Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2009-09-20 | s4:ldb: add ldb_parse_tree_copy_shallow() and change version to 0.9.7 | Stefan Metzmacher | 3 | -1/+65 | |
metze | |||||
2009-09-19 | s4-auth: add SID_NT_ENTERPRISE_DCS is a server trust account | Andrew Tridgell | 1 | -1/+13 | |
2009-09-19 | s4-drs: security checking on DRS needs to default to on | Andrew Tridgell | 1 | -1/+2 | |
2009-09-19 | s4-ldb: display an error if we can't decode a NDR blob | Andrew Tridgell | 1 | -1/+3 | |
2009-09-19 | s4-repl: need param.h for lp_parm_bool | Andrew Tridgell | 1 | -0/+1 | |
2009-09-19 | Handle dsdb_class_by_lDAPDisplayName returned values in schema_inferiors.c | Anatoliy Atanasov | 1 | -0/+8 | |
2009-09-19 | Move replmd_drsuapi_DsReplicaCursor2_compare to a common place. | Anatoliy Atanasov | 3 | -14/+8 | |
2009-09-19 | Add drs_security_level_check for dcesrv calls security checks | Anatoliy Atanasov | 6 | -20/+36 | |
There is also an option to disable the security check by specifying in the smb.conf file: drs:disable_sec_check = true | |||||
2009-09-20 | s4:provision_basedn_modify - fix the "auditPolicy" attribute | Matthias Dieter Wallnöfer | 1 | -1/+2 | |
I had to think about how to encode the string 0x0001 (taken from Windows Server). The problem is due to the "0" byte at the beginning of it. BASE64 encoding seems a good method to do it. | |||||
2009-09-19 | s4:utils Remove typo... | Andrew Bartlett | 1 | -1/+0 | |
2009-09-19 | s4:dsdb Print the partition we failed to suggest replication for | Andrew Bartlett | 1 | -1/+2 | |
2009-09-19 | s4:utils Explian fix for testparm -v | Andrew Bartlett | 1 | -2/+6 | |
The problem here was that we take an address of a bool, and then (via a void*) cast it to a int *, so put this in a comment. Andrew Bartlett | |||||
2009-09-19 | s4-ldb: bump minimum version in ldb too | Andrew Tridgell | 1 | -1/+1 | |
2009-09-19 | more include minimisation | Andrew Tridgell | 12 | -41/+0 | |
2009-09-19 | tdb: increase minor version | Andrew Tridgell | 1 | -1/+1 | |
we depend on reads in transactions for s4 replication | |||||
2009-09-19 | s4-smbd: removed unnecessary includes | Andrew Tridgell | 5 | -11/+0 | |
2009-09-19 | s4-scripts: make minimal_includes handle our -I overrides | Andrew Tridgell | 1 | -10/+20 | |
2009-09-19 | s4-smbd: minimise includes in smbd/ and smb_server | Andrew Tridgell | 21 | -40/+0 | |
2009-09-19 | s4-testparm: fixed -v option | Andrew Tridgell | 1 | -1/+1 | |
never pass a bool pointer to popt | |||||
2009-09-19 | s4-rpc_server: removed remaining unnecessary #includes | Andrew Tridgell | 4 | -5/+2 | |
2009-09-19 | s4-rpc: remove some unnecessary #include lines | Andrew Tridgell | 4 | -8/+0 | |
I should remember to run script/minimal_includes.pl more often | |||||
2009-09-19 | s4:samdb.py - further rework | Matthias Dieter Wallnöfer | 1 | -12/+9 | |
- I added a comment to the "new user" operation to point out that this works only on s4, since we add also ID mapping entries for winbind there - The "new user" operation adds now the password through the "set password" operation which I find better due to the re-use principle - Remove the word "DC" after "SAMBA 4" in the comment over the "set password" operation since this note and operation applies also to s4 in standalone mode | |||||
2009-09-19 | s4-netlogon: implement dcesrv_netr_DsRAddressToSitenamesExW | Andrew Tridgell | 1 | -2/+24 | |
We don't implement sites properly at the moment so we just return Default-First-Site-Name | |||||
2009-09-19 | s4-resolve: fixed a crash bug on timeout | Andrew Tridgell | 9 | -11/+13 | |
We were creating the name resolution context as a child of lp_ctx, which meant when we gave up on a connection the timer on name resolution kept running, and when it timed out the callback crashed as the socket was already removed. | |||||
2009-09-18 | s4-pipes: convert pipe names to lowercase and validate | Andrew Tridgell | 1 | -0/+19 | |
clients may provide arbitrary names, but we only want lowercase alnum names | |||||
2009-09-18 | s4-server: kill main daemon if a task fails to initialise | Andrew Tridgell | 25 | -77/+159 | |
When one of our core tasks fails to initialise it can now ask for the server as a whole to die, rather than limping along in a degraded state. | |||||
2009-09-18 | s4-kdc: ignore unknown keytypes | Andrew Tridgell | 1 | -0/+6 | |
don't fail hdb operations if one of the key types is unknown | |||||
2009-09-18 | s4-drs: cope with dupliate linked attributes | Andrew Tridgell | 1 | -1/+41 | |
With a w2k8-R2 DC, we sometimes get linked attribute updates via DRS which are duplicates of entries that we already have. We need to cope with this by using a remove/add pair in the ldb_modify() to avoid a "entry already exists" error | |||||
2009-09-18 | s4:provision_configuration - "sPNMappings": "http" missed on regeneration | Matthias Dieter Wallnöfer | 1 | -1/+1 | |
