Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | added -k options for kerberos to smbtorture and locktest | Andrew Tridgell | 2002-03-04 | 2 | -2/+28 | |
| | ||||||
* | Fixed typo for winbind on solaris and hpux. | Tim Potter | 2002-03-03 | 1 | -2/+2 | |
| | | | | | I have to say that having to link in winbind_nss_solaris.o for hpux is slightly dodgy... | |||||
* | make default unix charset UTF8 | Andrew Tridgell | 2002-03-03 | 1 | -0/+3 | |
| | | | | this means that we at least support all unicode chars by default | |||||
* | handle clock skew in getatr test | Andrew Tridgell | 2002-03-03 | 1 | -3/+3 | |
| | ||||||
* | fixed -c option to NBENCH test | Andrew Tridgell | 2002-03-03 | 1 | -1/+1 | |
| | ||||||
* | Some more fixes to enusre we execute the same code pathes as before this | Andrew Bartlett | 2002-03-03 | 1 | -8/+8 | |
| | | | | change, just in different packets. | |||||
* | Matching header files for the last netlogon cleanup. | Andrew Bartlett | 2002-03-03 | 1 | -0/+7 | |
| | | | | Andrew Bartlett | |||||
* | This patch allows NT4 domains to trust Samba. | Andrew Bartlett | 2002-03-03 | 1 | -84/+81 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Simply add an account (smbpasswd -a -i REMOTEDOM) and join with 'user manager' on the remote domain. The only issue (at the auth level at least) that prevented NT4 domains from trusting Samba was that our netlogon code was based on what appear to be invalid assumptions. The netlogon code appears to assume that the 'client name' specified corrosponds to an account of the same form. This doesn't apply in trusted domains, becouse the account is in the form domain$ Now that we use the supplied account name, and no longer make our access control checks at the challange stage (where this info is unavailable) we match the Win2k behaviour for invalid machine logins, and don't need to know the names of PDCs/BDCs in trusting domains. We also kill off the 'you logged on with a machine account, use your user account' error message, becouse the previous NT_STATUS return was compleatly bogus. (The ACCESS_DENIED we now return matches Win2k, and gives snane error messages on the client). TNG doesn't use this and has to do magic password syncs between the various accounts for domain/pdc/bdc. This patch feels like the much more natural way of doing things, and has been mildly tested. Andrew Bartlett | |||||
* | compile fix from vance | Simo Sorce | 2002-03-02 | 1 | -0/+2 | |
| | ||||||
* | Move these inside the #ifdef to fix the compile on non-LDAPsam systems. | Andrew Bartlett | 2002-03-02 | 1 | -4/+5 | |
| | ||||||
* | This is now unused | Andrew Bartlett | 2002-03-02 | 1 | -1/+0 | |
| | ||||||
* | This patch merges my private LDAP tree into HEAD. | Andrew Bartlett | 2002-03-02 | 9 | -290/+794 | |
| | | | | | | | | | | | | | | | | | | | | | The main change here is to move ldap into the new pluggable passdb subsystem and to take the LDAP location as a 'location' paramter on the 'passdb backend' line in the smb.conf. This is an LDAP URL, parsed by OpenLDAP where supported, and by hand where it isn't. It also adds the ldap user suffix and ldap machine suffix smb.conf options, so that machines added to the LDAP dir don't get mixed in with people. Non-unix account support is also added. This means that machines don't need to be in /etc/passwd or in nss_ldap's scope. This code has stood up well under my production environment, so it relitivly well tested. I'm commiting this now becouse others have shown interest in using it, and there is no point 'hording' the code :-). Andrew Bartlett | |||||
