2019-12-11 12:16:37 -08:00
|
|
|
// Package ldap provides a simple ldap client to authenticate,
|
|
|
|
// retrieve basic information and groups for a user.
|
2019-08-15 09:34:54 -07:00
|
|
|
package api
|
|
|
|
|
|
|
|
import (
|
|
|
|
"crypto/tls"
|
|
|
|
"crypto/x509"
|
|
|
|
"fmt"
|
2021-12-13 19:23:31 +00:00
|
|
|
"sync"
|
|
|
|
"time"
|
2019-12-11 12:16:37 -08:00
|
|
|
|
|
|
|
"github.com/go-ldap/ldap/v3"
|
2022-10-20 19:39:20 +03:00
|
|
|
|
2024-02-01 06:34:07 +02:00
|
|
|
"zotregistry.dev/zot/errors"
|
|
|
|
"zotregistry.dev/zot/pkg/log"
|
2019-08-15 09:34:54 -07:00
|
|
|
)
|
|
|
|
|
|
|
|
type LDAPClient struct {
|
2019-12-11 12:16:37 -08:00
|
|
|
InsecureSkipVerify bool
|
|
|
|
UseSSL bool
|
|
|
|
SkipTLS bool
|
|
|
|
SubtreeSearch bool
|
|
|
|
Port int
|
|
|
|
Attributes []string
|
|
|
|
Base string
|
|
|
|
BindDN string
|
|
|
|
BindPassword string
|
|
|
|
GroupFilter string // e.g. "(memberUid=%s)"
|
2023-03-08 21:47:15 +02:00
|
|
|
UserGroupAttribute string // e.g. "memberOf"
|
2019-12-11 12:16:37 -08:00
|
|
|
Host string
|
|
|
|
ServerName string
|
|
|
|
UserFilter string // e.g. "(uid=%s)"
|
|
|
|
Conn *ldap.Conn
|
|
|
|
ClientCertificates []tls.Certificate // Adding client certificates
|
|
|
|
ClientCAs *x509.CertPool
|
|
|
|
Log log.Logger
|
2021-09-18 00:00:59 +00:00
|
|
|
lock sync.Mutex
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// Connect connects to the ldap backend.
|
|
|
|
func (lc *LDAPClient) Connect() error {
|
|
|
|
if lc.Conn == nil {
|
2021-12-13 19:23:31 +00:00
|
|
|
var l *ldap.Conn
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
var err error
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
address := fmt.Sprintf("%s:%d", lc.Host, lc.Port)
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
if !lc.UseSSL {
|
2024-04-09 00:40:16 -07:00
|
|
|
l, err = ldap.Dial("tcp", address) //nolint:staticcheck
|
2019-08-15 09:34:54 -07:00
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("address", address).Msg("failed to establish a TCP connection")
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Reconnect with TLS
|
|
|
|
if !lc.SkipTLS {
|
|
|
|
config := &tls.Config{
|
2022-10-05 13:21:14 +03:00
|
|
|
InsecureSkipVerify: lc.InsecureSkipVerify, //nolint: gosec // InsecureSkipVerify is not true by default
|
2019-12-11 12:16:37 -08:00
|
|
|
RootCAs: lc.ClientCAs,
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
if lc.ClientCertificates != nil && len(lc.ClientCertificates) > 0 {
|
|
|
|
config.Certificates = lc.ClientCertificates
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
err = l.StartTLS(config)
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("address", address).Msg("failed to establish a TLS connection")
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
config := &tls.Config{
|
2022-10-05 13:21:14 +03:00
|
|
|
InsecureSkipVerify: lc.InsecureSkipVerify, //nolint: gosec // InsecureSkipVerify is not true by default
|
2019-08-15 09:34:54 -07:00
|
|
|
ServerName: lc.ServerName,
|
2019-12-11 12:16:37 -08:00
|
|
|
RootCAs: lc.ClientCAs,
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
if lc.ClientCertificates != nil && len(lc.ClientCertificates) > 0 {
|
|
|
|
config.Certificates = lc.ClientCertificates
|
2022-10-05 13:21:14 +03:00
|
|
|
// config.BuildNameToCertificate()
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
2024-04-09 00:40:16 -07:00
|
|
|
l, err = ldap.DialTLS("tcp", address, config) //nolint:staticcheck
|
2019-08-15 09:34:54 -07:00
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("address", address).Msg("failed to establish a TLS connection")
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
lc.Conn = l
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-12-11 12:16:37 -08:00
|
|
|
// Close closes the ldap backend connection.
|
|
|
|
func (lc *LDAPClient) Close() {
|
|
|
|
if lc.Conn != nil {
|
|
|
|
lc.Conn.Close()
|
|
|
|
lc.Conn = nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
const maxRetries = 8
|
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
func sleepAndRetry(retries, maxRetries int) bool {
|
|
|
|
if retries > maxRetries {
|
|
|
|
return false
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
if retries < maxRetries {
|
|
|
|
time.Sleep(time.Duration(retries) * time.Second) // gradually backoff
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
return true
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
// Authenticate authenticates the user against the ldap backend.
