2 Unix SMB/CIFS implementation.
6 Copyright (C) Gerald Carter 2006
7 Copyright (C) Guenther Deschner 2007-2008
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #define DSGETDCNAME_FMT "DSGETDCNAME/DOMAIN/%s"
27 #define DSGETDCNAME_CACHE_TTL 60*15
29 struct ip_service_name
{
30 struct sockaddr_storage ss
;
35 /****************************************************************
36 ****************************************************************/
38 void debug_dsdcinfo_flags(int lvl
, uint32_t flags
)
40 DEBUG(lvl
,("debug_dsdcinfo_flags: 0x%08x\n\t", flags
));
42 if (flags
& DS_FORCE_REDISCOVERY
)
43 DEBUGADD(lvl
,("DS_FORCE_REDISCOVERY "));
44 if (flags
& 0x000000002)
45 DEBUGADD(lvl
,("0x00000002 "));
46 if (flags
& 0x000000004)
47 DEBUGADD(lvl
,("0x00000004 "));
48 if (flags
& 0x000000008)
49 DEBUGADD(lvl
,("0x00000008 "));
50 if (flags
& DS_DIRECTORY_SERVICE_REQUIRED
)
51 DEBUGADD(lvl
,("DS_DIRECTORY_SERVICE_REQUIRED "));
52 if (flags
& DS_DIRECTORY_SERVICE_PREFERRED
)
53 DEBUGADD(lvl
,("DS_DIRECTORY_SERVICE_PREFERRED "));
54 if (flags
& DS_GC_SERVER_REQUIRED
)
55 DEBUGADD(lvl
,("DS_GC_SERVER_REQUIRED "));
56 if (flags
& DS_PDC_REQUIRED
)
57 DEBUGADD(lvl
,("DS_PDC_REQUIRED "));
58 if (flags
& DS_BACKGROUND_ONLY
)
59 DEBUGADD(lvl
,("DS_BACKGROUND_ONLY "));
60 if (flags
& DS_IP_REQUIRED
)
61 DEBUGADD(lvl
,("DS_IP_REQUIRED "));
62 if (flags
& DS_KDC_REQUIRED
)
63 DEBUGADD(lvl
,("DS_KDC_REQUIRED "));
64 if (flags
& DS_TIMESERV_REQUIRED
)
65 DEBUGADD(lvl
,("DS_TIMESERV_REQUIRED "));
66 if (flags
& DS_WRITABLE_REQUIRED
)
67 DEBUGADD(lvl
,("DS_WRITABLE_REQUIRED "));
68 if (flags
& DS_GOOD_TIMESERV_PREFERRED
)
69 DEBUGADD(lvl
,("DS_GOOD_TIMESERV_PREFERRED "));
70 if (flags
& DS_AVOID_SELF
)
71 DEBUGADD(lvl
,("DS_AVOID_SELF "));
72 if (flags
& DS_ONLY_LDAP_NEEDED
)
73 DEBUGADD(lvl
,("DS_ONLY_LDAP_NEEDED "));
74 if (flags
& DS_IS_FLAT_NAME
)
75 DEBUGADD(lvl
,("DS_IS_FLAT_NAME "));
76 if (flags
& DS_IS_DNS_NAME
)
77 DEBUGADD(lvl
,("DS_IS_DNS_NAME "));
78 if (flags
& 0x00040000)
79 DEBUGADD(lvl
,("0x00040000 "));
80 if (flags
& 0x00080000)
81 DEBUGADD(lvl
,("0x00080000 "));
82 if (flags
& 0x00100000)
83 DEBUGADD(lvl
,("0x00100000 "));
84 if (flags
& 0x00200000)
85 DEBUGADD(lvl
,("0x00200000 "));
86 if (flags
& 0x00400000)
87 DEBUGADD(lvl
,("0x00400000 "));
88 if (flags
& 0x00800000)
89 DEBUGADD(lvl
,("0x00800000 "));
90 if (flags
& 0x01000000)
91 DEBUGADD(lvl
,("0x01000000 "));
92 if (flags
& 0x02000000)
93 DEBUGADD(lvl
,("0x02000000 "));
94 if (flags
& 0x04000000)
95 DEBUGADD(lvl
,("0x04000000 "));
96 if (flags
& 0x08000000)
97 DEBUGADD(lvl
,("0x08000000 "));
98 if (flags
& 0x10000000)
99 DEBUGADD(lvl
,("0x10000000 "));
100 if (flags
& 0x20000000)
101 DEBUGADD(lvl
,("0x20000000 "));
102 if (flags
& DS_RETURN_DNS_NAME
)
103 DEBUGADD(lvl
,("DS_RETURN_DNS_NAME "));
104 if (flags
& DS_RETURN_FLAT_NAME
)
105 DEBUGADD(lvl
,("DS_RETURN_FLAT_NAME "));
107 DEBUGADD(lvl
,("\n"));
110 /****************************************************************
111 ****************************************************************/
113 static char *dsgetdcname_cache_key(TALLOC_CTX
*mem_ctx
, const char *domain
)
115 if (!mem_ctx
|| !domain
) {
119 return talloc_asprintf_strupper_m(mem_ctx
, DSGETDCNAME_FMT
, domain
);
122 /****************************************************************
123 ****************************************************************/
125 static NTSTATUS
dsgetdcname_cache_delete(TALLOC_CTX
*mem_ctx
,
126 const char *domain_name
)
130 if (!gencache_init()) {
131 return NT_STATUS_INTERNAL_DB_ERROR
;
134 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
136 return NT_STATUS_NO_MEMORY
;
139 if (!gencache_del(key
)) {
140 return NT_STATUS_UNSUCCESSFUL
;
146 /****************************************************************
