samba.git
12 years agokrb5: Require gss_get_name_attribute or Heimdal's PAC parsing to build with krb5
Andrew Bartlett [Fri, 6 Jan 2012 07:32:41 +0000 (18:32 +1100)]
krb5: Require gss_get_name_attribute or Heimdal's PAC parsing to build with krb5

Autobuild-User: Andrew Bartlett <abartlet@samba.org>
Autobuild-Date: Tue Jan 10 23:23:07 CET 2012 on sn-devel-104

12 years agokrb5: Require krb5_string_to_key be available to build with krb5
Andrew Bartlett [Thu, 5 Jan 2012 00:39:14 +0000 (11:39 +1100)]
krb5: Require krb5_string_to_key be available to build with krb5

12 years agokrb5: Require krb5_set_real_time is available to build with krb5
Andrew Bartlett [Thu, 5 Jan 2012 00:34:12 +0000 (11:34 +1100)]
krb5: Require krb5_set_real_time is available to build with krb5

12 years agokrb5: Require krb5_principal_compare_any_realm be available to build with krb5
Andrew Bartlett [Thu, 5 Jan 2012 00:30:22 +0000 (11:30 +1100)]
krb5: Require krb5_principal_compare_any_realm be available to build with krb5

12 years agokrb5: Require krb5_get_renewed_creds be available to build with krb5
Andrew Bartlett [Thu, 5 Jan 2012 00:16:24 +0000 (11:16 +1100)]
krb5: Require krb5_get_renewed_creds be available to build with krb5

12 years agokrb5: Remove now unused checks for krb5_verify_checksum
Andrew Bartlett [Thu, 5 Jan 2012 00:09:46 +0000 (11:09 +1100)]
krb5: Remove now unused checks for krb5_verify_checksum

12 years agokrb5: Require krb5_get_init_creds_opt_alloc/free for build with krb5
Andrew Bartlett [Thu, 5 Jan 2012 00:06:28 +0000 (11:06 +1100)]
krb5: Require krb5_get_init_creds_opt_alloc/free for build with krb5

This also assumes the modern API with a krb5_context argument.

Andrew Bartlett

12 years agokrb5: Require krb5_fwd_tgt_creds to be available to build with krb5
Andrew Bartlett [Wed, 4 Jan 2012 23:59:44 +0000 (10:59 +1100)]
krb5: Require krb5_fwd_tgt_creds to be available to build with krb5

12 years agokrb5: Require krb5_get_host_realm and krb5_free_host_realm be available to build...
Andrew Bartlett [Wed, 4 Jan 2012 23:54:50 +0000 (10:54 +1100)]
krb5: Require krb5_get_host_realm and krb5_free_host_realm be available to build with krb5

12 years agokrb5: Require krb5_c_verify_checksum is available to build with krb5
Andrew Bartlett [Wed, 4 Jan 2012 23:51:29 +0000 (10:51 +1100)]
krb5: Require krb5_c_verify_checksum is available to build with krb5

12 years agokrb5: Require krb5_c_enctype_compare is available to build with krb5
Andrew Bartlett [Wed, 4 Jan 2012 23:46:24 +0000 (10:46 +1100)]
krb5: Require krb5_c_enctype_compare is available to build with krb5

12 years agos4:provision: add "+dns" to server services if the dns backend is SAMBA_INTERNAL
Michael Adam [Sun, 8 Jan 2012 00:02:58 +0000 (01:02 +0100)]
s4:provision: add "+dns" to server services if the dns backend is SAMBA_INTERNAL

Signed-off-by: Kai Blin <kai@samba.org>
Autobuild-User: Kai Blin <kai@samba.org>
Autobuild-Date: Tue Jan 10 21:17:45 CET 2012 on sn-devel-104

12 years agos4:provision: add a server services line to the smb.conf template for the dc
Michael Adam [Wed, 4 Jan 2012 23:45:12 +0000 (00:45 +0100)]
s4:provision: add a server services line to the smb.conf template for the dc

