2 Unix SMB/CIFS implementation.
6 Copyright (C) Gerald Carter 2006
7 Copyright (C) Guenther Deschner 2007-2008
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #define DSGETDCNAME_FMT "DSGETDCNAME/DOMAIN/%s"
27 #define DSGETDCNAME_CACHE_TTL 60*15
29 struct ip_service_name {
30 struct sockaddr_storage ss;
35 /****************************************************************
36 ****************************************************************/
38 void debug_dsdcinfo_flags(int lvl, uint32_t flags)
40 DEBUG(lvl,("debug_dsdcinfo_flags: 0x%08x\n\t", flags));
42 if (flags & DS_FORCE_REDISCOVERY)
43 DEBUGADD(lvl,("DS_FORCE_REDISCOVERY "));
44 if (flags & 0x000000002)
45 DEBUGADD(lvl,("0x00000002 "));
46 if (flags & 0x000000004)
47 DEBUGADD(lvl,("0x00000004 "));
48 if (flags & 0x000000008)
49 DEBUGADD(lvl,("0x00000008 "));
50 if (flags & DS_DIRECTORY_SERVICE_REQUIRED)
51 DEBUGADD(lvl,("DS_DIRECTORY_SERVICE_REQUIRED "));
52 if (flags & DS_DIRECTORY_SERVICE_PREFERRED)
53 DEBUGADD(lvl,("DS_DIRECTORY_SERVICE_PREFERRED "));
54 if (flags & DS_GC_SERVER_REQUIRED)
55 DEBUGADD(lvl,("DS_GC_SERVER_REQUIRED "));
56 if (flags & DS_PDC_REQUIRED)
57 DEBUGADD(lvl,("DS_PDC_REQUIRED "));
58 if (flags & DS_BACKGROUND_ONLY)
59 DEBUGADD(lvl,("DS_BACKGROUND_ONLY "));
60 if (flags & DS_IP_REQUIRED)
61 DEBUGADD(lvl,("DS_IP_REQUIRED "));
62 if (flags & DS_KDC_REQUIRED)
63 DEBUGADD(lvl,("DS_KDC_REQUIRED "));
64 if (flags & DS_TIMESERV_REQUIRED)
65 DEBUGADD(lvl,("DS_TIMESERV_REQUIRED "));
66 if (flags & DS_WRITABLE_REQUIRED)
67 DEBUGADD(lvl,("DS_WRITABLE_REQUIRED "));
68 if (flags & DS_GOOD_TIMESERV_PREFERRED)
69 DEBUGADD(lvl,("DS_GOOD_TIMESERV_PREFERRED "));
70 if (flags & DS_AVOID_SELF)
71 DEBUGADD(lvl,("DS_AVOID_SELF "));
72 if (flags & DS_ONLY_LDAP_NEEDED)
73 DEBUGADD(lvl,("DS_ONLY_LDAP_NEEDED "));
74 if (flags & DS_IS_FLAT_NAME)
75 DEBUGADD(lvl,("DS_IS_FLAT_NAME "));
76 if (flags & DS_IS_DNS_NAME)
77 DEBUGADD(lvl,("DS_IS_DNS_NAME "));
78 if (flags & 0x00040000)
79 DEBUGADD(lvl,("0x00040000 "));
80 if (flags & 0x00080000)
81 DEBUGADD(lvl,("0x00080000 "));
82 if (flags & 0x00100000)
83 DEBUGADD(lvl,("0x00100000 "));
84 if (flags & 0x00200000)
85 DEBUGADD(lvl,("0x00200000 "));
86 if (flags & 0x00400000)
87 DEBUGADD(lvl,("0x00400000 "));
88 if (flags & 0x00800000)
89 DEBUGADD(lvl,("0x00800000 "));
90 if (flags & 0x01000000)
91 DEBUGADD(lvl,("0x01000000 "));
92 if (flags & 0x02000000)
93 DEBUGADD(lvl,("0x02000000 "));
94 if (flags & 0x04000000)
95 DEBUGADD(lvl,("0x04000000 "));
96 if (flags & 0x08000000)
97 DEBUGADD(lvl,("0x08000000 "));
98 if (flags & 0x10000000)
99 DEBUGADD(lvl,("0x10000000 "));
100 if (flags & 0x20000000)
101 DEBUGADD(lvl,("0x20000000 "));
102 if (flags & DS_RETURN_DNS_NAME)
103 DEBUGADD(lvl,("DS_RETURN_DNS_NAME "));
104 if (flags & DS_RETURN_FLAT_NAME)
105 DEBUGADD(lvl,("DS_RETURN_FLAT_NAME "));
107 DEBUGADD(lvl,("\n"));
110 /****************************************************************
111 ****************************************************************/
113 static char *dsgetdcname_cache_key(TALLOC_CTX *mem_ctx, const char *domain)
115 if (!mem_ctx || !domain) {
