package ftp; # $Id$

use Net::FTP;

use network::network;
use log;

my %hosts;

1;

sub fromEnv() {
    #- now URLPREFIX is generated from what is given by mdk-stage1 which is only this 4 variables.
    $ENV{URLPREFIX} = "ftp://" . ($ENV{LOGIN} && ($ENV{LOGIN} . ($ENV{PASSWORD} && ":$ENV{PASSWORD}") . '@')) .
      "$ENV{HOST}/$ENV{PREFIX}";
    @ENV{qw(HOST PREFIX LOGIN PASSWORD)};
}

sub new {
    my ($host, $prefix, $o_login, $o_password) = @_;
    my @l = do { if ($hosts{"$host$prefix"}) {
	@{$hosts{"$host$prefix"}};
    } else {
	my %options = (Passive => 1, Timeout => 60, Port => 21);
	$options{Firewall} = $ENV{PROXY} if $ENV{PROXY};
	$options{Port} = $ENV{PROXYPORT} if $ENV{PROXYPORT};
	unless ($o_login) {
	    $o_login = 'anonymous';
	    $o_password = '-drakx@';
	}

	my $ftp;
	foreach (1..10) {
	    $ftp = Net::FTP->new(resolv($host), %options) or die "Can't resolve hostname '$host'\n";
	    $ftp && $ftp->login($o_login, $o_password) and last;

	    log::l("ftp login failed, sleeping before trying again");
	    sleep 5 * $_;
	}
	$ftp or die "unable to open ftp connection to $host\n";
	$ftp->binary;
	$ftp->cwd($prefix);

	my @l = ($ftp, \ (my $_retr));
	$hosts{"$host$prefix"} = \@l;
	@l;
    } };
    wantarray() ? @l : $l[0];
}

sub getFile {
    my ($f, @para) = @_;
    $f eq 'XXX' and rewindGetFile(), return; #- special case to force closing connection.
    foreach (1..3) {
	my ($ftp, $retr) = new(@para ? @para : fromEnv());
	eval { $$retr->close if $$retr };
	$@ and rewindGetFile(); #- in case Timeout got us on "->close"
	$$retr = $ftp->retr($f) and return $$retr;
	$ftp->code == 550 and log::l("FTP: 550 file unavailable"), return;
	rewindGetFile();
	log::l("ftp get failed, sleeping before trying again");
	sleep 1;
    }
}

#-sub closeFiles() {
#-    #- close any existing connections
#-    foreach (values %hosts) {
#-	  my $retr = $_->[1] if ref $_;
#-	  $$retr->close if $$retr;
#-	  undef $$retr;
#-    }
#-}

sub rewindGetFile() {
    #- close any existing connection.
    foreach (values %hosts) {
	my ($ftp, $retr) = @{$_ || []};
	#- do not let Timeout kill us!
	eval { $$retr->close } if $$retr;
	eval { $ftp->close } if $ftp;
    }

