s4/libnet: Add "dNSHostName" attribute when joining the Site
[kamenim/samba.git] / source4 / libnet / libnet_site.c
1 /*
2    Unix SMB/CIFS implementation.
3
4    Copyright (C) Brad Henry     2005
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include "includes.h"
21 #include "libnet/libnet.h"
22 #include "libcli/cldap/cldap.h"
23 #include "lib/ldb/include/ldb.h"
24 #include "lib/ldb/include/ldb_errors.h"
25 #include "libcli/resolve/resolve.h"
26 #include "param/param.h"
27 #include "lib/tsocket/tsocket.h"
28
29 /**
30  * 1. Setup a CLDAP socket.
31  * 2. Lookup the default Site-Name.
32  */
33 NTSTATUS libnet_FindSite(TALLOC_CTX *ctx, struct libnet_context *lctx, struct libnet_JoinSite *r)
34 {
35         NTSTATUS status;
36         TALLOC_CTX *tmp_ctx;
37
38         char *site_name_str;
39         char *config_dn_str;
40         char *server_dn_str;
41
42         struct cldap_socket *cldap = NULL;
43         struct cldap_netlogon search;
44         int ret;
45         struct tsocket_address *dest_address;
46
47         tmp_ctx = talloc_named(ctx, 0, "libnet_FindSite temp context");
48         if (!tmp_ctx) {
49                 r->out.error_string = NULL;
50                 return NT_STATUS_NO_MEMORY;
51         }
52
53         /* Resolve the site name. */
54         ZERO_STRUCT(search);
55         search.in.dest_address = NULL;
56         search.in.dest_port = 0;
57         search.in.acct_control = -1;
58         search.in.version = NETLOGON_NT_VERSION_5 | NETLOGON_NT_VERSION_5EX;
59         search.in.map_response = true;
60
61         ret = tsocket_address_inet_from_strings(tmp_ctx, "ip",
62                                                 r->in.dest_address,
63                                                 r->in.cldap_port,
64                                                 &dest_address);
65         if (ret != 0) {
66                 r->out.error_string = NULL;
67                 status = map_nt_error_from_unix(errno);
68                 return status;
69         }
70
71         /* we want to use non async calls, so we're not passing an event context */
72         status = cldap_socket_init(tmp_ctx, NULL, NULL, dest_address, &cldap);
73         if (!NT_STATUS_IS_OK(status)) {
74                 talloc_free(tmp_ctx);
75                 r->out.error_string = NULL;
76                 return status;
77         }
78         status = cldap_netlogon(cldap, lp_iconv_convenience(lctx->lp_ctx), tmp_ctx, &search);
79         if (!NT_STATUS_IS_OK(status)
80             || !search.out.netlogon.data.nt5_ex.client_site) {
81                 /*
82                   If cldap_netlogon() returns in error,
83                   default to using Default-First-Site-Name.
84                 */
85                 site_name_str = talloc_asprintf(tmp_ctx, "%s",
86                                                 "Default-First-Site-Name");
87                 if (!site_name_str) {
88                         r->out.error_string = NULL;
89                         talloc_free(tmp_ctx);
90                         return NT_STATUS_NO_MEMORY;
91                 }
92         } else {
93                 site_name_str = talloc_asprintf(tmp_ctx, "%s",
94                                         search.out.netlogon.data.nt5_ex.client_site);
95                 if (!site_name_str) {
96                         r->out.error_string = NULL;
97                         talloc_free(tmp_ctx);
98                         return NT_STATUS_NO_MEMORY;
99                 }
100         }
101
102         /* Generate the CN=Configuration,... DN. */
103 /* TODO: look it up! */
104         config_dn_str = talloc_asprintf(tmp_ctx, "CN=Configuration,%s", r->in.domain_dn_str);
105         if (!config_dn_str) {
106                 r->out.error_string = NULL;
107                 talloc_free(tmp_ctx);
108                 return NT_STATUS_NO_MEMORY;
109         }
110
111         /* Generate the CN=Servers,... DN. */
112         server_dn_str = talloc_asprintf(tmp_ctx, "CN=%s,CN=Servers,CN=%s,CN=Sites,%s",
113                                                  r->in.netbios_name, site_name_str, config_dn_str);
114         if (!server_dn_str) {
115                 r->out.error_string = NULL;
116                 talloc_free(tmp_ctx);
117                 return NT_STATUS_NO_MEMORY;
118         }
119
120         r->out.site_name_str = site_name_str;
121         talloc_steal(r, site_name_str);
122
123         r->out.config_dn_str = config_dn_str;
124         talloc_steal(r, config_dn_str);
125
126         r->out.server_dn_str = server_dn_str;
127         talloc_steal(r, server_dn_str);
128
129         talloc_free(tmp_ctx);
130         return NT_STATUS_OK;
131 }
132
133 /*
134  * find out Site specific stuff:
135  * 1. Lookup the Site name.
