s3-build: only include krb5 environment variables where required.
[kai/samba.git] / source3 / printing / nt_printing_ads.c
1 /*
2  *  Unix SMB/CIFS implementation.
3  *  RPC Pipe client / server routines
4  *  Copyright (C) Andrew Tridgell              1992-2000,
5  *  Copyright (C) Jean François Micouleau      1998-2000.
6  *  Copyright (C) Gerald Carter                2002-2005.
7  *
8  *  This program is free software; you can redistribute it and/or modify
9  *  it under the terms of the GNU General Public License as published by
10  *  the Free Software Foundation; either version 3 of the License, or
11  *  (at your option) any later version.
12  *
13  *  This program is distributed in the hope that it will be useful,
14  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
15  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16  *  GNU General Public License for more details.
17  *
18  *  You should have received a copy of the GNU General Public License
19  *  along with this program; if not, see <http://www.gnu.org/licenses/>.
20  */
21
22 #include "includes.h"
23 #include "../librpc/gen_ndr/spoolss.h"
24 #include "rpc_server/srv_spoolss_util.h"
25 #include "nt_printing.h"
26 #include "ads.h"
27 #include "secrets.h"
28 #include "krb5_env.h"
29
30 #ifdef HAVE_ADS
31 /*****************************************************************
32  ****************************************************************/
33
34 static void store_printer_guid(struct messaging_context *msg_ctx,
35                                const char *printer, struct GUID guid)
36 {
37         TALLOC_CTX *tmp_ctx;
38         struct auth_serversupplied_info *server_info = NULL;
39         const char *guid_str;
40         DATA_BLOB blob;
41         NTSTATUS status;
42         WERROR result;
43
44         tmp_ctx = talloc_new(NULL);
45         if (!tmp_ctx) {
46                 DEBUG(0, ("store_printer_guid: Out of memory?!\n"));
47                 return;
48         }
49
50         status = make_server_info_system(tmp_ctx, &server_info);
51         if (!NT_STATUS_IS_OK(status)) {
52                 DEBUG(0, ("store_printer_guid: "
53                           "Could not create system server_info\n"));
54                 goto done;
55         }
56
57         guid_str = GUID_string(tmp_ctx, &guid);
58         if (!guid_str) {
59                 DEBUG(0, ("store_printer_guid: Out of memory?!\n"));
60                 goto done;
61         }
62
63         /* We used to store this as a REG_BINARY but that causes
64            Vista to whine */
65
66         if (!push_reg_sz(tmp_ctx, &blob, guid_str)) {
67                 DEBUG(0, ("store_printer_guid: "
68                           "Could not marshall string %s for objectGUID\n",
69                           guid_str));
70                 goto done;
71         }
72
73         result = winreg_set_printer_dataex(tmp_ctx, server_info, msg_ctx,
74                                            printer,
75                                            SPOOL_DSSPOOLER_KEY, "objectGUID",
76                                            REG_SZ, blob.data, blob.length);
77         if (!W_ERROR_IS_OK(result)) {
78                 DEBUG(0, ("store_printer_guid: "
79                           "Failed to store GUID for printer %s\n", printer));
80         }
81
82 done:
83         talloc_free(tmp_ctx);
84 }
85
86 static WERROR nt_printer_publish_ads(struct messaging_context *msg_ctx,
87                                      ADS_STRUCT *ads,
88                                      struct spoolss_PrinterInfo2 *pinfo2)
89 {
90         ADS_STATUS ads_rc;
91         LDAPMessage *res;
92         char *prt_dn = NULL, *srv_dn, *srv_cn_0, *srv_cn_escaped, *sharename_escaped;
93         char *srv_dn_utf8, **srv_cn_utf8;
94         TALLOC_CTX *ctx;
95         ADS_MODLIST mods;
96         const char *attrs[] = {"objectGUID", NULL};
97         struct GUID guid;
98         WERROR win_rc = WERR_OK;
99         size_t converted_size;
100         const char *printer = pinfo2->sharename;
101
102         /* build the ads mods */
103         ctx = talloc_init("nt_printer_publish_ads");
104         if (ctx == NULL) {
105                 return WERR_NOMEM;
106         }
107
108         DEBUG(5, ("publishing printer %s\n", printer));
109
110         /* figure out where to publish */
111         ads_find_machine_acct(ads, &res, global_myname());
112
113         /* We use ldap_get_dn here as we need the answer
114          * in utf8 to call ldap_explode_dn(). JRA. */
