;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2016, 2017 Ricardo Wurmus <>
;;; Copyright © 2017, 2018 Tobias Geerinckx-Rice <>
;;; Copyright © 2020 Efraim Flashner <>
;;; This file is part of GNU Guix.
;;; GNU Guix is free software; you can redistribute it and/or modify it
;;; under the terms of the GNU General Public License as published by
;;; the Free Software Foundation; either version 3 of the License, or (at
;;; your option) any later version.
;;; GNU Guix is distributed in the hope that it will be useful, but
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
;;; GNU General Public License for more details.
;;; You should have received a copy of the GNU General Public License
;;; along with GNU Guix. If not, see <>.
(define-module (gnu packages sssd)
#:use-module ((guix licenses) #:prefix license:)
#:use-module (guix packages)
#:use-module (guix download)
#:use-module (guix utils)
#:use-module (guix build-system gnu)
#:use-module (gnu packages)
#:use-module (gnu packages adns)
#:use-module (gnu packages augeas)
#:use-module (gnu packages check)
#:use-module (gnu packages curl)
#:use-module (gnu packages cyrus-sasl)
#:use-module (gnu packages databases)
#:use-module (gnu packages dns)
#:use-module (gnu packages docbook)
#:use-module (gnu packages documentation)
#:use-module (gnu packages glib)
#:use-module (gnu packages kerberos)
#:use-module (gnu packages libunistring)
#:use-module (gnu packages linux)
#:use-module (gnu packages nss)
#:use-module (gnu packages openldap)
#:use-module (gnu packages tls)
#:use-module (gnu packages pcre)
#:use-module (gnu packages popt)
#:use-module (gnu packages pkg-config)
#:use-module (gnu packages samba)
#:use-module (gnu packages selinux)
#:use-module (gnu packages web)
#:use-module (gnu packages xml))
(define-public ding-libs
(name "ding-libs")
(version "0.6.1")
(source (origin
(method url-fetch)
(uri (string-append ""
"ding-libs-" version ".tar.gz"))
(build-system gnu-build-system)
(home-page "")
(synopsis "Libraries for SSSD")
"DING-LIBS (DING Is Not Glib) are a set of small, useful libraries that
the @dfn{System Security Services Daemon} (SSSD) uses and makes available to
other projects. They include: libdhash, an implementation of a dynamic hash
table which will dynamically resize to achieve optimal storage and access time
properties; ini_config, a library for parsing and managing @code{INI} files;
path_utils, a library to manage UNIX paths and subsets of paths; collection, a
generic, hierarchical grouping mechanism for complex data sets; ref_array, a
dynamically-growing, reference-counted array; libbasicobjects, a set of
fundamental object types for C.")
(license license:lgpl3+)))
;; Note: This package installs modules for ldb and nss. For the former we
;; need to set LDB_MODULES_PATH. For the latter LD_PRELOAD or LD_LIBRARY_PATH
;; is needed.
(define-public sssd
(name "sssd")
(version "1.16.5")
(source (origin
(method url-fetch)
(uri (string-append ""
"sssd-" version ".tar.gz"))
(patches (search-patches "sssd-fix-samba.patch"))))
(build-system gnu-build-system)
(list (string-append "DOCBOOK_XSLT="
(assoc-ref %build-inputs "docbook-xsl")
,(package-version docbook-xsl)
;; Remove "--postvalid" option, because that requires access to
;; online DTDs.
"XMLLINT_FLAGS = --catalogs --nonet --noent --xinclude --noout")
(list "--disable-cifs-idmap-plugin"
(string-append "--with-plugin-path="
(assoc-ref %outputs "out")
(string-append "--with-krb5-plugin-path="
(assoc-ref %outputs "out")
(string-append "--with-cifs-plugin-path="
(assoc-ref %outputs "out")
(string-append "--with-init-dir="
(assoc-ref %outputs "out")
(string-append "--with-ldb-lib-dir="
(assoc-ref %outputs "out")
(string-append "--with-xml-catalog-path="
(assoc-ref %build-inputs "docbook-xml")
(modify-phases %standard-phases
(add-after 'unpack 'disable-failing-test
(lambda _
(substitute* "src/tests/responder_socket_access-tests.c"
(("tcase_add_test\\(tc_utils, resp_str_to_array_test\\);") ""))
`(("augeas" ,augeas)
("bind" ,isc-bind "utils")
("c-ares" ,c-ares)
("curl" ,curl)
("cyrus-sasl" ,cyrus-sasl)
("dbus" ,dbus)
("ding-libs" ,ding-libs)
("glib" ,glib)
("gnutls" ,gnutls)
("http-parser" ,http-parser)
("jansson" ,jansson)
("ldb" ,ldb)
("libselinux" ,libselinux)
("libsemanage" ,libsemanage)
("libunistring" ,libunistring)
("linux-pam" ,linux-pam)
("mit-krb5" ,mit-krb5)
("nss" ,nss)
("openldap" ,openldap)
("openssl" ,openssl)
("pcre" ,pcre)
("popt" ,popt)
("samba" ,samba)
("talloc" ,talloc)
("tdb" ,tdb)
("tevent" ,tevent)))
`(("check" ,check)
("docbook-xsl" ,docbook-xsl)
("docbook-xml" ,docbook-xml)
("libxml2" ,libxml2) ; for xmllint
("libxslt" ,libxslt)
("pkg-config" ,pkg-config)
("util-linux" ,util-linux "lib"))) ;for uuid.h, reqired for KCM
(home-page "")
(synopsis "System security services daemon")
(description "SSSD is a system daemon. Its primary function is to provide
access to identity and authentication remote resource through a common
framework that can provide caching and offline support to the system. It
provides PAM and NSS modules, and in the future will support D-BUS based
interfaces for extended user information. It also provides a better database
to store local users as well as extended user data.")
(license license:gpl3+)))