r21826: reorder functions
[ira/wip.git] / source4 / libnet / libnet_unbecome_dc.c
1 /*
2    Unix SMB/CIFS implementation.
3
4    Copyright (C) Stefan Metzmacher      2006
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 2 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program; if not, write to the Free Software
18    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
19 */
20
21 #include "includes.h"
22 #include "libnet/libnet.h"
23 #include "libcli/composite/composite.h"
24 #include "libcli/cldap/cldap.h"
25 #include "lib/ldb/include/ldb.h"
26 #include "lib/ldb/include/ldb_errors.h"
27 #include "lib/db_wrap.h"
28 #include "dsdb/samdb/samdb.h"
29 #include "dsdb/common/flags.h"
30 #include "librpc/gen_ndr/ndr_drsuapi_c.h"
31
32 struct libnet_UnbecomeDC_state {
33         struct composite_context *creq;
34
35         struct libnet_context *libnet;
36
37         struct {
38                 struct cldap_socket *sock;
39                 struct cldap_netlogon io;
40                 struct nbt_cldap_netlogon_5 netlogon5;
41         } cldap;
42
43         struct {
44                 struct ldb_context *ldb;
45         } ldap;
46
47         struct {
48                 struct dcerpc_binding *binding;
49                 struct dcerpc_pipe *pipe;
50                 struct drsuapi_DsBind bind_r;
51                 struct GUID bind_guid;
52                 struct drsuapi_DsBindInfoCtr bind_info_ctr;
53                 struct drsuapi_DsBindInfo28 local_info28;
54                 struct drsuapi_DsBindInfo28 remote_info28;
55                 struct policy_handle bind_handle;
56                 struct drsuapi_DsRemoveDSServer rm_ds_srv_r;
57         } drsuapi;
58
59         struct {
60                 /* input */
61                 const char *dns_name;
62                 const char *netbios_name;
63
64                 /* constructed */
65                 struct GUID guid;
66                 const char *dn_str;
67         } domain;
68
69         struct {
70                 /* constructed */
71                 const char *config_dn_str;
72         } forest;
73
74         struct {
75                 /* input */
76                 const char *address;
77
78                 /* constructed */
79                 const char *dns_name;
80                 const char *netbios_name;
81                 const char *site_name;
82         } source_dsa;
83
84         struct {
85                 /* input */
86                 const char *netbios_name;
87
88                 /* constructed */
89                 const char *dns_name;
90                 const char *site_name;
91                 const char *computer_dn_str;
92                 const char *server_dn_str;
93                 uint32_t user_account_control;
94         } dest_dsa;
95 };
96
97 static void unbecomeDC_recv_cldap(struct cldap_request *req);
98
99 static void unbecomeDC_send_cldap(struct libnet_UnbecomeDC_state *s)
100 {
101         struct composite_context *c = s->creq;
102         struct cldap_request *req;
103
104         s->cldap.io.in.dest_address     = s->source_dsa.address;
105         s->cldap.io.in.realm            = s->domain.dns_name;
106         s->cldap.io.in.host             = s->dest_dsa.netbios_name;
107         s->cldap.io.in.user             = NULL;
108         s->cldap.io.in.domain_guid      = NULL;
109         s->cldap.io.in.domain_sid       = NULL;
110         s->cldap.io.in.acct_control     = -1;
111         s->cldap.io.in.version          = 6;
112
113         s->cldap.sock = cldap_socket_init(s, s->libnet->event_ctx);
114         if (composite_nomem(s->cldap.sock, c)) return;
115
116         req = cldap_netlogon_send(s->cldap.sock, &s->cldap.io);