2009-09-18 | s4/provision_configuration - re-add the "sPNMappings" | Matthias Dieter Wallnöfer | 1 | -0/+3 | |
Accidentally removed by a previous commit. | |||||
2009-09-18 | s4:scripts - Cleans also the rest under the "setup" directory up | Matthias Dieter Wallnöfer | 3 | -30/+43 | |
- I removed also the "-H" parameter since those scripts are all thought for the use on a local s4 domain controller. Another reason is also the bind as SYSTEM account which itself is only possible on local binds. | |||||
2009-09-18 | s4:various scripts under "setup" - Unification | Matthias Dieter Wallnöfer | 4 | -73/+74 | |
- This unified the shape of those four scripts (comments, command sequence, call of SamDB) - To consider the samdb.py changes regarding the filter: there is now always the possibility either to specify the username or the search filter | |||||
2009-09-18 | s4:domainlevel/pwsettings - Remove unused import | Matthias Dieter Wallnöfer | 2 | -2/+0 | |
2009-09-18 | s4:samdb.py - Unification of the interfaces | Matthias Dieter Wallnöfer | 2 | -38/+54 | |
- When a user account is requested by a call always the search filter will be passed as argument. This helps us to unify the API - Add/fix some comments; in particular new comments inform the developer which requirements exist if he wants to use calls which manipulate the "userPassword" attribute (On s4 no problem - but on certain domain levels on Windows Server) | |||||
2009-09-18 | s4:minschema/fullschema - add correct header comments | Matthias Dieter Wallnöfer | 2 | -2/+2 | |
2009-09-18 | s4:rpc_server: remove some now unused code | Stefan Metzmacher | 2 | -199/+0 | |
metze | |||||
2009-09-18 | s4:ntvfs_ipc: add real named pipe support | Stefan Metzmacher | 2 | -236/+652 | |
We now open a named via the named_pipe_auth code and process IO via the tstream interface. This means we support byte mode and message mode named pipes. We also correctly issue NT_STATUS_PIPE_BUSY when a smb_trans request comes in and a read or smb_trans is already pending. We also have support for async dcerpc over ncacn_np now, and we now can remove the ncacn_np specific hacks from the rpc_server/ code. metze | |||||
2009-09-18 | s4:torture: the spoolss notify test should listen on the ncacn_np endpoint | Stefan Metzmacher | 1 | -0/+20 | |
metze | |||||
2009-09-18 | s4:rpc_server: export dcesrv_add_ep() so that torture tests can use it | Stefan Metzmacher | 2 | -5/+9 | |
metze | |||||
2009-09-18 | s4:service_named_pipe: accept delegated credentials | Stefan Metzmacher | 2 | -3/+101 | |
metze | |||||
2009-09-18 | s4:torture: don't use 'pipe' as variable name it's a system call | Stefan Metzmacher | 1 | -3/+3 | |
metze | |||||
2009-09-18 | s4:heimdal/gssapi/krb5: set cred_handle in _gsskrb5_import_cred | Stefan Metzmacher | 1 | -0/+1 | |
metze | |||||
2009-09-18 | s4:domainlevel - fix indentations | Matthias Dieter Wallnöfer | 1 | -4/+4 | |
2009-09-18 | s4:domainlevel - Add a script which allows raising the domain/forest level | Matthias Dieter Wallnöfer | 1 | -0/+181 | |
This simple script allows raising the domain and/or forest level for s4. I integrated also the basic checks (since we don't perform them in LDB yet): e.g. the forest level can't be higher than the domain level(s). | |||||
2009-09-18 | s4:pwsettings - Simplify the error handling a bit | Matthias Dieter Wallnöfer | 1 | -5/+2 | |
2009-09-18 | python: create a script for reorgnizing an LDB file. | Matthieu Patou | 1 | -0/+60 | |
This script helps to reclaim waisted place. | |||||
2009-09-18 | s4:provision - Bump down the domain and forest level to Windows 2000 | Matthias Dieter Wallnöfer | 2 | -9/+10 | |
- The DC level we keep on Windows Server 2008 R2 (we should call ourself always the newest server type) - The domain/forest level we set to the minimum (Windows 2000 native) to allow all AD DC types (from Windows 2000 on) in our domain - the NT4 "mixed" mode isn't supported by us (discussed on mailing list) -> "nTMixedDomain" is set always to 0 - I'll add a script which allows to bump the DC level (basically sets the "msDS-Behaviour-Version" attributes on the "Partitions/Configuration/DC" and on the "DC" object) | |||||
2009-09-17 | s4:provision - Some rework (continuation) | Matthias Dieter Wallnöfer | 4 | -40/+311 | |
- Fix up "servicePrincipalNames" attributes on the DC object - Add some informative comments (most in "provision_self_join.ldif") - Add also comments where objects are missing which we may add later when we support the feature (mainly for FRS) - Add "domain updates" objects also under "CN=Configuration" (they exist twice) - Add the default services under "Services" to allow interoperability with some MS client tools - Smaller changes | |||||
2009-09-17 | pyldb: Don't segfault when invalid type is specified to as_sddl and from_sddl. | Matthieu Patou | 2 | -2/+19 | |
Fix bug #6723 | |||||
2009-09-17 | s4-sam: add a note about the solaris client | Andrew Tridgell | 1 | -0/+2 | |