aboutsummaryrefslogtreecommitdiffstats
path: root/src/lib/sos/plugins/ldap.py
blob: 59ab53fc85ed41972daf5f924fea29d4a0315199 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
### This program is free software; you can redistribute it and/or modify
## it under the terms of the GNU General Public License as published by
## the Free Software Foundation; either version 2 of the License, or
## (at your option) any later version.

## This program is distributed in the hope that it will be useful,
## but WITHOUT ANY WARRANTY; without even the implied warranty of
## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
## GNU General Public License for more details.

## You should have received a copy of the GNU General Public License
## along with this program; if not, write to the Free Software
## Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.

import sos.plugintools
import os

class ldap(sos.plugintools.PluginBase):
    """LDAP related information
    """
    def get_ldap_opts(self):
        # capture /etc/openldap/ldap.conf options in dict
        # FIXME: possibly not hardcode these options in?
        ldapopts=["URI","BASE","TLS_CACERTDIR"]
        results={}
        tmplist=[]
        for i in ldapopts:
            t=self.doRegexFindAll(r"^(%s)\s+(.*)" % i,"/etc/openldap/ldap.conf")
            for x in t:
                results[x[0]]=x[1].rstrip("\n")
        return results

    def get_slapd_debug(self):
        """ Capture debugging information based on an existing log level
        """
        loglevel=self.doRegexFindAll(r"^local4.*\s+(\/var.*)", "/etc/syslog.conf")
        for i in loglevel:
            return i

    def diagnose(self):
        # Validate ldap client options
        ldapopts=self.get_ldap_opts()
        try:
            os.stat(ldapopts["TLS_CACERTDIR"])
        except:
            self.addDiagnose("%s does not exist and can cause connection issues "+
                             "involving TLS" % ldapopts["TLS_CACERTDIR"])

    def setup(self):
        self.addCopySpec("/etc/ldap.conf")
        self.addCopySpec("/etc/openldap")
        self.addCopySpec(self.get_slapd_debug())
        return

    def postproc(self):
        self.doRegexSub("/etc/ldap.conf", r"(\s*bindpw\s*)\S+", r"\1***")
        return