summaryrefslogtreecommitdiffstats
path: root/source4
Commit message (Collapse)AuthorAgeFilesLines
...
* s4:operational LDB module - fix warnings (missing parameters, unused variable)Matthias Dieter Wallnöfer2010-05-201-3/+5
|
* s4:auth handle addition of nested aliases of domain groups.Andrew Bartlett2010-05-201-8/+8
| | | | | | | | | The challenge here is that we are asked not to add the domain groups again, but we need to search inside them for any aliases that we need to add. So, we can't short-circuit the operation just because we found the domain group. Andrew Bartlett
* s4:auth Change auth_generate_session_info to take flagsAndrew Bartlett2010-05-2010-38/+139
| | | | | | | | | | | | | | This allows us to control what groups should be added in what use cases, and in particular to more carefully control the introduction of the 'authenticated' group. In particular, in the 'service_named_pipe' protocol, we do not have control over the addition of the authenticated users group, so we key of 'is this user the anonymous SID'. This also takes more care to allocate the right length ptoken->sids Andrew Bartlett
* s4:auth Push check for messaging context into winbind backendAndrew Bartlett2010-05-202-5/+5
| | | | | | | If we don't use the winbind backend, we don't (for now) need a messaging context- and we don't have one in LDB at the moment. Andrew Bartlett
* s4:auth Add dependency from the operational module onto authAndrew Bartlett2010-05-206-9/+39
| | | | | | | We had to split up the auth module into a module loaded by main deamon and a subsystem we manually init in the operational module. Andrew Bartlett
* s4:auth Allow the operational module to get a user's tokenGroups from authAndrew Bartlett2010-05-209-123/+200
| | | | | | | | This creates a new interface to the auth subsystem, to allow an auth_context to be created from the ldb, and then tokenGroups to be calculated in the same way that the auth subsystem would. Andrew Bartlett
* s4:torture Add tests to demonstrate S2U4Self in the RPC-PAC testAndrew Bartlett2010-05-202-9/+307
| | | | | | | | We also compare against SamLogon to try and validate the whole thing. Note that we must represent NULL as "" when comparing between the PAC and SamLogon, due to different marshalling of the structures. Andrew Bartlett
* s4:auth Move BUILTIN group addition into session.cAndrew Bartlett2010-05-204-84/+264
| | | | | | | | The group list in the PAC does not include 'enterprise DCs' and BUILTIN groups, so we should generate it on each server, not in the list we pass around in the PAC or SamLogon reply. Andrew Bartlett
* s4:dsdb disable tokenGroups until end of rewriteAndrew Bartlett2010-05-201-1/+2
| | | | | | I need to change the functions this calls Andrew Bartlett
* pynet: Raise proper exceptions rather than invoking sys.exit.Jelmer Vernooij2010-05-192-8/+6
|
* s4/metadata: fix whitespacesKamen Mazdrashki2010-05-191-71/+71
|
* s4/selftest: fix passwords in selftest-vars scriptKamen Mazdrashki2010-05-191-2/+2
|
* s4:smb_server/smb/trans2.c - remove unused define "DEFAULT_SITE_NAME"Matthias Dieter Wallnöfer2010-05-181-1/+0
| | | | | Obviously this isn't needed and in general site names shouldn't be hardcoded anymore (except there is a good reason).
* s4:smb_server: add dfs smbtorture to selftestsMatthieu Patou2010-05-181-0/+6
| | | | Signed-off-by: Stefan Metzmacher <metze@samba.org>
* s4:smb_server: Implement GET_DFS_REFERRAL for domain referral requestsMatthieu Patou2010-05-181-1/+871
| | | | Signed-off-by: Stefan Metzmacher <metze@samba.org>
* s4:smb_server: fix trailling whitespace in trans2.cMatthieu Patou2010-05-181-25/+25
| | | | Signed-off-by: Stefan Metzmacher <metze@samba.org>
* s4 torture: Add tests for dfs referrals handling in SMB/trans2 requestsMatthieu Patou2010-05-185-2/+578
| | | | Signed-off-by: Stefan Metzmacher <metze@samba.org>
* s4 torture test: Adapt ndr-dfsblobs torture test to new idlMatthieu Patou2010-05-181-2/+2
| | | | Signed-off-by: Stefan Metzmacher <metze@samba.org>
* s4:librpc: fix the autoconf buildStefan Metzmacher2010-05-181-1/+6
| | | | metze
* s4:dynconfig: let the autoconf build compile againStefan Metzmacher2010-05-181-1/+6
| | | | metze
* s3: Fix some more iconv convenience usages.Jelmer Vernooij2010-05-182-4/+4
|
* Remove more usages of iconv_convenience in files which were apparently not ↵Jelmer Vernooij2010-05-183-6/+3
| | | | recompiled by waf.