119 return talloc_asprintf_strupper_m(mem_ctx, DSGETDCNAME_FMT, domain);
122 /****************************************************************
123 ****************************************************************/
125 static NTSTATUS dsgetdcname_cache_delete(TALLOC_CTX *mem_ctx,
126 const char *domain_name)
130 if (!gencache_init()) {
131 return NT_STATUS_INTERNAL_DB_ERROR;
134 key = dsgetdcname_cache_key(mem_ctx, domain_name);
136 return NT_STATUS_NO_MEMORY;
139 if (!gencache_del(key)) {
140 return NT_STATUS_UNSUCCESSFUL;
146 /****************************************************************
147 ****************************************************************/
149 static NTSTATUS dsgetdcname_cache_store(TALLOC_CTX *mem_ctx,
150 const char *domain_name,
151 struct netr_DsRGetDCNameInfo *info)
157 enum ndr_err_code ndr_err;
159 if (!gencache_init()) {
160 return NT_STATUS_INTERNAL_DB_ERROR;
163 key = dsgetdcname_cache_key(mem_ctx, domain_name);
165 return NT_STATUS_NO_MEMORY;
168 expire_time = time(NULL) + DSGETDCNAME_CACHE_TTL;
170 ndr_err = ndr_push_struct_blob(&blob, mem_ctx, info,
171 (ndr_push_flags_fn_t)ndr_push_netr_DsRGetDCNameInfo);
172 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
173 return ndr_map_error2ntstatus(ndr_err);
176 if (gencache_lock_entry(key) != 0) {
177 data_blob_free(&blob);
178 return NT_STATUS_LOCK_NOT_GRANTED;
181 ret = gencache_set_data_blob(key, &blob, expire_time);
182 data_blob_free(&blob);
184 gencache_unlock_entry(key);
186 return ret ? NT_STATUS_OK : NT_STATUS_UNSUCCESSFUL;
189 /****************************************************************
190 ****************************************************************/
192 static NTSTATUS dsgetdcname_cache_refresh(TALLOC_CTX *mem_ctx,
193 const char *domain_name,
194 struct GUID *domain_guid,
196 const char *site_name,
197 struct netr_DsRGetDCNameInfo *info)
199 struct nbt_cldap_netlogon_5 r;
201 /* check if matching entry is older then 15 minutes, if yes, send
202 * CLDAP/MAILSLOT ping again and store the cached data */
206 if (ads_cldap_netlogon(mem_ctx, info->dc_unc,
207 info->domain_name, &r)) {
209 dsgetdcname_cache_delete(mem_ctx, domain_name);
211 return dsgetdcname_cache_store(mem_ctx,
216 return NT_STATUS_INVALID_NETWORK_RESPONSE;
219 /****************************************************************
220 ****************************************************************/
222 #define RETURN_ON_FALSE(x) if (!x) return false;
224 static bool check_cldap_reply_required_flags(uint32_t ret_flags,
227 if (req_flags & DS_PDC_REQUIRED)
228 RETURN_ON_FALSE(ret_flags & NBT_SERVER_PDC);
230 if (req_flags & DS_GC_SERVER_REQUIRED)
231 RETURN_ON_FALSE(ret_flags & NBT_SERVER_GC);
233 if (req_flags & DS_ONLY_LDAP_NEEDED)
234 RETURN_ON_FALSE(ret_flags & NBT_SERVER_LDAP);
236 if ((req_flags & DS_DIRECTORY_SERVICE_REQUIRED) ||
237 (req_flags & DS_DIRECTORY_SERVICE_PREFERRED))
238 RETURN_ON_FALSE(ret_flags & NBT_SERVER_DS);
240 if (req_flags & DS_KDC_REQUIRED)
241 RETURN_ON_FALSE(ret_flags & NBT_SERVER_KDC);
243 if (req_flags & DS_TIMESERV_REQUIRED)
244 RETURN_ON_FALSE(ret_flags & NBT_SERVER_TIMESERV);
