s3-secrets: only include secrets.h when needed.
[samba.git] / source3 / utils / net.c
index e0edeef61008827ad27c4de45af109266b9a44e9..1c342858ee3f2e00c7c530a215b7d7e6955648d5 100644 (file)
@@ -42,6 +42,7 @@
 
 #include "includes.h"
 #include "utils/net.h"
+#include "secrets.h"
 
 extern bool AllowDebugChange;
 
@@ -49,22 +50,11 @@ extern bool AllowDebugChange;
 #include "utils/net_afs.h"
 #endif
 
-/***********************************************************************/
-/* Beginning of internationalization section.  Translatable constants  */
-/* should be kept in this area and referenced in the rest of the code. */
-/*                                                                     */
-/* No functions, outside of Samba or LSB (Linux Standards Base) should */
-/* be used (if possible).                                              */
-/***********************************************************************/
-
-#define YES_STRING              "Yes"
-#define NO_STRING               "No"
-
 /***********************************************************************/
 /* end of internationalization section                                 */
 /***********************************************************************/
 
-uint32 get_sec_channel_type(const char *param)
+enum netr_SchannelType get_sec_channel_type(const char *param)
 {
        if (!(param && *param)) {
                return get_default_sec_channel();
@@ -102,7 +92,7 @@ static int net_changesecretpw(struct net_context *c, int argc,
                              const char **argv)
 {
         char *trust_pw;
-        uint32 sec_channel_type = SEC_CHAN_WKSTA;
+        enum netr_SchannelType sec_channel_type = SEC_CHAN_WKSTA;
 
        if(c->opt_force) {
                if (c->opt_stdin) {
@@ -111,31 +101,138 @@ static int net_changesecretpw(struct net_context *c, int argc,
                        set_line_buffering(stderr);
                }
 
-               trust_pw = get_pass("Enter machine password: ", c->opt_stdin);
+               trust_pw = get_pass(_("Enter machine password: "), c->opt_stdin);
 
                if (!secrets_store_machine_password(trust_pw, lp_workgroup(), sec_channel_type)) {
-                           d_fprintf(stderr, "Unable to write the machine account password in the secrets database");
+                           d_fprintf(stderr,
+                                     _("Unable to write the machine account password in the secrets database"));
                            return 1;
                }
                else {
-                   d_printf("Modified trust account password in secrets database\n");
+                   d_printf(_("Modified trust account password in secrets database\n"));
                }
        }
        else {
-               d_printf("Machine account password change requires the -f flag.\n");
-               d_printf("Do NOT use this function unless you know what it does!\n");
-               d_printf("This function will change the ADS Domain member machine account password in the secrets.tdb file!\n");
+               d_printf(_("Machine account password change requires the -f flag.\n"
+                          "Do NOT use this function unless you know what it does!\n"
+                          "This function will change the ADS Domain member "
+                          "machine account password in the secrets.tdb file!\n"));
        }
 