    #- make sure to reconnect to server.
    %hosts = ();
}
ate'>topic/MDK-10_2-update</option>
<option value='topic/MDK-2006_0-update'>topic/MDK-2006_0-update</option>
<option value='topic/MDK92-branch'>topic/MDK92-branch</option>
<option value='topic/MDKC_1_0'>topic/MDKC_1_0</option>
<option value='topic/PCMCIA_CS_DISTRO'>topic/PCMCIA_CS_DISTRO</option>
<option value='topic/R9_0-64bit-branch'>topic/R9_0-64bit-branch</option>
<option value='topic/R9_1_HP-branch'>topic/R9_1_HP-branch</option>
<option value='topic/a'>topic/a</option>
<option value='topic/before_matchbox_wm'>topic/before_matchbox_wm</option>
<option value='topic/bug-13680'>topic/bug-13680</option>
<option value='topic/dietlibc'>topic/dietlibc</option>
<option value='topic/efi'>topic/efi</option>
<option value='topic/extlinux'>topic/extlinux</option>
<option value='topic/firewall'>topic/firewall</option>
<option value='topic/gdk-pixbuf-0-branch'>topic/gdk-pixbuf-0-branch</option>
<option value='topic/gi-ppc'>topic/gi-ppc</option>
<option value='topic/ia64-8_1'>topic/ia64-8_1</option>
<option value='topic/mandrakesoft'>topic/mandrakesoft</option>
<option value='topic/mlcd4'>topic/mlcd4</option>
<option value='topic/ppp'>topic/ppp</option>
<option value='topic/rp-pppoe'>topic/rp-pppoe</option>
<option value='topic/switching_to_dnf'>topic/switching_to_dnf</option>
<option value='topic/switching_to_urpmi'>topic/switching_to_urpmi</option>
<option value='topic/unlabeled-1.1.1'>topic/unlabeled-1.1.1</option>
<option value='topic/v_webmin_0_87'>topic/v_webmin_0_87</option>
<option value='topic/x86_64-branch'>topic/x86_64-branch</option>
<option value='user/animtim/designWork'>user/animtim/designWork</option>
<option value='user/colin/rescue-systemd'>user/colin/rescue-systemd</option>
<option value='user/ennael/mga6'>user/ennael/mga6</option>
<option value='user/erwan/bug-13680'>user/erwan/bug-13680</option>
<option value='user/jibz/aarch64'>user/jibz/aarch64</option>
<option value='user/martinw/mga6'>user/martinw/mga6</option>
<option value='user/pterjan/arm64'>user/pterjan/arm64</option>
</select> <input type='submit' value='switch'/></form></td></tr>
<tr><td class='sub'>Mageia Installer and base platform for many utilities</td><td class='sub right'>Thierry Vignaud [tv]</td></tr></table>
<table class='tabs'><tr><td>
<a href='/software/drakx/?h=17.38'>summary</a><a href='/software/drakx/refs/?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>refs</a><a href='/software/drakx/log/perl-install/authentication.pm?h=17.38'>log</a><a class='active' href='/software/drakx/tree/perl-install/authentication.pm?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>tree</a><a href='/software/drakx/commit/perl-install/authentication.pm?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>commit</a><a href='/software/drakx/diff/perl-install/authentication.pm?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>diff</a><a href='/software/drakx/stats/perl-install/authentication.pm?h=17.38'>stats</a></td><td class='form'><form class='right' method='get' action='/software/drakx/log/perl-install/authentication.pm'>
<input type='hidden' name='h' value='17.38'/><input type='hidden' name='id' value='b8e72d60ea9da2b65565fc89fd8d8622d2f34340'/><select name='qt'>
<option value='grep'>log msg</option>
<option value='author'>author</option>
<option value='committer'>committer</option>
<option value='range'>range</option>
</select>
<input class='txt' type='search' size='10' name='q' value=''/>
<input type='submit' value='search'/>
</form>
</td></tr></table>
<div class='path'>path: <a href='/software/drakx/tree/?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>root</a>/<a href='/software/drakx/tree/perl-install?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>perl-install</a>/<a href='/software/drakx/tree/perl-install/authentication.pm?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>authentication.pm</a></div><div class='content'>blob: e4dc90125566c7e36ef28009ac06920330742bcc (<a href='/software/drakx/plain/perl-install/authentication.pm?h=17.38&amp;id=b8e72d60ea9da2b65565fc89fd8d8622d2f34340'>plain</a>)
<table summary='blob content' class='blob'>
<tr><td class='linenumbers'><pre><a id='n1' href='#n1'>1</a>
<a id='n2' href='#n2'>2</a>
<a id='n3' href='#n3'>3</a>
<a id='n4' href='#n4'>4</a>
<a id='n5' href='#n5'>5</a>
<a id='n6' href='#n6'>6</a>
<a id='n7' href='#n7'>7</a>
<a id='n8' href='#n8'>8</a>
<a id='n9' href='#n9'>9</a>
<a id='n10' href='#n10'>10</a>
<a id='n11' href='#n11'>11</a>
<a id='n12' href='#n12'>12</a>
<a id='n13' href='#n13'>13</a>
<a id='n14' href='#n14'>14</a>
<a id='n15' href='#n15'>15</a>
<a id='n16' href='#n16'>16</a>
<a id='n17' href='#n17'>17</a>
<a id='n18' href='#n18'>18</a>
<a id='n19' href='#n19'>19</a>
<a id='n20' href='#n20'>20</a>
<a id='n21' href='#n21'>21</a>
<a id='n22' href='#n22'>22</a>
<a id='n23' href='#n23'>23</a>
<a id='n24' href='#n24'>24</a>
<a id='n25' href='#n25'>25</a>
<a id='n26' href='#n26'>26</a>
<a id='n27' href='#n27'>27</a>
<a id='n28' href='#n28'>28</a>
<a id='n29' href='#n29'>29</a>
<a id='n30' href='#n30'>30</a>
<a id='n31' href='#n31'>31</a>
<a id='n32' href='#n32'>32</a>
<a id='n33' href='#n33'>33</a>
<a id='n34' href='#n34'>34</a>
<a id='n35' href='#n35'>35</a>
<a id='n36' href='#n36'>36</a>
<a id='n37' href='#n37'>37</a>
<a id='n38' href='#n38'>38</a>
<a id='n39' href='#n39'>39</a>
<a id='n40' href='#n40'>40</a>
<a id='n41' href='#n41'>41</a>
<a id='n42' href='#n42'>42</a>
<a id='n43' href='#n43'>43</a>
<a id='n44' href='#n44'>44</a>
<a id='n45' href='#n45'>45</a>
<a id='n46' href='#n46'>46</a>
<a id='n47' href='#n47'>47</a>
<a id='n48' href='#n48'>48</a>
<a id='n49' href='#n49'>49</a>
<a id='n50' href='#n50'>50</a>
<a id='n51' href='#n51'>51</a>
<a id='n52' href='#n52'>52</a>
<a id='n53' href='#n53'>53</a>
<a id='n54' href='#n54'>54</a>
<a id='n55' href='#n55'>55</a>
<a id='n56' href='#n56'>56</a>
<a id='n57' href='#n57'>57</a>
<a id='n58' href='#n58'>58</a>
<a id='n59' href='#n59'>59</a>
<a id='n60' href='#n60'>60</a>
<a id='n61' href='#n61'>61</a>
<a id='n62' href='#n62'>62</a>
<a id='n63' href='#n63'>63</a>
<a id='n64' href='#n64'>64</a>
<a id='n65' href='#n65'>65</a>
<a id='n66' href='#n66'>66</a>
<a id='n67' href='#n67'>67</a>
<a id='n68' href='#n68'>68</a>
<a id='n69' href='#n69'>69</a>
<a id='n70' href='#n70'>70</a>
<a id='n71' href='#n71'>71</a>
<a id='n72' href='#n72'>72</a>
<a id='n73' href='#n73'>73</a>
<a id='n74' href='#n74'>74</a>
<a id='n75' href='#n75'>75</a>
<a id='n76' href='#n76'>76</a>
<a id='n77' href='#n77'>77</a>
<a id='n78' href='#n78'>78</a>
<a id='n79' href='#n79'>79</a>
<a id='n80' href='#n80'>80</a>
<a id='n81' href='#n81'>81</a>
<a id='n82' href='#n82'>82</a>
<a id='n83' href='#n83'>83</a>
<a id='n84' href='#n84'>84</a>
<a id='n85' href='#n85'>85</a>
<a id='n86' href='#n86'>86</a>
<a id='n87' href='#n87'>87</a>
<a id='n88' href='#n88'>88</a>
<a id='n89' href='#n89'>89</a>
<a id='n90' href='#n90'>90</a>
<a id='n91' href='#n91'>91</a>
<a id='n92' href='#n92'>92</a>
<a id='n93' href='#n93'>93</a>
<a id='n94' href='#n94'>94</a>
<a id='n95' href='#n95'>95</a>
<a id='n96' href='#n96'>96</a>
<a id='n97' href='#n97'>97</a>
<a id='n98' href='#n98'>98</a>
<a id='n99' href='#n99'>99</a>
<a id='n100' href='#n100'>100</a>
<a id='n101' href='#n101'>101</a>
<a id='n102' href='#n102'>102</a>
<a id='n103' href='#n103'>103</a>
<a id='n104' href='#n104'>104</a>
<a id='n105' href='#n105'>105</a>
<a id='n106' href='#n106'>106</a>
<a id='n107' href='#n107'>107</a>
<a id='n108' href='#n108'>108</a>
<a id='n109' href='#n109'>109</a>
<a id='n110' href='#n110'>110</a>
<a id='n111' href='#n111'>111</a>
<a id='n112' href='#n112'>112</a>
<a id='n113' href='#n113'>113</a>
<a id='n114' href='#n114'>114</a>
<a id='n115' href='#n115'>115</a>
<a id='n116' href='#n116'>116</a>
<a id='n117' href='#n117'>117</a>
<a id='n118' href='#n118'>118</a>
<a id='n119' href='#n119'>119</a>
<a id='n120' href='#n120'>120</a>
<a id='n121' href='#n121'>121</a>
<a id='n122' href='#n122'>122</a>
<a id='n123' href='#n123'>123</a>
<a id='n124' href='#n124'>124</a>
<a id='n125' href='#n125'>125</a>
<a id='n126' href='#n126'>126</a>
<a id='n127' href='#n127'>127</a>
<a id='n128' href='#n128'>128</a>
<a id='n129' href='#n129'>129</a>
<a id='n130' href='#n130'>130</a>
<a id='n131' href='#n131'>131</a>
<a id='n132' href='#n132'>132</a>
<a id='n133' href='#n133'>133</a>
<a id='n134' href='#n134'>134</a>
<a id='n135' href='#n135'>135</a>
<a id='n136' href='#n136'>136</a>
<a id='n137' href='#n137'>137</a>
<a id='n138' href='#n138'>138</a>
<a id='n139' href='#n139'>139</a>
<a id='n140' href='#n140'>140</a>
<a id='n141' href='#n141'>141</a>
<a id='n142' href='#n142'>142</a>
<a id='n143' href='#n143'>143</a>
<a id='n144' href='#n144'>144</a>
<a id='n145' href='#n145'>145</a>
<a id='n146' href='#n146'>146</a>
<a id='n147' href='#n147'>147</a>
<a id='n148' href='#n148'>148</a>
<a id='n149' href='#n149'>149</a>
<a id='n150' href='#n150'>150</a>
<a id='n151' href='#n151'>151</a>
<a id='n152' href='#n152'>152</a>
<a id='n153' href='#n153'>153</a>
<a id='n154' href='#n154'>154</a>
<a id='n155' href='#n155'>155</a>
<a id='n156' href='#n156'>156</a>
<a id='n157' href='#n157'>157</a>
<a id='n158' href='#n158'>158</a>
<a id='n159' href='#n159'>159</a>
<a id='n160' href='#n160'>160</a>
<a id='n161' href='#n161'>161</a>
<a id='n162' href='#n162'>162</a>
<a id='n163' href='#n163'>163</a>
<a id='n164' href='#n164'>164</a>
<a id='n165' href='#n165'>165</a>
<a id='n166' href='#n166'>166</a>
<a id='n167' href='#n167'>167</a>
<a id='n168' href='#n168'>168</a>
<a id='n169' href='#n169'>169</a>
<a id='n170' href='#n170'>170</a>
<a id='n171' href='#n171'>171</a>
<a id='n172' href='#n172'>172</a>
<a id='n173' href='#n173'>173</a>
<a id='n174' href='#n174'>174</a>
<a id='n175' href='#n175'>175</a>
<a id='n176' href='#n176'>176</a>
<a id='n177' href='#n177'>177</a>
<a id='n178' href='#n178'>178</a>
<a id='n179' href='#n179'>179</a>
<a id='n180' href='#n180'>180</a>
<a id='n181' href='#n181'>181</a>
<a id='n182' href='#n182'>182</a>
<a id='n183' href='#n183'>183</a>
<a id='n184' href='#n184'>184</a>
<a id='n185' href='#n185'>185</a>
<a id='n186' href='#n186'>186</a>
<a id='n187' href='#n187'>187</a>
<a id='n188' href='#n188'>188</a>
<a id='n189' href='#n189'>189</a>
<a id='n190' href='#n190'>190</a>
<a id='n191' href='#n191'>191</a>
<a id='n192' href='#n192'>192</a>
<a id='n193' href='#n193'>193</a>
<a id='n194' href='#n194'>194</a>
<a id='n195' href='#n195'>195</a>
<a id='n196' href='#n196'>196</a>
<a id='n197' href='#n197'>197</a>
<a id='n198' href='#n198'>198</a>
<a id='n199' href='#n199'>199</a>
<a id='n200' href='#n200'>200</a>
<a id='n201' href='#n201'>201</a>
<a id='n202' href='#n202'>202</a>
<a id='n203' href='#n203'>203</a>
<a id='n204' href='#n204'>204</a>
<a id='n205' href='#n205'>205</a>
<a id='n206' href='#n206'>206</a>
<a id='n207' href='#n207'>207</a>
<a id='n208' href='#n208'>208</a>
<a id='n209' href='#n209'>209</a>
<a id='n210' href='#n210'>210</a>
<a id='n211' href='#n211'>211</a>
<a id='n212' href='#n212'>212</a>
<a id='n213' href='#n213'>213</a>
<a id='n214' href='#n214'>214</a>
<a id='n215' href='#n215'>215</a>
<a id='n216' href='#n216'>216</a>
<a id='n217' href='#n217'>217</a>
<a id='n218' href='#n218'>218</a>
<a id='n219' href='#n219'>219</a>
<a id='n220' href='#n220'>220</a>
<a id='n221' href='#n221'>221</a>
<a id='n222' href='#n222'>222</a>
<a id='n223' href='#n223'>223</a>
<a id='n224' href='#n224'>224</a>
<a id='n225' href='#n225'>225</a>
<a id='n226' href='#n226'>226</a>
<a id='n227' href='#n227'>227</a>
<a id='n228' href='#n228'>228</a>
<a id='n229' href='#n229'>229</a>
<a id='n230' href='#n230'>230</a>
<a id='n231' href='#n231'>231</a>
<a id='n232' href='#n232'>232</a>
<a id='n233' href='#n233'>233</a>
<a id='n234' href='#n234'>234</a>
<a id='n235' href='#n235'>235</a>
<a id='n236' href='#n236'>236</a>
<a id='n237' href='#n237'>237</a>
<a id='n238' href='#n238'>238</a>
<a id='n239' href='#n239'>239</a>
<a id='n240' href='#n240'>240</a>
<a id='n241' href='#n241'>241</a>
<a id='n242' href='#n242'>242</a>
<a id='n243' href='#n243'>243</a>
<a id='n244' href='#n244'>244</a>
<a id='n245' href='#n245'>245</a>
<a id='n246' href='#n246'>246</a>
<a id='n247' href='#n247'>247</a>
<a id='n248' href='#n248'>248</a>
<a id='n249' href='#n249'>249</a>
<a id='n250' href='#n250'>250</a>
<a id='n251' href='#n251'>251</a>
<a id='n252' href='#n252'>252</a>
<a id='n253' href='#n253'>253</a>
<a id='n254' href='#n254'>254</a>
<a id='n255' href='#n255'>255</a>
<a id='n256' href='#n256'>256</a>
<a id='n257' href='#n257'>257</a>
<a id='n258' href='#n258'>258</a>
<a id='n259' href='#n259'>259</a>
<a id='n260' href='#n260'>260</a>
<a id='n261' href='#n261'>261</a>
<a id='n262' href='#n262'>262</a>
<a id='n263' href='#n263'>263</a>
<a id='n264' href='#n264'>264</a>
<a id='n265' href='#n265'>265</a>
<a id='n266' href='#n266'>266</a>
<a id='n267' href='#n267'>267</a>
<a id='n268' href='#n268'>268</a>
<a id='n269' href='#n269'>269</a>
<a id='n270' href='#n270'>270</a>
<a id='n271' href='#n271'>271</a>
<a id='n272' href='#n272'>272</a>
<a id='n273' href='#n273'>273</a>
<a id='n274' href='#n274'>274</a>
<a id='n275' href='#n275'>275</a>
<a id='n276' href='#n276'>276</a>
<a id='n277' href='#n277'>277</a>
<a id='n278' href='#n278'>278</a>
<a id='n279' href='#n279'>279</a>
<a id='n280' href='#n280'>280</a>
<a id='n281' href='#n281'>281</a>
<a id='n282' href='#n282'>282</a>
<a id='n283' href='#n283'>283</a>
<a id='n284' href='#n284'>284</a>
<a id='n285' href='#n285'>285</a>
<a id='n286' href='#n286'>286</a>
<a id='n287' href='#n287'>287</a>
<a id='n288' href='#n288'>288</a>
<a id='n289' href='#n289'>289</a>
<a id='n290' href='#n290'>290</a>
<a id='n291' href='#n291'>291</a>
<a id='n292' href='#n292'>292</a>
<a id='n293' href='#n293'>293</a>
<a id='n294' href='#n294'>294</a>
<a id='n295' href='#n295'>295</a>
<a id='n296' href='#n296'>296</a>
<a id='n297' href='#n297'>297</a>
<a id='n298' href='#n298'>298</a>
<a id='n299' href='#n299'>299</a>
<a id='n300' href='#n300'>300</a>
<a id='n301' href='#n301'>301</a>
<a id='n302' href='#n302'>302</a>
<a id='n303' href='#n303'>303</a>
<a id='n304' href='#n304'>304</a>
<a id='n305' href='#n305'>305</a>
<a id='n306' href='#n306'>306</a>
<a id='n307' href='#n307'>307</a>
<a id='n308' href='#n308'>308</a>
<a id='n309' href='#n309'>309</a>
<a id='n310' href='#n310'>310</a>
<a id='n311' href='#n311'>311</a>
<a id='n312' href='#n312'>312</a>
<a id='n313' href='#n313'>313</a>
<a id='n314' href='#n314'>314</a>
<a id='n315' href='#n315'>315</a>
<a id='n316' href='#n316'>316</a>
<a id='n317' href='#n317'>317</a>
<a id='n318' href='#n318'>318</a>
<a id='n319' href='#n319'>319</a>
<a id='n320' href='#n320'>320</a>
<a id='n321' href='#n321'>321</a>
<a id='n322' href='#n322'>322</a>
<a id='n323' href='#n323'>323</a>
<a id='n324' href='#n324'>324</a>
<a id='n325' href='#n325'>325</a>
<a id='n326' href='#n326'>326</a>
<a id='n327' href='#n327'>327</a>
<a id='n328' href='#n328'>328</a>
<a id='n329' href='#n329'>329</a>
<a id='n330' href='#n330'>330</a>
<a id='n331' href='#n331'>331</a>
<a id='n332' href='#n332'>332</a>
<a id='n333' href='#n333'>333</a>
<a id='n334' href='#n334'>334</a>
<a id='n335' href='#n335'>335</a>
<a id='n336' href='#n336'>336</a>
<a id='n337' href='#n337'>337</a>
<a id='n338' href='#n338'>338</a>
<a id='n339' href='#n339'>339</a>
<a id='n340' href='#n340'>340</a>
<a id='n341' href='#n341'>341</a>
<a id='n342' href='#n342'>342</a>
<a id='n343' href='#n343'>343</a>
<a id='n344' href='#n344'>344</a>
<a id='n345' href='#n345'>345</a>
<a id='n346' href='#n346'>346</a>
<a id='n347' href='#n347'>347</a>
<a id='n348' href='#n348'>348</a>
<a id='n349' href='#n349'>349</a>
<a id='n350' href='#n350'>350</a>
<a id='n351' href='#n351'>351</a>
<a id='n352' href='#n352'>352</a>
<a id='n353' href='#n353'>353</a>
<a id='n354' href='#n354'>354</a>
<a id='n355' href='#n355'>355</a>
<a id='n356' href='#n356'>356</a>
<a id='n357' href='#n357'>357</a>
<a id='n358' href='#n358'>358</a>
<a id='n359' href='#n359'>359</a>
<a id='n360' href='#n360'>360</a>
<a id='n361' href='#n361'>361</a>
<a id='n362' href='#n362'>362</a>
<a id='n363' href='#n363'>363</a>
<a id='n364' href='#n364'>364</a>
<a id='n365' href='#n365'>365</a>
<a id='n366' href='#n366'>366</a>
<a id='n367' href='#n367'>367</a>
<a id='n368' href='#n368'>368</a>
<a id='n369' href='#n369'>369</a>
<a id='n370' href='#n370'>370</a>
<a id='n371' href='#n371'>371</a>
<a id='n372' href='#n372'>372</a>
<a id='n373' href='#n373'>373</a>
<a id='n374' href='#n374'>374</a>
<a id='n375' href='#n375'>375</a>
<a id='n376' href='#n376'>376</a>
<a id='n377' href='#n377'>377</a>
<a id='n378' href='#n378'>378</a>
<a id='n379' href='#n379'>379</a>
<a id='n380' href='#n380'>380</a>
<a id='n381' href='#n381'>381</a>
<a id='n382' href='#n382'>382</a>
<a id='n383' href='#n383'>383</a>
<a id='n384' href='#n384'>384</a>
<a id='n385' href='#n385'>385</a>
<a id='n386' href='#n386'>386</a>
<a id='n387' href='#n387'>387</a>
<a id='n388' href='#n388'>388</a>
<a id='n389' href='#n389'>389</a>
<a id='n390' href='#n390'>390</a>
<a id='n391' href='#n391'>391</a>
<a id='n392' href='#n392'>392</a>
<a id='n393' href='#n393'>393</a>
<a id='n394' href='#n394'>394</a>
<a id='n395' href='#n395'>395</a>
<a id='n396' href='#n396'>396</a>
<a id='n397' href='#n397'>397</a>
<a id='n398' href='#n398'>398</a>
<a id='n399' href='#n399'>399</a>
<a id='n400' href='#n400'>400</a>
<a id='n401' href='#n401'>401</a>
<a id='n402' href='#n402'>402</a>
<a id='n403' href='#n403'>403</a>
<a id='n404' href='#n404'>404</a>
<a id='n405' href='#n405'>405</a>
<a id='n406' href='#n406'>406</a>
<a id='n407' href='#n407'>407</a>
<a id='n408' href='#n408'>408</a>
<a id='n409' href='#n409'>409</a>
<a id='n410' href='#n410'>410</a>
<a id='n411' href='#n411'>411</a>
<a id='n412' href='#n412'>412</a>
<a id='n413' href='#n413'>413</a>
<a id='n414' href='#n414'>414</a>
<a id='n415' href='#n415'>415</a>
<a id='n416' href='#n416'>416</a>
<a id='n417' href='#n417'>417</a>
<a id='n418' href='#n418'>418</a>
<a id='n419' href='#n419'>419</a>
<a id='n420' href='#n420'>420</a>
<a id='n421' href='#n421'>421</a>
<a id='n422' href='#n422'>422</a>
<a id='n423' href='#n423'>423</a>
<a id='n424' href='#n424'>424</a>
<a id='n425' href='#n425'>425</a>
<a id='n426' href='#n426'>426</a>
<a id='n427' href='#n427'>427</a>
<a id='n428' href='#n428'>428</a>
<a id='n429' href='#n429'>429</a>
<a id='n430' href='#n430'>430</a>
<a id='n431' href='#n431'>431</a>
<a id='n432' href='#n432'>432</a>
<a id='n433' href='#n433'>433</a>
<a id='n434' href='#n434'>434</a>
<a id='n435' href='#n435'>435</a>
<a id='n436' href='#n436'>436</a>
<a id='n437' href='#n437'>437</a>
<a id='n438' href='#n438'>438</a>
<a id='n439' href='#n439'>439</a>
<a id='n440' href='#n440'>440</a>
<a id='n441' href='#n441'>441</a>
<a id='n442' href='#n442'>442</a>
<a id='n443' href='#n443'>443</a>
<a id='n444' href='#n444'>444</a>
<a id='n445' href='#n445'>445</a>
<a id='n446' href='#n446'>446</a>
<a id='n447' href='#n447'>447</a>
<a id='n448' href='#n448'>448</a>
<a id='n449' href='#n449'>449</a>
<a id='n450' href='#n450'>450</a>
<a id='n451' href='#n451'>451</a>
<a id='n452' href='#n452'>452</a>
<a id='n453' href='#n453'>453</a>
<a id='n454' href='#n454'>454</a>
<a id='n455' href='#n455'>455</a>
<a id='n456' href='#n456'>456</a>
<a id='n457' href='#n457'>457</a>
<a id='n458' href='#n458'>458</a>
<a id='n459' href='#n459'>459</a>
<a id='n460' href='#n460'>460</a>
<a id='n461' href='#n461'>461</a>
<a id='n462' href='#n462'>462</a>
<a id='n463' href='#n463'>463</a>
<a id='n464' href='#n464'>464</a>
<a id='n465' href='#n465'>465</a>
<a id='n466' href='#n466'>466</a>
<a id='n467' href='#n467'>467</a>
<a id='n468' href='#n468'>468</a>
<a id='n469' href='#n469'>469</a>
<a id='n470' href='#n470'>470</a>
<a id='n471' href='#n471'>471</a>
<a id='n472' href='#n472'>472</a>
<a id='n473' href='#n473'>473</a>
<a id='n474' href='#n474'>474</a>
<a id='n475' href='#n475'>475</a>
<a id='n476' href='#n476'>476</a>
<a id='n477' href='#n477'>477</a>
<a id='n478' href='#n478'>478</a>
<a id='n479' href='#n479'>479</a>
<a id='n480' href='#n480'>480</a>
<a id='n481' href='#n481'>481</a>
<a id='n482' href='#n482'>482</a>
<a id='n483' href='#n483'>483</a>
<a id='n484' href='#n484'>484</a>
<a id='n485' href='#n485'>485</a>
<a id='n486' href='#n486'>486</a>
<a id='n487' href='#n487'>487</a>
<a id='n488' href='#n488'>488</a>
<a id='n489' href='#n489'>489</a>
<a id='n490' href='#n490'>490</a>
<a id='n491' href='#n491'>491</a>
<a id='n492' href='#n492'>492</a>
<a id='n493' href='#n493'>493</a>
<a id='n494' href='#n494'>494</a>
<a id='n495' href='#n495'>495</a>
<a id='n496' href='#n496'>496</a>
<a id='n497' href='#n497'>497</a>
<a id='n498' href='#n498'>498</a>
<a id='n499' href='#n499'>499</a>
<a id='n500' href='#n500'>500</a>
<a id='n501' href='#n501'>501</a>
<a id='n502' href='#n502'>502</a>
<a id='n503' href='#n503'>503</a>
<a id='n504' href='#n504'>504</a>
<a id='n505' href='#n505'>505</a>
<a id='n506' href='#n506'>506</a>
<a id='n507' href='#n507'>507</a>
<a id='n508' href='#n508'>508</a>
<a id='n509' href='#n509'>509</a>
<a id='n510' href='#n510'>510</a>
<a id='n511' href='#n511'>511</a>
<a id='n512' href='#n512'>512</a>
<a id='n513' href='#n513'>513</a>
<a id='n514' href='#n514'>514</a>
<a id='n515' href='#n515'>515</a>
<a id='n516' href='#n516'>516</a>
<a id='n517' href='#n517'>517</a>
<a id='n518' href='#n518'>518</a>
<a id='n519' href='#n519'>519</a>
<a id='n520' href='#n520'>520</a>
<a id='n521' href='#n521'>521</a>
<a id='n522' href='#n522'>522</a>
<a id='n523' href='#n523'>523</a>
<a id='n524' href='#n524'>524</a>
<a id='n525' href='#n525'>525</a>
<a id='n526' href='#n526'>526</a>
<a id='n527' href='#n527'>527</a>
<a id='n528' href='#n528'>528</a>
<a id='n529' href='#n529'>529</a>
<a id='n530' href='#n530'>530</a>
<a id='n531' href='#n531'>531</a>
<a id='n532' href='#n532'>532</a>
<a id='n533' href='#n533'>533</a>
<a id='n534' href='#n534'>534</a>
<a id='n535' href='#n535'>535</a>
<a id='n536' href='#n536'>536</a>
<a id='n537' href='#n537'>537</a>
<a id='n538' href='#n538'>538</a>
<a id='n539' href='#n539'>539</a>
<a id='n540' href='#n540'>540</a>
<a id='n541' href='#n541'>541</a>
<a id='n542' href='#n542'>542</a>
<a id='n543' href='#n543'>543</a>
<a id='n544' href='#n544'>544</a>
<a id='n545' href='#n545'>545</a>
<a id='n546' href='#n546'>546</a>
<a id='n547' href='#n547'>547</a>
<a id='n548' href='#n548'>548</a>
<a id='n549' href='#n549'>549</a>
<a id='n550' href='#n550'>550</a>
<a id='n551' href='#n551'>551</a>
<a id='n552' href='#n552'>552</a>
<a id='n553' href='#n553'>553</a>
<a id='n554' href='#n554'>554</a>
<a id='n555' href='#n555'>555</a>
<a id='n556' href='#n556'>556</a>
<a id='n557' href='#n557'>557</a>
<a id='n558' href='#n558'>558</a>
<a id='n559' href='#n559'>559</a>
<a id='n560' href='#n560'>560</a>
<a id='n561' href='#n561'>561</a>
<a id='n562' href='#n562'>562</a>
<a id='n563' href='#n563'>563</a>
<a id='n564' href='#n564'>564</a>
<a id='n565' href='#n565'>565</a>
<a id='n566' href='#n566'>566</a>
<a id='n567' href='#n567'>567</a>
<a id='n568' href='#n568'>568</a>
<a id='n569' href='#n569'>569</a>
<a id='n570' href='#n570'>570</a>
<a id='n571' href='#n571'>571</a>
<a id='n572' href='#n572'>572</a>
<a id='n573' href='#n573'>573</a>
<a id='n574' href='#n574'>574</a>
<a id='n575' href='#n575'>575</a>
<a id='n576' href='#n576'>576</a>
<a id='n577' href='#n577'>577</a>
<a id='n578' href='#n578'>578</a>
<a id='n579' href='#n579'>579</a>
<a id='n580' href='#n580'>580</a>
<a id='n581' href='#n581'>581</a>
<a id='n582' href='#n582'>582</a>
<a id='n583' href='#n583'>583</a>
<a id='n584' href='#n584'>584</a>
<a id='n585' href='#n585'>585</a>
<a id='n586' href='#n586'>586</a>
<a id='n587' href='#n587'>587</a>
<a id='n588' href='#n588'>588</a>
<a id='n589' href='#n589'>589</a>
<a id='n590' href='#n590'>590</a>
<a id='n591' href='#n591'>591</a>
<a id='n592' href='#n592'>592</a>
<a id='n593' href='#n593'>593</a>
<a id='n594' href='#n594'>594</a>
<a id='n595' href='#n595'>595</a>
<a id='n596' href='#n596'>596</a>
<a id='n597' href='#n597'>597</a>
<a id='n598' href='#n598'>598</a>
<a id='n599' href='#n599'>599</a>
<a id='n600' href='#n600'>600</a>
<a id='n601' href='#n601'>601</a>
<a id='n602' href='#n602'>602</a>
<a id='n603' href='#n603'>603</a>
<a id='n604' href='#n604'>604</a>
<a id='n605' href='#n605'>605</a>
<a id='n606' href='#n606'>606</a>
<a id='n607' href='#n607'>607</a>
<a id='n608' href='#n608'>608</a>
<a id='n609' href='#n609'>609</a>
<a id='n610' href='#n610'>610</a>
<a id='n611' href='#n611'>611</a>
<a id='n612' href='#n612'>612</a>
<a id='n613' href='#n613'>613</a>
<a id='n614' href='#n614'>614</a>
<a id='n615' href='#n615'>615</a>
<a id='n616' href='#n616'>616</a>
<a id='n617' href='#n617'>617</a>
<a id='n618' href='#n618'>618</a>
<a id='n619' href='#n619'>619</a>
<a id='n620' href='#n620'>620</a>
<a id='n621' href='#n621'>621</a>
<a id='n622' href='#n622'>622</a>
<a id='n623' href='#n623'>623</a>
<a id='n624' href='#n624'>624</a>
<a id='n625' href='#n625'>625</a>
<a id='n626' href='#n626'>626</a>
<a id='n627' href='#n627'>627</a>
<a id='n628' href='#n628'>628</a>
<a id='n629' href='#n629'>629</a>
<a id='n630' href='#n630'>630</a>
<a id='n631' href='#n631'>631</a>
<a id='n632' href='#n632'>632</a>
<a id='n633' href='#n633'>633</a>
<a id='n634' href='#n634'>634</a>
<a id='n635' href='#n635'>635</a>
<a id='n636' href='#n636'>636</a>
<a id='n637' href='#n637'>637</a>
<a id='n638' href='#n638'>638</a>
<a id='n639' href='#n639'>639</a>
<a id='n640' href='#n640'>640</a>
<a id='n641' href='#n641'>641</a>
<a id='n642' href='#n642'>642</a>
<a id='n643' href='#n643'>643</a>
<a id='n644' href='#n644'>644</a>
<a id='n645' href='#n645'>645</a>
<a id='n646' href='#n646'>646</a>
<a id='n647' href='#n647'>647</a>
<a id='n648' href='#n648'>648</a>
<a id='n649' href='#n649'>649</a>
<a id='n650' href='#n650'>650</a>
<a id='n651' href='#n651'>651</a>
<a id='n652' href='#n652'>652</a>
<a id='n653' href='#n653'>653</a>
<a id='n654' href='#n654'>654</a>
<a id='n655' href='#n655'>655</a>
<a id='n656' href='#n656'>656</a>
<a id='n657' href='#n657'>657</a>
<a id='n658' href='#n658'>658</a>
<a id='n659' href='#n659'>659</a>
<a id='n660' href='#n660'>660</a>
<a id='n661' href='#n661'>661</a>
<a id='n662' href='#n662'>662</a>
<a id='n663' href='#n663'>663</a>
<a id='n664' href='#n664'>664</a>
<a id='n665' href='#n665'>665</a>
<a id='n666' href='#n666'>666</a>
<a id='n667' href='#n667'>667</a>
<a id='n668' href='#n668'>668</a>
<a id='n669' href='#n669'>669</a>
<a id='n670' href='#n670'>670</a>
<a id='n671' href='#n671'>671</a>
<a id='n672' href='#n672'>672</a>
<a id='n673' href='#n673'>673</a>
<a id='n674' href='#n674'>674</a>
<a id='n675' href='#n675'>675</a>
<a id='n676' href='#n676'>676</a>
<a id='n677' href='#n677'>677</a>
<a id='n678' href='#n678'>678</a>
<a id='n679' href='#n679'>679</a>
<a id='n680' href='#n680'>680</a>
<a id='n681' href='#n681'>681</a>
<a id='n682' href='#n682'>682</a>
<a id='n683' href='#n683'>683</a>
<a id='n684' href='#n684'>684</a>
<a id='n685' href='#n685'>685</a>
<a id='n686' href='#n686'>686</a>
<a id='n687' href='#n687'>687</a>
<a id='n688' href='#n688'>688</a>
<a id='n689' href='#n689'>689</a>
<a id='n690' href='#n690'>690</a>
<a id='n691' href='#n691'>691</a>
<a id='n692' href='#n692'>692</a>
<a id='n693' href='#n693'>693</a>
<a id='n694' href='#n694'>694</a>
<a id='n695' href='#n695'>695</a>
<a id='n696' href='#n696'>696</a>
<a id='n697' href='#n697'>697</a>
<a id='n698' href='#n698'>698</a>
<a id='n699' href='#n699'>699</a>
<a id='n700' href='#n700'>700</a>
<a id='n701' href='#n701'>701</a>
<a id='n702' href='#n702'>702</a>
<a id='n703' href='#n703'>703</a>
<a id='n704' href='#n704'>704</a>
<a id='n705' href='#n705'>705</a>
<a id='n706' href='#n706'>706</a>
<a id='n707' href='#n707'>707</a>
<a id='n708' href='#n708'>708</a>
<a id='n709' href='#n709'>709</a>
<a id='n710' href='#n710'>710</a>
<a id='n711' href='#n711'>711</a>
<a id='n712' href='#n712'>712</a>
<a id='n713' href='#n713'>713</a>
<a id='n714' href='#n714'>714</a>
<a id='n715' href='#n715'>715</a>
<a id='n716' href='#n716'>716</a>
<a id='n717' href='#n717'>717</a>
<a id='n718' href='#n718'>718</a>
<a id='n719' href='#n719'>719</a>
<a id='n720' href='#n720'>720</a>
<a id='n721' href='#n721'>721</a>
<a id='n722' href='#n722'>722</a>
<a id='n723' href='#n723'>723</a>
<a id='n724' href='#n724'>724</a>
<a id='n725' href='#n725'>725</a>
<a id='n726' href='#n726'>726</a>
<a id='n727' href='#n727'>727</a>
<a id='n728' href='#n728'>728</a>
<a id='n729' href='#n729'>729</a>
<a id='n730' href='#n730'>730</a>
<a id='n731' href='#n731'>731</a>
<a id='n732' href='#n732'>732</a>
<a id='n733' href='#n733'>733</a>
<a id='n734' href='#n734'>734</a>
<a id='n735' href='#n735'>735</a>
<a id='n736' href='#n736'>736</a>
<a id='n737' href='#n737'>737</a>
<a id='n738' href='#n738'>738</a>
<a id='n739' href='#n739'>739</a>
<a id='n740' href='#n740'>740</a>
<a id='n741' href='#n741'>741</a>
<a id='n742' href='#n742'>742</a>
<a id='n743' href='#n743'>743</a>
<a id='n744' href='#n744'>744</a>
<a id='n745' href='#n745'>745</a>
<a id='n746' href='#n746'>746</a>
<a id='n747' href='#n747'>747</a>
<a id='n748' href='#n748'>748</a>
<a id='n749' href='#n749'>749</a>
<a id='n750' href='#n750'>750</a>
<a id='n751' href='#n751'>751</a>
<a id='n752' href='#n752'>752</a>
<a id='n753' href='#n753'>753</a>
<a id='n754' href='#n754'>754</a>
<a id='n755' href='#n755'>755</a>
<a id='n756' href='#n756'>756</a>
<a id='n757' href='#n757'>757</a>
<a id='n758' href='#n758'>758</a>
<a id='n759' href='#n759'>759</a>
<a id='n760' href='#n760'>760</a>
<a id='n761' href='#n761'>761</a>
<a id='n762' href='#n762'>762</a>
<a id='n763' href='#n763'>763</a>
<a id='n764' href='#n764'>764</a>
<a id='n765' href='#n765'>765</a>
<a id='n766' href='#n766'>766</a>
</pre></td>
<td class='lines'><pre><code><span class="hl kwa">package</span> authentication<span class="hl opt">;</span> <span class="hl slc"># $Id$</span>

<span class="hl kwa">use</span> common<span class="hl opt">;</span>

<span class="hl kwa">sub</span> kinds <span class="hl opt">{</span> 
    <span class="hl kwc">my</span> <span class="hl kwb">$no_para</span> <span class="hl opt">=</span> <span class="hl kwb">&#64;_</span> <span class="hl opt">==</span> <span class="hl num">0</span><span class="hl opt">;</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$do_pkgs, $_meta_class</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$allow_SmartCard</span> <span class="hl opt">=</span> <span class="hl kwb">$no_para</span> <span class="hl opt">||</span> <span class="hl kwb">$do_pkgs</span><span class="hl opt">-&gt;</span><span class="hl kwd">is_available</span><span class="hl opt">(</span><span class="hl str">&apos;castella-pam&apos;</span><span class="hl opt">);</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$allow_AD</span> <span class="hl opt">=</span> <span class="hl num">1</span><span class="hl opt">;</span>
    <span class="hl opt">(</span>
	<span class="hl str">&apos;local&apos;</span><span class="hl opt">,</span> 
	<span class="hl str">&apos;LDAP&apos;</span><span class="hl opt">,</span>
	<span class="hl str">&apos;NIS&apos;</span><span class="hl opt">,</span> 
	if_<span class="hl opt">(</span><span class="hl kwb">$allow_SmartCard,</span> <span class="hl str">&apos;SmartCard&apos;</span><span class="hl opt">),</span> 
	<span class="hl str">&apos;winbind&apos;</span><span class="hl opt">,</span> 
	if_<span class="hl opt">(</span><span class="hl kwb">$allow_AD,</span> <span class="hl str">&apos;AD&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">),</span>
    <span class="hl opt">);</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> kind2name <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl slc"># Keep the following strings in sync with kind2description ones!!!</span>
    <span class="hl opt">${{</span> <span class="hl kwc">local</span> <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Local file&quot;</span><span class="hl opt">),</span> 
    LDAP <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP&quot;</span><span class="hl opt">),</span> 
    NIS <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;NIS&quot;</span><span class="hl opt">),</span>
    SmartCard <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Smart Card&quot;</span><span class="hl opt">),</span>
    winbind <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Windows Domain&quot;</span><span class="hl opt">),</span> 
    AD <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Active Directory with SFU&quot;</span><span class="hl opt">),</span>
    SMBKRB <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Active Directory with Winbind&quot;</span><span class="hl opt">) }}{</span><span class="hl kwb">$kind</span><span class="hl opt">};</span>
<span class="hl opt">}</span>

<span class="hl kwc">my</span> <span class="hl kwb">%kind2pam_kind</span> <span class="hl opt">= (</span>
    <span class="hl kwc">local</span>     <span class="hl opt">=&gt; [],</span>
    SmartCard <span class="hl opt">=&gt; [</span><span class="hl str">&apos;castella&apos;</span><span class="hl opt">],</span>
    LDAP      <span class="hl opt">=&gt; [</span><span class="hl str">&apos;ldap&apos;</span><span class="hl opt">],</span> 
    NIS       <span class="hl opt">=&gt; [],</span>
    AD        <span class="hl opt">=&gt; [</span><span class="hl str">&apos;krb5&apos;</span><span class="hl opt">],</span>
    winbind   <span class="hl opt">=&gt; [</span><span class="hl str">&apos;winbind&apos;</span><span class="hl opt">],</span> 
    SMBKRB    <span class="hl opt">=&gt; [</span><span class="hl str">&apos;winbind&apos;</span><span class="hl opt">],</span>
<span class="hl opt">);</span>

<span class="hl kwc">my</span> <span class="hl kwb">%kind2nsswitch</span> <span class="hl opt">= (</span>
    <span class="hl kwc">local</span>     <span class="hl opt">=&gt; [],</span>
    SmartCard <span class="hl opt">=&gt; [],</span>
    LDAP      <span class="hl opt">=&gt; [</span><span class="hl str">&apos;ldap&apos;</span><span class="hl opt">],</span> 
    NIS       <span class="hl opt">=&gt; [</span><span class="hl str">&apos;nis&apos;</span><span class="hl opt">],</span>
    AD        <span class="hl opt">=&gt; [</span><span class="hl str">&apos;ldap&apos;</span><span class="hl opt">],</span>
    winbind   <span class="hl opt">=&gt; [</span><span class="hl str">&apos;winbind&apos;</span><span class="hl opt">],</span> 
    SMBKRB    <span class="hl opt">=&gt; [</span><span class="hl str">&apos;winbind&apos;</span><span class="hl opt">],</span>
<span class="hl opt">);</span>

<span class="hl kwc">my</span> <span class="hl kwb">%kind2packages</span> <span class="hl opt">= (</span>
    <span class="hl kwc">local</span>     <span class="hl opt">=&gt; [],</span>
    SmartCard <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;castella-pam&apos;</span> <span class="hl opt">],</span>
    LDAP      <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;openldap-clients&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;nss_ldap&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_ldap&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;autofs&apos;</span> <span class="hl opt">],</span>
    AD        <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;nss_ldap&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_krb5&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;libsasl2-plug-gssapi&apos;</span> <span class="hl opt">],</span>
    NIS       <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;ypbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;autofs&apos;</span> <span class="hl opt">],</span>
    winbind   <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;samba-winbind&apos;</span> <span class="hl opt">],</span>
    SMBKRB    <span class="hl opt">=&gt; [</span> <span class="hl str">&apos;samba-winbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_krb5&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;samba-server&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;samba-client&apos;</span> <span class="hl opt">],</span>
<span class="hl opt">);</span>


<span class="hl kwa">sub</span> kind2description <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">&#64;kinds</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwc">my</span> <span class="hl kwb">%kind2description</span> <span class="hl opt">= (</span>
	<span class="hl kwc">local</span>     <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;Local file:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Use information stored in local files for all authentication&quot;</span><span class="hl opt">), ],</span>
	LDAP      <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Tells your computer to use LDAP for some or all authentication. LDAP consolidates certain types of information within your organization.&quot;</span><span class="hl opt">), ],</span>
	NIS       <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;NIS:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Allows you to run a group of computers in the same Network Information Service domain with a common password and group file.&quot;</span><span class="hl opt">), ],</span>
	winbind   <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;Windows Domain:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Winbind allows the system to retrieve information and authenticate users in a Windows domain.&quot;</span><span class="hl opt">), ],</span>
	AD        <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;Active Directory with SFU:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;With Kerberos and Ldap for authentication in Active Directory Server &quot;</span><span class="hl opt">), ],</span>
	SMBKRB    <span class="hl opt">=&gt; [</span> N<span class="hl opt">(</span><span class="hl str">&quot;Active Directory with Winbind:&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Winbind allows the system to authenticate users in a Windows Active Directory Server.&quot;</span><span class="hl opt">)  ],</span>
    <span class="hl opt">);</span>
    <span class="hl kwc">join</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span> <span class="hl kwc">map</span> <span class="hl opt">{</span> <span class="hl kwb">$_</span> ? <span class="hl str">qq(</span><span class="hl ipl">$_</span><span class="hl str">-&gt;[0]</span><span class="hl esc">\n</span><span class="hl str"></span><span class="hl ipl">$_</span><span class="hl str">-&gt;[1]</span><span class="hl esc">\n\n</span><span class="hl str">)</span> <span class="hl opt">:</span> <span class="hl str">&apos;&apos;</span> <span class="hl opt">}</span> <span class="hl kwc">map</span> <span class="hl opt">{</span> <span class="hl kwb">$kind2description</span><span class="hl opt">{</span><span class="hl kwb">$_</span><span class="hl opt">} }</span> <span class="hl kwb">&#64;kinds</span><span class="hl opt">);</span>
<span class="hl opt">}</span>
<span class="hl kwa">sub</span> to_kind <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl opt">(</span>find <span class="hl opt">{</span> <span class="hl kwc">exists</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span><span class="hl kwb">$_</span><span class="hl opt">} }</span> kinds<span class="hl opt">()) ||</span> <span class="hl str">&apos;local&apos;</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> domain_to_ldap_domain <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$domain</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwc">join</span><span class="hl opt">(</span><span class="hl str">&apos;,&apos;</span><span class="hl opt">,</span> <span class="hl kwc">map</span> <span class="hl opt">{</span> <span class="hl str">&quot;dc=</span><span class="hl ipl">$_</span><span class="hl str">&quot;</span> <span class="hl opt">}</span> <span class="hl kwc">split</span> <span class="hl kwd">/\./</span><span class="hl opt">,</span> <span class="hl kwb">$domain</span><span class="hl opt">);</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> ask_parameters <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$in, $net, $authentication, $kind</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>

    <span class="hl slc">#- keep only this authentication kind</span>
    <span class="hl kwa">foreach</span> <span class="hl opt">(</span>kinds<span class="hl opt">()) {</span>
	<span class="hl kwc">delete</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span><span class="hl kwb">$_</span><span class="hl opt">}</span> <span class="hl kwa">if</span> <span class="hl kwb">$_</span> <span class="hl kwc">ne</span> <span class="hl kwb">$kind</span><span class="hl opt">;</span>
    <span class="hl opt">}</span>

    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;LDAP&apos;</span><span class="hl opt">) {</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAPDOMAIN<span class="hl opt">} ||=</span> domain_to_ldap_domain<span class="hl opt">(</span><span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>resolv<span class="hl opt">}{</span>DOMAINNAME<span class="hl opt">});</span>
	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_from</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
		     N<span class="hl opt">(</span><span class="hl str">&quot;Authentication LDAP&quot;</span><span class="hl opt">),</span>
		     <span class="hl opt">[ {</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP Base dn&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAPDOMAIN<span class="hl opt">} },</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP Server&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAP_server<span class="hl opt">} },</span>
		     <span class="hl opt">])</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;AD&apos;</span><span class="hl opt">) {</span>
	
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">} ||=</span> <span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>resolv<span class="hl opt">}{</span>DOMAINNAME<span class="hl opt">};</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_users_db<span class="hl opt">} ||=</span> <span class="hl str">&apos;cn=users,&apos;</span> <span class="hl opt">.</span> domain_to_ldap_domain<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">});</span>

	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">do_pkgs</span><span class="hl opt">-&gt;</span><span class="hl kwd">ensure_are_installed</span><span class="hl opt">([</span> <span class="hl str">&apos;perl-Net-DNS&apos;</span> <span class="hl opt">],</span> <span class="hl num">1</span><span class="hl opt">)</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>

	<span class="hl kwc">my</span> <span class="hl kwb">&#64;srvs</span> <span class="hl opt">=</span> query_srv_names<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">});</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_server<span class="hl opt">} ||=</span> <span class="hl kwb">$srvs</span><span class="hl opt">[</span><span class="hl num">0</span><span class="hl opt">]</span> <span class="hl kwa">if</span> <span class="hl kwb">&#64;srvs</span><span class="hl opt">;</span>