Signed-off-by: Kai Blin <kai@samba.org>
12 years agos4:provision: add the possibility to provision "server services" in smb.conf
Michael Adam [Wed, 4 Jan 2012 23:44:39 +0000 (00:44 +0100)]
s4:provision: add the possibility to provision "server services" in smb.conf

Signed-off-by: Kai Blin <kai@samba.org>
12 years agos4:provision: improve a message
Michael Adam [Wed, 4 Jan 2012 23:05:26 +0000 (00:05 +0100)]
s4:provision: improve a message

Signed-off-by: Kai Blin <kai@samba.org>
12 years agosamba: check for AES encryption type defines.
Günther Deschner [Thu, 15 Dec 2011 16:50:33 +0000 (17:50 +0100)]
samba: check for AES encryption type defines.

Guenther

Autobuild-User: Günther Deschner <gd@samba.org>
Autobuild-Date: Tue Jan 10 15:05:38 CET 2012 on sn-devel-104

12 years agotalloc/testsuite: fix compiler warnings
Stefan Metzmacher [Wed, 4 Jan 2012 11:57:10 +0000 (12:57 +0100)]
talloc/testsuite: fix compiler warnings

metze

Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Tue Jan 10 13:31:33 CET 2012 on sn-devel-104

12 years agos3-aio_pthread: Fix the build
Volker Lendecke [Tue, 10 Jan 2012 09:12:49 +0000 (10:12 +0100)]
s3-aio_pthread: Fix the build

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Tue Jan 10 11:54:01 CET 2012 on sn-devel-104

12 years agos3-aio_pthread: Make "pd_list" static
Volker Lendecke [Tue, 10 Jan 2012 09:12:49 +0000 (10:12 +0100)]
s3-aio_pthread: Make "pd_list" static

12 years agos4:python tests __init__.py - do not depend on "subprocess.check_call()"
Matthias Dieter Wallnöfer [Mon, 9 Jan 2012 12:21:49 +0000 (13:21 +0100)]
s4:python tests __init__.py - do not depend on "subprocess.check_call()"

Method not present in Python 2.4

Reviewed-by: Jelmer
Autobuild-User: Matthias Dieter Wallnöfer <mdw@samba.org>
Autobuild-Date: Tue Jan 10 00:41:59 CET 2012 on sn-devel-104

12 years agos4:python tests __init__.py - do not depend on "subprocess.CalledProcessError"
Matthias Dieter Wallnöfer [Mon, 9 Jan 2012 10:55:08 +0000 (11:55 +0100)]
s4:python tests __init__.py - do not depend on "subprocess.CalledProcessError"

The class is not present in Python 2.4

Reviewed-by: Jelmer
12 years agos3: Remove an unused label
Volker Lendecke [Mon, 9 Jan 2012 20:33:54 +0000 (21:33 +0100)]
s3: Remove an unused label

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Mon Jan  9 23:07:32 CET 2012 on sn-devel-104

12 years agos4:scripting/devel: add repl_cleartext_pwd.py script
Stefan Metzmacher [Thu, 15 Dec 2011 15:28:08 +0000 (16:28 +0100)]
s4:scripting/devel: add repl_cleartext_pwd.py script

This is useful to sync passwords from an AD domain.

 $
 $ source4/scripting/devel/repl_cleartext_pwd.py \
  -Uadministrator%A1b2C3d4 \
  172.31.9.219 DC=bla,DC=base /tmp/cookie cleartext_utf8 131085 displayName
 # starting at usn[0]
 dn: CN=Test User1,CN=Users,DC=bla,DC=base
 cleartext_utf8: A1b2C3d4
 displayName:: VABlAHMAdAAgAFUAcwBlAHIAMQA=

 # up to usn[16449]
 $
 $ source4/scripting/devel/repl_cleartext_pwd.py \
  -Uadministrator%A1b2C3d4
  172.31.9.219 DC=bla,DC=base /tmp/cookie cleartext_utf8 131085 displayName
 # starting at usn[16449]
 # up to usn[16449]
 $

metze

Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Mon Jan  9 19:06:06 CET 2012 on sn-devel-104

12 years agos4-kerberos: remove some unused prototypes.
Günther Deschner [Mon, 9 Jan 2012 11:51:08 +0000 (12:51 +0100)]
s4-kerberos: remove some unused prototypes.

