kai/samba-autobuild/.git
14 years agoprovision: Avoid linking in multiple copies of security python module.
Jelmer Vernooij [Wed, 23 Sep 2009 09:01:52 +0000 (11:01 +0200)]
provision: Avoid linking in multiple copies of security python module.

14 years agos3:winbind: Fix an uninitialized variable
Volker Lendecke [Wed, 23 Sep 2009 04:23:50 +0000 (06:23 +0200)]
s3:winbind: Fix an uninitialized variable

14 years agos4-drsserver: sort by DN to give tree order
Andrew Tridgell [Wed, 23 Sep 2009 00:07:33 +0000 (17:07 -0700)]
s4-drsserver: sort by DN to give tree order

This might help the windows client with ordered requests. Later we
need to support the "ancestors" mode flag.

14 years agos4-ldb: server side sort args are const char *
Andrew Tridgell [Wed, 23 Sep 2009 00:06:38 +0000 (17:06 -0700)]
s4-ldb: server side sort args are const char *

14 years agos4-ldb: fixed call argument order for ldb_dn_from_ldb_val
Andrew Tridgell [Wed, 23 Sep 2009 00:06:14 +0000 (17:06 -0700)]
s4-ldb: fixed call argument order for ldb_dn_from_ldb_val

This caused _lots_ of problems, especially in server side sort

14 years agos4-ldb: added a bunch more debug for DC join
Andrew Tridgell [Tue, 22 Sep 2009 21:26:59 +0000 (14:26 -0700)]
s4-ldb: added a bunch more debug for DC join

These additional debug messages were added to help us track down
w2k8->s4 domain join

14 years agos4-ldb: when tracing, show ldb_set_debug messages
Andrew Tridgell [Tue, 22 Sep 2009 21:25:52 +0000 (14:25 -0700)]
s4-ldb: when tracing, show ldb_set_debug messages

14 years agos4-ldbmodules: allow instanceType to be specified by clients
Andrew Tridgell [Tue, 22 Sep 2009 21:25:12 +0000 (14:25 -0700)]
s4-ldbmodules: allow instanceType to be specified by clients

This is needed for the WSPP ADS testsuite

14 years agos4-util: windows only accepts lowercase hex encodings for extended DNs
Andrew Tridgell [Tue, 22 Sep 2009 21:20:36 +0000 (14:20 -0700)]
s4-util: windows only accepts lowercase hex encodings for extended DNs

14 years agos4-torture: add some debug info to RPC-HANDLES
Andrew Tridgell [Tue, 22 Sep 2009 07:18:25 +0000 (00:18 -0700)]
s4-torture: add some debug info to RPC-HANDLES

14 years agos4-rpcserver: added support for shared handles
Andrew Tridgell [Tue, 22 Sep 2009 07:18:03 +0000 (00:18 -0700)]
s4-rpcserver: added support for shared handles

This supports shared RPC handles across connections on all RPC
interfaces.

It turns out that w2k3 and w2k8 don't actually support this on all
pipes. We need to test which pipes we should enable this on.

14 years agos4-lsa: added support for QuerySecurity on LSA
Andrew Tridgell [Tue, 22 Sep 2009 07:16:58 +0000 (00:16 -0700)]
s4-lsa: added support for QuerySecurity on LSA

This follows the sd pattern from samba3

14 years agos4-rpcserver: added shared association groups
Andrew Tridgell [Tue, 22 Sep 2009 04:36:54 +0000 (21:36 -0700)]
s4-rpcserver: added shared association groups

This patch allows us to share association groups and their rpc handles
between connections. This is needed for some DRSUAPI behaviour when
recent windows clients connect.

14 years agos4-rpcserver: run all RPC operations in a single task
Andrew Tridgell [Tue, 22 Sep 2009 02:57:27 +0000 (19:57 -0700)]
s4-rpcserver: run all RPC operations in a single task

This will make it much easier to implement shared handles with
association groups. It also means we can shared the ldb between RPC
connections.