         return 0;
 }
 
+/**
+ * @brief Set the authorised user for winbindd access in secrets.tdb
+ */
+static int net_setauthuser(struct net_context *c, int argc, const char **argv)
+{
+       const char *password = NULL;
+
+       if (!secrets_init()) {
+               d_fprintf(stderr, _("Failed to open secrets.tdb.\n"));
+               return 1;
+       }
+
+       /* Delete the settings. */
+       if (argc >= 1) {
+               if (strncmp(argv[0], "delete", 6) != 0) {
+                       d_fprintf(stderr,_("Usage:\n"));
+                       d_fprintf(stderr,
+                                 _("    net setauthuser -U user[%%password] \n"
+                                   "        Set the auth user account to user"
+                                   "password. Prompt for password if not "
+                                   "specified.\n"));
+                       d_fprintf(stderr,
+                                 _("    net setauthuser delete\n"
+                                   "        Delete the auth user setting.\n"));
+                       return 1;
+               }
+               secrets_delete(SECRETS_AUTH_USER);
+               secrets_delete(SECRETS_AUTH_DOMAIN);
+               secrets_delete(SECRETS_AUTH_PASSWORD);
+               return 0;
+       }
+
+       if (!c->opt_user_specified) {
+               d_fprintf(stderr, _("Usage:\n"));
+               d_fprintf(stderr,
+                         _("    net setauthuser -U user[%%password]\n"
+                           "        Set the auth user account to user"
+                           "password. Prompt for password if not "
+                           "specified.\n"));
+               d_fprintf(stderr,
+                         _("    net setauthuser delete\n"
+                           "        Delete the auth user setting.\n"));
+               return 1;
+       }
+
+       password = net_prompt_pass(c, _("the auth user"));
+       if (password == NULL) {
+               d_fprintf(stderr,_("Failed to get the auth users password.\n"));
+               return 1;
+       }
+
+       if (!secrets_store(SECRETS_AUTH_USER, c->opt_user_name,
+                          strlen(c->opt_user_name) + 1)) {
+               d_fprintf(stderr, _("error storing auth user name\n"));
+               return 1;
+       }
+
+       if (!secrets_store(SECRETS_AUTH_DOMAIN, c->opt_workgroup,
+                          strlen(c->opt_workgroup) + 1)) {
+               d_fprintf(stderr, _("error storing auth user domain\n"));
+               return 1;
+       }
+
+       if (!secrets_store(SECRETS_AUTH_PASSWORD, password,
+                          strlen(password) + 1)) {
+               d_fprintf(stderr, _("error storing auth user password\n"));
+               return 1;
+       }
+
+       return 0;
+}
+
+/**
+ * @brief Get the auth user settings
+ */
+static int net_getauthuser(struct net_context *c, int argc, const char **argv)
+{
+       char *user, *domain, *password;
+
+       /* Lift data from secrets file */
+
+       secrets_fetch_ipc_userpass(&user, &domain, &password);
+
+       if ((!user || !*user) && (!domain || !*domain ) &&
+           (!password || !*password)){
+
+               SAFE_FREE(user);
+               SAFE_FREE(domain);
+               SAFE_FREE(password);
+               d_printf(_("No authorised user configured\n"));
+               return 0;
+       }
+
+       /* Pretty print authorised user info */
+
+       d_printf("%s%s%s%s%s\n", domain ? domain : "",
+                domain ? lp_winbind_separator(): "", user,
+                password ? "%" : "", password ? password : "");
+
+       SAFE_FREE(user);
+       SAFE_FREE(domain);
+       SAFE_FREE(password);
+
+       return 0;
+}
 /*
  Retrieve our local SID or the SID for the specified name
  */
 static int net_getlocalsid(struct net_context *c, int argc, const char **argv)
 {
-        DOM_SID sid;
+        struct dom_sid sid;
        const char *name;
        fstring sid_str;
 
@@ -155,7 +252,9 @@ static int net_getlocalsid(struct net_context *c, int argc, const char **argv)
           panic when we can't. */
 
        if (!secrets_init()) {
-               d_fprintf(stderr, "Unable to open secrets.tdb.  Can't fetch domain SID for name: %s\n", name);
+               d_fprintf(stderr,
+                         _("Unable to open secrets.tdb.  Can't fetch domain "
+                           "SID for name: %s\n"), name);
                return 1;
        }
 
@@ -167,19 +266,20 @@ static int net_getlocalsid(struct net_context *c, int argc, const char **argv)
                return 1;
        }
        sid_to_fstring(sid_str, &sid);
-       d_printf("SID for domain %s is: %s\n", name, sid_str);
+       d_printf(_("SID for domain %s is: %s\n"), name, sid_str);
        return 0;
 }
 
 static int net_setlocalsid(struct net_context *c, int argc, const char **argv)
 {
-       DOM_SID sid;
+       struct dom_sid sid;
 
        if ( (argc != 1)
             || (strncmp(argv[0], "S-1-5-21-", strlen("S-1-5-21-")) != 0)
             || (!string_to_sid(&sid, argv[0]))
             || (sid.num_auths != 4)) {
-               d_printf("usage: net setlocalsid S-1-5-21-x-y-z\n");
+               d_printf(_("Usage:"));
+               d_printf(" net setlocalsid S-1-5-21-x-y-z\n");
                return 1;
        }
 