These are defined in the krb5 abstraction headers elsewhere.

Guenther

Autobuild-User: Günther Deschner <gd@samba.org>
Autobuild-Date: Mon Jan  9 14:32:08 CET 2012 on sn-devel-104

12 years agos3-waf: rpcclient does not need libads.so.
Günther Deschner [Fri, 6 Jan 2012 16:50:50 +0000 (17:50 +0100)]
s3-waf: rpcclient does not need libads.so.

Guenther

Autobuild-User: Günther Deschner <gd@samba.org>
Autobuild-Date: Mon Jan  9 12:06:06 CET 2012 on sn-devel-104

12 years agos3-passdb: remove a forward declaration.
Günther Deschner [Fri, 6 Jan 2012 16:49:31 +0000 (17:49 +0100)]
s3-passdb: remove a forward declaration.

Guenther

12 years agos3-libads: pretty print a keytab list.
Günther Deschner [Fri, 6 Jan 2012 16:48:58 +0000 (17:48 +0100)]
s3-libads: pretty print a keytab list.

Guenther

12 years agos3-pdbtest: only test trusted domains when pdb backends offers trusted domain support.
Günther Deschner [Fri, 6 Jan 2012 16:27:03 +0000 (17:27 +0100)]
s3-pdbtest: only test trusted domains when pdb backends offers trusted domain support.

Guenther

12 years agos3-libads: fix malloc/talloc mismatch in ads_keytab_verify_ticket().
Günther Deschner [Fri, 6 Jan 2012 15:10:55 +0000 (16:10 +0100)]
s3-libads: fix malloc/talloc mismatch in ads_keytab_verify_ticket().

Guenther

12 years agos4:python/samba/ndr.py: add an optional 'allow_remaining' to ndr_unpack()
Stefan Metzmacher [Thu, 5 Jan 2012 15:34:02 +0000 (16:34 +0100)]
s4:python/samba/ndr.py: add an optional 'allow_remaining' to ndr_unpack()

metze

Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Mon Jan  9 10:28:30 CET 2012 on sn-devel-104

12 years agopidl:Samba4/Python: add an optional 'allow_remaining' argument to __ndr_unpack__...
Stefan Metzmacher [Thu, 5 Jan 2012 15:33:13 +0000 (16:33 +0100)]
pidl:Samba4/Python: add an optional 'allow_remaining' argument to __ndr_unpack__() hooks

Thanks to Amitay Isaacs <amitay@gmail.com> for the help with this.

metze

12 years agos3-build: Remove unused hooks to set smbtorture4 and test args
Andrew Bartlett [Mon, 9 Jan 2012 02:59:48 +0000 (13:59 +1100)]
s3-build: Remove unused hooks to set smbtorture4 and test args

These were left around after the selftest.pl script was introduced.

Andrew Bartlett

Autobuild-User: Andrew Bartlett <abartlet@samba.org>
Autobuild-Date: Mon Jan  9 06:13:21 CET 2012 on sn-devel-104

12 years agoauth/credentials Remove debug that prints in normal operation
Andrew Bartlett [Mon, 9 Jan 2012 00:52:54 +0000 (11:52 +1100)]
auth/credentials Remove debug that prints in normal operation

The fact that this function is unimplemented is unimportant to the callers
as credential caches are not handled via the auth/credentials code in s3.

Andrew Bartlett

Autobuild-User: Andrew Bartlett <abartlet@samba.org>
Autobuild-Date: Mon Jan  9 03:24:36 CET 2012 on sn-devel-104

12 years agos3-libsmb: Do not look up FQDN or use host/ for krb5 encrypted CIFS
Andrew Bartlett [Mon, 9 Jan 2012 00:19:33 +0000 (11:19 +1100)]
s3-libsmb: Do not look up FQDN or use host/ for krb5 encrypted CIFS

This is important, as we want to use exactly the same name and ticket
that the libsmb session setup code used, so we do not hit the KDC twice.

For the session setup to have succeded using the default 'client use
spnego principal = no', the cifs/ principal must exist anyway, so
looking for host/ is pointless.  The case of 'client use spnego
principal = yes' was never supported here.

