Make sure we can read SACLs from the registry.
[tprouty/samba.git] / source3 / utils / net_rpc_registry.c
index 776a49f99cc46567a872c86ea23e1d7d1a3b78cf..e1d65fb06b0916d6df6c75b54f2d9a70e19ebfbd 100644 (file)
@@ -6,7 +6,7 @@
 
    This program is free software; you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
-   the Free Software Foundation; either version 2 of the License, or
+   the Free Software Foundation; either version 3 of the License, or
    (at your option) any later version.
    
    This program is distributed in the hope that it will be useful,
    GNU General Public License for more details.
    
    You should have received a copy of the GNU General Public License
-   along with this program; if not, write to the Free Software
-   Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.  */
+   along with this program.  If not, see <http://www.gnu.org/licenses/>.  */
  
 #include "includes.h"
 #include "utils/net.h"
 #include "regfio.h"
 #include "reg_objects.h"
 
-/********************************************************************
-********************************************************************/
-
-void dump_regval_buffer( uint32 type, REGVAL_BUFFER *buffer )
+static bool reg_hive_key(const char *fullname, uint32 *reg_type,
+                        const char **key_name)
 {
-       pstring string;
-       uint32 value;
-       
-       switch (type) {
-       case REG_SZ:
-               rpcstr_pull( string, buffer->buffer, sizeof(string), -1, STR_TERMINATE );
-               d_printf("%s\n", string);
-               break;
-       case REG_MULTI_SZ: {
-               int i, num_values;
-               char **values;
+       const char *sep;
+       ptrdiff_t len;
 
-               d_printf("\n");
+       sep = strchr_m(fullname, '\\');
 
-               if (!NT_STATUS_IS_OK(reg_pull_multi_sz(NULL, buffer->buffer,
-                                                      buffer->buf_len,
-                                                      &num_values,
-                                                      &values))) {
-                       d_printf("reg_pull_multi_sz failed\n");
-                       break;
-               }
+       if (sep != NULL) {
+               len = sep - fullname;
+               *key_name = sep+1;
+       }
+       else {
+               len = strlen(fullname);
+               *key_name = "";
+       }
 
-               for (i=0; i<num_values; i++) {
-                       d_printf("%s\n", values[i]);
-               }
-               TALLOC_FREE(values);
-               break;
-       }
-       case REG_DWORD:
-               value = IVAL( buffer->buffer, 0 );
-               d_printf( "0x%x\n", value );
-               break;
-       case REG_BINARY:
-               d_printf("\n");
-               break;
-       
-       
-       default:
-               d_printf( "\tUnknown type [%d]\n", type );
+       if (strnequal(fullname, "HKLM", len) ||
+           strnequal(fullname, "HKEY_LOCAL_MACHINE", len))
+               (*reg_type) = HKEY_LOCAL_MACHINE;
+       else if (strnequal(fullname, "HKCR", len) ||
+                strnequal(fullname, "HKEY_CLASSES_ROOT", len))
+               (*reg_type) = HKEY_CLASSES_ROOT;
+       else if (strnequal(fullname, "HKU", len) ||
+                strnequal(fullname, "HKEY_USERS", len))
+               (*reg_type) = HKEY_USERS;
+       else if (strnequal(fullname, "HKCU", len) ||
+                strnequal(fullname, "HKEY_CURRENT_USER", len))
+               (*reg_type) = HKEY_CURRENT_USER;
+       else if (strnequal(fullname, "HKPD", len) ||
+                strnequal(fullname, "HKEY_PERFORMANCE_DATA", len))
+               (*reg_type) = HKEY_PERFORMANCE_DATA;
+       else {
+               DEBUG(10,("reg_hive_key: unrecognised hive key %s\n",
+                         fullname));
+               return False;
        }
-}
 
-/********************************************************************
-********************************************************************/
+       return True;
+}
 
-static NTSTATUS rpc_registry_enumerate_internal(const DOM_SID *domain_sid,
-                                               const char *domain_name, 
-                                               struct cli_state *cli,
-                                               struct rpc_pipe_client *pipe_hnd,
-                                               TALLOC_CTX *mem_ctx, 
-                                               int argc,
-                                               const char **argv )
+static NTSTATUS registry_openkey(TALLOC_CTX *mem_ctx,
+                                struct rpc_pipe_client *pipe_hnd,
+                                const char *name, uint32 access_mask,
+                                struct policy_handle *hive_hnd,
+                                struct policy_handle *key_hnd)
 {
-       WERROR result = WERR_GENERAL_FAILURE;
        uint32 hive;
-       pstring subpath;
-       POLICY_HND pol_hive, pol_key; 
-       uint32 idx;
        NTSTATUS status;
-       struct winreg_String subkeyname;
-       struct winreg_String classname;
-       uint32 num_subkeys, max_subkeylen, max_classlen;
-       uint32 num_values, max_valnamelen, max_valbufsize;
-       uint32 secdescsize;
-       NTTIME last_changed_time;
-       struct winreg_StringBuf subkey_namebuf;
-       char *name_buffer; 
-       uint8 *value_buffer;
-       
-       if (argc != 1 ) {
-               d_printf("Usage:    net rpc enumerate <path> [recurse]\n");
-               d_printf("Example:  net rpc enumerate 'HKLM\\Software\\Samba'\n");
-               return NT_STATUS_OK;
-       }
-       
-       if ( !reg_split_hive( argv[0], &hive, subpath ) ) {
-               d_fprintf(stderr, "invalid registry path\n");
-               return NT_STATUS_OK;
+       struct winreg_String key;
+
+       ZERO_STRUCT(key);
+
+       if (!reg_hive_key(name, &hive, &key.name)) {
+               return NT_STATUS_INVALID_PARAMETER;
        }
-       
-       /* open the top level hive and then the registry key */
-       
-       status = rpccli_winreg_Connect(pipe_hnd, mem_ctx, hive, MAXIMUM_ALLOWED_ACCESS, &pol_hive );
-       if ( !NT_STATUS_IS_OK(status) ) {
-               d_fprintf(stderr, "Unable to connect to remote registry: "
-                         "%s\n", nt_errstr(status));
+
+       status = rpccli_winreg_Connect(pipe_hnd, mem_ctx, hive, access_mask,
+                                      hive_hnd);
+       if (!(NT_STATUS_IS_OK(status))) {
                return status;
        }
-       
-       subkeyname.name = subpath;
-       status = rpccli_winreg_OpenKey(pipe_hnd, mem_ctx, &pol_hive, subkeyname,
-                                      0, MAXIMUM_ALLOWED_ACCESS, &pol_key );
-       if ( !NT_STATUS_IS_OK(status) ) {
-               d_fprintf(stderr, "Unable to open [%s]: %s\n", argv[0],
-                         nt_errstr(status));
-               return werror_to_ntstatus(result);
-       }
-
-       classname.name = NULL;
-       status = rpccli_winreg_QueryInfoKey( pipe_hnd, mem_ctx, &pol_key, 
-                       &classname, &num_subkeys, &max_subkeylen,
-                       &max_classlen, &num_values, &max_valnamelen,
-                       &max_valbufsize, &secdescsize, &last_changed_time );
 
-       if ( !NT_STATUS_IS_OK(status) ) {
-               d_fprintf(stderr, "Unable to determine subkeys (%s)\n", 
-                       nt_errstr(status));
+       status = rpccli_winreg_OpenKey(pipe_hnd, mem_ctx, hive_hnd, key, 0,
+                                      access_mask, key_hnd);
+       if (!(NT_STATUS_IS_OK(status))) {
+               rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, hive_hnd);
                return status;
        }
 
-       /* values do not include the terminating NULL */
+       return NT_STATUS_OK;
+}
 
-       max_subkeylen += 2;
-       max_valnamelen += 2;
+static NTSTATUS registry_enumkeys(TALLOC_CTX *ctx,
+                                 struct rpc_pipe_client *pipe_hnd,
+                                 struct policy_handle *key_hnd,
+                                 uint32 *pnum_keys, char ***pnames,
+                                 char ***pclasses, NTTIME ***pmodtimes)
+{
+       TALLOC_CTX *mem_ctx;
+       NTSTATUS status;
+       uint32 num_subkeys, max_subkeylen, max_classlen;
+       uint32 num_values, max_valnamelen, max_valbufsize;
+       uint32 i;
+       NTTIME last_changed_time;
+       uint32 secdescsize;
+       struct winreg_String classname;
+       char **names, **classes;
+       NTTIME **modtimes;
 
-       if ( (name_buffer = TALLOC_ARRAY( mem_ctx, char, max_subkeylen )) == NULL ) {
-               d_fprintf(stderr, "Memory allocation error.\n");
+       if (!(mem_ctx = talloc_new(ctx))) {
                return NT_STATUS_NO_MEMORY;
        }
 
-       /* get the subkeys */
-       
-       status = NT_STATUS_OK;
-       idx = 0;
-       while ( NT_STATUS_IS_OK(status) ) {
-               struct winreg_StringBuf class_namebuf;
-               struct winreg_StringBuf *p_class_namebuf = &class_namebuf;
-               fstring kname;
+       ZERO_STRUCT(classname);
+       status = rpccli_winreg_QueryInfoKey(
+               pipe_hnd, mem_ctx, key_hnd, &classname, &num_subkeys,
+               &max_subkeylen, &max_classlen, &num_values, &max_valnamelen,
+               &max_valbufsize, &secdescsize, &last_changed_time );
+
+       if (!NT_STATUS_IS_OK(status)) {
+               goto error;
+       }
+
+       if (num_subkeys == 0) {
+               *pnum_keys = 0;
+               TALLOC_FREE(mem_ctx);
+               return NT_STATUS_OK;
+       }
+
+       if ((!(names = TALLOC_ZERO_ARRAY(mem_ctx, char *, num_subkeys))) ||
+           (!(classes = TALLOC_ZERO_ARRAY(mem_ctx, char *, num_subkeys))) ||
+           (!(modtimes = TALLOC_ZERO_ARRAY(mem_ctx, NTTIME *,
+                                           num_subkeys)))) {
+               status = NT_STATUS_NO_MEMORY;
+               goto error;
+       }
+
+       for (i=0; i<num_subkeys; i++) {
+               char c, n;
+               struct winreg_StringBuf class_buf;
+               struct winreg_StringBuf name_buf;
                NTTIME modtime;
-               NTTIME *p_modtime = &modtime;
 