@@ -193,13 +293,14 @@ static int net_setlocalsid(struct net_context *c, int argc, const char **argv)
 
 static int net_setdomainsid(struct net_context *c, int argc, const char **argv)
 {
-       DOM_SID sid;
+       struct dom_sid sid;
 
        if ( (argc != 1)
             || (strncmp(argv[0], "S-1-5-21-", strlen("S-1-5-21-")) != 0)
             || (!string_to_sid(&sid, argv[0]))
             || (sid.num_auths != 4)) {
-               d_printf("usage: net setdomainsid S-1-5-21-x-y-z\n");
+               d_printf(_("Usage:"));
+               d_printf(" net setdomainsid S-1-5-21-x-y-z\n");
                return 1;
        }
 
@@ -213,11 +314,12 @@ static int net_setdomainsid(struct net_context *c, int argc, const char **argv)
 
 static int net_getdomainsid(struct net_context *c, int argc, const char **argv)
 {
-       DOM_SID domain_sid;
+       struct dom_sid domain_sid;
        fstring sid_str;
 
        if (argc > 0) {
-               d_printf("usage: net getdomainsid\n");
+               d_printf(_("Usage:"));
+               d_printf(" net getdomainsid\n");
                return 1;
        }
 
@@ -232,8 +334,9 @@ static int net_getdomainsid(struct net_context *c, int argc, const char **argv)
           panic when we can't. */
 
        if (!secrets_init()) {
-               d_fprintf(stderr, "Unable to open secrets.tdb.  Can't fetch domain"
-                                 "SID for name: %s\n", get_global_sam_name());
+               d_fprintf(stderr, _("Unable to open secrets.tdb.  Can't fetch "
+                                   "domain SID for name: %s\n"),
+                         get_global_sam_name());
                return 1;
        }
 
@@ -241,19 +344,20 @@ static int net_getdomainsid(struct net_context *c, int argc, const char **argv)
        get_global_sam_sid();
 
        if (!secrets_fetch_domain_sid(global_myname(), &domain_sid)) {
-               d_fprintf(stderr, "Could not fetch local SID\n");
+               d_fprintf(stderr, _("Could not fetch local SID\n"));
                return 1;
        }
        sid_to_fstring(sid_str, &domain_sid);
-       d_printf("SID for local machine %s is: %s\n", global_myname(), sid_str);
+       d_printf(_("SID for local machine %s is: %s\n"),
+                global_myname(), sid_str);
 
        if (!secrets_fetch_domain_sid(c->opt_workgroup, &domain_sid)) {
-               d_fprintf(stderr, "Could not fetch domain SID\n");
+               d_fprintf(stderr, _("Could not fetch domain SID\n"));
                return 1;
        }
 
        sid_to_fstring(sid_str, &domain_sid);
-       d_printf("SID for domain %s is: %s\n", c->opt_workgroup, sid_str);
+       d_printf(_("SID for domain %s is: %s\n"), c->opt_workgroup, sid_str);
 
        return 0;
 }
@@ -265,14 +369,14 @@ static bool search_maxrid(struct pdb_search *search, const char *type,
        uint32 i, num_entries;
 
        if (search == NULL) {
-               d_fprintf(stderr, "get_maxrid: Could not search %s\n", type);
+               d_fprintf(stderr, _("get_maxrid: Could not search %s\n"), type);
                return false;
        }
 
        num_entries = pdb_search_entries(search, 0, 0xffffffff, &entries);
        for (i=0; i<num_entries; i++)
                *max_rid = MAX(*max_rid, entries[i].rid);
-       pdb_search_destroy(search);
+       TALLOC_FREE(search);
        return true;
 }
 
@@ -280,13 +384,14 @@ static uint32 get_maxrid(void)
 {
        uint32 max_rid = 0;
 
-       if (!search_maxrid(pdb_search_users(0), "users", &max_rid))
+       if (!search_maxrid(pdb_search_users(talloc_tos(), 0), "users", &max_rid))
                return 0;
 
-       if (!search_maxrid(pdb_search_groups(), "groups", &max_rid))
+       if (!search_maxrid(pdb_search_groups(talloc_tos()), "groups", &max_rid))
                return 0;
 
-       if (!search_maxrid(pdb_search_aliases(get_global_sam_sid()),
+       if (!search_maxrid(pdb_search_aliases(talloc_tos(),
+                                             get_global_sam_sid()),
                           "aliases", &max_rid))
                return 0;
 
@@ -298,66 +403,357 @@ static int net_maxrid(struct net_context *c, int argc, const char **argv)
        uint32 rid;
 
        if (argc != 0) {
-               DEBUG(0, ("usage: net maxrid\n"));
+               d_fprintf(stderr, "%s net maxrid\n", _("Usage:"));
                return 1;
        }
 
        if ((rid = get_maxrid()) == 0) {
-               DEBUG(0, ("can't get current maximum rid\n"));
+               d_fprintf(stderr, _("can't get current maximum rid\n"));
                return 1;
        }
 
-       d_printf("Currently used maximum rid: %d\n", rid);
+       d_printf(_("Currently used maximum rid: %d\n"), rid);
 
        return 0;
 }
 
 /* main function table */
 static struct functable net_func[] = {
-       {"RPC", net_rpc},
-       {"RAP", net_rap},
-       {"ADS", net_ads},
+       {
+               "rpc",
+               net_rpc,
+               NET_TRANSPORT_RPC,
+               N_("Run functions using RPC transport"),
+               N_("  Use 'net help rpc' to get more extensive information "
+                  "about 'net rpc' commands.")
+       },
+       {
+               "rap",
+               net_rap,
+               NET_TRANSPORT_RAP,
+               N_("Run functions using RAP transport"),
+               N_("  Use 'net help rap' to get more extensive information "
+                  "about 'net rap' commands.")
+       },
+       {
+               "ads",
+               net_ads,
+               NET_TRANSPORT_ADS,
+               N_("Run functions using ADS transport"),
+               N_("  Use 'net help ads' to get more extensive information "
+                  "about 'net ads' commands.")
+       },
 
