s4:dsdb/password_hash: reject interdomain trust password changes via LDAP
commit8a63dd8bbccfaf5537ddf37f1037566bd73ff28c
authorStefan Metzmacher <metze@samba.org>
Mon, 30 Mar 2015 10:31:01 +0000 (30 12:31 +0200)
committerStefan Metzmacher <metze@samba.org>
Wed, 8 Jul 2015 16:38:21 +0000 (8 18:38 +0200)
treef1d7bda45395822ff0ea6f25f8631ff418eb3cbb
parentdd23d8e1b2a512c6e59b44796ab86e0144128528
s4:dsdb/password_hash: reject interdomain trust password changes via LDAP

Only the LSA and NETLOGON server should be able to change this, otherwise
the incoming passwords in the trust account and trusted domain object
get out of sync.

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
source4/dsdb/samdb/ldb_modules/password_hash.c