mirror of
git://git.gnupg.org/gnupg.git
synced 2025-07-02 22:46:30 +02:00
dirmngr: Support new gpgNtds parameter in LDAP keyserver URLs.
* dirmngr/ldap-parse-uri.c (ldap_parse_uri): Support a new gpgNtds
extension.
* dirmngr/ks-engine-ldap.c (my_ldap_connect): Do ldap_init always with
hostname - which is NULL and thus the same if not given. Fix minor
error in error code handling.
--
Note that "gpgNtds" is per RFC-4512 case insensitive and has not yet
been officially regisetered. Thus for correctness the OID can be
used:
1.3.6.1.4.1.11591.2.5 LDAP URL extensions
1.3.6.1.4.1.11591.2.5.1 gpgNtds=1 (auth. with current user)
Note that the value must be 1; all other values won't enable AD
authentication and are resevered for future use.
This has been cherry-picked from the 2.2 branch,
commit 55f46b33df
Signed-off-by: Werner Koch <wk@gnupg.org>
This commit is contained in:
parent
3fa1fa747b
commit
ab7dc4b524
5 changed files with 40 additions and 22 deletions
|
@ -332,6 +332,8 @@ built-in default of @code{hkps://hkps.pool.sks-keyservers.net}.
|
|||
|
||||
Windows users with a keyserver running on their Active Directory
|
||||
should use @code{ldap:///} for @var{name} to access this directory.
|
||||
As an alternative it is also possible to add @code{gpgNtds=1} as
|
||||
extension (i.e. after the fourth question mark).
|
||||
|
||||
For accessing anonymous LDAP keyservers @var{name} is in general just
|
||||
a @code{ldaps://ldap.example.com}. A BaseDN parameter should never be
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue