From 3edc8683807dfa809e57c6b9c4fd2bf2f2f13483 Mon Sep 17 00:00:00 2001 From: Bitnami Bot Date: Tue, 26 May 2026 17:05:42 +0200 Subject: [PATCH] [bitnami/openldap] Release 2.6.13-debian-12-r6 (#94007) Signed-off-by: Bitnami Bot --- bitnami/openldap/2.6/debian-12/Dockerfile | 12 +++--- ...6.13-0-linux-amd64-debian-12.tar.gz.sha256 | 1 + ...6.13-0-linux-arm64-debian-12.tar.gz.sha256 | 1 + .../prebuildfs/opt/bitnami/scripts/libfile.sh | 37 +++++++++++++++++++ .../rootfs/opt/bitnami/scripts/libopenldap.sh | 37 +++++++++++++++---- 5 files changed, 75 insertions(+), 13 deletions(-) create mode 100644 bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-amd64-debian-12.tar.gz.sha256 create mode 100644 bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-arm64-debian-12.tar.gz.sha256 diff --git a/bitnami/openldap/2.6/debian-12/Dockerfile b/bitnami/openldap/2.6/debian-12/Dockerfile index 3e05fa806c91..65d2d0f5b6c9 100644 --- a/bitnami/openldap/2.6/debian-12/Dockerfile +++ b/bitnami/openldap/2.6/debian-12/Dockerfile @@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith" ARG TARGETARCH LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \ - org.opencontainers.image.created="2026-05-23T10:04:57Z" \ + org.opencontainers.image.created="2026-05-26T14:56:46Z" \ org.opencontainers.image.description="Application packaged by Broadcom, Inc." \ org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/openldap/README.md" \ org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/openldap" \ @@ -33,12 +33,12 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \ for COMPONENT in "${COMPONENTS[@]}"; do \ if [ ! -f "${COMPONENT}.tar.gz" ]; then \ curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz" -O ; \ - curl -SsLf "https://${DOWNLOADS_URL}/${COMPONENT}.tar.gz.sha256" -O ; \ fi ; \ - sha256sum -c "${COMPONENT}.tar.gz.sha256" ; \ + sha256sum -c "/opt/bitnami/checksums/${COMPONENT}.tar.gz.sha256" ; \ tar -zxf "${COMPONENT}.tar.gz" -C /opt/bitnami --strip-components=2 --no-same-owner ; \ - rm -rf "${COMPONENT}".tar.gz{,.sha256} ; \ - done + rm -rf "${COMPONENT}".tar.gz ; \ + done ; \ + rm -rf /opt/bitnami/checksums ; RUN apt-get update && apt-get upgrade -y && \ apt-get clean && rm -rf /var/lib/apt/lists /var/cache/apt/archives RUN chmod g+rwX /opt/bitnami @@ -49,7 +49,7 @@ COPY rootfs / RUN /opt/bitnami/scripts/openldap/postunpack.sh ENV APP_VERSION="2.6.13" \ BITNAMI_APP_NAME="openldap" \ - IMAGE_REVISION="5" \ + IMAGE_REVISION="6" \ PATH="/opt/bitnami/openldap/bin:/opt/bitnami/openldap/sbin:$PATH" EXPOSE 1389 1636 diff --git a/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-amd64-debian-12.tar.gz.sha256 b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-amd64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..68ae2e68e0a6 --- /dev/null +++ b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-amd64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +4dae198c9cc1cf89ed874d2f10fb6de61396548d54b470197c47ae8cfaaba76b openldap-2.6.13-0-linux-amd64-debian-12.tar.gz diff --git a/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-arm64-debian-12.tar.gz.sha256 b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-arm64-debian-12.tar.gz.sha256 new file mode 100644 index 000000000000..99e04099431f --- /dev/null +++ b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/checksums/openldap-2.6.13-0-linux-arm64-debian-12.tar.gz.sha256 @@ -0,0 +1 @@ +77c330297160c10be9165991dd27f10500046cb5149d516feec052dbe90390d1 openldap-2.6.13-0-linux-arm64-debian-12.tar.gz diff --git a/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh index 1c69e0e48a5d..335c1c7c9ef7 100644 --- a/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh +++ b/bitnami/openldap/2.6/debian-12/prebuildfs/opt/bitnami/scripts/libfile.sh @@ -139,3 +139,40 @@ wait_for_log_entry() { return 1 fi } + +######################## +# Creates a secure temporary file containing the provided secret +# Arguments: +# $1 - secret to write to the temporary file +# Returns: +# String +######################### +credential_to_temp_file() { + local secret="$1" + local tmp_file + + # Use mktemp with a specific prefix for easier debugging if something lingers + if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then + echo "Error: Failed to create temp file" >&2 + return 1 + fi + + # Restrict permissions before writing the secret + chmod 0600 "$tmp_file" + # Write secret and ensure it's flushed to disk + printf "%s" "$secret" > "$tmp_file" + # Output the filename so the caller can capture it + echo "$tmp_file" +} + +######################## +# Cleans up temporary files created by credential_to_temp_file +# Arguments: +# None +# Returns: +# None +######################### +cleanup_credentials() { + debug "Cleaning up temporary files containing credentials" + rm -rf "${TMPDIR:-/tmp}"/at.cred.* +} diff --git a/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh b/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh index 37756a5909b0..3c958823d5bc 100644 --- a/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh +++ b/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh @@ -59,11 +59,11 @@ export LDAP_ROOT="${LDAP_ROOT:-dc=example,dc=org}" export LDAP_SUFFIX="$(if [ -z "${LDAP_SUFFIX+x}" ]; then echo "${LDAP_ROOT}"; else echo "${LDAP_SUFFIX}"; fi)" export LDAP_ADMIN_USERNAME="${LDAP_ADMIN_USERNAME:-admin}" export LDAP_ADMIN_DN="${LDAP_ADMIN_USERNAME/#/cn=},${LDAP_ROOT}" -export LDAP_ADMIN_PASSWORD="${LDAP_ADMIN_PASSWORD:-adminpassword}" +export LDAP_ADMIN_PASSWORD="${LDAP_ADMIN_PASSWORD:-}" export LDAP_CONFIG_ADMIN_ENABLED="${LDAP_CONFIG_ADMIN_ENABLED:-no}" export LDAP_CONFIG_ADMIN_USERNAME="${LDAP_CONFIG_ADMIN_USERNAME:-admin}" export