2 * idmap_adex: Support for AD Forests
4 * Copyright (C) Gerald (Jerry) Carter 2006-2008
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
23 #include "idmap_adex.h"
27 #define DBGC_CLASS DBGC_IDMAP
29 static struct likewise_cell *_lw_cell_list = NULL;
31 /**********************************************************************
32 Return the current HEAD of the list
33 *********************************************************************/
35 struct likewise_cell *cell_list_head(void)
41 /**********************************************************************
42 *********************************************************************/
44 void cell_destroy(struct likewise_cell *c)
50 ads_destroy(&c->conn);
55 /**********************************************************************
56 Free all cell entries and reset the list head to NULL
57 *********************************************************************/
59 void cell_list_destroy(void)
61 struct likewise_cell *p = _lw_cell_list;
64 struct likewise_cell *q = p->next;
76 /**********************************************************************
77 Add a new cell structure to the list
78 *********************************************************************/
80 struct likewise_cell* cell_new(void)
82 struct likewise_cell *c;
84 /* Each cell struct is a TALLOC_CTX* */
86 c = TALLOC_ZERO_P(NULL, struct likewise_cell);
88 DEBUG(0,("cell_new: memory allocation failure!\n"));
95 /**********************************************************************
96 Add a new cell structure to the list
97 *********************************************************************/
99 bool cell_list_add(struct likewise_cell * cell)
105 /* Always add to the end */
107 DLIST_ADD_END(_lw_cell_list, cell, struct likewise_cell *);
112 /**********************************************************************
113 Add a new cell structure to the list
114 *********************************************************************/
116 bool cell_list_remove(struct likewise_cell * cell)
122 /* Remove and drop the cell structure */
124 DLIST_REMOVE(_lw_cell_list, cell);
125 talloc_destroy(cell);
130 /**********************************************************************
131 Set the containing DNS domain for a cell
132 *********************************************************************/
134 void cell_set_dns_domain(struct likewise_cell *c, const char *dns_domain)
136 c->dns_domain = talloc_strdup(c, dns_domain);
139 /**********************************************************************
140 Set ADS connection for a cell
141 *********************************************************************/
143 void cell_set_connection(struct likewise_cell *c, ADS_STRUCT *ads)
148 /**********************************************************************
149 *********************************************************************/
151 void cell_set_flags(struct likewise_cell *c, uint32_t flags)
156 /**********************************************************************
157 *********************************************************************/
159 void cell_clear_flags(struct likewise_cell *c, uint32_t flags)
164 /**********************************************************************
166 *********************************************************************/
168 void cell_set_dn(struct likewise_cell *c, const char *dn)
175 c->dn = talloc_strdup(c, dn);
178 /**********************************************************************
179 *********************************************************************/
181 void cell_set_domain_sid(struct likewise_cell *c, struct dom_sid *sid)
183 sid_copy(&c->domain_sid, sid);
190 /**********************************************************************
191 *********************************************************************/
193 const char* cell_search_base(struct likewise_cell *c)
198 return talloc_asprintf(c, "cn=%s,%s", ADEX_CELL_RDN, c->dn);
201 /**********************************************************************
202 *********************************************************************/
204 bool cell_search_forest(struct likewise_cell *c)
206 uint32_t test_flags = LWCELL_FLAG_SEARCH_FOREST;
208 return ((c->flags & test_flags) == test_flags);
211 /**********************************************************************
212 *********************************************************************/
214 uint32_t cell_flags(struct likewise_cell *c)
222 /**********************************************************************