-               class_namebuf.name = NULL;
-               class_namebuf.size = 0;
-               class_namebuf.length = 0;
+               c = '\0';
+               class_buf.name = &c;
+               class_buf.size = max_classlen+2;
 
-               /* zero out each time */
+               n = '\0';
+               name_buf.name = &n;
+               name_buf.size = max_subkeylen+2;
 
-               subkey_namebuf.length = 0;
-               subkey_namebuf.size = max_subkeylen;
-               memset( name_buffer, 0x0, max_subkeylen );
-               subkey_namebuf.name = name_buffer;
+               ZERO_STRUCT(modtime);
 
-               status = rpccli_winreg_EnumKey(pipe_hnd, mem_ctx, &pol_key,
-                                              idx, &subkey_namebuf,
-                                              &p_class_namebuf, &p_modtime);
-                       
-               if ( W_ERROR_EQUAL(ntstatus_to_werror(status), WERR_NO_MORE_ITEMS) ) {
+               status = rpccli_winreg_EnumKey(pipe_hnd, mem_ctx, key_hnd,
+                                              i, &name_buf, &class_buf,
+                                              &modtime);
+               
+               if (W_ERROR_EQUAL(ntstatus_to_werror(status),
+                                 WERR_NO_MORE_ITEMS) ) {
                        status = NT_STATUS_OK;
                        break;
                }
+               if (!NT_STATUS_IS_OK(status)) {
+                       goto error;
+               }
 
-               if ( !NT_STATUS_IS_OK(status) )
-                       goto out;
-               
-               StrnCpy( kname, subkey_namebuf.name, MIN(subkey_namebuf.length,sizeof(kname))-1 );
-               kname[MIN(subkey_namebuf.length,sizeof(kname))-1] = '\0';
-               d_printf("Keyname   = %s\n", kname);
-               d_printf("Modtime   = %s\n", 
-                       http_timestring(nt_time_to_unix(modtime)) );
-               d_printf("\n" );
+               classes[i] = NULL;
 
-               idx++;
+               if (class_buf.name &&
+                   (!(classes[i] = talloc_strdup(classes, class_buf.name)))) {
+                       status = NT_STATUS_NO_MEMORY;
+                       goto error;
+               }
+
+               if (!(names[i] = talloc_strdup(names, name_buf.name))) {
+                       status = NT_STATUS_NO_MEMORY;
+                       goto error;
+               }
+
+               if ((!(modtimes[i] = (NTTIME *)talloc_memdup(
+                              modtimes, &modtime, sizeof(modtime))))) {
+                       status = NT_STATUS_NO_MEMORY;
+                       goto error;
+               }
        }
 
-       if ( !NT_STATUS_IS_OK(status) )
-               goto out;
+       *pnum_keys = num_subkeys;
+
+       if (pnames) {
+               *pnames = talloc_move(ctx, &names);
+       }
+       if (pclasses) {
+               *pclasses = talloc_move(ctx, &classes);
+       }
+       if (pmodtimes) {
+               *pmodtimes = talloc_move(ctx, &modtimes);
+       }
 
-       /* TALLOC_FREE( name_buffer ); */
+       status = NT_STATUS_OK;
 
-       if ( (name_buffer = TALLOC_ARRAY( mem_ctx, char, max_valnamelen )) == NULL ) {
-               d_fprintf(stderr, "Memory allocation error.\n");
+ error:
+       TALLOC_FREE(mem_ctx);
+       return status;
+}
+
+static NTSTATUS registry_enumvalues(TALLOC_CTX *ctx,
+                                   struct rpc_pipe_client *pipe_hnd,
+                                   struct policy_handle *key_hnd,
+                                   uint32 *pnum_values, char ***pvalnames,
+                                   struct registry_value ***pvalues)
+{
+       TALLOC_CTX *mem_ctx;
+       NTSTATUS status;
+       uint32 num_subkeys, max_subkeylen, max_classlen;
+       uint32 num_values, max_valnamelen, max_valbufsize;
+       uint32 i;
+       NTTIME last_changed_time;
+       uint32 secdescsize;
+       struct winreg_String classname;
+       struct registry_value **values;
+       char **names;
+
+       if (!(mem_ctx = talloc_new(ctx))) {
                return NT_STATUS_NO_MEMORY;
        }
 
-       if ( (value_buffer = TALLOC_ARRAY( mem_ctx, uint8, max_valbufsize )) == NULL ) {
-               d_fprintf(stderr, "Memory allocation error.\n");
-               return NT_STATUS_NO_MEMORY;
+       ZERO_STRUCT(classname);
+       status = rpccli_winreg_QueryInfoKey(
+               pipe_hnd, mem_ctx, key_hnd, &classname, &num_subkeys,
+               &max_subkeylen, &max_classlen, &num_values, &max_valnamelen,
+               &max_valbufsize, &secdescsize, &last_changed_time );
+
+       if (!NT_STATUS_IS_OK(status)) {
+               goto error;
        }
 
