| | |
| | | import org.opends.server.types.ResultCode; |
| | | |
| | | import static org.opends.server.config.ConfigConstants.*; |
| | | import static org.opends.server.extensions.ExtensionsConstants.*; |
| | | import static org.opends.server.loggers.Debug.*; |
| | | import static org.opends.server.loggers.Error.*; |
| | | import static org.opends.server.loggers.debug.DebugLogger.debugCought; |
| | | import static org.opends.server.loggers.debug.DebugLogger.debugEnabled; |
| | | import org.opends.server.types.DebugLogLevel; |
| | | import static org.opends.server.messages.ExtensionsMessages.*; |
| | | import static org.opends.server.messages.MessageHandler.*; |
| | | import static org.opends.server.util.ServerConstants.*; |
| | |
| | | extends SASLMechanismHandler |
| | | implements ConfigurableComponent |
| | | { |
| | | /** |
| | | * The fully-qualified name of this class for debugging purposes. |
| | | */ |
| | | private static final String CLASS_NAME = |
| | | "org.opends.server.extensions.CRAMMD5SASLMechanismHandler"; |
| | | |
| | | |
| | | |
| | |
| | | { |
| | | super(); |
| | | |
| | | assert debugConstructor(CLASS_NAME); |
| | | } |
| | | |
| | | |
| | |
| | | public void initializeSASLMechanismHandler(ConfigEntry configEntry) |
| | | throws ConfigException, InitializationException |
| | | { |
| | | assert debugEnter(CLASS_NAME, "initializeSASLMechanismHandler", |
| | | String.valueOf(configEntry)); |
| | | |
| | | |
| | | this.configEntryDN = configEntry.getDN(); |
| | |
| | | } |
| | | catch (Exception e) |
| | | { |
| | | assert debugException(CLASS_NAME, "initializeSASLMechanismHandler", e); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, e); |
| | | } |
| | | |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_GET_MESSAGE_DIGEST; |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_GET_MESSAGE_DIGEST; |
| | | String message = getMessage(msgID, stackTraceToSingleLineString(e)); |
| | | throw new InitializationException(msgID, message, e); |
| | | } |
| | |
| | | } |
| | | catch (Exception e) |
| | | { |
| | | assert debugException(CLASS_NAME, "initializeSASLMechanismHandler", e); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, e); |
| | | } |
| | | |
| | | msgID = MSGID_SASLCRAMMD5_CANNOT_GET_IDENTITY_MAPPER; |
| | | String message = getMessage(msgID, String.valueOf(configEntryDN), |
| | |
| | | @Override() |
| | | public void finalizeSASLMechanismHandler() |
| | | { |
| | | assert debugEnter(CLASS_NAME, "finalizeSASLMechanismHandler"); |
| | | |
| | | DirectoryServer.deregisterConfigurableComponent(this); |
| | | DirectoryServer.deregisterSASLMechanismHandler(SASL_MECHANISM_CRAM_MD5); |
| | |
| | | @Override() |
| | | public void processSASLBind(BindOperation bindOperation) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "processSASLBind", |
| | | String.valueOf(bindOperation)); |
| | | |
| | | |
| | | // The CRAM-MD5 bind process uses two stages. See if the client provided |
| | |
| | | } |
| | | catch (ParseException pe) |
| | | { |
| | | assert debugException(CLASS_NAME, "processSASLBind", pe); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, pe); |
| | | } |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | int msgID = MSGID_SASLCRAMMD5_INVALID_DIGEST_CONTENT; |
| | | int msgID = MSGID_SASLCRAMMD5_INVALID_DIGEST_CONTENT; |
| | | String message = getMessage(msgID, pe.getMessage()); |
| | | bindOperation.setAuthFailureReason(msgID, message); |
| | | return; |
| | |
| | | } |
| | | catch (DirectoryException de) |
| | | { |
| | | assert debugException(CLASS_NAME, "processSASLBind", de); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, de); |
| | | } |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_DECODE_USERNAME_AS_DN; |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_DECODE_USERNAME_AS_DN; |
