summaryrefslogtreecommitdiffstats
path: root/server
Commit message (Collapse)AuthorAgeFilesLines
* Hide uid and gid options in usermod and groupmodJakub Hrozek2009-03-102-3/+3
|
* Correct use of chkconfig in initscript and specfileJakub Hrozek2009-03-101-1/+1
| | | | Review issues in specfile
* added generic PAM return messages and a false login delaySumit Bose2009-03-106-65/+151
|
* Treat uids and gids as 32 bit numbers not 64Simo Sorce2009-03-101-23/+21
| | | | | | In the nss communication protocol we were treating uids and gids as 64 bit values, but uids and gids are really u32 values, change the protocol to reflect the real size.
* If a domain is MPG enabled return users a groupsSimo Sorce2009-03-102-15/+73
| | | | Turn user entries to Magic Private Groups when groups are quesried.
* Fix bugs in functions dealing with groupsSimo Sorce2009-03-101-0/+6
| | | | | | Fix infinite loop within initgr functions. Fix min length check copy&paste error, was filtering valid groups if the name was short enough and the group had no members.
* Always pass sss_domain_info to sysdb functions.Simo Sorce2009-03-096-95/+60
|
* Move MPG checks within sysdb.Simo Sorce2009-03-096-138/+199
| | | | | This allows to perform checks and modifications in one transaction. Uses configuration stored in confdb to determins if a domain uses MPGs.
* Do not duplicate attribute names macros.Simo Sorce2009-03-094-34/+31
| | | | Also shorten names oh other user attributes.
* make openldap the only used LDAP librarySumit Bose2009-03-092-41/+27
|
* typo, changed initrd to initSumit Bose2009-03-093-12/+12
|
* sss_groupmodJakub Hrozek2009-03-093-1/+288
|
* use fixed paths to sockets to make sure clients and server are using the sameSumit Bose2009-03-097-59/+80
|
* Make MPG a configurable option for the domain.Simo Sorce2009-03-092-0/+12
|
* Improve error handling and replies in the InfoPipeStephen Gallagher2009-03-093-48/+62
| | | | | | When detecting an internal error in the InfoPipe, make a best- attempt at sending an error message back to the calling program, instead of simply leaving the client to wait for the timeout.
* Implement SetGroupGID in the InfoPipeStephen Gallagher2009-03-096-3/+289
|
* Implement AddGroupMembers and RemoveGroupMembers in the InfoPipeStephen Gallagher2009-03-092-16/+263
|
* sss_usermodJakub Hrozek2009-03-096-45/+415
| | | | Move parse_groups into tools_utils
* Fix SIGSEGV in InfoPipe startupStephen Gallagher2009-03-091-2/+4
| | | | | | | | If the user that starts InfoPipe is not permitted by the system bus to request the InfoPipe name, the sssd_info process would segfault, since the destructor for the connection object was called before it was completely created. I have moved the initialization of the destructor to later in the setup routine.
* Fix parameter parsing and adding to groups in useraddJakub Hrozek2009-03-091-4/+10
|
* Use LOCAL for the default domain in confdb_init_dbStephen Gallagher2009-03-081-0/+4
|
* Fix initialization problemsJakub Hrozek2009-03-084-11/+12
| | | | Init tools ctx in groupadd before copying its value
* sss_groupdel, delete by DN in sss_userdelJakub Hrozek2009-03-074-74/+181
| | | | Don't convert username->uid in userdel, use DN
* Fix race condition with initial sysdb creationStephen Gallagher2009-03-071-0/+14
| | | | | | | | | When the sysdb LDB file does not exist on the system, the first attempt to connect to it will invoke a creation routine. However, both the NSS and the InfoPipe are started in parallel by the monitor, resulting in a race condition as they both try to initialize the sysdb. The easiest fix for this is to simply have the monitor create the sysdb before it launches NSS and InfoPipe.
* sss_groupaddJakub Hrozek2009-03-063-1/+176
|
* Implement DeleteGroup in InfoPipeStephen Gallagher2009-03-062-2/+149
|
* Implement CreateGroup in InfoPipeStephen Gallagher2009-03-062-4/+193
| | | | Also fixed two minor bugs in CreateUser
* Specfile changes related to package review, package initscript Call ldconfigJakub Hrozek2009-03-064-0/+126
|
* sss_userdelJakub Hrozek2009-03-063-2/+235
| | | | Also install tools into /sbin, own them in specfile
* Implement DeleteUser in the InfoPipeStephen Gallagher2009-03-061-2/+166
|
* Add sbus_reply_internal_error() feature to sbus_message_handler()Stephen Gallagher2009-03-061-2/+14
| | | | | | | If an SBUS function returns an error code, we'll immediately return an error reply to the client stating "Internal Error" instead of ignoring the request and forcing the client to wait for a timeout.
