2 Unix SMB/CIFS implementation.
5 Copyright (C) Andrew Tridgell 1992-2000,
6 Copyright (C) Luke Kenneth Casson Leighton 1996-2000,
7 Copyright (C) Elrond 2000,
8 Copyright (C) Tim Potter 2000
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 2 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program; if not, write to the Free Software
22 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
26 #include "rpcclient.h"
28 extern DOM_SID domain_sid
;
30 /****************************************************************************
31 display sam_user_info_7 structure
32 ****************************************************************************/
33 static void display_sam_user_info_7(SAM_USER_INFO_7
*usr
)
37 unistr2_to_ascii(temp
, &usr
->uni_name
, sizeof(temp
)-1);
38 printf("\tUser Name :\t%s\n", temp
);
41 /****************************************************************************
42 display sam_user_info_21 structure
43 ****************************************************************************/
44 static void display_sam_user_info_21(SAM_USER_INFO_21
*usr
)
48 unistr2_to_ascii(temp
, &usr
->uni_user_name
, sizeof(temp
)-1);
49 printf("\tUser Name :\t%s\n", temp
);
51 unistr2_to_ascii(temp
, &usr
->uni_full_name
, sizeof(temp
)-1);
52 printf("\tFull Name :\t%s\n", temp
);
54 unistr2_to_ascii(temp
, &usr
->uni_home_dir
, sizeof(temp
)-1);
55 printf("\tHome Drive :\t%s\n", temp
);
57 unistr2_to_ascii(temp
, &usr
->uni_dir_drive
, sizeof(temp
)-1);
58 printf("\tDir Drive :\t%s\n", temp
);
60 unistr2_to_ascii(temp
, &usr
->uni_profile_path
, sizeof(temp
)-1);
61 printf("\tProfile Path:\t%s\n", temp
);
63 unistr2_to_ascii(temp
, &usr
->uni_logon_script
, sizeof(temp
)-1);
64 printf("\tLogon Script:\t%s\n", temp
);
66 unistr2_to_ascii(temp
, &usr
->uni_acct_desc
, sizeof(temp
)-1);
67 printf("\tDescription :\t%s\n", temp
);
69 unistr2_to_ascii(temp
, &usr
->uni_workstations
, sizeof(temp
)-1);
70 printf("\tWorkstations:\t%s\n", temp
);
72 unistr2_to_ascii(temp
, &usr
->uni_unknown_str
, sizeof(temp
)-1);
73 printf("\tUnknown Str :\t%s\n", temp
);
75 unistr2_to_ascii(temp
, &usr
->uni_munged_dial
, sizeof(temp
)-1);
76 printf("\tRemote Dial :\t%s\n", temp
);
78 printf("\tLogon Time :\t%s\n",
79 http_timestring(nt_time_to_unix(&usr
->logon_time
)));
80 printf("\tLogoff Time :\t%s\n",
81 http_timestring(nt_time_to_unix(&usr
->logoff_time
)));
82 printf("\tKickoff Time :\t%s\n",
83 http_timestring(nt_time_to_unix(&usr
->kickoff_time
)));
84 printf("\tPassword last set Time :\t%s\n",
85 http_timestring(nt_time_to_unix(&usr
->pass_last_set_time
)));
86 printf("\tPassword can change Time :\t%s\n",
87 http_timestring(nt_time_to_unix(&usr
->pass_can_change_time
)));
88 printf("\tPassword must change Time:\t%s\n",
89 http_timestring(nt_time_to_unix(&usr
->pass_must_change_time
)));
91 printf("\tunknown_2[0..31]...\n"); /* user passwords? */
93 printf("\tuser_rid :\t0x%x\n" , usr
->user_rid
); /* User ID */
94 printf("\tgroup_rid:\t0x%x\n" , usr
->group_rid
); /* Group ID */
95 printf("\tacb_info :\t0x%04x\n", usr
->acb_info
); /* Account Control Info */
97 printf("\tfields_present:\t0x%08x\n", usr
->fields_present
); /* 0x00ff ffff */
98 printf("\tlogon_divs:\t%d\n", usr
->logon_divs
); /* 0x0000 00a8 which is 168 which is num hrs in a week */
99 printf("\tbad_password_count:\t0x%08x\n", usr
->bad_password_count
);
100 printf("\tlogon_count:\t0x%08x\n", usr
->logon_count
);
102 printf("\tpadding1[0..7]...\n");
104 if (usr
->ptr_logon_hrs
) {
105 printf("\tlogon_hrs[0..%d]...\n", usr
->logon_hrs
.len
);
109 static const char *display_time(NTTIME nttime
)
111 static fstring string
;
116 int days
, hours
, mins
, secs
;
118 if (nttime
.high
==0 && nttime
.low
==0)
121 if (nttime
.high
==0x80000000 && nttime
.low
==0)
128 high
= high
* (~nttime
.high
);
131 low
= low
/(1000*1000*10);
136 hours
=(sec
- (days
*60*60*24)) / (60*60);
137 mins
=(sec
- (days
*60*60*24) - (hours
*60*60) ) / 60;
138 secs
=sec
- (days
*60*60*24) - (hours
*60*60) - (mins
*60);
140 fstr_sprintf(string
, "%u days, %u hours, %u minutes, %u seconds", days
, hours
, mins
, secs
);
144 static const char* server_role_str(uint32 server_role
)
146 switch(server_role
) {
147 case ROLE_STANDALONE
:
148 return SMB_STRDUP("ROLE_STANDALONE");
150 case ROLE_DOMAIN_MEMBER
:
151 return SMB_STRDUP("ROLE_DOMAIN_MEMBER");
153 case ROLE_DOMAIN_BDC
:
154 return SMB_STRDUP("ROLE_DOMAIN_BDC");
156 case ROLE_DOMAIN_PDC
:
157 return SMB_STRDUP("ROLE_DOMAIN_PDC");
160 return SMB_STRDUP("Unknown -- internal error?");
165 static void display_sam_unk_info_1(SAM_UNK_INFO_1
*info1
)
168 printf("Minimum password length:\t\t\t%d\n", info1
->min_length_password
);
169 printf("Password uniqueness (remember x passwords):\t%d\n", info1
->password_history
);
170 printf("Password Properties:\t\t\t\t0x%08x\n", info1
->password_properties
);
172 if (info1
->password_properties
& DOMAIN_PASSWORD_COMPLEX
)
173 printf("\tDOMAIN_PASSWORD_COMPLEX\n");
175 if (info1
->password_properties
& DOMAIN_PASSWORD_NO_ANON_CHANGE
) {
176 printf("\tDOMAIN_PASSWORD_NO_ANON_CHANGE\n");
177 printf("users must open a session to change password ");
180 if (info1
->password_properties
& DOMAIN_PASSWORD_NO_CLEAR_CHANGE
)
181 printf("\tDOMAIN_PASSWORD_NO_CLEAR_CHANGE\n");
183 if (info1
->password_properties
& DOMAIN_LOCKOUT_ADMINS
)
184 printf("\tDOMAIN_LOCKOUT_ADMINS\n");
186 if (info1
->password_properties
& DOMAIN_PASSWORD_STORE_CLEARTEXT
)