147 ****************************************************************/
149 static NTSTATUS
dsgetdcname_cache_store(TALLOC_CTX
*mem_ctx
,
150 const char *domain_name
,
151 struct netr_DsRGetDCNameInfo
*info
)
157 enum ndr_err_code ndr_err
;
159 if (!gencache_init()) {
160 return NT_STATUS_INTERNAL_DB_ERROR
;
163 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
165 return NT_STATUS_NO_MEMORY
;
168 expire_time
= time(NULL
) + DSGETDCNAME_CACHE_TTL
;
170 ndr_err
= ndr_push_struct_blob(&blob
, mem_ctx
, info
,
171 (ndr_push_flags_fn_t
)ndr_push_netr_DsRGetDCNameInfo
);
172 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
173 return ndr_map_error2ntstatus(ndr_err
);
176 if (gencache_lock_entry(key
) != 0) {
177 data_blob_free(&blob
);
178 return NT_STATUS_LOCK_NOT_GRANTED
;
181 ret
= gencache_set_data_blob(key
, &blob
, expire_time
);
182 data_blob_free(&blob
);
184 gencache_unlock_entry(key
);
186 return ret
? NT_STATUS_OK
: NT_STATUS_UNSUCCESSFUL
;
189 /****************************************************************
190 ****************************************************************/
192 static NTSTATUS
dsgetdcname_cache_refresh(TALLOC_CTX
*mem_ctx
,
193 const char *domain_name
,
194 struct GUID
*domain_guid
,
196 const char *site_name
,
197 struct netr_DsRGetDCNameInfo
*info
)
199 uint32_t nt_version
= NETLOGON_VERSION_1
;
201 /* check if matching entry is older then 15 minutes, if yes, send
202 * CLDAP/MAILSLOT ping again and store the cached data */
204 if (ads_cldap_netlogon(mem_ctx
, info
->dc_unc
,
205 info
->domain_name
, &nt_version
, NULL
)) {
207 dsgetdcname_cache_delete(mem_ctx
, domain_name
);
209 return dsgetdcname_cache_store(mem_ctx
,
214 return NT_STATUS_INVALID_NETWORK_RESPONSE
;
217 /****************************************************************
218 ****************************************************************/
220 static uint32_t get_cldap_reply_server_flags(union nbt_cldap_netlogon
*r
,
223 switch (nt_version
& 0x000000ff) {
229 return r
->logon3
.server_type
;
234 return r
->logon5
.server_type
;
243 return r
->logon13
.server_type
;
245 return r
->logon29
.server_type
;
249 /****************************************************************
250 ****************************************************************/
252 #define RETURN_ON_FALSE(x) if (!x) return false;
254 static bool check_cldap_reply_required_flags(uint32_t ret_flags
,
257 if (req_flags
& DS_PDC_REQUIRED
)
258 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_PDC
);
260 if (req_flags
& DS_GC_SERVER_REQUIRED
)
261 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_GC
);
263 if (req_flags
& DS_ONLY_LDAP_NEEDED
)
264 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_LDAP
);
266 if ((req_flags
& DS_DIRECTORY_SERVICE_REQUIRED
) ||
267 (req_flags
& DS_DIRECTORY_SERVICE_PREFERRED
))
268 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_DS
);
270 if (req_flags
& DS_KDC_REQUIRED
)
271 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_KDC
);
273 if (req_flags
& DS_TIMESERV_REQUIRED
)
274 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_TIMESERV
);
276 if (req_flags
& DS_WRITABLE_REQUIRED
)
277 RETURN_ON_FALSE(ret_flags
& NBT_SERVER_WRITABLE
);
282 /****************************************************************
283 ****************************************************************/
285 static NTSTATUS
dsgetdcname_cache_fetch(TALLOC_CTX
*mem_ctx
,
286 const char *domain_name
,
287 struct GUID
*domain_guid
,
289 const char *site_name
,
290 struct netr_DsRGetDCNameInfo
**info_p
,
295 enum ndr_err_code ndr_err
;
296 struct netr_DsRGetDCNameInfo
*info
;
298 if (!gencache_init()) {
299 return NT_STATUS_INTERNAL_DB_ERROR
;
302 key
= dsgetdcname_cache_key(mem_ctx