| | | String message = getMessage(msgID, userName, de.getErrorMessage()); |
| | | bindOperation.setAuthFailureReason(msgID, message); |
| | | return; |
| | |
| | | } |
| | | catch (DirectoryException de) |
| | | { |
| | | assert debugException(CLASS_NAME, "processSASLBind", de); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, de); |
| | | } |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_GET_ENTRY_BY_DN; |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_GET_ENTRY_BY_DN; |
| | | String message = getMessage(msgID, String.valueOf(userDN), |
| | | de.getErrorMessage()); |
| | | bindOperation.setAuthFailureReason(msgID, message); |
| | |
| | | } |
| | | catch (DirectoryException de) |
| | | { |
| | | assert debugException(CLASS_NAME, "processSASLBind", de); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, de); |
| | | } |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_MAP_USERNAME; |
| | | int msgID = MSGID_SASLCRAMMD5_CANNOT_MAP_USERNAME; |
| | | String message = getMessage(msgID, String.valueOf(userName), |
| | | de.getErrorMessage()); |
| | | bindOperation.setAuthFailureReason(msgID, message); |
| | |
| | | */ |
| | | private byte[] generateDigest(ByteString password, ByteString challenge) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "generateDigest", |
| | | String.valueOf(password), String.valueOf(challenge)); |
| | | |
| | | |
| | | // Get the byte arrays backing the password and challenge. |
| | |
| | | */ |
| | | public DN getConfigurableComponentEntryDN() |
| | | { |
| | | assert debugEnter(CLASS_NAME, "getConfigurableComponentEntryDN"); |
| | | |
| | | return configEntryDN; |
| | | } |
| | |
| | | */ |
| | | public List<ConfigAttribute> getConfigurationAttributes() |
| | | { |
| | | assert debugEnter(CLASS_NAME, "getConfigurationAttributes"); |
| | | |
| | | |
| | | LinkedList<ConfigAttribute> attrList = new LinkedList<ConfigAttribute>(); |
| | |
| | | public boolean hasAcceptableConfiguration(ConfigEntry configEntry, |
| | | List<String> unacceptableReasons) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "hasAcceptableConfiguration", |
| | | String.valueOf(configEntry), "java.util.List<String>"); |
| | | |
| | | |
| | | // Look at the identity mapper configuration. |
| | |
| | | } |
| | | catch (Exception e) |
| | | { |
| | | assert debugException(CLASS_NAME, "hasAcceptableConfiguration", e); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, e); |
| | | } |
| | | |
| | | msgID = MSGID_SASLCRAMMD5_CANNOT_GET_IDENTITY_MAPPER; |
| | | unacceptableReasons.add(getMessage(msgID, String.valueOf(configEntryDN), |
| | |
| | | public ConfigChangeResult applyNewConfiguration(ConfigEntry configEntry, |
| | | boolean detailedResults) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "applyNewConfiguration", |
| | | String.valueOf(configEntry), |
| | | String.valueOf(detailedResults)); |
| | | |
| | | |
| | | ResultCode resultCode = ResultCode.SUCCESS; |
| | |
| | | } |
| | | catch (Exception e) |
| | | { |
| | | assert debugException(CLASS_NAME, "applyNewConfiguration", e); |
| | | if (debugEnabled()) |
| | | { |
| | | debugCought(DebugLogLevel.ERROR, e); |
| | | } |
| | | |
| | | msgID = MSGID_SASLCRAMMD5_CANNOT_GET_IDENTITY_MAPPER; |
| | | messages.add(getMessage(msgID, String.valueOf(configEntryDN), |
| | |
| | | @Override() |
| | | public boolean isPasswordBased(String mechanism) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "isPasswordBased", String.valueOf(mechanism)); |
| | | |
| | | // This is a password-based mechanism. |
| | | return true; |
| | |
| | | @Override() |
| | | public boolean isSecure(String mechanism) |
| | | { |
| | | assert debugEnter(CLASS_NAME, "isSecure", String.valueOf(mechanism)); |
| | | |
| | | // This may be considered a secure mechanism. |
| | | return true; |