From: Francis Cianfrocca Date: 2007-03-12T08:31:37+09:00 Subject: Re: NET::LDAP Problems..... ------=_Part_16199_6367555.1173655896005 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 3/11/07, ara.t.howard@noaa.gov wrote: > > > perhaps exporting the information on the cause of exit codes. eg: > > # > # determining reason for exit code == 49 > # > if @ldap.get_operation_result.code == 49 > Net::LDAP.open(:host => @ldap.host, > :port => @ldap.port, > :auth => @auth) do |conn| > @entry = conn.search(:base => @account_base, > :filter => "uid=#{ uid }", > :attributes => ["userpassword"]) > if test_sha_password(pw, @entry[0].userpassword[0]) > retval = [false, "Password good, but expired."] > else > retval = [false, "Invalid credentials, please try again."] > end > end > end > > i think this information is exported by the ldap server right? There are standard response codes in the RFC, most of which have corresponding strings in Net::LDAP, but I've always found LDAP servers to be remarkably inconsistent with the responses they send in different situations. I'm pretty sure there are methods in Net::LDAP now that access these strings. If they're not good enough, let me know or suggest a patch. Someone long ago requested support for LDAP controls, which are needed to access special features of some directories (like IBM's TDS). This is a good idea but I haven't gotten around to it and no else asked. Any need for this feature among whoever is reading this thread? I wrote a Ruby-scriptable LDAP server based on the Net::LDAP protocol implementation and have used it for special purpose attribute servers, directory aggregators, etc. Works quite well. If there is enough interest in this, I can publish it as well. ------=_Part_16199_6367555.1173655896005--