115
116         srv_dn_utf8 = ldap_get_dn((LDAP *)ads->ldap.ld, (LDAPMessage *)res);
117         if (!srv_dn_utf8) {
118                 TALLOC_FREE(ctx);
119                 return WERR_SERVER_UNAVAILABLE;
120         }
121         ads_msgfree(ads, res);
122         srv_cn_utf8 = ldap_explode_dn(srv_dn_utf8, 1);
123         if (!srv_cn_utf8) {
124                 TALLOC_FREE(ctx);
125                 ldap_memfree(srv_dn_utf8);
126                 return WERR_SERVER_UNAVAILABLE;
127         }
128         /* Now convert to CH_UNIX. */
129         if (!pull_utf8_talloc(ctx, &srv_dn, srv_dn_utf8, &converted_size)) {
130                 TALLOC_FREE(ctx);
131                 ldap_memfree(srv_dn_utf8);
132                 ldap_memfree(srv_cn_utf8);
133                 return WERR_SERVER_UNAVAILABLE;
134         }
135         if (!pull_utf8_talloc(ctx, &srv_cn_0, srv_cn_utf8[0], &converted_size)) {
136                 TALLOC_FREE(ctx);
137                 ldap_memfree(srv_dn_utf8);
138                 ldap_memfree(srv_cn_utf8);
139                 TALLOC_FREE(srv_dn);
140                 return WERR_SERVER_UNAVAILABLE;
141         }
142
143         ldap_memfree(srv_dn_utf8);
144         ldap_memfree(srv_cn_utf8);
145
146         srv_cn_escaped = escape_rdn_val_string_alloc(srv_cn_0);
147         if (!srv_cn_escaped) {
148                 TALLOC_FREE(ctx);
149                 return WERR_SERVER_UNAVAILABLE;
150         }
151         sharename_escaped = escape_rdn_val_string_alloc(printer);
152         if (!sharename_escaped) {
153                 SAFE_FREE(srv_cn_escaped);
154                 TALLOC_FREE(ctx);
155                 return WERR_SERVER_UNAVAILABLE;
156         }
157
158         prt_dn = talloc_asprintf(ctx, "cn=%s-%s,%s", srv_cn_escaped, sharename_escaped, srv_dn);
159
160         SAFE_FREE(srv_cn_escaped);
161         SAFE_FREE(sharename_escaped);
162
163         mods = ads_init_mods(ctx);
164
165         if (mods == NULL) {
166                 SAFE_FREE(prt_dn);
167                 TALLOC_FREE(ctx);
168                 return WERR_NOMEM;
169         }
170
171         ads_mod_str(ctx, &mods, SPOOL_REG_PRINTERNAME, printer);
172
173         /* publish it */
174         ads_rc = ads_mod_printer_entry(ads, prt_dn, ctx, &mods);
175         if (ads_rc.err.rc == LDAP_NO_SUCH_OBJECT) {
176                 int i;
177                 for (i=0; mods[i] != 0; i++)
178                         ;
179                 mods[i] = (LDAPMod *)-1;
180                 ads_rc = ads_add_printer_entry(ads, prt_dn, ctx, &mods);
181         }
182
183         if (!ADS_ERR_OK(ads_rc)) {
184                 DEBUG(3, ("error publishing %s: %s\n",
185                           printer, ads_errstr(ads_rc)));
186         }
187
188         /* retreive the guid and store it locally */
189         if (ADS_ERR_OK(ads_search_dn(ads, &res, prt_dn, attrs))) {
190                 ZERO_STRUCT(guid);
191                 ads_pull_guid(ads, res, &guid);
192                 ads_msgfree(ads, res);
193                 store_printer_guid(msg_ctx, printer, guid);
194         }
195         TALLOC_FREE(ctx);
196
197         return win_rc;
198 }
199
200 static WERROR nt_printer_unpublish_ads(ADS_STRUCT *ads,
201                                        const char *printer)
202 {
203         ADS_STATUS ads_rc;
204         LDAPMessage *res = NULL;
205         char *prt_dn = NULL;
206
207         DEBUG(5, ("unpublishing printer %s\n", printer));
208
209         /* remove the printer from the directory */
210         ads_rc = ads_find_printer_on_server(ads, &res,
211                                             printer, global_myname());
212
213         if (ADS_ERR_OK(ads_rc) && res && ads_count_replies(ads, res)) {
214                 prt_dn = ads_get_dn(ads, talloc_tos(), res);
215                 if (!prt_dn) {
216                         ads_msgfree(ads, res);
217                         return WERR_NOMEM;
218                 }
219                 ads_rc = ads_del_dn(ads, prt_dn);
220                 TALLOC_FREE(prt_dn);
221         }
222
223         if (res) {
224                 ads_msgfree(ads, res);
225         }
226         return WERR_OK;
227 }
228
229 /****************************************************************************
230  * Publish a printer in the directory
231  *
232  * @param mem_ctx      memory context
233  * @param server_info  server_info to access winreg pipe
234  * @param pinfo2       printer information
235  * @param action       publish/unpublish action
