[2026-09-29 15:25] Aly Dharshi <[email protected]>
> Hello Maintainers,
>
> This series fixes two issues encountered while using table-ldap for
> recipient checks against Microsoft Active Directory.
>
> The first patch changes O_CHECK to request the attributes configured
> for the query rather than the "dn" attribute. Active Directory returns
> the distinguished name as entry metadata rather than as an ordinary
> "dn" attribute. With the existing behaviour, an LDAP search can locate
> a valid entry but the table check does not successfully recognize it.

I though I already fixed this one. But looks good to me.

> The second patch handles LDAP_RES_SEARCH_REFERENCE during O_CHECK.
> Active Directory may return a search reference as an intermediate
> response. table-ldap currently treats this as an unknown LDAP response
> and completes the request with an error. The patch leaves the request
> outstanding so that a subsequent LDAP_RES_SEARCH_ENTRY or
> LDAP_RES_SEARCH_RESULT can determine the result.

looks good to me.

> The problems were reproduced against Microsoft Active Directory over
> LDAPS using mail address recipient checks.
>
> Aly Dharshi (2):
>   table-ldap: use configured attributes for check requests
>   table-ldap: ignore search references during check requests
>
>  table_ldap.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)

Philipp

Ps: when you attach the patches also remove the [PATCH 0/2]. I have
overseen the attachments and waited for the other mails.

Reply via email to