From b99dc808df7e1a4d51145f4ce0bd89819b037dc4 Mon Sep 17 00:00:00 2001 From: Luke Leighton Date: Thu, 3 Dec 1998 20:50:33 +0000 Subject: create domain group command (creategroup) added to rpcclient. renamed do_samr_xxxx to samr_xxxx. (This used to be commit 1e5d81c154740349a2cda4c1892b33a21c0683a8) --- source3/rpc_client/cli_samr.c | 347 +++++++++++++++++++++++++++++++++--------- 1 file changed, 278 insertions(+), 69 deletions(-) (limited to 'source3/rpc_client/cli_samr.c') diff --git a/source3/rpc_client/cli_samr.c b/source3/rpc_client/cli_samr.c index eb1acb2524..6e0e6ab71b 100644 --- a/source3/rpc_client/cli_samr.c +++ b/source3/rpc_client/cli_samr.c @@ -33,6 +33,45 @@ extern int DEBUGLEVEL; +/**************************************************************************** +do a SAMR query user groups +****************************************************************************/ +BOOL create_samr_domain_group(struct cli_state *cli, + POLICY_HND *pol_open_domain, + const char *acct_name, const char *acct_desc, + uint32 *rid) +{ + POLICY_HND pol_open_group; + GROUP_INFO_CTR ctr; + if (pol_open_domain == NULL || acct_name == NULL || acct_desc == NULL) return False; + + /* send create group*/ + if (!samr_create_dom_group(cli, + pol_open_domain, + acct_name, + &pol_open_group, rid)) + { + return False; + } + + DEBUG(5,("create_samr_domain_group: name: %s rid 0x%x\n", + acct_name, *rid)); + + ctr.switch_value1 = 4; + ctr.switch_value2 = 4; + make_samr_group_info4(&ctr.group.info4, acct_desc); + + /* send user groups query */ + if (!samr_set_groupinfo(cli, + &pol_open_group, + &ctr)) + { + DEBUG(5,("create_samr_domain_group: error in samr_set_groupinfo\n")); + } + + return samr_close(cli, &pol_open_group); +} + /**************************************************************************** do a SAMR query user groups ****************************************************************************/ @@ -44,7 +83,7 @@ BOOL get_samr_query_usergroups(struct cli_state *cli, if (pol_open_domain == NULL || num_groups == NULL || gid == NULL) return False; /* send open domain (on user sid) */ - if (!do_samr_open_user(cli, + if (!samr_open_user(cli, pol_open_domain, 0x02011b, user_rid, &pol_open_user)) @@ -53,14 +92,14 @@ BOOL get_samr_query_usergroups(struct cli_state *cli, } /* send user groups query */ - if (!do_samr_query_usergroups(cli, + if (!samr_query_usergroups(cli, &pol_open_user, num_groups, gid)) { - DEBUG(5,("do_samr_query_usergroups: error in query user groups\n")); + DEBUG(5,("samr_query_usergroups: error in query user groups\n")); } - return do_samr_close(cli, &pol_open_user); + return samr_close(cli, &pol_open_user); } /**************************************************************************** @@ -77,7 +116,7 @@ BOOL get_samr_query_userinfo(struct cli_state *cli, bzero(usr, sizeof(*usr)); /* send open domain (on user sid) */ - if (!do_samr_open_user(cli, + if (!samr_open_user(cli, pol_open_domain, 0x02011b, user_rid, &pol_open_user)) @@ -86,21 +125,21 @@ BOOL get_samr_query_userinfo(struct cli_state *cli, } /* send user info query */ - if (!do_samr_query_userinfo(cli, + if (!samr_query_userinfo(cli, &pol_open_user, info_level, (void*)usr)) { - DEBUG(5,("do_samr_query_userinfo: error in query user info, level 0x%x\n", + DEBUG(5,("samr_query_userinfo: error in query user info, level 0x%x\n", info_level)); } - return do_samr_close(cli, &pol_open_user); + return samr_close(cli, &pol_open_user); } /**************************************************************************** do a SAMR change user password command ****************************************************************************/ -BOOL do_samr_chgpasswd_user(struct cli_state *cli, +BOOL samr_chgpasswd_user(struct cli_state *cli, char *srv_name, char *user_name, char nt_newpass[516], uchar nt_oldhash[16], char lm_newpass[516], uchar lm_oldhash[16]) @@ -157,7 +196,7 @@ BOOL do_samr_chgpasswd_user(struct cli_state *cli, /**************************************************************************** do a SAMR unknown 0x38 command ****************************************************************************/ -BOOL do_samr_unknown_38(struct cli_state *cli, char *srv_name) +BOOL samr_unknown_38(struct cli_state *cli, char *srv_name) { prs_struct data; prs_struct rdata; @@ -209,7 +248,7 @@ BOOL do_samr_unknown_38(struct cli_state *cli, char *srv_name) /**************************************************************************** do a SAMR unknown 0x8 command ****************************************************************************/ -BOOL do_samr_query_dom_info(struct cli_state *cli, +BOOL samr_query_dom_info(struct cli_state *cli, POLICY_HND *domain_pol, uint16 switch_value) { prs_struct data; @@ -218,15 +257,15 @@ BOOL do_samr_query_dom_info(struct cli_state *cli, SAMR_Q_QUERY_DOMAIN_INFO q_e; BOOL valid_un8 = False; + DEBUG(4,("SAMR Unknown 8 switch:%d\n", switch_value)); + + if (domain_pol == NULL) return False; + /* create and send a MSRPC command with api SAMR_ENUM_DOM_USERS */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Unknown 8 switch:%d\n", switch_value)); - - if (domain_pol == NULL) return False; - /* store the parameters */ make_samr_q_query_dom_info(&q_e, domain_pol, switch_value); @@ -266,7 +305,7 @@ BOOL do_samr_query_dom_info(struct cli_state *cli, /**************************************************************************** do a SAMR enumerate users ****************************************************************************/ -BOOL do_samr_enum_dom_users(struct cli_state *cli, +BOOL samr_enum_dom_users(struct cli_state *cli, POLICY_HND *pol, uint16 num_entries, uint16 unk_0, uint16 acb_mask, uint16 unk_1, uint32 size, struct acct_info **sam, @@ -276,17 +315,17 @@ BOOL do_samr_enum_dom_users(struct cli_state *cli, prs_struct rdata; SAMR_Q_ENUM_DOM_USERS q_e; - BOOL valid_pol = False; + BOOL valid_pol = False; + + DEBUG(4,("SAMR Enum SAM DB max size:%x\n", size)); + + if (pol == NULL || num_sam_users == NULL) return False; /* create and send a MSRPC command with api SAMR_ENUM_DOM_USERS */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Enum SAM DB max size:%x\n", size)); - - if (pol == NULL || num_sam_users == NULL) return False; - /* store the parameters */ make_samr_q_enum_dom_users(&q_e, pol, num_entries, unk_0, @@ -320,7 +359,7 @@ BOOL do_samr_enum_dom_users(struct cli_state *cli, if (*num_sam_users > MAX_SAM_ENTRIES) { *num_sam_users = MAX_SAM_ENTRIES; - DEBUG(2,("do_samr_enum_dom_users: sam user entries limited to %d\n", + DEBUG(2,("samr_enum_dom_users: sam user entries limited to %d\n", *num_sam_users)); } @@ -346,7 +385,7 @@ BOOL do_samr_enum_dom_users(struct cli_state *cli, { bzero((*sam)[i].acct_name, sizeof((*sam)[i].acct_name)); } - DEBUG(5,("do_samr_enum_dom_users: idx: %4d rid: %8x acct: %s\n", + DEBUG(5,("samr_enum_dom_users: idx: %4d rid: %8x acct: %s\n", i, (*sam)[i].user_rid, (*sam)[i].acct_name)); } valid_pol = True; @@ -362,7 +401,7 @@ BOOL do_samr_enum_dom_users(struct cli_state *cli, /**************************************************************************** do a SAMR Connect ****************************************************************************/ -BOOL do_samr_connect(struct cli_state *cli, +BOOL samr_connect(struct cli_state *cli, char *srv_name, uint32 unknown_0, POLICY_HND *connect_pol) { @@ -370,18 +409,18 @@ BOOL do_samr_connect(struct cli_state *cli, prs_struct rdata; SAMR_Q_CONNECT q_o; - BOOL valid_pol = False; - - /* create and send a MSRPC command with api SAMR_CONNECT */ - - prs_init(&data , 1024, 4, SAFETY_MARGIN, False); - prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + BOOL valid_pol = False; DEBUG(4,("SAMR Open Policy server:%s undoc value:%x\n", srv_name, unknown_0)); if (srv_name == NULL || connect_pol == NULL) return False; + /* create and send a MSRPC command with api SAMR_CONNECT */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + /* store the parameters */ make_samr_q_connect(&q_o, srv_name, unknown_0); @@ -420,7 +459,7 @@ BOOL do_samr_connect(struct cli_state *cli, /**************************************************************************** do a SAMR Open User ****************************************************************************/ -BOOL do_samr_open_user(struct cli_state *cli, +BOOL samr_open_user(struct cli_state *cli, POLICY_HND *pol, uint32 unk_0, uint32 rid, POLICY_HND *user_pol) { @@ -428,18 +467,18 @@ BOOL do_samr_open_user(struct cli_state *cli, prs_struct rdata; SAMR_Q_OPEN_USER q_o; - BOOL valid_pol = False; - - /* create and send a MSRPC command with api SAMR_OPEN_USER */ - - prs_init(&data , 1024, 4, SAFETY_MARGIN, False); - prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + BOOL valid_pol = False; DEBUG(4,("SAMR Open User. unk_0: %08x RID:%x\n", unk_0, rid)); if (pol == NULL || user_pol == NULL) return False; + /* create and send a MSRPC command with api SAMR_OPEN_USER */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + /* store the parameters */ make_samr_q_open_user(&q_o, pol, unk_0, rid); @@ -475,10 +514,180 @@ BOOL do_samr_open_user(struct cli_state *cli, return valid_pol; } +/**************************************************************************** +do a SAMR Open Group +****************************************************************************/ +BOOL samr_open_group(struct cli_state *cli, + POLICY_HND *domain_pol, uint32 rid, + POLICY_HND *group_pol) +{ + prs_struct data; + prs_struct rdata; + + SAMR_Q_OPEN_GROUP q_o; + BOOL valid_pol = False; + + DEBUG(4,("SAMR Open Group. RID:%x\n", rid)); + + if (group_pol == NULL || domain_pol == NULL) return False; + + /* create and send a MSRPC command with api SAMR_OPEN_GROUP */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + + /* store the parameters */ + make_samr_q_open_group(&q_o, domain_pol, 0x0001, rid); + + /* turn parameters into data stream */ + samr_io_q_open_group("", &q_o, &data, 0); + + /* send the data on \PIPE\ */ + if (rpc_api_pipe_req(cli, SAMR_OPEN_GROUP, &data, &rdata)) + { + SAMR_R_OPEN_GROUP r_o; + BOOL p; + + samr_io_r_open_group("", &r_o, &rdata, 0); + p = rdata.offset != 0; + + if (p && r_o.status != 0) + { + /* report error code */ + DEBUG(0,("SAMR_R_OPEN_GROUP: %s\n", get_nt_error_msg(r_o.status))); + p = False; + } + + if (p) + { + memcpy(group_pol, &r_o.pol, sizeof(r_o.pol)); + valid_pol = True; + } + } + + prs_mem_free(&data ); + prs_mem_free(&rdata ); + + return valid_pol; +} + +/**************************************************************************** +do a SAMR Create Domain Group +****************************************************************************/ +BOOL samr_create_dom_group(struct cli_state *cli, + POLICY_HND *domain_pol, const char *acct_name, + POLICY_HND *group_pol, uint32 *rid) +{ + prs_struct data; + prs_struct rdata; + + SAMR_Q_CREATE_DOM_GROUP q_o; + BOOL valid_pol = False; + + if (group_pol == NULL || domain_pol == NULL || acct_name == NULL || rid == NULL) return False; + + /* create and send a MSRPC command with api SAMR_CREATE_DOM_GROUP */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + + DEBUG(4,("SAMR Create Domain Group. Name:%s\n", acct_name)); + + /* store the parameters */ + make_samr_q_create_dom_group(&q_o, domain_pol, acct_name); + + /* turn parameters into data stream */ + samr_io_q_create_dom_group("", &q_o, &data, 0); + + /* send the data on \PIPE\ */ + if (rpc_api_pipe_req(cli, SAMR_CREATE_DOM_GROUP, &data, &rdata)) + { + SAMR_R_CREATE_DOM_GROUP r_o; + BOOL p; + + samr_io_r_create_dom_group("", &r_o, &rdata, 0); + p = rdata.offset != 0; + + if (p && r_o.status != 