Openldap tls support rebased (#5859)
* Added TLS connection support for openldap collector * More readable name for tls variable
Manolis Kartsonakis committed
Apr 12, 2019 at 18:50 UTC
1d304ecdc34ce4ca42428992751055663403d095
2 files changed
+15
-4
collectors/python.d.plugin/openldap/openldap.chart.py
+10
-1
@@ -14,6 +14,8 @@ from bases.FrameworkServices.SimpleService import SimpleService
14
15
DEFAULT_SERVER = 'localhost'
16
DEFAULT_PORT = '389'
17
+DEFAULT_TLS = False
18
+DEFAULT_CERT_CHECK = True
19
DEFAULT_TIMEOUT = 1
20
21
ORDER = [
@@ -139,6 +141,8 @@ class Service(SimpleService):
141
self.username = configuration.get('username')
142
self.password = configuration.get('password')
143
self.timeout = configuration.get('timeout', DEFAULT_TIMEOUT)
144
+ self.use_tls = configuration.get('use_tls', DEFAULT_TLS)
145
+ self.cert_check = configuration.get('cert_check', DEFAULT_CERT_CHECK)
146
self.alive = False
147
self.conn = None
148
@@ -150,8 +154,13 @@ class Service(SimpleService):
154
155
def connect(self):
156
try:
153
- self.conn = ldap.initialize('ldap://%s:%s' % (self.server, self.port))
157
+ if self.use_tls:
158
+ self.conn = ldap.initialize('ldaps://%s:%s' % (self.server, self.port))
159
+ else:
160
+ self.conn = ldap.initialize('ldap://%s:%s' % (self.server, self.port))
161
self.conn.set_option(ldap.OPT_NETWORK_TIMEOUT, self.timeout)
162
+ if self.use_tls and not self.cert_check:
163
+ self.conn.set_option(ldap.OPT_X_TLS_REQUIRE_CERT, ldap.OPT_X_TLS_NEVER)
164
if self.username and self.password:
165
self.conn.simple_bind(self.username, self.password)
166
except ldap.LDAPError as error:
collectors/python.d.plugin/openldap/openldap.conf
+5
-3
@@ -67,6 +67,8 @@ update_every: 10
67
68
#username : "cn=admin,dc=example,dc=com" # The bind user with right to access monitor statistics
69
#password : "yourpass" # The password for the binded user
70
-#server : 'localhost' # The listening address of the LDAP server
71
-#port : 389 # The listening port of the LDAP server
72
-#timeout : 1 # Seconds to timeout if no connection exists
\ No newline at end of file
70
+#server : 'localhost' # The listening address of the LDAP server. In case of TLS, use the hostname which the certificate is published for.
71
+#port : 389 # The listening port of the LDAP server. Change to 636 port in case of TLS connection
72
+#use_tls : False # Make True if a TLS connection is used
73
+#cert_check : True # False if you want to ignore certificate check
74
+#timeout : 1 # Seconds to timeout if no connection exi