* s3: Remove use of iconv_convenience.Jelmer Vernooij2010-05-1816-25/+1
|
* Finish removal of iconv_convenience in public API's.Jelmer Vernooij2010-05-18160-923/+549
|
* s4:ntvfs Prepare for a possible future sharing of notify.idlAndrew Bartlett2010-05-181-0/+4
| | | | | | | | I would love for notify.idl to be shared between Samba4 and Samba3 some day, and this seems to be the point at which the structure is initialised. Andrew Bartlett
* s4:winbindd Record the privilaged pipe dirAndrew Bartlett2010-05-182-2/+7
| | | | | | This may help us return an accurate priv pipe dir later on. Andrew Bartlett
* s4:credentials Add in tracking of the password last set timeAndrew Bartlett2010-05-183-1/+33
| | | | | | | | We perhaps need a more general API here, but for now extend the credentials API to return the password last changed time that the s3compat layer will need. Andrew Bartlett
* s4:provision Remove unused 'account_name' parameterAndrew Bartlett2010-05-183-3/+0
| | | | | | | The python glue code didn't even de-reference this element in the structure. Andrew Bartlett
* s4:auth Make it clear to the callers the talloc lifetime.Andrew Bartlett2010-05-181-0/+2
| | | | | | | In other times, we might have used talloc_reference here, but this isn't used as much these days. Andrew Bartlett
* pynet: Remove unused credentials argument.Jelmer Vernooij2010-05-181-4/+3
|
* s4-rodc: Set am_rodc flag during provisionAnatoliy Atanasov2010-05-173-11/+16
|
* s4-rodc: Cache am_rodc flagAnatoliy Atanasov2010-05-172-0/+51
|
* s4:repl_meta_data LDB module - fix counter typesMatthias Dieter Wallnöfer2010-05-141-1/+1
|
* s4:net domainlevel tool - fix up the error handling as Jelmer suggestedMatthias Dieter Wallnöfer2010-05-141-2/+4
| | | | Sorry, I've copied this from the "ldap.py" test and thought it would work.
* s4:dsdb_cache LDB module - fix a typoMatthias Dieter Wallnöfer2010-05-141-1/+1
|
* s4:samldb LDB module - remove unused variablesMatthias Dieter Wallnöfer2010-05-141-2/+0
|
* s4:gensec expose gensec_set_target_principal for use outside GENSECAndrew Bartlett2010-05-144-3/+8
| | | | | | | | This allows for the rare case where the caller knows the target principal. The check for lp_client_use_spnego_principal() is moved to the spengo code to make this work. Andrew Bartlett
* s4:winbindd Rework some winbind structures to make s3compat easierAndrew Bartlett2010-05-143-178/+185
| | | | | | | | By making the winbindd_request and winbindd_response structures pointers, we can more easily integrate with the winbindd from source3/winbindd Andrew Bartlett
* s4:process_model Fix process_standard and process_onefork not to useAndrew Bartlett2010-05-142-55/+19
| | | | | | | | | | | multiple event contexts It is NEVER valid to free an event context that anybody else may have a reference to, and never normally valid to have two 'live' at once. We must instead call tevent_re_initialise() to wipe clean an existing pointer. Andrew Bartlett
* s4:process_modals Add another process modal - 'onefork'Andrew Bartlett2010-05-143-0/+183
| | | | | | | | This will fork off exactly one child to handle some task, ensuring that if it dies or changes global state, that this does not change everything. Andrew Bartlett
* s4:credentials Allow setting of an empty Kerberos CCACHEAndrew Bartlett2010-05-141-18/+12
| | | | | | | This allows us to tell the credentials code where we want the credentials put. Andrew Bartlett
* s4:ntvfs Prepare for a possible future sharing of notify.idlAndrew Bartlett2010-05-141-0/+4
| | | | | | | | I would love for notify.idl to be shared between Samba4 and Samba3 some day, and this seems to be the point at which the structure is initialised. Andrew Bartlett
* s3compat: use right variable for STATEDIRAndrew Tridgell2010-05-141-1/+1
| | | | Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>
* s4-dynconfig: make dynconfig more compatible with s3Andrew Tridgell2010-05-142-54/+55
|
* Revert "s4: remove unused references to swat"Andrew Bartlett2010-05-146-0/+10
| | | | | | | This reverts most of commit 1765732f82719a4bc925f21ef4999bd19a8d1f6c. The s3compat build needs the SWAT location to be compatible with Samba3.
* s4-libndr: fix ndr_pull_string_array() for non utf16 arrays in s4 as well.Günther Deschner2010-05-141-1/+1
| | | | Guenther
* s4:heimdal_build: move #undef __APPLE__ to the end of roken.hStefan Metzmacher2010-05-142-5/+5
| | | | | | Some system includes need __APPLE__ defined. metze
* Now we behave as Windows does, remove a Samba3 specific test return.Jeremy Allison2010-05-131-1/+7
| | | | Jeremy.
* s4:domainlevel - handle exceptions more preciselyMatthias Dieter Wallnöfer2010-05-131-2/+2
| | | | | | | | | LDB_ERR_UNWILLING_TO_PERFORM should be the right error code when the "msDS-Behavior-Version" was already raised by the first change as it is on Windows Server. When s4 itself does implement this trigger then we don't need to do the second write operation anymore (they're kept in sync).
* s4: Do not display by default the message Failed to send DsReplicaSync is ↵Matthieu Patou2010-05-131-1/+6
| | | | | | other host is just unreachable Signed-off-by: Stefan Metzmacher <metze@samba.org>