0) + { + /* report error code */ + DEBUG(0,("SAMR_R_CREATE_DOM_GROUP: %s\n", get_nt_error_msg(r_o.status))); + p = False; + } + + if (p) + { + memcpy(group_pol, &r_o.pol, sizeof(r_o.pol)); + *rid = r_o.rid; + valid_pol = True; + } + } + + prs_mem_free(&data ); + prs_mem_free(&rdata ); + + return valid_pol; +} + +/**************************************************************************** +do a SAMR Set Group Info +****************************************************************************/ +BOOL samr_set_groupinfo(struct cli_state *cli, + POLICY_HND *group_pol, GROUP_INFO_CTR *ctr) +{ + prs_struct data; + prs_struct rdata; + + SAMR_Q_SET_GROUPINFO q_o; + BOOL valid_pol = False; + + if (group_pol == NULL || ctr == NULL) return False; + + /* create and send a MSRPC command with api SAMR_SET_GROUPINFO */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + + DEBUG(4,("SAMR Set Group Info\n")); + + /* store the parameters */ + make_samr_q_set_groupinfo(&q_o, group_pol, ctr); + + /* turn parameters into data stream */ + samr_io_q_set_groupinfo("", &q_o, &data, 0); + + /* send the data on \PIPE\ */ + if (rpc_api_pipe_req(cli, SAMR_SET_GROUPINFO, &data, &rdata)) + { + SAMR_R_SET_GROUPINFO r_o; + BOOL p; + + samr_io_r_set_groupinfo("", &r_o, &rdata, 0); + p = rdata.offset != 0; + + if (p && r_o.status != 0) + { + /* report error code */ + DEBUG(0,("SAMR_R_SET_GROUPINFO: %s\n", get_nt_error_msg(r_o.status))); + p = False; + } + + if (p) + { + valid_pol = True; + } + } + + prs_mem_free(&data ); + prs_mem_free(&rdata ); + + return valid_pol; +} + /**************************************************************************** do a SAMR Open Domain ****************************************************************************/ -BOOL do_samr_open_domain(struct cli_state *cli, +BOOL samr_open_domain(struct cli_state *cli, POLICY_HND *connect_pol, uint32 rid, DOM_SID *sid, POLICY_HND *domain_pol) { @@ -489,16 +698,16 @@ BOOL do_samr_open_domain(struct cli_state *cli, SAMR_Q_OPEN_DOMAIN q_o; BOOL valid_pol = False; - /* create and send a MSRPC command with api SAMR_OPEN_DOMAIN */ - - prs_init(&data , 1024, 4, SAFETY_MARGIN, False); - prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - sid_to_string(sid_str, sid); DEBUG(4,("SAMR Open Domain. SID:%s RID:%x\n", sid_str, rid)); if (connect_pol == NULL || sid == NULL || domain_pol == NULL) return False; + /* create and send a MSRPC command with api SAMR_OPEN_DOMAIN */ + + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + /* store the parameters */ make_samr_q_open_domain(&q_o, connect_pol, rid, sid); @@ -537,7 +746,7 @@ BOOL do_samr_open_domain(struct cli_state *cli, /**************************************************************************** do a SAMR Query Unknown 12 ****************************************************************************/ -BOOL do_samr_query_unknown_12(struct cli_state *cli, +BOOL samr_query_unknown_12(struct cli_state *cli, POLICY_HND *pol, uint32 rid, uint32 num_gids, uint32 *gids, uint32 *num_names, fstring names[MAX_LOOKUP_SIDS], @@ -549,6 +758,9 @@ BOOL do_samr_query_unknown_12(struct cli_state *cli, SAMR_Q_UNKNOWN_12 q_o; BOOL valid_query = False; + if (pol == NULL || rid == 0 || num_gids == 0 || gids == NULL || + num_names == NULL || names == NULL || type == NULL ) return False; + /* create and send a MSRPC command with api SAMR_UNKNOWN_12 */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); @@ -556,9 +768,6 @@ BOOL do_samr_query_unknown_12(struct cli_state *cli, DEBUG(4,("SAMR Query Unknown 12.