-       /* get the values */
-       
-       status = NT_STATUS_OK;
-       idx = 0;
-       while ( NT_STATUS_IS_OK(status) ) {
+       if (num_values == 0) {
+               *pnum_values = 0;
+               TALLOC_FREE(mem_ctx);
+               return NT_STATUS_OK;
+       }
+
+       if ((!(names = TALLOC_ARRAY(mem_ctx, char *, num_values))) ||
+           (!(values = TALLOC_ARRAY(mem_ctx, struct registry_value *,
+                                    num_values)))) {
+               status = NT_STATUS_NO_MEMORY;
+               goto error;
+       }
+
+       for (i=0; i<num_values; i++) {
                enum winreg_Type type = REG_NONE;
-               enum winreg_Type *ptype = &type;
-               fstring name;
-               uint8 *data;
-               uint32 data_size, value_length;
-               uint32 *pdata_size = &data_size;
-               uint32 *pvalue_length = &value_length;
-               struct winreg_StringBuf value_namebuf;
-               REGVAL_BUFFER value;
-               
-               fstrcpy( name, "" );
-               ZERO_STRUCT( value );
+               uint8 *data = NULL;
+               uint32 data_size;
+               uint32 value_length;
 
-               memset( name_buffer, 0x0, max_valnamelen );
-               value_namebuf.name = name_buffer;
-               value_namebuf.length = 0;
-               value_namebuf.size = max_valnamelen;
+               char n;
+               struct winreg_ValNameBuf name_buf;
+               WERROR err;
+
+               n = '\0';
+               name_buf.name = &n;
+               name_buf.size = max_valnamelen + 2;
 
-               memset( value_buffer, 0x0, max_valbufsize );
-               data = value_buffer;
                data_size = max_valbufsize;
+               data = (uint8 *)TALLOC(mem_ctx, data_size);
                value_length = 0;
 
-               status = rpccli_winreg_EnumValue(pipe_hnd, mem_ctx, &pol_key,
-                                                idx, &value_namebuf, &ptype,
-                                                &data, &pdata_size,
-                                                &pvalue_length );
-                       
-               if ( W_ERROR_EQUAL(ntstatus_to_werror(status), WERR_NO_MORE_ITEMS) ) {
+               status = rpccli_winreg_EnumValue(pipe_hnd, mem_ctx, key_hnd,
+                                                i, &name_buf, &type,
+                                                data, &data_size,
+                                                &value_length );
+
+               if ( W_ERROR_EQUAL(ntstatus_to_werror(status),
+                                  WERR_NO_MORE_ITEMS) ) {
                        status = NT_STATUS_OK;
                        break;
                }
 
-               if ( !NT_STATUS_IS_OK(status) )
-                       goto out;
+               if (!(NT_STATUS_IS_OK(status))) {
+                       goto error;
+               }
 
-               init_regval_buffer( &value, data, value_length );
-                       
-               StrnCpy( name, value_namebuf.name, MIN(max_valnamelen, sizeof(name)-1) );
-               name[MIN(max_valnamelen, sizeof(name)-1)] = '\0';
+               if (name_buf.name == NULL) {
+                       status = NT_STATUS_INVALID_PARAMETER;
+                       goto error;
+               }
 
-               d_printf("Valuename  = %s\n", name );
-               d_printf("Type       = %s\n", reg_type_lookup(type));
-               d_printf("Data       = " );
-               dump_regval_buffer( type, &value );
-               d_printf("\n" );
+               if (!(names[i] = talloc_strdup(names, name_buf.name))) {
+                       status = NT_STATUS_NO_MEMORY;
+                       goto error;
+               }
 
