96373c |
if (rc) {
|
|
|
96373c |
diff --git a/ldap/servers/slapd/libglobs.c b/ldap/servers/slapd/libglobs.c
|
|
|
96373c |
index c1a765aca..eb6552af1 100644
|
|
|
96373c |
--- a/ldap/servers/slapd/libglobs.c
|
|
|
96373c |
+++ b/ldap/servers/slapd/libglobs.c
|
|
|
96373c |
@@ -157,7 +157,8 @@ typedef enum {
|
|
|
96373c |
CONFIG_STRING_OR_EMPTY, /* use an empty string */
|
|
|
96373c |
CONFIG_SPECIAL_ANON_ACCESS_SWITCH, /* maps strings to an enumeration */
|
|
|
96373c |
CONFIG_SPECIAL_VALIDATE_CERT_SWITCH, /* maps strings to an enumeration */
|
|
|
96373c |
- CONFIG_SPECIAL_UNHASHED_PW_SWITCH /* unhashed pw: on/off/nolog */
|
|
|
96373c |
+ CONFIG_SPECIAL_UNHASHED_PW_SWITCH, /* unhashed pw: on/off/nolog */
|
|
|
96373c |
+ CONFIG_SPECIAL_TLS_CHECK_CRL, /* maps enum tls_check_crl_t to char * */
|
|
|
96373c |
} ConfigVarType;
|
|
|
96373c |
|
|
|
96373c |
static int32_t config_set_onoff(const char *attrname, char *value, int32_t *configvalue, char *errorbuf, int apply);
|
|
|
96373c |
@@ -1173,7 +1174,15 @@ static struct config_get_and_set
|
|
|
96373c |
{CONFIG_LOGGING_BACKEND, NULL,
|
|
|
96373c |
log_set_backend, 0,
|
|
|
96373c |
(void **)&global_slapdFrontendConfig.logging_backend,
|
|
|
96373c |
- CONFIG_STRING_OR_EMPTY, NULL, SLAPD_INIT_LOGGING_BACKEND_INTERNAL}};
|
|
|
96373c |
+ CONFIG_STRING_OR_EMPTY, NULL, SLAPD_INIT_LOGGING_BACKEND_INTERNAL},
|
|
|
96373c |
+ {CONFIG_TLS_CHECK_CRL_ATTRIBUTE, config_set_tls_check_crl,
|
|
|
96373c |
+ NULL, 0,
|
|
|
96373c |
+ (void **)&global_slapdFrontendConfig.tls_check_crl,
|
|
|
96373c |
+ CONFIG_SPECIAL_TLS_CHECK_CRL, (ConfigGetFunc)config_get_tls_check_crl,
|
|
|
96373c |
+ "none" /* Allow reset to this value */}
|
|
|
96373c |
+
|
|
|
96373c |
+ /* End config */
|
|
|
96373c |
+ };
|
|
|
96373c |
|
|
|
96373c |
/*
|
|
|
96373c |
* hashNocaseString - used for case insensitive hash lookups
|
|
|
96373c |
@@ -1506,7 +1515,6 @@ FrontendConfig_init(void)
|
|
|
96373c |
cfg->maxdescriptors = SLAPD_DEFAULT_MAXDESCRIPTORS;
|
|
|
96373c |
cfg->groupevalnestlevel = SLAPD_DEFAULT_GROUPEVALNESTLEVEL;
|
|
|
96373c |
cfg->snmp_index = SLAPD_DEFAULT_SNMP_INDEX;
|
|
|
96373c |
-
|
|
|
96373c |
cfg->SSLclientAuth = SLAPD_DEFAULT_SSLCLIENTAUTH;
|
|
|
96373c |
|
|
|
96373c |
#ifdef USE_SYSCONF
|
|
|
96373c |
@@ -1524,6 +1532,7 @@ FrontendConfig_init(void)
|
|
|
96373c |
#endif
|
|
|
96373c |
init_security = cfg->security = LDAP_OFF;
|
|
|
96373c |
init_ssl_check_hostname = cfg->ssl_check_hostname = LDAP_ON;
|
|
|
96373c |
+ cfg->tls_check_crl = TLS_CHECK_NONE;
|
|
|
96373c |
init_return_exact_case = cfg->return_exact_case = LDAP_ON;
|
|
|
96373c |
init_result_tweak = cfg->result_tweak = LDAP_OFF;
|
|
|
96373c |
init_attrname_exceptions = cfg->attrname_exceptions = LDAP_OFF;
|
|
|
96373c |
@@ -2042,6 +2051,7 @@ config_set_port(const char *attrname, char *port, char *errorbuf, int apply)
|
|
|
96373c |
return retVal;
|
|
|
96373c |
}
|
|
|
96373c |
|
|
|
96373c |
+
|
|
|
96373c |
int
|
|
|
96373c |
config_set_secureport(const char *attrname, char *port, char *errorbuf, int apply)
|
|
|
96373c |
{
|
|
|
96373c |
@@ -2073,6 +2083,33 @@ config_set_secureport(const char *attrname, char *port, char *errorbuf, int appl
|
|
|
96373c |
}
|
|
|
96373c |
|
|
|
