enable tls unless kerberos is used (SASL GSS-API doesn't seem to work over TLS)
This commit is contained in:
parent
46f54cb918
commit
a08154cff8
@ -21,7 +21,7 @@ def search(*, config: Config, arguments: Arguments) -> typing.Iterable[Result]:
|
||||
if not arguments.base:
|
||||
arguments.base = realm.default_base(gc=arguments.gc)
|
||||
|
||||
ldap_con = ldap.initialize(realm.ldap_uri(gc=arguments.gc, tls=False, server=arguments.server))
|
||||
ldap_con = ldap.initialize(realm.ldap_uri(gc=arguments.gc, tls=not arguments.krb, server=arguments.server))
|
||||
ldap_con.set_option(ldap.OPT_REFERRALS, 0)
|
||||
if arguments.krb:
|
||||
ldap_con.sasl_gssapi_bind_s()
|
||||
|
Loading…
Reference in New Issue
Block a user