@cryptotaxi247 / netdata-1 / commits / 1d304ecdc

Openldap tls support rebased (#5859)

* Added TLS connection support for openldap collector * More readable name for tls variable

Manolis Kartsonakis committed Apr 12, 2019 at 18:50 UTC 1d304ecdc34ce4ca42428992751055663403d095
2 files changed +15 -4
collectors/python.d.plugin/openldap/openldap.chart.py
+10 -1
@@ -14,6 +14,8 @@ from bases.FrameworkServices.SimpleService import SimpleService
14
15 DEFAULT_SERVER = 'localhost'
16 DEFAULT_PORT = '389'
17 +DEFAULT_TLS = False
18 +DEFAULT_CERT_CHECK = True
19 DEFAULT_TIMEOUT = 1
20
21 ORDER = [
@@ -139,6 +141,8 @@ class Service(SimpleService):
141 self.username = configuration.get('username')
142 self.password = configuration.get('password')
143 self.timeout = configuration.get('timeout', DEFAULT_TIMEOUT)
144 + self.use_tls = configuration.get('use_tls', DEFAULT_TLS)
145 + self.cert_check = configuration.get('cert_check', DEFAULT_CERT_CHECK)
146 self.alive = False
147 self.conn = None
148
@@ -150,8 +154,13 @@ class Service(SimpleService):
154
155 def connect(self):
156 try:
153 - self.conn = ldap.initialize('ldap://%s:%s' % (self.server, self.port))
157 + if self.use_tls:
158 + self.conn = ldap.initialize('ldaps://%s:%s' % (self.server, self.port))
159 + else:
160 + self.conn = ldap.initialize('ldap://%s:%s' % (self.server, self.port))
161 self.conn.set_option(ldap.OPT_NETWORK_TIMEOUT, self.timeout)
162 + if self.use_tls and not self.cert_check:
163 + self.conn.set_option(ldap.OPT_X_TLS_REQUIRE_CERT, ldap.OPT_X_TLS_NEVER)
164 if self.username and self.password:
165 self.conn.simple_bind(self.username, self.password)
166 except ldap.LDAPError as error:
collectors/python.d.plugin/openldap/openldap.conf
+5 -3
@@ -67,6 +67,8 @@ update_every: 10
67
68 #username : "cn=admin,dc=example,dc=com" # The bind user with right to access monitor statistics
69 #password : "yourpass" # The password for the binded user
70 -#server : 'localhost' # The listening address of the LDAP server
71 -#port : 389 # The listening port of the LDAP server
72 -#timeout : 1 # Seconds to timeout if no connection exists
\ No newline at end of file
70 +#server : 'localhost' # The listening address of the LDAP server. In case of TLS, use the hostname which the certificate is published for.
71 +#port : 389 # The listening port of the LDAP server. Change to 636 port in case of TLS connection
72 +#use_tls : False # Make True if a TLS connection is used
73 +#cert_check : True # False if you want to ignore certificate check
74 +#timeout : 1 # Seconds to timeout if no connection exi