        /* eventually these should auto-choose the transport ... */
-       {"FILE", net_file},
-       {"SHARE", net_share},
-       {"SESSION", net_rap_session},
-       {"SERVER", net_rap_server},
-       {"DOMAIN", net_rap_domain},
-       {"PRINTQ", net_rap_printq},
-       {"USER", net_user},
-       {"GROUP", net_group},
-       {"GROUPMAP", net_groupmap},
-       {"SAM", net_sam},
-       {"VALIDATE", net_rap_validate},
-       {"GROUPMEMBER", net_rap_groupmember},
-       {"ADMIN", net_rap_admin},
-       {"SERVICE", net_rap_service},
-       {"PASSWORD", net_rap_password},
-       {"CHANGETRUSTPW", net_changetrustpw},
-       {"CHANGESECRETPW", net_changesecretpw},
-       {"TIME", net_time},
-       {"LOOKUP", net_lookup},
-       {"JOIN", net_join},
-       {"DOM", net_dom},
-       {"CACHE", net_cache},
-       {"GETLOCALSID", net_getlocalsid},
-       {"SETLOCALSID", net_setlocalsid},
-       {"SETDOMAINSID", net_setdomainsid},
-       {"GETDOMAINSID", net_getdomainsid},
-       {"MAXRID", net_maxrid},
-       {"IDMAP", net_idmap},
-       {"STATUS", net_status},
-       {"USERSHARE", net_usershare},
-       {"USERSIDLIST", net_usersidlist},
-       {"CONF", net_conf},
-       {"REGISTRY", net_registry},
+       {
+               "file",
+               net_file,
+               NET_TRANSPORT_RPC | NET_TRANSPORT_RAP,
+               N_("Functions on remote opened files"),
+               N_("  Use 'net help file' to get more information about 'net "
+                  "file' commands.")
+       },
+       {
+               "share",
+               net_share,
+               NET_TRANSPORT_RPC | NET_TRANSPORT_RAP,
+               N_("Functions on shares"),
+               N_("  Use 'net help share' to get more information about 'net "
+                  "share' commands.")
+       },
+       {
+               "session",
+               net_rap_session,
+               NET_TRANSPORT_RAP,
+               N_("Manage sessions"),
+               N_("  Use 'net help session' to get more information about "
+                  "'net session' commands.")
+       },
+       {
+               "server",
+               net_rap_server,
+               NET_TRANSPORT_RAP,
+               N_("List servers in workgroup"),
+               N_("  Use 'net help server' to get more information about 'net "
+                  "server' commands.")
+       },
+       {
+               "domain",
+               net_rap_domain,
+               NET_TRANSPORT_RAP,
+               N_("List domains/workgroups on network"),
+               N_("  Use 'net help domain' to get more information about 'net "
+                  "domain' commands.")
+       },
+       {
+               "printq",
+               net_rap_printq,
+               NET_TRANSPORT_RAP,
+               N_("Modify printer queue"),
+               N_("  Use 'net help printq' to get more information about 'net "
+                  "printq' commands.")
+       },
+       {
+               "user",
+               net_user,
+               NET_TRANSPORT_ADS | NET_TRANSPORT_RPC | NET_TRANSPORT_RAP,
+               N_("Manage users"),
+               N_("  Use 'net help user' to get more information about 'net "
+                  "user' commands.")
+       },
+       {
+               "group",
+               net_group,
+               NET_TRANSPORT_ADS | NET_TRANSPORT_RPC | NET_TRANSPORT_RAP,
+               N_("Manage groups"),
+               N_("  Use 'net help group' to get more information about 'net "
+                  "group' commands.")
+       },
+       {
+               "groupmap",
+               net_groupmap,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage group mappings"),
+               N_("  Use 'net help groupmap' to get more information about "
+                  "'net groupmap' commands.")
+       },
+       {
+               "sam",
+               net_sam,
+               NET_TRANSPORT_LOCAL,
+               N_("Functions on the SAM database"),
+               N_("  Use 'net help sam' to get more information about 'net "
+                  "sam' commands.")
+       },
+       {
+               "validate",
+               net_rap_validate,
+               NET_TRANSPORT_RAP,
+               N_("Validate username and password"),
+               N_("  Use 'net help validate' to get more information about "
+                  "'net validate' commands.")
+       },
+       {
+               "groupmember",
+               net_rap_groupmember,
+               NET_TRANSPORT_RAP,
+               N_("Modify group memberships"),
+               N_("  Use 'net help groupmember' to get more information about "
+                  "'net groupmember' commands.")
+       },
+       {       "admin",
+               net_rap_admin,
+               NET_TRANSPORT_RAP,
+               N_("Execute remote command on a remote OS/2 server"),
+               N_("  Use 'net help admin' to get more information about 'net "
+                  "admin' commands.")
+       },
+       {       "service",
+               net_rap_service,
+               NET_TRANSPORT_RAP,
+               N_("List/modify running services"),
+               N_("  Use 'net help service' to get more information about "
+                  "'net service' commands.")
+       },
+       {
+               "password",
+               net_rap_password,
+               NET_TRANSPORT_RAP,
+               N_("Change user password on target server"),
+               N_("  Use 'net help password' to get more information about "
+                  "'net password' commands.")
+       },
+       {       "changetrustpw",
+               net_changetrustpw,
+               NET_TRANSPORT_ADS | NET_TRANSPORT_RPC,
+               N_("Change the trust password"),
+               N_("  Use 'net help changetrustpw' to get more information "
+                  "about 'net changetrustpw'.")
+       },
+       {       "changesecretpw",
+               net_changesecretpw,
+               NET_TRANSPORT_LOCAL,
+               N_("Change the secret password"),
+               N_("  net [options] changesecretpw\n"
+                  "    Change the ADS domain member machine account password "
+                  "in secrets.tdb.\n"
+                  "    Do NOT use this function unless you know what it does.\n"
