summaryrefslogtreecommitdiffstats
path: root/source4
Commit message (Collapse)AuthorAgeFilesLines
* s4-auth: fixed infinite loop in krb5 authAndrew Tridgell2010-11-141-1/+1
| | | | | | | | we were continually trying the first address returned, instead of moving to the next address Autobuild-User: Andrew Tridgell <tridge@samba.org> Autobuild-Date: Sun Nov 14 04:11:28 UTC 2010 on sn-devel-104
* s4-auth: fixed crash in krb5 authAndrew Tridgell2010-11-141-2/+1
| | | | remote_addr was used after free
* s4:password_hash LDB module - return "ERR_CONSTRAINT_VIOLATION" on password ↵Matthias Dieter Wallnöfer2010-11-131-6/+9
| | | | | | | | | | conversion errors This errors can happen also on a regular basis - then we shouldn't return ERR_OPERATIONS_ERROR (this error code is reserved for very serious failures). Autobuild-User: Matthias Dieter Wallnöfer <mdw@samba.org> Autobuild-Date: Sat Nov 13 12:37:36 UTC 2010 on sn-devel-104
* s4:upgradeprovision - why not directly use "provision:0"?Matthias Dieter Wallnöfer2010-11-131-4/+4
|
* s4:objectclass LDB module - multiple "objectClass" change elements are ↵Matthias Dieter Wallnöfer2010-11-132-173/+178
| | | | | | unfortunately still allowed The test message has been compressed - therefore I've now used "modify_ldif".
* s4-drs: fixed a crash in writspnAndrew Tridgell2010-11-131-2/+8
| | | | | | | sam_ctx_system may be NULL for non-privileged users Autobuild-User: Andrew Tridgell <tridge@samba.org> Autobuild-Date: Sat Nov 13 08:52:53 UTC 2010 on sn-devel-104
* s4-test: we need to import testtools before subunit/pythonAndrew Tridgell2010-11-131-1/+1
| | | | | | | subunit/python depends on testtools Autobuild-User: Andrew Tridgell <tridge@samba.org> Autobuild-Date: Sat Nov 13 02:02:45 UTC 2010 on sn-devel-104
* ktpass: also use userPrincipalName for locating the principalMatthieu Patou2010-11-121-1/+2
| | | | | Autobuild-User: Matthieu Patou <mat@samba.org> Autobuild-Date: Fri Nov 12 20:24:23 UTC 2010 on sn-devel-104
* ktpass: fix the search path for when running in samba's source dirMatthieu Patou2010-11-121-0/+3
|
* python: use the ldbMessage + modify notation instead of modify_ldif that we ↵Matthieu Patou2010-11-121-7/+6
| | | | try to avoid
* Fix typoMatthieu Patou2010-11-121-1/+1
|
* unit tests: add testing for dns account password changeMatthieu Patou2010-11-121-0/+4
|
* upgradeprovision: use relaxed control while adding missing object containerMatthieu Patou2010-11-121-1/+3
|
* upgradeprovision: fix pb with dns-hostname, regenerate a correct keytabMatthieu Patou2010-11-122-1/+75
|
* upgradeprovision: use the relax/(upgrade)provision when modifying objectMatthieu Patou2010-11-121-1/+8
| | | | | | For certain attribute we use the relax/provision control so that we try to respect checks as this is not a good idea to always force unwanted behavior.
* upgradeprovision: use the (upgrade)provision control alsoMatthieu Patou2010-11-121-2/+2
|
* upgradeprovision: update revision for forestupdate and domainupdate objectsMatthieu Patou2010-11-121-1/+4
|
* samldb: relax groupType modification checksMatthieu Patou2010-11-121-27/+32
| | | | | Allow programs with the PROVISION control to bypass groupType checks. This is needed by upgradeprovision for older alpha (11, 10 ...)
* Add a script to make backup of samba provisionMatthieu Patou2010-11-121-0/+65
|
* s4:objectclass LDB module - we should not simply ignore additional ↵Matthias Dieter Wallnöfer2010-11-122-2/+29
| | | | | | | | | | "objectClass" attribute changes There first one we perform all other tentatives are terminated with ERR_ATTRIBUTE_OR_VALUE_EXISTS (tested against Windows). Autobuild-User: Matthias Dieter Wallnöfer <mdw@samba.org> Autobuild-Date: Fri Nov 12 19:39:07 UTC 2010 on sn-devel-104
* s4:repl_meta_data LDB module - convert two debug messages into error messagesMatthias Dieter Wallnöfer2010-11-121-4/+4
| | | | These regarding "objectGUID".
* s4:samldb/objectclass_attrs LDB modules - move "description" logic from ↵Matthias Dieter Wallnöfer2010-11-124-198/+245
| | | | | | "objectclass_attrs" into "samldb" This according to an answer from dochelp is SAM specific behaviour.
* s4: Remove obsolete mkversion.shJelmer Vernooij2010-11-121-133/+0
|
* samba_version: When working from git checkout, display git revision SHA1 ratherJelmer Vernooij2010-11-121-1/+1
| | | | than Bazaar revision ids.
* torture: Only add in tests for socket_wrapper/nss_wrapper when they have ↵Jelmer Vernooij2010-11-122-2/+18
| | | | been enabled.
* unix_privs: Add missing dependency on libreplace.Jelmer Vernooij2010-11-121-1/+1
|
* heimdal_build: Add missing dependency on replace, necessary because ↵Jelmer Vernooij2010-11-121-1/+1
| | | | replace.h is included.