LDAP_CONFIG_ADMIN_DN="${LDAP_CONFIG_ADMIN_USERNAME/#/cn=},cn=config" -export LDAP_CONFIG_ADMIN_PASSWORD="${LDAP_CONFIG_ADMIN_PASSWORD:-configpassword}" +export LDAP_CONFIG_ADMIN_PASSWORD="${LDAP_CONFIG_ADMIN_PASSWORD:-}" export LDAP_ADD_SCHEMAS="${LDAP_ADD_SCHEMAS:-yes}" export LDAP_EXTRA_SCHEMAS="${LDAP_EXTRA_SCHEMAS:-cosine,inetorgperson,nis}" export LDAP_SKIP_DEFAULT_TREE="${LDAP_SKIP_DEFAULT_TREE:-no}" @@ -76,7 +76,7 @@ export LDAP_GROUP="${LDAP_GROUP:-readers}" export LDAP_ENABLE_TLS="${LDAP_ENABLE_TLS:-no}" export LDAP_REQUIRE_TLS="${LDAP_REQUIRE_TLS:-no}" export LDAP_ULIMIT_NOFILES="${LDAP_ULIMIT_NOFILES:-1024}" -export LDAP_ALLOW_ANON_BINDING="${LDAP_ALLOW_ANON_BINDING:-yes}" +export LDAP_ALLOW_ANON_BINDING="${LDAP_ALLOW_ANON_BINDING:-no}" export LDAP_LOGLEVEL="${LDAP_LOGLEVEL:-256}" export LDAP_PASSWORD_HASH="${LDAP_PASSWORD_HASH:-{SSHA\}}" export LDAP_CONFIGURE_PPOLICY="${LDAP_CONFIGURE_PPOLICY:-no}" @@ -91,7 +91,7 @@ export LDAP_ACCESSLOG_LOGOLD="${LDAP_ACCESSLOG_LOGOLD:-(objectClass=*)}" export LDAP_ACCESSLOG_LOGOLDATTR="${LDAP_ACCESSLOG_LOGOLDATTR:-objectClass}" export LDAP_ACCESSLOG_ADMIN_USERNAME="${LDAP_ACCESSLOG_ADMIN_USERNAME:-admin}" export LDAP_ACCESSLOG_ADMIN_DN="${LDAP_ACCESSLOG_ADMIN_USERNAME/#/cn=},${LDAP_ACCESSLOG_DB:-cn=accesslog}" -export LDAP_ACCESSLOG_ADMIN_PASSWORD="${LDAP_ACCESSLOG_PASSWORD:-accesspassword}" +export LDAP_ACCESSLOG_ADMIN_PASSWORD="${LDAP_ACCESSLOG_PASSWORD:-}" export LDAP_ENABLE_SYNCPROV="${LDAP_ENABLE_SYNCPROV:-no}" export LDAP_SYNCPROV_CHECKPPOINT="${LDAP_SYNCPROV_CHECKPPOINT:-100 10}" export LDAP_SYNCPROV_SESSIONLOG="${LDAP_SYNCPROV_SESSIONLOG:-100}" @@ -141,6 +141,12 @@ ldap_validate() { error "$1" error_code=1 } + check_empty_value() { + if is_empty_value "${!1}"; then + print_validation_error "The $1 environment variable is empty or not set." + fi + } + for var in LDAP_SKIP_DEFAULT_TREE LDAP_ENABLE_TLS LDAP_ENABLE_PROXYPROTO; do if ! is_yes_no_value "${!var}"; then print_validation_error "The allowed values for $var are: yes or no" @@ -165,6 +171,9 @@ ldap_validate() { fi fi + check_empty_value "LDAP_ADMIN_PASSWORD" + is_boolean_yes "$LDAP_CONFIG_ADMIN_ENABLED" && check_empty_value "LDAP_CONFIG_ADMIN_PASSWORD" + is_boolean_yes "$LDAP_ENABLE_ACCESSLOG" && check_empty_value "LDAP_ACCESSLOG_ADMIN_PASSWORD" read -r -a users <<< "$(tr ',;' ' ' <<< "${LDAP_USERS}")" read -r -a passwords <<< "$(tr ',;' ' ' <<< "${LDAP_PASSWORDS}")" if [[ "${#users[@]}" -ne "${#passwords[@]}" ]]; then @@ -375,6 +384,8 @@ olcMonitoring: FALSE olcDbDirectory: /bitnami/openldap/data olcDbIndex: objectClass eq,pres olcDbIndex: ou,cn,mail,surname,givenname eq,pres,sub +olcAccess: to attrs=userPassword by self write by anonymous auth by * none +olcAccess: to * by self read by users read by * none EOF } @@ -399,6 +410,7 @@ ldap_create_online_configuration() { else debug_execute slapadd "${flags[@]}" fi + rm -f "${LDAP_SHARE_DIR}/slapd.ldif" } ######################## @@ -448,6 +460,7 @@ olcRootPW: $LDAP_ENCRYPTED_CONFIG_ADMIN_PASSWORD EOF fi debug_execute ldapmodify -Y EXTERNAL -H "ldapi:///" -f "${LDAP_SHARE_DIR}/admin.ldif" + rm -f "${LDAP_SHARE_DIR}/admin.ldif" } ######################## @@ -520,7 +533,11 @@ ldap_add_custom_schema() { ######################### ldap_add_custom_schemas() { info "Adding custom schemas : $LDAP_CUSTOM_SCHEMA_DIR ..." - find "$LDAP_CUSTOM_SCHEMA_DIR" -maxdepth 1 \( -type f -o -type l \) -iname '*.ldif' -print0 | sort -z | xargs --null -I{} bash -c ". /opt/bitnami/scripts/libos.sh && debug_execute slapadd -F \"$LDAP_ONLINE_CONF_DIR\" -n 0 -l {}" + + while IFS= read -r -d '' schema_file; do + debug_execute ldapadd -f "$schema_file" -H 'ldapi:///' -D "$LDAP_CONFIG_ADMIN_DN" -w "$LDAP_CONFIG_ADMIN_PASSWORD" + done < <(find "$LDAP_CUSTOM_SCHEMA_DIR" -maxdepth 1 \( -type f -o -type l \) -iname '*.ldif' -print0 | sort -z) + ldap_stop while is_ldap_running; do sleep 1; done ldap_start_bg @@ -576,7 +593,7 @@ sn: Bar$((index + 1 )) objectClass: inetOrgPerson objectClass: posixAccount objectClass: shadowAccount -userPassword: ${passwords[$index]} +userPassword: $(printf '%s' "${passwords[$index]}" | slappasswd -n -T /dev/stdin) uid: $user uidNumber: $((index + 1000 )) gidNumber: $((index + 1000 )) @@ -600,6 +617,7 @@ EOF done debug_execute ldapadd -f "${LDAP_SHARE_DIR}/tree.ldif" -H "ldapi:///" -D "$LDAP_ADMIN_DN" -w "$LDAP_ADMIN_PASSWORD" + rm -f "${LDAP_SHARE_DIR}/tree.ldif" } ######################## @@ -614,7 +632,10 @@ EOF ldap_add_custom_ldifs() { info "Loading custom LDIF files..." warn "Ignoring LDAP_USERS, LDAP_PASSWORDS, LDAP_USER_OU, LDAP_GROUP_OU and LDAP_GROUP environment variables..." - find "$LDAP_CUSTOM_LDIF_DIR" -maxdepth 1 \( -type f -o -type l \) -iname '*.ldif' -print0 | sort -z | xargs --null -I{} bash -c ". /opt/bitnami/scripts/libos.sh && debug_execute ldapadd -f {} -H 'ldapi:///' -D \"$LDAP_ADMIN_DN\" -w \"$LDAP_ADMIN_PASSWORD\"" + + while IFS= read -r -d '' ldif_file; do + debug_execute ldapadd -f "$ldif_file" -H 'ldapi:///' -D "$LDAP_ADMIN_DN" -w "$LDAP_ADMIN_PASSWORD" + done < <(find "$LDAP_CUSTOM_LDIF_DIR" -maxdepth 1 \( -type f -o -type l \) -iname '*.ldif' -print0 | sort -z) } ######################## @@ -772,6 +793,7 @@ olcTLSDHParamFile: $LDAP_TLS_DH_PARAMS_FILE EOF fi debug_execute ldapmodify -Y EXTERNAL -H "ldapi:///" -f "${LDAP_SHARE_DIR}/certs.ldif" + rm -f "${LDAP_SHARE_DIR}/certs.ldif" } ######################## @@ -934,6 +956,7 @@ olcAccessLogOldAttr: $LDAP_ACCESSLOG_LOGOLDATTR EOF info "adding accesslog_create_overlay_configuration.ldif" debug_execute ldapadd -Q -Y EXTERNAL -H "ldapi:///" -f "${LDAP_SHARE_DIR}/accesslog_create_overlay_configuration.ldif" + rm -f "${LDAP_SHARE_DIR}/accesslog_create_overlay_configuration.ldif" } ########################