14 years agos4-rpc: remove two unused functions
Andrew Tridgell [Tue, 22 Sep 2009 02:56:36 +0000 (19:56 -0700)]
s4-rpc: remove two unused functions

14 years agos4-ldb: only show the outer level of ldb ops when tracing
Andrew Tridgell [Tue, 22 Sep 2009 01:15:19 +0000 (18:15 -0700)]
s4-ldb: only show the outer level of ldb ops when tracing

14 years agos4-ldb: don't show timestamps on every line of ldb traces
Andrew Tridgell [Tue, 22 Sep 2009 00:52:21 +0000 (17:52 -0700)]
s4-ldb: don't show timestamps on every line of ldb traces

This adds ldb_debug_add() and ldb_debug_end() to format multiline
messages

14 years agobuild: use AS_HELP_STRING() for --with-localedir
Michael Adam [Tue, 22 Sep 2009 22:52:03 +0000 (00:52 +0200)]
build: use AS_HELP_STRING() for --with-localedir

Michael

14 years agobuild: add switch "--with-codepagedir=DIR" to configure.
Michael Adam [Tue, 22 Sep 2009 22:48:44 +0000 (00:48 +0200)]
build: add switch "--with-codepagedir=DIR" to configure.

This is to address bug #6444.

Michael

14 years agobuild: add datadir to "make showlayout"
Michael Adam [Tue, 22 Sep 2009 21:23:02 +0000 (23:23 +0200)]
build: add datadir to "make showlayout"

Michael

14 years agoMove the check above the talloc
Anatoliy Atanasov [Tue, 22 Sep 2009 21:37:58 +0000 (14:37 -0700)]
Move the check above the talloc

14 years agos3-winbindd: Fix Bug #6711: trusts to windows 2008 (2008 r2) not working.
Günther Deschner [Thu, 17 Sep 2009 07:43:36 +0000 (09:43 +0200)]
s3-winbindd: Fix Bug #6711: trusts to windows 2008 (2008 r2) not working.

Winbindd should always try to use LSA via an schannel authenticated ncacn_ip_tcp
connection when talking to AD for LSA lookup calls.

In Samba <-> W2k8 interdomain trust scenarios, LookupSids3 and LookupNames4 via an
schannel ncacn_ip_tcp LSA connection are the *only* options to successfully resolve
sids and names.

Guenther

14 years agos3-winbindd: add cm_connect_lsa_tcp().
Günther Deschner [Sat, 12 Sep 2009 21:30:39 +0000 (23:30 +0200)]
s3-winbindd: add cm_connect_lsa_tcp().

Guenther

14 years agolib/tevent: a cleaner fix for be4ac227842530d484659f2db683453366326d8b segv
Rusty Russell [Tue, 22 Sep 2009 01:02:10 +0000 (10:32 +0930)]
lib/tevent: a cleaner fix for be4ac227842530d484659f2db683453366326d8b segv

Revert 23abcd2318c69753aa2a144e1dc0f9cf9efdb705 and fix logic bug.

The current code loops through the event contexts, when it sees a different
one, it notifies the current one (ev) and updates ev to point to the new one.

This is dumb, because:
(1) ev starts as NULL, so this code crashes, and
(2) The final context will not be notified.

The correct fix for this is to update ev to the new one, then notify it.
Volker's fix works because we currently always have one event context.

Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
14 years agos4:dsdb Fix of double addition of SD-s
Nadezhda Ivanova [Tue, 22 Sep 2009 03:08:52 +0000 (20:08 -0700)]
s4:dsdb Fix of double addition of SD-s

Also add error strings in descriptor module

14 years agos4:ldb Add 'single-value' support to LDB.
Andrew Bartlett [Tue, 22 Sep 2009 02:26:59 +0000 (19:26 -0700)]
s4:ldb Add 'single-value' support to LDB.

This is currently only triggered via Samba4's schema code.

14 years agoMerge branch 'master' of git://git.samba.org/samba
Nadezhda Ivanova [Tue, 22 Sep 2009 00:29:28 +0000 (17:29 -0700)]
Merge branch 'master' of git://git.samba.org/samba

14 years agoInitial Implementation of the DS objects access checks.
Nadezhda Ivanova [Tue, 22 Sep 2009 00:27:50 +0000 (17:27 -0700)]
Initial Implementation of the DS objects access checks.

