2 * Unix SMB/Netbios implementation. Version 1.9. SMB parameters and setup
3 * Copyright (C) Andrew Tridgell 1992-1998 Modified by Jeremy Allison 1995.
5 * This program is free software; you can redistribute it and/or modify it under
6 * the terms of the GNU General Public License as published by the Free
7 * Software Foundation; either version 2 of the License, or (at your option)
10 * This program is distributed in the hope that it will be useful, but WITHOUT
11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
15 * You should have received a copy of the GNU General Public License along with
16 * this program; if not, write to the Free Software Foundation, Inc., 675
17 * Mass Ave, Cambridge, MA 02139, USA.
24 extern int DEBUGLEVEL;
27 extern DOM_SID global_sam_sid;
28 extern fstring global_sam_name;
30 /***************************************************************
31 Start to enumerate the alspasswd list. Returns a void pointer
32 to ensure no modification outside this module.
33 ****************************************************************/
35 static void *startalsunixpwent(BOOL update)
41 /***************************************************************
42 End enumeration of the alspasswd list.
43 ****************************************************************/
45 static void endalsunixpwent(void *vp)
50 /*************************************************************************
51 Return the current position in the alspasswd list as an SMB_BIG_UINT.
52 This must be treated as an opaque token.
53 *************************************************************************/
54 static SMB_BIG_UINT getalsunixpwpos(void *vp)
56 return (SMB_BIG_UINT)0;
59 /*************************************************************************
60 Set the current position in the alspasswd list from an SMB_BIG_UINT.
61 This must be treated as an opaque token.
62 *************************************************************************/
63 static BOOL setalsunixpwpos(void *vp, SMB_BIG_UINT tok)
68 /*************************************************************************
69 maps a unix group to a domain sid and an nt alias name.
70 *************************************************************************/
71 static void map_unix_grp_to_nt_als(char *unix_name,
72 struct group *unix_grp, char *nt_name, DOM_SID *sid)
79 if (isdigit(unix_name[0]))
81 unix_grp->gr_gid = get_number(unix_name);
82 unix_grp->gr_name = unix_name;
83 found = map_alias_gid(unix_grp->gr_gid, sid, ntname, ntdomain);
87 unix_grp->gr_name = unix_name;
88 found = map_unix_alias_name(unix_grp->gr_name, sid, ntname, ntdomain);
94 * find the NT name represented by this UNIX gid.
95 * then, only accept NT aliass that are in our domain
98 sid_split_rid(sid, &rid);
103 * assume that the UNIX group is an NT alias with
104 * the same name. convert gid to a alias rid.
107 fstrcpy(ntdomain, global_sam_name);
108 fstrcpy(ntname, unix_grp->gr_name);
109 sid_copy(sid, &global_sam_sid);
112 slprintf(nt_name, sizeof(fstring)-1, "\\%s\\%s",
116 /*************************************************************************
117 Routine to return the next entry in the smbdomainalias list.
118 *************************************************************************/
119 BOOL get_unixalias_members(struct group *als,
120 int *num_mem, LOCAL_GRP_MEMBER **members)
126 if (num_mem == NULL || members == NULL)
134 for (i = 0; (unix_name = als->gr_mem[i]) != NULL; i++)
137 struct group unix_grp;
139 map_unix_grp_to_nt_als(unix_name, &unix_grp, nt_name, &sid);
141 if (!sid_equal(&sid, &global_sam_sid))
143 DEBUG(0,("alias database: could not resolve name %s in domain %s\n",
144 unix_name, global_sam_name));
148 (*members) = Realloc((*members), ((*num_mem)+1) * sizeof(LOCAL_GRP_MEMBER));
149 if ((*members) == NULL)
154 fstrcpy((*members)[(*num_mem)].name, nt_name);
160 /*************************************************************************
161 Routine to return the next entry in the domain alias list.
163 when we are a PDC or BDC, then unix groups that are explicitly NOT mapped
164 to aliases (map_alias_gid) are treated as DOMAIN groups (see groupunix.c).
166 when we are a member of a domain (not a PDC or BDC) then unix groups
167 that are explicitly NOT mapped to aliases (map_alias_gid) are treated
170 the reasoning behind this is to make it as simple as possible (not an easy
171 task) for people to set up a domain-aware samba server, in each role that
174 *************************************************************************/
175 static LOCAL_GRP *getalsunixpwent(void *vp, LOCAL_GRP_MEMBER **mem, int *num_mem)
177 /* Static buffers we will return. */
178 static LOCAL_GRP gp_buf;
179 struct group *unix_grp;
181 if (lp_server_role() == ROLE_DOMAIN_NONE)
184 * no domain role, no domain aliases (or domain groups,
185 * but that's dealt with by groupdb...).
191 aldb_init_als(&gp_buf);
193 fstrcpy(gp_buf.comment, "");
195 /* cycle through unix groups */
196 while ((unix_grp = getgrent()) != NULL)
199 if (map_alias_gid(unix_grp->gr_gid, &sid, gp_buf.name, NULL))
202 * find the NT name represented by this UNIX gid.
203 * then, only accept NT aliases that are in our domain
206 sid_split_rid(&sid, &gp_buf.rid);
207 if (sid_equal(&sid, &global_sam_sid))
212 else if (lp_server_role() == ROLE_DOMAIN_MEMBER)
215 * if we are a member of a domain,
216 * assume that the UNIX alias is an NT alias with
217 * the same name. convert gid to a alias rid.
220 fstrcpy(gp_buf.name, unix_grp->gr_name);
221 gp_buf.rid = pwdb_gid_to_alias_rid(unix_grp->gr_gid);
225 if (unix_grp == NULL)
230 /* get the user's domain aliases. there are a maximum of 32 */
232 if (mem != NULL && num_mem != NULL)
237 get_unixalias_members(unix_grp, num_mem, mem);
242 make_alias_line(linebuf, sizeof(linebuf), &gp_buf, mem, num_mem);
243 DEBUG(10,("line: '%s'\n", linebuf));
249 /************************************************************************
250 Routine to add an entry to the alspasswd file.
251 *************************************************************************/
253 static BOOL add_alsunixgrp_entry(LOCAL_GRP *newals)
255 DEBUG(0, ("add_alsunixgrp_entry: NOT IMPLEMENTED\n"));
259 /************************************************************************
260 Routine to search the alspasswd file for an entry matching the aliasname.
261 and then modify its alias entry. We can't use the startalspwent()/
262 getalspwent()/endalspwent() interfaces here as we depend on looking
263 in the actual file to decide how much room we have to write data.
264 override = False, normal
265 override = True, override XXXXXXXX'd out alias or NO PASS
266 ************************************************************************/
268 static BOOL mod_alsunixgrp_entry(LOCAL_GRP* als)
270 DEBUG(0, ("mod_alsunixgrp_entry: NOT IMPLEMENTED\n"));
275 static struct aliasdb_ops unix_ops =
282 iterate_getaliasnam, /* In aliasdb.c */
283 iterate_getaliasgid, /* In aliasdb.c */
284 iterate_getaliasrid, /* In aliasdb.c */
287 add_alsunixgrp_entry,
288 mod_alsunixgrp_entry,
290 iterate_getuseraliasnam /* in aliasdb.c */
293 struct aliasdb_ops *unix_initialise_alias_db(void)
299 /* Do *NOT* make this function static. It breaks the compile on gcc. JRA */
300 void unix_alspass_dummy_function(void) { } /* stop some compilers complaining */
301 #endif /* USE_SMBPASS_DB */