96373c |
|
|
|
96373c |
+int32_t
|
|
|
96373c |
+config_set_tls_check_crl(const char *attrname, char *value, char *errorbuf, int apply)
|
|
|
96373c |
+{
|
|
|
96373c |
+ int32_t retVal = LDAP_SUCCESS;
|
|
|
96373c |
+ /* Default */
|
|
|
96373c |
+ tls_check_crl_t state = TLS_CHECK_NONE;
|
|
|
96373c |
+ slapdFrontendConfig_t *slapdFrontendConfig = getFrontendConfig();
|
|
|
96373c |
+
|
|
|
96373c |
+ if (strcasecmp(value, "none") == 0) {
|
|
|
96373c |
+ state = TLS_CHECK_NONE;
|
|
|
96373c |
+ } else if (strcasecmp(value, "peer") == 0) {
|
|
|
96373c |
+ state = TLS_CHECK_PEER;
|
|
|
96373c |
+ } else if (strcasecmp(value, "all") == 0) {
|
|
|
96373c |
+ state = TLS_CHECK_ALL;
|
|
|
96373c |
+ } else {
|
|
|
96373c |
+ retVal = LDAP_OPERATIONS_ERROR;
|
|
|
96373c |
+ slapi_create_errormsg(errorbuf, SLAPI_DSE_RETURNTEXT_SIZE, "%s: unsupported value: %s", attrname, value);
|
|
|
96373c |
+ }
|
|
|
96373c |
+
|
|
|
96373c |
+ if (retVal == LDAP_SUCCESS && apply) {
|
|
|
96373c |
+ slapi_atomic_store_32((int32_t *)&(slapdFrontendConfig->tls_check_crl), state, __ATOMIC_RELEASE);
|
|
|
96373c |
+ }
|
|
|
96373c |
+
|
|
|
96373c |
+ return retVal;
|
|
|
96373c |
+}
|
|
|
96373c |
+
|
|
|
96373c |
+
|
|
|
96373c |
int
|
|
|
96373c |
config_set_SSLclientAuth(const char *attrname, char *value, char *errorbuf, int apply)
|
|
|
96373c |
{
|
|
|
96373c |
@@ -4591,6 +4628,12 @@ config_set_versionstring(const char *attrname __attribute__((unused)), char *ver
|
|
|
96373c |
|
|
|
96373c |
#define config_copy_strval(s) s ? slapi_ch_strdup(s) : NULL;
|
|
|
96373c |
|
|
|
96373c |
+tls_check_crl_t
|
|
|
96373c |
+config_get_tls_check_crl() {
|
|
|
96373c |
+ slapdFrontendConfig_t *slapdFrontendConfig = getFrontendConfig();
|
|
|
96373c |
+ return (tls_check_crl_t)slapi_atomic_load_32((int32_t *)&(slapdFrontendConfig->tls_check_crl), __ATOMIC_ACQUIRE);
|
|
|
96373c |
+}
|
|
|
96373c |
+
|
|
|
96373c |
int
|
|
|
96373c |
config_get_port()
|
|
|
96373c |
{
|
|
|
96373c |
@@ -7439,6 +7482,23 @@ config_set_value(
|
|
|
96373c |
slapi_entry_attr_set_int(e, cgas->attr_name, ival);
|
|
|
96373c |
break;
|
|
|
96373c |
|
|
|
96373c |
+ case CONFIG_SPECIAL_TLS_CHECK_CRL:
|
|
|
96373c |
+ if (!value) {
|
|
|
96373c |
+ slapi_entry_attr_set_charptr(e, cgas->attr_name, (char *)cgas->initvalue);
|
|
|
96373c |
+ break;
|
|
|
96373c |
+ }
|
|
|
96373c |
+ tls_check_crl_t state = *(tls_check_crl_t *)value;
|
|
|
96373c |
+
|
|
|
96373c |
+ if (state == TLS_CHECK_ALL) {
|
|
|
96373c |
+ sval = "all";
|
|
|
96373c |
+ } else if (state == TLS_CHECK_PEER) {
|
|
|
96373c |
+ sval = "peer";
|
|
|
96373c |
+ } else {
|
|
|
96373c |
+ sval = "none";
|
|
|
96373c |
+ }
|
|
|
96373c |
+ slapi_entry_attr_set_charptr(e, cgas->attr_name, sval);
|
|
|
96373c |
+ break;
|
|
|
96373c |
+
|
|
|
96373c |
case CONFIG_SPECIAL_SSLCLIENTAUTH:
|
|
|
96373c |
if (!value) {
|
|
|
96373c |
slapi_entry_attr_set_charptr(e, cgas->attr_name, "off");
|
|
|
96373c |
diff --git a/ldap/servers/slapd/proto-slap.h b/ldap/servers/slapd/proto-slap.h
|
|
|
96373c |
index 3b7ab53b2..b13334ad1 100644
|
|
|
96373c |
--- a/ldap/servers/slapd/proto-slap.h
|
|
|
96373c |
+++ b/ldap/servers/slapd/proto-slap.h
|
|
|
96373c |
