auth: Allow auth_samba4 to be forced to run a specific auth module
[Samba/wip.git] / source4 / libnet / libnet_site.c
blobaf105b78ea634fa998c5022555af8e70fcdf7704
1 /*
2 Unix SMB/CIFS implementation.
4 Copyright (C) Brad Henry 2005
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
20 #include "includes.h"
21 #include "libnet/libnet.h"
22 #include "libcli/cldap/cldap.h"
23 #include <ldb.h>
24 #include <ldb_errors.h>
25 #include "libcli/resolve/resolve.h"
26 #include "param/param.h"
27 #include "lib/tsocket/tsocket.h"
29 /**
30 * 1. Setup a CLDAP socket.
31 * 2. Lookup the default Site-Name.
33 NTSTATUS libnet_FindSite(TALLOC_CTX *ctx, struct libnet_context *lctx, struct libnet_JoinSite *r)
35 NTSTATUS status;
36 TALLOC_CTX *tmp_ctx;
38 char *site_name_str;
39 char *config_dn_str;
40 char *server_dn_str;
42 struct cldap_socket *cldap = NULL;
43 struct cldap_netlogon search;
44 int ret;
45 struct tsocket_address *dest_address;
47 tmp_ctx = talloc_named(ctx, 0, "libnet_FindSite temp context");
48 if (!tmp_ctx) {
49 r->out.error_string = NULL;
50 return NT_STATUS_NO_MEMORY;
53 /* Resolve the site name. */
54 ZERO_STRUCT(search);
55 search.in.dest_address = NULL;
56 search.in.dest_port = 0;
57 search.in.acct_control = -1;
58 search.in.version = NETLOGON_NT_VERSION_5 | NETLOGON_NT_VERSION_5EX;
59 search.in.map_response = true;
61 ret = tsocket_address_inet_from_strings(tmp_ctx, "ip",
62 r->in.dest_address,
63 r->in.cldap_port,
64 &dest_address);
65 if (ret != 0) {
66 r->out.error_string = NULL;
67 status = map_nt_error_from_unix_common(errno);
68 talloc_free(tmp_ctx);
69 return status;
72 /* we want to use non async calls, so we're not passing an event context */
73 status = cldap_socket_init(tmp_ctx, NULL, dest_address, &cldap);
74 if (!NT_STATUS_IS_OK(status)) {
75 talloc_free(tmp_ctx);
76 r->out.error_string = NULL;
77 return status;
79 status = cldap_netlogon(cldap, tmp_ctx, &search);
80 if (!NT_STATUS_IS_OK(status)
81 || !search.out.netlogon.data.nt5_ex.client_site) {
83 If cldap_netlogon() returns in error,
84 default to using Default-First-Site-Name.
86 site_name_str = talloc_asprintf(tmp_ctx, "%s",
87 "Default-First-Site-Name");
88 if (!site_name_str) {
89 r->out.error_string = NULL;
90 talloc_free(tmp_ctx);
91 return NT_STATUS_NO_MEMORY;
93 } else {
94 site_name_str = talloc_asprintf(tmp_ctx, "%s",
95 search.out.netlogon.data.nt5_ex.client_site);
96 if (!site_name_str) {
97 r->out.error_string = NULL;
98 talloc_free(tmp_ctx);
99 return NT_STATUS_NO_MEMORY;
103 /* Generate the CN=Configuration,... DN. */
104 /* TODO: look it up! */
105 config_dn_str = talloc_asprintf(tmp_ctx, "CN=Configuration,%s", r->in.domain_dn_str);
106 if (!config_dn_str) {
107 r->out.error_string = NULL;
108 talloc_free(tmp_ctx);
109 return NT_STATUS_NO_MEMORY;
112 /* Generate the CN=Servers,... DN. */
113 server_dn_str = talloc_asprintf(tmp_ctx, "CN=%s,CN=Servers,CN=%s,CN=Sites,%s",
114 r->in.netbios_name, site_name_str, config_dn_str);
115 if (!server_dn_str) {
116 r->out.error_string = NULL;
117 talloc_free(tmp_ctx);
118 return NT_STATUS_NO_MEMORY;
121 r->out.site_name_str = site_name_str;
122 talloc_steal(r, site_name_str);
124 r->out.config_dn_str = config_dn_str;
125 talloc_steal(r, config_dn_str);
127 r->out.server_dn_str = server_dn_str;
128 talloc_steal(r, server_dn_str);
130 talloc_free(tmp_ctx);
131 return NT_STATUS_OK;
135 * find out Site specific stuff:
136 * 1. Lookup the Site name.
137 * 2. Add entry CN=<netbios name>,CN=Servers,CN=<site name>,CN=Sites,CN=Configuration,<domain dn>.
138 * TODO: 3.) use DsAddEntry() to create CN=NTDS Settings,CN=<netbios name>,CN=Servers,CN=<site name>,...