, domain_name
);
304 return NT_STATUS_NO_MEMORY
;
307 if (!gencache_get_data_blob(key
, &blob
, expired
)) {
308 return NT_STATUS_OBJECT_NAME_NOT_FOUND
;
311 info
= TALLOC_ZERO_P(mem_ctx
, struct netr_DsRGetDCNameInfo
);
313 return NT_STATUS_NO_MEMORY
;
316 ndr_err
= ndr_pull_struct_blob(&blob
, mem_ctx
, info
,
317 (ndr_pull_flags_fn_t
)ndr_pull_netr_DsRGetDCNameInfo
);
319 data_blob_free(&blob
);
320 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
321 dsgetdcname_cache_delete(mem_ctx
, domain_name
);
322 return ndr_map_error2ntstatus(ndr_err
);
325 if (DEBUGLEVEL
>= 10) {
326 NDR_PRINT_DEBUG(netr_DsRGetDCNameInfo
, info
);
330 if (!check_cldap_reply_required_flags(info
->dc_flags
, flags
)) {
331 DEBUG(10,("invalid flags\n"));
332 return NT_STATUS_INVALID_PARAMETER
;
335 if ((flags
& DS_IP_REQUIRED
) &&
336 (info
->dc_address_type
!= DS_ADDRESS_TYPE_INET
)) {
337 return NT_STATUS_INVALID_PARAMETER_MIX
;
345 /****************************************************************
346 ****************************************************************/
348 static NTSTATUS
dsgetdcname_cached(TALLOC_CTX
*mem_ctx
,
349 const char *domain_name
,
350 struct GUID
*domain_guid
,
352 const char *site_name
,
353 struct netr_DsRGetDCNameInfo
**info
)
356 bool expired
= false;
358 status
= dsgetdcname_cache_fetch(mem_ctx
, domain_name
, domain_guid
,
359 flags
, site_name
, info
, &expired
);
360 if (!NT_STATUS_IS_OK(status
)) {
361 DEBUG(10,("dsgetdcname_cached: cache fetch failed with: %s\n",
363 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
366 if (flags
& DS_BACKGROUND_ONLY
) {
371 status
= dsgetdcname_cache_refresh(mem_ctx
, domain_name
,
374 if (!NT_STATUS_IS_OK(status
)) {
382 /****************************************************************
383 ****************************************************************/
385 static bool check_allowed_required_flags(uint32_t flags
)
387 uint32_t return_type
= flags
& (DS_RETURN_FLAT_NAME
|DS_RETURN_DNS_NAME
);
388 uint32_t offered_type
= flags
& (DS_IS_FLAT_NAME
|DS_IS_DNS_NAME
);
389 uint32_t query_type
= flags
& (DS_BACKGROUND_ONLY
|DS_FORCE_REDISCOVERY
);
391 /* FIXME: check for DSGETDC_VALID_FLAGS and check for excluse bits
392 * (DS_PDC_REQUIRED, DS_KDC_REQUIRED, DS_GC_SERVER_REQUIRED) */
394 debug_dsdcinfo_flags(10, flags
);
396 if (return_type
== (DS_RETURN_FLAT_NAME
|DS_RETURN_DNS_NAME
)) {
400 if (offered_type
== (DS_IS_DNS_NAME
|DS_IS_FLAT_NAME
)) {
404 if (query_type
== (DS_BACKGROUND_ONLY
|DS_FORCE_REDISCOVERY
)) {
409 if ((flags
& DS_RETURN_DNS_NAME
) && (!(flags
& DS_IP_REQUIRED
))) {
410 printf("gd: here5 \n");
417 /****************************************************************
418 ****************************************************************/
420 static NTSTATUS
discover_dc_netbios(TALLOC_CTX
*mem_ctx
,
421 const char *domain_name
,
423 struct ip_service_name
**returned_dclist
,
427 enum nbt_name_type name_type
= NBT_NAME_LOGON
;
428 struct ip_service
*iplist
;
430 struct ip_service_name
*dclist
= NULL
;
433 *returned_dclist
= NULL
;
436 if (lp_disable_netbios()) {
437 return NT_STATUS_NOT_SUPPORTED
;
440 if (flags
& DS_PDC_REQUIRED
) {
441 name_type
= NBT_NAME_PDC
;
444 status
= internal_resolve_name(domain_name
, name_type
, NULL
,
446 "lmhosts wins bcast");
447 if (!NT_STATUS_IS_OK(status
)) {
448 DEBUG(10,("discover_dc_netbios: failed to find DC\n"));
452 dclist
= TALLOC_ZERO_ARRAY(mem_ctx
, struct ip_service_name
, count
);
454 return NT_STATUS_NO_MEMORY
;
457 for (i
=0; i
<count
; i
++) {
459 char addr
[INET6_ADDRSTRLEN
];
460 struct ip_service_name
*r
= &dclist
[i
];
462 print_sockaddr(addr
, sizeof(addr
),
465 r
->ss
= iplist
[i
].ss
;
466 r
->port
= iplist
[i
].port
;
467 r
->hostname
= talloc_strdup(mem_ctx
, addr
);
