asn/samba.git
4 days agoWIP s3: Enable IAKerb asn-iakerb
Andreas Schneider [Mon, 29 Apr 2024 14:18:57 +0000 (16:18 +0200)]
WIP s3: Enable IAKerb

4 days agoWIP s3:gse: Implement support for IAKerb
Andreas Schneider [Thu, 25 Apr 2024 14:11:29 +0000 (16:11 +0200)]
WIP s3:gse: Implement support for IAKerb

4 days agoauth:gensec: Add definitions for IAKerb
Andreas Schneider [Thu, 25 Apr 2024 13:36:47 +0000 (15:36 +0200)]
auth:gensec: Add definitions for IAKerb

4 days agos3:gse: Send GSS_C_NO_BUFFER on the first pass
Andreas Schneider [Mon, 29 Apr 2024 07:36:01 +0000 (09:36 +0200)]
s3:gse: Send GSS_C_NO_BUFFER on the first pass

Documentation you find for gss_init_sec_context() states for
input_token:

    Specifies the token received from the context acceptor.
    GSS_C_NO_BUFFER should be specified if this is the first call to the
    gss_init_sec_context() routine.

Some of them also allow GSS_C_EMPTY_BUFFER to be passed. So better use
GSS_C_NO_BUFFER to be safe.

Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
4 days agos3:gse: Use smb_gss_mech_import_cred() in gse_init_server()
Andreas Schneider [Fri, 26 Apr 2024 08:54:47 +0000 (10:54 +0200)]
s3:gse: Use smb_gss_mech_import_cred() in gse_init_server()

4 days agos3:gse: Pass down the mech to gse_context_init()
Andreas Schneider [Fri, 26 Apr 2024 08:49:33 +0000 (10:49 +0200)]
s3:gse: Pass down the mech to gse_context_init()

4 days agolib:krb5_wrap: Implement smb_gss_mech_import_cred()
Andreas Schneider [Fri, 26 Apr 2024 08:40:13 +0000 (10:40 +0200)]
lib:krb5_wrap: Implement smb_gss_mech_import_cred()

4 days agos3:gse: Implement gensec_gse_security_by_oid()
Andreas Schneider [Thu, 25 Apr 2024 13:51:40 +0000 (15:51 +0200)]
s3:gse: Implement gensec_gse_security_by_oid()

4 days agoauth:gensec: Rename GENSEC_GSSAPI to GENSEC_GSS_KRB5
Andreas Schneider [Thu, 25 Apr 2024 13:33:07 +0000 (15:33 +0200)]
auth:gensec: Rename GENSEC_GSSAPI to GENSEC_GSS_KRB5

4 days agos4:auth:gensec: Remove trailing spaces in gensec_gssapi.c
Andreas Schneider [Thu, 25 Apr 2024 13:31:58 +0000 (15:31 +0200)]
s4:auth:gensec: Remove trailing spaces in gensec_gssapi.c

4 days agoRevert "HACK source4/lib/tls/tls_tstream.c gnutls_alpn_set_protocols(GNUTLS_ALPN_MAND...
Stefan Metzmacher [Fri, 15 Mar 2024 22:28:26 +0000 (23:28 +0100)]
Revert "HACK source4/lib/tls/tls_tstream.c gnutls_alpn_set_protocols(GNUTLS_ALPN_MANDATORY)"

This reverts commit 15ad5fcfc2c93dd7b3f96ce32f7ad095233f4c20.

4 days agoHACK source4/lib/tls/tls_tstream.c gnutls_alpn_set_protocols(GNUTLS_ALPN_MANDATORY)
Stefan Metzmacher [Fri, 15 Mar 2024 22:28:07 +0000 (23:28 +0100)]
HACK source4/lib/tls/tls_tstream.c gnutls_alpn_set_protocols(GNUTLS_ALPN_MANDATORY)

4 days agoRevert "HACK simulate GNUTLS_FORCE_FIPS_MODE=1"
Stefan Metzmacher [Wed, 13 Mar 2024 15:57:07 +0000 (16:57 +0100)]
Revert "HACK simulate GNUTLS_FORCE_FIPS_MODE=1"

This reverts commit f01ebfb6674ed77557617841ad5b104d3685a255.