* | more const | Andrew Bartlett | 2002-03-02 | 1 | -2/+2 | |
| | ||||||
* | Allow Samba to trust NT4 Domains. | Andrew Bartlett | 2002-03-02 | 7 | -27/+139 | |
| | | | | | | | | | | | | | | | | This commit builds on the auth subsystem to give Samba support for trusting NT4 domains. It is off by default, but is enabled by adding 'trustdomain' to the 'auth methods' smb.conf paramater. Tested against NT4 only - there are still some issues with the join code for Win2k servers (spnego stuff). The main work TODO involves enumerating the trusted domains (including the RPC calls to match), and getting winbind to run on the PDC correctly. Similarly, work remains on getting NT4 to trust Samba domains. Andrew Bartlett | |||||
* | Remove util_list.h, as its matching .c file has already gone, and nobody is | Andrew Bartlett | 2002-03-02 | 3 | -61/+3 | |
| | | | | | | | using it anymore. This also removes an early #include of smb.h, making it slightly easier to track whats being included where. Andrew Bartlett | |||||
* | Missing include file update for the secrets.c trustdom changes | Andrew Bartlett | 2002-03-02 | 1 | -1/+1 | |
| | ||||||
* | Fix up the trusted domains secrets code so as to have a slight chance of | Andrew Bartlett | 2002-03-02 | 1 | -12/+10 | |
| | | | | working. | |||||
* | And a little more const. | Andrew Bartlett | 2002-03-02 | 1 | -3/+3 | |
| | ||||||
* | Add a dash of const here and there... | Andrew Bartlett | 2002-03-02 | 2 | -6/+6 | |
| | ||||||
* | Fix lseek-on-pipe problem in VFS (where it belongs IMHO). | Jeremy Allison | 2002-03-02 | 2 | -18/+19 | |
| | | | | Jeremy. | |||||
* | SECURITY FIXES: | Andrew Bartlett | 2002-03-01 | 2 | -7/+11 | |
| | | | | | | | | | Remove a stray 'unbecome_root()' in the ntdomain an auth failure case. Only allow trust accounts to request a challange in srv_netlogon_nt.c. Currently any user can be the 'machine' for the domain logon. MERGE for 2.2. Andrew Bartlett | |||||
* | Added requested cast for splint. | Jeremy Allison | 2002-03-01 | 1 | -1/+1 | |
| | | | | Jeremy. | |||||
* | Fixed EXTRA vs EXTGRA typo. Thanks Mike :-). | Jeremy Allison | 2002-03-01 | 2 | -2/+2 | |
| | | | | Jeremy. | |||||
* | merge from 2.2 | Gerald Carter | 2002-03-01 | 1 | -2/+7 | |
| | ||||||
* | Missed the Makefile.in update... | Andrew Bartlett | 2002-03-01 | 1 | -2/+2 | |
| | ||||||
* | Cause nmbd to take signal processing in-band, rather than in | Jeremy Allison | 2002-03-01 | 1 | -339/+368 | |
| | | | | | signal handlers. THIS NEEDS TESTING ! Jeremy. | |||||
* | The beginning of trusted and trusting domain support from | Andrew Bartlett | 2002-03-01 | 6 | -20/+629 | |
| | | | | | | | | Rafal Szczesniak <mimir@diament.ists.pwr.wroc.pl> This adds the 'net' tools to manipulate the trusted domains. Andrew Bartlett | |||||
* | Another comment fix for mirmir | Andrew Bartlett | 2002-03-01 | 1 | -1/+1 | |
| | ||||||
* | use the variable passed as a paramater, not just one randomly in our namespace. | Andrew Bartlett | 2002-03-01 | 1 | -1/+1 | |
| | | | | Andrew Bartlett | |||||
