Compare commits
12 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 90e0af59c3 | |||
| b7a6689b9b | |||
| ab597c221b | |||
| add02d2554 | |||
| a4adf1210a | |||
| cb9cf1ab36 | |||
| 17d41e4f61 | |||
| 558519f048 | |||
| 122f76c3f9 | |||
| 9f2ad13f6f | |||
| 5ea547c077 | |||
| 485f629a07 |
@@ -6,5 +6,5 @@ ldapPass here_lies_the_password
|
||||
# "domain" sera ajoute a relayName pour former le FQDN
|
||||
domain example.org
|
||||
# Le nom de l'attribut LDAP contenant le relais a retourner
|
||||
lapAttr relayName
|
||||
ldapAttr relayName
|
||||
|
||||
|
||||
+87
-37
@@ -10,6 +10,7 @@
|
||||
// Use a single LDAP connection protected by a mutex
|
||||
//
|
||||
// v0.9.6 : add PID file
|
||||
// v0.9.8 : Check MX format with regex
|
||||
//
|
||||
|
||||
package main
|
||||
@@ -21,8 +22,10 @@ import (
|
||||
"log/syslog"
|
||||
"net"
|
||||
"os"
|
||||
"regexp"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/go-ldap/ldap/v3"
|
||||
"github.com/peterbourgon/ff"
|
||||
@@ -30,7 +33,10 @@ import (
|
||||
)
|
||||
|
||||
const (
|
||||
version = "0.9.6"
|
||||
version = "0.9.9"
|
||||
// Match le nom de domaine, soit les 2 dernieres chaines separees par un point.
|
||||
// Peut aussi terminer par un point (Ex: srv.domaine.com. => domaine.com)
|
||||
DomainRegexpFormat = `([0-9A-Za-z\-]*)\.([0-9A-Za-z\-]*)(?:\.)?$`
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -46,14 +52,17 @@ var (
|
||||
ldapAttr *string
|
||||
defDomain *string
|
||||
pidFilePath *string
|
||||
timeout *int
|
||||
)
|
||||
|
||||
// attempt is useless now. It was introduced to break after N attempts, but this is not implemented. Should it be?
|
||||
func ldapSearch(searchReq *ldap.SearchRequest, attempt int) (*ldap.SearchResult, error) {
|
||||
mutex.Lock()
|
||||
result, err := conLdap.Search(searchReq)
|
||||
mutex.Unlock()
|
||||
// Let's just manage connection errors here
|
||||
if err != nil && strings.HasSuffix(err.Error(), "ldap: connection closed") {
|
||||
if err != nil {
|
||||
if strings.HasSuffix(err.Error(), "ldap: connection closed") {
|
||||
logstream.Err("LDAP connection closed, retrying")
|
||||
mutex.Lock()
|
||||
conLdap.Close()
|
||||
@@ -65,20 +74,63 @@ func ldapSearch(searchReq *ldap.SearchRequest, attempt int) (*ldap.SearchResult,
|
||||
attempt = attempt + 1
|
||||
return ldapSearch(searchReq, attempt)
|
||||
}
|
||||
} else if err == ldap.ErrNilConnection {
|
||||
logstream.Err("LDAP connection is nil, reconnecting")
|
||||
mutex.Lock()
|
||||
// conLdap is nil so this would be a sigsegv/panic
|
||||
//conLdap.Close()
|
||||
conLdap, err = connectLdap()
|
||||
mutex.Unlock()
|
||||
if err != nil {
|
||||
return result, err
|
||||
} else {
|
||||
attempt = attempt + 1
|
||||
return ldapSearch(searchReq, attempt)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return result, err
|
||||
}
|
||||
|
||||
func sendResponse(con net.Conn, respMsg string, respCode int) error {
|
||||
response := fmt.Sprintf("%d %s\n", respCode, strings.Replace(respMsg, " ", "%20", -1))
|
||||
_, err := con.Write([]byte(response))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func handleConnection(connClt net.Conn, conLdap *ldap.Conn) {
|
||||
var s string
|
||||
var mxdom string
|
||||
|
||||
buf := make([]byte, 1024)
|
||||
|
||||
defer connClt.Close()
|
||||
re := regexp.MustCompile(DomainRegexpFormat)
|
||||
|
||||
// Close connection when this function ends
|
||||
defer func() {
|
||||
logstream.Debug("Closing connection")
|
||||
connClt.Close()
|
||||
}()
|
||||
|
||||
timeoutDuration := time.Duration(*timeout) * time.Second
|
||||
|
||||
for {
|
||||
// Set a deadline for reading. Read operation will fail if no data
|
||||
// is received after deadline.
|
||||
connClt.SetReadDeadline(time.Now().Add(timeoutDuration))
|
||||
|
||||
readlen, err := connClt.Read(buf)
|
||||
if err != nil {
|
||||
fmt.Println("Error reading:", err.Error())
|
||||
// Dont notice if client closed connection
|
||||
if err.Error() != "EOF" && !strings.HasSuffix(err.Error(), "i/o timeout") {
|
||||
logstream.Err(fmt.Sprintln("Error reading connection :", err.Error()))
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// 1) Recupere le MX du domaine de l'adresse mail recue
|
||||
@@ -88,29 +140,29 @@ func handleConnection(connClt net.Conn, conLdap *ldap.Conn) {
|
||||
mxs, err := net.LookupMX(domain)
|
||||
if err != nil {
|
||||
logstream.Err(fmt.Sprintln("Error lookup mx: ", err))
|
||||
s := strings.Replace(fmt.Sprintf("Error lookup MX: %s", err.Error()), " ", "%20", -1)
|
||||
response := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(response))
|
||||
return
|
||||
s := fmt.Sprintf("Error lookup MX: %s", err.Error())
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
// 2) Requete LDAP pour voir si le domaine de second niveau du MX possede un routage particulier
|
||||
// Protection contre ca : example.org. 72 IN MX 0 .