-               idx++;
+               err = registry_pull_value(values, &values[i], type, data,
+                                         data_size, value_length);
+               if (!W_ERROR_IS_OK(err)) {
+                       status = werror_to_ntstatus(err);
+                       goto error;
+               }
        }
+
+       *pnum_values = num_values;
+
+       if (pvalnames) {
+               *pvalnames = talloc_move(ctx, &names);
+       }
+       if (pvalues) {
+               *pvalues = talloc_move(ctx, &values);
+       }
+
+       status = NT_STATUS_OK;
+
+ error:
+       TALLOC_FREE(mem_ctx);
+       return status;
+}
+
+static NTSTATUS registry_getsd(TALLOC_CTX *mem_ctx,
+                              struct rpc_pipe_client *pipe_hnd,
+                              struct policy_handle *key_hnd,
+                              uint32_t sec_info,
+                              struct KeySecurityData *sd)
+{
+       return rpccli_winreg_GetKeySecurity(pipe_hnd, mem_ctx, key_hnd,
+                                           sec_info, sd);
+}
+
+
+static NTSTATUS registry_setvalue(TALLOC_CTX *mem_ctx,
+                                 struct rpc_pipe_client *pipe_hnd,
+                                 struct policy_handle *key_hnd,
+                                 const char *name,
+                                 const struct registry_value *value)
+{
+       struct winreg_String name_string;
+       DATA_BLOB blob;
+       NTSTATUS result;
+       WERROR err;
+
+       err = registry_push_value(mem_ctx, value, &blob);
+       if (!W_ERROR_IS_OK(err)) {
+               return werror_to_ntstatus(err);
+       }
+
+       ZERO_STRUCT(name_string);
+
+       name_string.name = name;
+       result = rpccli_winreg_SetValue(pipe_hnd, blob.data, key_hnd,
+                                       name_string, value->type,
+                                       blob.data, blob.length);
+       TALLOC_FREE(blob.data);
+       return result;
+}
+
+static NTSTATUS rpc_registry_setvalue_internal(const DOM_SID *domain_sid,
+                                              const char *domain_name, 
+                                              struct cli_state *cli,
+                                              struct rpc_pipe_client *pipe_hnd,
+                                              TALLOC_CTX *mem_ctx, 
+                                              int argc,
+                                              const char **argv )
+{
+       struct policy_handle hive_hnd, key_hnd;
+       NTSTATUS status;
+       struct registry_value value;
+
+       status = registry_openkey(mem_ctx, pipe_hnd, argv[0], 
+                                 SEC_RIGHTS_MAXIMUM_ALLOWED,
+                                 &hive_hnd, &key_hnd);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_openkey failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       if (!strequal(argv[2], "multi_sz") && (argc != 4)) {
+               d_fprintf(stderr, "Too many args for type %s\n", argv[2]);
+               return NT_STATUS_NOT_IMPLEMENTED;
+       }
+
+       if (strequal(argv[2], "dword")) {
+               value.type = REG_DWORD;
+               value.v.dword = strtoul(argv[3], NULL, 10);
+       }
+       else if (strequal(argv[2], "sz")) {
+               value.type = REG_SZ;
+               value.v.sz.len = strlen(argv[3])+1;
+               value.v.sz.str = CONST_DISCARD(char *, argv[3]);
+       }
+       else {
+               d_fprintf(stderr, "type \"%s\" not implemented\n", argv[2]);
+               status = NT_STATUS_NOT_IMPLEMENTED;
+               goto error;
+       }
+
+       status = registry_setvalue(mem_ctx, pipe_hnd, &key_hnd,
+                                  argv[1], &value);
+
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_setvalue failed: %s\n",
+                         nt_errstr(status));
+       }
+
+ error:
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &key_hnd);
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &hive_hnd);
+
+       return NT_STATUS_OK;
+}
+
+static int rpc_registry_setvalue( int argc, const char **argv )
+{
+       if (argc < 4) {
+               d_fprintf(stderr, "usage: net rpc registry setvalue <key> "
+                         "<valuename> <type> [<val>]+\n");
+               return -1;
+       }
+
+       return run_rpc_command( NULL, PI_WINREG, 0, 
+               rpc_registry_setvalue_internal, argc, argv );
+}
+
+static NTSTATUS rpc_registry_deletevalue_internal(const DOM_SID *domain_sid,
+                                                 const char *domain_name, 
+                                                 struct cli_state *cli,
+                                                 struct rpc_pipe_client *pipe_hnd,
+                                                 TALLOC_CTX *mem_ctx, 
+                                                 int argc,
+                                                 const char **argv )
+{
+       struct policy_handle hive_hnd, key_hnd;
+       NTSTATUS status;
+       struct winreg_String valuename;
+
+       ZERO_STRUCT(valuename);
+
+       status = registry_openkey(mem_ctx, pipe_hnd, argv[0],
+                                 SEC_RIGHTS_MAXIMUM_ALLOWED,
+                                 &hive_hnd, &key_hnd);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_openkey failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       valuename.name = argv[1];
+
+       status = rpccli_winreg_DeleteValue(pipe_hnd, mem_ctx, &key_hnd,
+                                          valuename);
+
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_deletevalue failed: %s\n",
+                         nt_errstr(status));
+       }
+
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &key_hnd);
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &hive_hnd);
+
+       return NT_STATUS_OK;
+}
+
+static int rpc_registry_deletevalue( int argc, const char **argv )
+{
+       if (argc != 2) {
+               d_fprintf(stderr, "usage: net rpc registry deletevalue <key> "
+                         "<valuename>\n");
+               return -1;
+       }
+
+       return run_rpc_command( NULL, PI_WINREG, 0, 
+               rpc_registry_deletevalue_internal, argc, argv );
+}
+
+static NTSTATUS rpc_registry_createkey_internal(const DOM_SID *domain_sid,
+                                               const char *domain_name, 
+                                               struct cli_state *cli,
+                                               struct rpc_pipe_client *pipe_hnd,
+                                               TALLOC_CTX *mem_ctx, 
+                                               int argc,
+                                               const char **argv )
+{
+       uint32 hive;
+       struct policy_handle hive_hnd, key_hnd;
+       struct winreg_String key, keyclass;
+       enum winreg_CreateAction action;
+       NTSTATUS status;
+
+       ZERO_STRUCT(key);
+       ZERO_STRUCT(keyclass);
+
+       if (!reg_hive_key(argv[0], &hive, &key.name)) {
+               return NT_STATUS_INVALID_PARAMETER;
+       }
+
+       status = rpccli_winreg_Connect(pipe_hnd, mem_ctx, hive,
+                                      SEC_RIGHTS_MAXIMUM_ALLOWED,
+                                      &hive_hnd);
+       if (!(NT_STATUS_IS_OK(status))) {
+               return status;
+       }
+
+       action = REG_ACTION_NONE;
+       keyclass.name = "";
+
+       status = rpccli_winreg_CreateKey(pipe_hnd, mem_ctx, &hive_hnd, key,
+                                        keyclass, 0, REG_KEY_READ, NULL,
+                                        &key_hnd, &action);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "createkey returned %s\n",
+                         nt_errstr(status));
+               rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &hive_hnd);
+               return status;
+       }
+
+       switch (action) {
+               case REG_ACTION_NONE:
+                       d_printf("createkey did nothing -- huh?\n");
+                       break;
+               case REG_CREATED_NEW_KEY:
+                       d_printf("createkey created %s\n", argv[0]);
+                       break;
+               case REG_OPENED_EXISTING_KEY:
+                       d_printf("createkey opened existing %s\n", argv[0]);
+                       break;
+       }
+
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &key_hnd);
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &hive_hnd);
+
+       return status;
+}
+
+static int rpc_registry_createkey( int argc, const char **argv )
+{
+       if (argc != 1) {
+               d_fprintf(stderr, "usage: net rpc registry createkey <key>\n");
+               return -1;
+       }
+
+       return run_rpc_command( NULL, PI_WINREG, 0, 
+               rpc_registry_createkey_internal, argc, argv );
+}
+
+static NTSTATUS rpc_registry_deletekey_internal(const DOM_SID *domain_sid,
+                                               const char *domain_name, 
+                                               struct cli_state *cli,
+                                               struct rpc_pipe_client *pipe_hnd,
+                                               TALLOC_CTX *mem_ctx, 
+                                               int argc,
+                                               const char **argv )
+{
+       uint32 hive;
+       struct policy_handle hive_hnd;
+       struct winreg_String key;
+       NTSTATUS status;
+
+       ZERO_STRUCT(key);
+
+       if (!reg_hive_key(argv[0], &hive, &key.name)) {
+               return NT_STATUS_INVALID_PARAMETER;
+       }
+
+       status = rpccli_winreg_Connect(pipe_hnd, mem_ctx, hive,
+                                      SEC_RIGHTS_MAXIMUM_ALLOWED,
+                                      &hive_hnd);
+       if (!(NT_STATUS_IS_OK(status))) {
+               return status;
+       }
+
+       status = rpccli_winreg_DeleteKey(pipe_hnd, mem_ctx, &hive_hnd, key);
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &hive_hnd);
+
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "deletekey returned %s\n",
+                         nt_errstr(status));
+       }
+
+       return status;
+}
+
+static int rpc_registry_deletekey( int argc, const char **argv )
+{
+       if (argc != 1) {
+               d_fprintf(stderr, "usage: net rpc registry deletekey <key>\n");
+               return -1;
+       }
+
+       return run_rpc_command( NULL, PI_WINREG, 0, 
+               rpc_registry_deletekey_internal, argc, argv );
+}
+
+/********************************************************************
+********************************************************************/
+
+static NTSTATUS rpc_registry_enumerate_internal(const DOM_SID *domain_sid,
+                                               const char *domain_name, 
+                                               struct cli_state *cli,
+                                               struct rpc_pipe_client *pipe_hnd,
+                                               TALLOC_CTX *mem_ctx, 
+                                               int argc,
+                                               const char **argv )
+{
+       POLICY_HND pol_hive, pol_key; 
+       NTSTATUS status;
+       uint32 num_subkeys = 0;
+       uint32 num_values = 0;
+       char **names = NULL, **classes = NULL;
+       NTTIME **modtimes = NULL;
+       uint32 i;
+       struct registry_value **values = NULL;
        