* Add infp_req_init() function to simplify method setupStephen Gallagher2009-03-063-64/+43
|
* Implement CreateUser in InfoPipeStephen Gallagher2009-03-065-9/+223
| | | | | | | | | | | Changed the order of the arguments to CreateUser in the Introspection XML to match the other functions (domain belongs second on the list) A few other minor fixes as well: Fixed a typo in SYSDB_GETCACHED_FILTER and sysdb_transaction_end(). Added missing error handling in infp_do_user_set_uid().
* Remove obsolete commentSimo Sorce2009-03-061-3/+0
|
* Add userspace tools to manipulate accounts.Simo Sorce2009-03-066-1/+654
| | | | | The first functional command is sss_useradd (Name is temporary, while looking for a better one)
* added PAM default configuration to confdb_init_dbSumit Bose2009-03-062-7/+36
| | | | | | set default value of enumerate in LOCAL domain to 1 added checks to talloc_asprintf return values fixed InfoPipe defaults
* Fix reporting non-default users.Simo Sorce2009-03-063-301/+318
| | | | | We need to add the domain when users are not part of the default domain, otherwise name conflicts may happen.
* minor fixes for the build processSumit Bose2009-03-063-1/+10
| | | | enable --without-tests
* Remove _PW_ and _GR_ from SYSDB_ definesSimo Sorce2009-03-058-82/+78
| | | | Also unify SYSDB_PW_NAME and SYSDB_GR_NAME in SYSDB_NAME and make it "name"
* Implement GetCachedUsers in the InfoPipeStephen Gallagher2009-03-054-10/+205
| | | | | | | | | | | | | This function allows a caller to retrieve a list of users who have logged in on the system, specifying an optional minimum last login time to trim the list. I modified sysdb_enumpwent to accept an optional search argument. GetCachedUsers takes advantage of this argument to limit the search by the last login time. I also found and fixed a few additional low-memory conditions around D-BUS message replies.
* Add functions to add regular users and groupsSimo Sorce2009-03-053-27/+445
| | | | | | Calulates next id automatically if uid/gid are not specified. Fixes to sysdb_get_next_available_id. Add tests to create users and groups through the new functions.
* Adding support for SetUserUID to the InfoPipeStephen Gallagher2009-03-054-7/+159
| | | | | | | | | | The InfoPipe interface Set_YouReallyDoNotWantToUseThisFunction_UserUID1 is now available. I also fixed a memory leak in SetUserAttributes and modified the prototype for infp_get_permissions to make it more clear that the first argument is the caller's username, not the username being checked for permission.
* added password reset by rootSumit Bose2009-03-051-0/+5
|
* added a privileged pipeSumit Bose2009-03-056-8/+137
|
* Add internal min/max/next id management fucntionsSimo Sorce2009-03-045-15/+336
| | | | | | | | Retrieve minID and maxID from domain configuration so that lower and upper bounds can be set per domain. Add function that keeps track of the next available id, increments and returns it on requests, avoiding collisions with existing ids.
* Add enumeration backout period.Simo Sorce2009-03-043-2/+39
| | | | | | | | | If an enumeration has been requested recently enough, force the nss responder to read from the cache and not go out to each backend and do slow network operations. This greatly improves performances if enumerations are used often. Currently the balcout period is harcoded to 2 min, we will need to make it a configurable option.
* Implement SetUserAttributes in the InfoPipeStephen Gallagher2009-03-047-17/+573
| | | | | | | | | SetUserAttributes is now available for use in the Infopipe. I also reorganized a few of the internal InfoPipe objects to reduce code duplication. One very simple test is included in this checkin to validate that the parser is working.
* Simplify some aspects of pam_LOCAL_domainSimo Sorce2009-03-043-138/+87
| | | | | | | | | | Use only one context (the local request) for all functions. Use new helper function in sysdb to set numbers as sysdb_attrs values. Do not use pam_status to report internal errors, use an error variable and check it only when we finally reply. Use sysdb_error_to_errno() to convert and ldb error to errno. Do not free every single buffer allocated, they are all appended to the local request and will be automatically freed once the request is finished.
* Improve sysdbSimo Sorce2009-03-044-33/+87
| | | | | | Add comments in header files to better explain interfaces and intended usage. Expose function to convert from ldb errors to errnos. Add sysdb_attrs helper to add a long integer as a value.
* Fixing memory leak in GetUserAttributesStephen Gallagher2009-03-041-1/+2
|