	<span class="hl kwc">my</span> <span class="hl kwb">%sub_kinds</span> <span class="hl opt">= (</span>
	    simple <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;simple&quot;</span><span class="hl opt">),</span> 
	    tls <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;TLS&quot;</span><span class="hl opt">),</span>
	    ssl <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;SSL&quot;</span><span class="hl opt">),</span>
	    kerberos <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;security layout (SASL/Kerberos)&quot;</span><span class="hl opt">),</span>
	<span class="hl opt">);</span>

	<span class="hl kwc">my</span> <span class="hl kwb">$AD_user</span> <span class="hl opt">=</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_user<span class="hl opt">} =~</span> <span class="hl kwd">/(.*)\&#64;\Q$authentication-&gt;{AD_domain}\E$/</span> ? <span class="hl kwb">$1</span> <span class="hl opt">:</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_user<span class="hl opt">};</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$anonymous</span> <span class="hl opt">=</span> <span class="hl kwb">$AD_user</span><span class="hl opt">;</span>

	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_from</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
		     N<span class="hl opt">(</span><span class="hl str">&quot;Authentication Active Directory&quot;</span><span class="hl opt">),</span>
		     <span class="hl opt">[ {</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Domain&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">} },</span>
		     <span class="hl slc">#{ label =&gt; N(&quot;Server&quot;), val =&gt; \$authentication-&gt;{AD_server} },</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Server&quot;</span><span class="hl opt">),</span> type <span class="hl opt">=&gt;</span> <span class="hl str">&apos;combo&apos;</span><span class="hl opt">,</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_server<span class="hl opt">},</span> list <span class="hl opt">=&gt;</span> \<span class="hl kwb">&#64;srvs</span> <span class="hl opt">,</span> not_edit <span class="hl opt">=&gt;</span> <span class="hl num">0</span> <span class="hl opt">},</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP users database&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_users_db<span class="hl opt">} },</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Use Anonymous BIND &quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$anonymous,</span> type <span class="hl opt">=&gt;</span> <span class="hl str">&apos;bool&apos;</span> <span class="hl opt">},</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;LDAP user allowed to browse the Active Directory&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$AD_user,</span> disabled <span class="hl opt">=&gt;</span> <span class="hl kwa">sub</span> <span class="hl opt">{</span> <span class="hl kwb">$anonymous</span> <span class="hl opt">} },</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Password for user&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_password<span class="hl opt">},</span> hidden <span class="hl opt">=&gt;</span> <span class="hl num">1</span><span class="hl opt">,</span> disabled <span class="hl opt">=&gt;</span> <span class="hl kwa">sub</span> <span class="hl opt">{</span> <span class="hl kwb">$anonymous</span> <span class="hl opt">} },</span>
		       <span class="hl slc">#{ label =&gt; N(&quot;Encryption&quot;), val =&gt; \$authentication-&gt;{sub_kind}, list =&gt; [ map { $_-&gt;[0] } group_by2(&#64;sub_kinds) ], format =&gt; sub { $sub_kinds{$_[0]} } },</span>
		     <span class="hl opt">])</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_user<span class="hl opt">} = !</span><span class="hl kwb">$AD_user</span> <span class="hl opt">||</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>sub_kind<span class="hl opt">}</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;anonymous&apos;</span> ? <span class="hl str">&apos;&apos;</span> <span class="hl opt">:</span> 
	                             <span class="hl kwb">$AD_user</span> <span class="hl opt">=~</span> <span class="hl kwd">/&#64;/</span> ? <span class="hl kwb">$AD_user</span> <span class="hl opt">:</span> <span class="hl str">&quot;</span><span class="hl ipl">$AD_user\&#64;$authentication</span><span class="hl str">-&gt;{AD_domain}&quot;</span><span class="hl opt">;</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_password<span class="hl opt">} =</span> <span class="hl str">&apos;&apos;</span> <span class="hl kwa">if</span> <span class="hl opt">!</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_user<span class="hl opt">};</span>


    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;NIS&apos;</span><span class="hl opt">) {</span> 
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>NIS_server<span class="hl opt">} ||=</span> <span class="hl str">&apos;broadcast&apos;</span><span class="hl opt">;</span>
	<span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>network<span class="hl opt">}{</span>NISDOMAIN<span class="hl opt">} ||=</span> <span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>resolv<span class="hl opt">}{</span>DOMAINNAME<span class="hl opt">};</span>
	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_from</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
		     N<span class="hl opt">(</span><span class="hl str">&quot;Authentication NIS&quot;</span><span class="hl opt">),</span>
		     <span class="hl opt">[ {</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;NIS Domain&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>network<span class="hl opt">}{</span>NISDOMAIN<span class="hl opt">} },</span>
		       <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;NIS Server&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>NIS_server<span class="hl opt">},</span> list <span class="hl opt">=&gt; [</span><span class="hl str">&quot;broadcast&quot;</span><span class="hl opt">],</span> not_edit <span class="hl opt">=&gt;</span> <span class="hl num">0</span> <span class="hl opt">},</span>
		     <span class="hl opt">])</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;winbind&apos;</span> <span class="hl opt">||</span> <span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">) {</span>
	<span class="hl slc">#- maybe we should browse the network like diskdrake --smb and get the &apos;doze server names in a list </span>
	<span class="hl slc">#- but networking is not setup yet necessarily</span>
	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_warn</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span> N<span class="hl opt">(</span><span class="hl str">&quot;For this to work for a W2K PDC, you will probably need to have the admin run: C:</span><span class="hl esc">\\</span><span class="hl str">&gt;net localgroup</span> <span class="hl esc">\&quot;</span><span class="hl str">Pre-Windows 2000 Compatible Access</span><span class="hl esc">\&quot;</span> <span class="hl str">everyone /add and reboot the server.</span>
<span class="hl str">You will also need the username/password of a Domain Admin to join the machine to the Windows(TM) domain.</span>
<span class="hl str">If networking is not yet enabled, Drakx will attempt to join the domain after the network setup step.</span>
<span class="hl str">Should this setup fail for some reason and domain authentication is not working, run &apos;smbpasswd -j DOMAIN -U USER</span><span class="hl ipl">%%PASSWORD</span><span class="hl str">&apos; using your Windows(tm) Domain, and Admin Username/Password, after system boot.</span>
<span class="hl str">The command &apos;wbinfo -t&apos; will test whether your authentication secrets are good.&quot;</span><span class="hl opt">))</span>
	  <span class="hl kwa">if</span> <span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;winbind&apos;</span><span class="hl opt">;</span>

	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">} ||=</span> <span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>resolv<span class="hl opt">}{</span>DOMAINNAME<span class="hl opt">}</span> <span class="hl kwa">if</span> <span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">;</span>
	 <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_users_idmap<span class="hl opt">} ||=</span> <span class="hl str">&apos;ou=idmap,&apos;</span> <span class="hl opt">.</span> domain_to_ldap_domain<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">})</span> <span class="hl kwa">if</span> <span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">;</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>WINDOMAIN<span class="hl opt">} ||=</span> <span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>resolv<span class="hl opt">}{</span>DOMAINNAME<span class="hl opt">};</span>

	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_from</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
		      <span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span> ? N<span class="hl opt">(</span><span class="hl str">&quot;Authentication Active Directory&quot;</span><span class="hl opt">) :</span> N<span class="hl opt">(</span><span class="hl str">&quot;Authentication Windows Domain&quot;</span><span class="hl opt">),</span>
		        <span class="hl opt">[</span> if_<span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">,</span> 
			  <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Active Directory Realm &quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">} }</span>
			     <span class="hl opt">),</span>
			  <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Windows Domain&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>WINDOMAIN<span class="hl opt">} },</span>
			  <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Domain Admin User Name&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winuser<span class="hl opt">} },</span>
			  <span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Domain Admin Password&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winpass<span class="hl opt">},</span> hidden <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span>
			  <span class="hl slc">#{ label =&gt; N(&quot;Use Idmap for store UID/SID &quot;), val =&gt; \$anonymous, type =&gt; &apos;bool&apos; },</span>
			  <span class="hl slc">#{ label =&gt; N(&quot;Default Idmap &quot;), val =&gt; \$authentication-&gt;{AD_users_idmap}, disabled =&gt; sub { $anonymous } },</span>
			<span class="hl opt">])</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
    <span class="hl opt">}</span>
    <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span><span class="hl kwb">$kind</span><span class="hl opt">} ||=</span> <span class="hl num">1</span><span class="hl opt">;</span>
    <span class="hl num">1</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> ask_root_password_and_authentication <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$in, $net, $superuser, $authentication, $meta_class, $security</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>

    <span class="hl kwc">my</span> <span class="hl kwb">$kind</span> <span class="hl opt">=</span> to_kind<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">);</span>
    <span class="hl kwc">my</span> <span class="hl kwb">&#64;kinds</span> <span class="hl opt">=</span> kinds<span class="hl opt">(</span><span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">do_pkgs</span><span class="hl opt">,</span> <span class="hl kwb">$meta_class</span><span class="hl opt">);</span>

    <span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_from_</span><span class="hl opt">({</span>
	 title <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Authentication&quot;</span><span class="hl opt">),</span> 
	 messages <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Set administrator (root) password&quot;</span><span class="hl opt">),</span>
	 icon <span class="hl opt">=&gt;</span> <span class="hl str">&apos;banner-pw&apos;</span><span class="hl opt">,</span>
	 advanced_label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Authentication method&quot;</span><span class="hl opt">),</span>
	 advanced_messages <span class="hl opt">=&gt;</span> kind2description<span class="hl opt">(</span><span class="hl kwb">&#64;kinds</span><span class="hl opt">),</span>
	 interactive_help_id <span class="hl opt">=&gt;</span> <span class="hl str">&quot;setRootPassword&quot;</span><span class="hl opt">,</span>
	 cancel <span class="hl opt">=&gt; (</span><span class="hl kwb">$security</span> <span class="hl opt">&lt;=</span> <span class="hl num">2</span> ? 
		    <span class="hl slc">#-PO: keep this short or else the buttons will not fit in the window</span>
		    N<span class="hl opt">(</span><span class="hl str">&quot;No password&quot;</span><span class="hl opt">) :</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">),</span>
	 focus_first <span class="hl opt">=&gt;</span> <span class="hl num">1</span><span class="hl opt">,</span>
	 callbacks <span class="hl opt">=&gt; {</span> 
	     complete <span class="hl opt">=&gt;</span> <span class="hl kwa">sub</span> <span class="hl opt">{</span>
		 check_given_password<span class="hl opt">(</span><span class="hl kwb">$in, $superuser,</span> <span class="hl num">2</span> <span class="hl opt">*</span> <span class="hl kwb">$security</span><span class="hl opt">)</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span> <span class="hl num">1</span><span class="hl opt">,</span><span class="hl num">0</span><span class="hl opt">;</span>
		 <span class="hl kwa">return</span> <span class="hl num">0</span><span class="hl opt">;</span>
        <span class="hl opt">} } }, [</span>
<span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Password&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$superuser</span><span class="hl opt">-&gt;{</span>password<span class="hl opt">},</span>  hidden <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span>
<span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Password (again)&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$superuser</span><span class="hl opt">-&gt;{</span>password2<span class="hl opt">},</span> hidden <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span>
<span class="hl opt">{</span> label <span class="hl opt">=&gt;</span> N<span class="hl opt">(</span><span class="hl str">&quot;Authentication&quot;</span><span class="hl opt">),</span> val <span class="hl opt">=&gt;</span> \<span class="hl kwb">$kind,</span> type <span class="hl opt">=&gt;</span> <span class="hl str">&apos;list&apos;</span><span class="hl opt">,</span> list <span class="hl opt">=&gt;</span> \<span class="hl kwb">&#64;kinds,</span> format <span class="hl opt">=&gt;</span> \<span class="hl opt">&amp;</span>kind2name<span class="hl opt">,</span> advanced <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span>
        <span class="hl opt">])</span> <span class="hl kwc">or delete</span> <span class="hl kwb">$superuser</span><span class="hl opt">-&gt;{</span>password<span class="hl opt">};</span>

    ask_parameters<span class="hl opt">(</span><span class="hl kwb">$in, $net, $authentication, $kind</span><span class="hl opt">)</span> <span class="hl kwc">or</span> <span class="hl kwa">goto</span> <span class="hl opt">&amp;</span>ask_root_password_and_authentication<span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> check_given_password <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$in, $u, $min_length</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$u</span><span class="hl opt">-&gt;{</span>password<span class="hl opt">}</span> <span class="hl kwc">ne</span> <span class="hl kwb">$u</span><span class="hl opt">-&gt;{</span>password2<span class="hl opt">}) {</span>
	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_warn</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">, [</span> N<span class="hl opt">(</span><span class="hl str">&quot;The passwords do not match&quot;</span><span class="hl opt">),</span> N<span class="hl opt">(</span><span class="hl str">&quot;Please try again&quot;</span><span class="hl opt">) ]);</span>
	<span class="hl num">0</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwc">length</span> <span class="hl kwb">$u</span><span class="hl opt">-&gt;{</span>password<span class="hl opt">} &lt;</span> <span class="hl kwb">$min_length</span><span class="hl opt">) {</span>
	<span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">ask_warn</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span> N<span class="hl opt">(</span><span class="hl str">&quot;This password is too short (it must be at least</span> <span class="hl ipl">%d</span> <span class="hl str">characters long)&quot;</span><span class="hl opt">,</span> <span class="hl kwb">$min_length</span><span class="hl opt">));</span>
	<span class="hl num">0</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">else</span> <span class="hl opt">{</span>
	<span class="hl num">1</span><span class="hl opt">;</span>
    <span class="hl opt">}</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> get<span class="hl opt">() {</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$system_auth</span> <span class="hl opt">=</span> cat_<span class="hl opt">(</span><span class="hl str">&quot;/etc/pam.d/system-auth&quot;</span><span class="hl opt">);</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$authentication</span> <span class="hl opt">= {</span> 
	md5 <span class="hl opt">=&gt;</span> <span class="hl kwb">$system_auth</span> <span class="hl opt">=~</span> <span class="hl kwd">/md5/</span><span class="hl opt">,</span> shadow <span class="hl opt">=&gt;</span> <span class="hl kwb">$system_auth</span> <span class="hl opt">=~</span> <span class="hl kwd">/shadow/</span><span class="hl opt">,</span> 
    <span class="hl opt">};</span>