4 days agoHACK simulate GNUTLS_FORCE_FIPS_MODE=1
Stefan Metzmacher [Wed, 13 Mar 2024 15:48:23 +0000 (16:48 +0100)]
HACK simulate GNUTLS_FORCE_FIPS_MODE=1

4 days agoRevert "HACK .gitlab-ci-main.yml only MIT fedora"
Stefan Metzmacher [Fri, 8 Mar 2024 10:50:32 +0000 (11:50 +0100)]
Revert "HACK .gitlab-ci-main.yml only MIT fedora"

This reverts commit 8268cfb12e340d7b7d572f7de0f6eb86c177ba6a.

4 days agoRevert "HACK debug smb_krb5_cc_get_lifetime"
Stefan Metzmacher [Fri, 8 Mar 2024 10:50:22 +0000 (11:50 +0100)]
Revert "HACK debug smb_krb5_cc_get_lifetime"

This reverts commit a495d388e6a2b25af5467f60bcb23b548cd790c1.

4 days agoRevert "DEBUG python/samba/tests/krb5/test_smb.py"
Stefan Metzmacher [Fri, 8 Mar 2024 10:50:22 +0000 (11:50 +0100)]
Revert "DEBUG python/samba/tests/krb5/test_smb.py"

This reverts commit 3e463b6d3f7bac78c83015c211422e17c441693c.

4 days agoDEBUG python/samba/tests/krb5/test_smb.py
Stefan Metzmacher [Fri, 8 Mar 2024 10:44:57 +0000 (11:44 +0100)]
DEBUG python/samba/tests/krb5/test_smb.py

4 days agoHACK debug smb_krb5_cc_get_lifetime
Stefan Metzmacher [Fri, 8 Mar 2024 10:44:29 +0000 (11:44 +0100)]
HACK debug smb_krb5_cc_get_lifetime

4 days agoHACK .gitlab-ci-main.yml only MIT fedora
Stefan Metzmacher [Fri, 8 Mar 2024 09:25:31 +0000 (10:25 +0100)]
HACK .gitlab-ci-main.yml only MIT fedora

4 days agoRevert "TODO cli_session_creds_init use_global_krb5_ccache"
Stefan Metzmacher [Thu, 7 Mar 2024 16:06:53 +0000 (17:06 +0100)]
Revert "TODO cli_session_creds_init use_global_krb5_ccache"

This reverts commit 1e82da22c043fe960a0a2d3028fd67fdcfb4d4cc.

4 days agoTODO cli_session_creds_init use_global_krb5_ccache
Stefan Metzmacher [Thu, 7 Mar 2024 15:43:43 +0000 (16:43 +0100)]
TODO cli_session_creds_init use_global_krb5_ccache

4 days agoRevert "TODO split KERB_AP_OPTIONS_CBT"
Stefan Metzmacher [Fri, 1 Mar 2024 15:17:51 +0000 (16:17 +0100)]
Revert "TODO split KERB_AP_OPTIONS_CBT"

This reverts commit a659c0807ec02ff97588c1c5cd838d39cb2f8707.

4 days agoRevert "third_party/heimdal/lib/asn1/krb5.asn1 fix KRB5-AUTHDATA-KERB-LOCAL KRB5...
Stefan Metzmacher [Mon, 12 Feb 2024 08:19:10 +0000 (09:19 +0100)]
Revert "third_party/heimdal/lib/asn1/krb5.asn1 fix KRB5-AUTHDATA-KERB-LOCAL KRB5-AUTHDATA-TOKEN-RESTRICTIONS"

This reverts commit b38fa8a12c33f2e9937b3b16b56fd6ea17e632bf.

4 days agoRevert "source3/librpc/crypto/gse.c authenticator-ad-types 141, 142, 143, 144"
Stefan Metzmacher [Mon, 12 Feb 2024 08:19:10 +0000 (09:19 +0100)]
Revert "source3/librpc/crypto/gse.c authenticator-ad-types 141, 142, 143, 144"

This reverts commit 45bdf4e51a1105243e8544f415503fd260ac6eb6.