+                  "    Requires the -f flag to work.")
+       },
+       {
+               "setauthuser",
+               net_setauthuser,
+               NET_TRANSPORT_LOCAL,
+               N_("Set the winbind auth user"),
+               N_("  net -U user[%%password] [-W domain] setauthuser\n"
+                  "    Set the auth user, password (and optionally domain\n"
+                  "    Will prompt for password if not given.\n"
+                  "  net setauthuser delete\n"
+                  "    Delete the existing auth user settings.")
+       },
+       {
+               "getauthuser",
+               net_getauthuser,
+               NET_TRANSPORT_LOCAL,
+               N_("Get the winbind auth user settings"),
+               N_("  net getauthuser\n"
+                  "    Get the current winbind auth user settings.")
+       },
+       {       "time",
+               net_time,
+               NET_TRANSPORT_LOCAL,
+               N_("Show/set time"),
+               N_("  Use 'net help time' to get more information about 'net "
+                  "time' commands.")
+       },
+       {       "lookup",
+               net_lookup,
+               NET_TRANSPORT_LOCAL,
+               N_("Look up host names/IP addresses"),
+               N_("  Use 'net help lookup' to get more information about 'net "
+                  "lookup' commands.")
+       },
+       {       "g_lock",
+               net_g_lock,
+               NET_TRANSPORT_LOCAL,
+               N_("Manipulate the global lock table"),
+               N_("  Use 'net help g_lock' to get more information about "
+                  "'net g_lock' commands.")
+       },
+       {       "join",
+               net_join,
+               NET_TRANSPORT_ADS | NET_TRANSPORT_RPC,
+               N_("Join a domain/AD"),
+               N_("  Use 'net help join' to get more information about 'net "
+                  "join'.")
+       },
+       {       "dom",
+               net_dom,
+               NET_TRANSPORT_LOCAL,
+               N_("Join/unjoin (remote) machines to/from a domain/AD"),
+               N_("  Use 'net help dom' to get more information about 'net "
+                  "dom' commands.")
+       },
+       {       "cache",
+               net_cache,
+               NET_TRANSPORT_LOCAL,
+               N_("Operate on the cache tdb file"),
+               N_("  Use 'net help cache' to get more information about 'net "
+                  "cache' commands.")
+       },
+       {       "getlocalsid",
+               net_getlocalsid,
+               NET_TRANSPORT_LOCAL,
+               N_("Get the SID for the local domain"),
+               N_("  net getlocalsid")
+       },
+       {       "setlocalsid",
+               net_setlocalsid,
+               NET_TRANSPORT_LOCAL,
+               N_("Set the SID for the local domain"),
+               N_("  net setlocalsid S-1-5-21-x-y-z")
+       },
+       {       "setdomainsid",
+               net_setdomainsid,
+               NET_TRANSPORT_LOCAL,
+               N_("Set domain SID on member servers"),
+               N_("  net setdomainsid S-1-5-21-x-y-z")
+       },
+       {       "getdomainsid",
+               net_getdomainsid,
+               NET_TRANSPORT_LOCAL,
+               N_("Get domain SID on member servers"),
+               N_("  net getdomainsid")
+       },
+       {       "maxrid",
+               net_maxrid,
+               NET_TRANSPORT_LOCAL,
+               N_("Display the maximul RID currently used"),
+               N_("  net maxrid")
+       },
+       {       "idmap",
+               net_idmap,
+               NET_TRANSPORT_LOCAL,
+               N_("IDmap functions"),
+               N_("  Use 'net help idmap to get more information about 'net "
+                 "idmap' commands.")
+       },
+       {       "status",
+               net_status,
+               NET_TRANSPORT_LOCAL,
+               N_("Display server status"),
+               N_("  Use 'net help status' to get more information about 'net "
+                  "status' commands.")
+       },
+       {       "usershare",
+               net_usershare,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage user-modifiable shares"),
+               N_("  Use 'net help usershare to get more information about "
+                  "'net usershare' commands.")
+       },
+       {       "usersidlist",
+               net_usersidlist,
+               NET_TRANSPORT_RPC,
+               N_("Display list of all users with SID"),
+               N_("  Use 'net help usersidlist' to get more information about "
+                  "'net usersidlist'.")
+       },
+       {       "conf",
+               net_conf,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage Samba registry based configuration"),
+               N_("  Use 'net help conf' to get more information about 'net "
+                  "conf' commands.")
+       },
+       {       "registry",
+               net_registry,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage the Samba registry"),
+               N_("  Use 'net help registry' to get more information about "
+                  "'net registry' commands.")
+       },
+       {       "eventlog",
+               net_eventlog,
+               NET_TRANSPORT_LOCAL,
+               N_("Process Win32 *.evt eventlog files"),
+               N_("  Use 'net help eventlog' to get more information about "
+                  "'net eventlog' commands.")
+       },
+       {       "printing",
+               net_printing,
+               NET_TRANSPORT_LOCAL,
+               N_("Process tdb printer files"),
+               N_("  Use 'net help printing' to get more information about "
+                  "'net printing' commands.")
+       },
+
+       {       "serverid",
+               net_serverid,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage the serverid tdb"),
+               N_("  Use 'net help serverid' to get more information about "
+                  "'net serverid' commands.")
+       },
+
 #ifdef WITH_FAKE_KASERVER
-       {"AFS", net_afs},
+       {       "afs",
+               net_afs,
+               NET_TRANSPORT_LOCAL,
+               N_("Manage AFS tokens"),
+               N_("  Use 'net help afs' to get more information about 'net "
+                  "afs' commands.")
+       },
 #endif
 