187 printf("\tDOMAIN_PASSWORD_STORE_CLEARTEXT\n");
189 if (info1
->password_properties
& DOMAIN_REFUSE_PASSWORD_CHANGE
)
190 printf("\tDOMAIN_REFUSE_PASSWORD_CHANGE\n");
192 printf("password expire in:\t\t\t\t%s\n", display_time(info1
->expire
));
193 printf("Min password age (allow changing in x days):\t%s\n", display_time(info1
->min_passwordage
));
196 static void display_sam_unk_info_2(SAM_UNK_INFO_2
*info2
)
200 unistr2_to_ascii(name
, &info2
->uni_domain
, sizeof(name
) - 1);
201 printf("Domain:\t\t%s\n", name
);
203 unistr2_to_ascii(name
, &info2
->uni_server
, sizeof(name
) - 1);
204 printf("Server:\t\t%s\n", name
);
206 unistr2_to_ascii(name
, &info2
->uni_comment
, sizeof(name
) - 1);
207 printf("Comment:\t%s\n", name
);
209 printf("Total Users:\t%d\n", info2
->num_domain_usrs
);
210 printf("Total Groups:\t%d\n", info2
->num_domain_grps
);
211 printf("Total Aliases:\t%d\n", info2
->num_local_grps
);
213 printf("Sequence No:\t%d\n", info2
->seq_num
.low
);
215 printf("Force Logoff:\t%d\n", (int)nt_time_to_unix_abs(&info2
->logout
));
217 printf("Unknown 4:\t0x%x\n", info2
->unknown_4
);
218 printf("Server Role:\t%s\n", server_role_str(info2
->server_role
));
219 printf("Unknown 6:\t0x%x\n", info2
->unknown_6
);
222 static void display_sam_unk_info_7(SAM_UNK_INFO_7
*info7
)
224 printf("Server Role:\t%s\n", server_role_str(info7
->server_role
));
227 static void display_sam_unk_info_8(SAM_UNK_INFO_8
*info8
)
229 printf("Sequence No:\t%d\n", info8
->seq_num
.low
);
230 printf("Domain Create Time:\t%s\n",
231 http_timestring(nt_time_to_unix(&info8
->domain_create_time
)));
235 static void display_sam_unk_info_12(SAM_UNK_INFO_12
*info12
)
237 printf("Bad password lockout duration: %s\n", display_time(info12
->duration
));
238 printf("Reset Lockout after: %s\n", display_time(info12
->reset_count
));
239 printf("Lockout after bad attempts: %d\n", info12
->bad_attempt_lockout
);
242 static void display_sam_info_1(SAM_ENTRY1
*e1
, SAM_STR1
*s1
)
246 printf("index: 0x%x ", e1
->user_idx
);
247 printf("RID: 0x%x ", e1
->rid_user
);
248 printf("acb: 0x%x ", e1
->acb_info
);
250 unistr2_to_ascii(tmp
, &s1
->uni_acct_name
, sizeof(tmp
)-1);
251 printf("Account: %s\t", tmp
);
253 unistr2_to_ascii(tmp
, &s1
->uni_full_name
, sizeof(tmp
)-1);
254 printf("Name: %s\t", tmp
);
256 unistr2_to_ascii(tmp
, &s1
->uni_acct_desc
, sizeof(tmp
)-1);
257 printf("Desc: %s\n", tmp
);
260 static void display_sam_info_2(SAM_ENTRY2
*e2
, SAM_STR2
*s2
)
264 printf("index: 0x%x ", e2
->user_idx
);
265 printf("RID: 0x%x ", e2
->rid_user
);
266 printf("acb: 0x%x ", e2
->acb_info
);
268 unistr2_to_ascii(tmp
, &s2
->uni_srv_name
, sizeof(tmp
)-1);
269 printf("Account: %s\t", tmp
);
271 unistr2_to_ascii(tmp
, &s2
->uni_srv_desc
, sizeof(tmp
)-1);
272 printf("Name: %s\n", tmp
);
276 static void display_sam_info_3(SAM_ENTRY3
*e3
, SAM_STR3
*s3
)
280 printf("index: 0x%x ", e3
->grp_idx
);
281 printf("RID: 0x%x ", e3
->rid_grp
);
282 printf("attr: 0x%x ", e3
->attr
);
284 unistr2_to_ascii(tmp
, &s3
->uni_grp_name
, sizeof(tmp
)-1);
285 printf("Account: %s\t", tmp
);
287 unistr2_to_ascii(tmp
, &s3
->uni_grp_desc
, sizeof(tmp
)-1);
288 printf("Name: %s\n", tmp
);
292 static void display_sam_info_4(SAM_ENTRY4
*e4
, SAM_STR4
*s4
)
296 printf("index: %d ", e4
->user_idx
);
299 for (i
=0; i
<s4
->acct_name
.str_str_len
; i
++)
300 printf("%c", s4
->acct_name
.buffer
[i
]);
305 static void display_sam_info_5(SAM_ENTRY5
*e5
, SAM_STR5
*s5
)
309 printf("index: 0x%x ", e5
->grp_idx
);
312 for (i
=0; i
<s5
->grp_name
.str_str_len
; i
++)
313 printf("%c", s5
->grp_name
.buffer
[i
]);
318 /****************************************************************************
319 Try samr_connect4 first, then samr_conenct if it fails
320 ****************************************************************************/
321 static NTSTATUS
try_samr_connects(struct rpc_pipe_client
*cli
, TALLOC_CTX
*mem_ctx
,
322 uint32 access_mask
, POLICY_HND
*connect_pol
)
324 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
326 result
= rpccli_samr_connect4(cli
, mem_ctx
, access_mask
, connect_pol
);
327 if (!NT_STATUS_IS_OK(result
)) {
328 result
= rpccli_samr_connect(cli
, mem_ctx
, access_mask
,
334 /**********************************************************************
335 * Query user information
337 static NTSTATUS
cmd_samr_query_user(struct rpc_pipe_client
*cli
,
339 int argc
, const char **argv
)
341 POLICY_HND connect_pol
, domain_pol
, user_pol
;
342 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
343 uint32 info_level
= 21;
344 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
345 SAM_USERINFO_CTR
*user_ctr
;
349 if ((argc
< 2) || (argc
> 4)) {
350 printf("Usage: %s rid [info level] [access mask] \n", argv
[0]);
354 sscanf(argv
[1], "%i", &user_rid
);
357 sscanf(argv
[2], "%i", &info_level
);
360 sscanf(argv
[3], "%x", &access_mask
);
363 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
366 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
369 if (!NT_STATUS_IS_OK(result
))
372 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
373 MAXIMUM_ALLOWED_ACCESS
,
374 &domain_sid
, &domain_pol
);
376 if (!NT_STATUS_IS_OK(result
))
379 result
= rpccli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
381 user_rid
, &user_pol
);
383 if (!NT_STATUS_IS_OK(result
))
386 ZERO_STRUCT(user_ctr
);
388 result
= rpccli_samr_query_userinfo(cli
, mem_ctx
, &user_pol
,
389 info_level
, &user_ctr
);
391 if (!NT_STATUS_IS_OK(result
))
394 switch (user_ctr