136  * 2. Add entry CN=<netbios name>,CN=Servers,CN=<site name>,CN=Sites,CN=Configuration,<domain dn>.
137  * TODO: 3.) use DsAddEntry() to create CN=NTDS Settings,CN=<netbios name>,CN=Servers,CN=<site name>,...
138  */
139 NTSTATUS libnet_JoinSite(struct libnet_context *ctx, 
140                          struct ldb_context *remote_ldb,
141                          struct libnet_JoinDomain *libnet_r)
142 {
143         NTSTATUS status;
144         TALLOC_CTX *tmp_ctx;
145
146         struct libnet_JoinSite *r;
147
148         struct ldb_dn *server_dn;
149         struct ldb_message *msg;
150         int rtn;
151
152         const char *server_dn_str;
153         const char *config_dn_str;
154         struct nbt_name name;
155         const char *dest_addr = NULL;
156         char *dns_host_name;
157
158         tmp_ctx = talloc_named(libnet_r, 0, "libnet_JoinSite temp context");
159         if (!tmp_ctx) {
160                 libnet_r->out.error_string = NULL;
161                 return NT_STATUS_NO_MEMORY;
162         }
163
164         r = talloc(tmp_ctx, struct libnet_JoinSite);
165         if (!r) {
166                 libnet_r->out.error_string = NULL;
167                 talloc_free(tmp_ctx);
168                 return NT_STATUS_NO_MEMORY;
169         }
170
171         make_nbt_name_client(&name, libnet_r->out.samr_binding->host);
172         status = resolve_name(lp_resolve_context(ctx->lp_ctx), &name, r, &dest_addr, ctx->event_ctx);
173         if (!NT_STATUS_IS_OK(status)) {
174                 libnet_r->out.error_string = NULL;
175                 talloc_free(tmp_ctx);
176                 return status;
177         }
178
179         /* Resolve the site name and AD DN's. */
180         r->in.dest_address = dest_addr;
181         r->in.netbios_name = libnet_r->in.netbios_name;
182         r->in.domain_dn_str = libnet_r->out.domain_dn_str;
183         r->in.cldap_port = lp_cldap_port(ctx->lp_ctx);
184
185         status = libnet_FindSite(tmp_ctx, ctx, r);
186         if (!NT_STATUS_IS_OK(status)) {
187                 libnet_r->out.error_string =
188                         talloc_steal(libnet_r, r->out.error_string);
189                 talloc_free(tmp_ctx);
190                 return status;
191         }
192
193         config_dn_str = r->out.config_dn_str;
194         server_dn_str = r->out.server_dn_str;