@@ -236,6 +236,7 @@ int config_set_port(const char *attrname, char *port, char *errorbuf, int apply)
|
|
|
96373c |
int config_set_secureport(const char *attrname, char *port, char *errorbuf, int apply);
|
|
|
96373c |
int config_set_SSLclientAuth(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
int config_set_ssl_check_hostname(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
+int32_t config_set_tls_check_crl(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
int config_set_SSL3ciphers(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
int config_set_localhost(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
int config_set_listenhost(const char *attrname, char *value, char *errorbuf, int apply);
|
|
|
96373c |
@@ -397,6 +398,7 @@ void log_disable_hr_timestamps(void);
|
|
|
96373c |
|
|
|
96373c |
int config_get_SSLclientAuth(void);
|
|
|
96373c |
int config_get_ssl_check_hostname(void);
|
|
|
96373c |
+tls_check_crl_t config_get_tls_check_crl(void);
|
|
|
96373c |
char *config_get_SSL3ciphers(void);
|
|
|
96373c |
char *config_get_localhost(void);
|
|
|
96373c |
char *config_get_listenhost(void);
|
|
|
96373c |
diff --git a/ldap/servers/slapd/slap.h b/ldap/servers/slapd/slap.h
|
|
|
96373c |
index 216d94afd..443d90094 100644
|
|
|
96373c |
--- a/ldap/servers/slapd/slap.h
|
|
|
96373c |
+++ b/ldap/servers/slapd/slap.h
|
|
|
96373c |
@@ -443,6 +443,13 @@ typedef void (*VFPV)(); /* takes undefined arguments */
|
|
|
96373c |
typedef int32_t slapi_onoff_t;
|
|
|
96373c |
typedef int32_t slapi_int_t;
|
|
|
96373c |
|
|
|
96373c |
+typedef enum _tls_check_crl_t {
|
|
|
96373c |
+ TLS_CHECK_NONE = 0,
|
|
|
96373c |
+ TLS_CHECK_PEER = 1,
|
|
|
96373c |
+ TLS_CHECK_ALL = 2,
|
|
|
96373c |
+} tls_check_crl_t;
|
|
|
96373c |
+
|
|
|
96373c |
+
|
|
|
96373c |
struct subfilt
|
|
|
96373c |
{
|
|
|
96373c |
char *sf_type;
|
|
|
96373c |
@@ -2151,6 +2158,7 @@ typedef struct _slapdEntryPoints
|
|
|
96373c |
#define CONFIG_RUNDIR_ATTRIBUTE "nsslapd-rundir"
|
|
|
96373c |
#define CONFIG_SSLCLIENTAUTH_ATTRIBUTE "nsslapd-SSLclientAuth"
|
|
|
96373c |
#define CONFIG_SSL_CHECK_HOSTNAME_ATTRIBUTE "nsslapd-ssl-check-hostname"
|
|
|
96373c |
+#define CONFIG_TLS_CHECK_CRL_ATTRIBUTE "nsslapd-tls-check-crl"
|
|
|
96373c |
#define CONFIG_HASH_FILTERS_ATTRIBUTE "nsslapd-hash-filters"
|
|
|
96373c |
#define CONFIG_OUTBOUND_LDAP_IO_TIMEOUT_ATTRIBUTE "nsslapd-outbound-ldap-io-timeout"
|
|
|
96373c |
#define CONFIG_FORCE_SASL_EXTERNAL_ATTRIBUTE "nsslapd-force-sasl-external"
|
|
|
96373c |
@@ -2263,6 +2271,7 @@ typedef struct _slapdFrontendConfig
|
|
|
96373c |
slapi_onoff_t security;
|
|
|
96373c |
int SSLclientAuth;
|
|
|
96373c |
slapi_onoff_t ssl_check_hostname;
|
|
|
96373c |
+ tls_check_crl_t tls_check_crl;
|
|
|
96373c |
int validate_cert;
|
|
|
96373c |
int sizelimit;
|
|
|
96373c |
int SNMPenabled;
|
|
|
96373c |
@@ -2294,7 +2303,6 @@ typedef struct _slapdFrontendConfig
|
|
|
96373c |
slapi_onoff_t plugin_track;
|
|
|
96373c |
slapi_onoff_t moddn_aci;
|
|
|
96373c |
struct pw_scheme *pw_storagescheme;
|
|
|
96373c |
-
|
|
|
96373c |
slapi_onoff_t pwpolicy_local;
|
|
|
96373c |
slapi_onoff_t pw_is_global_policy;
|
|
|
96373c |
slapi_onoff_t pwpolicy_inherit_global;
|
|
|
96373c |
--
|
|
|
96373c |
2.13.6
|
|
|
96373c |
|