246 if (req_flags & DS_WRITABLE_REQUIRED)
247 RETURN_ON_FALSE(ret_flags & NBT_SERVER_WRITABLE);
252 /****************************************************************
253 ****************************************************************/
255 static NTSTATUS dsgetdcname_cache_fetch(TALLOC_CTX *mem_ctx,
256 const char *domain_name,
257 struct GUID *domain_guid,
259 const char *site_name,
260 struct netr_DsRGetDCNameInfo **info_p,
265 enum ndr_err_code ndr_err;
266 struct netr_DsRGetDCNameInfo *info;
268 if (!gencache_init()) {
269 return NT_STATUS_INTERNAL_DB_ERROR;
272 key = dsgetdcname_cache_key(mem_ctx, domain_name);
274 return NT_STATUS_NO_MEMORY;
277 if (!gencache_get_data_blob(key, &blob, expired)) {
278 return NT_STATUS_OBJECT_NAME_NOT_FOUND;
281 info = TALLOC_ZERO_P(mem_ctx, struct netr_DsRGetDCNameInfo);
283 return NT_STATUS_NO_MEMORY;
286 ndr_err = ndr_pull_struct_blob(&blob, mem_ctx, info,
287 (ndr_pull_flags_fn_t)ndr_pull_netr_DsRGetDCNameInfo);
289 data_blob_free(&blob);
290 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
291 dsgetdcname_cache_delete(mem_ctx, domain_name);
292 return ndr_map_error2ntstatus(ndr_err);
295 if (DEBUGLEVEL >= 10) {
296 NDR_PRINT_DEBUG(netr_DsRGetDCNameInfo, info);
300 if (!check_cldap_reply_required_flags(info->dc_flags, flags)) {
301 DEBUG(10,("invalid flags\n"));
302 return NT_STATUS_INVALID_PARAMETER;
305 if ((flags & DS_IP_REQUIRED) &&
306 (info->dc_address_type != DS_ADDRESS_TYPE_INET)) {
307 return NT_STATUS_INVALID_PARAMETER_MIX;
315 /****************************************************************
316 ****************************************************************/
318 static NTSTATUS dsgetdcname_cached(TALLOC_CTX *mem_ctx,
319 const char *domain_name,
320 struct GUID *domain_guid,
322 const char *site_name,
323 struct netr_DsRGetDCNameInfo **info)
326 bool expired = false;
328 status = dsgetdcname_cache_fetch(mem_ctx, domain_name, domain_guid,
329 flags, site_name, info, &expired);
330 if (!NT_STATUS_IS_OK(status)) {
331 DEBUG(10,("dsgetdcname_cached: cache fetch failed with: %s\n",
333 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
336 if (flags & DS_BACKGROUND_ONLY) {
341 status = dsgetdcname_cache_refresh(mem_ctx, domain_name,
344 if (!NT_STATUS_IS_OK(status)) {
352 /****************************************************************
353 ****************************************************************/
355 static bool check_allowed_required_flags(uint32_t flags)
357 uint32_t return_type = flags & (DS_RETURN_FLAT_NAME|DS_RETURN_DNS_NAME);
358 uint32_t offered_type = flags & (DS_IS_FLAT_NAME|DS_IS_DNS_NAME);
359 uint32_t query_type = flags & (DS_BACKGROUND_ONLY|DS_FORCE_REDISCOVERY);
361 /* FIXME: check for DSGETDC_VALID_FLAGS and check for excluse bits
362 * (DS_PDC_REQUIRED, DS_KDC_REQUIRED, DS_GC_SERVER_REQUIRED) */
364 debug_dsdcinfo_flags(10, flags);
366 if (return_type == (DS_RETURN_FLAT_NAME|DS_RETURN_DNS_NAME)) {
370 if (offered_type == (DS_IS_DNS_NAME|DS_IS_FLAT_NAME)) {
374 if (query_type == (DS_BACKGROUND_ONLY|DS_FORCE_REDISCOVERY)) {