469 return NT_STATUS_NO_MEMORY
;
474 *returned_dclist
= dclist
;
475 *returned_count
= count
;
480 /****************************************************************
481 ****************************************************************/
483 static NTSTATUS
discover_dc_dns(TALLOC_CTX
*mem_ctx
,
484 const char *domain_name
,
485 struct GUID
*domain_guid
,
487 const char *site_name
,
488 struct ip_service_name
**returned_dclist
,
493 struct dns_rr_srv
*dcs
= NULL
;
496 struct ip_service_name
*dclist
= NULL
;
499 if (flags
& DS_PDC_REQUIRED
) {
500 status
= ads_dns_query_pdc(mem_ctx
, domain_name
,
502 } else if (flags
& DS_GC_SERVER_REQUIRED
) {
503 status
= ads_dns_query_gcs(mem_ctx
, domain_name
, site_name
,
505 } else if (flags
& DS_KDC_REQUIRED
) {
506 status
= ads_dns_query_kdcs(mem_ctx
, domain_name
, site_name
,
508 } else if (flags
& DS_DIRECTORY_SERVICE_REQUIRED
) {
509 status
= ads_dns_query_dcs(mem_ctx
, domain_name
, site_name
,
511 } else if (domain_guid
) {
512 status
= ads_dns_query_dcs_guid(mem_ctx
, domain_name
,
513 domain_guid
, &dcs
, &numdcs
);
515 status
= ads_dns_query_dcs(mem_ctx
, domain_name
, site_name
,
519 if (!NT_STATUS_IS_OK(status
)) {
524 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
527 for (i
=0;i
<numdcs
;i
++) {
528 numaddrs
+= MAX(dcs
[i
].num_ips
,1);
531 dclist
= TALLOC_ZERO_ARRAY(mem_ctx
,
532 struct ip_service_name
,
535 return NT_STATUS_NO_MEMORY
;
538 /* now unroll the list of IP addresses */
544 while ((i
< numdcs
) && (count
< numaddrs
)) {
546 struct ip_service_name
*r
= &dclist
[count
];
548 r
->port
= dcs
[count
].port
;
549 r
->hostname
= dcs
[count
].hostname
;
551 if (!(flags
& DS_IP_REQUIRED
)) {
556 /* If we don't have an IP list for a name, lookup it up */
559 interpret_string_addr(&r
->ss
, dcs
[i
].hostname
, 0);
563 /* use the IP addresses from the SRV sresponse */
565 if (j
>= dcs
[i
].num_ips
) {
571 r
->ss
= dcs
[i
].ss_s
[j
];
575 /* make sure it is a valid IP. I considered checking the
576 * negative connection cache, but this is the wrong place for
577 * it. Maybe only as a hac. After think about it, if all of
578 * the IP addresses retuend from DNS are dead, what hope does a
579 * netbios name lookup have? The standard reason for falling
580 * back to netbios lookups is that our DNS server doesn't know
581 * anything about the DC's -- jerry */
583 if (!is_zero_addr(&r
->ss
)) {
589 *returned_dclist
= dclist
;
590 *return_count
= count
;
596 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
599 /****************************************************************
600 ****************************************************************/
602 static NTSTATUS
make_domain_controller_info(TALLOC_CTX
*mem_ctx
,
604 const char *dc_address
,
605 uint32_t dc_address_type
,
606 const struct GUID
*domain_guid
,
607 const char *domain_name
,
608 const char *forest_name
,
610 const char *dc_site_name
,
611 const char *client_site_name
,
612 struct netr_DsRGetDCNameInfo
**info_out
)
614 struct netr_DsRGetDCNameInfo
*info
;
616 info
= TALLOC_ZERO_P(mem_ctx
, struct netr_DsRGetDCNameInfo
);
617 NT_STATUS_HAVE_NO_MEMORY(info
);
620 info
->dc_unc
= talloc_strdup(mem_ctx
, dc_unc
);
621 NT_STATUS_HAVE_NO_MEMORY(info
->dc_unc
);
625 info
->dc_address
= talloc_strdup(mem_ctx
, dc_address
);
626 NT_STATUS_HAVE_NO_MEMORY(info
->dc_address
);
629 info
->dc_address_type
= dc_address_type
;
632 info
->domain_guid
= *domain_guid
;
636 info
->domain_name
= talloc_strdup(mem_ctx
, domain_name
);
637 NT_STATUS_HAVE_NO_MEMORY(info
->domain_name
);
641 info
->forest_name
= talloc_strdup(mem_ctx
, forest_name
);
642 NT_STATUS_HAVE_NO_MEMORY(info
->forest_name
);
643 flags
|= DS_DNS_FOREST
;
646 info
->dc_flags
= flags
;
649 info
->dc_site_name
= talloc_strdup(mem_ctx