|
||||
// Considerons qu'il n'y aura jamais de "one letter TLD"
|
||||
if len(mxs[0].Host) < 4 {
|
||||
logstream.Err(fmt.Sprintln("No usable mx found"))
|
||||
s := strings.Replace("No usable MX found", " ", "%20", -1)
|
||||
resp := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(resp))
|
||||
return
|
||||
s := "No usable MX found"
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
|
||||
mxslic := strings.Split(mxs[0].Host, ".")
|
||||
// les MXs terminent par '.', on le retire
|
||||
if mxs[0].Host[len(mxs[0].Host)-1] == '.' {
|
||||
mxdom = strings.Join(mxslic[len(mxslic)-3:len(mxslic)-1], ".")
|
||||
} else {
|
||||
mxdom = strings.Join(mxslic[len(mxslic)-2:len(mxslic)], ".")
|
||||
// On recuperer le nom de domaine de 1er niveau
|
||||
group := re.FindSubmatch([]byte(mxs[0].Host))
|
||||
if len(group) < 3 || len(group[2]) == 0 {
|
||||
logstream.Err(fmt.Sprintln("MX format incorrect: ", mxs[0].Host))
|
||||
s := fmt.Sprintf("MX format incorrect: %s", mxs[0].Host)
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
mxdom = string(group[1]) + "." + string(group[2])
|
||||
|
||||
filter := fmt.Sprintf("(dc=%s)", ldap.EscapeFilter(mxdom))
|
||||
searchReq := ldap.NewSearchRequest(*ldapBaseDN, ldap.ScopeWholeSubtree, 0, 0, 0,
|
||||
@@ -119,29 +171,26 @@ func handleConnection(connClt net.Conn, conLdap *ldap.Conn) {
|
||||
result, err := ldapSearch(searchReq, 0)
|
||||
if err != nil {
|
||||
logstream.Err(fmt.Sprintln("Error searching into LDAP: ", err))
|
||||
s := strings.Replace(err.Error(), " ", "%20", -1)
|
||||
response := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(response))
|
||||
return
|
||||
s := err.Error()
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
|
||||
if len(result.Entries) != 1 {
|
||||
if *debug {
|
||||
logstream.Debug("Got no result, returning 500")
|
||||
}
|
||||
s := strings.Replace("No route defined", " ", "%20", -1)
|
||||
response := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(response))
|
||||
return
|
||||
s := "No route defined"
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
|
||||
// L'attribut n'existe pas
|
||||
if len(result.Entries[0].Attributes) == 0 {
|
||||
logstream.Err(fmt.Sprintf("Error searching into LDAP: Attribute %s not found for entry %s\n", *ldapAttr, result.Entries[0]))
|
||||
s := strings.Replace(fmt.Sprintf("Attribute not found: %s", *ldapAttr), " ", "%20", -1)
|
||||
response := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(response))
|
||||
return
|
||||
s := fmt.Sprintf("Attribute not found: %s", *ldapAttr)
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
|
||||
if *debug {
|
||||
@@ -149,19 +198,19 @@ func handleConnection(connClt net.Conn, conLdap *ldap.Conn) {
|
||||
}
|
||||
// Check if result is a FQDN, if not append defDomain
|
||||
if strings.Contains(string(result.Entries[0].Attributes[0].Values[0]), ".") {
|
||||
s = strings.Replace(fmt.Sprintf("FILTER relay:[%s]", result.Entries[0].Attributes[0].Values[0]), " ", "%20", -1)
|
||||
s = fmt.Sprintf("FILTER relay:[%s]", result.Entries[0].Attributes[0].Values[0])
|
||||
} else {
|
||||
s = strings.Replace(fmt.Sprintf("FILTER relay:[%s]", fmt.Sprintf("%s.%s", result.Entries[0].Attributes[0].Values[0], *defDomain)), " ", "%20", -1)
|
||||
s = fmt.Sprintf("FILTER relay:[%s]", fmt.Sprintf("%s.%s", result.Entries[0].Attributes[0].Values[0], *defDomain))
|
||||
}
|
||||
connClt.Write([]byte(fmt.Sprintf("200 %s\n", s)))
|
||||
sendResponse(connClt, s, 200)
|
||||
} else {
|
||||
if *debug {
|
||||
logstream.Debug("Incorrect input format : " + string(buf[:readlen-1]))
|
||||
}
|
||||
s := strings.Replace("Incorrect input format", " ", "%20", -1)
|
||||
response := fmt.Sprintf("500 %s\n", s)
|
||||
connClt.Write([]byte(response))
|
||||
return
|
||||
s := "Incorrect input format"
|
||||
sendResponse(connClt, s, 500)
|
||||
continue
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -218,6 +267,7 @@ func main() {
|
||||
ldapAttr = fs.String("ldapAttr", "relayName", "LDAP attribute containing the relay name to return")
|
||||
defDomain = fs.String("domain", "", "Domain to add to relay name if not a FQDN (also via DOMAIN env var)")
|
||||
pidFilePath = fs.String("pidfile", "/var/run/mxrouter/mxrouter.pid", "PID File (also via PIDFILE env var)")
|
||||
timeout = fs.Int("timeout", 5, "timeout in seconds")
|
||||
_ = fs.String("config", "", "config file (optional)")
|
||||
|
||||
// Surcharge de la fonction Usage()
|
||||
|
||||
Reference in New Issue
Block a user