379 if ((flags & DS_RETURN_DNS_NAME) && (!(flags & DS_IP_REQUIRED))) {
380 printf("gd: here5 \n");
387 /****************************************************************
388 ****************************************************************/
390 static NTSTATUS discover_dc_netbios(TALLOC_CTX *mem_ctx,
391 const char *domain_name,
393 struct ip_service_name **returned_dclist,
396 if (lp_disable_netbios()) {
397 return NT_STATUS_NOT_SUPPORTED;
400 /* FIXME: code here */
402 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
405 /****************************************************************
406 ****************************************************************/
408 static NTSTATUS discover_dc_dns(TALLOC_CTX *mem_ctx,
409 const char *domain_name,
410 struct GUID *domain_guid,
412 const char *site_name,
413 struct ip_service_name **returned_dclist,
418 struct dns_rr_srv *dcs = NULL;
421 struct ip_service_name *dclist = NULL;
424 if ((!(flags & DS_DIRECTORY_SERVICE_REQUIRED)) &&
425 (!(flags & DS_KDC_REQUIRED)) &&
426 (!(flags & DS_GC_SERVER_REQUIRED)) &&
427 (!(flags & DS_PDC_REQUIRED))) {
428 DEBUG(1,("discover_dc_dns: invalid flags\n"));
429 return NT_STATUS_INVALID_PARAMETER;
432 if (flags & DS_PDC_REQUIRED) {
433 status = ads_dns_query_pdc(mem_ctx, domain_name,
435 } else if (flags & DS_GC_SERVER_REQUIRED) {
436 status = ads_dns_query_gcs(mem_ctx, domain_name, site_name,
438 } else if (flags & DS_KDC_REQUIRED) {
439 status = ads_dns_query_kdcs(mem_ctx, domain_name, site_name,
441 } else if (flags & DS_DIRECTORY_SERVICE_REQUIRED) {
442 status = ads_dns_query_dcs(mem_ctx, domain_name, site_name,
444 } else if (domain_guid) {
445 status = ads_dns_query_dcs_guid(mem_ctx, domain_name,
446 domain_guid, &dcs, &numdcs);
449 DEBUG(1,("discover_dc_dns: not enough input\n"));
450 status = NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
453 if (!NT_STATUS_IS_OK(status)) {
458 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
461 for (i=0;i<numdcs;i++) {
462 numaddrs += MAX(dcs[i].num_ips,1);
465 dclist = TALLOC_ZERO_ARRAY(mem_ctx,
466 struct ip_service_name,
469 return NT_STATUS_NO_MEMORY;
472 /* now unroll the list of IP addresses */
478 while ((i < numdcs) && (count < numaddrs)) {
480 struct ip_service_name *r = &dclist[count];
482 r->port = dcs[i].port;
483 r->hostname = dcs[i].hostname;
485 if (!(flags & DS_IP_REQUIRED)) {
490 /* If we don't have an IP list for a name, lookup it up */
493 interpret_string_addr(&r->ss, dcs[i].hostname, 0);
497 /* use the IP addresses from the SRV sresponse */
499 if (j >= dcs[i].num_ips) {
505 r->ss = dcs[i].ss_s[j];
509 /* make sure it is a valid IP. I considered checking the
510 * negative connection cache, but this is the wrong place for
511 * it. Maybe only as a hac. After think about it, if all of
512 * the IP addresses retuend from DNS are dead, what hope does a
513 * netbios name lookup have? The standard reason for falling
514 * back to netbios lookups is that our DNS server doesn't know
515 * anything about the DC's -- jerry */
517 if (!is_zero_addr(&r->ss)) {
523 *returned_dclist = dclist;
524 *return_count = count;