Andrew Bartlett

12 years agos3-sefltest Make krb5 tests contain the word krb5
Andrew Bartlett [Sun, 8 Jan 2012 23:50:14 +0000 (10:50 +1100)]
s3-sefltest Make krb5 tests contain the word krb5

12 years agos3-selftst Add encrypted CIFS testing with kerberos
Andrew Bartlett [Sun, 8 Jan 2012 23:49:49 +0000 (10:49 +1100)]
s3-selftst Add encrypted CIFS testing with kerberos

12 years agos3-libsmb: match the rest of Samba3 in kerberos name selection in smb sealing
Andrew Bartlett [Sun, 8 Jan 2012 23:30:47 +0000 (10:30 +1100)]
s3-libsmb: match the rest of Samba3 in kerberos name selection in smb sealing

This mirrors 860ad734ba77238d187520f72afcbdc1c73d94ef which in turn
mirrors the behaviour of the libsmb client code at session setup time.

Andrew Bartlett

12 years agos3-selftest: Add test for smbclient kerberos support
Andrew Bartlett [Sun, 8 Jan 2012 23:18:37 +0000 (10:18 +1100)]
s3-selftest: Add test for smbclient kerberos support

12 years agos3-build SMBTORTRUE4 variable is unused in make test
Andrew Bartlett [Fri, 6 Jan 2012 08:16:32 +0000 (19:16 +1100)]
s3-build SMBTORTRUE4 variable is unused in make test

12 years agos3-build SAMBA4SHAREDIR is unused in make test
Andrew Bartlett [Fri, 6 Jan 2012 08:14:33 +0000 (19:14 +1100)]
s3-build SAMBA4SHAREDIR is unused in make test

12 years agos3-build: smbtorture4 can be built regardless of use_ads
Andrew Bartlett [Fri, 6 Jan 2012 08:12:08 +0000 (19:12 +1100)]
s3-build: smbtorture4 can be built regardless of use_ads

12 years agos3-selftest: remove smb4torture_possible and add have_ads_support
Andrew Bartlett [Sun, 8 Jan 2012 22:47:47 +0000 (09:47 +1100)]
s3-selftest: remove smb4torture_possible and add have_ads_support

The smb4torture_possible check has already been hidden in
plansmbtorturetestsuite to reduce extra complexity and indentation.

The have_ads_support check will allow ADS tests to be run when we
do not have the ability to run smbtorture4

Andrew Bartlett

12 years agos3-selftest Hide smb4torture_possible inside plansmbtorturetestsuite()
Andrew Bartlett [Sun, 8 Jan 2012 22:26:57 +0000 (09:26 +1100)]
s3-selftest Hide smb4torture_possible inside plansmbtorturetestsuite()

12 years agoAdd "repack" command to tdbtool.
Ira Cooper [Fri, 6 Jan 2012 23:45:06 +0000 (15:45 -0800)]
Add "repack" command to tdbtool.

Autobuild-User: Jeremy Allison <jra@samba.org>
Autobuild-Date: Sat Jan  7 02:18:41 CET 2012 on sn-devel-104

12 years agoRemove the commented out code.
Jeremy Allison [Fri, 6 Jan 2012 22:56:36 +0000 (14:56 -0800)]
Remove the commented out code.

12 years agoComment out sys_get_number_of_cores() as we're no longer using this.
Jeremy Allison [Fri, 6 Jan 2012 22:55:30 +0000 (14:55 -0800)]
Comment out sys_get_number_of_cores() as we're no longer using this.

12 years agoAdd "aio num threads" parameter to allow manual configuration of
Jeremy Allison [Fri, 6 Jan 2012 22:33:56 +0000 (14:33 -0800)]
Add "aio num threads" parameter to allow manual configuration of
threads via smb.conf if required. Ignore the number of cores. See
comments inline.

12 years agoFix format warning message.
Jeremy Allison [Fri, 6 Jan 2012 22:25:06 +0000 (14:25 -0800)]
Fix format warning message.