-out:
-       /* cleanup */
-       
-       if ( strlen( subpath ) != 0 )
-               rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &pol_key );
+       if (argc != 1 ) {
+               d_printf("Usage:    net rpc registry enumerate <path> [recurse]\n");
+               d_printf("Example:  net rpc registry enumerate 'HKLM\\Software\\Samba'\n");
+               return NT_STATUS_OK;
+       }
+
+       status = registry_openkey(mem_ctx, pipe_hnd, argv[0], REG_KEY_READ,
+                                 &pol_hive, &pol_key);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_openkey failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       status = registry_enumkeys(mem_ctx, pipe_hnd, &pol_key, &num_subkeys,
+                                  &names, &classes, &modtimes);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "enumerating keys failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       for (i=0; i<num_subkeys; i++) {
+               d_printf("Keyname   = %s\n", names[i]);
+               d_printf("Modtime   = %s\n", modtimes[i]
+                        ? http_timestring(nt_time_to_unix(*modtimes[i]))
+                        : "None");
+               d_printf("\n" );
+       }
+
+       status = registry_enumvalues(mem_ctx, pipe_hnd, &pol_key, &num_values,
+                                    &names, &values);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "enumerating values failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       for (i=0; i<num_values; i++) {
+               struct registry_value *v = values[i];
+               d_printf("Valuename  = %s\n", names[i]);
+               d_printf("Type       = %s\n",
+                        reg_type_lookup(v->type));
+               switch(v->type) {
+               case REG_DWORD:
+                       d_printf("Value      = %d\n", v->v.dword);
+                       break;
+               case REG_SZ:
+               case REG_EXPAND_SZ:
+                       d_printf("Value      = \"%s\"\n", v->v.sz.str);
+                       break;
+               case REG_MULTI_SZ: {
+                       uint32 j;
+                       for (j = 0; j < v->v.multi_sz.num_strings; j++) {
+                               d_printf("Value[%3.3d] = \"%s\"\n", j,
+                                        v->v.multi_sz.strings[j]);
+                       }
+                       break;
+               }
+               case REG_BINARY:
+                       d_printf("Value      = %d bytes\n",
+                                (int)v->v.binary.length);
+                       break;
+               default:
+                       d_printf("Value      = <unprintable>\n");
+                       break;
+               }
+                       
+               d_printf("\n");
+       }
+
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &pol_key );
        rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &pol_hive );
 