530 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
533 /****************************************************************
534 ****************************************************************/
536 static NTSTATUS make_domain_controller_info(TALLOC_CTX *mem_ctx,
538 const char *dc_address,
539 uint32_t dc_address_type,
540 const struct GUID *domain_guid,
541 const char *domain_name,
542 const char *forest_name,
544 const char *dc_site_name,
545 const char *client_site_name,
546 struct netr_DsRGetDCNameInfo **info_out)
548 struct netr_DsRGetDCNameInfo *info;
550 info = TALLOC_ZERO_P(mem_ctx, struct netr_DsRGetDCNameInfo);
551 NT_STATUS_HAVE_NO_MEMORY(info);
554 info->dc_unc = talloc_strdup(mem_ctx, dc_unc);
555 NT_STATUS_HAVE_NO_MEMORY(info->dc_unc);
559 info->dc_address = talloc_strdup(mem_ctx, dc_address);
560 NT_STATUS_HAVE_NO_MEMORY(info->dc_address);
563 info->dc_address_type = dc_address_type;
566 info->domain_guid = *domain_guid;
570 info->domain_name = talloc_strdup(mem_ctx, domain_name);
571 NT_STATUS_HAVE_NO_MEMORY(info->domain_name);
575 info->forest_name = talloc_strdup(mem_ctx, forest_name);
576 NT_STATUS_HAVE_NO_MEMORY(info->forest_name);
579 info->dc_flags = flags;
582 info->dc_site_name = talloc_strdup(mem_ctx, dc_site_name);
583 NT_STATUS_HAVE_NO_MEMORY(info->dc_site_name);
586 if (client_site_name) {
587 info->client_site_name = talloc_strdup(mem_ctx,
589 NT_STATUS_HAVE_NO_MEMORY(info->client_site_name);
597 /****************************************************************
598 ****************************************************************/
600 static NTSTATUS process_dc_dns(TALLOC_CTX *mem_ctx,
601 const char *domain_name,
603 struct ip_service_name *dclist,
605 struct netr_DsRGetDCNameInfo **info)
608 bool valid_dc = false;
609 struct nbt_cldap_netlogon_5 r;
610 const char *dc_hostname, *dc_domain_name;
611 const char *dc_address;
612 uint32_t dc_address_type;
615 for (i=0; i<num_dcs; i++) {
619 DEBUG(10,("LDAP ping to %s\n", dclist[i].hostname));
621 if ((ads_cldap_netlogon(mem_ctx, dclist[i].hostname,
623 (check_cldap_reply_required_flags(r.server_type, flags))) {
632 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
635 dc_flags = r.server_type;
637 if (flags & DS_RETURN_FLAT_NAME) {
638 if (!strlen(r.pdc_name) || !strlen(r.domain)) {
639 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
641 dc_hostname = r.pdc_name;
642 dc_domain_name = r.domain;
643 } else if (flags & DS_RETURN_DNS_NAME) {
644 if (!strlen(r.pdc_dns_name) || !strlen(r.dns_domain)) {
645 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
647 dc_hostname = r.pdc_dns_name;
648 dc_domain_name = r.dns_domain;
649 dc_flags |= DS_DNS_DOMAIN | DS_DNS_CONTROLLER;
652 dc_hostname = r.pdc_dns_name;
653 dc_domain_name = r.dns_domain;
654 dc_flags |= DS_DNS_DOMAIN | DS_DNS_CONTROLLER;
657 if (flags & DS_IP_REQUIRED) {
658 char addr[INET6_ADDRSTRLEN];
659 print_sockaddr(addr, sizeof(addr), &dclist[i].ss);
660 dc_address = talloc_asprintf(mem_ctx, "\\\\%s",
662 dc_address_type = DS_ADDRESS_TYPE_INET;
664 dc_address = talloc_asprintf(mem_ctx, "\\\\%s",
666 dc_address_type = DS_ADDRESS_TYPE_NETBIOS;