117         if (composite_nomem(req, c)) return;
118         req->async.fn           = unbecomeDC_recv_cldap;
119         req->async.private      = s;
120 }
121
122 static void unbecomeDC_connect_ldap(struct libnet_UnbecomeDC_state *s);
123
124 static void unbecomeDC_recv_cldap(struct cldap_request *req)
125 {
126         struct libnet_UnbecomeDC_state *s = talloc_get_type(req->async.private,
127                                             struct libnet_UnbecomeDC_state);
128         struct composite_context *c = s->creq;
129
130         c->status = cldap_netlogon_recv(req, s, &s->cldap.io);
131         if (!composite_is_ok(c)) return;
132
133         s->cldap.netlogon5 = s->cldap.io.out.netlogon.logon5;
134
135         s->domain.dns_name              = s->cldap.netlogon5.dns_domain;
136         s->domain.netbios_name          = s->cldap.netlogon5.domain;
137         s->domain.guid                  = s->cldap.netlogon5.domain_uuid;
138
139         s->source_dsa.dns_name          = s->cldap.netlogon5.pdc_dns_name;
140         s->source_dsa.netbios_name      = s->cldap.netlogon5.pdc_name;
141         s->source_dsa.site_name         = s->cldap.netlogon5.server_site;
142
143         s->dest_dsa.site_name           = s->cldap.netlogon5.client_site;
144
145         unbecomeDC_connect_ldap(s);
146 }
147
148 static NTSTATUS unbecomeDC_ldap_connect(struct libnet_UnbecomeDC_state *s)
149 {
150         char *url;
151
152         url = talloc_asprintf(s, "ldap://%s/", s->source_dsa.dns_name);
153         NT_STATUS_HAVE_NO_MEMORY(url);
154
155         s->ldap.ldb = ldb_wrap_connect(s, url,
156                                        NULL,
157                                        s->libnet->cred,
158                                        0, NULL);
159         talloc_free(url);
160         if (s->ldap.ldb == NULL) {
161                 return NT_STATUS_UNEXPECTED_NETWORK_ERROR;
162         }
163
164         return NT_STATUS_OK;
165 }
166
167 static NTSTATUS unbecomeDC_ldap_rootdse(struct libnet_UnbecomeDC_state *s)
168 {
169         int ret;
170         struct ldb_result *r;
171         struct ldb_dn *basedn;
172         static const char *attrs[] = {
173                 "defaultNamingContext",
174                 "configurationNamingContext",
175                 NULL
176         };
177
178         basedn = ldb_dn_new(s, s->ldap.ldb, NULL);
179         NT_STATUS_HAVE_NO_MEMORY(basedn);
180
181         ret = ldb_search(s->ldap.ldb, basedn, LDB_SCOPE_BASE, 
182                          "(objectClass=*)", attrs, &r);
183         talloc_free(basedn);
184         if (ret != LDB_SUCCESS) {
185                 return NT_STATUS_LDAP(ret);
186         } else if (r->count != 1) {
187                 talloc_free(r);
188                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
189         }
190         talloc_steal(s, r);
191
192         s->domain.dn_str        = ldb_msg_find_attr_as_string(r->msgs[0], "defaultNamingContext", NULL);
193         if (!s->domain.dn_str) return NT_STATUS_INVALID_NETWORK_RESPONSE;
194         talloc_steal(s, s->domain.dn_str);
195
196         s->forest.config_dn_str = ldb_msg_find_attr_as_string(r->msgs[0], "configurationNamingContext", NULL);
197         if (!s->forest.config_dn_str) return NT_STATUS_INVALID_NETWORK_RESPONSE;
198         talloc_steal(s, s->forest.config_dn_str);
199
200         s->dest_dsa.server_dn_str = talloc_asprintf(s, "CN=%s,CN=Servers,CN=%s,CN=Sites,%s",
201                                                     s->dest_dsa.netbios_name,
202                                                     s->dest_dsa.site_name,
203                                                     s->forest.config_dn_str);