Currently disabled. The search will be greatly modified,
also the object tree stuff will be simplified.

14 years agoAdd support in the ldb_dn.c code for MS-ADTS:3.1.1.5.1.2 Naming Constraints
Anatoliy Atanasov [Tue, 22 Sep 2009 00:14:06 +0000 (17:14 -0700)]
Add support in the ldb_dn.c code for MS-ADTS:3.1.1.5.1.2 Naming Constraints

14 years agoAdd tests for MS-ADTS:3.1.1.5.1.2 Naming Constraints
Anatoliy Atanasov [Tue, 22 Sep 2009 00:01:20 +0000 (17:01 -0700)]
Add tests for MS-ADTS:3.1.1.5.1.2 Naming Constraints

14 years agos4:dsdb Run the new 'descriptor' module by default.
Andrew Bartlett [Mon, 21 Sep 2009 23:31:08 +0000 (16:31 -0700)]
s4:dsdb Run the new 'descriptor' module by default.

This code was derived from the objectclass module, and we need the new
code in the default provision, or else no ACL is set on each object.

Andrew Bartlett

14 years agos4-ldb: bit prettier output
Andrew Tridgell [Mon, 21 Sep 2009 23:29:44 +0000 (16:29 -0700)]
s4-ldb: bit prettier output

14 years agos4-ldb: fixed O(n^2) string handling in ldif debug print
Andrew Tridgell [Mon, 21 Sep 2009 23:29:22 +0000 (16:29 -0700)]
s4-ldb: fixed O(n^2) string handling in ldif debug print

14 years agos4-samdb: enable ldb tracing when log level >= 10
Andrew Tridgell [Mon, 21 Sep 2009 22:25:10 +0000 (15:25 -0700)]
s4-samdb: enable ldb tracing when log level >= 10

14 years agos4-schema: don't trace the schema load (too verbose)
Andrew Tridgell [Mon, 21 Sep 2009 22:24:55 +0000 (15:24 -0700)]
s4-schema: don't trace the schema load (too verbose)

14 years agos4-ldb: add --trace command line option to ldb tools
Andrew Tridgell [Mon, 21 Sep 2009 22:24:39 +0000 (15:24 -0700)]
s4-ldb: add --trace command line option to ldb tools

This enabled LDB_FLG_ENABLE_TRACING

14 years agos4-ldb: add a LDB_FLG_ENABLE_TRACING for full ldb tracing
Andrew Tridgell [Mon, 21 Sep 2009 22:24:14 +0000 (15:24 -0700)]
s4-ldb: add a LDB_FLG_ENABLE_TRACING for full ldb tracing

When LDB_FLG_ENABLE_TRACING is set ldb will send full traces
of all operations and results

14 years agos4-ldap: default edn type is 0
Andrew Tridgell [Mon, 21 Sep 2009 01:58:18 +0000 (18:58 -0700)]
s4-ldap: default edn type is 0

14 years agos4-ldb: add support for extended DNs in the rootDSE
Andrew Tridgell [Mon, 21 Sep 2009 01:24:23 +0000 (18:24 -0700)]
s4-ldb: add support for extended DNs in the rootDSE

W2K8 join as a DC relies on being able to ask for the sid component of
extended DNs from the rootDSE DNs

14 years agos4-dsdb: fixed a printf format warning
Andrew Tridgell [Sun, 20 Sep 2009 22:45:53 +0000 (15:45 -0700)]
s4-dsdb: fixed a printf format warning

14 years agoMerge branch 'master' of git://git.samba.org/samba
Nadezhda Ivanova [Mon, 21 Sep 2009 21:26:15 +0000 (14:26 -0700)]
Merge branch 'master' of git://git.samba.org/samba

14 years agos4:kerberos Fix the salt to match Windows 2008.
Andrew Bartlett [Mon, 21 Sep 2009 19:28:38 +0000 (12:28 -0700)]
s4:kerberos Fix the salt to match Windows 2008.

The previous commit changed the wrong end - we must fix our server,
not our client.

Andrew Bartlett

14 years agos4:provision Make our default salt match our server behaviour
Andrew Bartlett [Mon, 21 Sep 2009 18:59:33 +0000 (11:59 -0700)]
s4:provision Make our default salt match our server behaviour

We need to look into salting algorithms further.