140 NTSTATUS libnet_JoinSite(struct libnet_context *ctx,
141 struct ldb_context *remote_ldb,
142 struct libnet_JoinDomain *libnet_r)
144 NTSTATUS status;
145 TALLOC_CTX *tmp_ctx;
147 struct libnet_JoinSite *r;
149 struct ldb_dn *server_dn;
150 struct ldb_message *msg;
151 int rtn;
153 const char *server_dn_str;
154 const char *host;
155 struct nbt_name name;
156 const char *dest_addr = NULL;
158 tmp_ctx = talloc_named(libnet_r, 0, "libnet_JoinSite temp context");
159 if (!tmp_ctx) {
160 libnet_r->out.error_string = NULL;
161 return NT_STATUS_NO_MEMORY;
164 r = talloc(tmp_ctx, struct libnet_JoinSite);
165 if (!r) {
166 libnet_r->out.error_string = NULL;
167 talloc_free(tmp_ctx);
168 return NT_STATUS_NO_MEMORY;
171 host = dcerpc_binding_get_string_option(libnet_r->out.samr_binding, "host");
172 make_nbt_name_client(&name, host);
173 status = resolve_name_ex(lpcfg_resolve_context(ctx->lp_ctx),
174 0, 0,
175 &name, r, &dest_addr, ctx->event_ctx);
176 if (!NT_STATUS_IS_OK(status)) {
177 libnet_r->out.error_string = NULL;
178 talloc_free(tmp_ctx);
179 return status;
182 /* Resolve the site name and AD DN's. */
183 r->in.dest_address = dest_addr;
184 r->in.netbios_name = libnet_r->in.netbios_name;
185 r->in.domain_dn_str = libnet_r->out.domain_dn_str;
186 r->in.cldap_port = lpcfg_cldap_port(ctx->lp_ctx);
188 status = libnet_FindSite(tmp_ctx, ctx, r);
189 if (!NT_STATUS_IS_OK(status)) {
190 libnet_r->out.error_string =
191 talloc_steal(libnet_r, r->out.error_string);
192 talloc_free(tmp_ctx);
193 return status;
196 server_dn_str = r->out.server_dn_str;
199 Add entry CN=<netbios name>,CN=Servers,CN=<site name>,CN=Sites,CN=Configuration,<domain dn>.
201 msg = ldb_msg_new(tmp_ctx);
202 if (!msg) {
203 libnet_r->out.error_string = NULL;
204 talloc_free(tmp_ctx);
205 return NT_STATUS_NO_MEMORY;
208 rtn = ldb_msg_add_string(msg, "objectClass", "server");
209 if (rtn != LDB_SUCCESS) {
210 libnet_r->out.error_string = NULL;
211 talloc_free(tmp_ctx);
212 return NT_STATUS_NO_MEMORY;
214 rtn = ldb_msg_add_string(msg, "systemFlags", "50000000");
215 if (rtn != LDB_SUCCESS) {
216 libnet_r->out.error_string = NULL;
217 talloc_free(tmp_ctx);
218 return NT_STATUS_NO_MEMORY;
220 rtn = ldb_msg_add_string(msg, "serverReference", libnet_r->out.account_dn_str);
221 if (rtn != LDB_SUCCESS) {
222 libnet_r->out.error_string = NULL;
223 talloc_free(tmp_ctx);
224 return NT_STATUS_NO_MEMORY;
227 server_dn = ldb_dn_new(tmp_ctx, remote_ldb, server_dn_str);
228 if ( ! ldb_dn_validate(server_dn)) {
229 libnet_r->out.error_string = talloc_asprintf(libnet_r,
230 "Invalid server dn: %s",
231 server_dn_str);
232 talloc_free(tmp_ctx);
233 return NT_STATUS_UNSUCCESSFUL;
236 msg->dn = server_dn;
238 rtn = ldb_add(remote_ldb, msg);
239 if (rtn == LDB_ERR_ENTRY_ALREADY_EXISTS) {
240 unsigned int i;
242 /* make a 'modify' msg, and only for serverReference */
243 msg = ldb_msg_new(tmp_ctx);
244 if (!msg) {
245 libnet_r->out.error_string = NULL;
246 talloc_free(tmp_ctx);
247 return NT_STATUS_NO_MEMORY;
249 msg->dn = server_dn;
251 rtn = ldb_msg_add_string(msg, "serverReference",libnet_r->out.account_dn_str);
252 if (rtn != LDB_SUCCESS) {
253 libnet_r->out.error_string = NULL;
254 talloc_free(tmp_ctx);
255 return NT_STATUS_NO_MEMORY;
258 /* mark all the message elements (should be just one)
259 as LDB_FLAG_MOD_REPLACE */
260 for (i=0;i<msg->num_elements;i++) {
261 msg->elements[i].flags = LDB_FLAG_MOD_REPLACE;
264 rtn = ldb_modify(remote_ldb, msg);
265 if (rtn != LDB_SUCCESS) {
266 libnet_r->out.error_string
267 = talloc_asprintf(libnet_r,
268 "Failed to modify server entry %s: %s: %d",
269 server_dn_str,
270 ldb_errstring(remote_ldb), rtn);
271 talloc_free(tmp_ctx);
272 return NT_STATUS_INTERNAL_DB_CORRUPTION;
274 } else if (rtn != LDB_SUCCESS) {
275 libnet_r->out.error_string
276 = talloc_asprintf(libnet_r,
277 "Failed to add server entry %s: %s: %d",
278 server_dn_str, ldb_errstring(remote_ldb),
279 rtn);
280 talloc_free(tmp_ctx);
281 return NT_STATUS_INTERNAL_DB_CORRUPTION;
283 DEBUG(0, ("We still need to perform a DsAddEntry() so that we can create the CN=NTDS Settings container.\n"));
285 /* Store the server DN in libnet_r */
286 libnet_r->out.server_dn_str = server_dn_str;
287 talloc_steal(libnet_r, server_dn_str);
289 talloc_free(tmp_ctx);
290 return NT_STATUS_OK;