4 days agoRevert "source4/auth/gensec/gensec_gssapi.c authenticator-ad-types 141, 142, 143...
Stefan Metzmacher [Mon, 12 Feb 2024 08:19:10 +0000 (09:19 +0100)]
Revert "source4/auth/gensec/gensec_gssapi.c authenticator-ad-types 141, 142, 143, 144"

This reverts commit fbe7878b1149322f1f445eaaa80bb984622f69dd.

4 days agoRevert "third_party/heimdal/lib/asn1/krb5.asn1 gss_set_name_attribute("ticket-authz...
Stefan Metzmacher [Mon, 12 Feb 2024 08:19:10 +0000 (09:19 +0100)]
Revert "third_party/heimdal/lib/asn1/krb5.asn1 gss_set_name_attribute("ticket-authz-data")"

This reverts commit bad3caa5f38938261746f45e4e21493b400e0364.

4 days agoRevert "SPLIT GENSEC_FEATURE_UNVERIFIED_TARGET_NAME"
Stefan Metzmacher [Mon, 12 Feb 2024 08:19:10 +0000 (09:19 +0100)]
Revert "SPLIT GENSEC_FEATURE_UNVERIFIED_TARGET_NAME"

This reverts commit c77664e055ff3fe68c3136850a97ac65b244298b.

4 days agoSPLIT GENSEC_FEATURE_UNVERIFIED_TARGET_NAME
Stefan Metzmacher [Wed, 7 Feb 2024 16:32:59 +0000 (17:32 +0100)]
SPLIT GENSEC_FEATURE_UNVERIFIED_TARGET_NAME

4 days agothird_party/heimdal/lib/asn1/krb5.asn1 gss_set_name_attribute("ticket-authz-data")
Stefan Metzmacher [Wed, 7 Feb 2024 16:19:08 +0000 (17:19 +0100)]
third_party/heimdal/lib/asn1/krb5.asn1 gss_set_name_attribute("ticket-authz-data")

4 days agosource4/auth/gensec/gensec_gssapi.c authenticator-ad-types 141, 142, 143, 144
Stefan Metzmacher [Wed, 31 Jan 2024 15:14:03 +0000 (16:14 +0100)]
source4/auth/gensec/gensec_gssapi.c authenticator-ad-types 141, 142, 143, 144

4 days agosource3/librpc/crypto/gse.c authenticator-ad-types 141, 142, 143, 144
Stefan Metzmacher [Wed, 31 Jan 2024 15:14:03 +0000 (16:14 +0100)]
source3/librpc/crypto/gse.c authenticator-ad-types 141, 142, 143, 144

4 days agothird_party/heimdal/lib/asn1/krb5.asn1 fix KRB5-AUTHDATA-KERB-LOCAL KRB5-AUTHDATA...
Stefan Metzmacher [Wed, 31 Jan 2024 15:52:54 +0000 (16:52 +0100)]
third_party/heimdal/lib/asn1/krb5.asn1 fix KRB5-AUTHDATA-KERB-LOCAL KRB5-AUTHDATA-TOKEN-RESTRICTIONS

4 days agoTODO split KERB_AP_OPTIONS_CBT
Stefan Metzmacher [Tue, 30 Jan 2024 15:39:15 +0000 (16:39 +0100)]
TODO split KERB_AP_OPTIONS_CBT

4 days agoRevert "debug dcname winbind"
Stefan Metzmacher [Thu, 15 Feb 2024 17:55:52 +0000 (18:55 +0100)]
Revert "debug dcname winbind"

This reverts commit c1bfbc7ba752d27989239e36a070e4689e0a8f7c.

4 days agoRevert "debug source4/rpc_server/netlogon/dcerpc_netlogon.c dsname"
Stefan Metzmacher [Thu, 15 Feb 2024 17:55:52 +0000 (18:55 +0100)]
Revert "debug source4/rpc_server/netlogon/dcerpc_netlogon.c dsname"

This reverts commit 3d3400c2820f59bc054d828009a017c7c77e6466.