, dc_site_name
);
650 NT_STATUS_HAVE_NO_MEMORY(info
->dc_site_name
);
653 if (client_site_name
) {
654 info
->client_site_name
= talloc_strdup(mem_ctx
,
656 NT_STATUS_HAVE_NO_MEMORY(info
->client_site_name
);
664 /****************************************************************
665 ****************************************************************/
667 static NTSTATUS
make_dc_info_from_cldap_reply(TALLOC_CTX
*mem_ctx
,
669 struct sockaddr_storage
*ss
,
671 union nbt_cldap_netlogon
*r
,
672 struct netr_DsRGetDCNameInfo
**info
)
674 const char *dc_hostname
, *dc_domain_name
;
675 const char *dc_address
= NULL
;
676 const char *dc_forest
= NULL
;
677 uint32_t dc_address_type
= 0;
678 uint32_t dc_flags
= 0;
679 struct GUID
*dc_domain_guid
= NULL
;
680 const char *dc_server_site
= NULL
;
681 const char *dc_client_site
= NULL
;
683 char addr
[INET6_ADDRSTRLEN
];
685 print_sockaddr(addr
, sizeof(addr
), ss
);
687 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s", addr
);
688 NT_STATUS_HAVE_NO_MEMORY(dc_address
);
689 dc_address_type
= DS_ADDRESS_TYPE_INET
;
691 switch (nt_version
& 0x000000ff) {
693 return NT_STATUS_INVALID_PARAMETER
;
695 dc_hostname
= r
->logon1
.pdc_name
;
696 dc_domain_name
= r
->logon1
.domain_name
;
697 if (flags
& DS_PDC_REQUIRED
) {
698 dc_flags
= NBT_SERVER_WRITABLE
| NBT_SERVER_PDC
;
703 switch (flags
& 0xf0000000) {
704 case DS_RETURN_FLAT_NAME
:
705 dc_hostname
= r
->logon3
.pdc_name
;
706 dc_domain_name
= r
->logon3
.domain_name
;
708 case DS_RETURN_DNS_NAME
:
710 dc_hostname
= r
->logon3
.pdc_dns_name
;
711 dc_domain_name
= r
->logon3
.dns_domain
;
712 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
716 dc_flags
|= r
->logon3
.server_type
;
717 dc_forest
= r
->logon3
.forest
;
718 dc_domain_guid
= &r
->logon3
.domain_uuid
;
725 switch (flags
& 0xf0000000) {
726 case DS_RETURN_FLAT_NAME
:
727 dc_hostname
= r
->logon5
.pdc_name
;
728 dc_domain_name
= r
->logon5
.domain
;
730 case DS_RETURN_DNS_NAME
:
732 dc_hostname
= r
->logon5
.pdc_dns_name
;
733 dc_domain_name
= r
->logon5
.dns_domain
;
734 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
738 dc_flags
|= r
->logon5
.server_type
;
739 dc_forest
= r
->logon5
.forest
;
740 dc_domain_guid
= &r
->logon5
.domain_uuid
;
741 dc_server_site
= r
->logon5
.server_site
;
742 dc_client_site
= r
->logon5
.client_site
;
753 switch (flags
& 0xf0000000) {
754 case DS_RETURN_FLAT_NAME
:
755 dc_hostname
= r
->logon13
.pdc_name
;
756 dc_domain_name
= r
->logon13
.domain
;
758 case DS_RETURN_DNS_NAME
:
760 dc_hostname
= r
->logon13
.pdc_dns_name
;
761 dc_domain_name
= r
->logon13
.dns_domain
;
762 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
766 dc_flags
|= r
->logon13
.server_type
;
767 dc_forest
= r
->logon13
.forest
;
768 dc_domain_guid
= &r
->logon13
.domain_uuid
;
769 dc_server_site
= r
->logon13
.server_site
;
770 dc_client_site
= r
->logon13
.client_site
;
774 switch (flags
& 0xf0000000) {
775 case DS_RETURN_FLAT_NAME
:
776 dc_hostname
= r
->logon29
.pdc_name
;
777 dc_domain_name
= r
->logon29
.domain
;
779 case DS_RETURN_DNS_NAME
:
781 dc_hostname
= r
->logon29
.pdc_dns_name
;
782 dc_domain_name
= r
->logon29
.dns_domain
;
783 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
787 dc_flags
|= r
->logon29
.server_type
;
788 dc_forest
= r
->logon29
.forest
;
789 dc_domain_guid
= &r
->logon29
.domain_uuid
;
790 dc_server_site
= r
->logon29
.server_site
;
791 dc_client_site
= r
->logon29
.client_site
;
796 return make_domain_controller_info(mem_ctx
,
809 /****************************************************************
810 ****************************************************************/
812 static uint32_t map_ds_flags_to_nt_version(uint32_t flags
)
814 uint32_t nt_version
= 0;
816 if (flags
