2015-02-11 17:07:40 +03:00
#!/bin/sh
# Copyright (C) 2015 Stefan Metzmacher <metze@samba.org>
if [ $# -lt 13 ] ; then
cat <<EOF
Usage: test_kinit_trusts.sh SERVER USERNAME PASSWORD REALM DOMAIN TRUST_USERNAME TRUST_PASSWORD TRUST_REALM TRUST_DOMAIN PREFIX TYPE ENCTYPE
EOF
exit 1;
fi
SERVER = $1
USERNAME = $2
PASSWORD = $3
REALM = $4
DOMAIN = $5
shift 5
TRUST_SERVER = $1
TRUST_USERNAME = $2
TRUST_PASSWORD = $3
TRUST_REALM = $4
TRUST_DOMAIN = $5
shift 5
PREFIX = $1
TYPE = $2
ENCTYPE = $3
shift 3
failed = 0
samba4bindir = " $BINDIR "
samba4kinit = kinit
if test -x $samba4bindir /samba4kinit; then
samba4kinit = $samba4bindir /samba4kinit
fi
2017-03-06 11:13:09 +03:00
smbclient = " $samba4bindir /smbclient "
2015-02-11 17:07:40 +03:00
wbinfo = " $samba4bindir /wbinfo "
rpcclient = " $samba4bindir /rpcclient "
samba_tool = " $samba4bindir /samba-tool "
. ` dirname $0 ` /subunit.sh
2016-04-24 21:09:05 +03:00
. ` dirname $0 ` /common_test_fns.inc
2015-02-11 17:07:40 +03:00
2016-04-24 21:09:05 +03:00
unc = " // $SERVER . $REALM /tmp "
2015-02-11 17:07:40 +03:00
enctype = " -e $ENCTYPE "
KRB5CCNAME_PATH = " $PREFIX /tmpccache "
KRB5CCNAME = " FILE: $KRB5CCNAME_PATH "
export KRB5CCNAME
rm -rf $KRB5CCNAME_PATH
echo $TRUST_PASSWORD > $PREFIX /tmppassfile
testit "kinit with password" $samba4kinit $enctype --password-file= $PREFIX /tmppassfile --request-pac $TRUST_USERNAME @$TRUST_REALM || failed = ` expr $failed + 1`
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with user kerberos ccache" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
2017-03-06 11:15:45 +03:00
rm -rf $KRB5CCNAME_PATH
# Test with smbclient4
smbclient = " $samba4bindir /smbclient4 "
testit "kinit with password" $samba4kinit $enctype --password-file= $PREFIX /tmppassfile --request-pac $TRUST_USERNAME @$TRUST_REALM || failed = ` expr $failed + 1`
test_smbclient "Test login with user kerberos ccache (smbclient4)" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
rm -rf $KRB5CCNAME_PATH
2015-02-11 17:07:40 +03:00
testit "kinit with password (enterprise style)" $samba4kinit $enctype --enterprise --password-file= $PREFIX /tmppassfile --request-pac $TRUST_USERNAME @$TRUST_REALM || failed = ` expr $failed + 1`
2017-03-06 11:15:45 +03:00
smbclient = " $samba4bindir /smbclient "
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with user kerberos ccache" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
2015-05-11 16:07:49 +03:00
if test x" ${ TYPE } " = x"forest" ; then
testit "kinit with password (upn enterprise style)" $samba4kinit $enctype --enterprise --password-file= $PREFIX /tmppassfile --request-pac testdenied_upn@${ TRUST_REALM } .upn || failed = ` expr $failed + 1`
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with user kerberos ccache" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
2015-05-11 16:07:49 +03:00
fi
2015-02-11 17:07:40 +03:00
testit "kinit with password (windows style)" $samba4kinit $enctype --renewable --windows --password-file= $PREFIX /tmppassfile --request-pac $TRUST_USERNAME @$TRUST_REALM || failed = ` expr $failed + 1`
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with user kerberos ccache" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
testit "kinit renew ticket" $samba4kinit $enctype --request-pac -R
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with kerberos ccache" 'ls' " $unc " -k yes || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
testit "check time with kerberos ccache" $VALGRIND $samba_tool time $SERVER .$REALM $CONFIGURATION -k yes $@ || failed = ` expr $failed + 1`
lowerrealm = $( echo $TRUST_REALM | tr '[A-Z]' '[a-z]' )
2016-04-24 21:09:05 +03:00
test_smbclient "Test login with user kerberos lowercase realm" 'ls' " $unc " -k yes -U$TRUST_USERNAME @$lowerrealm %$TRUST_PASSWORD || failed = ` expr $failed + 1`
test_smbclient "Test login with user kerberos lowercase realm 2" 'ls' " $unc " -k yes -U$TRUST_USERNAME @$TRUST_REALM %$TRUST_PASSWORD --realm= $lowerrealm || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
# Test the outgoing direction
SMBCLIENT_UNC = " // $TRUST_SERVER . $TRUST_REALM /tmp "
2016-04-24 21:09:05 +03:00
test_smbclient "Test user login with the first outgoing secret" 'ls' " $unc " -k yes -U$USERNAME @$REALM %$PASSWORD || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
2015-06-11 19:58:42 +03:00
testit_expect_failure "setpassword should not work" $VALGRIND $samba_tool user setpassword " ${ TRUST_DOMAIN } \$ " --random-password || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
testit "wbinfo ping dc" $VALGRIND $wbinfo --ping-dc --domain= $TRUST_DOMAIN || failed = ` expr $failed + 1`
testit "wbinfo change outgoing trust pw" $VALGRIND $wbinfo --change-secret --domain= $TRUST_DOMAIN || failed = ` expr $failed + 1`
testit "wbinfo check outgoing trust pw" $VALGRIND $wbinfo --check-secret --domain= $TRUST_DOMAIN || failed = ` expr $failed + 1`
2016-04-24 21:09:05 +03:00
test_smbclient "Test user login with the changed outgoing secret" 'ls' " $unc " -k yes -U$USERNAME @$REALM %$PASSWORD || failed = ` expr $failed + 1`
2015-02-11 17:07:40 +03:00
2018-03-22 03:15:34 +03:00
rm -f $PREFIX /tmpccache tmpccfile tmppassfile tmpuserpassfile tmpuserccache
2015-02-11 17:07:40 +03:00
exit $failed