4 days agodebug source4/rpc_server/netlogon/dcerpc_netlogon.c dsname
Stefan Metzmacher [Wed, 14 Feb 2024 11:37:18 +0000 (12:37 +0100)]
debug source4/rpc_server/netlogon/dcerpc_netlogon.c dsname

4 days agodebug dcname winbind
Stefan Metzmacher [Wed, 14 Feb 2024 11:35:57 +0000 (12:35 +0100)]
debug dcname winbind

4 days agoRevert "selftest ldaps ad_member_idmap_ad"
Stefan Metzmacher [Fri, 5 Apr 2024 14:32:32 +0000 (16:32 +0200)]
Revert "selftest ldaps ad_member_idmap_ad"

This reverts commit 43d1232223f8c419ff7dece8491ffc3d297596b3.

4 days agoselftest ldaps ad_member_idmap_ad
Stefan Metzmacher [Wed, 14 Feb 2024 11:36:33 +0000 (12:36 +0100)]
selftest ldaps ad_member_idmap_ad

4 days agosource4/dsdb/repl/drepl_out_helpers.c always go via dreplsrv_out_drsuapi_send() https...
Stefan Metzmacher [Tue, 6 Feb 2024 20:09:58 +0000 (21:09 +0100)]
source4/dsdb/repl/drepl_out_helpers.c always go via dreplsrv_out_drsuapi_send() https://bugzilla.samba.org/show_bug.cgi?id=15573

to call dreplsrv_op_pull_source_get_changes_trigger

4 days agoTODO: docs-xml/smbdotconf/security/clientusedefaultkrb5ccache.xml
Stefan Metzmacher [Thu, 14 Apr 2022 10:48:54 +0000 (12:48 +0200)]
TODO: docs-xml/smbdotconf/security/clientusedefaultkrb5ccache.xml

4 days agosource3/script/tests/test_smbclient_krb5.sh STEP3
Stefan Metzmacher [Wed, 16 Mar 2022 11:30:39 +0000 (12:30 +0100)]
source3/script/tests/test_smbclient_krb5.sh STEP3

4 days agosource3/script/tests/test_smbclient_krb5.sh STEP2
Stefan Metzmacher [Wed, 16 Mar 2022 11:30:28 +0000 (12:30 +0100)]
source3/script/tests/test_smbclient_krb5.sh STEP2

4 days agosource3/script/tests/test_smbclient_krb5.sh STEP 1
Stefan Metzmacher [Wed, 16 Mar 2022 11:29:58 +0000 (12:29 +0100)]
source3/script/tests/test_smbclient_krb5.sh STEP 1

4 days agoHACK testprogs/blackbox/test_kinit.sh force fail
Stefan Metzmacher [Fri, 8 Mar 2024 12:20:19 +0000 (13:20 +0100)]
HACK testprogs/blackbox/test_kinit.sh force fail

4 days agotestprogs/blackbox/test_kinit.sh also test --use-default-krb5-ccache
Stefan Metzmacher [Fri, 8 Mar 2024 12:03:05 +0000 (13:03 +0100)]
testprogs/blackbox/test_kinit.sh also test --use-default-krb5-ccache

4 days agosq docs-xml/build/DTD/samba.entities
Stefan Metzmacher [Sat, 9 Mar 2024 10:05:16 +0000 (11:05 +0100)]
sq docs-xml/build/DTD/samba.entities

4 days agosq fix python/samba/getopt.py
Stefan Metzmacher [Wed, 16 Mar 2022 13:08:11 +0000 (14:08 +0100)]
sq fix python/samba/getopt.py

4 days agofix python/samba/getopt.py
Stefan Metzmacher [Wed, 16 Mar 2022 13:08:11 +0000 (14:08 +0100)]
fix python/samba/getopt.py

4 days agoTODO-SPLIT add --use-default-krb5-ccache to select the default ccache
Stefan Metzmacher [Wed, 16 Mar 2022 10:39:56 +0000 (11:39 +0100)]
TODO-SPLIT add --use-default-krb5-ccache to select the default ccache

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15018

Signed-off-by: Stefan Metzmacher <metze@samba.org>
4 days agoRevert "lib/cmdline/cmdline.c --use-krb5-ccache= needs to export KRB5CCNAME"
Stefan Metzmacher [Thu, 7 Mar 2024 13:59:09 +0000 (14:59 +0100)]
Revert "lib/cmdline/cmdline.c --use-krb5-ccache= needs to export KRB5CCNAME"

This reverts commit e8d407360d1ac2cf835c6321bb94e55c4a5bb150.