->switch_value
) {
396 display_sam_user_info_21(user_ctr
->info
.id21
);
399 display_sam_user_info_7(user_ctr
->info
.id7
);
402 printf("Unsupported infolevel: %d\n", info_level
);
406 rpccli_samr_close(cli
, mem_ctx
, &user_pol
);
407 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
408 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
414 /****************************************************************************
416 ****************************************************************************/
417 static void display_group_info1(GROUP_INFO1
*info1
)
421 unistr2_to_ascii(temp
, &info1
->uni_acct_name
, sizeof(temp
)-1);
422 printf("\tGroup Name:\t%s\n", temp
);
423 unistr2_to_ascii(temp
, &info1
->uni_acct_desc
, sizeof(temp
)-1);
424 printf("\tDescription:\t%s\n", temp
);
425 printf("\tGroup Attribute:%d\n", info1
->group_attr
);
426 printf("\tNum Members:%d\n", info1
->num_members
);
429 /****************************************************************************
431 ****************************************************************************/
432 static void display_group_info3(GROUP_INFO3
*info3
)
434 printf("\tGroup Attribute:%d\n", info3
->group_attr
);
438 /****************************************************************************
440 ****************************************************************************/
441 static void display_group_info4(GROUP_INFO4
*info4
)
445 unistr2_to_ascii(desc
, &info4
->uni_acct_desc
, sizeof(desc
)-1);
446 printf("\tGroup Description:%s\n", desc
);
449 /****************************************************************************
450 display sam sync structure
451 ****************************************************************************/
452 static void display_group_info_ctr(GROUP_INFO_CTR
*ctr
)
454 switch (ctr
->switch_value1
) {
456 display_group_info1(&ctr
->group
.info1
);
460 display_group_info3(&ctr
->group
.info3
);
464 display_group_info4(&ctr
->group
.info4
);
470 /***********************************************************************
471 * Query group information
473 static NTSTATUS
cmd_samr_query_group(struct rpc_pipe_client
*cli
,
475 int argc
, const char **argv
)
477 POLICY_HND connect_pol
, domain_pol
, group_pol
;
478 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
479 uint32 info_level
= 1;
480 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
481 GROUP_INFO_CTR
*group_ctr
;
485 if ((argc
< 2) || (argc
> 4)) {
486 printf("Usage: %s rid [info level] [access mask]\n", argv
[0]);
490 sscanf(argv
[1], "%i", &group_rid
);
493 sscanf(argv
[2], "%i", &info_level
);
496 sscanf(argv
[3], "%x", &access_mask
);
498 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
501 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
504 if (!NT_STATUS_IS_OK(result
))
507 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
508 MAXIMUM_ALLOWED_ACCESS
,
509 &domain_sid
, &domain_pol
);
511 if (!NT_STATUS_IS_OK(result
))
514 result
= rpccli_samr_open_group(cli
, mem_ctx
, &domain_pol
,
516 group_rid
, &group_pol
);
518 if (!NT_STATUS_IS_OK(result
))
521 result
= rpccli_samr_query_groupinfo(cli
, mem_ctx
, &group_pol
,
522 info_level
, &group_ctr
);
523 if (!NT_STATUS_IS_OK(result
)) {
527 display_group_info_ctr(group_ctr
);
529 rpccli_samr_close(cli
, mem_ctx
, &group_pol
);
530 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
531 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
536 /* Query groups a user is a member of */
538 static NTSTATUS
cmd_samr_query_usergroups(struct rpc_pipe_client
*cli
,
540 int argc
, const char **argv
)
542 POLICY_HND connect_pol
,
545 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
548 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
553 if ((argc
< 2) || (argc
> 3)) {
554 printf("Usage: %s rid [access mask]\n", argv
[0]);
558 sscanf(argv
[1], "%i", &user_rid
);
561 sscanf(argv
[2], "%x", &access_mask
);
563 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
566 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
569 if (!NT_STATUS_IS_OK(result
))
572 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
573 MAXIMUM_ALLOWED_ACCESS
,
574 &domain_sid
, &domain_pol
);
576 if (!NT_STATUS_IS_OK(result
))
579 result
= rpccli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
581 user_rid
, &user_pol
);
583 if (!NT_STATUS_IS_OK(result
))
586 result
= rpccli_samr_query_usergroups(cli
, mem_ctx
, &user_pol
,
587 &num_groups
, &user_gids
);
589 if (!NT_STATUS_IS_OK(result
))
592 for (i
= 0; i
< num_groups
; i
++) {
593 printf("\tgroup rid:[0x%x] attr:[0x%x]\n",
594 user_gids
[i
].g_rid
, user_gids
[i
].attr
);
597 rpccli_samr_close(cli
, mem_ctx
, &user_pol
);
598 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
599 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
604 /* Query aliases a user is a member of */
606 static NTSTATUS
cmd_samr_query_useraliases(struct rpc_pipe_client
*cli
,
608 int argc
, const char **argv
)
610 POLICY_HND connect_pol
, domain_pol
;
611 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
614 uint32 num_aliases
, *alias_rids
;
615 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
621 printf("Usage: %s builtin|domain sid1 sid2 ...\n", argv
[0]);
622 return NT_STATUS_INVALID_PARAMETER
;
628 for (i
=2; i
<argc
; i
++) {
630 if (!string_to_sid(&tmp_sid
, argv
[i
])) {
631 printf("%s is not a legal SID\n", argv
[i
]);
632 return NT_STATUS_INVALID_PARAMETER
;
634 add_sid_to_array(mem_ctx
, &tmp_sid
, &sids
, &num_sids
