Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2010-01-10 | s4:provision_users.ldif - Import all essential groups for Windows Server ↵ | Matthias Dieter Wallnöfer | 1 | -85/+113 | |
2008 mode Additionally I had to fix some bugs (especially wrong "groupTypes") and reordered the objects using the SID (this is easier when enhancing the file). | |||||
2010-01-10 | s4-ldb: display security descriptors with correct SDL for known SIDs | Andrew Tridgell | 2 | -1/+7 | |
This makes it much easier to compare SDs | |||||
2010-01-10 | s4-dsdb: added samdb_domain_sid_cache_only() | Andrew Tridgell | 1 | -1/+8 | |
2010-01-09 | s3: Remove a pointless "else" branch from add_ccache_to_list() | Volker Lendecke | 1 | -4/+3 | |
2010-01-09 | s3: Slightly simplify winbindd_store_creds | Volker Lendecke | 1 | -4/+2 | |
2010-01-09 | s3: Fix a segfault in winbindd_dual_ccache_ntlm_auth() | Volker Lendecke | 1 | -1/+1 | |
ntlmssp_update allocates the reply_blob as a child of ntlmssp_state. This means with ntlmss_end() it will be gone. winbindd_dual_ccache_ntlm_auth used the blob after the ntlmssp_end(). | |||||
2010-01-09 | s4-drs: instanceType is always sent, regardless of UDV values | Andrew Tridgell | 1 | -4/+6 | |
2010-01-09 | s4-debug: lower the verbosity of a couple of common log messages | Andrew Tridgell | 2 | -2/+2 | |
2010-01-09 | s4-samldb: fixed primaryGroupID when promoting a machine to a DC | Andrew Tridgell | 1 | -17/+30 | |
The machine gets a primaryGroupID of DOMAIN_RID_DCS. This is done without changing the member attributes of its groups. | |||||
2010-01-09 | s4-schema: fixed the SDDL for the schema root security descriptor | Andrew Tridgell | 1 | -10/+14 | |
This was preventing a DCPROMO client from allowing outgoing replication | |||||
2010-01-09 | s4-drs: add a local UDV entry even when no replUpToDateVector present on NC | Andrew Tridgell | 1 | -3/+3 | |
This allows us to filter correctly for a NC that we have created but not pulled from anyone. | |||||
2010-01-09 | s4-drs: give DN of failed replication partition | Andrew Tridgell | 1 | -4/+5 | |
2010-01-09 | s4-drs: base is_nc_prefix on instanceType | Andrew Tridgell | 1 | -1/+3 | |
for extended operations comparing to the ncRoot_dn is not correct | |||||
2010-01-09 | s4-drs: having no SPNs to change is not an error | Andrew Tridgell | 1 | -0/+7 | |
2010-01-09 | s4-drs: fixed writespn to ignore add/delete errors | Andrew Tridgell | 1 | -3/+40 | |
When a SPN is added and already exists, it is ignored. Similarly, when a SPN is deleted and doesn't exist, it is ignored. | |||||
2010-01-09 | s4-dsdb: added samdb_ldb_val_case_cmp() | Andrew Tridgell | 1 | -0/+16 | |
2010-01-09 | s4-drs: moved the DsWriteAccountSpn call to its own file | Andrew Tridgell | 4 | -75/+104 | |
2010-01-09 | s4-libnet: dsdb_wellknown_dn() in vampire code | Andrew Tridgell | 1 | -60/+17 | |
2010-01-09 | s4-drs: need to set the getncchanges extended_ret on success too | Andrew Tridgell | 1 | -0/+3 | |
2010-01-09 | s4-drs: calculate and send a uptodateness_vector with replication requests | Andrew Tridgell | 2 | -7/+82 | |
This stops us getting objects changes twice if they came via an indirect path. | |||||
2010-01-09 | s4-drs: be less verbose when we filter objects by UDV | Andrew Tridgell | 1 | -5/+5 | |
2010-01-09 | s4-drs: added filtering by udv in getncchanges | Andrew Tridgell | 2 | -9/+63 | |
When a client supplied an uptodateness_vector, we can use it to filter what objects we return. This greatly reduces the amount of replication traffic between DCs. | |||||
2010-01-09 | s4-idl: give a enum for attribute cn and a 'NONE' attribute | Andrew Tridgell | 3 | -2/+10 | |
The 'NONE' attribute has value 0xFFFFFFFF. Adding this ensures the compiler will complain if it is set to use 16 bit enums. We rely on being able to store 32 bits in an attid enum. | |||||
2010-01-09 | s4-drs: fixed the NC in the getncchanges RID alloc reply | Andrew Tridgell | 1 | -11/+13 | |
the search happens on a different DN to the NC of the request, but the reply is with the original NC | |||||
2010-01-09 | s4-debug: removed debug_ctx(). It didn't catch on :-) | Andrew Tridgell | 1 | -4/+0 | |