& DS_PDC_REQUIRED
) {
817 nt_version
|= NETLOGON_VERSION_PDC
;
820 if (flags
& DS_GC_SERVER_REQUIRED
) {
821 nt_version
|= NETLOGON_VERSION_GC
;
824 if (flags
& DS_TRY_NEXTCLOSEST_SITE
) {
825 nt_version
|= NETLOGON_VERSION_WITH_CLOSEST_SITE
;
828 if (flags
& DS_IP_REQUIRED
) {
829 nt_version
|= NETLOGON_VERSION_IP
;
835 /****************************************************************
836 ****************************************************************/
838 static NTSTATUS
process_dc_dns(TALLOC_CTX
*mem_ctx
,
839 const char *domain_name
,
841 struct ip_service_name
*dclist
,
843 struct netr_DsRGetDCNameInfo
**info
)
846 bool valid_dc
= false;
847 struct nbt_cldap_netlogon_5 r
;
848 const char *dc_hostname
, *dc_domain_name
;
849 const char *dc_address
;
850 uint32_t dc_address_type
;
853 for (i
=0; i
<num_dcs
; i
++) {
857 DEBUG(10,("LDAP ping to %s\n", dclist
[i
].hostname
));
859 if ((ads_cldap_netlogon(mem_ctx
, dclist
[i
].hostname
,
861 (check_cldap_reply_required_flags(r
.server_type
, flags
))) {
870 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
873 dc_flags
= r
.server_type
;
875 if (flags
& DS_RETURN_FLAT_NAME
) {
876 if (!strlen(r
.pdc_name
) || !strlen(r
.domain
)) {
877 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
879 dc_hostname
= r
.pdc_name
;
880 dc_domain_name
= r
.domain
;
881 } else if (flags
& DS_RETURN_DNS_NAME
) {
882 if (!strlen(r
.pdc_dns_name
) || !strlen(r
.dns_domain
)) {
883 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
885 dc_hostname
= r
.pdc_dns_name
;
886 dc_domain_name
= r
.dns_domain
;
887 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
890 dc_hostname
= r
.pdc_dns_name
;
891 dc_domain_name
= r
.dns_domain
;
892 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
895 if (flags
& DS_IP_REQUIRED
) {
896 char addr
[INET6_ADDRSTRLEN
];
897 print_sockaddr(addr
, sizeof(addr
), &dclist
[i
].ss
);
898 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s",
900 dc_address_type
= DS_ADDRESS_TYPE_INET
;
902 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s",
904 dc_address_type
= DS_ADDRESS_TYPE_NETBIOS
;
906 NT_STATUS_HAVE_NO_MEMORY(dc_address
);
909 dc_flags
|= DS_DNS_FOREST
;
912 return make_domain_controller_info(mem_ctx
,
926 /****************************************************************
927 ****************************************************************/
929 static struct event_context
*ev_context(void)
931 static struct event_context
*ctx
;
933 if (!ctx
&& !(ctx
= event_context_init(NULL
))) {
934 smb_panic("Could not init event context");
939 /****************************************************************
940 ****************************************************************/
942 static struct messaging_context
*msg_context(TALLOC_CTX
*mem_ctx
)
944 static struct messaging_context
*ctx
;
946 if (!ctx
&& !(ctx
= messaging_init(mem_ctx
, server_id_self(),
948 smb_panic("Could not init messaging context");
953 /****************************************************************
954 ****************************************************************/
956 static NTSTATUS
process_dc_netbios(TALLOC_CTX
*mem_ctx
,
957 const char *domain_name
,
959 struct ip_service_name
*dclist
,
961 struct netr_DsRGetDCNameInfo
**info
)
963 struct sockaddr_storage ss
;
964 struct ip_service ip_list
;
965 enum nbt_name_type name_type
= NBT_NAME_LOGON
;
968 const char *dc_hostname
, *dc_domain_name
;
969 const char *dc_address
;
970 uint32_t dc_address_type
;
971 uint32_t dc_flags
= 0;
972 const char *dc_name
= NULL
;
973 const char *dc_forest
= NULL
;
974 const char *dc_server_site
= NULL
;
975 const char *dc_client_site
= NULL
;
976 struct GUID
*dc_domain_guid
= NULL
;
978 struct messaging_context
*msg_ctx
= msg_context(mem_ctx
);
