2 Samba Unix/Linux SMB client library
4 Copyright (C) 2021 Guenther Deschner (gd@samba.org)
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "utils/net.h"
23 #include "netapi/netapi_net.h"
24 #include "libcli/registry/util_reg.h"
25 #include "libcli/security/dom_sid.h"
26 #include "lib/cmdline/cmdline.h"
28 int net_offlinejoin_usage(struct net_context *c, int argc, const char **argv)
30 d_printf(_("\nnet offlinejoin [misc. options]\n"
31 "\tjoins a computer to a domain\n"));
32 d_printf(_("Valid commands:\n"));
33 d_printf(_("\tprovision\t\t\tProvision machine account in AD\n"));
34 d_printf(_("\trequestodj\t\t\tRequest offline domain join\n"));
35 d_printf(_("\tcomposeodj\t\t\tCompose offline domain join blob\n"));
36 net_common_flags_usage(c, argc, argv);
40 int net_offlinejoin(struct net_context *c, int argc, const char **argv)
43 NET_API_STATUS status;
45 if ((argc > 0) && (strcasecmp_m(argv[0], "HELP") == 0)) {
46 net_offlinejoin_usage(c, argc, argv);
51 net_offlinejoin_usage(c, argc, argv);
55 net_warn_member_options();
57 status = libnetapi_net_init(&c->netapi_ctx);
62 status = libnetapi_set_creds(c->netapi_ctx, c->creds);
67 if (c->opt_kerberos) {
68 libnetapi_set_use_kerberos(c->netapi_ctx);
71 if (strcasecmp_m(argv[0], "provision") == 0) {
72 ret = net_offlinejoin_provision(c, argc, argv);
78 if (strcasecmp_m(argv[0], "requestodj") == 0) {
79 ret = net_offlinejoin_requestodj(c, argc, argv);
85 if (strcasecmp_m(argv[0], "composeodj") == 0) {
86 ret = net_offlinejoin_composeodj(c, argc, argv);
95 static int net_offlinejoin_provision_usage(struct net_context *c, int argc, const char **argv)
97 d_printf(_("\nnet offlinejoin provision [misc. options]\n"
98 "\tProvisions machine account in AD\n"));
99 d_printf(_("Valid options:\n"));
100 d_printf(_("\tdomain=<DOMAIN>\t\t\t\tDefines AD Domain to join\n"));
101 d_printf(_("\tmachine_name=<MACHINE_NAME>\t\tDefines the machine account name\n"));
102 d_printf(_("\tmachine_account_ou=<OU>\t\t\tDefines the machine account organizational unit DN\n"));
103 d_printf(_("\tdcname=<DCNAME>\t\t\t\tSpecifices a Domain Controller to join to\n"));
104 d_printf(_("\tdefpwd\t\t\t\t\tUse default machine account password\n"));
105 d_printf(_("\treuse\t\t\t\t\tReuse existing machine account in AD\n"));
106 d_printf(_("\tsavefile=<FILENAME>\t\t\tFile to store the ODJ data\n"));
107 d_printf(_("\tprintblob\t\t\t\tPrint the base64 encoded ODJ data on stdout\n"));
108 net_common_flags_usage(c, argc, argv);
112 int net_offlinejoin_provision(struct net_context *c,
113 int argc, const char **argv)
115 NET_API_STATUS status;
116 const char *dcname = NULL;
117 const char *domain = NULL;
118 const char *machine_name = NULL;
119 const char *machine_account_ou = NULL;
120 const char *provision_text_data = NULL;
121 uint32_t options = 0;
122 const char *savefile = NULL;
123 bool printblob = false;
126 if (c->display_usage || argc == 1) {
127 return net_offlinejoin_provision_usage(c, argc, argv);
130 /* process additional command line args */
132 for (i = 0; i < argc; i++) {
134 if (strnequal(argv[i], "domain", strlen("domain"))) {
135 domain = get_string_param(argv[i]);
136 if (domain == NULL) {
140 if (strnequal(argv[i], "machine_name", strlen("machine_name"))) {