* Lowercase DNS_UPDATE_SRV name.Jelmer Vernooij2010-11-121-1/+1
|
* s4-kdc: added proxying of kdc requests for RODCsAndrew Tridgell2010-11-125-66/+782
| | | | | | | | | | | | when we are an RODC and we get a request for a principal that we don't have the right secrets for, we need to proxy the request to a writeable DC. This happens for both TCP and UDP requests, for both krb5 and kpasswd Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> Autobuild-User: Andrew Tridgell <tridge@samba.org> Autobuild-Date: Fri Nov 12 08:03:20 UTC 2010 on sn-devel-104
* s4-kdc Return HDB_ERR_NOT_FOUND_HERE on un-revealed accounts on an RODCAndrew Bartlett2010-11-121-1/+7
| | | | | | | | | | This means that when we are an RODC, and an account does not have the password attributes, we can now indicate to the kdc code that it should forward the request to a real DC. (The proxy code itself is not in this commit). Andrew Bartlett
* heimdal Return HDB_ERR_NOT_FOUND_HERE to the callerAndrew Bartlett2010-11-123-11/+34
| | | | | | | | This means that no reply packet should be generated, but that instead the user of the libkdc API should forward the packet to a real KDC, that has a full database. Andrew Bartlett
* s4-kdc: split the kdc process return into a tri-stateAndrew Tridgell2010-11-123-53/+59
| | | | | | this is in preparation for doing forwarding of packets for RODCs Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>
* s4-kdc: we don't need the special include handling nowAndrew Tridgell2010-11-121-6/+0
| | | | | | | the special handling was to cope with the conflict with the kdc.h header Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>
* s4-kdc: rename kdc/kdc.h to kdc/kdc-glue.hAndrew Tridgell2010-11-126-5/+5
| | | | kdc.h conflicts with a heimdal header name
* s4-tests: Make repl_schema.py test part of Samba4 test suiteKamen Mazdrashki2010-11-111-0/+1
| | | | | Autobuild-User: Kamen Mazdrashki <kamenim@samba.org> Autobuild-Date: Thu Nov 11 19:38:18 UTC 2010 on sn-devel-104
* s4-repl: Propagate remote prefixMap in DRSUAPI data conversion functionsKamen Mazdrashki2010-11-113-4/+31
|
* s4-dsdb_syntax: Warning message that we can't find requested ATTID in Schema ↵Kamen Mazdrashki2010-11-111-0/+1
| | | | Cache
* s4-prefixMap: dsdb_schema_pfm_oid_from_attid() to use const prefixMapKamen Mazdrashki2010-11-111-1/+2
| | | | It is not supposed to change supplied prefixMap
* s4-dsdb_syntax: Use remote prefixMap to handle generic cases in ↵Kamen Mazdrashki2010-11-111-2/+7
| | | | drsuapi_to_ldb conversions
* s4-dsdb_syntax: Add remote prefixMap member for dsdb_syntax conversionsKamen Mazdrashki2010-11-112-0/+5
|
* s4-repl: dsdb_extended_replicated_objects_convert -> ↵Kamen Mazdrashki2010-11-114-54/+54
| | | | | | dsdb_replicated_objects_convert/ It is part of dsdb_replicated_* family of functions
* s4-repl: dsdb_extended_replicated_objects_commit -> ↵Kamen Mazdrashki2010-11-113-9/+8
| | | | | | dsdb_replicated_objects_commit It is part of dsdb_replicated_* family of functions
* s4-repl: dsdb_convert_object -> dsdb_origin_object_convertKamen Mazdrashki2010-11-111-7/+7
| | | | | It is used in dsdb_origin_objects_commit() func, hence the dsdb_origin_ prefix
* s4-test: repl_schema - Make sure LdbError and ERR_NO_SUCH_OBJECT are visibleKamen Mazdrashki2010-11-111-0/+1
|
* s4/test: Expand BindTestAnatoliy Atanasov2010-11-111-20/+60
| | | | | | | The test now binds with user@realm, domain\user, user dn, computer dn Autobuild-User: Anatoliy Atanasov <anatoliy.atanasov@postpath.com> Autobuild-Date: Thu Nov 11 16:15:30 UTC 2010 on sn-devel-104
* s4/test: Add bind.py to make testAnatoliy Atanasov2010-11-111-0/+1
| | | | | bind.py is a place to have tests for ldb binding with different credentials. For starter we have a simple bind with machine account.
* heimdal Don't dereference NULL in error verify_checksum error pathAndrew Bartlett2010-11-111-1/+1
| | | | | Autobuild-User: Andrew Bartlett <abartlet@samba.org> Autobuild-Date: Thu Nov 11 10:37:03 UTC 2010 on sn-devel-104
* s4-provision UTF16 encode the password in sam.ldb, not secrets.ldbAndrew Bartlett2010-11-111-2/+2
| | | | | | | | | | The password in secrets.ldb is UTF8, while clearTextPassword in sam.ldb is UTF16. This corrects commit bd5039546e520b6d6897a658bc0a358f0511f7c7, which had these the wrong way around. Andrew Bartlett
* s4-dsdb Remove incorrectly declared ** variable used as *.Andrew Bartlett2010-11-111-6/+3
| | | | | | | | | | | The cleartext_utf16_str variable was declared char **, but due to the cast on convert_string_talloc() and the lack of type checking here and on data_blob_const (due to void *) it was able to be used as if it was a char *. The simple solution seems to be to fill in cleartext_utf16 blob directly. Andrew Bartlett
* s4-dsdb Convert new krbtgt_xxx password into UTF16Andrew Bartlett2010-11-111-1/+12
| | | | | | | The new stricter test on clearTextPassword values caught out that we did not provide a utf16 password here. Andrew Bartlett