12 years agos3: Avoid a potential alignment requirement issue
Volker Lendecke [Fri, 6 Jan 2012 15:42:08 +0000 (16:42 +0100)]
s3: Avoid a potential alignment requirement issue

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Fri Jan  6 18:58:11 CET 2012 on sn-devel-104

12 years agos3: Avoid a potential alignment requirement issue
Volker Lendecke [Fri, 6 Jan 2012 15:38:44 +0000 (16:38 +0100)]
s3: Avoid a potential alignment requirement issue

12 years agos3: Use DELETE_ON_CLOSE instead of unlink
Volker Lendecke [Fri, 6 Jan 2012 13:28:55 +0000 (14:28 +0100)]
s3: Use DELETE_ON_CLOSE instead of unlink

12 years agos3: No value change, just use the correct enum value
Volker Lendecke [Fri, 6 Jan 2012 13:21:37 +0000 (14:21 +0100)]
s3: No value change, just use the correct enum value

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Fri Jan  6 16:33:42 CET 2012 on sn-devel-104

12 years agos3-ntlmssp Remove unused ntlmssp_set_hashes() and do not set an invalid LM hash
Andrew Bartlett [Tue, 27 Dec 2011 08:39:32 +0000 (19:39 +1100)]
s3-ntlmssp Remove unused ntlmssp_set_hashes() and do not set an invalid LM hash

When E_deshash() returns false, it indicates that the password is either > 14 chars
in length, or could not be represented as an LM hash value for some other
reason.  In this case, we should not regard the LM hash being missing
as an error or a no-password situation.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Fri Jan  6 14:59:13 CET 2012 on sn-devel-104

12 years agontlmssp: merge initial packet implementations
Andrew Bartlett [Tue, 27 Dec 2011 08:16:14 +0000 (19:16 +1100)]
ntlmssp: merge initial packet implementations

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-winbindd: convert cached credentials to use auth_generic/gensec for NTLMSSP
Andrew Bartlett [Tue, 27 Dec 2011 03:59:17 +0000 (14:59 +1100)]
s3-winbindd: convert cached credentials to use auth_generic/gensec for NTLMSSP

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-torture convert smb2 test to use auth_generic/gensec for NTLMSSP
Andrew Bartlett [Tue, 27 Dec 2011 02:27:45 +0000 (13:27 +1100)]
s3-torture convert smb2 test to use auth_generic/gensec for NTLMSSP

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Fri Jan  6 12:09:12 CET 2012 on sn-devel-104

12 years agos3:SMB2-SESSION-RECONNECT: also expect NETWORK_NAME_DELETED is signing isn't used
Stefan Metzmacher [Fri, 6 Jan 2012 07:31:16 +0000 (08:31 +0100)]
s3:SMB2-SESSION-RECONNECT: also expect NETWORK_NAME_DELETED is signing isn't used

metze

12 years agos3-libads Use NTLMSSP via auth_generic/gensec
Andrew Bartlett [Tue, 27 Dec 2011 01:27:11 +0000 (12:27 +1100)]
s3-libads Use NTLMSSP via auth_generic/gensec

This allows us to use the shared gensec_wrap() implementation already used by the
smb sealing code, as well as making this code more generic.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-libsmb Make auth_ntlmssp client more generic
Andrew Bartlett [Mon, 26 Dec 2011 23:25:55 +0000 (10:25 +1100)]
s3-libsmb Make auth_ntlmssp client more generic

As well as renaming, this allows us to start the mech by DCE/RPC auth
type or OID.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-libsmb Use gensec_settings to set s3 ntlmssp client backend
Andrew Bartlett [Mon, 26 Dec 2011 23:33:36 +0000 (10:33 +1100)]
s3-libsmb Use gensec_settings to set s3 ntlmssp client backend

This prepares us for making the code generic to multiple mechansims

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth Rename make_auth_ntlmssp() -> make_auth_gensec()
Andrew Bartlett [Mon, 26 Dec 2011 04:58:11 +0000 (15:58 +1100)]
s3-auth Rename make_auth_ntlmssp() -> make_auth_gensec()

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agoFix compile when TDB_TRACE is enabled.
Ira Cooper [Fri, 6 Jan 2012 01:13:27 +0000 (17:13 -0800)]
Fix compile when TDB_TRACE is enabled.