141 machine_name = get_string_param(argv[i]);
142 if (machine_name == NULL) {
146 if (strnequal(argv[i], "machine_account_ou", strlen("machine_account_ou"))) {
147 machine_account_ou = get_string_param(argv[i]);
148 if (machine_account_ou == NULL) {
152 if (strnequal(argv[i], "dcname", strlen("dcname"))) {
153 dcname = get_string_param(argv[i]);
154 if (dcname == NULL) {
158 if (strnequal(argv[i], "defpwd", strlen("defpwd"))) {
159 options |= NETSETUP_PROVISION_USE_DEFAULT_PASSWORD;
161 if (strnequal(argv[i], "reuse", strlen("reuse"))) {
162 options |= NETSETUP_PROVISION_REUSE_ACCOUNT;
164 if (strnequal(argv[i], "savefile", strlen("savefile"))) {
165 savefile = get_string_param(argv[i]);
166 if (savefile == NULL) {
170 if (strnequal(argv[i], "printblob", strlen("printblob"))) {
175 if (domain == NULL) {
176 d_printf("Failed to provision computer account: %s\n",
177 libnetapi_errstr(W_ERROR_V(WERR_INVALID_DOMAINNAME)));
181 if (machine_name == NULL) {
182 d_printf("Failed to provision computer account: %s\n",
183 libnetapi_errstr(W_ERROR_V(WERR_INVALID_COMPUTERNAME)));
187 status = NetProvisionComputerAccount(domain,
194 &provision_text_data);
196 d_printf("Failed to provision computer account: %s\n",
197 libnetapi_get_error_string(c->netapi_ctx, status));
201 if (savefile != NULL) {
203 DATA_BLOB ucs2_blob, blob;
207 * Windows produces and consumes UTF16/UCS2 encoded blobs
208 * so we also do it for compatibility. Someone may provision an
209 * account for a Windows machine with samba.
211 ok = push_reg_sz(c, &ucs2_blob, provision_text_data);
216 /* Add the unicode BOM mark */
217 blob = data_blob_talloc(c, NULL, ucs2_blob.length + 2);
222 memcpy(blob.data + 2, ucs2_blob.data, ucs2_blob.length);
224 ok = file_save(savefile, blob.data, blob.length);
226 d_printf("Failed to save %s: %s\n", savefile,
232 d_printf("Successfully provisioned computer '%s' in domain '%s'\n",
233 machine_name, domain);
236 printf("%s\n", provision_text_data);
242 static int net_offlinejoin_requestodj_usage(struct net_context *c, int argc, const char **argv)
244 d_printf(_("\nnet offlinejoin requestodj [misc. options]\n"
245 "\tRequests offline domain join\n"));
246 d_printf(_("Valid options:\n"));
247 d_printf(_("\tloadfile=<FILENAME>\t\t\tFile that provides the ODJ data\n"));
248 /*d_printf(_("\tlocalos\t\t\t\t\tModify the local machine\n"));*/
249 net_common_flags_usage(c, argc, argv);
253 int net_offlinejoin_requestodj(struct net_context *c,
254 int argc, const char **argv)
256 NET_API_STATUS status;
257 uint8_t *provision_bin_data = NULL;
258 size_t provision_bin_data_size = 0;
259 uint32_t options = NETSETUP_PROVISION_ONLINE_CALLER;
260 const char *loadfile = NULL;
261 const char *windows_path = NULL;
264 if (c->display_usage || argc == 1) {
265 return net_offlinejoin_requestodj_usage(c, argc, argv);
268 /* process additional command line args */
270 for (i = 0; i < argc; i++) {
272 if (strnequal(argv[i], "loadfile", strlen("loadfile"))) {
273 loadfile = get_string_param(argv[i]);
274 if (loadfile == NULL) {
279 if (strnequal(argv[i], "localos", strlen("localos"))) {
280 options |= NETSETUP_PROVISION_ONLINE_CALLER;
286 (uint8_t *)file_load(loadfile, &provision_bin_data_size, 0, c);
287 if (provision_bin_data == NULL) {