    <span class="hl kwc">my</span> <span class="hl kwb">&#64;pam_kinds</span> <span class="hl opt">=</span> get_pam_authentication_kinds<span class="hl opt">();</span>
    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl kwb">$kind</span> <span class="hl opt">=</span> find <span class="hl opt">{</span> intersection<span class="hl opt">(</span>\<span class="hl kwb">&#64;pam_kinds, $kind2pam_kind</span><span class="hl opt">{</span><span class="hl kwb">$_</span><span class="hl opt">}) }</span> <span class="hl kwc">keys</span> <span class="hl kwb">%kind2pam_kind</span><span class="hl opt">) {</span>
	<span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span><span class="hl kwb">$kind</span><span class="hl opt">} =</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">else</span> <span class="hl opt">{</span>
	<span class="hl slc">#- we can&apos;t use pam to detect NIS</span>
	<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl kwb">$yp_conf</span> <span class="hl opt">=</span> read_yp_conf<span class="hl opt">()) {</span>
	    <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>NIS<span class="hl opt">} =</span> <span class="hl num">1</span><span class="hl opt">;</span>
	    map_each <span class="hl opt">{</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span><span class="hl str">&quot;NIS_$::a&quot;</span><span class="hl opt">} = $::</span>b <span class="hl opt">}</span> <span class="hl kwb">%$yp_conf</span><span class="hl opt">;</span>
	<span class="hl opt">}</span>
    <span class="hl opt">}</span>
    <span class="hl kwb">$authentication</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> install_needed_packages <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$do_pkgs, $kind</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl kwb">$pkgs</span> <span class="hl opt">=</span> <span class="hl kwb">$kind2packages</span><span class="hl opt">{</span><span class="hl kwb">$kind</span><span class="hl opt">}) {</span>
	<span class="hl slc">#- automatic during install</span>
	<span class="hl kwb">$do_pkgs</span><span class="hl opt">-&gt;</span><span class="hl kwd">ensure_are_installed</span><span class="hl opt">(</span><span class="hl kwb">$pkgs,</span> <span class="hl opt">$::</span>isInstall<span class="hl opt">)</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
    <span class="hl opt">}</span> <span class="hl kwa">else</span> <span class="hl opt">{</span>
	<span class="hl kwc">log</span><span class="hl opt">::</span>l<span class="hl opt">(</span><span class="hl str">&quot;ERROR:</span> <span class="hl ipl">$kind</span> <span class="hl str">not listed in kind2packages&quot;</span><span class="hl opt">);</span>
    <span class="hl opt">}</span>
    <span class="hl num">1</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> set <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$in, $net, $authentication, $o_when_network_is_up</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>

    install_needed_packages<span class="hl opt">(</span><span class="hl kwb">$in</span><span class="hl opt">-&gt;</span><span class="hl kwd">do_pkgs</span><span class="hl opt">,</span> to_kind<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">))</span> <span class="hl kwc">or</span> <span class="hl kwa">return</span><span class="hl opt">;</span>
    set_raw<span class="hl opt">(</span><span class="hl kwb">$net, $authentication, $o_when_network_is_up</span><span class="hl opt">);</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> set_raw <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$net, $authentication, $o_when_network_is_up</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>

    <span class="hl kwc">my</span> <span class="hl kwb">$when_network_is_up</span> <span class="hl opt">=</span> <span class="hl kwb">$o_when_network_is_up</span> <span class="hl opt">||</span> <span class="hl kwa">sub</span> <span class="hl opt">{</span> <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$f</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span> <span class="hl kwb">$f</span><span class="hl opt">-&gt;() };</span>

    enable_shadow<span class="hl opt">()</span> <span class="hl kwa">if</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>shadow<span class="hl opt">};</span>    

    <span class="hl kwc">my</span> <span class="hl kwb">$kind</span> <span class="hl opt">=</span> to_kind<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">);</span>

    <span class="hl kwc">log</span><span class="hl opt">::</span>l<span class="hl opt">(</span><span class="hl str">&quot;authentication::set</span> <span class="hl ipl">$kind</span><span class="hl str">&quot;</span><span class="hl opt">);</span>

    <span class="hl kwc">my</span> <span class="hl kwb">$pam_modules</span> <span class="hl opt">=</span> <span class="hl kwb">$kind2pam_kind</span><span class="hl opt">{</span><span class="hl kwb">$kind</span><span class="hl opt">}</span> <span class="hl kwc">or log</span><span class="hl opt">::</span>l<span class="hl opt">(</span><span class="hl str">&quot;kind2pam_kind does not know</span> <span class="hl ipl">$kind</span><span class="hl str">&quot;</span><span class="hl opt">);</span>
    <span class="hl kwb">$pam_modules</span> <span class="hl opt">||= [];</span>
    sshd_config_UsePAM<span class="hl opt">(</span><span class="hl kwb">&#64;$pam_modules</span> <span class="hl opt">&gt;</span> <span class="hl num">0</span><span class="hl opt">);</span>
    set_pam_authentication<span class="hl opt">(</span><span class="hl kwb">&#64;$pam_modules</span><span class="hl opt">);</span>

    <span class="hl kwc">my</span> <span class="hl kwb">$nsswitch</span> <span class="hl opt">=</span> <span class="hl kwb">$kind2nsswitch</span><span class="hl opt">{</span><span class="hl kwb">$kind</span><span class="hl opt">}</span> <span class="hl kwc">or log</span><span class="hl opt">::</span>l<span class="hl opt">(</span><span class="hl str">&quot;kind2nsswitch does not know</span> <span class="hl ipl">$kind</span><span class="hl str">&quot;</span><span class="hl opt">);</span>
    <span class="hl kwb">$nsswitch</span> <span class="hl opt">||= [];</span>
    set_nsswitch_priority<span class="hl opt">(</span><span class="hl kwb">&#64;$nsswitch</span><span class="hl opt">);</span>

    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;local&apos;</span><span class="hl opt">) {</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SmartCard&apos;</span><span class="hl opt">) {</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;LDAP&apos;</span><span class="hl opt">) {</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$domain</span> <span class="hl opt">=</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAPDOMAIN<span class="hl opt">} ||</span> <span class="hl kwa">do</span> <span class="hl opt">{</span>
	    <span class="hl kwc">my</span> <span class="hl kwb">$s</span> <span class="hl opt">=</span> run_program<span class="hl opt">::</span>rooted_get_stdout<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;ldapsearch&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;-x&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;-h&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAP_server<span class="hl opt">},</span> <span class="hl str">&apos;-b&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;-s&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;base&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;+&apos;</span><span class="hl opt">);</span>
	    first<span class="hl opt">(</span><span class="hl kwb">$s</span> <span class="hl opt">=~</span> <span class="hl kwd">/namingContexts: (.+)/</span><span class="hl opt">);</span>
	<span class="hl opt">}</span> <span class="hl kwc">or log</span><span class="hl opt">::</span>l<span class="hl opt">(</span><span class="hl str">&quot;no ldap domain found on server</span> <span class="hl ipl">$authentication</span><span class="hl str">-&gt;{LDAP_server}&quot;</span><span class="hl opt">),</span> <span class="hl kwa">return</span><span class="hl opt">;</span>

	update_ldap_conf<span class="hl opt">(</span>
			 host <span class="hl opt">=&gt;</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>LDAP_server<span class="hl opt">},</span>
			 base <span class="hl opt">=&gt;</span> <span class="hl kwb">$domain,</span>
			 nss_base_shadow <span class="hl opt">=&gt;</span> <span class="hl kwb">$domain</span> <span class="hl opt">.</span> <span class="hl str">&quot;?sub&quot;</span><span class="hl opt">,</span>
			 nss_base_passwd <span class="hl opt">=&gt;</span> <span class="hl kwb">$domain</span> <span class="hl opt">.</span> <span class="hl str">&quot;?sub&quot;</span><span class="hl opt">,</span>
			 nss_base_group <span class="hl opt">=&gt;</span> <span class="hl kwb">$domain</span> <span class="hl opt">.</span> <span class="hl str">&quot;?sub&quot;</span><span class="hl opt">,</span>
			<span class="hl opt">);</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;AD&apos;</span><span class="hl opt">) {</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$port</span> <span class="hl opt">=</span> <span class="hl str">&quot;389&quot;</span><span class="hl opt">;</span>
	
	<span class="hl kwc">my</span> <span class="hl kwb">$ssl</span> <span class="hl opt">= {</span> 
		   anonymous <span class="hl opt">=&gt;</span> <span class="hl str">&apos;off&apos;</span><span class="hl opt">,</span> 
		   simple <span class="hl opt">=&gt;</span> <span class="hl str">&apos;off&apos;</span><span class="hl opt">,</span> 
		   tls <span class="hl opt">=&gt;</span> <span class="hl str">&apos;start_tls&apos;</span><span class="hl opt">,</span>
		   ssl <span class="hl opt">=&gt;</span> <span class="hl str">&apos;on&apos;</span><span class="hl opt">,</span>
		   kerberos <span class="hl opt">=&gt;</span> <span class="hl str">&apos;off&apos;</span><span class="hl opt">,</span>
		  <span class="hl opt">}-&gt;{</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>sub_kind<span class="hl opt">}};</span>

	<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$ssl</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;on&apos;</span><span class="hl opt">) {</span>
		<span class="hl kwb">$port</span> <span class="hl opt">=</span> <span class="hl str">&apos;636&apos;</span><span class="hl opt">;</span>
	<span class="hl opt">}</span>
	
	
	
	update_ldap_conf<span class="hl opt">(</span>
			 host <span class="hl opt">=&gt;</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_server<span class="hl opt">},</span>
			 base <span class="hl opt">=&gt;</span> domain_to_ldap_domain<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">}),</span>
			 nss_base_shadow <span class="hl opt">=&gt;</span> <span class="hl str">&quot;</span><span class="hl ipl">$authentication</span><span class="hl str">-&gt;{AD_users_db}?sub&quot;</span><span class="hl opt">,</span>
			 nss_base_passwd <span class="hl opt">=&gt;</span> <span class="hl str">&quot;</span><span class="hl ipl">$authentication</span><span class="hl str">-&gt;{AD_users_db}?sub&quot;</span><span class="hl opt">,</span>
			 nss_base_group <span class="hl opt">=&gt;</span> <span class="hl str">&quot;</span><span class="hl ipl">$authentication</span><span class="hl str">-&gt;{AD_users_db}?sub&quot;</span><span class="hl opt">,</span>

			 ssl <span class="hl opt">=&gt;</span> <span class="hl kwb">$ssl,</span>
			 sasl_mech <span class="hl opt">=&gt;</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>sub_kind<span class="hl opt">}</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;kerberos&apos;</span> ? <span class="hl str">&apos;GSSAPI&apos;</span> <span class="hl opt">:</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
			 port <span class="hl opt">=&gt;</span> <span class="hl kwb">$port,</span>

			 binddn <span class="hl opt">=&gt;</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_user<span class="hl opt">},</span>
			 bindpw <span class="hl opt">=&gt;</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_password<span class="hl opt">},</span>

			 <span class="hl opt">(</span>map_each <span class="hl opt">{</span> <span class="hl str">&quot;nss_map_objectclass_$::a&quot;</span> <span class="hl opt">=&gt; $::</span>b <span class="hl opt">}</span>
			  posixAccount <span class="hl opt">=&gt;</span> <span class="hl str">&apos;User&apos;</span><span class="hl opt">,</span>
			  shadowAccount <span class="hl opt">=&gt;</span> <span class="hl str">&apos;User&apos;</span><span class="hl opt">,</span>
			  posixGroup <span class="hl opt">=&gt;</span> <span class="hl str">&apos;Group&apos;</span><span class="hl opt">,</span>
			 <span class="hl opt">),</span>


			 scope <span class="hl opt">=&gt;</span> <span class="hl str">&apos;sub&apos;</span><span class="hl opt">,</span>
			 pam_login_attribute <span class="hl opt">=&gt;</span> <span class="hl str">&apos;sAMAccountName&apos;</span><span class="hl opt">,</span>
			 pam_filter <span class="hl opt">=&gt;</span> <span class="hl str">&apos;objectclass=User&apos;</span><span class="hl opt">,</span>
			 pam_password <span class="hl opt">=&gt;</span> <span class="hl str">&apos;ad&apos;</span><span class="hl opt">,</span>