-       {"HELP", net_help},
-       {NULL, NULL}
+       {       "help",
+               net_help,
+               NET_TRANSPORT_LOCAL,
+               N_("Print usage information"),
+               N_("  Use 'net help help' to list usage information for 'net' "
+                  "commands.")
+       },
+       {NULL, NULL, 0, NULL, NULL}
 };
 
 
@@ -383,7 +779,7 @@ static struct functable net_func[] = {
                {"port",        'p', POPT_ARG_INT,    &c->opt_port},
                {"myname",      'n', POPT_ARG_STRING, &c->opt_requester_name},
                {"server",      'S', POPT_ARG_STRING, &c->opt_host},
-               {"encrypt",     'e', POPT_ARG_NONE,   NULL, 'e', "Encrypt SMB transport (UNIX extended servers only)" },
+               {"encrypt",     'e', POPT_ARG_NONE,   NULL, 'e', N_("Encrypt SMB transport (UNIX extended servers only)") },
                {"container",   'c', POPT_ARG_STRING, &c->opt_container},
                {"comment",     'C', POPT_ARG_STRING, &c->opt_comment},
                {"maxusers",    'M', POPT_ARG_INT,    &c->opt_maxusers},
@@ -393,8 +789,11 @@ static struct functable net_func[] = {
                {"force",       'f', POPT_ARG_NONE,   &c->opt_force},
                {"stdin",       'i', POPT_ARG_NONE,   &c->opt_stdin},
                {"timeout",     't', POPT_ARG_INT,    &c->opt_timeout},
+               {"request-timeout",0,POPT_ARG_INT,    &c->opt_request_timeout},
                {"machine-pass",'P', POPT_ARG_NONE,   &c->opt_machine_pass},
+               {"kerberos",    'k', POPT_ARG_NONE,   &c->opt_kerberos},
                {"myworkgroup", 'W', POPT_ARG_STRING, &c->opt_workgroup},
+               {"use-ccache",    0, POPT_ARG_NONE,   &c->opt_ccache},
                {"verbose",     'v', POPT_ARG_NONE,   &c->opt_verbose},
                {"test",        'T', POPT_ARG_NONE,   &c->opt_testmode},
                /* Options for 'net groupmap set' */
@@ -409,19 +808,31 @@ static struct functable net_func[] = {
                {"exclude",     'X', POPT_ARG_STRING, &c->opt_exclude},
                {"destination", 0, POPT_ARG_STRING,   &c->opt_destination},
                {"tallocreport", 0, POPT_ARG_NONE,    &c->do_talloc_report},
+               /* Options for 'net rpc vampire (keytab)' */
+               {"force-full-repl", 0, POPT_ARG_NONE, &c->opt_force_full_repl},
+               {"single-obj-repl", 0, POPT_ARG_NONE, &c->opt_single_obj_repl},
+               {"clean-old-entries", 0, POPT_ARG_NONE, &c->opt_clean_old_entries},
 