204         NT_STATUS_HAVE_NO_MEMORY(s->dest_dsa.server_dn_str);
205
206         talloc_free(r);
207         return NT_STATUS_OK;
208 }
209
210 static NTSTATUS unbecomeDC_ldap_computer_object(struct libnet_UnbecomeDC_state *s)
211 {
212         int ret;
213         struct ldb_result *r;
214         struct ldb_dn *basedn;
215         char *filter;
216         static const char *attrs[] = {
217                 "distinguishedName",
218                 "userAccountControl",
219                 NULL
220         };
221
222         basedn = ldb_dn_new(s, s->ldap.ldb, s->domain.dn_str);
223         NT_STATUS_HAVE_NO_MEMORY(basedn);
224
225         filter = talloc_asprintf(basedn, "(&(|(objectClass=user)(objectClass=computer))(sAMAccountName=%s$))",
226                                  s->dest_dsa.netbios_name);
227         NT_STATUS_HAVE_NO_MEMORY(filter);
228
229         ret = ldb_search(s->ldap.ldb, basedn, LDB_SCOPE_SUBTREE, 
230                          filter, attrs, &r);
231         talloc_free(basedn);
232         if (ret != LDB_SUCCESS) {
233                 return NT_STATUS_LDAP(ret);
234         } else if (r->count != 1) {
235                 talloc_free(r);
236                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
237         }
238
239         s->dest_dsa.computer_dn_str     = samdb_result_string(r->msgs[0], "distinguishedName", NULL);
240         if (!s->dest_dsa.computer_dn_str) return NT_STATUS_INVALID_NETWORK_RESPONSE;
241         talloc_steal(s, s->dest_dsa.computer_dn_str);
242
243         s->dest_dsa.user_account_control = samdb_result_uint(r->msgs[0], "userAccountControl", 0);
244
245         talloc_free(r);
246         return NT_STATUS_OK;
247 }
248
249 static NTSTATUS unbecomeDC_ldap_modify_computer(struct libnet_UnbecomeDC_state *s)
250 {
251         int ret;
252         struct ldb_message *msg;
253         uint32_t user_account_control = UF_WORKSTATION_TRUST_ACCOUNT;
254         uint32_t i;
255
256         /* as the value is already as we want it to be, we're done */
257         if (s->dest_dsa.user_account_control == user_account_control) {
258                 return NT_STATUS_OK;
259         }
260
261         /* make a 'modify' msg, and only for serverReference */
262         msg = ldb_msg_new(s);
263         NT_STATUS_HAVE_NO_MEMORY(msg);
264         msg->dn = ldb_dn_new(msg, s->ldap.ldb, s->dest_dsa.computer_dn_str);
265         NT_STATUS_HAVE_NO_MEMORY(msg->dn);
266
267         ret = ldb_msg_add_fmt(msg, "userAccountControl", "%u", user_account_control);
268         if (ret != 0) {
269                 talloc_free(msg);
270                 return NT_STATUS_NO_MEMORY;
271         }
272
273         /* mark all the message elements (should be just one)
274            as LDB_FLAG_MOD_REPLACE */
275         for (i=0;i<msg->num_elements;i++) {
276                 msg->elements[i].flags = LDB_FLAG_MOD_REPLACE;
277         }
278
279         ret = ldb_modify(s->ldap.ldb, msg);
280         talloc_free(msg);
281         if (ret != LDB_SUCCESS) {
282                 return NT_STATUS_LDAP(ret);
283         }
284
285         s->dest_dsa.user_account_control = user_account_control;
286
287         return NT_STATUS_OK;
288 }
289
290 static NTSTATUS unbecomeDC_ldap_move_computer(struct libnet_UnbecomeDC_state *s)
291 {
292         int ret;
293         struct ldb_result *r;
294         struct ldb_dn *basedn;
295         struct ldb_dn *old_dn;
296         struct ldb_dn *new_dn;
297         static const char *_1_1_attrs[] = {
298                 "1.1",
299                 NULL
300         };
301
302         basedn = ldb_dn_new_fmt(s, s->ldap.ldb, "<WKGUID=aa312825768811d1aded00c04fd8d5cd,%s>",
