Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2010-05-10 | s4:password_hash LDB module - we might not have a cleartext password at all | Matthias Dieter Wallnöfer | 1 | -26/+29 | |
When we don't have the cleartext of the new password then don't check it using "samdb_check_password". | |||||
2010-05-10 | s4/tort: Add test for comparing special DNs | Kamen Mazdrashki | 1 | -0/+18 | |
2010-05-10 | s4/dn: handle case 'base' dn has no components | Kamen Mazdrashki | 1 | -1/+1 | |
This could if the 'base' dn is special for example. | |||||
2010-05-10 | s4-smbtorture: add smbcli_rap_netoemchangepassword(). | Günther Deschner | 1 | -0/+49 | |
Guenther | |||||
2010-05-10 | s4:password_hash LDB module - quiet a warning | Matthias Dieter Wallnöfer | 1 | -1/+1 | |
2010-05-10 | s4:password hash LDB module - check that password hashes are != NULL before ↵ | Matthias Dieter Wallnöfer | 1 | -6/+10 | |
copying them | |||||
2010-05-10 | s4:password_hash LDB module - don't break the provision | Matthias Dieter Wallnöfer | 1 | -0/+3 | |
This is to don't break the provision process at the moment. We need to find a better solution. | |||||
2010-05-10 | s4:passwords.py - add a python unittest for additional testing of my ↵ | Matthias Dieter Wallnöfer | 2 | -0/+580 | |
passwords work This performs checks on direct password changes over LDB/LDAP. Indirect password changes over the RPCs are already tested by some torture suite (SAMR passwords). So no need to do this again here. | |||||
2010-05-10 | s4:samdb_set_password - adapt it for the user password change handling | Matthias Dieter Wallnöfer | 1 | -0/+12 | |
Make use of the new "change old password checked" control. | |||||
2010-05-10 | s4:samdb_set_password/samdb_set_password_sid - Rework | Matthias Dieter Wallnöfer | 4 | -383/+159 | |
Adapt the two functions for the restructured "password_hash" module. This means that basically all checks are now performed in the mentioned module. An exception consists in the SAMR password change calls since they need very precise NTSTATUS return codes on wrong constraints ("samr_password.c") file | |||||
2010-05-10 | s4:password_hash - Implement password restrictions | Stefan Metzmacher | 1 | -0/+195 | |
Based on the Patch from Matthias Dieter Wallnöfer <mwallnoefer@yahoo.de>. metze | |||||
2010-05-10 | s4:password_hash - Rework to handle password changes | Matthias Dieter Wallnöfer | 1 | -138/+450 | |
- Implement the password restrictions as specified in "samdb_set_password" (complexity, minimum password length, minimum password age...). - We support only (administrative) password reset operations at the moment - Support password (administrative) reset and change operations (consider MS-ADTS 3.1.1.3.1.5) | |||||
2010-05-10 | s4:password_hash - Rework unique value checks | Matthias Dieter Wallnöfer | 1 | -49/+71 | |
Windows Server performs the constraint checks in a different way than we do. All testing has been done using "passwords.py". | |||||
2010-05-10 | s4:password_hash - Various (mostly cosmetic) prework | Matthias Dieter Wallnöfer | 1 | -176/+240 | |
- Enhance comments - Get some more attributes from the domain and user object (needed later) - Check for right objectclass on change/set operations (instances of "user" and/or "inetOrgPerson") - otherwise forward the request - (Cosmetic) cleanup in asynchronous results regarding return values | |||||
2010-05-10 | s4:dsdb: add new controls | Matthias Dieter Wallnöfer | 2 | -0/+24 | |
- Add a new control for getting status informations (domain informations, password change status) directly from the module - Add a new control for allowing direct hash changes - Introduce an addtional control "change_old password checked" for the password | |||||
2010-05-10 | s4:setup: mark DSDB_CONTROL_DN_STORAGE_FORMAT_OID 1.3.6.1.4.1.7165.4.3.4 as ↵ | Stefan Metzmacher | 1 | -2/+4 | |
allocated metze | |||||
2010-05-10 | v2 Latest enhancements in ldapcmp tool | Zahari Zahariev | 1 | -140/+262 | |
- Added support for replicating hosts versus hosts in different domains - Added switches for the following modes: = two - ignores additional attributes that cannot be the same in two different provisions (domains) = quiet - display nothing, only return code = verbose - display all dn objects through compare fase = default - display only objects with differences - Added more placeholders for nETBIOSDomainName and ServerName | |||||
2010-05-10 | s4-rodc: Fix provision warnings by creating ntds objectGUID in provision | Anatoliy Atanasov | 3 | -1/+32 | |
2010-05-10 | s4:acl ldb module - fix typos | Matthias Dieter Wallnöfer | 1 | -3/+3 | |
2010-05-10 | s4:dsdb/util.c - Add a new function for retrieving password change attributes | Matthias Dieter Wallnöfer | 1 | -0/+41 | |
This is needed since we have not only reset operations on password fields (attributes marked with REPLACE flag) but also change operations which can be performed by users itself. They have one attribute with the old value marked with the REMOVE flag and one with the new one marked with the ADD flag. This function helps to retrieve them (argument "new" is used for the new password on both reset and change). | |||||