668 NT_STATUS_HAVE_NO_MEMORY(dc_address);
671 dc_flags |= DS_DNS_FOREST;
674 return make_domain_controller_info(mem_ctx,
688 /****************************************************************
689 ****************************************************************/
691 static NTSTATUS process_dc_netbios(TALLOC_CTX *mem_ctx,
692 const char *domain_name,
694 struct ip_service_name **dclist,
696 struct netr_DsRGetDCNameInfo **info)
698 /* FIXME: code here */
700 return NT_STATUS_NOT_SUPPORTED;
703 /****************************************************************
704 ****************************************************************/
706 static NTSTATUS dsgetdcname_rediscover(TALLOC_CTX *mem_ctx,
707 const char *domain_name,
708 struct GUID *domain_guid,
710 const char *site_name,
711 struct netr_DsRGetDCNameInfo **info)
713 NTSTATUS status = NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
714 struct ip_service_name *dclist;
717 DEBUG(10,("dsgetdcname_rediscover\n"));
719 if (flags & DS_IS_FLAT_NAME) {
721 status = discover_dc_netbios(mem_ctx, domain_name, flags,
723 NT_STATUS_NOT_OK_RETURN(status);
725 return process_dc_netbios(mem_ctx, domain_name, flags,
726 &dclist, num_dcs, info);
729 if (flags & DS_IS_DNS_NAME) {
731 status = discover_dc_dns(mem_ctx, domain_name, domain_guid,
732 flags, site_name, &dclist, &num_dcs);
733 NT_STATUS_NOT_OK_RETURN(status);
735 return process_dc_dns(mem_ctx, domain_name, flags,
736 dclist, num_dcs, info);
739 status = discover_dc_dns(mem_ctx, domain_name, domain_guid, flags,
740 site_name, &dclist, &num_dcs);
742 if (NT_STATUS_IS_OK(status) && num_dcs != 0) {
744 status = process_dc_dns(mem_ctx, domain_name, flags, dclist,
746 if (NT_STATUS_IS_OK(status)) {
751 status = discover_dc_netbios(mem_ctx, domain_name, flags, &dclist,
753 NT_STATUS_NOT_OK_RETURN(status);
755 return process_dc_netbios(mem_ctx, domain_name, flags, &dclist,
759 /********************************************************************
762 This will be the only public function here.
763 ********************************************************************/
765 NTSTATUS dsgetdcname(TALLOC_CTX *mem_ctx,
766 const char *domain_name,
767 struct GUID *domain_guid,
768 const char *site_name,
770 struct netr_DsRGetDCNameInfo **info)
772 NTSTATUS status = NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND;
773 struct netr_DsRGetDCNameInfo *myinfo = NULL;
775 DEBUG(10,("dsgetdcname: domain_name: %s, "
776 "domain_guid: %s, site_name: %s, flags: 0x%08x\n",
778 domain_guid ? GUID_string(mem_ctx, domain_guid) : "(null)",
783 if (!check_allowed_required_flags(flags)) {
784 DEBUG(0,("invalid flags specified\n"));
785 return NT_STATUS_INVALID_PARAMETER;
788 if (flags & DS_FORCE_REDISCOVERY) {
792 status = dsgetdcname_cached(mem_ctx, domain_name, domain_guid,
793 flags, site_name, &myinfo);
794 if (NT_STATUS_IS_OK(status)) {
799 if (flags & DS_BACKGROUND_ONLY) {
804 status = dsgetdcname_rediscover(mem_ctx, domain_name,
805 domain_guid, flags, site_name,
808 if (NT_STATUS_IS_OK(status)) {
809 dsgetdcname_cache_store(mem_ctx, domain_name, myinfo);