303                                 s->domain.dn_str);
304         NT_STATUS_HAVE_NO_MEMORY(basedn);
305
306         ret = ldb_search(s->ldap.ldb, basedn, LDB_SCOPE_BASE,
307                          "(objectClass=*)", _1_1_attrs, &r);
308         talloc_free(basedn);
309         if (ret != LDB_SUCCESS) {
310                 return NT_STATUS_LDAP(ret);
311         } else if (r->count != 1) {
312                 talloc_free(r);
313                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
314         }
315
316         old_dn = ldb_dn_new(r, s->ldap.ldb, s->dest_dsa.computer_dn_str);
317         NT_STATUS_HAVE_NO_MEMORY(old_dn);
318
319         new_dn = r->msgs[0]->dn;
320
321         if (!ldb_dn_add_child_fmt(new_dn, "CN=%s", s->dest_dsa.netbios_name)) {
322                 talloc_free(r);
323                 return NT_STATUS_NO_MEMORY;
324         }
325
326         if (ldb_dn_compare(old_dn, new_dn) == 0) {
327                 /* we don't need to rename if the old and new dn match */
328                 talloc_free(r);
329                 return NT_STATUS_OK;
330         }
331
332         ret = ldb_rename(s->ldap.ldb, old_dn, new_dn);
333         if (ret != LDB_SUCCESS) {
334                 talloc_free(r);
335                 return NT_STATUS_LDAP(ret);
336         }
337
338         s->dest_dsa.computer_dn_str = ldb_dn_alloc_linearized(s, new_dn);
339         NT_STATUS_HAVE_NO_MEMORY(s->dest_dsa.computer_dn_str);
340
341         talloc_free(r);
342
343         return NT_STATUS_OK;
344 }
345
346 static void unbecomeDC_drsuapi_connect_send(struct libnet_UnbecomeDC_state *s);
347
348 static void unbecomeDC_connect_ldap(struct libnet_UnbecomeDC_state *s)
349 {
350         struct composite_context *c = s->creq;
351
352         c->status = unbecomeDC_ldap_connect(s);
353         if (!composite_is_ok(c)) return;
354
355         c->status = unbecomeDC_ldap_rootdse(s);
356         if (!composite_is_ok(c)) return;
357
358         c->status = unbecomeDC_ldap_computer_object(s);
359         if (!composite_is_ok(c)) return;
360
361         c->status = unbecomeDC_ldap_modify_computer(s);
362         if (!composite_is_ok(c)) return;
363
364         c->status = unbecomeDC_ldap_move_computer(s);
365         if (!composite_is_ok(c)) return;
366
367         unbecomeDC_drsuapi_connect_send(s);
368 }
369
370 static void unbecomeDC_drsuapi_connect_recv(struct composite_context *creq);
371
372 static void unbecomeDC_drsuapi_connect_send(struct libnet_UnbecomeDC_state *s)
373 {
374         struct composite_context *c = s->creq;
375         struct composite_context *creq;
376         char *binding_str;
377
378         binding_str = talloc_asprintf(s, "ncacn_ip_tcp:%s[seal]", s->source_dsa.dns_name);
379         if (composite_nomem(binding_str, c)) return;
380
381         c->status = dcerpc_parse_binding(s, binding_str, &s->drsuapi.binding);
382         talloc_free(binding_str);
383         if (!composite_is_ok(c)) return;
384
385         creq = dcerpc_pipe_connect_b_send(s, s->drsuapi.binding, &dcerpc_table_drsuapi,
386                                           s->libnet->cred, s->libnet->event_ctx);
387         composite_continue(c, creq, unbecomeDC_drsuapi_connect_recv, s);
388 }
389
390 static void unbecomeDC_drsuapi_bind_send(struct libnet_UnbecomeDC_state *s);
391
392 static void unbecomeDC_drsuapi_connect_recv(struct composite_context *req)
393 {
394         struct libnet_UnbecomeDC_state *s = talloc_get_type(req->async.private_data,
395                                             struct libnet_UnbecomeDC_state);
396         struct composite_context *c = s->creq;
397
398         c->status = dcerpc_pipe_connect_b_recv(req, s, &s->drsuapi.pipe);