Andrew Bartlett

14 years agotdb:tdbtool: fix indentation.
Michael Adam [Sun, 20 Sep 2009 22:08:34 +0000 (00:08 +0200)]
tdb:tdbtool: fix indentation.

Michael

14 years agotdb:tdbtool: add transaction_start/_commit/_cancel commands.
Michael Adam [Sun, 20 Sep 2009 21:58:27 +0000 (23:58 +0200)]
tdb:tdbtool: add transaction_start/_commit/_cancel commands.

So one can perform tdbtool operations protected by transactions.

Michael

14 years agotdb:tdbtool: add the "speed" command to the help text.
Michael Adam [Sun, 20 Sep 2009 21:58:05 +0000 (23:58 +0200)]
tdb:tdbtool: add the "speed" command to the help text.

Michael

14 years agos4:provision - Fix up ProvisioningError class as suggested by Jelmer
Matthias Dieter Wallnöfer [Mon, 21 Sep 2009 15:20:49 +0000 (17:20 +0200)]
s4:provision - Fix up ProvisioningError class as suggested by Jelmer

14 years agos4:samdb/tools - That should fix now the last failures
Matthias Dieter Wallnöfer [Mon, 21 Sep 2009 11:53:47 +0000 (13:53 +0200)]
s4:samdb/tools - That should fix now the last failures

14 years agos4:libnet_become_dc - bump down the level requested by abartlet
Matthias Dieter Wallnöfer [Mon, 21 Sep 2009 09:59:07 +0000 (11:59 +0200)]
s4:libnet_become_dc - bump down the level requested by abartlet

14 years agos4:scripts - Reintroduce "-H" parameter
Matthias Dieter Wallnöfer [Mon, 21 Sep 2009 09:53:19 +0000 (11:53 +0200)]
s4:scripts - Reintroduce "-H" parameter

I removed it since on some scripts it was present, on others not - so I thought
it wouldn't be really needed. This was a bad decision (pointed out by abartlet).
So I reintroduce it on all scripts (to have consistent parameters).

14 years agoRevert "blackbox:test_kinit - Remove the "-H" (hive) parameter"
Matthias Dieter Wallnöfer [Mon, 21 Sep 2009 09:33:13 +0000 (11:33 +0200)]
Revert "blackbox:test_kinit - Remove the "-H" (hive) parameter"

This reverts commit d4389a230b6aea5a0b2a98e255b14a59c8248b0b.

This revert changed the behaviour which I didn't expect. Thanks abartlet to
point this out!

14 years agos4:provision Make us Windows 2008 level by defualt again
Andrew Bartlett [Mon, 21 Sep 2009 04:32:16 +0000 (21:32 -0700)]
s4:provision Make us Windows 2008 level by defualt again

Also add a note to clarify that this should not be changed without
discussion and consensus.  We don't want this bouncing around.

Paramater support to allow optional selection of Win2003 mode welcomed.

Andrew Bartlett

14 years agos3:secrets_schannel: revert to using version 1
Stefan Metzmacher [Mon, 21 Sep 2009 04:26:30 +0000 (06:26 +0200)]
s3:secrets_schannel: revert to using version 1

It doesn't really matter if the entries
have invalid context in it. Older versions of samba
refuse to open the file if the version doesn't match.

If we can't parse individual records, we'll fail schannel binds,
but the clients are supposed to reestablish the netlogon secure channel
by doing ServerReqChallenge/ServerAuthenticate* again. This
will just overwrite the old record.

metze

14 years agos3:winbindd: avoid writing to a closed connection and generate SIGPIPE
Stefan Metzmacher [Mon, 21 Sep 2009 00:42:35 +0000 (02:42 +0200)]
s3:winbindd: avoid writing to a closed connection and generate SIGPIPE

metze

14 years agoasync_sock: return -1/EPIPE if we're getting an end of file on read.
Stefan Metzmacher [Mon, 21 Sep 2009 00:36:06 +0000 (02:36 +0200)]
async_sock: return -1/EPIPE if we're getting an end of file on read.