);
637 sid2
= TALLOC_ARRAY(mem_ctx
, DOM_SID2
, num_sids
);
639 return NT_STATUS_NO_MEMORY
;
641 for (i
=0; i
<num_sids
; i
++) {
642 sid_copy(&sid2
[i
].sid
, &sids
[i
]);
643 sid2
[i
].num_auths
= sid2
[i
].sid
.num_auths
;
646 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
649 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
652 if (!NT_STATUS_IS_OK(result
))
655 if (StrCaseCmp(argv
[1], "domain")==0)
656 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
658 &domain_sid
, &domain_pol
);
659 else if (StrCaseCmp(argv
[1], "builtin")==0)
660 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
665 printf("Usage: %s builtin|domain sid1 sid2 ...\n", argv
[0]);
666 return NT_STATUS_INVALID_PARAMETER
;
669 if (!NT_STATUS_IS_OK(result
))
672 result
= rpccli_samr_query_useraliases(cli
, mem_ctx
, &domain_pol
,
674 &num_aliases
, &alias_rids
);
676 if (!NT_STATUS_IS_OK(result
))
679 for (i
= 0; i
< num_aliases
; i
++) {
680 printf("\tgroup rid:[0x%x]\n", alias_rids
[i
]);
683 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
684 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
689 /* Query members of a group */
691 static NTSTATUS
cmd_samr_query_groupmem(struct rpc_pipe_client
*cli
,
693 int argc
, const char **argv
)
695 POLICY_HND connect_pol
, domain_pol
, group_pol
;
696 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
697 uint32 num_members
, *group_rids
, *group_attrs
, group_rid
;
698 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
702 if ((argc
< 2) || (argc
> 3)) {
703 printf("Usage: %s rid [access mask]\n", argv
[0]);
707 sscanf(argv
[1], "%i", &group_rid
);
710 sscanf(argv
[2], "%x", &access_mask
);
712 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
715 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
718 if (!NT_STATUS_IS_OK(result
))
721 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
722 MAXIMUM_ALLOWED_ACCESS
,
723 &domain_sid
, &domain_pol
);
725 if (!NT_STATUS_IS_OK(result
))
728 result
= rpccli_samr_open_group(cli
, mem_ctx
, &domain_pol
,
730 group_rid
, &group_pol
);
732 if (!NT_STATUS_IS_OK(result
))
735 result
= rpccli_samr_query_groupmem(cli
, mem_ctx
, &group_pol
,
736 &num_members
, &group_rids
,
739 if (!NT_STATUS_IS_OK(result
))
742 for (i
= 0; i
< num_members
; i
++) {
743 printf("\trid:[0x%x] attr:[0x%x]\n", group_rids
[i
],
747 rpccli_samr_close(cli
, mem_ctx
, &group_pol
);
748 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
749 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
754 /* Enumerate domain users */
756 static NTSTATUS
cmd_samr_enum_dom_users(struct rpc_pipe_client
*cli
,
758 int argc
, const char **argv
)
760 POLICY_HND connect_pol
, domain_pol
;
761 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
762 uint32 start_idx
, size
, num_dom_users
, i
;
765 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
766 uint16 acb_mask
= ACB_NORMAL
;
767 BOOL got_connect_pol
= False
, got_domain_pol
= False
;
769 if ((argc
< 1) || (argc
> 3)) {
770 printf("Usage: %s [access_mask] [acb_mask]\n", argv
[0]);
775 sscanf(argv
[1], "%x", &access_mask
);
778 sscanf(argv
[2], "%hx", &acb_mask
);
780 /* Get sam policy handle */
782 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
785 if (!NT_STATUS_IS_OK(result
))
788 got_connect_pol
= True
;
790 /* Get domain policy handle */
792 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
794 &domain_sid
, &domain_pol
);
796 if (!NT_STATUS_IS_OK(result
))
799 got_domain_pol
= True
;
801 /* Enumerate domain users */
807 result
= rpccli_samr_enum_dom_users(
808 cli
, mem_ctx
, &domain_pol
, &start_idx
, acb_mask
,
809 size
, &dom_users
, &dom_rids
, &num_dom_users
);
811 if (NT_STATUS_IS_OK(result
) ||
812 NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
)) {
814 for (i
= 0; i
< num_dom_users
; i
++)
815 printf("user:[%s] rid:[0x%x]\n",
816 dom_users
[i
], dom_rids
[i
]);
819 } while (NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
));
823 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
826 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
831 /* Enumerate domain groups */
833 static NTSTATUS
cmd_samr_enum_dom_groups(struct rpc_pipe_client
*cli
,
835 int argc
, const char **argv
)
837 POLICY_HND connect_pol
, domain_pol
;
838 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
839 uint32 start_idx
, size
, num_dom_groups
, i
;
840 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
841 struct acct_info
*dom_groups
;
842 BOOL got_connect_pol
= False
, got_domain_pol
= False
;
844 if ((argc
< 1) || (argc
> 2)) {
845 printf("Usage: %s [access_mask]\n", argv
[0]);
850 sscanf(argv
[1], "%x", &access_mask
);
852 /* Get sam policy handle */
854 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
857 if (!NT_STATUS_IS_OK(result
))
860 got_connect_pol
= True
;
862 /* Get domain policy handle */
864 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
866 &domain_sid
, &domain_pol
);
868 if (!NT_STATUS_IS_OK(result
))
871 got_domain_pol
= True
;
873 /* Enumerate domain groups */
879 result
= rpccli_samr_enum_dom_groups(
880 cli
, mem_ctx
, &domain_pol
, &start_idx
, size
,
881 &dom_groups
, &num_dom_groups
);
883 if (NT_STATUS_IS_OK(result
) ||
884 NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
)) {
886 for (i
= 0; i
< num_dom_groups
; i
++)
887 printf("group:[%s] rid:[0x%x]\n",
888 dom_groups
[i
].acct_name
,
892 } while (NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
));
896 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