4 days agolib/cmdline/cmdline.c --use-krb5-ccache= needs to export KRB5CCNAME
Stefan Metzmacher [Wed, 16 Mar 2022 11:42:56 +0000 (12:42 +0100)]
lib/cmdline/cmdline.c --use-krb5-ccache= needs to export KRB5CCNAME

4 days agotestprogs/blackbox/test_weak_disable_ntlmssp_ldap.sh sq s3:libads: let ads_sasl_spneg...
Stefan Metzmacher [Wed, 13 Mar 2024 15:54:45 +0000 (16:54 +0100)]
testprogs/blackbox/test_weak_disable_ntlmssp_ldap.sh sq s3:libads: let ads_sasl_spnego_bind() really use spnego to negotiate krb5/ntlmssp

4 days agotestprogs/blackbox/test_weak_disable_ntlmssp_ldap.sh better names
Stefan Metzmacher [Wed, 13 Mar 2024 15:53:44 +0000 (16:53 +0100)]
testprogs/blackbox/test_weak_disable_ntlmssp_ldap.sh better names

4 days agosq lib/addns/dnsgss.c GENSEC_UPDATE_IS_NTERROR
Stefan Metzmacher [Wed, 13 Mar 2024 14:41:00 +0000 (15:41 +0100)]
sq lib/addns/dnsgss.c GENSEC_UPDATE_IS_NTERROR

4 days agosq source3/utils/net_rpc.c !c->explicit_credentials => NET_FLAGS_ANONYMOUS
Stefan Metzmacher [Wed, 13 Mar 2024 16:56:56 +0000 (17:56 +0100)]
sq source3/utils/net_rpc.c !c->explicit_credentials => NET_FLAGS_ANONYMOUS

4 days agosource3/utils/net.c cli_credentials_get_principal_obtained => c->explicit_credentials
Stefan Metzmacher [Wed, 13 Mar 2024 16:56:33 +0000 (17:56 +0100)]
source3/utils/net.c cli_credentials_get_principal_obtained => c->explicit_credentials

4 days agopython/samba/tests/ntlm_auth.py fix test_ntlmssp_gss_spnego_cached_creds
Stefan Metzmacher [Wed, 13 Mar 2024 09:49:55 +0000 (10:49 +0100)]
python/samba/tests/ntlm_auth.py fix test_ntlmssp_gss_spnego_cached_creds

4 days agomove ads_simple_creds up
Stefan Metzmacher [Wed, 13 Mar 2024 09:16:36 +0000 (10:16 +0100)]
move ads_simple_creds up

4 days agosq remove ads_legacy_creds source3/libads/ads_proto.h
Stefan Metzmacher [Wed, 13 Mar 2024 09:15:29 +0000 (10:15 +0100)]
sq remove ads_legacy_creds source3/libads/ads_proto.h

4 days agosq ads_connect_simple_anon
Stefan Metzmacher [Wed, 13 Mar 2024 08:27:13 +0000 (09:27 +0100)]
sq ads_connect_simple_anon

4 days agosq ads_connect_cldap_only
Stefan Metzmacher [Wed, 13 Mar 2024 08:26:11 +0000 (09:26 +0100)]
sq ads_connect_cldap_only

4 days agoremove ads_connect_no_bind
Stefan Metzmacher [Wed, 13 Mar 2024 08:25:03 +0000 (09:25 +0100)]
remove ads_connect_no_bind

4 days agono ADS_AUTH_CLDAP_ONLY
Stefan Metzmacher [Wed, 13 Mar 2024 08:24:18 +0000 (09:24 +0100)]
no ADS_AUTH_CLDAP_ONLY

4 days agosplit cldap_only
Stefan Metzmacher [Wed, 13 Mar 2024 08:23:04 +0000 (09:23 +0100)]
split cldap_only

4 days agostill ok
Stefan Metzmacher [Wed, 13 Mar 2024 08:13:44 +0000 (09:13 +0100)]
still ok