\n")); - if (pol == NULL || rid == 0 || num_gids == 0 || gids == NULL || - num_names == NULL || names == NULL || type == NULL ) return False; - /* store the parameters */ make_samr_q_unknown_12(&q_o, pol, rid, num_gids, gids); @@ -621,7 +830,7 @@ BOOL do_samr_query_unknown_12(struct cli_state *cli, /**************************************************************************** do a SAMR Query User Aliases ****************************************************************************/ -BOOL do_samr_query_useraliases(struct cli_state *cli, +BOOL samr_query_useraliases(struct cli_state *cli, POLICY_HND *pol, DOM_SID *sid, uint32 *num_aliases, uint32 *rid) { @@ -631,15 +840,15 @@ BOOL do_samr_query_useraliases(struct cli_state *cli, SAMR_Q_QUERY_USERALIASES q_o; BOOL valid_query = False; + DEBUG(4,("SAMR Query User Aliases.\n")); + + if (pol == NULL || sid == NULL || rid == NULL || num_aliases == 0) return False; + /* create and send a MSRPC command with api SAMR_QUERY_USERALIASES */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Query User Aliases.\n")); - - if (pol == NULL || sid == NULL || rid == NULL || num_aliases == 0) return False; - /* store the parameters */ make_samr_q_query_useraliases(&q_o, pol, sid); @@ -682,7 +891,7 @@ BOOL do_samr_query_useraliases(struct cli_state *cli, /**************************************************************************** do a SAMR Query User Groups ****************************************************************************/ -BOOL do_samr_query_usergroups(struct cli_state *cli, +BOOL samr_query_usergroups(struct cli_state *cli, POLICY_HND *pol, uint32 *num_groups, DOM_GID *gid) { prs_struct data; @@ -691,15 +900,15 @@ BOOL do_samr_query_usergroups(struct cli_state *cli, SAMR_Q_QUERY_USERGROUPS q_o; BOOL valid_query = False; + DEBUG(4,("SAMR Query User Groups.\n")); + + if (pol == NULL || gid == NULL || num_groups == 0) return False; + /* create and send a MSRPC command with api SAMR_QUERY_USERGROUPS */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Query User Groups.\n")); - - if (pol == NULL || gid == NULL || num_groups == 0) return False; - /* store the parameters */ make_samr_q_query_usergroups(&q_o, pol); @@ -742,24 +951,24 @@ BOOL do_samr_query_usergroups(struct cli_state *cli, /**************************************************************************** do a SAMR Query User Info ****************************************************************************/ -BOOL do_samr_query_userinfo(struct cli_state *cli, +BOOL samr_query_userinfo(struct cli_state *cli, POLICY_HND *pol, uint16 switch_value, void* usr) { prs_struct data; prs_struct rdata; SAMR_Q_QUERY_USERINFO q_o; - BOOL valid_query = False; + BOOL valid_query = False; + + DEBUG(4,("SAMR Query User Info. level: %d\n", switch_value)); + + if (pol == NULL || usr == NULL || switch_value == 0) return False; /* create and send a MSRPC command with api SAMR_QUERY_USERINFO */ prs_init(&data , 1024, 4, SAFETY_MARGIN, False); prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Query User Info. level: %d\n", switch_value)); - - if (pol == NULL || usr == NULL || switch_value == 0) return False; - /* store the parameters */ make_samr_q_query_userinfo(&q_o, pol, switch_value); @@ -806,22 +1015,22 @@ BOOL do_samr_query_userinfo(struct cli_state *cli, /**************************************************************************** do a SAMR Close ****************************************************************************/ -BOOL do_samr_close(struct cli_state *cli, POLICY_HND *hnd) +BOOL samr_close(struct cli_state *cli, POLICY_HND *hnd) { prs_struct data; prs_struct rdata; SAMR_Q_CLOSE_HND q_c; - BOOL valid_close = False; + BOOL valid_close = False; - prs_init(&data , 1024, 4, SAFETY_MARGIN, False); - prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); + DEBUG(4,("SAMR Close\n")); if (hnd == NULL) return False; - /* create and send a MSRPC command with api SAMR_CLOSE_HND */ + prs_init(&data , 1024, 4, SAFETY_MARGIN, False); + prs_init(&rdata, 0 , 4, SAFETY_MARGIN, True ); - DEBUG(4,("SAMR Close\n")); + /* create and send a MSRPC command with api SAMR_CLOSE_HND */ /* store the parameters */ make_samr_q_close_hnd(&q_c, hnd); -- cgit