Jan Vcelak a431c66
# Author: Jan Vcelak <jvcelak@redhat.com>
Jan Vcelak a431c66
Jan Vcelak a431c66
SLAPD_USER=
Jan Vcelak a431c66
SLAPD_CONFIG_FILE=
Jan Vcelak a431c66
SLAPD_CONFIG_DIR=
Jan Vcelak a431c66
SLAPD_CONFIG_CUSTOM=
Jan Vcelak a431c66
SLAPD_GLOBAL_OPTIONS=
Jan Vcelak a431c66
SLAPD_SYSCONFIG_FILE=
Jan Vcelak a431c66
Jan Vcelak a431c66
function default_config()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	SLAPD_USER=ldap
Jan Vcelak a431c66
	SLAPD_CONFIG_FILE=/etc/openldap/slapd.conf
Jan Vcelak a431c66
	SLAPD_CONFIG_DIR=/etc/openldap/slapd.d
Jan Vcelak a431c66
	SLAPD_CONFIG_CUSTOM=
Jan Vcelak a431c66
	SLAPD_GLOBAL_OPTIONS=
Jan Vcelak a431c66
	SLAPD_SYSCONFIG_FILE=/etc/sysconfig/slapd
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function parse_config_options()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	user=
Jan Vcelak a431c66
	config_file=
Jan Vcelak a431c66
	config_dir=
Jan Vcelak a431c66
	while getopts :u:f:F: opt; do
Jan Vcelak a431c66
		case "$opt" in
Jan Vcelak a431c66
		u)
Jan Vcelak a431c66
			user="$OPTARG"
Jan Vcelak a431c66
			;;
Jan Vcelak a431c66
		f)
Jan Vcelak a431c66
			config_file="$OPTARG"
Jan Vcelak a431c66
			;;
Jan Vcelak a431c66
		F)
Jan Vcelak a431c66
			config_dir="$OPTARG"
Jan Vcelak a431c66
			;;
Jan Vcelak a431c66
		esac
Jan Vcelak a431c66
	done
Jan Vcelak a431c66
Jan Vcelak a431c66
	if [ -n "$user" ]; then
Jan Vcelak a431c66
		SLAPD_USER="$user"
Jan Vcelak a431c66
	fi
Jan Vcelak a431c66
Jan Vcelak a431c66
	if [ -n "$config_dir" ]; then
Jan Vcelak a431c66
		SLAPD_CONFIG_DIR="$config_dir"
Jan Vcelak a431c66
		SLAPD_CONFIG_FILE=
Jan Vcelak a431c66
		SLAPD_CONFIG_CUSTOM=1
Jan Vcelak a431c66
		SLAPD_GLOBAL_OPTIONS="-F '$config_dir'"
Jan Vcelak a431c66
	elif [ -n "$config_file" ]; then
Jan Vcelak a431c66
		SLAPD_CONFIG_DIR=
Jan Vcelak a431c66
		SLAPD_CONFIG_FILE="$config_file"
Jan Vcelak a431c66
		SLAPD_CONFIG_CUSTOM=1
Jan Vcelak a431c66
		SLAPD_GLOBAL_OPTIONS="-f '$config_file'"
Jan Vcelak a431c66
	fi
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function uses_new_config()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	[ -n "$SLAPD_CONFIG_DIR" ]
Jan Vcelak a431c66
	return $?
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function run_as_ldap()
Jan Vcelak a431c66
{
Jan Vcelak d5cbb77
	/sbin/runuser --shell /bin/sh --session-command "$1" "$SLAPD_USER"
Jan Vcelak a431c66
	return $?
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function ldif_unbreak()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	sed ':a;N;s/\n //;ta;P;D'
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function ldif_value()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	sed 's/^[^:]*: //'
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function databases_new()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	slapcat $SLAPD_GLOBAL_OPTIONS -c \
Jan Vcelak a431c66
	-H 'ldap:///cn=config???(|(objectClass=olcBdbConfig)(objectClass=olcHdbConfig))' 2>/dev/null | \
Jan Vcelak a431c66
		ldif_unbreak | \
Jan Vcelak a431c66
		grep '^olcDbDirectory: ' | \
Jan Vcelak a431c66
		ldif_value
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function databases_old()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	awk	'begin { database="" }
Jan Vcelak a431c66
		$1 == "database" { database=$2 }
Jan Vcelak a431c66
		$1 == "directory" { if (database == "bdb" || database == "hdb") print $2}' \
Jan Vcelak a431c66
		"$SLAPD_CONFIG_FILE"
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function certificates_new()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	slapcat $SLAPD_GLOBAL_OPTIONS -c -H 'ldap:///cn=config???(cn=config)' 2>/dev/null | \
Jan Vcelak a431c66
		ldif_unbreak | \
Jan Vcelak a431c66
		grep '^olcTLS\(CACertificateFile\|CACertificatePath\|CertificateFile\|CertificateKeyFile\): ' | \
Jan Vcelak a431c66
		ldif_value
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function certificates_old()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	awk '$1 ~ "^TLS(CACertificate(File|Path)|CertificateFile|CertificateKeyFile)$" { print $2 } ' \
Jan Vcelak a431c66
		"$SLAPD_CONFIG_FILE"
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function certificates()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	uses_new_config && certificates_new || certificates_old
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function databases()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	uses_new_config && databases_new || databases_old
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
Jan Vcelak a431c66
function error()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	format="$1\n"; shift
Jan Vcelak a431c66
	printf "$format" $@ >&2
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
function load_sysconfig()
Jan Vcelak a431c66
{
Jan Vcelak a431c66
	[ -r "$SLAPD_SYSCONFIG_FILE" ] || return
Jan Vcelak a431c66
Jan Vcelak a431c66
	. "$SLAPD_SYSCONFIG_FILE"
Jan Vcelak a431c66
	[ -n "$SLAPD_OPTIONS" ] && parse_config_options $SLAPD_OPTIONS
Jan Vcelak a431c66
}
Jan Vcelak a431c66
Jan Vcelak a431c66
default_config