288 d_printf("Failed to read loadfile: %s\n", loadfile);
291 if (provision_bin_data_size > UINT32_MAX) {
292 d_printf("provision binary data size too big: %zu\n",
293 provision_bin_data_size);
297 status = NetRequestOfflineDomainJoin(provision_bin_data,
298 provision_bin_data_size,
301 if (status != 0 && status != 0x00000a99) {
302 /* NERR_JoinPerformedMustRestart */
303 printf("Failed to call NetRequestOfflineDomainJoin: %s\n",
304 libnetapi_get_error_string(c->netapi_ctx, status));
308 d_printf("Successfully requested Offline Domain Join\n");
313 static int net_offlinejoin_composeodj_usage(struct net_context *c,
317 d_printf(_("\nnet offlinejoin composeodj [misc. options]\n"
318 "\tComposes offline domain join blob\n"));
319 d_printf(_("Valid options:\n"));
320 d_printf(_("\tdomain_sid=<SID>\t\t\tThe domain SID\n"));
321 d_printf(_("\tdomain_guid=<GUID>\t\t\tThe domain GUID\n"));
322 d_printf(_("\tforest_name=<NAME>\t\t\tThe forest name\n"));
323 d_printf(_("\tdomain_is_nt4\t\t\t\tThe domain not AD but NT4\n"));
324 d_printf(_("\tsavefile=<FILENAME>\t\t\tFile to store the ODJ data\n"));
325 d_printf(_("\tprintblob\t\t\t\tPrint the base64 encoded ODJ data on stdout\n"));
326 net_common_flags_usage(c, argc, argv);
327 d_printf(_("Example:\n"));
328 d_printf("\tnet offlinejoin composeodj --realm=<realm> "
329 "--workgroup=<domain> domain_sid=<sid> domain_guid=<guid> "
330 "forest_name=<name> -S <dc name> -I <dc address> "
331 "--password=<password> printblob\n");
335 int net_offlinejoin_composeodj(struct net_context *c,
339 struct cli_credentials *creds = samba_cmdline_get_creds();
340 NET_API_STATUS status;
341 const char *dns_domain_name = NULL;
342 const char *netbios_domain_name = NULL;
343 const char *machine_account_name = NULL;
344 const char *machine_account_password = NULL;
345 const char *domain_sid_str = NULL;
346 const char *domain_guid_str = NULL;
347 struct dom_sid domain_sid;
348 struct GUID domain_guid;
349 const char *forest_name = NULL;
350 const char *dc_name = NULL;
351 char dc_address[INET6_ADDRSTRLEN] = { 0 };
352 bool domain_is_ad = true;
353 const char *provision_text_data = NULL;
354 const char *savefile = NULL;
355 bool printblob = false;
356 enum credentials_obtained obtained;
361 if (c->display_usage || argc < 4) {
362 return net_offlinejoin_composeodj_usage(c, argc, argv);
365 dns_domain_name = cli_credentials_get_realm(creds);
366 netbios_domain_name = cli_credentials_get_domain(creds);
368 machine_account_name = cli_credentials_get_username_and_obtained(creds, &obtained);
369 if (obtained < CRED_CALLBACK_RESULT) {
370 const char *netbios_name = cli_credentials_get_workstation(creds);
371 cli_credentials_set_username(
373 talloc_asprintf(c, "%s$", netbios_name),
377 machine_account_name = cli_credentials_get_username(creds);
378 machine_account_password = cli_credentials_get_password(creds);
379 dc_name = c->opt_host;
381 if (c->opt_have_ip) {
382 struct sockaddr_in *in4 = NULL;
383 struct sockaddr_in6 *in6 = NULL;
384 const char *p = NULL;
386 switch(c->opt_dest_ip.ss_family) {
388 in4 = (struct sockaddr_in *)&c->opt_dest_ip;
389 p = inet_ntop(AF_INET, &in4->sin_addr, dc_address, sizeof(dc_address));
392 in6 = (struct sockaddr_in6 *)&c->opt_dest_ip;
