Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Change uint_t to unsigned int in source4 | Matt Kraai | 2010-02-02 | 1 | -1/+1 |
| | | | | Signed-off-by: Stefan Metzmacher <metze@samba.org> | ||||
* | s4-sddl: DRS replication needs REVISION_ADS for SDs | Andrew Tridgell | 2010-01-02 | 1 | -1/+1 |
| | | | | | DRS replication with w2k8-r2 fails with a schema mismatch error if we set the revision to NT4 | ||||
* | py/security: Add test for dom_sid.split. | Jelmer Vernooij | 2009-12-31 | 1 | -3/+8 |
| | | | | Signed-off-by: Andrew Tridgell <tridge@samba.org> | ||||
* | Fixed incorrect checking of PRINCIPAL_SELF permissions. | Nadezhda Ivanova | 2009-12-17 | 1 | -3/+12 |
| | | | | | | If an ace has the PRINCIPAL_SELF as trustee, this sid has to be replaced with the onjectSid of the object being checked. PRINCIPAL_SELF is the way to grant rights to an account over itself. | ||||
* | s4:security/sddl - rework of the security descriptor abbreviations | Matthias Dieter Wallnöfer | 2009-11-27 | 1 | -28/+33 |
| | | | | | - Reoder them - Add some new ones (needed for the security descriptor in the provision script) | ||||
* | Fixed incorrect SID for RAS Servers. | Nadezhda Ivanova | 2009-11-17 | 2 | -1/+2 |
| | |||||
* | Fixed some major bugs in inheritance and access checks. | Nadezhda Ivanova | 2009-11-15 | 1 | -13/+16 |
| | | | | | | | | Fixed sd creation not working on LDAP modify. Fixed incorrect replacement of CO and CG. Fixed incorrect access check on modify for SD modification. Fixed failing sec_descriptor test and enabled it. Fixed failing sd add test in ldap.python | ||||
* | Version 1.0 of the directory service acls module. | Nadezhda Ivanova | 2009-11-05 | 2 | -47/+60 |
| | | | | | | | At this point, support for checks on LDAP add, delete, rename and modify. Old kludge_acl is still there to handle the searches. This module is synchronous as the async version was impossible to debug, will be converted to async after some user testing. | ||||
* | Fixed some missing flags and bugs in the security creation. | Nadezhda Ivanova | 2009-11-03 | 1 | -11/+47 |
| | | | | | Also, added some logging. It needs improvement, possibly ability to turn in on and off via configuration file. | ||||
* | Fixed a bug in object specific access checks. | Nadezhda Ivanova | 2009-11-03 | 1 | -2/+4 |
| | |||||
* | s4:libcli/security/access_check - Add "const" in front of "type" | Matthias Dieter Wallnöfer | 2009-10-22 | 1 | -1/+1 |
| | | | | Signed-off-by: Andrew Bartlett <abartlet@samba.org> | ||||
* | s4-acl: SEC_FLAG_MAXIMUM_ALLOWED doesn't auto-apply privilege access masks | Andrew Tridgell | 2009-10-17 | 1 | -6/+2 |
| | |||||
* | s4-security: honor more of the privilege access bits | Andrew Tridgell | 2009-10-17 | 1 | -4/+12 |
| | |||||
* | s4: fix various warnings (not "const" related ones) | Matthias Dieter Wallnöfer | 2009-10-02 | 1 | -3/+3 |
| | |||||
* | s4-acl: fixed SD creation | Andrew Tridgell | 2009-09-28 | 1 | -12/+22 |
| | | | | | Thanks for Nadya and Metze for this. The SDs were being created with invalid fields (noticed by w2k8-r2 client when joining our domain) | ||||
* | Fixed a dereferenced null pointer. | Nadezhda Ivanova | 2009-09-24 | 1 | -16/+14 |
| | |||||
* | Initial Implementation of the DS objects access checks. | Nadezhda Ivanova | 2009-09-21 | 4 | -1/+252 |
| | | | | | Currently disabled. The search will be greatly modified, also the object tree stuff will be simplified. | ||||
* | Initial implementation of security descriptor creation in DS | Nadezhda Ivanova | 2009-09-20 | 1 | -4/+348 |
| | | | | | TODO's: ACE sorting and clarifying the inheritance of object specific ace's. | ||||
* | pyldb: Don't segfault when invalid type is specified to as_sddl and from_sddl. | Matthieu Patou | 2009-09-17 | 1 | -0/+17 |
| | | | | Fix bug #6723 | ||||
* | Owner and group defaulting. | Nadezhda Ivanova | 2009-09-16 | 2 | -1/+118 |
| | | | | Signed-off-by: Andrew Bartlett <abartlet@samba.org> | ||||
* | s4-security: added a new security level SECURITY_DOMAIN_CONTROLLER | Andrew Tridgell | 2009-09-15 | 2 | -0/+10 |
| | | | | | This will be used as a simple way to lock down DRS replication to administrators and domain controllers | ||||