Autobuild-User: Jeremy Allison <jra@samba.org>
Autobuild-Date: Fri Jan  6 04:16:41 CET 2012 on sn-devel-104

12 years agoAdd a sys_get_number_of_cores() function that calls sysconf or sysctl
Jeremy Allison [Thu, 5 Jan 2012 23:48:24 +0000 (15:48 -0800)]
Add a sys_get_number_of_cores() function that calls sysconf or sysctl
and tunes the aio threads.

12 years agosamba-tool:dns: Check through all the DNS records for a match
Amitay Isaacs [Thu, 5 Jan 2012 23:28:52 +0000 (10:28 +1100)]
samba-tool:dns: Check through all the DNS records for a match

There can be multiple dns records for a specified record type.

Autobuild-User: Amitay Isaacs <amitay@samba.org>
Autobuild-Date: Fri Jan  6 02:41:22 CET 2012 on sn-devel-104

12 years agos4-rpc:dnsserver: Do not replace @ with zone_name in update operation
Amitay Isaacs [Thu, 5 Jan 2012 22:26:49 +0000 (09:26 +1100)]
s4-rpc:dnsserver: Do not replace @ with zone_name in update operation

This fixes the problem when updating DNS record for '@' or domain name.

12 years agoFix bug #8687 - net memberships usage info is wrong
Jeremy Allison [Thu, 5 Jan 2012 21:54:29 +0000 (13:54 -0800)]
Fix bug #8687 - net memberships usage info is wrong

Typo in usage.

Autobuild-User: Jeremy Allison <jra@samba.org>
Autobuild-Date: Fri Jan  6 00:30:20 CET 2012 on sn-devel-104

12 years agoFix the local-memcache test for 64-bit
Volker Lendecke [Thu, 5 Jan 2012 12:12:26 +0000 (13:12 +0100)]
Fix the local-memcache test for 64-bit

The memcache test walks the purge functionality. The maximum memcache size also
takes all memcache internal headers into account. Those headers contain
pointers, so on 64-bit they take more space...

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Thu Jan  5 22:01:00 CET 2012 on sn-devel-104

12 years agos3: Run the CLEANUP2 test
Volker Lendecke [Thu, 5 Jan 2012 16:47:16 +0000 (17:47 +0100)]
s3: Run the CLEANUP2 test

12 years agos3: Add a test for proper brlock cleanup
Volker Lendecke [Thu, 5 Jan 2012 16:44:44 +0000 (17:44 +0100)]
s3: Add a test for proper brlock cleanup

We need to improve the server here.

Maybe we should validate the brlock entry whenever we detect a read/write being
blocked from locking? This is not our hot code path anyway, and it would gain
us significant robustness. The code might become quite a bit simpler as well.

12 years agos3: Clarify what CLEANUP1 does
Volker Lendecke [Thu, 5 Jan 2012 14:46:22 +0000 (15:46 +0100)]
s3: Clarify what CLEANUP1 does

12 years agoAdd some debug to vfs_aio_pthread so I can see when jobs start and stop.
Jeremy Allison [Thu, 5 Jan 2012 01:02:21 +0000 (17:02 -0800)]
Add some debug to vfs_aio_pthread so I can see when jobs start and stop.

Autobuild-User: Jeremy Allison <jra@samba.org>
Autobuild-Date: Thu Jan  5 20:28:00 CET 2012 on sn-devel-104

12 years agos3-auth remove outdated comment
Andrew Bartlett [Mon, 26 Dec 2011 04:52:59 +0000 (15:52 +1100)]
s3-auth remove outdated comment

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Thu Jan  5 18:51:47 CET 2012 on sn-devel-104

12 years agos3-librpc remove unused headers
Andrew Bartlett [Mon, 26 Dec 2011 04:21:23 +0000 (15:21 +1100)]
s3-librpc remove unused headers

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth Remove more unused headers
Andrew Bartlett [Mon, 26 Dec 2011 04:02:50 +0000 (15:02 +1100)]
s3-auth Remove more unused headers