979 struct nbt_ntlogon_packet
*reply
= NULL
;
980 uint32_t nt_version
= NETLOGON_VERSION_1
|
982 NETLOGON_VERSION_5EX_WITH_IP
;
984 if (flags
& DS_PDC_REQUIRED
) {
985 name_type
= NBT_NAME_PDC
;
988 nt_version
|= map_ds_flags_to_nt_version(flags
);
990 DEBUG(10,("process_dc_netbios\n"));
992 for (i
=0; i
<num_dcs
; i
++) {
994 ip_list
.ss
= dclist
[i
].ss
;
997 if (!interpret_string_addr(&ss
, dclist
[i
].hostname
, AI_NUMERICHOST
)) {
998 return NT_STATUS_UNSUCCESSFUL
;
1001 if (send_getdc_request(mem_ctx
, msg_ctx
,
1002 &dclist
[i
].ss
, domain_name
,
1007 for (k
=0; k
<5; k
++) {
1008 if (receive_getdc_response(mem_ctx
,
1013 namecache_store(dc_name
, NBT_NAME_SERVER
, 1, &ip_list
);
1014 dc_hostname
= dc_name
;
1015 dc_domain_name
= talloc_strdup_upper(mem_ctx
, domain_name
);
1016 NT_STATUS_HAVE_NO_MEMORY(dc_domain_name
);
1023 if (name_status_find(domain_name
,
1029 dc_hostname
= tmp_dc_name
;
1030 dc_domain_name
= talloc_strdup_upper(mem_ctx
, domain_name
);
1031 namecache_store(tmp_dc_name
, NBT_NAME_SERVER
, 1, &ip_list
);
1036 return NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1040 if (reply
&& reply
->command
== NTLOGON_RESPONSE_FROM_PDC2
) {
1042 dc_flags
|= reply
->req
.reply2
.server_type
;
1043 dc_forest
= reply
->req
.reply2
.forest
;
1044 dc_server_site
= reply
->req
.reply2
.server_site
;
1045 dc_client_site
= reply
->req
.reply2
.client_site
;
1047 dc_domain_guid
= &reply
->req
.reply2
.domain_uuid
;
1049 if (flags
& DS_RETURN_DNS_NAME
) {
1050 dc_domain_name
= reply
->req
.reply2
.dns_domain
;
1051 dc_hostname
= reply
->req
.reply2
.pdc_dns_name
;
1052 dc_flags
|= DS_DNS_DOMAIN
| DS_DNS_CONTROLLER
;
1053 } else if (flags
& DS_RETURN_FLAT_NAME
) {
1054 dc_domain_name
= reply
->req
.reply2
.domain
;
1055 dc_hostname
= reply
->req
.reply2
.pdc_name
;
1059 if (flags
& DS_IP_REQUIRED
) {
1060 char addr
[INET6_ADDRSTRLEN
];
1061 print_sockaddr(addr
, sizeof(addr
), &dclist
[i
].ss
);
1062 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s", addr
);
1063 dc_address_type
= DS_ADDRESS_TYPE_INET
;
1065 dc_address
= talloc_asprintf(mem_ctx
, "\\\\%s", dc_hostname
);
1066 dc_address_type
= DS_ADDRESS_TYPE_NETBIOS
;
1069 if (flags
& DS_PDC_REQUIRED
) {
1070 dc_flags
|= NBT_SERVER_PDC
| NBT_SERVER_WRITABLE
;
1074 dc_flags
|= DS_DNS_FOREST
;
1077 return make_domain_controller_info(mem_ctx
,
1090 /****************************************************************
1091 ****************************************************************/
1093 static NTSTATUS
dsgetdcname_rediscover(TALLOC_CTX
*mem_ctx
,
1094 const char *domain_name
,
1095 struct GUID
*domain_guid
,
1097 const char *site_name
,
1098 struct netr_DsRGetDCNameInfo
**info
)
1100 NTSTATUS status
= NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1101 struct ip_service_name
*dclist
= NULL
;
1104 DEBUG(10,("dsgetdcname_rediscover\n"));
1106 if (flags
& DS_IS_FLAT_NAME
) {
1108 status
= discover_dc_netbios(mem_ctx
, domain_name
, flags
,
1110 NT_STATUS_NOT_OK_RETURN(status
);
1112 return process_dc_netbios(mem_ctx
, domain_name
, flags
,
1113 dclist
, num_dcs
, info
);
1116 if (flags
& DS_IS_DNS_NAME
) {
1118 status
= discover_dc_dns(mem_ctx
, domain_name
, domain_guid
,
1119 flags
, site_name
, &dclist
, &num_dcs
);
1120 NT_STATUS_NOT_OK_RETURN(status
);
1122 return process_dc_dns(mem_ctx
, domain_name
, flags
,
1123 dclist
, num_dcs
, info
);
1126 status
= discover_dc_dns(mem_ctx
, domain_name
, domain_guid
, flags
,
1127 site_name
, &dclist
, &num_dcs
);
1129 if (NT_STATUS_IS_OK(status
) && num_dcs
!= 0) {
1131 status
= process_dc_dns(mem_ctx
, domain_name
, flags
, dclist
,
1133 if (NT_STATUS_IS_OK(status
)) {
1138 status
= discover_dc_netbios(mem_ctx
, domain_name
, flags
, &dclist
,
1140 NT_STATUS_NOT_OK_RETURN(status
);
