| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
|
|
|
|
|
|
| |
position zero being the primary group sid. Authenicating
via winbindd call returned a non-sorted sid list. This
fixes is for both a winbindd call and a pac list from
an info3 struct. Without this we mess up the
primary group associated with created files. Found by
Herb.
Jeremy.
(cherry picked from commit 5cfa78d6e45477cb952d3b12cc914635842d6251)
|
|
|
|
|
| |
Jeremy.
(cherry picked from commit 096ff390a24ce971c9a207493dc1b5d9f88518b6)
|
|
|
|
|
| |
Jeremy.
(cherry picked from commit 132a5f4a5740f8a4e3bd634af654c9761c11aa1a)
|
|
|
|
|
|
|
| |
account logon.
Jeremy.
(cherry picked from commit 2a3e2c9550acb1c55c0c55e4bfb0faaadad2f6fd)
|
|
|
|
|
|
|
|
|
| |
This has brown paper bag quality and is definitely needed for 3.2.0.
Thanks to Orion Poplawski for reporting this!
Volker
(cherry picked from commit 779a3af0cd3ecbf82e3de16a4e0aec046c19d869)
|
|
|
|
|
|
|
| |
Raise the debug msgs from Lvl 0 in the create_builtin_XX() functions
to prevent unnecessary panic from people reading the logs.
(cherry picked from commit 2983b9dc790e0f90ec1e6add131438c6bfd361b4)
(cherry picked from commit c28e21c63eca87a266078b65d65b436badc4e349)
|
|
|
|
|
| |
Michael
(cherry picked from commit 6bb107b17d557c27d035ca518ab61296814a3cea)
|
|
|
|
|
| |
Guenther
(cherry picked from commit 65b4cb20ea3fb806cfd50281e08f32bea70fafce)
|
|
|
|
|
| |
Karolin
(cherry picked from commit 6cee34703503fbf3629057345fe221b866560648)
|
|
|
|
|
|
|
|
|
|
|
|
| |
In order to avoid receiving NT_STATUS_DOWNGRADE_DETECTED from a w2k8
netr_ServerAuthenticate2 reply, we need to start with the AD netlogon negotiate
flags everywhere (not only when running in security=ads). Only for NT4 we need
to do a downgrade to the returned negotiate flags.
Tested with w2k8, w2ksp4, w2k3r2 and nt4sp6.
Guenther
(cherry picked from commit 0970369ca0cb9ae465cff40e5c75739824daf1d0)
|
|
|
|
|
|
|
| |
NTLMSSP and Kerberos session setup
Guenther
(cherry picked from commit 18b8c2c19e50aee8fc900c7507244cb95014a4fa)
|
|
|
|
|
|
|
| |
talloc_steal and talloc_free on the sam account already.
Guenther
(cherry picked from commit dbc7237a8a566f3e86bd6e4b48593b93c5bfb94e)
|
|
|
|
|
| |
Guenther
(cherry picked from commit 0ad00a452f03d8af6e6b6fabd4a05ca26a9910d0)
|
|
|
|
|
| |
Thanks to oster@cs.usask.ca
(cherry picked from commit f18a80575921a241c7243c5af5a0101a2956ff17)
|
|
|
|
|
|
|
|
| |
Another preparation to convert secrets.c to dbwrap: The dbwrap API does not
provide a sane tdb_lock_with_timeout abstraction. In the clustered case the DC
mutex is needed per-node anyway, so it is perfectly fine to use a local mutex
only.
(cherry picked from commit f94a63cd8f94490780ad9331da229c0bcb2ca5d6)
|
|
|
|
| |
Guenther
|
|
|
|
| |
Guenther
|
|
|
|
| |
Jeremy.
|
|
|
|
|
|
|
|
| |
smbd doesn't need $(WBCOMMON_OBJ) anymore,
it works with any libwbclient.so now
and may talk to an older winbindd.
metze
|
|
|
|
| |
Karolin
|
| |
|
| |
|
|
|
|
| |
Interop fixes for AD specific flags. Original patch from Todd Stetcher.
|
|
|
|
| |
Jeremy.
|
|
|
|
| |
Michael
|
|
|
|
| |
Jeremy.
|
|
|
|
|
| |
get_root_nt_token asks for "struct nt_user_token". talloc_get_type is not smart
enough to see that this is the same as NT_USER_TOKEN... :-)
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
| |
Implements a wrapper layer in winbind_util.c which are just stubs
if compiled --without-winbind. When building with winbindd, it
is now required to build the libwbclient DSO first (in the Makefile)
and then either set LD_LIBRARY_PATH or /etc/ld.so.conf to pick up the
library PATH.
|
|
|
|
| |
All callers are replaced by Get_Pwnam_alloc
|
|
|
|
| |
Jeremy.
|
|
|
|
| |
Jeremy.
|
|
|
|
| |
Michael
|
|
|
|
| |
Michael
|
|
|
|
| |
Jeremy.
|
| |
|
| |
|
|
|
|
| |
Michael
|
|
|
|
| |
Michael
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Up to now each caller used its own logic.
This eliminates code paths where there was a special treatment
of the following situation: the domain given is not our workgroup
(i.e. our own domain) and we are not a DC (i.e. it is not a typical
trusted domain situation). In situation the given domain name was
previously used as the machine account name, resulting in an account
name of DOMAIN\\DOMAIN$, which does not seem very reasonable to me.
get_trust_pw would not have obtained a password in this situation
anyways.
I hope I have not missed an important point here!
Michael
|
| |
|
|
|
|
| |
Jeremy, please check
|
|
|
|
|
| |
No more temptations to use static length strings.
Jeremy.
|
|
|
|
| |
Jeremy.
|
|
|
|
| |
Jeremy.
|
|
|
|
| |
Jeremy.
|
|
|
|
|
|
| |
I have a plan for dealing with the remaining..... Watch
this space.
Jeremy.
|
|
|
|
| |
Jeremy.
|