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth remove unused ntlmssp.h
Andrew Bartlett [Mon, 26 Dec 2011 04:01:41 +0000 (15:01 +1100)]
s3-auth remove unused ntlmssp.h

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth Remove ntlmssp_wrap.h which is no longer required
Andrew Bartlett [Mon, 26 Dec 2011 03:57:02 +0000 (14:57 +1100)]
s3-auth Remove ntlmssp_wrap.h which is no longer required

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth use gensec directly rather than via auth_generic_state
Andrew Bartlett [Mon, 26 Dec 2011 03:23:15 +0000 (14:23 +1100)]
s3-auth use gensec directly rather than via auth_generic_state

This is possible because the s3 gensec modules are started as
normal gensec modules, so we do not need a wrapper any more.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth Set remote address for both AD and s3 gensec modes
Andrew Bartlett [Mon, 26 Dec 2011 02:42:37 +0000 (13:42 +1100)]
s3-auth Set remote address for both AD and s3 gensec modes

12 years agos3-auth re-create the auth context in the s3 ntlmssp server module
Andrew Bartlett [Mon, 26 Dec 2011 01:26:43 +0000 (12:26 +1100)]
s3-auth re-create the auth context in the s3 ntlmssp server module

This removes the abstraction violation in auth_generic.c.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth Add TALLOC_CTX * to auth_generic_prepare()
Andrew Bartlett [Mon, 26 Dec 2011 01:13:21 +0000 (12:13 +1100)]
s3-auth Add TALLOC_CTX * to auth_generic_prepare()

This makes the long term owner of this memory more clear.  So far only the
clear cases have been moved from NULL however.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-auth supply s3 ntlmssp module via gensec_settings
Andrew Bartlett [Mon, 26 Dec 2011 00:39:29 +0000 (11:39 +1100)]
s3-auth supply s3 ntlmssp module via gensec_settings

This will allow the supply of multiple modules in future
without duplicating the module selection logic.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-selftest: Add test for rpcclient, including kerberos authentication
Andrew Bartlett [Tue, 3 Jan 2012 04:57:40 +0000 (15:57 +1100)]
s3-selftest: Add test for rpcclient, including kerberos authentication

Some knownfail entries are added for things the currently fail.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3:gse: MIT krb5 1.8.1 has a bug in gss_wrap_iov()
Stefan Metzmacher [Thu, 5 Jan 2012 13:59:20 +0000 (14:59 +0100)]
s3:gse: MIT krb5 1.8.1 has a bug in gss_wrap_iov()

gss_krb5int_make_seal_token_v3_iov() doesn't set '*conf_state'.

metze

12 years agos3-librpc store the sign/seal flags we got in the gssapi client
Andrew Bartlett [Tue, 3 Jan 2012 04:48:01 +0000 (15:48 +1100)]
s3-librpc store the sign/seal flags we got in the gssapi client

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-libads Factor out a new routine kerberos_get_principal_from_service_hostname()
Andrew Bartlett [Wed, 4 Jan 2012 00:39:38 +0000 (11:39 +1100)]
s3-libads Factor out a new routine kerberos_get_principal_from_service_hostname()

This is now used in the GSE GSSAPI client, so that when we connect to
a target server at the CIFS level, we use the same name to connect
at the DCE/RPC level.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3-librpc Use gsskrb5_get_subkey() where available to get the session key
Andrew Bartlett [Mon, 2 Jan 2012 11:17:06 +0000 (22:17 +1100)]
s3-librpc Use gsskrb5_get_subkey() where available to get the session key

This allows gse_get_session_key() to work against Heimdal.