899 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
904 /* Enumerate alias groups */
906 static NTSTATUS
cmd_samr_enum_als_groups(struct rpc_pipe_client
*cli
,
908 int argc
, const char **argv
)
910 POLICY_HND connect_pol
, domain_pol
;
911 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
912 uint32 start_idx
, size
, num_als_groups
, i
;
913 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
914 struct acct_info
*als_groups
;
915 BOOL got_connect_pol
= False
, got_domain_pol
= False
;
917 if ((argc
< 2) || (argc
> 3)) {
918 printf("Usage: %s builtin|domain [access mask]\n", argv
[0]);
923 sscanf(argv
[2], "%x", &access_mask
);
925 /* Get sam policy handle */
927 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
930 if (!NT_STATUS_IS_OK(result
))
933 got_connect_pol
= True
;
935 /* Get domain policy handle */
937 if (StrCaseCmp(argv
[1], "domain")==0)
938 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
940 &domain_sid
, &domain_pol
);
941 else if (StrCaseCmp(argv
[1], "builtin")==0)
942 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
944 &global_sid_Builtin
, &domain_pol
);
948 if (!NT_STATUS_IS_OK(result
))
951 got_domain_pol
= True
;
953 /* Enumerate alias groups */
956 size
= 0xffff; /* Number of groups to retrieve */
959 result
= rpccli_samr_enum_als_groups(
960 cli
, mem_ctx
, &domain_pol
, &start_idx
, size
,
961 &als_groups
, &num_als_groups
);
963 if (NT_STATUS_IS_OK(result
) ||
964 NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
)) {
966 for (i
= 0; i
< num_als_groups
; i
++)
967 printf("group:[%s] rid:[0x%x]\n",
968 als_groups
[i
].acct_name
,
971 } while (NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
));
975 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
978 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
983 /* Query alias membership */
985 static NTSTATUS
cmd_samr_query_aliasmem(struct rpc_pipe_client
*cli
,
987 int argc
, const char **argv
)
989 POLICY_HND connect_pol
, domain_pol
, alias_pol
;
990 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
991 uint32 alias_rid
, num_members
, i
;
992 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
995 if ((argc
< 3) || (argc
> 4)) {
996 printf("Usage: %s builtin|domain rid [access mask]\n", argv
[0]);
1000 sscanf(argv
[2], "%i", &alias_rid
);
1003 sscanf(argv
[3], "%x", &access_mask
);
1005 /* Open SAMR handle */
1007 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1010 if (!NT_STATUS_IS_OK(result
))
1013 /* Open handle on domain */
1015 if (StrCaseCmp(argv
[1], "domain")==0)
1016 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1017 MAXIMUM_ALLOWED_ACCESS
,
1018 &domain_sid
, &domain_pol
);
1019 else if (StrCaseCmp(argv
[1], "builtin")==0)
1020 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1021 MAXIMUM_ALLOWED_ACCESS
,
1022 &global_sid_Builtin
, &domain_pol
);
1024 return NT_STATUS_OK
;
1026 if (!NT_STATUS_IS_OK(result
))
1029 /* Open handle on alias */
1031 result
= rpccli_samr_open_alias(cli
, mem_ctx
, &domain_pol
,
1033 alias_rid
, &alias_pol
);
1034 if (!NT_STATUS_IS_OK(result
))
1037 result
= rpccli_samr_query_aliasmem(cli
, mem_ctx
, &alias_pol
,
1038 &num_members
, &alias_sids
);
1040 if (!NT_STATUS_IS_OK(result
))
1043 for (i
= 0; i
< num_members
; i
++) {
1046 sid_to_string(sid_str
, &alias_sids
[i
]);
1047 printf("\tsid:[%s]\n", sid_str
);
1050 rpccli_samr_close(cli
, mem_ctx
, &alias_pol
);
1051 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1052 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1057 /* Query display info */
1059 static NTSTATUS
cmd_samr_query_dispinfo(struct rpc_pipe_client
*cli
,
1060 TALLOC_CTX
*mem_ctx
,
1061 int argc
, const char **argv
)
1063 POLICY_HND connect_pol
, domain_pol
;
1064 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1065 uint32 start_idx
=0, max_entries
=250, max_size
= 0xffff, num_entries
, i
;
1066 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1067 uint32 info_level
= 1;
1068 SAM_DISPINFO_CTR ctr
;
1069 SAM_DISPINFO_1 info1
;
1070 SAM_DISPINFO_2 info2
;
1071 SAM_DISPINFO_3 info3
;
1072 SAM_DISPINFO_4 info4
;
1073 SAM_DISPINFO_5 info5
;
1075 BOOL got_params
= False
; /* Use get_query_dispinfo_params() or not? */
1078 printf("Usage: %s [info level] [start index] [max entries] [max size] [access mask]\n", argv
[0]);
1079 return NT_STATUS_OK
;
1083 sscanf(argv
[1], "%i", &info_level
);
1086 sscanf(argv
[2], "%i", &start_idx
);
1089 sscanf(argv
[3], "%i", &max_entries
);
1094 sscanf(argv
[4], "%i", &max_size
);
1099 sscanf(argv
[5], "%x", &access_mask
);
1101 /* Get sam policy handle */
1103 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1106 if (!NT_STATUS_IS_OK(result
))
1109 /* Get domain policy handle */
1111 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1113 &domain_sid
, &domain_pol
);
1115 if (!NT_STATUS_IS_OK(result
))
1118 /* Query display info */
1123 switch (info_level
) {
1126 ctr
.sam
.info1
= &info1
;
1130 ctr
.sam
.info2
= &info2
;
1134 ctr
.sam
.info3
= &info3
;
1138 ctr
.sam
.info4
= &info4
;
1142 ctr
.sam
.info5
= &info5
;
1150 get_query_dispinfo_params(
1151 loop_count
, &max_entries
, &max_size
);
1153 result
= rpccli_samr_query_dispinfo(cli
, mem_ctx
, &domain_pol
,
1154 &start_idx
, info_level
,
1155 &num_entries
, max_entries
,
1160 if (NT_STATUS_IS_ERR(result
))
1163 if (num_entries
== 0)
1166 for (i
= 0; i
< num_entries
; i
++) {
1167 switch (info_level
) {
1169 display_sam_info_1(&ctr
.sam
.info1