* | Fix typo | Matthias Dieter Wallnöfer | 2009-07-19 | 1 | -1/+1 |
| | |||||
* | s4: Add additional 2-letter SID/RID mappings. | Andrew Kroeger | 2009-05-29 | 1 | -0/+23 |
| | | | | Information from http://msdn.microsoft.com/en-us/library/aa379602(VS.85).aspx | ||||
* | s4: try to fix privileges implementation in order to pass the ↵ | Günther Deschner | 2009-05-20 | 1 | -1/+5 |
| | | | | | | RPC-SAMR-USERS-PRIVILEGES test. Guenther | ||||
* | Fix of a bug in the security.descriptor.as_sddl() method | nadezhda ivanova | 2009-04-23 | 1 | -0/+6 |
| | | | | | | | | security.descriptor.as_sddl() method did not work correctly when invoked without supplying the domain sid. Returned the same value as when the sid was provided. Test added for this case in libcli/security/tests/bindings.py Signed-off-by: Jelmer Vernooij <jelmer@samba.org> | ||||
* | Move the security_descriptor utility code to the top-level. | Jelmer Vernooij | 2009-04-21 | 3 | -535/+2 |
| | |||||
* | Add a unit test for security_descriptor.as_sddl() without arguments. | Jelmer Vernooij | 2009-04-20 | 1 | -0/+10 |
| | |||||
* | display_sec: Move to common libcli/security directory. | Jelmer Vernooij | 2009-03-25 | 1 | -2/+0 |
| | |||||
* | Add header files for secace and secacl. | Jelmer Vernooij | 2009-03-01 | 1 | -1/+2 |
| | |||||
* | Move secacl to top-level. | Jelmer Vernooij | 2009-03-01 | 1 | -1/+2 |
| | |||||
* | Move secace.c to top-level. | Jelmer Vernooij | 2009-03-01 | 1 | -1/+2 |
| | |||||
* | shared: Move dom_sid_* utility functions to top level | Kai Blin | 2009-02-01 | 3 | -308/+5 |
| | |||||
* | Fix the mess with ldb includes. | Simo Sorce | 2009-01-30 | 1 | -1/+0 |
| | | | | | | | | Separate again the public from the private headers. Add a new header specific for modules. Also add service function for modules as now ldb_context and ldb_module are opaque structures for them. | ||||
* | Implement as_sddl. | Jelmer Vernooij | 2009-01-22 | 1 | -0/+10 |
| | |||||
* | Support parsing sddl for security descriptors. | Jelmer Vernooij | 2009-01-22 | 1 | -0/+8 |
| | |||||
* | Fix more compiler warnings in various places. | Jelmer Vernooij | 2008-12-23 | 1 | -1/+0 |
| | |||||
* | Fix comparison in tests now that we use __cmp__ rather than __eq__. | Jelmer Vernooij | 2008-12-21 | 1 | -2/+2 |
| | |||||
* | Fix more tests, improve repr() functions for various Python types. | Jelmer Vernooij | 2008-12-21 | 2 | -8/+8 |
| | |||||
* | Simplify customization of pidl-generated Python modules. | Jelmer Vernooij | 2008-12-21 | 1 | -16/+24 |
| | |||||
* | Merge the rest of security.i into samba.dcerpc.security. | Jelmer Vernooij | 2008-12-21 | 4 | -3701/+0 |
| | |||||
* | Remove duplicate Python bindings for dom_sid, security_descriptor and | Jelmer Vernooij | 2008-12-21 | 3 | -1022/+40 |
| | | | | security_token. | ||||
* | Include errors.i verbatim in security.i, as it's the only file still using it. | Jelmer Vernooij | 2008-12-21 | 1 | -1/+33 |
| | |||||
* | Fix compiler warning when parsing a SID in a data blob | Andrew Bartlett | 2008-12-20 | 1 | -1/+1 |
| | |||||
* | Manually marshall dom_sid, so we can use a fixed size array for | Jelmer Vernooij | 2008-12-12 | 3 | -37/+1 |
| | | | | | | | | | dom_sid.sub_auths rather than a dynamically allocated one. This makes it possible to use the same DCE/RPC object code for Samba 3 and Samba 4's DCE/RPC parsers and allows copying sids more easily (since they no longer contain any pointers). The cost of having additional manual marshalling code is limited (~35 additional lines of C code). | ||||
* | s4:librpc/ndr: integrate NDR_MISC into LIBNDR | Stefan Metzmacher | 2008-11-16 | 1 | -1/+1 |
| | | | | metze | ||||
* | s4: libcli/security: a NULL DACL allows access | Stefan Metzmacher | 2008-10-28 | 1 | -11/+2 |
| | | | | | | This fixes bug 4284. metze | ||||
* | Make Sid member variables accessible from Python. | Jelmer Vernooij | 2008-09-30 | 3 | -0/+128 |
| | |||||
* | fixed problem with ACLs with an empty DACL list | Andrew Tridgell | 2008-09-23 | 1 | -1/+14 |
| | |||||
* | Add test for Sid.__repr__. | Jelmer Vernooij | 2008-09-19 | 1 | -0/+4 |
| | |||||
* | Generate with 1.3.36. | Jelmer Vernooij | 2008-09-18 | 2 | -31/+36 |
| |