aboutsummaryrefslogtreecommitdiff
path: root/handlers/ldap.in
blob: 600f1723e0ad64c48b1448845853c837ae3e272a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
# -*- mode: sh; sh-basic-offset: 3; indent-tabs-mode: nil; -*-
# vim: set filetype=sh sw=3 sts=3 expandtab autoindent:
#
# openldap backup handler script for backupninja
#

getconf backupdir /var/backups/ldap
getconf conf /etc/ldap/slapd.conf
getconf databases all
getconf compress yes
getconf ldif yes
getconf restart no
getconf method ldapsearch
getconf passwordfile
getconf binddn
getconf ldaphost
getconf ssl yes
getconf tls no

if [ $ssl = 'yes' ]; then
   URLBASE="ldaps"
else
   URLBASE="ldap"
fi

status="ok"

[ -f $conf ] || fatal "slapd config file ($conf) not found"
[ -d $backupdir ] || mkdir -p $backupdir
[ -d $backupdir ] || fatal "Backup directory '$backupdir'"

dbsuffixes=(`@AWK@ 'BEGIN {OFS=":"} /[:space:]*^database[:space:]*\w*/ {db=$2}; /^[:space:]*suffix[:space:]*\w*/ {if (db=="bdb"||db=="hdb"||db="ldbm") print db,$2}' $conf|@SED@ -e 's/[" ]//g'`)

## LDIF DUMP

if [ "$ldif" == "yes" ]; then
   dumpdir="$backupdir"
   [ -d $dumpdir ] || mkdir -p $dumpdir

   if [ "$databases" == 'all' ]; then
      dbcount=`grep '^database' $conf | wc -l`
      let "dbcount = dbcount - 1"
      databases=`seq 0 $dbcount`;
   fi

   for db in $databases; do
      if [ `expr index "$db" "="` == "0" ]; then
                        # db is a number, get the suffix.
         dbsuffix=${dbsuffixes[$db]/*:/}
      else
         dbsuffix=$db
      fi
                # some databases don't have suffix (like monitor), skip these
      if [ "$dbsuffix" == "" ]; then
         continue;
      fi

      if [ "$method" == "slapcat" ]; then
         execstr="$SLAPCAT -f $conf -b $dbsuffix"
      else
         LDAPARGS=""
         if [ "$tls" == "yes" ]; then
            LDAPARGS="-ZZ"
         fi
         if [ -n "$ldaphost" ]; then
            execstr="$LDAPSEARCH $LDAPARGS -H $URLBASE://$ldaphost -x -L -b ""$dbsuffix"" -D ""$binddn"" -y $passwordfile"
         else
            execstr="$LDAPSEARCH -H $URLBASE://$ldaphost -x -L -b ""$dbsuffix"" -D ""$binddn"" -y $passwordfile"
         fi
         [ -f "$passwordfile" ] || fatal "Password file $passwordfile not found. When method is set to ldapsearch, you must also specify a password file."
         debug "$execstr"
      fi
      if [ ! $test ]; then
         if [ "$restart" == "yes" ]; then
            debug "Shutting down ldap server..."
            /etc/init.d/slapd stop
         fi

         ext=
         if [ "$compress" == "yes" ]; then
            ext=".gz"
         fi
         touch $dumpdir/$dbsuffix.ldif$ext
         if [ ! -f $dumpdir/$dbsuffix.ldif$ext ]; then
            fatal "Couldn't create ldif dump file: $dumpdir/$dbsuffix.ldif$ext"
         fi

         if [ "$compress" == "yes" ]; then
            execstr="$execstr | $GZIP $GZIP_OPTS > $dumpdir/$dbsuffix.ldif.gz"
         else
            execstr="$execstr > $dumpdir/$dbsuffix.ldif"
         fi
         debug "$execstr"
         output=`su root -s /bin/bash -c "set -o pipefail ; $execstr" 2>&1`
         code=$?
         if [ "$code" == "0" ]; then
            debug $output
            info "Successfully finished ldif export of $dbsuffix"
         else
            warning $output
            warning "Failed ldif export of $dbsuffix"
         fi

         if [ "$restart" == "yes" ]; then
            debug "Starting ldap server..."
            /etc/init.d/slapd start
         fi
      fi
   done
fi

return 0