Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2009-09-20 | Initial implementation of security descriptor creation in DS | Nadezhda Ivanova | 8 | -14/+459 | |
TODO's: ACE sorting and clarifying the inheritance of object specific ace's. | |||||
2009-09-20 | Disable descriptor module unless enabled in smb.conf | Nadezhda Ivanova | 1 | -0/+29 | |
Since this code may still have some problems, it is not executed by default. To enable descriptor inheritance add: acl:inheritance = true in your smb.conf | |||||
2009-09-20 | talloc: fixed talloc_disable_null_tracking() | Andrew Tridgell | 3 | -1/+30 | |
When we disable null tracking, we need to move any existing objects that are under the null_context to be parented by the true NULL context. We also need a new talloc_enable_null_tracking_no_autofree() function, as the talloc testsuite cannot cope with the moving of the autofree context under the null_context as it wants to check exact counts of objects under the null_context, and smbtorture has a large number of objects in the autofree_context from .init functions | |||||
2009-09-20 | Fixed a difference in domain sid type when SID is provided by user. | Nadezhda Ivanova | 1 | -1/+4 | |
2009-09-20 | s4:ldb_parse - Fix the type of an array entry | Matthias Dieter Wallnöfer | 1 | -1/+1 | |
I found this through a compile warning. Hope that I got this right. | |||||
2009-09-20 | s4:provision_configuration - fix "sPNMappings" | Matthias Dieter Wallnöfer | 1 | -2/+1 | |
I reread some docs about this attributes and it seems that this as mapping attribute isn't host specific but in common for the whole domain. To allow Windows DCs to join our s4 domain sooner or later we have to provide the full attribute. | |||||
2009-09-20 | s4:domainlevel - further improvements | Matthias Dieter Wallnöfer | 1 | -9/+50 | |
- The tool displays now also mixed/interim domain levels and warns about them (s4 isn't capable to run on them) - But it allows now also to raise/step-up from them - It displays now also levels higher than 2008 R2 (altough we don't support them yet) but to be able to get a correct output | |||||
2009-09-20 | blackbox/test_ldb.sh: test searching using OIDs instead of names for ↵ | Stefan Metzmacher | 1 | -0/+16 | |
attributes and classes metze | |||||
2009-09-20 | s4:provision: add the 'resolve_oids' on the top of the module stack | Stefan Metzmacher | 1 | -1/+2 | |
metze | |||||
2009-09-20 | dsdb/samdb: add resolve_oids module | Stefan Metzmacher | 2 | -0/+438 | |
Windows Servers allow OID strings to be used instead of attribute/class names. For now we only resolve the OIDs in the search expressions, the rest will follow. metze | |||||
2009-09-20 | s4:build: require ldb 0.9.7 | Stefan Metzmacher | 1 | -1/+1 | |
metze | |||||
2009-09-20 | s4:ldb: add ldb_parse_tree_copy_shallow() and change version to 0.9.7 | Stefan Metzmacher | 3 | -1/+65 | |
metze | |||||
2009-09-20 | librpc: rerun 'make idl' | Stefan Metzmacher | 2 | -3/+3 | |
metze | |||||
2009-09-20 | drsblobs.idl: fix repsFromTo2 blob size calculation | Stefan Metzmacher | 1 | -1/+1 | |
metze | |||||
2009-09-20 | rerun: make idl | Stefan Metzmacher | 3 | -0/+324 | |
metze | |||||
2009-09-20 | drsblobs.idl: add decoding for repsFromTo2 | Stefan Metzmacher | 1 | -0/+30 | |
This is used in windows 2008. metze | |||||
2009-09-19 | s4-auth: add SID_NT_ENTERPRISE_DCS is a server trust account | Andrew Tridgell | 1 | -1/+13 | |
2009-09-19 | s4-drs: security checking on DRS needs to default to on | Andrew Tridgell | 1 | -1/+2 | |
2009-09-19 | s4-ldb: display an error if we can't decode a NDR blob | Andrew Tridgell | 1 | -1/+3 | |
2009-09-19 | s4-repl: need param.h for lp_parm_bool | Andrew Tridgell | 1 | -0/+1 | |
2009-09-19 | Handle dsdb_class_by_lDAPDisplayName returned values in schema_inferiors.c | Anatoliy Atanasov | 1 | -0/+8 | |
2009-09-19 | Move replmd_drsuapi_DsReplicaCursor2_compare to a common place. | Anatoliy Atanasov | 3 | -14/+8 | |
2009-09-19 | Add drs_security_level_check for dcesrv calls security checks | Anatoliy Atanasov | 6 | -20/+36 | |
There is also an option to disable the security check by specifying in the smb.conf file: drs:disable_sec_check = true | |||||
2009-09-20 | s4:provision_basedn_modify - fix the "auditPolicy" attribute | Matthias Dieter Wallnöfer | 1 | -1/+2 | |
I had to think about how to encode the string 0x0001 (taken from Windows Server). The problem is due to the "0" byte at the beginning of it. BASE64 encoding seems a good method to do it. | |||||