399         if (!composite_is_ok(c)) return;
400
401         unbecomeDC_drsuapi_bind_send(s);
402 }
403
404 static void unbecomeDC_drsuapi_bind_recv(struct rpc_request *req);
405
406 static void unbecomeDC_drsuapi_bind_send(struct libnet_UnbecomeDC_state *s)
407 {
408         struct composite_context *c = s->creq;
409         struct rpc_request *req;
410         struct drsuapi_DsBindInfo28 *bind_info28;
411
412         GUID_from_string(DRSUAPI_DS_BIND_GUID, &s->drsuapi.bind_guid);
413
414         bind_info28                             = &s->drsuapi.local_info28;
415         bind_info28->supported_extensions       = 0;
416         bind_info28->site_guid                  = GUID_zero();
417         bind_info28->u1                         = 508;
418         bind_info28->repl_epoch                 = 0;
419
420         s->drsuapi.bind_info_ctr.length         = 28;
421         s->drsuapi.bind_info_ctr.info.info28    = *bind_info28;
422
423         s->drsuapi.bind_r.in.bind_guid = &s->drsuapi.bind_guid;
424         s->drsuapi.bind_r.in.bind_info = &s->drsuapi.bind_info_ctr;
425         s->drsuapi.bind_r.out.bind_handle = &s->drsuapi.bind_handle;
426
427         req = dcerpc_drsuapi_DsBind_send(s->drsuapi.pipe, s, &s->drsuapi.bind_r);
428         composite_continue_rpc(c, req, unbecomeDC_drsuapi_bind_recv, s);
429 }
430
431 static void unbecomeDC_drsuapi_remove_ds_server_send(struct libnet_UnbecomeDC_state *s);
432
433 static void unbecomeDC_drsuapi_bind_recv(struct rpc_request *req)
434 {
435         struct libnet_UnbecomeDC_state *s = talloc_get_type(req->async.private,
436                                             struct libnet_UnbecomeDC_state);
437         struct composite_context *c = s->creq;
438
439         c->status = dcerpc_ndr_request_recv(req);
440         if (!composite_is_ok(c)) return;
441
442         if (!W_ERROR_IS_OK(s->drsuapi.bind_r.out.result)) {
443                 composite_error(c, werror_to_ntstatus(s->drsuapi.bind_r.out.result));
444                 return;
445         }
446
447         ZERO_STRUCT(s->drsuapi.remote_info28);
448         if (s->drsuapi.bind_r.out.bind_info) {
449                 switch (s->drsuapi.bind_r.out.bind_info->length) {
450                 case 24: {
451                         struct drsuapi_DsBindInfo24 *info24;
452                         info24 = &s->drsuapi.bind_r.out.bind_info->info.info24;
453                         s->drsuapi.remote_info28.supported_extensions   = info24->supported_extensions;
454                         s->drsuapi.remote_info28.site_guid              = info24->site_guid;
455                         s->drsuapi.remote_info28.u1                     = info24->u1;
456                         s->drsuapi.remote_info28.repl_epoch             = 0;
457                         break;
458                 }
459                 case 28:
460                         s->drsuapi.remote_info28 = s->drsuapi.bind_r.out.bind_info->info.info28;
461                         break;
462                 }
463         }
464
465         unbecomeDC_drsuapi_remove_ds_server_send(s);
466 }
467
468 static void unbecomeDC_drsuapi_remove_ds_server_recv(struct rpc_request *req);
469
470 static void unbecomeDC_drsuapi_remove_ds_server_send(struct libnet_UnbecomeDC_state *s)
471 {
472         struct composite_context *c = s->creq;
473         struct rpc_request *req;
474         struct drsuapi_DsRemoveDSServer *r = &s->drsuapi.rm_ds_srv_r;
475
476         r->in.bind_handle       = &s->drsuapi.bind_handle;
477         r->in.level             = 1;
478         r->in.req.req1.server_dn= s->dest_dsa.server_dn_str;
479         r->in.req.req1.domain_dn= s->domain.dn_str;
480         r->in.req.req1.unknown  = 0x00000001;