->sam
[i
], &ctr
.sam
.info1
->str
[i
]);
1172 display_sam_info_2(&ctr
.sam
.info2
->sam
[i
], &ctr
.sam
.info2
->str
[i
]);
1175 display_sam_info_3(&ctr
.sam
.info3
->sam
[i
], &ctr
.sam
.info3
->str
[i
]);
1178 display_sam_info_4(&ctr
.sam
.info4
->sam
[i
], &ctr
.sam
.info4
->str
[i
]);
1181 display_sam_info_5(&ctr
.sam
.info5
->sam
[i
], &ctr
.sam
.info5
->str
[i
]);
1185 } while ( NT_STATUS_EQUAL(result
, STATUS_MORE_ENTRIES
));
1187 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1188 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1193 /* Query domain info */
1195 static NTSTATUS
cmd_samr_query_dominfo(struct rpc_pipe_client
*cli
,
1196 TALLOC_CTX
*mem_ctx
,
1197 int argc
, const char **argv
)
1199 POLICY_HND connect_pol
, domain_pol
;
1200 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1201 uint32 switch_level
= 2;
1202 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1206 printf("Usage: %s [info level] [access mask]\n", argv
[0]);
1207 return NT_STATUS_OK
;
1211 sscanf(argv
[1], "%i", &switch_level
);
1214 sscanf(argv
[2], "%x", &access_mask
);
1216 /* Get sam policy handle */
1218 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1221 if (!NT_STATUS_IS_OK(result
))
1224 /* Get domain policy handle */
1226 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1228 &domain_sid
, &domain_pol
);
1230 if (!NT_STATUS_IS_OK(result
))
1233 /* Query domain info */
1235 result
= rpccli_samr_query_dom_info(cli
, mem_ctx
, &domain_pol
,
1236 switch_level
, &ctr
);
1238 if (!NT_STATUS_IS_OK(result
))
1241 /* Display domain info */
1243 switch (switch_level
) {
1245 display_sam_unk_info_1(&ctr
.info
.inf1
);
1248 display_sam_unk_info_2(&ctr
.info
.inf2
);
1251 display_sam_unk_info_7(&ctr
.info
.inf7
);
1254 display_sam_unk_info_8(&ctr
.info
.inf8
);
1257 display_sam_unk_info_12(&ctr
.info
.inf12
);
1260 printf("cannot display domain info for switch value %d\n",
1267 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1268 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1272 /* Create domain user */
1274 static NTSTATUS
cmd_samr_create_dom_user(struct rpc_pipe_client
*cli
,
1275 TALLOC_CTX
*mem_ctx
,
1276 int argc
, const char **argv
)
1278 POLICY_HND connect_pol
, domain_pol
, user_pol
;
1279 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1280 const char *acct_name
;
1282 uint32 unknown
, user_rid
;
1283 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1285 if ((argc
< 2) || (argc
> 3)) {
1286 printf("Usage: %s username [access mask]\n", argv
[0]);
1287 return NT_STATUS_OK
;
1290 acct_name
= argv
[1];
1293 sscanf(argv
[2], "%x", &access_mask
);
1295 /* Get sam policy handle */
1297 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1300 if (!NT_STATUS_IS_OK(result
))
1303 /* Get domain policy handle */
1305 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1307 &domain_sid
, &domain_pol
);
1309 if (!NT_STATUS_IS_OK(result
))
1312 /* Create domain user */
1314 acb_info
= ACB_NORMAL
;
1315 unknown
= 0xe005000b; /* No idea what this is - a permission mask? */
1317 result
= rpccli_samr_create_dom_user(cli
, mem_ctx
, &domain_pol
,
1318 acct_name
, acb_info
, unknown
,
1319 &user_pol
, &user_rid
);
1321 if (!NT_STATUS_IS_OK(result
))
1324 result
= rpccli_samr_close(cli
, mem_ctx
, &user_pol
);
1325 if (!NT_STATUS_IS_OK(result
)) goto done
;
1327 result
= rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1328 if (!NT_STATUS_IS_OK(result
)) goto done
;
1330 result
= rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1331 if (!NT_STATUS_IS_OK(result
)) goto done
;
1337 /* Create domain group */
1339 static NTSTATUS
cmd_samr_create_dom_group(struct rpc_pipe_client
*cli
,
1340 TALLOC_CTX
*mem_ctx
,
1341 int argc
, const char **argv
)
1343 POLICY_HND connect_pol
, domain_pol
, group_pol
;
1344 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1345 const char *grp_name
;
1346 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1348 if ((argc
< 2) || (argc
> 3)) {
1349 printf("Usage: %s groupname [access mask]\n", argv
[0]);
1350 return NT_STATUS_OK
;
1356 sscanf(argv
[2], "%x", &access_mask
);
1358 /* Get sam policy handle */
1360 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1363 if (!NT_STATUS_IS_OK(result
))
1366 /* Get domain policy handle */
1368 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1370 &domain_sid
, &domain_pol
);
1372 if (!NT_STATUS_IS_OK(result
))
1375 /* Create domain user */
1377 result
= rpccli_samr_create_dom_group(cli
, mem_ctx
, &domain_pol
,
1378 grp_name
, MAXIMUM_ALLOWED_ACCESS
,
1381 if (!NT_STATUS_IS_OK(result
))
1384 result
= rpccli_samr_close(cli
, mem_ctx
, &group_pol
);
1385 if (!NT_STATUS_IS_OK(result
)) goto done
;
1387 result
= rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1388 if (!NT_STATUS_IS_OK(result
)) goto done
;
1390 result
= rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1391 if (!NT_STATUS_IS_OK(result
)) goto done
;
1397 /* Lookup sam names */
1399 static NTSTATUS
cmd_samr_lookup_names(struct rpc_pipe_client
*cli
,
1400 TALLOC_CTX
*mem_ctx
,
1401 int argc
, const char **argv
)
1403 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1404 POLICY_HND connect_pol
, domain_pol
;
1405 uint32 flags
= 0x000003e8; /* Unknown */
1406 uint32 num_rids
, num_names
, *name_types
, *rids
;
1411 printf("Usage: %s domain|builtin name1 [name2 [name3] [...]]\n", argv
[0]);
1412 printf("check on the domain SID: S-1-5-21-x-y-z\n");
1413 printf("or check on the builtin SID: S-1-5-32\n");