This makes the error handling in the callers easier.

metze

14 years agos3:lib/select: don't overwrite errno in the signal handler
Stefan Metzmacher [Sun, 20 Sep 2009 21:29:34 +0000 (23:29 +0200)]
s3:lib/select: don't overwrite errno in the signal handler

metze

14 years agotevent: make sure we don't set errno within the signal handler function.
Stefan Metzmacher [Mon, 21 Sep 2009 01:16:18 +0000 (03:16 +0200)]
tevent: make sure we don't set errno within the signal handler function.

metze

14 years agos4:dsdb/resolve_oids: add fast pathes for the common operations without oids
Stefan Metzmacher [Mon, 21 Sep 2009 03:15:59 +0000 (05:15 +0200)]
s4:dsdb/resolve_oids: add fast pathes for the common operations without oids

metze

14 years agos4:dsdb/resolve_oids: check return values in recursion
Stefan Metzmacher [Mon, 21 Sep 2009 03:15:38 +0000 (05:15 +0200)]
s4:dsdb/resolve_oids: check return values in recursion

metze

14 years agos4:py_security Add missing header
Andrew Bartlett [Mon, 21 Sep 2009 03:28:42 +0000 (20:28 -0700)]
s4:py_security Add missing header

14 years agoMerge branch 'master' of git://git.samba.org/samba
Nadezhda Ivanova [Mon, 21 Sep 2009 00:43:46 +0000 (17:43 -0700)]
Merge branch 'master' of git://git.samba.org/samba

14 years agos4:provision Use code to store domain join in 'net join' as well
Andrew Bartlett [Sun, 20 Sep 2009 23:27:24 +0000 (16:27 -0700)]
s4:provision Use code to store domain join in 'net join' as well

This ensures we only have one codepath to store the secret, and
therefore that we have a single choke point for setting the
saltPrincipal, which we were previously skipping.

Andrew Bartlett

14 years agos4:ldb print out which LDB the transaction is still active on.
Andrew Bartlett [Sun, 20 Sep 2009 22:38:29 +0000 (15:38 -0700)]
s4:ldb print out which LDB the transaction is still active on.

14 years agos4:provision split provision of DNS zone and self join keytab
Andrew Bartlett [Sun, 20 Sep 2009 03:40:17 +0000 (20:40 -0700)]
s4:provision split provision of DNS zone and self join keytab

14 years agos4-selftest: disable RAP-SCAN test
Andrew Tridgell [Sun, 20 Sep 2009 22:27:09 +0000 (15:27 -0700)]
s4-selftest: disable RAP-SCAN test

also pointless now we have docs

14 years agos4-selftest: disable RPC-COUNTCALLS
Andrew Tridgell [Sun, 20 Sep 2009 22:23:34 +0000 (15:23 -0700)]
s4-selftest: disable RPC-COUNTCALLS

The RPC-COUNTCALLS was useful when we were working out IDL by hand

14 years agoInitial implementation of security descriptor creation in DS
Nadezhda Ivanova [Sun, 20 Sep 2009 20:50:34 +0000 (13:50 -0700)]
Initial implementation of security descriptor creation in DS

TODO's:
ACE sorting and clarifying the inheritance of object specific ace's.

14 years agoMerge branch 'master' of git://git.samba.org/samba
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 22:03:42 +0000 (00:03 +0200)]
Merge branch 'master' of git://git.samba.org/samba

14 years agos4:python tools - try to fix some test problems
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 21:49:05 +0000 (23:49 +0200)]
s4:python tools - try to fix some test problems

14 years agos4:samba3sam.py test - remove the primary group ID attribute here
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 21:27:47 +0000 (23:27 +0200)]
s4:samba3sam.py test - remove the primary group ID attribute here

This shouldn't be specified on creation time (Windows Server doesn't allow that).
Hope this also fixes the test (see buildfarm).

14 years agos4:sec_descriptor - fix constant
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 21:16:04 +0000 (23:16 +0200)]
s4:sec_descriptor - fix constant

14 years agoblackbox:test_kinit - Remove the "-H" (hive) parameter
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 21:07:22 +0000 (23:07 +0200)]
blackbox:test_kinit - Remove the "-H" (hive) parameter

The "enableaccount" script works only on local LDB anymore - therefore remove
this parameter.

