4 Authentication IDL structures
6 These are NOT public network structures, but it is helpful to define
7 these things in IDL. They may change without ABI breakage or
12 import
"misc.idl", "security.idl", "lsa.idl", "krb5pac.idl";
14 pyhelper
("librpc/ndr/py_auth.c"),
15 helper
("../librpc/ndr/ndr_auth.h"),
16 helpstring("internal Samba authentication structures")
21 typedef [public] enum {
22 SEC_AUTH_METHOD_UNAUTHENTICATED
= 0,
23 SEC_AUTH_METHOD_NTLM
= 1,
24 SEC_AUTH_METHOD_KERBEROS
= 2
27 /* This is the parts of the session_info that don't change
28 * during local privilage and group manipulations */
29 typedef [public] struct {
30 utf8string account_name
;
31 utf8string domain_name
;
34 utf8string logon_script
;
35 utf8string profile_path
;
36 utf8string home_directory
;
37 utf8string home_drive
;
38 utf8string logon_server
;
43 NTTIME last_password_change
;
44 NTTIME allow_password_change
;
45 NTTIME force_password_change
;
48 uint16 bad_password_count
;
55 /* This information is preserved only to assist torture tests */
56 typedef [public] struct {
57 /* Number SIDs from the DC netlogon validation info */
59 [size_is(num_dc_sids
)] dom_sid dc_sids
[*];
60 PAC_SIGNATURE_DATA
*pac_srv_sig
;
61 PAC_SIGNATURE_DATA
*pac_kdc_sig
;
62 } auth_user_info_torture
;
64 typedef [public] struct {
68 * For performance reasons we keep an alpha_strcpy-sanitized version
69 * of the username around as long as the global variable current_user
70 * still exists. If we did not do keep this, we'd have to call
71 * alpha_strcpy whenever we do a become_user(), potentially on every
72 * smb request. See set_current_user_info in source3.
74 utf8string sanitized_username
;
75 } auth_user_info_unix
;
77 /* This is the interim product of the auth subsystem, before
78 * privileges and local groups are handled */
79 typedef [public] struct {
81 [size_is(num_sids
)] dom_sid sids
[*];
83 DATA_BLOB user_session_key
;
84 DATA_BLOB lm_session_key
;
87 typedef [public] struct {
88 security_token
*security_token
;
89 security_unix_token
*unix_token
;
91 auth_user_info_unix
*unix_info
;
92 [value
(NULL
), ignore] auth_user_info_torture
*torture
;
93 DATA_BLOB session_key
;
94 [value
(NULL
), ignore] cli_credentials
*credentials
;
97 typedef [public] struct {
98 auth_session_info
*session_info
;
99 DATA_BLOB exported_gssapi_credentials
;
100 } auth_session_info_transport
;