                POPT_COMMON_SAMBA
                { 0, 0, 0, 0}
        };
 
-
-       zero_addr(&c->opt_dest_ip);
+       zero_sockaddr(&c->opt_dest_ip);
 
        load_case_tables();
 
+       setlocale(LC_ALL, "");
+#if defined(HAVE_BINDTEXTDOMAIN)
+       bindtextdomain(MODULE_NAME, dyn_LOCALEDIR);
+#endif
+#if defined(HAVE_TEXTDOMAIN)
+       textdomain(MODULE_NAME);
+#endif
+
        /* set default debug level to 0 regardless of what smb.conf sets */
        DEBUGLEVEL_CLASS[DBGC_ALL] = 0;
        dbf = x_stderr;
+       c->private_data = net_func;
 
        pc = poptGetContext(NULL, argc, (const char **) argv, long_options,
                            POPT_CONTEXT_KEEP_FIRST);
@@ -429,8 +840,7 @@ static struct functable net_func[] = {
        while((opt = poptGetNextOpt(pc)) != -1) {
                switch (opt) {
                case 'h':
-                       net_help(c, argc, argv);
-                       exit(0);
+                       c->display_usage = true;
                        break;
                case 'e':
                        c->smb_encrypt = true;
@@ -438,7 +848,7 @@ static struct functable net_func[] = {
                case 'I':
                        if (!interpret_string_addr(&c->opt_dest_ip,
                                                poptGetOptArg(pc), 0)) {
-                               d_fprintf(stderr, "\nInvalid ip address specified\n");
+                               d_fprintf(stderr, _("\nInvalid ip address specified\n"));
                        } else {
                                c->opt_have_ip = true;
                        }
@@ -453,7 +863,7 @@ static struct functable net_func[] = {
                        }
                        break;
                default:
-                       d_fprintf(stderr, "\nInvalid option %s: %s\n",
+                       d_fprintf(stderr, _("\nInvalid option %s: %s\n"),
                                 poptBadOption(pc, 0), poptStrerror(opt));
                        net_help(c, argc, argv);
                        exit(1);
@@ -503,7 +913,7 @@ static struct functable net_func[] = {
        load_interfaces();
 
        /* this makes sure that when we do things like call scripts,
-          that it won't assert becouse we are not root */
+          that it won't assert because we are not root */
        sec_init();
 
        if (c->opt_machine_pass) {
@@ -517,10 +927,12 @@ static struct functable net_func[] = {
                c->opt_password = getenv("PASSWD");
        }
 
-       rc = net_run_function(c, argc_new-1, argv_new+1, net_func, net_help);
+       rc = net_run_function(c, argc_new-1, argv_new+1, "net", net_func);
 
        DEBUG(2,("return code = %d\n", rc));
 
+       gencache_stabilize();
+
        libnetapi_free(c->netapi_ctx);
 
        poptFreeContext(pc);