        return status;
@@ -293,39 +711,23 @@ static NTSTATUS rpc_registry_save_internal(const DOM_SID *domain_sid,
                                        const char **argv )
 {
        WERROR result = WERR_GENERAL_FAILURE;
-       uint32 hive;
-       pstring subpath;
        POLICY_HND pol_hive, pol_key; 
        NTSTATUS status = NT_STATUS_UNSUCCESSFUL;
-       struct winreg_String subkeyname;
        struct winreg_String filename;
        
        if (argc != 2 ) {
-               d_printf("Usage:    net rpc backup <path> <file> \n");
-               return NT_STATUS_OK;
-       }
-       
-       if ( !reg_split_hive( argv[0], &hive, subpath ) ) {
-               d_fprintf(stderr, "invalid registry path\n");
+               d_printf("Usage:    net rpc registry backup <path> <file> \n");
                return NT_STATUS_OK;
        }
        
-       /* open the top level hive and then the registry key */
-       
-       status = rpccli_winreg_Connect(pipe_hnd, mem_ctx, hive, MAXIMUM_ALLOWED_ACCESS, &pol_hive );
-       if ( !NT_STATUS_IS_OK(status) ) {
-               d_fprintf(stderr, "Unable to connect to remote registry\n");
+       status = registry_openkey(mem_ctx, pipe_hnd, argv[0], REG_KEY_ALL,
+                                 &pol_hive, &pol_key);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_openkey failed: %s\n",
+                         nt_errstr(status));
                return status;
        }
-       
-       subkeyname.name = subpath;
-       status = rpccli_winreg_OpenKey(pipe_hnd, mem_ctx, &pol_hive, subkeyname,
-                       0, MAXIMUM_ALLOWED_ACCESS, &pol_key );
-       if ( !NT_STATUS_IS_OK(status) ) {
-               d_fprintf(stderr, "Unable to open [%s]\n", argv[0]);
-               return werror_to_ntstatus(result);
-       }
-       
+
        filename.name = argv[1];
        status = rpccli_winreg_SaveKey( pipe_hnd, mem_ctx, &pol_key, &filename, NULL  );
        if ( !W_ERROR_IS_OK(result) ) {
@@ -400,7 +802,7 @@ static void dump_values( REGF_NK_REC *nk )
 /********************************************************************
 ********************************************************************/
 
-static BOOL dump_registry_tree( REGF_FILE *file, REGF_NK_REC *nk, const char *parent )
+static bool dump_registry_tree( REGF_FILE *file, REGF_NK_REC *nk, const char *parent )
 {
        REGF_NK_REC *key;
        pstring regpath;
@@ -421,7 +823,7 @@ static BOOL dump_registry_tree( REGF_FILE *file, REGF_NK_REC *nk, const char *pa
 /********************************************************************
 ********************************************************************/
 
-static BOOL write_registry_tree( REGF_FILE *infile, REGF_NK_REC *nk, 
+static bool write_registry_tree( REGF_FILE *infile, REGF_NK_REC *nk, 
                                  REGF_NK_REC *parent, REGF_FILE *outfile,
                                 const char *parentpath )
 {
@@ -480,7 +882,7 @@ static int rpc_registry_dump( int argc, const char **argv )
        REGF_NK_REC *nk;
        
        if (argc != 1 ) {
-               d_printf("Usage:    net rpc dump <file> \n");
+               d_printf("Usage:    net rpc registry dump <file> \n");
                return 0;
        }
        
