phpman > perldoc > Net::LDAP::Control::ProxyAuth(3pm)

Markdown | JSON | MCP    

NAME
    Net::LDAP::Control::ProxyAuth - LDAPv3 Proxy Authorization control object

SYNOPSIS
     use Net::LDAP;
     use Net::LDAP::Control::ProxyAuth;

     $ldap = Net::LDAP->new( "ldap.mydomain.eg" );

     $auth = Net::LDAP::Control::ProxyAuth->new( authzID => 'dn:cn=me,ou=people,o=myorg.com' );

     @args = ( base     => "cn=subnets,cn=sites,cn=configuration,$BASE_DN",
               scope    => "subtree",
               filter   => "(objectClass=subnet)",
               callback => \&process_entry, # Call this sub for each entry
               control  => [ $auth ],
     );

     while (1) {
       # Perform search
       my $mesg = $ldap->search( @args );

       # Only continue on LDAP_SUCCESS
       $mesg->code and last;

     }

DESCRIPTION
    "Net::LDAP::Control::ProxyAuth" provides an interface for the creation and manipulation of
    objects that represent the "Proxy Authorization Control" as described by RFC 4370.

    It allows a client to be bound to an LDAP server with its own identity, but to perform
    operations on behalf of another user, the "authzID".

    With the exception of any extension that causes a change in authentication, authorization or
    data confidentiality, a single "Proxy Authorization Control" may be included in any search,
    compare, modify, add, delete, or moddn or extended operation.

    As required by the RFC, the criticality of this control is automatically set to TRUE in order to
    protect clients from submitting requests with other identities than they intend to.

CONSTRUCTOR ARGUMENTS
    In addition to the constructor arguments described in Net::LDAP::Control the following are
    provided.

    authzID
        The authzID that is required. This is the identity we are requesting operations to use.

    proxyDN
        In early versions of the drafts to RFC 4370, draft-weltman-ldapv3-proxy-XX.txt, the value in
        the control and thus the constructor argument was a DN and was called "proxyDN". It served
        the same purpose as "authzID" in recent versions of "proxyAuthorization" control.

    Please note: Unfortunately the OID and the encoding or the "Proxy Authorization Control" changed
    significantly between early versions of draft-weltman-ldapv3-proxy-XX.txt and the final RFC.
    Net::LDAP::Control::ProxyAuth tries to cope with that situation and changes the OID and encoding
    used depending on the constructor argument.

    With "proxyDN" as constructor argument the old OID and encoding are used, while with "authzID"
    as constructor argument the new OID and encoding are used. Using this logic servers supporting
    either OID can be handled correctly.

METHODS
    As with Net::LDAP::Control each constructor argument described above is also available as a
    method on the object which will return the current value for the attribute if called without an
    argument, and set a new value for the attribute if called with an argument.

SEE ALSO
    Net::LDAP, Net::LDAP::Control,

AUTHORS
    Olivier Dubois, Swift sa/nv based on Net::LDAP::Control::Page from Graham Barr
    <gbarr AT pobox.com>. Peter Marschall <peter AT adpm.de> added authzID extensions based on ideas from
    Graham Barr <gbarr AT pobox.com>.

    Please report any bugs, or post any suggestions, to the perl-ldap mailing list
    <perl-ldap AT perl.org>

COPYRIGHT
    Copyright (c) 2001-2004 Graham Barr. All rights reserved. This program is free software; you can
    redistribute it and/or modify it under the same terms as Perl itself.

Net::LDAP::Control::ProxyAuth(3pm)
NAME SYNOPSIS DESCRIPTION CONSTRUCTOR ARGUMENTS METHODS SEE ALSO AUTHORS COPYRIGHT

Generated by phpman v3.7.12 Author: Che Dong Under GNU General Public License
2026-06-13 21:10 @216.73.216.215
CrawledBy Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
Valid XHTML 1.0 TransitionalValid CSS!

^_back to top