Blame SOURCES/0154-RESPONDER_COMMON-update-certmaps-in-responders.patch

ecf709
From d363bd0f829fa7af5f96c2b07b975b7b2c5fdcfa Mon Sep 17 00:00:00 2001
ecf709
From: Sumit Bose <sbose@redhat.com>
ecf709
Date: Tue, 2 May 2017 15:25:10 +0200
ecf709
Subject: [PATCH 154/160] RESPONDER_COMMON: update certmaps in responders
ecf709
MIME-Version: 1.0
ecf709
Content-Type: text/plain; charset=UTF-8
ecf709
Content-Transfer-Encoding: 8bit
ecf709
ecf709
Make certificate mapping data available to the responders.
ecf709
ecf709
Related to https://pagure.io/SSSD/sssd/issue/3395
ecf709
ecf709
Reviewed-by: Fabiano FidĂȘncio <fidencio@redhat.com>
ecf709
(cherry picked from commit 749963195393efa3a4f9b168dd02fbcc68976ba3)
ecf709
---
ecf709
 src/confdb/confdb.h                          |  3 +++
ecf709
 src/responder/common/responder_get_domains.c | 23 +++++++++++++++++++++++
ecf709
 2 files changed, 26 insertions(+)
ecf709
ecf709
diff --git a/src/confdb/confdb.h b/src/confdb/confdb.h
ecf709
index 8719c239362b371fcdb1b78956bcddde871f141b..797353141edcccbf3341d161ca598c99492e54fe 100644
ecf709
--- a/src/confdb/confdb.h
ecf709
+++ b/src/confdb/confdb.h
ecf709
@@ -351,6 +351,9 @@ struct sss_domain_info {
ecf709
     char *forest;
ecf709
     struct sss_domain_info *forest_root;
ecf709
     const char **upn_suffixes;
ecf709
+
ecf709
+    struct certmap_info **certmaps;
ecf709
+    bool user_name_hint;
ecf709
 };
ecf709
 
ecf709
 /**
ecf709
diff --git a/src/responder/common/responder_get_domains.c b/src/responder/common/responder_get_domains.c
ecf709
index 8c90b7773e248e1dd6d846c5050e1931fc50c786..155631676d9449f69865919e1b74ee9399607c27 100644
ecf709
--- a/src/responder/common/responder_get_domains.c
ecf709
+++ b/src/responder/common/responder_get_domains.c
ecf709
@@ -224,6 +224,26 @@ immediately:
ecf709
     return req;
ecf709
 }
ecf709
 
ecf709
+static void sss_resp_update_certmaps(struct resp_ctx *rctx)
ecf709
+{
ecf709
+    int ret;
ecf709
+    struct certmap_info **certmaps;
ecf709
+    bool user_name_hint;
ecf709
+    struct sss_domain_info *dom;
ecf709
+
ecf709
+    for (dom = rctx->domains; dom != NULL; dom = dom->next) {
ecf709
+        ret = sysdb_get_certmap(dom, dom->sysdb, &certmaps, &user_name_hint);
ecf709
+        if (ret == EOK) {
ecf709
+            dom->user_name_hint = user_name_hint;
ecf709
+            talloc_free(dom->certmaps);
ecf709
+            dom->certmaps = certmaps;
ecf709
+        } else {
ecf709
+            DEBUG(SSSDBG_OP_FAILURE,
ecf709
+                  "sysdb_get_certmap failed for domain [%s].\n", dom->name);
ecf709
+        }
ecf709
+    }
ecf709
+}
ecf709
+
ecf709
 static void
ecf709
 sss_dp_get_domains_process(struct tevent_req *subreq)
ecf709
 {
ecf709
@@ -267,6 +287,9 @@ sss_dp_get_domains_process(struct tevent_req *subreq)
ecf709
                   ret, sss_strerror(ret));
ecf709
             goto fail;
ecf709
         }
ecf709
+
ecf709
+        sss_resp_update_certmaps(state->rctx);
ecf709
+
ecf709
         tevent_req_done(req);
ecf709
         return;
ecf709
     }
ecf709
-- 
ecf709
2.9.4
ecf709