pub async fn ldap_auth(options: &Options) -> Result<Ldap, Box<dyn Error>>Expand description
Connect to the Domain Controller and authenticate, returning a ready
ldap3::Ldap session. The method is chosen from options:
- certificate :
pfxorcrt/keypresent (Pass-the-Certificate) - pass-the-hash:
hashespresent (NTLM) - Kerberos :
kerberos == true(ccache from KRB5CCNAME) - simple bind : otherwise (
username/password)
Certificate auth uses LDAP 389 + StartTLS by default, or LDAPS 636 with
options.ldaps. Returns Err on failure (no process::exit), and never
unbinds — the caller owns the returned session.