4 days agofix ADS_AUTH_GENERATE_KRB5_CONFIG recursion
Stefan Metzmacher [Wed, 13 Mar 2024 08:09:33 +0000 (09:09 +0100)]
fix ADS_AUTH_GENERATE_KRB5_CONFIG recursion

4 days agostill ok
Stefan Metzmacher [Tue, 12 Mar 2024 14:17:26 +0000 (15:17 +0100)]
still ok

4 days agostill ok
Stefan Metzmacher [Tue, 12 Mar 2024 14:13:33 +0000 (15:13 +0100)]
still ok

4 days agostill ok
Stefan Metzmacher [Tue, 12 Mar 2024 14:11:08 +0000 (15:11 +0100)]
still ok

4 days agostill ok
Stefan Metzmacher [Tue, 12 Mar 2024 14:09:37 +0000 (15:09 +0100)]
still ok

4 days agosq sq s3:net_ads: make use of ads_connect_creds() in ads_startup_int() AND ads_connec...
Stefan Metzmacher [Tue, 12 Mar 2024 13:55:54 +0000 (14:55 +0100)]
sq sq s3:net_ads: make use of ads_connect_creds() in ads_startup_int() AND ads_connect_no_bind OK!

4 days agosq ads_connect_creds => ads_connect_internal
Stefan Metzmacher [Tue, 12 Mar 2024 13:45:57 +0000 (14:45 +0100)]
sq ads_connect_creds => ads_connect_internal

4 days agosq ads_connect_creds ADS_AUTH_NO_BIND no asserted creds OK!
Stefan Metzmacher [Tue, 12 Mar 2024 13:22:14 +0000 (14:22 +0100)]
sq ads_connect_creds ADS_AUTH_NO_BIND no asserted creds OK!

4 days agosq s3:net_ads: make use of ads_connect_creds() in ads_startup_int()
Stefan Metzmacher [Tue, 12 Mar 2024 13:16:37 +0000 (14:16 +0100)]
sq s3:net_ads: make use of ads_connect_creds() in ads_startup_int()

4 days agosq ads_connect_machine ok?
Stefan Metzmacher [Tue, 12 Mar 2024 13:11:31 +0000 (14:11 +0100)]
sq ads_connect_machine ok?

4 days agosq ads_connect_anon() ok?
Stefan Metzmacher [Tue, 12 Mar 2024 13:10:01 +0000 (14:10 +0100)]
sq ads_connect_anon() ok?

4 days agosq ADS_AUTH_GENERATE_KRB5_CONFIG ok?
Stefan Metzmacher [Tue, 12 Mar 2024 12:59:06 +0000 (13:59 +0100)]
sq ADS_AUTH_GENERATE_KRB5_CONFIG ok?

4 days agoworks net_offline
Stefan Metzmacher [Tue, 12 Mar 2024 12:57:52 +0000 (13:57 +0100)]
works net_offline

4 days agoRevert "sq ADS_AUTH_GENERATE_KRB5_CONFIG"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "sq ADS_AUTH_GENERATE_KRB5_CONFIG"

This reverts commit f3ea4a5ffe4f0adaa40e1bbdb6b5b4e7657f4d09.

4 days agoRevert "sq ads_connect_anon"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "sq ads_connect_anon"

This reverts commit 9ce6bdc773e1eaeb8983a6a5917a33f13dd6f3c6.

4 days agoRevert "SQ??? ads_connect_creds allow NO/ANON_BIND upgrades"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "SQ??? ads_connect_creds allow NO/ANON_BIND upgrades"

This reverts commit 18064b62abe554ce08fd0e0ceed4cb0ff9a04a3e.

4 days agoRevert "sq ads_connect_anon"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "sq ads_connect_anon"

This reverts commit 8c81208038c88e7520d5a412b2bb89314405893a.

4 days agoRevert "sq ads_connect_no_bind"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "sq ads_connect_no_bind"

This reverts commit 080a38b93460e7930464ced893a5736cd2555a1a.