481
482         req = dcerpc_drsuapi_DsRemoveDSServer_send(s->drsuapi.pipe, s, r);
483         composite_continue_rpc(c, req, unbecomeDC_drsuapi_remove_ds_server_recv, s);
484 }
485
486 static void unbecomeDC_drsuapi_remove_ds_server_recv(struct rpc_request *req)
487 {
488         struct libnet_UnbecomeDC_state *s = talloc_get_type(req->async.private,
489                                             struct libnet_UnbecomeDC_state);
490         struct composite_context *c = s->creq;
491         struct drsuapi_DsRemoveDSServer *r = &s->drsuapi.rm_ds_srv_r;
492
493         c->status = dcerpc_ndr_request_recv(req);
494         if (!composite_is_ok(c)) return;
495
496         if (!W_ERROR_IS_OK(r->out.result)) {
497                 composite_error(c, werror_to_ntstatus(r->out.result));
498                 return;
499         }
500
501         if (r->out.level != 1) {
502                 composite_error(c, NT_STATUS_INVALID_NETWORK_RESPONSE);
503                 return;
504         }
505                 
506         if (!W_ERROR_IS_OK(r->out.res.res1.status)) {
507                 composite_error(c, werror_to_ntstatus(r->out.res.res1.status));
508                 return;
509         }
510
511         composite_done(c);
512 }
513
514 struct composite_context *libnet_UnbecomeDC_send(struct libnet_context *ctx, TALLOC_CTX *mem_ctx, struct libnet_UnbecomeDC *r)
515 {
516         struct composite_context *c;
517         struct libnet_UnbecomeDC_state *s;
518         char *tmp_name;
519
520         c = composite_create(mem_ctx, ctx->event_ctx);
521         if (c == NULL) return NULL;
522
523         s = talloc_zero(c, struct libnet_UnbecomeDC_state);
524         if (composite_nomem(s, c)) return c;
525         c->private_data = s;
526         s->creq         = c;
527         s->libnet       = ctx;
528
529         /* Domain input */
530         s->domain.dns_name      = talloc_strdup(s, r->in.domain_dns_name);
531         if (composite_nomem(s->domain.dns_name, c)) return c;
532         s->domain.netbios_name  = talloc_strdup(s, r->in.domain_netbios_name);
533         if (composite_nomem(s->domain.netbios_name, c)) return c;
534
535         /* Source DSA input */
536         s->source_dsa.address   = talloc_strdup(s, r->in.source_dsa_address);
537         if (composite_nomem(s->source_dsa.address, c)) return c;
538
539         /* Destination DSA input */
540         s->dest_dsa.netbios_name= talloc_strdup(s, r->in.dest_dsa_netbios_name);
541         if (composite_nomem(s->dest_dsa.netbios_name, c)) return c;
542
543         /* Destination DSA dns_name construction */
544         tmp_name                = strlower_talloc(s, s->dest_dsa.netbios_name);
545         if (composite_nomem(tmp_name, c)) return c;
546         s->dest_dsa.dns_name    = talloc_asprintf_append(tmp_name, ".%s",
547                                                          s->domain.dns_name);
548         if (composite_nomem(s->dest_dsa.dns_name, c)) return c;
549
550         unbecomeDC_send_cldap(s);
551         return c;
552 }
553
554 NTSTATUS libnet_UnbecomeDC_recv(struct composite_context *c, TALLOC_CTX *mem_ctx, struct libnet_UnbecomeDC *r)
555 {
556         NTSTATUS status;
557
558         status = composite_wait(c);
559
560         ZERO_STRUCT(r->out);
561
562         talloc_free(c);
563         return status;
564 }
565
566 NTSTATUS libnet_UnbecomeDC(struct libnet_context *ctx, TALLOC_CTX *mem_ctx, struct libnet_UnbecomeDC *r)
567 {
568         NTSTATUS status;
569         struct composite_context *c;
570         c = libnet_UnbecomeDC_send(ctx, mem_ctx, r);
571         status = libnet_UnbecomeDC_recv(c, mem_ctx, r);
572         return status;
573 }