* | See if we can get a slight chance of this actually working... | Andrew Bartlett | 2002-03-01 | 1 | -6/+6 | |
| | ||||||
* | Various comment fixes from Rafal Szczesniak <mimir@diament.ists.pwr.wroc.pl> | Andrew Bartlett | 2002-03-01 | 3 | -3/+3 | |
| | ||||||
* | Move wbinfo over to d_printf(). Patch by Hasch@t-online.de (Juergen Hasch) | Andrew Bartlett | 2002-03-01 | 1 | -55/+55 | |
| | | | | Andrew Bartlett | |||||
* | Fix up the pull_utf8_fstring/pstring functions, and add their push eqivilants. | Andrew Bartlett | 2002-03-01 | 1 | -4/+14 | |
| | | | | | | patch by Hasch@t-online.de (Juergen Hasch) Andrew Bartlett | |||||
* | Attempt to fix Solaris winbind nss build. | Jeremy Allison | 2002-03-01 | 3 | -30/+53 | |
| | | | | Jeremy. | |||||
* | This should kill off the 'cannot convert' error messages on non-iconv hosts. | Andrew Bartlett | 2002-03-01 | 1 | -1/+1 | |
| | ||||||
* | enable locking on the idmap database to make it safe to dump/restore | Andrew Tridgell | 2002-02-28 | 1 | -1/+1 | |
| | | | | it externally while winbindd is running | |||||
* | Ensure that winbindd and smbd both use identical logic to find dc's. | Jeremy Allison | 2002-02-28 | 3 | -47/+47 | |
| | | | | | Fix bug where zeroip addresses were being checked. Jeremy. | |||||
* | this allows us to support foreign SIDs in winbindd and smbd | Andrew Tridgell | 2002-02-27 | 6 | -119/+186 | |
| | | | | | | | this means "xcopy /o" has a chance of working with ACLs that contain ACEs that use SIDs that the Samba server has no knowledge of. It's a bit hackish, Tim, can you look at my uid.c changes? | |||||
* | Fix from JohnR - Fixed SetPrinterData(magic key) to support zero length ↵ | Jeremy Allison | 2002-02-27 | 1 | -1/+1 | |
| | | | | | | DEVMODE as is the case with the Okidata Okipage 20 PCLXL Advanced printer driver. | |||||
* | Patch for Domain users not showing up from "Ivan Zhakov" <vunny@mail.ru>. | Jeremy Allison | 2002-02-27 | 1 | -11/+11 | |
| | | | | Jeremy. | |||||
* | Added "nt status support" parameter. Fix offline synchronisation. | Jeremy Allison | 2002-02-27 | 6 | -28/+37 | |
| | | | | Jeremy. | |||||
* | Fixed usage of uninitialised variable in strict_allocate_ftruncate() | Tim Potter | 2002-02-27 | 1 | -1/+3 | |
| | ||||||
* | Memory leak on error condition fixed by Kian Win <codegrunt@rubbercookie.com>. | Jeremy Allison | 2002-02-27 | 1 | -0/+1 | |
| | | | | Jeremy. | |||||
* | Fixed dumb typo caught by Herb. | Jeremy Allison | 2002-02-27 | 1 | -1/+1 | |
| | | | | Jeremy. | |||||
* | This should fix up the level 0 'convert_string' debug messages that we have | Andrew Bartlett | 2002-02-27 | 1 | -1/+1 | |
| | | | | | | | | been seing since the unicode conversion. It looks like a simple oversight in the move away from StrnCpy (which takes amount of space -1 as an arg) to push_ascii etc which take the absolute amount of space. Andrew Bartlett | |||||
* | "user doesn't exist" isn't worthy of a level 1 debug. Make it level 3. | Andrew Bartlett | 2002-02-27 | 1 | -1/+1 | |
| | ||||||
* | This apparently makes winbind work on Solaris again | Andrew Bartlett | 2002-02-27 | 1 | -1/+1 | |
| | ||||||
* | Make this function static | Andrew Bartlett | 2002-02-27 | 1 | -1/+1 | |
| | ||||||
* | fix a few defines | Gerald Carter | 2002-02-27 | 1 | -0/+1 | |
| | ||||||
* | FIXME: Use next_token rather than strtok! | Martin Pool | 2002-02-26 | 1 | -0/+1 | |
| |