393 p = inet_ntop(AF_INET6, &in6->sin6_addr, dc_address, sizeof(dc_address));
396 d_printf("Unknown IP address family\n");
401 d_fprintf(stderr, "Failed to parse IP address: %s\n", strerror(errno));
406 /* process additional command line args */
408 for (i = 0; i < argc; i++) {
409 if (strnequal(argv[i], "domain_sid", strlen("domain_sid"))) {
410 domain_sid_str = get_string_param(argv[i]);
411 if (domain_sid_str == NULL) {
416 if (strnequal(argv[i], "domain_guid", strlen("domain_guid"))) {
417 domain_guid_str = get_string_param(argv[i]);
418 if (domain_guid_str == NULL) {
423 if (strnequal(argv[i], "forest_name", strlen("forest_name"))) {
424 forest_name = get_string_param(argv[i]);
425 if (forest_name == NULL) {
430 if (strnequal(argv[i], "savefile", strlen("savefile"))) {
431 savefile = get_string_param(argv[i]);
432 if (savefile == NULL) {
437 if (strnequal(argv[i], "printblob", strlen("printblob"))) {
441 if (strnequal(argv[i], "domain_is_nt4", strlen("domain_is_nt4"))) {
442 domain_is_ad = false;
446 /* Check command line arguments */
448 if (savefile == NULL && !printblob) {
449 d_printf("Choose either save the blob to a file or print it\n");
453 if (dns_domain_name == NULL) {
454 d_printf("Please provide a valid realm parameter (--realm)\n");
458 if (netbios_domain_name == NULL) {
459 d_printf("Please provide a valid domain parameter (--workgroup)\n");
463 if (dc_name == NULL) {
464 d_printf("Please provide a valid DC name parameter (-S)\n");
468 if (strlen(dc_address) == 0) {
469 d_printf("Please provide a valid domain controller address parameter (-I)\n");
473 if (machine_account_name == NULL) {
474 d_printf("Please provide a valid netbios name parameter\n");
478 if (machine_account_password == NULL) {
479 d_printf("Please provide a valid password parameter\n");
483 if (domain_sid_str == NULL) {
484 d_printf("Please provide a valid <domain_sid> parameter\n");
488 if (domain_guid_str == NULL) {
489 d_printf("Please provide a valid <domain_guid> parameter\n");
493 if (forest_name == NULL) {
494 d_printf("Please provide a valid <forest_name> parameter\n");
498 ok = dom_sid_parse(domain_sid_str, &domain_sid);
500 d_fprintf(stderr, _("Failed to parse domain SID\n"));
504 ntstatus = GUID_from_string(domain_guid_str, &domain_guid);
505 if (NT_STATUS_IS_ERR(ntstatus)) {
506 d_fprintf(stderr, _("Failed to parse domain GUID\n"));
510 status = NetComposeOfflineDomainJoin(dns_domain_name,
512 (struct domsid *)&domain_sid,
515 machine_account_name,
516 machine_account_password,
522 &provision_text_data);
524 d_printf("Failed to compose offline domain join blob: %s\n",
525 libnetapi_get_error_string(c->netapi_ctx, status));
529 if (savefile != NULL) {
530 DATA_BLOB ucs2_blob, blob;
533 * Windows produces and consumes UTF16/UCS2 encoded blobs
534 * so we also do it for compatibility. Someone may provision an
535 * account for a Windows machine with samba.
537 ok = push_reg_sz(c, &ucs2_blob, provision_text_data);
542 /* Add the unicode BOM mark */
543 blob = data_blob_talloc(c, NULL, ucs2_blob.length + 2);
548 memcpy(blob.data + 2, ucs2_blob.data, ucs2_blob.length);
550 ok = file_save(savefile, blob.data, blob.length);
552 d_printf("Failed to save %s: %s\n", savefile,
559 printf("%s\n", provision_text_data);