1414 return NT_STATUS_OK
;
1417 /* Get sam policy and domain handles */
1419 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1422 if (!NT_STATUS_IS_OK(result
))
1425 if (StrCaseCmp(argv
[1], "domain")==0)
1426 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1427 MAXIMUM_ALLOWED_ACCESS
,
1428 &domain_sid
, &domain_pol
);
1429 else if (StrCaseCmp(argv
[1], "builtin")==0)
1430 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1431 MAXIMUM_ALLOWED_ACCESS
,
1432 &global_sid_Builtin
, &domain_pol
);
1434 return NT_STATUS_OK
;
1436 if (!NT_STATUS_IS_OK(result
))
1441 num_names
= argc
- 2;
1442 names
= TALLOC_ARRAY(mem_ctx
, const char *, num_names
);
1444 for (i
= 0; i
< argc
- 2; i
++)
1445 names
[i
] = argv
[i
+ 2];
1447 result
= rpccli_samr_lookup_names(cli
, mem_ctx
, &domain_pol
,
1448 flags
, num_names
, names
,
1449 &num_rids
, &rids
, &name_types
);
1451 if (!NT_STATUS_IS_OK(result
))
1454 /* Display results */
1456 for (i
= 0; i
< num_names
; i
++)
1457 printf("name %s: 0x%x (%d)\n", names
[i
], rids
[i
],
1460 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1461 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1466 /* Lookup sam rids */
1468 static NTSTATUS
cmd_samr_lookup_rids(struct rpc_pipe_client
*cli
,
1469 TALLOC_CTX
*mem_ctx
,
1470 int argc
, const char **argv
)
1472 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1473 POLICY_HND connect_pol
, domain_pol
;
1474 uint32 num_rids
, num_names
, *rids
, *name_types
;
1479 printf("Usage: %s domain|builtin rid1 [rid2 [rid3] [...]]\n", argv
[0]);
1480 return NT_STATUS_OK
;
1483 /* Get sam policy and domain handles */
1485 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1488 if (!NT_STATUS_IS_OK(result
))
1491 if (StrCaseCmp(argv
[1], "domain")==0)
1492 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1493 MAXIMUM_ALLOWED_ACCESS
,
1494 &domain_sid
, &domain_pol
);
1495 else if (StrCaseCmp(argv
[1], "builtin")==0)
1496 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1497 MAXIMUM_ALLOWED_ACCESS
,
1498 &global_sid_Builtin
, &domain_pol
);
1500 return NT_STATUS_OK
;
1502 if (!NT_STATUS_IS_OK(result
))
1507 num_rids
= argc
- 2;
1508 rids
= TALLOC_ARRAY(mem_ctx
, uint32
, num_rids
);
1510 for (i
= 0; i
< argc
- 2; i
++)
1511 sscanf(argv
[i
+ 2], "%i", &rids
[i
]);
1513 result
= rpccli_samr_lookup_rids(cli
, mem_ctx
, &domain_pol
, num_rids
, rids
,
1514 &num_names
, &names
, &name_types
);
1516 if (!NT_STATUS_IS_OK(result
) &&
1517 !NT_STATUS_EQUAL(result
, STATUS_SOME_UNMAPPED
))
1520 /* Display results */
1522 for (i
= 0; i
< num_names
; i
++)
1523 printf("rid 0x%x: %s (%d)\n", rids
[i
], names
[i
], name_types
[i
]);
1525 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1526 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1531 /* Delete domain user */
1533 static NTSTATUS
cmd_samr_delete_dom_user(struct rpc_pipe_client
*cli
,
1534 TALLOC_CTX
*mem_ctx
,
1535 int argc
, const char **argv
)
1537 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1538 POLICY_HND connect_pol
, domain_pol
, user_pol
;
1539 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1541 if ((argc
< 2) || (argc
> 3)) {
1542 printf("Usage: %s username\n", argv
[0]);
1543 return NT_STATUS_OK
;
1547 sscanf(argv
[2], "%x", &access_mask
);
1549 /* Get sam policy and domain handles */
1551 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1554 if (!NT_STATUS_IS_OK(result
))
1557 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1558 MAXIMUM_ALLOWED_ACCESS
,
1559 &domain_sid
, &domain_pol
);
1561 if (!NT_STATUS_IS_OK(result
))
1564 /* Get handle on user */
1567 uint32
*user_rids
, num_rids
, *name_types
;
1568 uint32 flags
= 0x000003e8; /* Unknown */
1570 result
= rpccli_samr_lookup_names(cli
, mem_ctx
, &domain_pol
,
1571 flags
, 1, (const char **)&argv
[1],
1572 &num_rids
, &user_rids
,
1575 if (!NT_STATUS_IS_OK(result
))
1578 result
= rpccli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
1580 user_rids
[0], &user_pol
);
1582 if (!NT_STATUS_IS_OK(result
))
1588 result
= rpccli_samr_delete_dom_user(cli
, mem_ctx
, &user_pol
);
1590 if (!NT_STATUS_IS_OK(result
))
1593 /* Display results */
1595 rpccli_samr_close(cli
, mem_ctx
, &user_pol
);
1596 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1597 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1603 /**********************************************************************
1604 * Query user security object
1606 static NTSTATUS
cmd_samr_query_sec_obj(struct rpc_pipe_client
*cli
,
1607 TALLOC_CTX
*mem_ctx
,
1608 int argc
, const char **argv
)
1610 POLICY_HND connect_pol
, domain_pol
, user_pol
, *pol
;
1611 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1612 uint32 info_level
= 4;
1614 uint32 user_rid
= 0;
1615 TALLOC_CTX
*ctx
= NULL
;
1616 SEC_DESC_BUF
*sec_desc_buf
=NULL
;
1617 BOOL domain
= False
;
1619 ctx
=talloc_init("cmd_samr_query_sec_obj");
1621 if ((argc
< 1) || (argc
> 2)) {
1622 printf("Usage: %s [rid|-d]\n", argv
[0]);
1623 printf("\tSpecify rid for security on user, -d for security on domain\n");
1624 return NT_STATUS_OK
;
1628 if (strcmp(argv
[1], "-d") == 0)
1631 sscanf(argv
[1], "%i", &user_rid
);
1634 slprintf(server
, sizeof(fstring
)-1, "\\\\%s", cli
->cli
->desthost
);
1636 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1639 if (!NT_STATUS_IS_OK(result
))
1642 if (domain
|| user_rid
)
1643 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1644 MAXIMUM_ALLOWED_ACCESS
,
1645 &domain_sid
, &domain_pol