Andrew Bartlett

Signed-off-by: Stefan Metzmacher <metze@samba.org>
12 years agos3: Remove some redundant code
Volker Lendecke [Thu, 5 Jan 2012 14:41:50 +0000 (15:41 +0100)]
s3: Remove some redundant code

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Thu Jan  5 17:16:45 CET 2012 on sn-devel-104

12 years agos3: Run the CLEANUP1 test
Volker Lendecke [Thu, 5 Jan 2012 11:25:39 +0000 (12:25 +0100)]
s3: Run the CLEANUP1 test

Autobuild-User: Volker Lendecke <vlendec@samba.org>
Autobuild-Date: Thu Jan  5 14:42:43 CET 2012 on sn-devel-104

12 years agos3: Add a test excercising the share mode cleanup routine
Volker Lendecke [Thu, 5 Jan 2012 08:23:42 +0000 (09:23 +0100)]
s3: Add a test excercising the share mode cleanup routine

12 years agolibcli/smb: Add smbXcli_conn_samba_suicide
Volker Lendecke [Wed, 4 Jan 2012 12:28:07 +0000 (13:28 +0100)]
libcli/smb: Add smbXcli_conn_samba_suicide

This is a pure test tool against Samba servers

12 years agos3: Move basic SMB checking to a much earlier point
Volker Lendecke [Thu, 5 Jan 2012 10:58:17 +0000 (11:58 +0100)]
s3: Move basic SMB checking to a much earlier point

12 years agos3: Add a suicide mode to smbd
Volker Lendecke [Tue, 3 Jan 2012 21:30:09 +0000 (22:30 +0100)]
s3: Add a suicide mode to smbd

To test our cleanup code paths properly, we need a way to make smbd exit hard
without cleaning up

12 years agos3: Fix some nonempty blank lines
Volker Lendecke [Mon, 2 Jan 2012 12:06:10 +0000 (13:06 +0100)]
s3: Fix some nonempty blank lines

12 years agos4:repl_meta_data LDB module - set "isRecycled" time correctly
Matthias Dieter Wallnöfer [Wed, 4 Jan 2012 15:17:24 +0000 (16:17 +0100)]
s4:repl_meta_data LDB module - set "isRecycled" time correctly

"unix_to_nt_time()" which is based on "time_t" behaves differently for
literals > 32 bit on 32 and 64 bit platforms.

Reviewed-by: ekacnet
Autobuild-User: Matthias Dieter Wallnöfer <mdw@samba.org>
Autobuild-Date: Thu Jan  5 11:59:20 CET 2012 on sn-devel-104

12 years agoAdd S3 vfs_aio_pthread module to replace broken glibc aio code.
Jeremy Allison [Wed, 4 Jan 2012 20:54:16 +0000 (12:54 -0800)]
Add S3 vfs_aio_pthread module to replace broken glibc aio code.

Compiles but not yet tested.

Autobuild-User: Jeremy Allison <jra@samba.org>
Autobuild-Date: Thu Jan  5 01:43:51 CET 2012 on sn-devel-104

12 years agowaf: Use git repository.
Jelmer Vernooij [Wed, 4 Jan 2012 20:00:42 +0000 (21:00 +0100)]
waf: Use git repository.

Autobuild-User: Jelmer Vernooij <jelmer@samba.org>
Autobuild-Date: Thu Jan  5 00:10:24 CET 2012 on sn-devel-104

12 years agoInclude waf as an extracted source directory, rather than as a one-in-a-file script.
Jelmer Vernooij [Tue, 3 Jan 2012 23:31:27 +0000 (00:31 +0100)]
Include waf as an extracted source directory, rather than as a one-in-a-file script.

12 years agos4:pyrpc: add 'user_session_key' getter to the connection object
Stefan Metzmacher [Fri, 16 Dec 2011 09:55:46 +0000 (10:55 +0100)]
s4:pyrpc: add 'user_session_key' getter to the connection object

This gets the session key from gensec for usage in DRSUAPI.

metze

Autobuild-User: Stefan Metzmacher <metze@samba.org>
Autobuild-Date: Wed Jan  4 22:31:52 CET 2012 on sn-devel-104

12 years agos4:pygensec/tests: check that the client and server have the same session key
Stefan Metzmacher [Wed, 4 Jan 2012 19:49:08 +0000 (20:49 +0100)]
s4:pygensec/tests: check that the client and server have the same session key

metze

12 years agos4:pygensec: add session_key() method
Stefan Metzmacher [Fri, 16 Dec 2011 09:37:51 +0000 (10:37 +0100)]
s4:pygensec: add session_key() method

metze