2009-09-19 | s4:utils Remove typo... | Andrew Bartlett | 1 | -1/+0 | |
2009-09-19 | s4:dsdb Print the partition we failed to suggest replication for | Andrew Bartlett | 1 | -1/+2 | |
2009-09-19 | libcli:nbt move prototypes of lmhosts functions to libnbt.h | Andrew Bartlett | 2 | -5/+6 | |
2009-09-19 | s4:utils Explian fix for testparm -v | Andrew Bartlett | 1 | -2/+6 | |
The problem here was that we take an address of a bool, and then (via a void*) cast it to a int *, so put this in a comment. Andrew Bartlett | |||||
2009-09-19 | s4-ldb: bump minimum version in ldb too | Andrew Tridgell | 1 | -1/+1 | |
2009-09-19 | more include minimisation | Andrew Tridgell | 12 | -41/+0 | |
2009-09-19 | tdb: increase minor version | Andrew Tridgell | 2 | -2/+2 | |
we depend on reads in transactions for s4 replication | |||||
2009-09-19 | s4-smbd: removed unnecessary includes | Andrew Tridgell | 5 | -11/+0 | |
2009-09-19 | s4-scripts: make minimal_includes handle our -I overrides | Andrew Tridgell | 1 | -10/+20 | |
2009-09-19 | s4-smbd: minimise includes in smbd/ and smb_server | Andrew Tridgell | 21 | -40/+0 | |
2009-09-19 | s4-testparm: fixed -v option | Andrew Tridgell | 1 | -1/+1 | |
never pass a bool pointer to popt | |||||
2009-09-19 | s4-rpc_server: removed remaining unnecessary #includes | Andrew Tridgell | 4 | -5/+2 | |
2009-09-19 | s4-rpc: remove some unnecessary #include lines | Andrew Tridgell | 4 | -8/+0 | |
I should remember to run script/minimal_includes.pl more often | |||||
2009-09-19 | s4:samdb.py - further rework | Matthias Dieter Wallnöfer | 1 | -12/+9 | |
- I added a comment to the "new user" operation to point out that this works only on s4, since we add also ID mapping entries for winbind there - The "new user" operation adds now the password through the "set password" operation which I find better due to the re-use principle - Remove the word "DC" after "SAMBA 4" in the comment over the "set password" operation since this note and operation applies also to s4 in standalone mode | |||||
2009-09-19 | pidl: update expected output for NDR64 changes | Andrew Tridgell | 1 | -1/+1 | |
2009-09-19 | s4-netlogon: implement dcesrv_netr_DsRAddressToSitenamesExW | Andrew Tridgell | 1 | -2/+24 | |
We don't implement sites properly at the moment so we just return Default-First-Site-Name | |||||
2009-09-19 | s4-resolve: fixed a crash bug on timeout | Andrew Tridgell | 9 | -11/+13 | |
We were creating the name resolution context as a child of lp_ctx, which meant when we gave up on a connection the timer on name resolution kept running, and when it timed out the callback crashed as the socket was already removed. | |||||
2009-09-18 | s4-pipes: convert pipe names to lowercase and validate | Andrew Tridgell | 1 | -0/+19 | |
clients may provide arbitrary names, but we only want lowercase alnum names | |||||
2009-09-18 | s4-server: kill main daemon if a task fails to initialise | Andrew Tridgell | 25 | -77/+159 | |
When one of our core tasks fails to initialise it can now ask for the server as a whole to die, rather than limping along in a degraded state. | |||||
2009-09-18 | s4-kdc: ignore unknown keytypes | Andrew Tridgell | 1 | -0/+6 | |
don't fail hdb operations if one of the key types is unknown | |||||
2009-09-18 | Merge branch 'master' of /home/tridge/samba/git/combined | Andrew Tridgell | 38 | -686/+2020 | |
2009-09-18 | s4-drs: cope with dupliate linked attributes | Andrew Tridgell | 1 | -1/+41 | |
With a w2k8-R2 DC, we sometimes get linked attribute updates via DRS which are duplicates of entries that we already have. We need to cope with this by using a remove/add pair in the ldb_modify() to avoid a "entry already exists" error | |||||
2009-09-18 | s4:provision_configuration - "sPNMappings": "http" missed on regeneration | Matthias Dieter Wallnöfer | 1 | -1/+1 | |
2009-09-18 | s4/provision_configuration - re-add the "sPNMappings" | Matthias Dieter Wallnöfer | 1 | -0/+3 | |
Accidentally removed by a previous commit. | |||||
2009-09-18 | s4:scripts - Cleans also the rest under the "setup" directory up | Matthias Dieter Wallnöfer | 3 | -30/+43 | |
- I removed also the "-H" parameter since those scripts are all thought for the use on a local s4 domain controller. Another reason is also the bind as SYSTEM account which itself is only possible on local binds. | |||||
2009-09-18 | s3-rpc_client: fix non initialized structure in rpccli_lsa_lookup_sids_noalloc. | Günther Deschner | 1 | -0/+2 | |
Guenther |