);
1647 if (!NT_STATUS_IS_OK(result
))
1651 result
= rpccli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
1652 MAXIMUM_ALLOWED_ACCESS
,
1653 user_rid
, &user_pol
);
1655 if (!NT_STATUS_IS_OK(result
))
1658 /* Pick which query pol to use */
1668 /* Query SAM security object */
1670 result
= rpccli_samr_query_sec_obj(cli
, mem_ctx
, pol
, info_level
, ctx
,
1673 if (!NT_STATUS_IS_OK(result
))
1676 display_sec_desc(sec_desc_buf
->sec
);
1678 rpccli_samr_close(cli
, mem_ctx
, &user_pol
);
1679 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1680 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1682 talloc_destroy(ctx
);
1686 static NTSTATUS
cmd_samr_get_dom_pwinfo(struct rpc_pipe_client
*cli
,
1687 TALLOC_CTX
*mem_ctx
,
1688 int argc
, const char **argv
)
1690 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1691 uint16 min_pwd_length
;
1692 uint32 password_properties
;
1695 printf("Usage: %s\n", argv
[0]);
1696 return NT_STATUS_OK
;
1699 result
= rpccli_samr_get_dom_pwinfo(cli
, mem_ctx
, &min_pwd_length
, &password_properties
) ;
1701 if (NT_STATUS_IS_OK(result
)) {
1702 printf("min_pwd_length: %d\n", min_pwd_length
);
1703 printf("password_properties: 0x%08x\n", password_properties
);
1705 if (password_properties
& DOMAIN_PASSWORD_COMPLEX
)
1706 printf("\tDOMAIN_PASSWORD_COMPLEX\n");
1708 if (password_properties
& DOMAIN_PASSWORD_NO_ANON_CHANGE
)
1709 printf("\tDOMAIN_PASSWORD_NO_ANON_CHANGE\n");
1711 if (password_properties
& DOMAIN_PASSWORD_NO_CLEAR_CHANGE
)
1712 printf("\tDOMAIN_PASSWORD_NO_CLEAR_CHANGE\n");
1714 if (password_properties
& DOMAIN_LOCKOUT_ADMINS
)
1715 printf("\tDOMAIN_LOCKOUT_ADMINS\n");
1717 if (password_properties
& DOMAIN_PASSWORD_STORE_CLEARTEXT
)
1718 printf("\tDOMAIN_PASSWORD_STORE_CLEARTEXT\n");
1720 if (password_properties
& DOMAIN_REFUSE_PASSWORD_CHANGE
)
1721 printf("\tDOMAIN_REFUSE_PASSWORD_CHANGE\n");
1727 /* Look up domain name */
1729 static NTSTATUS
cmd_samr_lookup_domain(struct rpc_pipe_client
*cli
,
1730 TALLOC_CTX
*mem_ctx
,
1731 int argc
, const char **argv
)
1733 POLICY_HND connect_pol
, domain_pol
;
1734 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1735 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1736 fstring domain_name
,sid_string
;
1740 printf("Usage: %s domain_name\n", argv
[0]);
1741 return NT_STATUS_OK
;
1744 sscanf(argv
[1], "%s", domain_name
);
1746 result
= try_samr_connects(cli
, mem_ctx
, access_mask
, &connect_pol
);
1748 if (!NT_STATUS_IS_OK(result
))
1751 result
= rpccli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1752 access_mask
, &domain_sid
, &domain_pol
);
1754 if (!NT_STATUS_IS_OK(result
))
1757 result
= rpccli_samr_lookup_domain(
1758 cli
, mem_ctx
, &connect_pol
, domain_name
, &sid
);
1760 sid_to_string(sid_string
,&sid
);
1762 if (NT_STATUS_IS_OK(result
))
1763 printf("SAMR_LOOKUP_DOMAIN: Domain Name: %s Domain SID: %s\n",
1764 domain_name
,sid_string
);
1766 rpccli_samr_close(cli
, mem_ctx
, &domain_pol
);
1767 rpccli_samr_close(cli
, mem_ctx
, &connect_pol
);
1773 /* List of commands exported by this module */
1775 struct cmd_set samr_commands
[] = {
1779 { "queryuser", RPC_RTYPE_NTSTATUS
, cmd_samr_query_user
, NULL
, PI_SAMR
, NULL
, "Query user info", "" },
1780 { "querygroup", RPC_RTYPE_NTSTATUS
, cmd_samr_query_group
, NULL
, PI_SAMR
, NULL
, "Query group info", "" },
1781 { "queryusergroups", RPC_RTYPE_NTSTATUS
, cmd_samr_query_usergroups
, NULL
, PI_SAMR
, NULL
, "Query user groups", "" },
1782 { "queryuseraliases", RPC_RTYPE_NTSTATUS
, cmd_samr_query_useraliases
, NULL
, PI_SAMR
, NULL
, "Query user aliases", "" },
1783 { "querygroupmem", RPC_RTYPE_NTSTATUS
, cmd_samr_query_groupmem
, NULL
, PI_SAMR
, NULL
, "Query group membership", "" },
1784 { "queryaliasmem", RPC_RTYPE_NTSTATUS
, cmd_samr_query_aliasmem
, NULL
, PI_SAMR
, NULL
, "Query alias membership", "" },
1785 { "querydispinfo", RPC_RTYPE_NTSTATUS
, cmd_samr_query_dispinfo
, NULL
, PI_SAMR
, NULL
, "Query display info", "" },
1786 { "querydominfo", RPC_RTYPE_NTSTATUS
, cmd_samr_query_dominfo
, NULL
, PI_SAMR
, NULL
, "Query domain info", "" },
1787 { "enumdomusers", RPC_RTYPE_NTSTATUS
, cmd_samr_enum_dom_users
, NULL
, PI_SAMR
, NULL
, "Enumerate domain users", "" },
1788 { "enumdomgroups", RPC_RTYPE_NTSTATUS
, cmd_samr_enum_dom_groups
, NULL
, PI_SAMR
, NULL
, "Enumerate domain groups", "" },
1789 { "enumalsgroups", RPC_RTYPE_NTSTATUS
, cmd_samr_enum_als_groups
, NULL
, PI_SAMR
, NULL
, "Enumerate alias groups", "" },
1791 { "createdomuser", RPC_RTYPE_NTSTATUS
, cmd_samr_create_dom_user
, NULL
, PI_SAMR
, NULL
, "Create domain user", "" },
1792 { "createdomgroup", RPC_RTYPE_NTSTATUS
, cmd_samr_create_dom_group
, NULL
, PI_SAMR
, NULL
, "Create domain group", "" },
1793 { "samlookupnames", RPC_RTYPE_NTSTATUS
, cmd_samr_lookup_names
, NULL
, PI_SAMR
, NULL
, "Look up names", "" },
1794 { "samlookuprids", RPC_RTYPE_NTSTATUS
, cmd_samr_lookup_rids
, NULL
, PI_SAMR
, NULL
, "Look up names", "" },
1795 { "deletedomuser", RPC_RTYPE_NTSTATUS
, cmd_samr_delete_dom_user
, NULL
, PI_SAMR
, NULL
, "Delete domain user", "" },
1796 { "samquerysecobj", RPC_RTYPE_NTSTATUS
, cmd_samr_query_sec_obj
, NULL
, PI_SAMR
, NULL
, "Query SAMR security object", "" },
1797 { "getdompwinfo", RPC_RTYPE_NTSTATUS
, cmd_samr_get_dom_pwinfo
, NULL
, PI_SAMR
, NULL
, "Retrieve domain password info", "" },
1799 { "lookupdomain", RPC_RTYPE_NTSTATUS
, cmd_samr_lookup_domain
, NULL
, PI_SAMR
, NULL
, "Lookup Domain Name", "" },