223 *********************************************************************/
225 const char *cell_dns_domain(struct likewise_cell *c)
230 return c->dns_domain;
233 /**********************************************************************
234 *********************************************************************/
236 ADS_STRUCT *cell_connection(struct likewise_cell *c)
245 * Connection functions
248 /********************************************************************
249 *******************************************************************/
251 NTSTATUS cell_connect(struct likewise_cell *c)
253 ADS_STRUCT *ads = NULL;
254 ADS_STATUS ads_status;
256 struct sockaddr_storage dcip;
257 NTSTATUS nt_status = NT_STATUS_UNSUCCESSFUL;
259 /* have to at least have the AD domain name */
261 if (!c->dns_domain) {
262 nt_status = NT_STATUS_CANT_ACCESS_DOMAIN_INFO;
263 BAIL_ON_NTSTATUS_ERROR(nt_status);
266 /* clear out any old information */
269 ads_destroy(&c->conn);
273 /* now setup the new connection */
275 ads = ads_init(c->dns_domain, NULL, NULL);
276 BAIL_ON_PTR_ERROR(ads, nt_status);
279 secrets_fetch_machine_password(lp_workgroup(), NULL, NULL);
280 ads->auth.realm = SMB_STRDUP(lp_realm());
282 /* Make the connection. We should already have an initial
283 TGT using the machine creds */
285 if (cell_flags(c) & LWCELL_FLAG_GC_CELL) {
286 ads_status = ads_connect_gc(ads);
288 /* Set up server affinity for normal cells and the client
291 if (!get_dc_name("", c->dns_domain, dc_name, &dcip)) {
292 nt_status = NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
293 BAIL_ON_NTSTATUS_ERROR(nt_status);
296 ads_status = ads_connect(ads);
302 nt_status = ads_ntstatus(ads_status);
305 if (!NT_STATUS_IS_OK(nt_status)) {
313 /********************************************************************
314 *******************************************************************/
316 NTSTATUS cell_connect_dn(struct likewise_cell **c, const char *dn)
318 NTSTATUS nt_status = NT_STATUS_UNSUCCESSFUL;
319 struct likewise_cell *new_cell = NULL;
320 char *dns_domain = NULL;
323 nt_status = NT_STATUS_INVALID_PARAMETER;
324 BAIL_ON_NTSTATUS_ERROR(nt_status);
327 if ((new_cell = cell_new()) == NULL) {
328 nt_status = NT_STATUS_NO_MEMORY;
329 BAIL_ON_NTSTATUS_ERROR(nt_status);
332 /* Set the DNS domain, dn, etc ... and add it to the list */
334 dns_domain = cell_dn_to_dns(dn);
335 cell_set_dns_domain(new_cell, dns_domain);
336 SAFE_FREE(dns_domain);
338 cell_set_dn(new_cell, dn);
340 nt_status = cell_connect(new_cell);
341 BAIL_ON_NTSTATUS_ERROR(nt_status);
346 if (!NT_STATUS_IS_OK(nt_status)) {
347 DEBUG(1,("LWI: Failled to connect to cell \"%s\" (%s)\n",
348 dn ? dn : "NULL", nt_errstr(nt_status)));
349 talloc_destroy(new_cell);
356 /********************************************************************
357 *******************************************************************/
359 #define MAX_SEARCH_COUNT 2
361 ADS_STATUS cell_do_search(struct likewise_cell *c,
362 const char *search_base,
368 int search_count = 0;
372 /* check for a NULL connection */
375 nt_status = cell_connect(c);
376 if (!NT_STATUS_IS_OK(nt_status)) {
377 status = ADS_ERROR_NT(nt_status);
382 DEBUG(10, ("cell_do_search: Base = %s, Filter = %s, Scope = %d, GC = %s\n",
383 search_base, expr, scope,
384 c->conn->server.gc ? "yes" : "no"));
386 /* we try multiple times in case the ADS_STRUCT is bad
387 and we need to reconnect */
389 while (search_count < MAX_SEARCH_COUNT) {
391 status = ads_do_search(c->conn, search_base,
392 scope, expr, attrs, msg);
393 if (ADS_ERR_OK(status)) {
394 if (DEBUGLEVEL >= 10) {
395 LDAPMessage *e = NULL;
397 int n = ads_count_replies(c->conn, *msg);
399 DEBUG(10,("cell_do_search: Located %d entries\n", n));
401 for (e=ads_first_entry(c->conn, *msg);
403 e = ads_next_entry(c->conn, e))
405 char *dn = ads_get_dn(c->conn, talloc_tos(), e);
407 DEBUGADD(10,(" dn: %s\n", dn ? dn : "<NULL>"));
416 DEBUG(5, ("cell_do_search: search[%d] failed (%s)\n",
417 search_count, ads_errstr(status)));
421 /* Houston, we have a problem */
423 if (status.error_type == ENUM_ADS_ERROR_LDAP) {
424 switch (status.err.rc) {
425 case LDAP_TIMELIMIT_EXCEEDED:
427 case -1: /* we get this error if we cannot contact
429 nt_status = cell_connect(c);
430 if (!NT_STATUS_IS_OK(nt_status)) {
431 status = ADS_ERROR_NT(nt_status);
436 /* we're all done here */
442 DEBUG(5, ("cell_do_search: exceeded maximum search count!\n"));
444 return ADS_ERROR_NT(NT_STATUS_UNSUCCESSFUL);