1
0
mirror of https://github.com/samba-team/samba.git synced 2024-12-22 13:34:15 +03:00
samba-mirror/source4/ldap_server
Andrew Bartlett 3507e96b3d CVE-2021-3670 ldap_server: Clearly log LDAP queries and timeouts
This puts all the detail on one line so it can be searched
by IP address and connecting SID.

This relies on the anr handling as otherwise this log
becomes the expanded query, not the original one.

RN: Provide clear logs of the LDAP search and who made it, including
a warning (at log level 3) for queries that are 1/4 of the hard timeout.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=14694

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz>

Autobuild-User(master): Douglas Bagnall <dbagnall@samba.org>
Autobuild-Date(master): Thu Nov 25 02:30:42 UTC 2021 on sn-devel-184
2021-11-25 02:30:42 +00:00
..
devdocs
ldap_backend.c CVE-2021-3670 ldap_server: Clearly log LDAP queries and timeouts 2021-11-25 02:30:42 +00:00
ldap_bind.c s4: rename source4/smbd/ to source4/samba/ 2020-11-27 10:07:18 +00:00
ldap_extended.c s4: rename source4/smbd/ to source4/samba/ 2020-11-27 10:07:18 +00:00
ldap_server.c CVE-2021-3670 ldap_server: Ensure value of MaxQueryDuration is greater than zero 2021-11-25 01:41:30 +00:00
ldap_server.h ldap_server: Terminate LDAP connections on krb ticket expiry 2020-08-21 19:14:32 +00:00
wscript_build ldap_server: Log access without a bind 2017-03-29 02:37:27 +02:00