summaryrefslogtreecommitdiffstats
path: root/source
diff options
context:
space:
mode:
authorBo Yang <boyang@samba.org>2009-10-20 02:23:36 +0800
committerKarolin Seeger <kseeger@samba.org>2010-01-13 14:00:51 +0100
commitd935ac91bce2d46f3dd9f9297e1fa1045d5b4b79 (patch)
tree885007adfe0af61bc526234332daee5198fe5616 /source
parent5df02f641b011c8bf35ea456e154ec6965e4dbff (diff)
downloadsamba-d935ac91bce2d46f3dd9f9297e1fa1045d5b4b79.tar.gz
samba-d935ac91bce2d46f3dd9f9297e1fa1045d5b4b79.tar.xz
samba-d935ac91bce2d46f3dd9f9297e1fa1045d5b4b79.zip
s3: Don't fail authentication when one or some group of require-membership-of is invalid.
Signed-off-by: Bo Yang <boyang@samba.org> Fix bug #6826. (cherry picked from commit 74b861908edc427d57928a7af0aa7ffd5fdb8d5a)
Diffstat (limited to 'source')
-rw-r--r--source/nsswitch/pam_winbind.c25
1 files changed, 23 insertions, 2 deletions
diff --git a/source/nsswitch/pam_winbind.c b/source/nsswitch/pam_winbind.c
index 0dcd084f33a..3d0c5ef90e5 100644
--- a/source/nsswitch/pam_winbind.c
+++ b/source/nsswitch/pam_winbind.c
@@ -1053,7 +1053,23 @@ static bool winbind_name_list_to_sid_string_list(struct pwb_context *ctx,
current_name,
sid_list_buffer,
sid_list_buffer_size)) {
- goto out;
+ /*
+ * If one group name failed, we must not fail
+ * the authentication totally, continue with
+ * the following group names. If user belongs to
+ * one of the valid groups, we must allow it
+ * login. -- BoYang
+ */
+
+ _pam_log(ctx, LOG_INFO, "cannot convert group %s to sid, "
+ "check if group %s is valid group.", current_name,
+ current_name);
+ _make_remark_format(ctx, PAM_TEXT_INFO, _("Cannot convert group %s "
+ "to sid, please contact your administrator to see "
+ "if group %s is valid."), current_name, current_name);
+ SAFE_FREE(current_name);
+ search_location = comma + 1;
+ continue;
}
SAFE_FREE(current_name);
@@ -1069,7 +1085,12 @@ static bool winbind_name_list_to_sid_string_list(struct pwb_context *ctx,
if (!winbind_name_to_sid_string(ctx, user, search_location,
sid_list_buffer,
sid_list_buffer_size)) {
- goto out;
+ _pam_log(ctx, LOG_INFO, "cannot convert group %s to sid, "
+ "check if group %s is valid group.", search_location,
+ search_location);
+ _make_remark_format(ctx, PAM_TEXT_INFO, _("Cannot convert group %s "
+ "to sid, please contact your administrator to see "
+ "if group %s is valid."), search_location, search_location);
}
result = true;