1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
//! A pure-Rust LDAP client library using the Tokio stack.
//!
//! ## Usage
//!
//! In `Cargo.toml`:
//!
//! ```toml
//! [dependencies.ldap3]
//! version = "0.12.1"
//! ```
//!
//! ## Summary
//!
//! The library provides both synchronous and asynchronous interfaces. The [`LdapConn`](struct.LdapConn.html)
//! structure is the starting point for all synchronous operations. [`LdapConnAsync`](struct.LdapConnAsync.html)
//! is its asynchronous analogue, and [`Ldap`](struct.Ldap.html) is the low-level asynchronous handle used
//! internally by `LdapConn`, and explicitly by the users of the asynchronous interface.
//!
//! In the [struct list](#structs), async-related structs have an asterisk (__*__) after
//! the short description.
//!
//! The documentation is written for readers familiar with LDAP concepts and terminology,
//! which it won't attempt to explain. If you need an introductory text, you can try the
//! [primer](https://github.com/inejge/ldap3/blob/27a247c8a6e4e2c86f664f4280c4c6499f0e9fe5/LDAP-primer.md)
//! included in this library.
//!
//! ## Compile-time features
//!
//! The following features are available at compile time:
//!
//! * __sync__ (enabled by default): Synchronous API support.
//!
//! * __gssapi__ (disabled by default): Kerberos/GSSAPI support. On Windows, system support
//! crates and SDK libraries are used. Elsewhere, the feature needs Clang and its development
//! libraries (for `bindgen`), as well as the Kerberos development libraries. On Debian/Ubuntu,
//! that means `clang-N`, `libclang-N-dev` and `libkrb5-dev`. It should be clear from these
//! requirements that GSSAPI support uses FFI to C libraries; you should consider the security
//! implications of this fact.
//!
//! For usage notes and caveats, see the documentation for
//! [`Ldap::sasl_gssapi_bind()`](struct.Ldap.html#method.sasl_gssapi_bind).
//!
//! * __ntlm__ (disabled by default): NTLM authentication support. Username and password must
//! be provided, and the password must be in cleartext. It works on TLS connections, or clear
//! connections with no signing or sealing. With TLS, a channel binding token is sent to the
//! server if possible. See [`Ldap::sasl_ntlm_bind()`](struct.Ldap.html#method.sasl_ntlm_bind).
//!
//! * __tls__ (enabled by default): TLS support, backed by the `native-tls` crate, which uses
//! a platform-specific TLS backend. This is an alias for __tls-native__.
//!
//! * __tls-rustls-...__ (disabled by default): TLS support, backed by the Rustls library. The
//! bare __tls-rustls__ flag, used previously for this purpose, won't work by itself; one
//! must choose the crypto provider for Rustls. There are two predefined flags for this
//! purpose, __tls-rustls-aws-lc-rs__ and __tls-rustls-ring__. If another provider is
//! needed, it can be chosen by activating the corresponding feature in Rustls and setting
//! the flags __tls-rustls__ and __rustls-provider__. For example the AWS FIPS provider can
//! be chosen with:
//!
//! ... `--features tls-rustls,rustls/fips,rustls-provider`
//!
//! Not selecting a provider, or selecting one without specifying __rustls-provider__, will
//! produce a compile-time error.
//!
//! Without any features, only plain TCP connections (and Unix domain sockets on Unix-like
//! platforms) are available. For TLS support, __tls__ and __tls-rustls__ are mutually
//! exclusive: choosing both will produce a compile-time error.
//!
//! ## Examples
//!
//! The following two examples perform exactly the same operation and should produce identical
//! results. They should be run against the example server in the `data` subdirectory of the crate source.
//! Other sample programs expecting the same server setup can be found in the `examples` subdirectory.
//!
//! ### Synchronous search
//!
//! ```rust,no_run
//! use ldap3::{LdapConn, Scope, SearchEntry};
//! use ldap3::result::Result;
//!
//! fn main() -> Result<()> {
//! let mut ldap = LdapConn::new("ldap://localhost:2389")?;
//! let (rs, _res) = ldap.search(
//! "ou=Places,dc=example,dc=org",
//! Scope::Subtree,
//! "(&(objectClass=locality)(l=ma*))",
//! vec!["l"]
//! )?.success()?;
//! for entry in rs {
//! println!("{:?}", SearchEntry::construct(entry));
//! }
//! Ok(ldap.unbind()?)
//! }
//! ```
//!
//! ### Asynchronous search
//!
//! ```rust,no_run
//! use ldap3::{LdapConnAsync, Scope, SearchEntry};
//! use ldap3::result::Result;
//!
//! #[tokio::main]
//! async fn main() -> Result<()> {
//! let (conn, mut ldap) = LdapConnAsync::new("ldap://localhost:2389").await?;
//! ldap3::drive!(conn);
//! let (rs, _res) = ldap.search(
//! "ou=Places,dc=example,dc=org",
//! Scope::Subtree,
//! "(&(objectClass=locality)(l=ma*))",
//! vec!["l"]
//! ).await?.success()?;
//! for entry in rs {
//! println!("{:?}", SearchEntry::construct(entry));
//! }
//! Ok(ldap.unbind().await?)
//! }
//! ```
pub extern crate log;
pub use tokio;
/// Type alias for the LDAP message ID.
pub type RequestId = i32;
pub use ;
pub use parse as parse_filter;
pub use ;
pub use ;
pub use parse_refs;
pub use ;
pub use ;
pub use ;