14 years agoDisable descriptor module unless enabled in smb.conf
Nadezhda Ivanova [Sun, 20 Sep 2009 04:45:07 +0000 (21:45 -0700)]
Disable descriptor module unless enabled in smb.conf

Since this code may still have some problems, it is not executed by default.
To enable descriptor inheritance add:
acl:inheritance = true
in your smb.conf

14 years agos4:dsdb/common/util - Check for the right forest/domain function level
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 20:49:55 +0000 (22:49 +0200)]
s4:dsdb/common/util - Check for the right forest/domain function level

This adds a function which performs the check for the supported forest and
domain function levels. On an unsuccessful result a textual error message can
be created (parameter "errmsg" != NULL) which gives hints for the user to help
him fixing the issue.

14 years agos4:server.c - add linespace (only cosmetic)
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 20:17:35 +0000 (22:17 +0200)]
s4:server.c - add linespace (only cosmetic)

14 years agotalloc: fixed talloc_disable_null_tracking()
Andrew Tridgell [Sun, 20 Sep 2009 20:14:40 +0000 (13:14 -0700)]
talloc: fixed talloc_disable_null_tracking()

When we disable null tracking, we need to move any existing objects
that are under the null_context to be parented by the true NULL
context.

We also need a new talloc_enable_null_tracking_no_autofree() function,
as the talloc testsuite cannot cope with the moving of the autofree
context under the null_context as it wants to check exact counts of
objects under the null_context, and smbtorture has a large number of
objects in the autofree_context from .init functions

14 years agos4:domainlevel - fixed another error
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 19:25:49 +0000 (21:25 +0200)]
s4:domainlevel - fixed another error

The second "nTMixedDomain" attribute (under Partitions/Domain-DN) is only a
copy of the one under the directory root object. Therefore there doesn't exist
the "Windows 2000 Mixed" forest level.

14 years agoFixed a difference in domain sid type when SID is provided by user.
Nadezhda Ivanova [Sat, 19 Sep 2009 00:48:26 +0000 (17:48 -0700)]
Fixed a difference in domain sid type when SID is provided by user.

14 years agos4:ldb_parse - Fix the type of an array entry
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 10:47:52 +0000 (12:47 +0200)]
s4:ldb_parse - Fix the type of an array entry

I found this through a compile warning. Hope that I got this right.

14 years agos4:provision_configuration - fix "sPNMappings"
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 09:57:54 +0000 (11:57 +0200)]
s4:provision_configuration - fix "sPNMappings"

I reread some docs about this attributes and it seems that this as mapping
attribute isn't host specific but in common for the whole domain. To allow
Windows DCs to join our s4 domain sooner or later we have to provide the full
attribute.

14 years agos4:domainlevel - further improvements
Matthias Dieter Wallnöfer [Sun, 20 Sep 2009 09:44:39 +0000 (11:44 +0200)]
s4:domainlevel - further improvements

- The tool displays now also mixed/interim domain levels and warns about them
  (s4 isn't capable to run on them)
- But it allows now also to raise/step-up from them
- It displays now also levels higher than 2008 R2 (altough we don't support them
  yet) but to be able to get a correct output

14 years agoblackbox/test_ldb.sh: test searching using OIDs instead of names for attributes and...
Stefan Metzmacher [Sun, 20 Sep 2009 04:05:59 +0000 (06:05 +0200)]
blackbox/test_ldb.sh: test searching using OIDs instead of names for attributes and classes

metze

14 years agos4:provision: add the 'resolve_oids' on the top of the module stack
Stefan Metzmacher [Sat, 19 Sep 2009 05:54:59 +0000 (07:54 +0200)]
s4:provision: add the 'resolve_oids' on the top of the module stack

metze

14 years agodsdb/samdb: add resolve_oids module
Stefan Metzmacher [Sat, 19 Sep 2009 05:01:26 +0000 (07:01 +0200)]
dsdb/samdb: add resolve_oids module

Windows Servers allow OID strings to be used instead of
attribute/class names.

