summaryrefslogtreecommitdiffstats
path: root/source4/utils
diff options
context:
space:
mode:
authorAndrew Bartlett <abartlet@samba.org>2009-07-27 22:04:26 +1000
committerAndrew Bartlett <abartlet@samba.org>2009-07-27 22:41:42 +1000
commita40ce5d0d9d06f592a8885162bbaf644006b9f0f (patch)
tree27a367040a91d1cd6605db042acda7e45c1ca2cb /source4/utils
parent56f4516399431cc508ca0c3e0dd7f179cc7ab62c (diff)
downloadsamba-a40ce5d0d9d06f592a8885162bbaf644006b9f0f.tar.gz
samba-a40ce5d0d9d06f592a8885162bbaf644006b9f0f.tar.xz
samba-a40ce5d0d9d06f592a8885162bbaf644006b9f0f.zip
s4:kerberos Add 'net export keytab' command for wireshark decryption
It is much easier to do decryption with wireshark when the keytab is available for every host in the domain. Running 'net export keytab <keytab name>' will export the current (as pointed to by the supplied smb.conf) local Samba4 doamin. (This uses Heimdal's 'hdb' keytab and then the existing hdb-samba4, and so has a good chance of keeping working in the long term). Andrew Bartlett
Diffstat (limited to 'source4/utils')
-rw-r--r--source4/utils/net/config.mk3
-rw-r--r--source4/utils/net/net.c4
-rw-r--r--source4/utils/net/net_export_keytab.c110
3 files changed, 114 insertions, 3 deletions
diff --git a/source4/utils/net/config.mk b/source4/utils/net/config.mk
index b2f0fcf6b1f..ff8cb2c5269 100644
--- a/source4/utils/net/config.mk
+++ b/source4/utils/net/config.mk
@@ -21,7 +21,8 @@ net_OBJ_FILES = $(addprefix $(utilssrcdir)/net/, \
net_time.o \
net_join.o \
net_vampire.o \
- net_user.o)
+ net_user.o \
+ net_export_keytab.o)
$(eval $(call proto_header_template,$(utilssrcdir)/net/net_proto.h,$(net_OBJ_FILES:.o=.c)))
diff --git a/source4/utils/net/net.c b/source4/utils/net/net.c
index d934403ade2..a96c672dfdc 100644
--- a/source4/utils/net/net.c
+++ b/source4/utils/net/net.c
@@ -104,11 +104,11 @@ static const struct net_functable net_functable[] = {
{"time", "get remote server's time\n", net_time, net_time_usage},
{"join", "join a domain\n", net_join, net_join_usage},
{"samdump", "dump the sam of a domain\n", net_samdump, net_samdump_usage},
+ {"export", "dump the sam of this domain\n", net_export, net_export_usage},
{"vampire", "join and syncronise an AD domain onto the local server\n", net_vampire, net_vampire_usage},
{"samsync", "synchronise into the local ldb the sam of an NT4 domain\n", net_samsync_ldb, net_samsync_ldb_usage},
{"user", "manage user accounts\n", net_user, net_user_usage},
- {"machinepw", "Get a machine password out of our SAM\n", net_machinepw,
- net_machinepw_usage},
+ {"machinepw", "Get a machine password out of our SAM\n", net_machinepw, net_machinepw_usage},
{NULL, NULL, NULL, NULL}
};
diff --git a/source4/utils/net/net_export_keytab.c b/source4/utils/net/net_export_keytab.c
new file mode 100644
index 00000000000..7f13278a9e1
--- /dev/null
+++ b/source4/utils/net/net_export_keytab.c
@@ -0,0 +1,110 @@
+/*
+ Samba Unix/Linux SMB client library
+ Distributed SMB/CIFS Server Management Utility
+
+ Copyright (C) 2004 Stefan Metzmacher <metze@samba.org>
+ Copyright (C) 2005 Andrew Bartlett <abartlet@samba.org>
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>.
+*/
+
+#include "includes.h"
+#include "utils/net/net.h"
+#include "libnet/libnet.h"
+#include "param/param.h"
+
+static int net_export_keytab_usage(struct net_context *ctx, int argc, const char **argv)
+{
+ d_printf("net export keytab <keytab>\n");
+ return 0;
+}
+
+static int net_export_keytab_help(struct net_context *ctx, int argc, const char **argv)
+{
+ d_printf("Dumps kerberos keys of the domain into a keytab.\n");
+ return 0;
+}
+
+static int net_export_keytab(struct net_context *ctx, int argc, const char **argv)
+{
+ NTSTATUS status;
+ struct libnet_context *libnetctx;
+ struct libnet_export_keytab r;
+
+ switch (argc) {
+ case 0:
+ return net_export_keytab_usage(ctx, argc, argv);
+ break;
+ case 1:
+ r.in.keytab_name = argv[0];
+ break;
+ }
+
+ libnetctx = libnet_context_init(ctx->event_ctx, ctx->lp_ctx);
+ if (!libnetctx) {
+ return -1;
+ }
+ libnetctx->cred = ctx->credentials;
+
+ r.out.error_string = NULL;
+
+ status = libnet_export_keytab(libnetctx, ctx, &r);
+ if (!NT_STATUS_IS_OK(status)) {
+ DEBUG(0,("libnet_export_keytab returned %s: %s\n",
+ nt_errstr(status),
+ r.out.error_string));
+ return -1;
+ }
+
+ talloc_free(libnetctx);
+
+ return 0;
+}
+
+/* main function table */
+static const struct net_functable net_export_functable[] = {
+ {"keytab", "dump keys into a keytab\n", net_export_keytab, net_export_keytab_usage},
+ {NULL, NULL, NULL, NULL}
+};
+
+int net_export(struct net_context *ctx, int argc, const char **argv)
+{
+ int rc;
+
+ switch (argc) {
+ case 0:
+ rc = net_export_usage(ctx, argc, argv);
+ return rc;
+ case 1:
+ default:
+ rc = net_run_function(ctx, argc, argv, net_export_functable,
+ net_export_usage);
+ return rc;
+ }
+
+ return 0;
+}
+
+int net_export_usage(struct net_context *ctx, int argc, const char **argv)
+{
+ d_printf("net export keytab <keytab>\n");
+ return 0;
+}
+
+int net_export_help(struct net_context *ctx, int argc, const char **argv)
+{
+ d_printf("Dumps the sam of the domain we are joined to.\n");
+ return 0;
+}
+