IP*Works! Auth V9 - Online Help
IP*Works! Auth V9
Questions / Feedback?

LDAP Class

Properties   Methods   Events   Configuration Settings   Errors  

The LDAP Component is used to search, manage, and maintain Internet Directory (LDAP) servers.

Class Name

IPWorksAuth_LDAP

Procedural Interface

 ipworksauth_ldap_open();
 ipworksauth_ldap_close($res);
 ipworksauth_ldap_register_callback($res, $id, $function);
 ipworksauth_ldap_get_last_error($res);
 ipworksauth_ldap_get_last_error_code($res);
 ipworksauth_ldap_set($res, $id, $index, $value);
 ipworksauth_ldap_get($res, $id, $index);
 ipworksauth_ldap_do_abandon($res, $messageid);
 ipworksauth_ldap_do_add($res);
 ipworksauth_ldap_do_attr($res, $attrtype);
 ipworksauth_ldap_do_bind($res);
 ipworksauth_ldap_do_compare($res);
 ipworksauth_ldap_do_config($res, $configurationstring);
 ipworksauth_ldap_do_delete($res);
 ipworksauth_ldap_do_doevents($res);
 ipworksauth_ldap_do_extendedrequest($res, $requestname, $requestvalue);
 ipworksauth_ldap_do_interrupt($res);
 ipworksauth_ldap_do_modify($res);
 ipworksauth_ldap_do_modifyrdn($res, $newrdn);
 ipworksauth_ldap_do_movetodn($res, $newsuperior);
 ipworksauth_ldap_do_search($res, $searchfilter);
 ipworksauth_ldap_do_unbind($res);

Remarks

The LDAP Class is the SSL-enabled equivalent of the IP*Works! LDAP class. The main difference is the introduction of a set of new configuration settings, properties and events that deal with SSL security. The SSLEnabledProtocols and SSLCipherStrength configuration settings determine which protocols are enabled and at what security level. The SSLCert property is used to select a client certificate if the server is requesting client authentication. The SSLSecurityFlags configuration setting, together with the SSLServerAuthentication event allow you to check the server identity and other security attributes. Finally, the SSLStatus event provides information about the SSL handshake.

The LDAP Class implements a standard LDAP client as specified in RFC 1777, 2251, and other LDAP RFCs. Support for both LDAP v2 and v3 is provided.

The first step in using the class is specifying the ServerName, a DN (Distinguished Name) to bind as, and optionally a Password. Then you can call one or more of the class methods to act upon the server. Server responses are normally received through the Result event. The only exceptions are search requests which result in one or more SearchResult events, followed by a final SearchComplete event.

Attributes are set and returned through the Attributes properties. Other command arguments are specified through other properties. These are specified in detail in each method.

Search filters are to be specified as string arguments to the Search method. The format must be a standard LDAP search string as specified in RFC 1558. Other search attributes are set in properties such as SearchScope, SearchTimeLimit, SearchSizeLimit, SearchReturnValues, and SearchDerefAliases.

The class operates synchronously by default (waits for a response before returning control to the caller), however, the class may also operate asynchronously (return control immediately), by setting Timeout to 0. Please refer to the Timeout property for more information.

Property List


The following is the full list of the properties of the class with short descriptions. Click on the links for further details.

AcceptDataEnables or disables data reception from the server.
AttrCountThe number of records in the Attr arrays.
AttrTypeAttribute type for the current entry.
AttrModOpAn operation to apply on attributes during an LDAP modify operation.
AttrValueAttribute value for the current entry.
AuthMechanismThe authentication mechanism to be used when connecting to the LDAP server.
ConnectedShows whether the component is connected.
DeleteOldRDNControls whether the old RDN (Relative Distinguished Name) should be deleted.
DNThe Distinguished Name used as the base for LDAP operations.
FirewallAutoDetectThis property tells the component whether or not to automatically detect and use firewall system settings, if available.
FirewallTypeThis property determines the type of firewall to connect through.
FirewallHostThis property contains the name or IP address of firewall (optional).
FirewallPasswordThis property contains a password if authentication is to be used when connecting through the firewall.
FirewallPortThis property contains the TCP port for the firewall Host .
FirewallUserThis property contains a user name if authentication is to be used connecting through a firewall.
IdleThe current status of the component.
LDAPVersionThe version of LDAP used.
LocalHostThe name of the local host or user-assigned IP interface through which connections are initiated or accepted.
MessageIdThe message identifier for the next LDAP request.
PageSizeThe maximum number of results per page for the Search method.
PasswordThe password used to authenticate to the LDAP server.
ReferenceCountThe number of records in the Reference arrays.
ReferenceURLThe url of the LDAP reference.
ResultCodeThe result code returned in the last server response.
ResultDescriptionThe descriptive text returned in the last server response (if any).
ResultDNThe Distinguished Name returned in the last server response (if any).
SearchDerefAliasesControls alias dereferencing during searching.
SearchReturnValuesControls whether the search operation returns values of attributes, or only types.
SearchScopeControls the scope of LDAP search operations.
SearchSizeLimitMaximum number of entries that can be returned by the next search operation.
SearchTimeLimitA time limit for the next search operation (in seconds).
ServerNameThe name or address of the LDAP server.
ServerPortThe server port for the LDAP connection (default is 636).
SortAttributesA string of attribute names to sort on with optional relative matching rules.
SSLAcceptServerCertEncodedThe certificate (PEM/base64 encoded).
SSLCertEncodedThe certificate (PEM/base64 encoded).
SSLCertStoreThe name of the certificate store for the client certificate.
SSLCertStorePasswordIf the certificate store is of a type that requires a password, this property is used to specify that password in order to open the certificate store.
SSLCertStoreTypeThe type of certificate store for this certificate.
SSLCertSubjectThe subject of the certificate used for client authentication.
SSLServerCertEncodedThe certificate (PEM/base64 encoded).
SSLStartModeDetermines how the component starts the SSL negotiation.
TimeoutA timeout for the component.