For now we only resolve the OIDs in the search expressions,
the rest will follow.

metze

14 years agos4:build: require ldb 0.9.7
Stefan Metzmacher [Sun, 20 Sep 2009 03:42:27 +0000 (05:42 +0200)]
s4:build: require ldb 0.9.7

metze

14 years agos4:ldb: add ldb_parse_tree_copy_shallow() and change version to 0.9.7
Stefan Metzmacher [Sun, 20 Sep 2009 03:41:42 +0000 (05:41 +0200)]
s4:ldb: add ldb_parse_tree_copy_shallow() and change version to 0.9.7

metze

14 years agolibrpc: rerun 'make idl'
Stefan Metzmacher [Sun, 20 Sep 2009 04:37:24 +0000 (06:37 +0200)]
librpc: rerun 'make idl'

metze

14 years agodrsblobs.idl: fix repsFromTo2 blob size calculation
Stefan Metzmacher [Sun, 20 Sep 2009 04:36:39 +0000 (06:36 +0200)]
drsblobs.idl: fix repsFromTo2 blob size calculation

metze

14 years agorerun: make idl
Stefan Metzmacher [Sun, 20 Sep 2009 03:57:37 +0000 (05:57 +0200)]
rerun: make idl

metze

14 years agodrsblobs.idl: add decoding for repsFromTo2
Stefan Metzmacher [Sun, 20 Sep 2009 03:52:14 +0000 (05:52 +0200)]
drsblobs.idl: add decoding for repsFromTo2

This is used in windows 2008.

metze

14 years agos4-auth: add SID_NT_ENTERPRISE_DCS is a server trust account
Andrew Tridgell [Sun, 20 Sep 2009 02:40:03 +0000 (19:40 -0700)]
s4-auth: add SID_NT_ENTERPRISE_DCS is a server trust account

14 years agos4-drs: security checking on DRS needs to default to on
Andrew Tridgell [Sun, 20 Sep 2009 02:39:42 +0000 (19:39 -0700)]
s4-drs: security checking on DRS needs to default to on

14 years agos4-ldb: display an error if we can't decode a NDR blob
Andrew Tridgell [Sun, 20 Sep 2009 01:41:22 +0000 (18:41 -0700)]
s4-ldb: display an error if we can't decode a NDR blob

14 years agos4-repl: need param.h for lp_parm_bool
Andrew Tridgell [Sat, 19 Sep 2009 22:53:22 +0000 (15:53 -0700)]
s4-repl: need param.h for lp_parm_bool

14 years agoHandle dsdb_class_by_lDAPDisplayName returned values in schema_inferiors.c
Anatoliy Atanasov [Fri, 11 Sep 2009 15:57:34 +0000 (18:57 +0300)]
Handle dsdb_class_by_lDAPDisplayName returned values in schema_inferiors.c

14 years agoMove replmd_drsuapi_DsReplicaCursor2_compare to a common place.
Anatoliy Atanasov [Mon, 14 Sep 2009 18:46:59 +0000 (11:46 -0700)]
Move replmd_drsuapi_DsReplicaCursor2_compare to a common place.

14 years agoAdd drs_security_level_check for dcesrv calls security checks
Anatoliy Atanasov [Sat, 19 Sep 2009 22:08:19 +0000 (15:08 -0700)]
Add drs_security_level_check for dcesrv calls security checks

There is also an option to disable the security check
by specifying in the smb.conf file:
drs:disable_sec_check = true

14 years agos4:provision_basedn_modify - fix the "auditPolicy" attribute
Matthias Dieter Wallnöfer [Sat, 19 Sep 2009 22:09:05 +0000 (00:09 +0200)]
s4:provision_basedn_modify - fix the "auditPolicy" attribute

I had to think about how to encode the string 0x0001 (taken from Windows Server).
The problem is due to the "0" byte at the beginning of it. BASE64 encoding
seems a good method to do it.

14 years agos4:utils Remove typo...
Andrew Bartlett [Sat, 19 Sep 2009 21:51:18 +0000 (14:51 -0700)]
s4:utils Remove typo...

14 years agos4:dsdb Print the partition we failed to suggest replication for
Andrew Bartlett [Sat, 19 Sep 2009 21:27:29 +0000 (14:27 -0700)]
s4:dsdb Print the partition we failed to suggest replication for