195
196         /*
197          Add entry CN=<netbios name>,CN=Servers,CN=<site name>,CN=Sites,CN=Configuration,<domain dn>.
198         */
199         msg = ldb_msg_new(tmp_ctx);
200         if (!msg) {
201                 libnet_r->out.error_string = NULL;
202                 talloc_free(tmp_ctx);
203                 return NT_STATUS_NO_MEMORY;
204         }
205
206         rtn = ldb_msg_add_string(msg, "objectClass", "server");
207         if (rtn != 0) {
208                 libnet_r->out.error_string = NULL;
209                 talloc_free(tmp_ctx);
210                 return NT_STATUS_NO_MEMORY;
211         }
212         rtn = ldb_msg_add_string(msg, "systemFlags", "50000000");
213         if (rtn != 0) {
214                 libnet_r->out.error_string = NULL;
215                 talloc_free(tmp_ctx);
216                 return NT_STATUS_NO_MEMORY;
217         }
218         rtn = ldb_msg_add_string(msg, "serverReference", libnet_r->out.account_dn_str);
219         if (rtn != 0) {
220                 libnet_r->out.error_string = NULL;
221                 talloc_free(tmp_ctx);
222                 return NT_STATUS_NO_MEMORY;
223         }
224         dns_host_name = talloc_asprintf(tmp_ctx, "%s.%s",
225                                         libnet_r->in.netbios_name, libnet_r->out.realm);
226         if (!dns_host_name) {
227                 r->out.error_string = NULL;
228                 talloc_free(tmp_ctx);
229                 return NT_STATUS_NO_MEMORY;
230         }
231         strlower_m(dns_host_name);
232         rtn = ldb_msg_add_string(msg, "dNSHostName", dns_host_name);
233
234         server_dn = ldb_dn_new(tmp_ctx, remote_ldb, server_dn_str);
235         if ( ! ldb_dn_validate(server_dn)) {
236                 libnet_r->out.error_string = talloc_asprintf(libnet_r,
237                                         "Invalid server dn: %s",
238                                         server_dn_str);
239                 talloc_free(tmp_ctx);
240                 return NT_STATUS_UNSUCCESSFUL;
241         }
242
243         msg->dn = server_dn;
244
245         rtn = ldb_add(remote_ldb, msg);
246         if (rtn == LDB_ERR_ENTRY_ALREADY_EXISTS) {
247                 unsigned int i;
248
249                 /* make a 'modify' msg, and only for serverReference */
250                 msg = ldb_msg_new(tmp_ctx);
251                 if (!msg) {
252                         libnet_r->out.error_string = NULL;
253                         talloc_free(tmp_ctx);
254                         return NT_STATUS_NO_MEMORY;
255                 }
256                 msg->dn = server_dn;
257
258                 rtn = ldb_msg_add_string(msg, "serverReference",libnet_r->out.account_dn_str);
259                 if (rtn != 0) {
260                         libnet_r->out.error_string = NULL;
261                         talloc_free(tmp_ctx);
262                         return NT_STATUS_NO_MEMORY;
263                 }
264
265                 /* mark all the message elements (should be just one)
266                    as LDB_FLAG_MOD_REPLACE */
267                 for (i=0;i<msg->num_elements;i++) {
268                         msg->elements[i].flags = LDB_FLAG_MOD_REPLACE;
269                 }
270
271                 rtn = ldb_modify(remote_ldb, msg);
272                 if (rtn != 0) {
273                         libnet_r->out.error_string
274                                 = talloc_asprintf(libnet_r,
275                                                   "Failed to modify server entry %s: %s: %d",
276                                                   server_dn_str,
277                                                   ldb_errstring(remote_ldb), rtn);
278                         talloc_free(tmp_ctx);
279                         return NT_STATUS_INTERNAL_DB_CORRUPTION;
280                 }
281         } else if (rtn != 0) {
282                 libnet_r->out.error_string
283                         = talloc_asprintf(libnet_r,
284                                 "Failed to add server entry %s: %s: %d",
285                                 server_dn_str, ldb_errstring(remote_ldb),
286                                 rtn);
287                 talloc_free(tmp_ctx);
288                 return NT_STATUS_INTERNAL_DB_CORRUPTION;
289         }
290         DEBUG(0, ("We still need to perform a DsAddEntry() so that we can create the CN=NTDS Settings container.\n"));
291
292         /* Store the server DN in libnet_r */
293         libnet_r->out.server_dn_str = server_dn_str;
294         talloc_steal(libnet_r, server_dn_str);
295
296         talloc_free(tmp_ctx);
297         return NT_STATUS_OK;
298 }