There was only one user, which isn't worth it for the overhead. | |||||
2010-01-09 | s4-messaging: remove only usage of debug_ctx() | Andrew Tridgell | 1 | -2/+4 | |
2010-01-09 | s4-messaging: fixed a memory leak in messaging_path() | Andrew Tridgell | 1 | -2/+9 | |
It is a bit convoluted to fix, as cluster_id_string() may return a const string. | |||||
2010-01-09 | s4-drs: fixed usage of ldb_dn_new() | Andrew Tridgell | 1 | -1/+1 | |
2010-01-09 | s4-ldb: validate the type of the ldb argument to ldb_dn_new() | Andrew Tridgell | 1 | -1/+7 | |
It has been a common bug to get the first two arguments the wrong way around | |||||
2010-01-08 | Fix comment | Simo Sorce | 1 | -1/+1 | |
2010-01-08 | Re-fix bug 5202 - cannot change ACLs on writable file with "dos filemode=yes" | Jeremy Allison | 1 | -0/+3 | |
This bug re-occurred for 3.3.x and above. The reason is that to change a NT ACL we now have to open the file requesting WRITE_DAC and WRITE_OWNER access. The mapping from POSIX "w" to NT permissions in posix_acls doesn't add these bits when "dos filemode = yes", so even though the permission or owner change would be allowed by the POSIX ACL code, the NTCreateX call fails with ACCESS_DENIED now we always check NT permissions first. Added in the mapping from "w" to WRITE_DAC and WRITE_OWNER access. Jeremy. | |||||
2010-01-08 | s4:provision_self_join.ldif - Adapt comment after implementation of ↵ | Matthias Dieter Wallnöfer | 1 | -2/+2 | |
distributed RIDs | |||||
2010-01-08 | s4-kdc: Migrate tcp connections to tsocket. | Andreas Schneider | 1 | -89/+188 | |
Signed-off-by: Stefan Metzmacher <metze@samba.org> | |||||
2010-01-08 | s4:kdc: use LIBSAMBA_TSOCKET | Stefan Metzmacher | 1 | -1/+1 | |
metze | |||||
2010-01-08 | s4:kdc: the ->process function returns "bool" | Stefan Metzmacher | 1 | -9/+9 | |
metze | |||||
2010-01-08 | libcli/util: add tstream_read_pdu_blob_send/recv | Stefan Metzmacher | 3 | -0/+251 | |
This will take the some full_request callback function as the Samba4 packet code. metze | |||||
2010-01-08 | s3-time: fix build warnings after we moved to shared time functions. | Günther Deschner | 1 | -6/+6 | |
Bjoern, please check. Guenther | |||||
2010-01-08 | s3-docs: mention -K option in pdbedit manpage. | Günther Deschner | 1 | -0/+1 | |
Guenther | |||||
2010-01-08 | s4-drs: added two more SPNs in addentry | Andrew Tridgell | 1 | -13/+32 | |
w2k8r2 wants these after a DCPROMO Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: fixes for W2K8-R2 schema | Andrew Tridgell | 2 | -35/+143 | |
The schema from WSPP had a number of typos that prevented it from working. These changes allow it to work with Samba, and allow w2k8r2 to run DCPROMO against Samba successfully Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: added msDS-NcType to schema container | Andrew Tridgell | 1 | -0/+1 | |
Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: fixed attributes of aggregate schema | Andrew Tridgell | 1 | -0/+2 | |
Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: switch to W2K8-R2 schema | Andrew Tridgell | 1 | -2/+2 | |
Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: added adminDisplayName and adminDescription | Andrew Tridgell | 1 | -0/+2 | |
These are missing from the WSPP schemas Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org> | |||||
2010-01-08 | s4-schema: added some debug for bad attributes | Andrew Tridgell | 1 | -0/+8 | |
2010-01-08 | s4-provision: added W2K8-R2 schema as provided by WSPP | Andrew Tridgell | 2 | -0/+19529 | |
2010-01-08 | s4-samba3samtest: we need to force netbios name as well | Andrew Tridgell | 1 | -0/+1 | |
needed for when run in CLIENT context | |||||
2010-01-08 | s4-samba3sid: fixed error returns when res->count != 1 and oom | Andrew Tridgell | 1 | -3/+3 | |
2010-01-08 | s4-samba3samtest: force workgroup so the domain is right | Andrew Tridgell | 1 | -0/+1 | |
the samba3sid backend looks at lp_sam_name() which is based on the workgroup | |||||
2010-01-08 | s4-samba3sid: the sambaNextRid attribute is actually the previous RID | Andrew Tridgell | 1 | -3/+6 | |
Not well named .... though same mistake that MS made with rIDNextRid |