|
2023-03-08 21:47:15 +02:00
|
|
|
func (lc *LDAPClient) Authenticate(username, password string) (bool, map[string]string, []string, error) {
|
2021-09-18 00:00:59 +00:00
|
|
|
// serialize LDAP calls since some LDAP servers don't allow searches when binds are in flight
|
|
|
|
lc.lock.Lock()
|
|
|
|
defer lc.lock.Unlock()
|
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
if password == "" {
|
|
|
|
// RFC 4513 section 5.1.2
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, nil, nil, errors.ErrLDAPEmptyPassphrase
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
connected := false
|
|
|
|
for retries := 0; !connected && sleepAndRetry(retries, maxRetries); retries++ {
|
|
|
|
err := lc.Connect()
|
2019-08-15 09:34:54 -07:00
|
|
|
if err != nil {
|
2019-11-18 11:28:52 -08:00
|
|
|
continue
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
2019-11-18 11:28:52 -08:00
|
|
|
|
|
|
|
// First bind with a read only user
|
2023-11-15 02:21:36 +02:00
|
|
|
if lc.BindPassword != "" {
|
2019-11-18 11:28:52 -08:00
|
|
|
err := lc.Conn.Bind(lc.BindDN, lc.BindPassword)
|
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", lc.BindDN).Msg("failed to bind")
|
2019-11-18 11:28:52 -08:00
|
|
|
// clean up the cached conn, so we can retry
|
|
|
|
lc.Conn.Close()
|
|
|
|
lc.Conn = nil
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2023-11-15 02:21:36 +02:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
err := lc.Conn.UnauthenticatedBind(lc.BindDN)
|
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", lc.BindDN).Msg("failed to bind")
|
2023-11-15 02:21:36 +02:00
|
|
|
// clean up the cached conn, so we can retry
|
|
|
|
lc.Conn.Close()
|
|
|
|
lc.Conn = nil
|
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-11-18 11:28:52 -08:00
|
|
|
connected = true
|
|
|
|
}
|
|
|
|
|
|
|
|
// exhausted all retries?
|
|
|
|
if !connected {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(errors.ErrLDAPBadConn).Msg("failed to authenticate, exhausted all retries")
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, nil, nil, errors.ErrLDAPBadConn
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
attributes := lc.Attributes
|
2024-01-12 14:08:35 -08:00
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
attributes = append(attributes, "dn")
|
2024-01-12 14:08:35 -08:00
|
|
|
if lc.UserGroupAttribute != "" {
|
|
|
|
attributes = append(attributes, lc.UserGroupAttribute)
|
|
|
|
}
|
2023-03-08 21:47:15 +02:00
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
searchScope := ldap.ScopeSingleLevel
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-12-11 12:16:37 -08:00
|
|
|
if lc.SubtreeSearch {
|
2021-12-13 19:23:31 +00:00
|
|
|
searchScope = ldap.ScopeWholeSubtree
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
// Search for the given username
|
2021-12-13 19:23:31 +00:00
|
|
|
searchRequest := ldap.NewSearchRequest(
|
2019-08-15 09:34:54 -07:00
|
|
|
lc.Base,
|
2021-12-13 19:23:31 +00:00
|
|
|
searchScope, ldap.NeverDerefAliases, 0, 0, false,
|
2019-08-15 09:34:54 -07:00
|
|
|
fmt.Sprintf(lc.UserFilter, username),
|
|
|
|
attributes,
|
|
|
|
nil,
|
|
|
|
)
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
search, err := lc.Conn.Search(searchRequest)
|
2019-08-15 09:34:54 -07:00
|
|
|
if err != nil {
|
|
|
|
fmt.Printf("%v\n", err)
|
2019-12-11 12:16:37 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", lc.BindDN).Str("username", username).
|
2023-12-08 00:05:02 -08:00
|
|
|
Str("baseDN", lc.Base).Msg("failed to perform a search request")
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, nil, nil, err
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
if len(search.Entries) < 1 {
|
2019-08-15 09:34:54 -07:00
|
|
|
err := errors.ErrBadUser
|
2019-12-11 12:16:37 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", lc.BindDN).Str("username", username).
|
2023-12-08 00:05:02 -08:00
|
|
|
Str("baseDN", lc.Base).Msg("failed to find entry")
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, nil, nil, err
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
if len(search.Entries) > 1 {
|
2019-08-15 09:34:54 -07:00
|
|
|
err := errors.ErrEntriesExceeded
|
2019-12-11 12:16:37 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", lc.BindDN).Str("username", username).
|
2023-12-08 00:05:02 -08:00
|
|
|
Str("baseDN", lc.Base).Msg("failed to retrieve due to an excessive amount of entries")
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, nil, nil, err
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
userDN := search.Entries[0].DN
|
2024-01-12 14:08:35 -08:00
|
|
|
|
|
|
|
var userGroups []string
|
|
|
|
|
|
|
|
if lc.UserGroupAttribute != "" && len(search.Entries[0].Attributes) > 0 {
|
|
|
|
userAttributes := search.Entries[0].Attributes[0]
|
|
|
|
userGroups = userAttributes.Values
|
|
|
|
}
|
2019-08-15 09:34:54 -07:00
|
|
|
user := map[string]string{}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
for _, attr := range lc.Attributes {
|
2021-12-13 19:23:31 +00:00
|
|
|
user[attr] = search.Entries[0].GetAttributeValue(attr)
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// Bind as the user to verify their password
|
|
|
|
err = lc.Conn.Bind(userDN, password)
|
|
|
|
if err != nil {
|
2023-12-08 00:05:02 -08:00
|
|
|
lc.Log.Error().Err(err).Str("bindDN", userDN).Msg("failed to bind user")
|
2021-12-13 19:23:31 +00:00
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return false, user, userGroups, err
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2023-03-08 21:47:15 +02:00
|
|
|
return true, user, userGroups, nil
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|