4 days agoRevert "sq ads_connect_machine"
Stefan Metzmacher [Tue, 12 Mar 2024 12:50:15 +0000 (13:50 +0100)]
Revert "sq ads_connect_machine"

This reverts commit 232539c59ebf72d5671e13da0b340588bc7043b9.

4 days agosq ads_connect_machine
Stefan Metzmacher [Tue, 12 Mar 2024 12:46:02 +0000 (13:46 +0100)]
sq ads_connect_machine

4 days agosq ads_connect_no_bind
Stefan Metzmacher [Tue, 12 Mar 2024 12:45:48 +0000 (13:45 +0100)]
sq ads_connect_no_bind

4 days agosq ads_connect_anon
Stefan Metzmacher [Tue, 12 Mar 2024 12:45:35 +0000 (13:45 +0100)]
sq ads_connect_anon

4 days agoSQ??? ads_connect_creds allow NO/ANON_BIND upgrades
Stefan Metzmacher [Tue, 12 Mar 2024 12:45:03 +0000 (13:45 +0100)]
SQ??? ads_connect_creds allow NO/ANON_BIND upgrades

4 days agosq ads_connect_anon
Stefan Metzmacher [Tue, 12 Mar 2024 12:21:32 +0000 (13:21 +0100)]
sq ads_connect_anon

4 days agosq ADS_AUTH_GENERATE_KRB5_CONFIG
Stefan Metzmacher [Tue, 12 Mar 2024 12:21:10 +0000 (13:21 +0100)]
sq ADS_AUTH_GENERATE_KRB5_CONFIG

4 days agoSPLIT require explicit ccache
Stefan Metzmacher [Mon, 11 Mar 2024 16:46:45 +0000 (17:46 +0100)]
SPLIT require explicit ccache

4 days agoSPLIT??? kerberos_set_password ads_krb5_set_password no implicit ccache
Stefan Metzmacher [Mon, 11 Mar 2024 16:45:43 +0000 (17:45 +0100)]
SPLIT??? kerberos_set_password ads_krb5_set_password no implicit ccache

4 days agos3:libsmb: fix lpcfg_gensec_settings() no memory check in auth_generic_client_prepare()
Stefan Metzmacher [Tue, 12 Mar 2024 10:51:25 +0000 (11:51 +0100)]
s3:libsmb: fix lpcfg_gensec_settings() no memory check in auth_generic_client_prepare()

Signed-off-by: Stefan Metzmacher <metze@samba.org>
4 days agoDoDNSUpdateNegotiateGensec GENSEC_FEATURE_SIGN why crash???
Stefan Metzmacher [Sat, 9 Mar 2024 10:04:59 +0000 (11:04 +0100)]
DoDNSUpdateNegotiateGensec GENSEC_FEATURE_SIGN why crash???

4 days agoblackbox/test_kinit.sh: verify that --use-krb5-ccache= works without KRB5CCNAME
Stefan Metzmacher [Fri, 8 Mar 2024 11:57:06 +0000 (12:57 +0100)]
blackbox/test_kinit.sh: verify that --use-krb5-ccache= works without KRB5CCNAME

Signed-off-by: Stefan Metzmacher <metze@samba.org>
4 days agos3:net: finally remove net_context->opt_{user_specified,user_name,password}
Stefan Metzmacher [Thu, 7 Mar 2024 13:56:45 +0000 (14:56 +0100)]
s3:net: finally remove net_context->opt_{user_specified,user_name,password}

Signed-off-by: Stefan Metzmacher <metze@samba.org>
4 days agos3:net_ads: use cli_credentials_get_principal() in order to call kerberos functions
Stefan Metzmacher [Thu, 7 Mar 2024 13:55:09 +0000 (14:55 +0100)]
s3:net_ads: use cli_credentials_get_principal() in order to call kerberos functions

This is better than the value from cli_credentials_get_username()...

Signed-off-by: Stefan Metzmacher <metze@samba.org>
4 days agos3:net: remove useless net_prompt_pass() wrapper
Stefan Metzmacher [Thu, 7 Mar 2024 13:54:18 +0000 (14:54 +0100)]
s3:net: remove useless net_prompt_pass() wrapper

Signed-off-by: Stefan Metzmacher <metze@samba.org>