			 
			 <span class="hl opt">(</span>map_each <span class="hl opt">{</span> <span class="hl str">&quot;nss_map_attribute_$::a&quot;</span> <span class="hl opt">=&gt; $::</span>b <span class="hl opt">}</span>
			  uid <span class="hl opt">=&gt;</span> <span class="hl str">&apos;sAMAccountName&apos;</span><span class="hl opt">,</span>
			  uidNumber <span class="hl opt">=&gt;</span> <span class="hl str">&apos;msSFU30UidNumber&apos;</span><span class="hl opt">,</span>
			  gidNumber <span class="hl opt">=&gt;</span> <span class="hl str">&apos;msSFU30GidNumber&apos;</span><span class="hl opt">,</span>
			  cn <span class="hl opt">=&gt;</span> <span class="hl str">&apos;sAMAccountName&apos;</span><span class="hl opt">,</span>
			  uniqueMember <span class="hl opt">=&gt;</span> <span class="hl str">&apos;member&apos;</span><span class="hl opt">,</span>
			  userPassword <span class="hl opt">=&gt;</span> <span class="hl str">&apos;msSFU30Password&apos;</span><span class="hl opt">,</span>
			  homeDirectory <span class="hl opt">=&gt;</span> <span class="hl str">&apos;msSFU30HomeDirectory&apos;</span><span class="hl opt">,</span>
			  loginShell <span class="hl opt">=&gt;</span> <span class="hl str">&apos;msSFU30LoginShell&apos;</span><span class="hl opt">,</span>
			  gecos <span class="hl opt">=&gt;</span> <span class="hl str">&apos;name&apos;</span><span class="hl opt">,</span>
			 <span class="hl opt">),</span>
			<span class="hl opt">);</span>

	configure_krb5_for_AD<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">);</span>

    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;NIS&apos;</span><span class="hl opt">) {</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$domain</span> <span class="hl opt">=</span> <span class="hl kwb">$net</span><span class="hl opt">-&gt;{</span>network<span class="hl opt">}{</span>NISDOMAIN<span class="hl opt">};</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$NIS_server</span> <span class="hl opt">=</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>NIS_server<span class="hl opt">};</span>
	<span class="hl kwb">$domain</span> <span class="hl opt">||</span> <span class="hl kwb">$NIS_server</span> <span class="hl kwc">ne</span> <span class="hl str">&quot;broadcast&quot;</span> <span class="hl kwc">or die</span> N<span class="hl opt">(</span><span class="hl str">&quot;Can not use broadcast with no NIS domain&quot;</span><span class="hl opt">);</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$t</span> <span class="hl opt">=</span> <span class="hl kwb">$domain</span> ? 
	  <span class="hl opt">(</span><span class="hl kwb">$NIS_server</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;broadcast&apos;</span> ? 
	     <span class="hl str">&quot;domain</span> <span class="hl ipl">$domain</span> <span class="hl str">broadcast&quot;</span> <span class="hl opt">:</span> 
	     <span class="hl str">&quot;domain</span> <span class="hl ipl">$domain</span> <span class="hl str">server</span> <span class="hl ipl">$NIS_server</span><span class="hl str">&quot;</span><span class="hl opt">) :</span>
	     <span class="hl str">&quot;server</span> <span class="hl ipl">$NIS_server</span><span class="hl str">&quot;</span><span class="hl opt">;</span>

	substInFile <span class="hl opt">{</span>
	    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwd">/^#/</span><span class="hl opt">) {</span>
		<span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl str">&apos;&apos;</span> <span class="hl kwa">if</span> <span class="hl kwd">/^#\Q[PREVIOUS]/</span><span class="hl opt">;</span>
	    <span class="hl opt">}</span> <span class="hl kwa">else</span> <span class="hl opt">{</span>
		<span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl str">&quot;#[PREVIOUS]</span> <span class="hl ipl">$_</span><span class="hl str">&quot;</span><span class="hl opt">;</span>
	    <span class="hl opt">}</span>
	    <span class="hl kwb">$_</span> <span class="hl opt">.=</span> <span class="hl str">&quot;</span><span class="hl ipl">$t\n</span><span class="hl str">&quot;</span> <span class="hl kwa">if</span> <span class="hl kwc">eof</span><span class="hl opt">;</span>
	<span class="hl opt">}</span> <span class="hl str">&quot;$::prefix/etc/yp.conf&quot;</span><span class="hl opt">;</span>

	<span class="hl slc">#- no need to modify system-auth for nis</span>

	<span class="hl kwb">$when_network_is_up</span><span class="hl opt">-&gt;(</span><span class="hl kwa">sub</span> <span class="hl opt">{</span>
	    run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;nisdomainname&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$domain</span><span class="hl opt">);</span>
	    run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;service&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;ypbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;restart&apos;</span><span class="hl opt">);</span>
	<span class="hl opt">});</span>
<span class="hl slc">#    } elsif ($kind eq &apos;winbind&apos; || $kind eq &apos;AD&apos; &amp;&amp; $authentication-&gt;{subkind} eq &apos;winbind&apos;) {</span>

    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;winbind&apos;</span><span class="hl opt">) {</span>

	<span class="hl kwc">my</span> <span class="hl kwb">$domain</span> <span class="hl opt">=</span> <span class="hl kwc">uc</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>WINDOMAIN<span class="hl opt">};</span>
	
	<span class="hl kwa">require</span> fs<span class="hl opt">::</span>remote<span class="hl opt">::</span>smb<span class="hl opt">;</span>
	fs<span class="hl opt">::</span>remote<span class="hl opt">::</span>smb<span class="hl opt">::</span>write_smb_conf<span class="hl opt">(</span><span class="hl kwb">$domain</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&quot;chkconfig&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;--level&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;35&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;winbind&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;on&quot;</span><span class="hl opt">);</span>
	mkdir_p<span class="hl opt">(</span><span class="hl str">&quot;$::prefix/home/</span><span class="hl ipl">$domain</span><span class="hl str">&quot;</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;service&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;smb&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;restart&apos;</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;service&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;winbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;restart&apos;</span><span class="hl opt">);</span>
	
	<span class="hl slc">#- defer running smbpassword until the network is up</span>

	<span class="hl kwb">$when_network_is_up</span><span class="hl opt">-&gt;(</span><span class="hl kwa">sub</span> <span class="hl opt">{</span>
	    run_program<span class="hl opt">::</span>raw<span class="hl opt">({</span> root <span class="hl opt">=&gt; $::</span>prefix<span class="hl opt">,</span> sensitive_arguments <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span>
			     <span class="hl str">&apos;net&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;join&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$domain,</span> <span class="hl str">&apos;-U&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winuser<span class="hl opt">} .</span> <span class="hl str">&apos;%&apos;</span> <span class="hl opt">.</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winpass<span class="hl opt">});</span>
	<span class="hl opt">});</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$kind</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;SMBKRB&apos;</span><span class="hl opt">) {</span>
	 <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_server<span class="hl opt">} ||=</span> <span class="hl str">&apos;ads.&apos;</span> <span class="hl opt">.</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">};</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$domain</span> <span class="hl opt">=</span> <span class="hl kwc">uc</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>WINDOMAIN<span class="hl opt">};</span>
	<span class="hl kwc">my</span> <span class="hl kwb">$realm</span> <span class="hl opt">=</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_domain<span class="hl opt">};</span>

	configure_krb5_for_AD<span class="hl opt">(</span><span class="hl kwb">$authentication</span><span class="hl opt">);</span>
		
	<span class="hl kwa">require</span> fs<span class="hl opt">::</span>remote<span class="hl opt">::</span>smb<span class="hl opt">;</span>
	fs<span class="hl opt">::</span>remote<span class="hl opt">::</span>smb<span class="hl opt">::</span>write_smb_ads_conf<span class="hl opt">(</span><span class="hl kwb">$domain,$realm</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&quot;chkconfig&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;--level&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;35&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;winbind&quot;</span><span class="hl opt">,</span> <span class="hl str">&quot;on&quot;</span><span class="hl opt">);</span>
	mkdir_p<span class="hl opt">(</span><span class="hl str">&quot;$::prefix/home/</span><span class="hl ipl">$domain</span><span class="hl str">&quot;</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;net&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;time&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;set&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;-S&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>AD_server<span class="hl opt">});</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;service&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;smb&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;restart&apos;</span><span class="hl opt">);</span>
	run_program<span class="hl opt">::</span>rooted<span class="hl opt">($::</span>prefix<span class="hl opt">,</span> <span class="hl str">&apos;service&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;winbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;restart&apos;</span><span class="hl opt">);</span>
	
	<span class="hl kwb">$when_network_is_up</span><span class="hl opt">-&gt;(</span><span class="hl kwa">sub</span> <span class="hl opt">{</span>
	    run_program<span class="hl opt">::</span>raw<span class="hl opt">({</span> root <span class="hl opt">=&gt; $::</span>prefix<span class="hl opt">,</span> sensitive_arguments <span class="hl opt">=&gt;</span> <span class="hl num">1</span> <span class="hl opt">},</span> 
			     <span class="hl str">&apos;net&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;ads&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;join&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;-U&apos;</span><span class="hl opt">,</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winuser<span class="hl opt">} .</span> <span class="hl str">&apos;%&apos;</span> <span class="hl opt">.</span> <span class="hl kwb">$authentication</span><span class="hl opt">-&gt;{</span>winpass<span class="hl opt">});</span>
	<span class="hl opt">});</span>
    <span class="hl opt">}</span>
    <span class="hl num">1</span><span class="hl opt">;</span>
<span class="hl opt">}</span>


<span class="hl kwa">sub</span> pam_modules<span class="hl opt">() {</span>
    <span class="hl str">&apos;pam_ldap&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_castella&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_winbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_krb5&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_mkhomedir&apos;</span><span class="hl opt">;</span>
<span class="hl opt">}</span>
<span class="hl kwa">sub</span> pam_module_from_path <span class="hl opt">{</span> 
    <span class="hl kwb">$_</span><span class="hl opt">[</span><span class="hl num">0</span><span class="hl opt">] &amp;&amp;</span> <span class="hl kwb">$_</span><span class="hl opt">[</span><span class="hl num">0</span><span class="hl opt">] =~</span> m<span class="hl opt">|(</span><span class="hl kwd">/lib/s</span>ecurity<span class="hl opt">/)</span>?<span class="hl opt">(</span>pam_<span class="hl opt">.*)</span>\<span class="hl opt">.</span>so<span class="hl opt">| &amp;&amp;</span> <span class="hl kwb">$2</span><span class="hl opt">;</span>
<span class="hl opt">}</span>
<span class="hl kwa">sub</span> pam_module_to_path <span class="hl opt">{</span> 
    <span class="hl str">&quot;</span><span class="hl ipl">$_</span><span class="hl str">[0].so&quot;</span><span class="hl opt">;</span>
<span class="hl opt">}</span>
<span class="hl kwa">sub</span> pam_format_line <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$type, $control, $module, &#64;para</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwc">sprintf</span><span class="hl opt">(</span><span class="hl str">&quot;%-11s %-13s</span> <span class="hl ipl">%s\n</span><span class="hl str">&quot;</span><span class="hl opt">,</span> <span class="hl kwb">$type, $control,</span> <span class="hl kwc">join</span><span class="hl opt">(</span><span class="hl str">&apos; &apos;</span><span class="hl opt">,</span> pam_module_to_path<span class="hl opt">(</span><span class="hl kwb">$module</span><span class="hl opt">),</span> <span class="hl kwb">&#64;para</span><span class="hl opt">));</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> get_raw_pam_authentication<span class="hl opt">() {</span>
    <span class="hl kwc">my</span> <span class="hl kwb">%before_deny</span><span class="hl opt">;</span>
    <span class="hl kwa">foreach</span> <span class="hl opt">(</span>cat_<span class="hl opt">(</span><span class="hl str">&quot;$::prefix/etc/pam.d/system-auth&quot;</span><span class="hl opt">)) {</span>
	<span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$type, $control, $module, &#64;para</span><span class="hl opt">) =</span> <span class="hl kwc">split</span><span class="hl opt">;</span>
	<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$module</span> <span class="hl opt">=</span> pam_module_from_path<span class="hl opt">(</span><span class="hl kwb">$module</span><span class="hl opt">)) {</span>
	    <span class="hl kwb">$before_deny</span><span class="hl opt">{</span><span class="hl kwb">$type</span><span class="hl opt">}{</span><span class="hl kwb">$module</span><span class="hl opt">} =</span> \<span class="hl kwb">&#64;para</span> <span class="hl kwa">if</span> <span class="hl kwb">$control</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;sufficient&apos;</span> <span class="hl opt">&amp;&amp;</span> member<span class="hl opt">(</span><span class="hl kwb">$module,</span> pam_modules<span class="hl opt">());</span>
	<span class="hl opt">}</span>
    <span class="hl opt">}</span>
    \<span class="hl kwb">%before_deny</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> get_pam_authentication_kinds<span class="hl opt">() {</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$before_deny</span> <span class="hl opt">=</span> get_raw_pam_authentication<span class="hl opt">();</span>
    <span class="hl kwc">map</span> <span class="hl opt">{</span> <span class="hl kwd">s/pam_//</span><span class="hl opt">;</span> <span class="hl kwb">$_</span> <span class="hl opt">}</span> <span class="hl kwc">keys</span> <span class="hl opt">%{</span><span class="hl kwb">$before_deny</span><span class="hl opt">-&gt;{</span>auth<span class="hl opt">}};</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> set_pam_authentication <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">&#64;authentication_kinds</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    
    <span class="hl kwc">my</span> <span class="hl kwb">%special</span> <span class="hl opt">= (</span>
	auth <span class="hl opt">=&gt; [</span> difference2<span class="hl opt">(</span>\<span class="hl kwb">&#64;authentication_kinds,,</span> <span class="hl opt">[</span> <span class="hl str">&apos;mount&apos;</span> <span class="hl opt">]) ],</span>
	account <span class="hl opt">=&gt; [</span> difference2<span class="hl opt">(</span>\<span class="hl kwb">&#64;authentication_kinds,</span> <span class="hl opt">[</span> <span class="hl str">&apos;castella&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;mount&apos;</span> <span class="hl opt">]) ],</span>
	password <span class="hl opt">=&gt; [</span> intersection<span class="hl opt">(</span>\<span class="hl kwb">&#64;authentication_kinds,</span> <span class="hl opt">[</span> <span class="hl str">&apos;ldap&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;krb5&apos;</span> <span class="hl opt">]) ],</span>
    <span class="hl opt">);</span>
    <span class="hl kwc">my</span> <span class="hl kwb">%before_first</span> <span class="hl opt">= (</span>
	auth <span class="hl opt">=&gt;</span> member<span class="hl opt">(</span><span class="hl str">&apos;mount&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;authentication_kinds</span><span class="hl opt">)</span> ? pam_format_line<span class="hl opt">(</span><span class="hl str">&apos;auth&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;required&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_mount&apos;</span><span class="hl opt">) :</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
	session <span class="hl opt">=&gt;</span> 
	  intersection<span class="hl opt">(</span>\<span class="hl kwb">&#64;authentication_kinds,</span> <span class="hl opt">[</span> <span class="hl str">&apos;winbind&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;krb5&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;ldap&apos;</span> <span class="hl opt">])</span> 
	    ? pam_format_line<span class="hl opt">(</span><span class="hl str">&apos;session&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;optional&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_mkhomedir&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;skel=/etc/skel/&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;umask=0022&apos;</span><span class="hl opt">) :</span>
	  member<span class="hl opt">(</span><span class="hl str">&apos;castella&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;authentication_kinds</span><span class="hl opt">)</span>
	    ? pam_format_line<span class="hl opt">(</span><span class="hl str">&apos;session&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;optional&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_castella&apos;</span><span class="hl opt">) :</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
    <span class="hl opt">);</span>
    <span class="hl kwc">my</span> <span class="hl kwb">%after_deny</span> <span class="hl opt">= (</span>
	session <span class="hl opt">=&gt;</span>
          member<span class="hl opt">(</span><span class="hl str">&apos;krb5&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;authentication_kinds</span><span class="hl opt">)</span>
            ? pam_format_line<span class="hl opt">(</span><span class="hl str">&apos;session&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;optional&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_krb5&apos;</span><span class="hl opt">) :</span>
          member<span class="hl opt">(</span><span class="hl str">&apos;mount&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;authentication_kinds</span><span class="hl opt">)</span>
            ? pam_format_line<span class="hl opt">(</span><span class="hl str">&apos;session&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;optional&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_mount&apos;</span><span class="hl opt">) :</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">,</span>
    <span class="hl opt">);</span>