@@ -524,7 +926,7 @@ static int rpc_registry_copy( int argc, const char **argv )
        int result = 1;
        
        if (argc != 2 ) {
-               d_printf("Usage:    net rpc copy <srcfile> <newfile>\n");
+               d_printf("Usage:    net rpc registry copy <srcfile> <newfile>\n");
                return 0;
        }
        
@@ -574,13 +976,83 @@ out:
 /********************************************************************
 ********************************************************************/
 
-static int net_help_registry( int argc, const char **argv )
+static NTSTATUS rpc_registry_getsd_internal(const DOM_SID *domain_sid,
+                                           const char *domain_name,
+                                           struct cli_state *cli,
+                                           struct rpc_pipe_client *pipe_hnd,
+                                           TALLOC_CTX *mem_ctx,
+                                           int argc,
+                                           const char **argv)
 {
-       d_printf("net rpc registry enumerate <path> [recurse]  Enumerate the subkeya and values for a given registry path\n");
-       d_printf("net rpc registry save <path> <file>          Backup a registry tree to a file on the server\n");
-       d_printf("net rpc registry dump <file>                 Dump the contents of a registry file to stdout\n");
-       
-       return -1;
+       POLICY_HND pol_hive, pol_key;
+       NTSTATUS status;
+       struct KeySecurityData *sd = NULL;
+       uint32_t sec_info;
+       DATA_BLOB blob;
+       struct security_descriptor sec_desc;
+       uint32_t access_mask = REG_KEY_READ |
+                              SEC_RIGHT_MAXIMUM_ALLOWED |
+                              SEC_RIGHT_SYSTEM_SECURITY;
+
+       if (argc <1 || argc > 2) {
+               d_printf("Usage:    net rpc registry getsd <path> <secinfo>\n");
+               d_printf("Example:  net rpc registry getsd 'HKLM\\Software\\Samba'\n");
+               return NT_STATUS_OK;
+       }
+
+       status = registry_openkey(mem_ctx, pipe_hnd, argv[0],
+                                 access_mask,
+                                 &pol_hive, &pol_key);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "registry_openkey failed: %s\n",
+                         nt_errstr(status));
+               return status;
+       }
+
+       sd = TALLOC_ZERO_P(mem_ctx, struct KeySecurityData);
+       if (!sd) {
+               status = NT_STATUS_NO_MEMORY;
+               goto out;
+       }
+
+       sd->size = 0x1000;
+
+       if (argc >= 2) {
+               sscanf(argv[1], "%x", &sec_info);
+       } else {
+               sec_info = SECINFO_OWNER | SECINFO_GROUP | SECINFO_DACL;
+       }
+
+       status = registry_getsd(mem_ctx, pipe_hnd, &pol_key, sec_info, sd);
+       if (!NT_STATUS_IS_OK(status)) {
+               d_fprintf(stderr, "getting sd failed: %s\n",
+                         nt_errstr(status));
+               goto out;
+       }
+
+       blob.data = sd->data;
+       blob.length = sd->size;
+
+       status = ndr_pull_struct_blob(&blob, mem_ctx, &sec_desc,
+                                     (ndr_pull_flags_fn_t)ndr_pull_security_descriptor);
+       if (!NT_STATUS_IS_OK(status)) {
+               goto out;
+       }
+
+       display_sec_desc(&sec_desc);
+
+ out:
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &pol_key);
+       rpccli_winreg_CloseKey(pipe_hnd, mem_ctx, &pol_hive);
+
+       return status;
+}
+
+
+static int rpc_registry_getsd(int argc, const char **argv)
+{
+       return run_rpc_command(NULL, PI_WINREG, 0,
+               rpc_registry_getsd_internal, argc, argv);
 }
 
 /********************************************************************
@@ -588,16 +1060,27 @@ static int net_help_registry( int argc, const char **argv )
 
 int net_rpc_registry(int argc, const char **argv) 
 {
-       struct functable func[] = {
-               {"enumerate", rpc_registry_enumerate},
-               {"save",      rpc_registry_save},
-               {"dump",      rpc_registry_dump},
-               {"copy",      rpc_registry_copy},
-               {NULL, NULL}
+       struct functable2 func[] = {
+               { "enumerate", rpc_registry_enumerate,
+                 "Enumerate registry keys and values" },
+               { "createkey",  rpc_registry_createkey,
+                 "Create a new registry key" },
+               { "deletekey",  rpc_registry_deletekey,
+                 "Delete a registry key" },
+               { "setvalue",  rpc_registry_setvalue,
+                 "Set a new registry value" },
+               { "deletevalue",  rpc_registry_deletevalue,
+                 "Delete a registry value" },
+               { "save", rpc_registry_save,
+                 "Save a registry file" },
+               { "dump", rpc_registry_dump,
+                 "Dump a registry file" },
+               { "copy", rpc_registry_copy,
+                 "Copy a registry file" },
+               { "getsd", rpc_registry_getsd,
+                 "Get security descriptor" },
+               {NULL, NULL, NULL}
        };
        
-       if ( argc )
-               return net_run_function( argc, argv, func, net_help_registry );
-               
-       return net_help_registry( argc, argv );
+       return net_run_function2(argc, argv, "net rpc registry", func);
 }