CVE-2020-25719 kdc: Avoid races and multiple DB lookups in s4u2self check
[Samba.git] / source3 / utils / net_dns.c
blob751a6c120e050a5a8b54d06feb4e3d9459a392a6
1 /*
2 Samba Unix/Linux Dynamic DNS Update
3 net ads commands
5 Copyright (C) Krishna Ganugapati (krishnag@centeris.com) 2006
6 Copyright (C) Gerald Carter 2006
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "includes.h"
23 #include "utils/net.h"
24 #include "../lib/addns/dns.h"
25 #include "utils/net_dns.h"
27 #if defined(HAVE_KRB5)
29 /*********************************************************************
30 *********************************************************************/
32 DNS_ERROR DoDNSUpdate(char *pszServerName,
33 const char *pszDomainName, const char *pszHostName,
34 const struct sockaddr_storage *sslist, size_t num_addrs,
35 uint32_t flags, bool remove_host)
37 DNS_ERROR err;
38 struct dns_connection *conn;
39 TALLOC_CTX *mem_ctx;
40 OM_uint32 minor;
41 struct dns_update_request *req, *resp;
43 DEBUG(10,("DoDNSUpdate called with flags: 0x%08x\n", flags));
45 if (!(flags & DNS_UPDATE_SIGNED) &&
46 !(flags & DNS_UPDATE_UNSIGNED) &&
47 !(flags & DNS_UPDATE_PROBE)) {
48 return ERROR_DNS_INVALID_PARAMETER;
51 if ( !remove_host && ((num_addrs <= 0) || !sslist) ) {
52 return ERROR_DNS_INVALID_PARAMETER;
55 if (!(mem_ctx = talloc_init("DoDNSUpdate"))) {
56 return ERROR_DNS_NO_MEMORY;
59 err = dns_open_connection( pszServerName, DNS_TCP, mem_ctx, &conn );
60 if (!ERR_DNS_IS_OK(err)) {
61 goto error;
64 if (flags & DNS_UPDATE_PROBE) {
67 * Probe if everything's fine
70 err = dns_create_probe(mem_ctx, pszDomainName, pszHostName,
71 num_addrs, sslist, &req);
72 if (!ERR_DNS_IS_OK(err)) goto error;
74 err = dns_update_transaction(mem_ctx, conn, req, &resp);
76 if (!ERR_DNS_IS_OK(err)) {
77 DEBUG(3,("DoDNSUpdate: failed to probe DNS\n"));
78 goto error;
81 if ((dns_response_code(resp->flags) == DNS_NO_ERROR) &&
82 (flags & DNS_UPDATE_PROBE_SUFFICIENT)) {
83 TALLOC_FREE(mem_ctx);
84 return ERROR_DNS_SUCCESS;
88 if (flags & DNS_UPDATE_UNSIGNED) {
91 * First try without signing
94 err = dns_create_update_request(mem_ctx, pszDomainName, pszHostName,
95 sslist, num_addrs, &req);
96 if (!ERR_DNS_IS_OK(err)) goto error;
98 err = dns_update_transaction(mem_ctx, conn, req, &resp);
99 if (!ERR_DNS_IS_OK(err)) {
100 DEBUG(3,("DoDNSUpdate: unsigned update failed\n"));
101 goto error;
104 if ((dns_response_code(resp->flags) == DNS_NO_ERROR) &&
105 (flags & DNS_UPDATE_UNSIGNED_SUFFICIENT)) {
106 TALLOC_FREE(mem_ctx);
107 return ERROR_DNS_SUCCESS;
112 * Okay, we have to try with signing
114 if (flags & DNS_UPDATE_SIGNED) {
115 gss_ctx_id_t gss_context;
116 char *keyname;
118 err = dns_create_update_request(mem_ctx, pszDomainName, pszHostName,
119 sslist, num_addrs, &req);
120 if (!ERR_DNS_IS_OK(err)) goto error;
122 if (!(keyname = dns_generate_keyname( mem_ctx ))) {
123 err = ERROR_DNS_NO_MEMORY;
124 goto error;
127 err = dns_negotiate_sec_ctx( pszDomainName, pszServerName,
128 keyname, &gss_context, DNS_SRV_ANY );
130 /* retry using the Windows 2000 DNS hack */
131 if (!ERR_DNS_IS_OK(err)) {
132 err = dns_negotiate_sec_ctx( pszDomainName, pszServerName,
133 keyname, &gss_context,
134 DNS_SRV_WIN2000 );
137 if (!ERR_DNS_IS_OK(err))
138 goto error;
140 err = dns_sign_update(req, gss_context, keyname,
141 "gss.microsoft.com", time(NULL), 3600);
143 gss_delete_sec_context(&minor, &gss_context, GSS_C_NO_BUFFER);
145 if (!ERR_DNS_IS_OK(err)) goto error;
147 err = dns_update_transaction(mem_ctx, conn, req, &resp);
148 if (!ERR_DNS_IS_OK(err)) goto error;
150 err = (dns_response_code(resp->flags) == DNS_NO_ERROR) ?
151 ERROR_DNS_SUCCESS : ERROR_DNS_UPDATE_FAILED;
153 if (!ERR_DNS_IS_OK(err)) {
154 DEBUG(3,("DoDNSUpdate: signed update failed\n"));
159 error:
160 TALLOC_FREE(mem_ctx);
161 return err;
164 /*********************************************************************
165 *********************************************************************/
167 int get_my_ip_address( struct sockaddr_storage **pp_ss )
170 int i, n;
171 struct sockaddr_storage *list = NULL;
172 int count = 0;
174 /* Honor the configured list of interfaces to register */
176 load_interfaces();
177 n = iface_count();
179 if (n <= 0) {
180 return -1;
183 if ( (list = SMB_MALLOC_ARRAY( struct sockaddr_storage, n )) == NULL ) {
184 return -1;
187 for ( i=0; i<n; i++ ) {
188 const struct sockaddr_storage *nic_sa_storage = NULL;
190 if ((nic_sa_storage = iface_n_sockaddr_storage(i)) == NULL)
191 continue;
193 /* Don't register loopback addresses */
194 if (is_loopback_addr((const struct sockaddr *)nic_sa_storage)) {
195 continue;
198 /* Don't register link-local addresses */
199 if (is_linklocal_addr(nic_sa_storage)) {
200 continue;
203 memcpy(&list[count++], nic_sa_storage, sizeof(struct sockaddr_storage));
205 *pp_ss = list;
207 return count;
210 #endif /* defined(HAVE_KRB5) */