1142 return process_dc_netbios(mem_ctx
, domain_name
, flags
, dclist
,
1146 /********************************************************************
1149 This will be the only public function here.
1150 ********************************************************************/
1152 NTSTATUS
dsgetdcname(TALLOC_CTX
*mem_ctx
,
1153 const char *domain_name
,
1154 struct GUID
*domain_guid
,
1155 const char *site_name
,
1157 struct netr_DsRGetDCNameInfo
**info
)
1159 NTSTATUS status
= NT_STATUS_DOMAIN_CONTROLLER_NOT_FOUND
;
1160 struct netr_DsRGetDCNameInfo
*myinfo
= NULL
;
1162 DEBUG(10,("dsgetdcname: domain_name: %s, "
1163 "domain_guid: %s, site_name: %s, flags: 0x%08x\n",
1165 domain_guid
? GUID_string(mem_ctx
, domain_guid
) : "(null)",
1170 if (!check_allowed_required_flags(flags
)) {
1171 DEBUG(0,("invalid flags specified\n"));
1172 return NT_STATUS_INVALID_PARAMETER
;
1175 if (flags
& DS_FORCE_REDISCOVERY
) {
1179 status
= dsgetdcname_cached(mem_ctx
, domain_name
, domain_guid
,
1180 flags
, site_name
, &myinfo
);
1181 if (NT_STATUS_IS_OK(status
)) {
1186 if (flags
& DS_BACKGROUND_ONLY
) {
1191 status
= dsgetdcname_rediscover(mem_ctx
, domain_name
,
1192 domain_guid
, flags
, site_name
,
1195 if (NT_STATUS_IS_OK(status
)) {
1196 dsgetdcname_cache_store(mem_ctx
, domain_name
, myinfo
);
1203 /****************************************************************
1204 ****************************************************************/
1206 bool pull_mailslot_cldap_reply(TALLOC_CTX
*mem_ctx
,
1207 const DATA_BLOB
*blob
,
1208 union nbt_cldap_netlogon
*r
,
1209 uint32_t *nt_version
)
1211 enum ndr_err_code ndr_err
;
1212 uint32_t nt_version_query
= ((*nt_version
) & 0x000000ff);
1213 uint16_t command
= 0;
1215 ndr_err
= ndr_pull_struct_blob(blob
, mem_ctx
, &command
,
1216 (ndr_pull_flags_fn_t
)ndr_pull_uint16
);
1217 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1227 DEBUG(1,("got unexpected command: %d (0x%08x)\n",
1232 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1233 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1234 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1238 /* when the caller requested just those nt_version bits that the server
1239 * was able to reply to, we are fine and all done. otherwise we need to
1240 * assume downgraded replies which are painfully parsed here - gd */
1242 if (nt_version_query
& NETLOGON_VERSION_WITH_CLOSEST_SITE
) {
1243 nt_version_query
&= ~NETLOGON_VERSION_WITH_CLOSEST_SITE
;
1245 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1246 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1247 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1250 if (nt_version_query
& NETLOGON_VERSION_5EX_WITH_IP
) {
1251 nt_version_query
&= ~NETLOGON_VERSION_5EX_WITH_IP
;
1253 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1254 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1255 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1258 if (nt_version_query
& NETLOGON_VERSION_5EX
) {
1259 nt_version_query
&= ~NETLOGON_VERSION_5EX
;
1261 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1262 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1263 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1266 if (nt_version_query
& NETLOGON_VERSION_5
) {
1267 nt_version_query
&= ~NETLOGON_VERSION_5
;
1269 ndr_err
= ndr_pull_union_blob_all(blob
, mem_ctx
, r
, nt_version_query
,
1270 (ndr_pull_flags_fn_t
)ndr_pull_nbt_cldap_netlogon
);
1271 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err
)) {
1278 if (DEBUGLEVEL
>= 10) {
1279 NDR_PRINT_UNION_DEBUG(nbt_cldap_netlogon
, nt_version_query
, r
);
1282 *nt_version
= nt_version_query
;