2 Unix SMB/CIFS implementation.
4 Convert a server info struct into the form for PAC and NETLOGON replies
6 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2004
7 Copyright (C) Stefan Metzmacher <metze@samba.org> 2005
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 2 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program; if not, write to the Free Software
21 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
25 #include "auth/auth.h"
26 #include "libcli/security/security.h"
27 #include "librpc/gen_ndr/ndr_netlogon.h"
29 NTSTATUS
auth_convert_server_info_sambaseinfo(TALLOC_CTX
*mem_ctx
,
30 struct auth_serversupplied_info
*server_info
,
31 struct netr_SamBaseInfo
**_sam
)
33 struct netr_SamBaseInfo
*sam
= talloc_zero(mem_ctx
, struct netr_SamBaseInfo
);
34 NT_STATUS_HAVE_NO_MEMORY(sam
);
36 sam
->domain_sid
= dom_sid_dup(mem_ctx
, server_info
->account_sid
);
37 NT_STATUS_HAVE_NO_MEMORY(sam
->domain_sid
);
38 sam
->domain_sid
->num_auths
--;
40 sam
->last_logon
= server_info
->last_logon
;
41 sam
->last_logoff
= server_info
->last_logoff
;
42 sam
->acct_expiry
= server_info
->acct_expiry
;
43 sam
->last_password_change
= server_info
->last_password_change
;
44 sam
->allow_password_change
= server_info
->allow_password_change
;
45 sam
->force_password_change
= server_info
->force_password_change
;
47 sam
->account_name
.string
= server_info
->account_name
;
48 sam
->full_name
.string
= server_info
->full_name
;
49 sam
->logon_script
.string
= server_info
->logon_script
;
50 sam
->profile_path
.string
= server_info
->profile_path
;
51 sam
->home_directory
.string
= server_info
->home_directory
;
52 sam
->home_drive
.string
= server_info
->home_drive
;
54 sam
->logon_count
= server_info
->logon_count
;
55 sam
->bad_password_count
= sam
->bad_password_count
;
56 sam
->rid
= server_info
->account_sid
->sub_auths
[server_info
->account_sid
->num_auths
-1];
57 sam
->primary_gid
= server_info
->primary_group_sid
->sub_auths
[server_info
->primary_group_sid
->num_auths
-1];
59 sam
->groups
.count
= 0;
60 sam
->groups
.rids
= NULL
;
62 if (server_info
->n_domain_groups
> 0) {
64 sam
->groups
.rids
= talloc_array(sam
, struct samr_RidWithAttribute
,
65 server_info
->n_domain_groups
);
67 if (sam
->groups
.rids
== NULL
)
68 return NT_STATUS_NO_MEMORY
;
70 for (i
=0; i
<server_info
->n_domain_groups
; i
++) {
71 struct dom_sid
*group_sid
= server_info
->domain_groups
[i
];
72 if (!dom_sid_in_domain(sam
->domain_sid
, group_sid
)) {
73 /* We handle this elsewhere */
76 sam
->groups
.rids
[sam
->groups
.count
].rid
=
77 group_sid
->sub_auths
[group_sid
->num_auths
-1];
79 sam
->groups
.rids
[sam
->groups
.count
].attributes
=
80 SE_GROUP_MANDATORY
| SE_GROUP_ENABLED_BY_DEFAULT
| SE_GROUP_ENABLED
;
81 sam
->groups
.count
+= 1;
85 sam
->user_flags
= 0; /* TODO: w2k3 uses 0x120. We know 0x20
86 * as extra sids (PAC doc) but what is
88 sam
->acct_flags
= server_info
->acct_flags
;
89 sam
->logon_server
.string
= server_info
->logon_server
;
90 sam
->domain
.string
= server_info
->domain_name
;
92 ZERO_STRUCT(sam
->unknown
);
94 ZERO_STRUCT(sam
->key
);
95 if (server_info
->user_session_key
.length
== sizeof(sam
->key
.key
)) {
96 memcpy(sam
->key
.key
, server_info
->user_session_key
.data
, sizeof(sam
->key
.key
));
99 ZERO_STRUCT(sam
->LMSessKey
);
100 if (server_info
->lm_session_key
.length
== sizeof(sam
->LMSessKey
.key
)) {
101 memcpy(sam
->LMSessKey
.key
, server_info
->lm_session_key
.data
,
102 sizeof(sam
->LMSessKey
.key
));
110 NTSTATUS
auth_convert_server_info_saminfo3(TALLOC_CTX
*mem_ctx
,
111 struct auth_serversupplied_info
*server_info
,
112 struct netr_SamInfo3
**_sam3
)
114 struct netr_SamBaseInfo
*sam
;
115 struct netr_SamInfo3
*sam3
= talloc_zero(mem_ctx
, struct netr_SamInfo3
);
118 NT_STATUS_HAVE_NO_MEMORY(sam3
);
120 status
= auth_convert_server_info_sambaseinfo(mem_ctx
, server_info
, &sam
);
121 if (!NT_STATUS_IS_OK(status
)) {
129 sam3
->sids
= talloc_array(sam
, struct netr_SidAttr
,
130 server_info
->n_domain_groups
);
131 NT_STATUS_HAVE_NO_MEMORY(sam3
->sids
);
133 for (i
=0; i
<server_info
->n_domain_groups
; i
++) {
134 if (dom_sid_in_domain(sam
->domain_sid
, server_info
->domain_groups
[i
])) {
137 sam3
->sids
[sam3
->sidcount
].sid
= talloc_reference(sam3
->sids
,server_info
->domain_groups
[i
]);
138 sam3
->sids
[sam3
->sidcount
].attribute
=
139 SE_GROUP_MANDATORY
| SE_GROUP_ENABLED_BY_DEFAULT
| SE_GROUP_ENABLED
;
142 if (sam3
->sidcount
) {
143 sam3
->base
.user_flags
|= NETLOGON_EXTRA_SIDS
;