#! /bin/sh # $OpenLDAP$ ## This work is part of OpenLDAP Software . ## ## Copyright 1998-2022 The OpenLDAP Foundation. ## All rights reserved. ## ## Redistribution and use in source and binary forms, with or without ## modification, are permitted only as authorized by the OpenLDAP ## Public License. ## ## A copy of this license is available in the file LICENSE in the ## top-level directory of the distribution or, alternatively, at ## . echo "running defines.sh" . $SRCDIR/scripts/defines.sh if test $WITH_TLS = no ; then echo "TLS support not available, test skipped" exit 0 fi if test $BACKLDAP = "ldapno" ; then echo "LDAP backend not available, test skipped" exit 0 fi if test "$BACKEND" = "ldap"; then echo "LDAP backend not valid, test skipped" exit 0 fi mkdir -p $TESTDIR $DBDIR1 cp -r $DATADIR/tls $TESTDIR $SLAPPASSWD -g -n >$CONFIGPWF echo "rootpw `$SLAPPASSWD -T $CONFIGPWF`" >$TESTDIR/configpw.conf ITS=8427 ITSDIR=$DATADIR/regressions/its$ITS echo "Running slapadd to build slapd database..." . $CONFFILTER $BACKEND < $TLSCONF > $CONF1 $SLAPADD -f $CONF1 -l $LDIFORDERED RC=$? if test $RC != 0 ; then echo "slapadd failed ($RC)!" exit $RC fi echo "database config" >> $CONF1 echo "include $TESTDIR/configpw.conf" >> $CONF1 echo "Starting slapd listening on $URIP1 and $SURIP2..." $SLAPD -f $CONF1 -h "$URIP1 $SURIP2" -d $LVL > $LOG1 2>&1 & SERVERPID=$! if test $WAIT != 0 ; then echo SERVERPID $SERVERPID read foo fi KILLPIDS="$SERVERPID" sleep 1 echo "Using ldapsearch to check that slapd is running..." for i in 0 1 2 3 4 5; do $LDAPSEARCH -s base -b "$MONITOR" -H $URI1 \ 'objectclass=*' > /dev/null 2>&1 RC=$? if test $RC = 0 ; then break fi echo "Waiting 5 seconds for slapd to start..." sleep 5 done if test $RC != 0 ; then echo "ldapsearch failed ($RC)!" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit $RC fi echo "database config" >> $CONF2 echo "include $TESTDIR/configpw.conf" >> $CONF2 echo "Starting proxy slapd on TCP/IP port $PORT3..." . $CONFFILTER $BACKEND < $ITSDIR/slapd.conf > $CONF2 $SLAPD -f $CONF2 -h $URI3 -d $LVL > $LOG2 2>&1 & PROXYPID=$! if test $WAIT != 0 ; then echo PROXYPID $PROXYPID read foo fi KILLPIDS="$KILLPIDS $PROXYPID" sleep 1 echo "Using ldapsearch to check that proxy slapd is running..." for i in 0 1 2 3 4 5; do $LDAPSEARCH -s base -b "$MONITOR" -H $URI3 \ 'objectclass=*' > /dev/null 2>&1 RC=$? if test $RC = 0 ; then break fi echo "Waiting 5 seconds for slapd to start..." sleep 5 done if test $RC != 0 ; then echo "ldapsearch failed ($RC)!" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit $RC fi echo "Configuring proxy..." $LDAPMODIFY -D cn=config -H $URI3 -y $CONFIGPWF \ > $TESTOUT 2>&1 < $SEARCHOUT $LDAPSEARCH -b "$BASEDN" -H $URI3 \ -D "$BABSDN" -w bjensen \ '(objectClass=*)' >> $SEARCHOUT 2>&1 RC=$? if test $RC != 0 ; then echo "ldapsearch failed ($RC)!" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit $RC fi echo "Filtering ldapsearch results..." $LDIFFILTER < $SEARCHOUT > $SEARCHFLT echo "Filtering original ldif used to create database..." $LDIFFILTER < $LDIFORDERED > $LDIFFLT echo "" >> $LDIFFLT echo "Comparing filter output..." $CMP $SEARCHFLT $LDIFFLT > $CMPOUT if test $? != 0 ; then echo "Comparison failed" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit 1 fi echo "Reconfiguring database to only allow TLS binds..." $LDAPMODIFY -D cn=config -H $URI1 -y $CONFIGPWF \ > $TESTOUT 2>&1 < $TESTOUT 2>&1 < $TESTOUT 2>&1 < $SEARCHOUT $LDAPSEARCH -b "$BASEDN" -H $URI3 \ -D "$BABSDN" -w bjensen \ '(objectClass=*)' >> $SEARCHOUT 2>&1 RC=$? if test $RC != 0 ; then echo "ldapsearch failed ($RC)!" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit $RC fi echo "Filtering ldapsearch results..." $LDIFFILTER < $SEARCHOUT > $SEARCHFLT echo "Comparing filter output..." $CMP $SEARCHFLT $LDIFFLT > $CMPOUT if test $? != 0 ; then echo "Comparison failed" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit 1 fi echo "Re-configuring proxy to use LDAP+StartTLS correctly on privileged connections..." $LDAPMODIFY -D cn=config -H $URI3 -y $CONFIGPWF \ > $TESTOUT 2>&1 < $TESTOUT 2>&1 < $SEARCHOUT $LDAPSEARCH -b "$BASEDN" -H $URI3 \ -D "$BABSDN" -w bjensen \ '(objectClass=*)' >> $SEARCHOUT 2>&1 RC=$? if test $RC != 0 ; then echo "ldapsearch failed ($RC)!" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit $RC fi echo "Filtering ldapsearch results..." $LDIFFILTER < $SEARCHOUT > $SEARCHFLT echo "Comparing filter output..." $CMP $SEARCHFLT $LDIFFLT > $CMPOUT if test $? != 0 ; then echo "Comparison failed" test $KILLSERVERS != no && kill -HUP $KILLPIDS exit 1 fi test $KILLSERVERS != no && kill -HUP $KILLPIDS echo ">>>>> Test succeeded" test $KILLSERVERS != no && wait exit 0