    substInFile <span class="hl opt">{</span>
	<span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$type, $control, $module, &#64;para</span><span class="hl opt">) =</span> <span class="hl kwc">split</span><span class="hl opt">;</span>
	<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$module</span> <span class="hl opt">=</span> pam_module_from_path<span class="hl opt">(</span><span class="hl kwb">$module</span><span class="hl opt">)) {</span>
	    <span class="hl kwa">if</span> <span class="hl opt">(</span>member<span class="hl opt">(</span><span class="hl kwb">$module,</span> pam_modules<span class="hl opt">())) {</span>
		<span class="hl slc">#- first removing previous config</span>
		<span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl str">&apos;&apos;</span><span class="hl opt">;</span>
	    <span class="hl opt">}</span>
	    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$module</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;pam_unix&apos;</span> <span class="hl opt">&amp;&amp;</span> <span class="hl kwb">$special</span><span class="hl opt">{</span><span class="hl kwb">$type</span><span class="hl opt">}) {</span>
		<span class="hl kwc">my</span> <span class="hl kwb">&#64;para_for_last</span> <span class="hl opt">=</span> 
		    member<span class="hl opt">(</span><span class="hl kwb">$type,</span> <span class="hl str">&apos;auth&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;account&apos;</span><span class="hl opt">)</span> ? <span class="hl str">qw(use_first_pass)</span> <span class="hl opt">: &#64;{[]};</span>
		<span class="hl kwb">&#64;para</span> <span class="hl opt">=</span> difference2<span class="hl opt">(</span>\<span class="hl kwb">&#64;para,</span> \<span class="hl kwb">&#64;para_for_last</span><span class="hl opt">);</span>

		<span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$before_noask, $ask</span><span class="hl opt">) =</span> partition <span class="hl opt">{</span> <span class="hl kwb">$_</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;castella&apos;</span> <span class="hl opt">} &#64;{</span><span class="hl kwb">$special</span><span class="hl opt">{</span><span class="hl kwb">$type</span><span class="hl opt">}};</span>
		<span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$before, $after</span><span class="hl opt">) =</span> partition <span class="hl opt">{</span> <span class="hl kwb">$_</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;krb5&apos;</span> <span class="hl opt">}</span> <span class="hl kwb">&#64;$ask</span><span class="hl opt">;</span>

		<span class="hl kwa">if</span> <span class="hl opt">(!</span><span class="hl kwb">&#64;$ask</span><span class="hl opt">) {</span>
		    <span class="hl kwb">&#64;para_for_last</span> <span class="hl opt">=</span> <span class="hl kwc">grep</span> <span class="hl opt">{</span> <span class="hl kwb">$_</span> <span class="hl kwc">ne</span> <span class="hl str">&apos;use_first_pass&apos;</span> <span class="hl opt">}</span> <span class="hl kwb">&#64;para_for_last</span><span class="hl opt">;</span>
		<span class="hl opt">}</span>

		<span class="hl kwc">my</span> <span class="hl kwb">&#64;l</span> <span class="hl opt">= ((</span><span class="hl kwc">map</span> <span class="hl opt">{ [</span> <span class="hl str">&quot;pam_</span><span class="hl ipl">$_</span><span class="hl str">&quot;</span> <span class="hl opt">] }</span> <span class="hl kwb">&#64;$before_noask, &#64;$before</span><span class="hl opt">),</span>
			 <span class="hl opt">[</span> <span class="hl str">&apos;pam_unix&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;para</span> <span class="hl opt">],</span>
			 <span class="hl opt">(</span><span class="hl kwc">map</span> <span class="hl opt">{ [</span> <span class="hl str">&quot;pam_</span><span class="hl ipl">$_</span><span class="hl str">&quot;</span> <span class="hl opt">] }</span> <span class="hl kwb">&#64;$after</span><span class="hl opt">),</span>
			 <span class="hl opt">);</span>
		<span class="hl kwc">push</span> <span class="hl opt">&#64;{</span><span class="hl kwb">$l</span><span class="hl opt">[-</span><span class="hl num">1</span><span class="hl opt">]},</span> <span class="hl kwb">&#64;para_for_last</span><span class="hl opt">;</span>
		<span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl kwc">join</span><span class="hl opt">(</span><span class="hl str">&apos;&apos;</span><span class="hl opt">,</span> <span class="hl kwc">map</span> <span class="hl opt">{</span> pam_format_line<span class="hl opt">(</span><span class="hl kwb">$type,</span> <span class="hl str">&apos;sufficient&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;$_</span><span class="hl opt">) }</span> <span class="hl kwb">&#64;l</span><span class="hl opt">);</span>

		<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$control</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;required&apos;</span><span class="hl opt">) {</span>
		    <span class="hl slc">#- ensure a pam_deny line is there</span>
		    <span class="hl opt">(</span><span class="hl kwb">$control, $module, &#64;para</span><span class="hl opt">) = (</span><span class="hl str">&apos;required&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_deny&apos;</span><span class="hl opt">);</span>
		    <span class="hl kwb">$_</span> <span class="hl opt">.=</span> pam_format_line<span class="hl opt">(</span><span class="hl kwb">$type, $control, $module</span><span class="hl opt">);</span>
		<span class="hl opt">}</span>
	    <span class="hl opt">}</span>
	    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl kwb">$s</span> <span class="hl opt">=</span> <span class="hl kwc">delete</span> <span class="hl kwb">$before_first</span><span class="hl opt">{</span><span class="hl kwb">$type</span><span class="hl opt">}) {</span>
		<span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl kwb">$s</span> <span class="hl opt">.</span> <span class="hl kwb">$_</span><span class="hl opt">;</span>
	    <span class="hl opt">}</span>
	    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$control</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;required&apos;</span> <span class="hl opt">&amp;&amp;</span> member<span class="hl opt">(</span><span class="hl kwb">$module,</span> <span class="hl str">&apos;pam_deny&apos;</span><span class="hl opt">,</span> <span class="hl str">&apos;pam_unix&apos;</span><span class="hl opt">)) {</span>
		<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl kwb">$s</span> <span class="hl opt">=</span> <span class="hl kwc">delete</span> <span class="hl kwb">$after_deny</span><span class="hl opt">{</span><span class="hl kwb">$type</span><span class="hl opt">}) {</span>
		    <span class="hl kwb">$_</span> <span class="hl opt">.=</span> <span class="hl kwb">$s</span><span class="hl opt">;</span>
		<span class="hl opt">}</span>
	    <span class="hl opt">}</span>
	<span class="hl opt">}</span>
    <span class="hl opt">}</span> <span class="hl str">&quot;$::prefix/etc/pam.d/system-auth&quot;</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> set_nsswitch_priority <span class="hl opt">{</span>
    <span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">&#64;kinds</span><span class="hl opt">) =</span> <span class="hl kwb">&#64;_</span><span class="hl opt">;</span>
    <span class="hl kwc">my</span> <span class="hl kwb">&#64;known</span> <span class="hl opt">=</span> <span class="hl str">qw(nis ldap winbind)</span><span class="hl opt">;</span>
    substInFile <span class="hl opt">{</span>
	<span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwc">my</span> <span class="hl opt">(</span><span class="hl kwb">$database, $l</span><span class="hl opt">) =</span> <span class="hl kwd">/^(\s*(?:passwd|shadow|group|automount):\s*)(.*)/</span><span class="hl opt">) {</span>
	    <span class="hl kwc">my</span> <span class="hl kwb">&#64;l</span> <span class="hl opt">=</span> difference2<span class="hl opt">([</span> <span class="hl kwc">split</span><span class="hl opt">(</span><span class="hl str">&apos; &apos;</span><span class="hl opt">,</span> <span class="hl kwb">$l</span><span class="hl opt">) ],</span> \<span class="hl kwb">&#64;known</span><span class="hl opt">);</span>
	    <span class="hl kwb">$_</span> <span class="hl opt">=</span> <span class="hl kwb">$database</span> <span class="hl opt">.</span> <span class="hl kwc">join</span><span class="hl opt">(</span><span class="hl str">&apos; &apos;</span><span class="hl opt">,</span> uniq<span class="hl opt">(</span><span class="hl str">&apos;files&apos;</span><span class="hl opt">,</span> <span class="hl kwb">&#64;kinds, &#64;l</span><span class="hl opt">)) .</span> <span class="hl str">&quot;</span><span class="hl esc">\n</span><span class="hl str">&quot;</span><span class="hl opt">;</span>
	<span class="hl opt">}</span>	
    <span class="hl opt">}</span> <span class="hl str">&quot;$::prefix/etc/nsswitch.conf&quot;</span><span class="hl opt">;</span>
<span class="hl opt">}</span>

<span class="hl kwa">sub</span> read_yp_conf<span class="hl opt">() {</span>
    <span class="hl kwc">my</span> <span class="hl kwb">$yp_conf</span> <span class="hl opt">=</span> cat_<span class="hl opt">(</span><span class="hl str">&quot;$::prefix/etc/yp.conf&quot;</span><span class="hl opt">);</span>
    
    <span class="hl kwa">if</span> <span class="hl opt">(</span><span class="hl kwb">$yp_conf</span> <span class="hl opt">=~</span> <span class="hl kwd">/^domain\s+(\S+)\s+(\S+)\s*(.*)/m</span><span class="hl opt">) {</span>
	<span class="hl opt">{</span> domain <span class="hl opt">=&gt;</span> <span class="hl kwb">$1,</span> server <span class="hl opt">=&gt;</span> <span class="hl kwb">$2</span> <span class="hl kwc">eq</span> <span class="hl str">&apos;broadcast&apos;</span> ? <span class="hl str">&apos;broadcast&apos;</span> <span class="hl opt">:</span> <span class="hl kwb">$3</span> <span class="hl opt">};</span>
    <span class="hl opt">}</span> <span class="hl kwa">elsif</span> <span class="hl opt">(</span><span class="hl kwb">$yp_conf</span> <span class="hl opt">=~</span> <span class="hl kwd">/^server\s+(.*)/m</span><span class="hl opt">) {</span>
	<span class="hl opt">{</span> server <span class="hl opt">=&gt;</span> <span class="hl kwb">$1</span> <span class="hl opt">};</span>
    <span class="hl opt">}</span> <span class="hl kwa">else</span> <span class="hl opt">{</span>
	<span class="hl kwc">undef</span><span class="hl opt">;</span>
    <span class="hl opt">}</span>    
<span class="hl opt">}</span>