Method List


The following is the full list of the methods of the class with short descriptions. Click on the links for further details.

AbandonAsks the server to abandon a request.
AddAdds an entry specified by DN to the directory server using the type and value attributes defined in the Attributes properties.
AttrReturns the value of the specified LDAP attribute.
BindConnects and binds to the directory server.
CompareCompares attributes and values with those of the entry specified by DN .
ConfigSets or retrieves a configuration setting .
DeleteDeletes an entry specified by DN from the directory server.
DoEventsProcesses events from the internal message queue.
ExtendedRequestPerforms an LDAP V3 Extended Operation.
InterruptInterrupt the current method.
ModifyPerforms an LDAP 'modify' operation on the entry specified by DN .
ModifyRDNPerforms an LDAP 'modify RDN' operation an entry specified by DN .
MoveToDNPerforms an LDAP 'modify' operation on the entry specified by DN by changing its superior.
SearchSearches the directory server using the base object specified in DN and the search filter SearchFilter .
UnbindUnbinds from the directory server.

Event List


The following is the full list of the events fired by the class with short descriptions. Click on the links for further details.

ConnectedFired immediately after a connection completes (or fails).
ConnectionStatusFired to indicate changes in connection state.
DisconnectedFired when a connection is closed.
ErrorInformation about errors during data delivery.
ExtendedResponseFired for LDAP V3 Extended Responses.
ResultFired for every server response, except search responses.
SearchCompleteFired upon completion of a search operation.
SearchPageFired for every page returned from a search operation.
SearchResultFired for every entry returned from a search operation.
SearchResultReferenceFired for every result reference returned from a search operation.
SSLServerAuthenticationFired after the server presents its certificate to the client.
SSLStatusShows the progress of the secure connection.

Configuration Settings


The following is a list of configuration settings for the class with short descriptions. Click on the links for further details.

FriendlyGUIDWhether to return GUID attribute values in a human readable format.
FriendlySIDWhether to return SID attribute values in a human readable format.
RequestControlsControls to include in the request.
ResponseControlsControls present in the response.
SingleResultModeDetermines how ResultDN behaves.
UseDefaultDCWhether to connect to the default Domain Controller when calling Bind.
DomainControllerReturns the name of the domain controller.
ConnectionTimeoutSets a separate timeout value for establishing a connection.
FirewallAutoDetectTells the component whether or not to automatically detect and use firewall system settings, if available.
FirewallHostName or IP address of firewall (optional).
FirewallPasswordPassword to be used if authentication is to be used when connecting through the firewall.
FirewallPortThe TCP port for the FirewallHost;.
FirewallTypeDetermines the type of firewall to connect through.
FirewallUserA user name if authentication is to be used connecting through a firewall.
KeepAliveTimeThe inactivity time in milliseconds before a TCP keep-alive packet is sent.
KeepAliveIntervalThe retry interval, in milliseconds, to be used when a TCP keep-alive packet is sent and no response is received.
LingerWhen set to True, connections are terminated gracefully.
LingerTimeTime in seconds to have the connection linger.
LocalHostThe name of the local host through which connections are initiated or accepted.
LocalPortThe TCP port in the local host where the component binds.
MaxLineLengthThe maximum amount of data to accumulate when no EOL is found.
MaxTransferRateThe transfer rate limit in bytes per second.
RecordLengthThe length of received data records.
TCPKeepAliveDetermines whether or not the keep alive socket option is enabled.
UseIPv6Whether to use IPv6.
TcpNoDelayWhether or not to delay when sending packets.
ReuseSSLSessionDetermines if the SSL session is reused.
SSLCipherStrengthThe minimum cipher strength used for bulk encryption.
SSLEnabledProtocolsUsed to enable/disable the supported security protocols.
SSLProviderThe name of the security provider to use.
SSLSecurityFlagsFlags that control certificate verification.
OpenSSLCADirThe path to a directory containing CA certificates.
OpenSSLCAFileName of the file containing the list of CA's trusted by your application.
OpenSSLCipherListA string that controls the ciphers to be used by SSL.
OpenSSLPrngSeedDataThe data to seed the pseudo random number generator (PRNG).
AbsoluteTimeoutDetermines whether timeouts are inactivity timeouts or absolute timeouts.
FirewallDataUsed to send extra data to the firewall.
InBufferSizeThe size in bytes of the incoming queue of the socket.
OutBufferSizeThe size in bytes of the outgoing queue of the socket.
CodePageThe system code page used for Unicode to Multibyte translations.

 
 
Copyright (c) 2017 /n software inc. - All rights reserved.
Build 9.0.6240.0