236  * @return WERROR indicating status of publishing
237  ***************************************************************************/
238
239 WERROR nt_printer_publish(TALLOC_CTX *mem_ctx,
240                           struct auth_serversupplied_info *server_info,
241                           struct messaging_context *msg_ctx,
242                           struct spoolss_PrinterInfo2 *pinfo2,
243                           int action)
244 {
245         uint32_t info2_mask = SPOOLSS_PRINTER_INFO_ATTRIBUTES;
246         struct spoolss_SetPrinterInfo2 *sinfo2;
247         ADS_STATUS ads_rc;
248         ADS_STRUCT *ads = NULL;
249         WERROR win_rc;
250
251         sinfo2 = talloc_zero(mem_ctx, struct spoolss_SetPrinterInfo2);
252         if (!sinfo2) {
253                 return WERR_NOMEM;
254         }
255
256         switch (action) {
257         case DSPRINT_PUBLISH:
258         case DSPRINT_UPDATE:
259                 pinfo2->attributes |= PRINTER_ATTRIBUTE_PUBLISHED;
260                 break;
261         case DSPRINT_UNPUBLISH:
262                 pinfo2->attributes ^= PRINTER_ATTRIBUTE_PUBLISHED;
263                 break;
264         default:
265                 win_rc = WERR_NOT_SUPPORTED;
266                 goto done;
267         }
268
269         sinfo2->attributes = pinfo2->attributes;
270
271         win_rc = winreg_update_printer(mem_ctx, server_info, msg_ctx,
272                                         pinfo2->sharename, info2_mask,
273                                         sinfo2, NULL, NULL);
274         if (!W_ERROR_IS_OK(win_rc)) {
275                 DEBUG(3, ("err %d saving data\n", W_ERROR_V(win_rc)));
276                 goto done;
277         }
278
279         TALLOC_FREE(sinfo2);
280
281         ads = ads_init(lp_realm(), lp_workgroup(), NULL);
282         if (!ads) {
283                 DEBUG(3, ("ads_init() failed\n"));
284                 win_rc = WERR_SERVER_UNAVAILABLE;
285                 goto done;
286         }
287         setenv(KRB5_ENV_CCNAME, "MEMORY:prtpub_cache", 1);
288         SAFE_FREE(ads->auth.password);
289         ads->auth.password = secrets_fetch_machine_password(lp_workgroup(),
290                 NULL, NULL);
291
292         /* ads_connect() will find the DC for us */
293         ads_rc = ads_connect(ads);
294         if (!ADS_ERR_OK(ads_rc)) {
295                 DEBUG(3, ("ads_connect failed: %s\n", ads_errstr(ads_rc)));
296                 win_rc = WERR_ACCESS_DENIED;
297                 goto done;
298         }
299
300         switch (action) {
301         case DSPRINT_PUBLISH:
302         case DSPRINT_UPDATE:
303                 win_rc = nt_printer_publish_ads(msg_ctx, ads, pinfo2);
304                 break;
305         case DSPRINT_UNPUBLISH:
306                 win_rc = nt_printer_unpublish_ads(ads, pinfo2->sharename);
307                 break;
308         }
309
310 done:
311         ads_destroy(&ads);
312         return win_rc;
313 }
314
315 WERROR check_published_printers(struct messaging_context *msg_ctx)
316 {
317         ADS_STATUS ads_rc;
318         ADS_STRUCT *ads = NULL;
319         int snum;
320         int n_services = lp_numservices();
321         TALLOC_CTX *tmp_ctx = NULL;
322         struct auth_serversupplied_info *server_info = NULL;
323         struct spoolss_PrinterInfo2 *pinfo2;
324         NTSTATUS status;
325         WERROR result;
326
327         tmp_ctx = talloc_new(NULL);
328         if (!tmp_ctx) return WERR_NOMEM;
329
330         ads = ads_init(lp_realm(), lp_workgroup(), NULL);
331         if (!ads) {
332                 DEBUG(3, ("ads_init() failed\n"));
333                 return WERR_SERVER_UNAVAILABLE;
334         }
335         setenv(KRB5_ENV_CCNAME, "MEMORY:prtpub_cache", 1);
336         SAFE_FREE(ads->auth.password);
337         ads->auth.password = secrets_fetch_machine_password(lp_workgroup(),
338                 NULL, NULL);
339
340         /* ads_connect() will find the DC for us */
341         ads_rc = ads_connect(ads);
342         if (!ADS_ERR_OK(ads_rc)) {
343                 DEBUG(3, ("ads_connect failed: %s\n", ads_errstr(ads_rc)));
344                 result = WERR_ACCESS_DENIED;
345                 goto done;
346         }
347
348         status = make_server_info_system(tmp_ctx, &server_info);
349         if (!NT_STATUS_IS_OK(status)) {
350                 DEBUG(0, ("check_published_printers: "
351                           "Could not create system server_info\n"));
352                 result = WERR_ACCESS_DENIED;