2010-05-10 | s4:blackbox password tests - more complex passwords | Stefan Metzmacher | 2 | -5/+5 | |
2010-05-10 | s4:selftest: add --socket-wrapper[-keep]-pcap options to "waf test" | Stefan Metzmacher | 1 | -0/+10 | |
metze | |||||
2010-05-10 | s3:provision_basedn_modify.ldif - add "msDS-NcType" attribute and fix comments | Matthias Dieter Wallnöfer | 1 | -1/+5 | |
2010-05-09 | s4:samldb LDB module - make "samldb_member_check" synchronous again | Matthias Dieter Wallnöfer | 1 | -64/+33 | |
2010-05-09 | s4:samldb LDB module - make "samldb_prim_group_users_check" synchronous again | Matthias Dieter Wallnöfer | 1 | -235/+24 | |
2010-05-09 | s4:samldb LDB module - update the copyright notice | Matthias Dieter Wallnöfer | 1 | -1/+1 | |
2010-05-09 | s4:net utility - make outprinted description comments more consistent | Matthias Dieter Wallnöfer | 14 | -16/+16 | |
I've added a [server connection needed] when commands won't work on the local SamDB. | |||||
2010-05-09 | s4:net utility - remove unixname parameter of samdb.newuser | Matthias Dieter Wallnöfer | 1 | -9/+4 | |
We don't handle the id mapping stuff manually anymore. | |||||
2010-05-09 | s4:samdb python bindings - remove idmap creation stuff from this call | Matthias Dieter Wallnöfer | 1 | -22/+1 | |
The id mapping should now be handled automatically by the s4 daemon. | |||||
2010-05-09 | s4:net utility - add an optional password attribute to "net user add" | Matthias Dieter Wallnöfer | 1 | -3/+5 | |
To make it behave similar to "net newuser". | |||||
2010-05-09 | s4:dsdb Provide an intelegent fallback if not CN=Subnets is found | Andrew Bartlett | 1 | -3/+7 | |
We may as well fall back rather than return NULL (which callers don't do useful things with). Andrew Bartlett | |||||
2010-05-09 | dsdb/password_hash: remove usage of msDs-KeyVersionNumber | Stefan Metzmacher | 1 | -37/+1 | |
metze | |||||
2010-05-09 | s4:dsdb Use replPropertyMetaData as the basis for msDS-KeyVersionNumber | Andrew Bartlett | 1 | -10/+76 | |
This means that the existing kvno will no longer be valid, all unix-based domain members may need to be rejoined, and upgradeprovision run to update the local kvno in secrets.ldb/secrets.keytab. This is required to match the algorithm used by Windows DCs, which we may be replicating with. We also need to find a way to generate a reasonable kvno with the OpenLDAP backend. Andrew Bartlett | |||||
2010-05-08 | s4-smbtorture: add smbcli_rap_netuserpasswordset2(). | Günther Deschner | 1 | -0/+55 | |
Guenther | |||||
2010-05-07 | s4-devel: a very useful script when dealing with library/linking issues | Andrew Tridgell | 1 | -0/+15 | |
I use this all the time, so I thought I'd put it in the tree for others | |||||
2010-05-06 | s4-devel: auto-delete any leftover IPs | Andrew Tridgell | 1 | -0/+8 | |
remove IP from a previous vampire_ad.sh run | |||||
2010-05-06 | s4-devel: a useful script for giving DRS replication demos | Andrew Tridgell | 1 | -0/+14 | |
2010-05-06 | build: added a reconfigure target | Andrew Tridgell | 1 | -0/+4 | |
this is meant to be used by the s3 build, to allow jelmers work on smbtorture4 in s3 to avoid re-running configure unless its needed | |||||
2010-05-05 | s4-ldb: check for ldap_initialize | Andrew Tridgell | 1 | -1/+1 | |
HPUX 11.0 has a ldap library that doesn't have ldap_initialize | |||||
2010-05-05 | s4-smbtorture: remove unused variable from smbcli_rap_netprintdestgetinfo(). | Günther Deschner | 1 | -1/+0 | |
Guenther | |||||
2010-05-05 | s4-ldb: add msg saying which build system is being used | Andrew Tridgell | 1 | -0/+2 | |
(this is a gratuituous commit to trigger the build farm to rebuild ldb on all systems) | |||||
2010-05-04 | s4-torture: Added the printername to the AddPrinter comment. | Andreas Schneider | 1 | -2/+4 | |
Signed-off-by: Günther Deschner <gd@samba.org> | |||||
2010-05-04 | s4-torture: Fixed spoolss dsspooler printername test. | Andreas Schneider | 1 | -1/+9 | |
Signed-off-by: Günther Deschner <gd@samba.org> | |||||
2010-05-04 | s4/waf: ABI update for lib/ldb | Anatoliy Atanasov | 2 | -1/+225 | |
2010-05-04 | s4/rodc: Support read-only database | Anatoliy Atanasov | 8 | -33/+299 | |
Check on modify if we are RODC and return referral. On the ldap backend side now we pass context and ldb_modify_default_callback to propagate the referral error to the client. | |||||
2010-05-04 | s4/rodc: Fix the callbacks up the stack to handle referrals on modify requests | Anatoliy Atanasov | 7 | -0/+63 | |
2010-05-04 | s4:py_nttime2string - removed unused variable "nt2" | Matthias Dieter Wallnöfer | 1 | -2/+3 | |
And add some linespaces to look better. | |||||
2010-05-04 | s4-smbtorture: fill in test_rap_print(). | Günther Deschner | 1 | -12/+98 | |
This tests pauses a printer over RAP, prints a file, enumerates the job, deletes the job and resumes the print queue. Guenther | |||||
2010-05-04 | s4-smbtorture: add test_netprintdestgetinfo() to RAP-PRINTING. | Günther Deschner | 1 | -0/+54 | |
Guenther | |||||
2010-05-04 | s4-smbtorture: add smbcli_rap_netprintdestgetinfo(). | Günther Deschner | 1 | -0/+81 | |
Guenther |