diff -Naur cyrus-imapd-2.2.12/configure cyrus-imapd-2.2.12.oden/configure --- cyrus-imapd-2.2.12/configure 2005-02-14 18:59:46.000000000 +0100 +++ cyrus-imapd-2.2.12.oden/configure 2005-07-22 22:52:40.320275163 +0200 @@ -14395,7 +14395,7 @@ done IMAP_COM_ERR_LIBS="${COM_ERR_LIBS}" -IMAP_LIBS="${LIB_SASL} ${LIBS}" +IMAP_LIBS="${LIB_SASL} -lldap -llber ${LIBS}" diff -Naur cyrus-imapd-2.2.12/configure.in cyrus-imapd-2.2.12.oden/configure.in --- cyrus-imapd-2.2.12/configure.in 2005-01-19 00:46:00.000000000 +0100 +++ cyrus-imapd-2.2.12.oden/configure.in 2005-07-22 22:54:13.704431566 +0200 @@ -1015,7 +1015,7 @@ done IMAP_COM_ERR_LIBS="${COM_ERR_LIBS}" -IMAP_LIBS="${LIB_SASL} ${LIBS}" +IMAP_LIBS="${LIB_SASL} -lldap -llber ${LIBS}" AC_SUBST(LIB_RT) AC_SUBST(IMAP_COM_ERR_LIBS) diff -Naur cyrus-imapd-2.2.12/imap/global.c cyrus-imapd-2.2.12.oden/imap/global.c --- cyrus-imapd-2.2.12/imap/global.c 2004-11-23 18:40:15.000000000 +0100 +++ cyrus-imapd-2.2.12.oden/imap/global.c 2005-07-22 22:52:40.322275209 +0200 @@ -52,6 +52,9 @@ #include <netinet/in.h> #include <sys/stat.h> +#include <ldap.h> +#include <lber.h> + #if HAVE_UNISTD_H # include <unistd.h> #endif @@ -349,6 +352,18 @@ char *domain = NULL; int len = strlen(user); char buf[81]; + const char *uri; + const char *base; + const char *binddn; + const char *bindpw; + struct timeval timeout; + char filter[255]; + LDAP *handle; + LDAPMessage *res; + LDAPMessage *entry; + char ** vals; + + int rc; /* check for domain */ if (config_virtdomains && @@ -367,6 +382,47 @@ } if (config_virtdomains) { + if (config_virtdomains == IMAP_ENUM_VIRTDOMAINS_LDAP) { + uri = config_getstring(IMAPOPT_LDAP_URI); + base = config_getstring(IMAPOPT_LDAP_BASE); + binddn = config_getstring(IMAPOPT_LDAP_BIND_DN); + bindpw = config_getstring(IMAPOPT_LDAP_PASSWORD); + timeout.tv_sec = config_getint(IMAPOPT_LDAP_TIME_LIMIT); + timeout.tv_usec = 0; + sprintf(filter, "(uid=%s)", user); + rc = ldap_initialize(&handle, uri); + if (rc != LDAP_SUCCESS) { + syslog(LOG_ERR, "ldap_initialize failed (%s)", uri); + } else { + rc = ldap_simple_bind_s(handle, binddn, bindpw); + if (rc != LDAP_SUCCESS) { + syslog(LOG_ERR, "ldap_simple_bind() failed %d (%s)", rc, ldap_err2string(rc)); + } else { + rc = ldap_search_st(handle, base, LDAP_SCOPE_SUBTREE, filter, NULL, 0, &timeout, &res); + if (rc != LDAP_SUCCESS) { + syslog(LOG_ERR, "ldap_search_st failed %d (%s)", rc, ldap_err2string(rc)); + } else { + if ( (entry = ldap_first_entry(handle, res)) != NULL ) { + // read mail attribute from entry + if ( (vals = ldap_get_values(handle, entry, "mail")) ) { + if (strchr(vals[0], '@')) { + static char buf[81]; /* same size as in auth_canonifyid */ + strncpy( buf, vals[0], sizeof(buf) ); + buf[80] = '\0'; /* make sure it's null-terminated */ + ldap_value_free( vals ); + ldap_msgfree( res ); + ldap_unbind_s(handle); /* also frees handle */ + return auth_canonifyid( buf, 0) ; + } + ldap_value_free( vals ); + } + } + ldap_msgfree( res ); + } + } + ldap_unbind_s(handle); /* also frees handle */ + } + } if (domain) { if (config_defdomain && !strcasecmp(config_defdomain, domain+1)) { *domain = '\0'; /* trim the default domain */ @@ -379,7 +435,7 @@ user = buf; } } - else if (config_virtdomains != IMAP_ENUM_VIRTDOMAINS_USERID) { + else if (config_virtdomains != IMAP_ENUM_VIRTDOMAINS_USERID && config_virtdomains != IMAP_ENUM_VIRTDOMAINS_LDAP) { socklen_t salen; int error; struct sockaddr_storage localaddr; diff -Naur cyrus-imapd-2.2.12/lib/imapoptions cyrus-imapd-2.2.12.oden/lib/imapoptions --- cyrus-imapd-2.2.12/lib/imapoptions 2004-07-21 21:07:45.000000000 +0200 +++ cyrus-imapd-2.2.12.oden/lib/imapoptions 2005-07-22 22:52:40.323275232 +0200 @@ -839,7 +839,7 @@ mailbox hierarchy. The default is to use the netnews separator character '.'. */ -{ "virtdomains", "off", ENUM("off", "userid", "on") } +{ "virtdomains", "off", ENUM("off", "userid", "ldap", "on") } /* Enable virtual domain support. If enabled, the user's domain will be determined by splitting a fully qualified userid at the last '@' or '%' symbol. If the userid is unqualified, and the virtdomains