353                 goto done;
354         }
355
356         for (snum = 0; snum < n_services; snum++) {
357                 if (!lp_snum_ok(snum) || !lp_print_ok(snum)) {
358                         continue;
359                 }
360
361                 result = winreg_get_printer(tmp_ctx, server_info, msg_ctx,
362                                             NULL, lp_servicename(snum),
363                                             &pinfo2);
364                 if (!W_ERROR_IS_OK(result)) {
365                         continue;
366                 }
367
368                 if (pinfo2->attributes & PRINTER_ATTRIBUTE_PUBLISHED) {
369                         nt_printer_publish_ads(msg_ctx, ads, pinfo2);
370                 }
371
372                 TALLOC_FREE(pinfo2);
373         }
374
375         result = WERR_OK;
376 done:
377         ads_destroy(&ads);
378         ads_kdestroy("MEMORY:prtpub_cache");
379         talloc_free(tmp_ctx);
380         return result;
381 }
382
383 bool is_printer_published(TALLOC_CTX *mem_ctx,
384                           struct auth_serversupplied_info *server_info,
385                           struct messaging_context *msg_ctx,
386                           char *servername, char *printer, struct GUID *guid,
387                           struct spoolss_PrinterInfo2 **info2)
388 {
389         struct spoolss_PrinterInfo2 *pinfo2 = NULL;
390         enum winreg_Type type;
391         uint8_t *data;
392         uint32_t data_size;
393         WERROR result;
394         NTSTATUS status;
395
396         result = winreg_get_printer(mem_ctx, server_info, msg_ctx,
397                                     servername, printer, &pinfo2);
398         if (!W_ERROR_IS_OK(result)) {
399                 return false;
400         }
401
402         if (!(pinfo2->attributes & PRINTER_ATTRIBUTE_PUBLISHED)) {
403                 TALLOC_FREE(pinfo2);
404                 return false;
405         }
406
407         if (!guid) {
408                 goto done;
409         }
410
411         /* fetching printer guids really ought to be a separate function. */
412
413         result = winreg_get_printer_dataex(mem_ctx, server_info, msg_ctx,
414                                            printer,
415                                            SPOOL_DSSPOOLER_KEY, "objectGUID",
416                                            &type, &data, &data_size);
417         if (!W_ERROR_IS_OK(result)) {
418                 TALLOC_FREE(pinfo2);
419                 return false;
420         }
421
422         /* We used to store the guid as REG_BINARY, then swapped
423            to REG_SZ for Vista compatibility so check for both */
424
425         switch (type) {
426         case REG_SZ:
427                 status = GUID_from_string((char *)data, guid);
428                 if (!NT_STATUS_IS_OK(status)) {
429                         TALLOC_FREE(pinfo2);
430                         return false;
431                 }
432                 break;
433
434         case REG_BINARY:
435                 if (data_size != sizeof(struct GUID)) {
436                         TALLOC_FREE(pinfo2);
437                         return false;
438                 }
439                 memcpy(guid, data, sizeof(struct GUID));
440                 break;
441         default:
442                 DEBUG(0,("is_printer_published: GUID value stored as "
443                          "invaluid type (%d)\n", type));
444                 break;
445         }
446
447 done:
448         if (info2) {
449                 *info2 = talloc_move(mem_ctx, &pinfo2);
450         }
451         talloc_free(pinfo2);
452         return true;
453 }
454 #else
455 WERROR nt_printer_publish(TALLOC_CTX *mem_ctx,
456                           struct auth_serversupplied_info *server_info,
457                           struct messaging_context *msg_ctx,
458                           struct spoolss_PrinterInfo2 *pinfo2,
459                           int action)
460 {
461         return WERR_OK;
462 }
463
464 WERROR check_published_printers(struct messaging_context *msg_ctx)
465 {
466         return WERR_OK;
467 }
468
469 bool is_printer_published(TALLOC_CTX *mem_ctx,
470                           struct auth_serversupplied_info *server_info,
471                           struct messaging_context *msg_ctx,
472                           char *servername, char *printer, struct GUID *guid,
473                           struct spoolss_PrinterInfo2 **info2)
474 {
475         return False;
476 }
477 #endif /* HAVE_ADS */