2003-08-13 01:53:07 +00:00
/*
Unix SMB / CIFS implementation .
Copyright ( C ) Andrew Tridgell 1992 - 2001
Copyright ( C ) Andrew Bartlett 2002
Copyright ( C ) Rafal Szczesniak 2002
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-10 02:07:03 +00:00
the Free Software Foundation ; either version 3 of the License , or
2003-08-13 01:53:07 +00:00
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
2007-07-10 02:07:03 +00:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2003-08-13 01:53:07 +00:00
*/
/* the Samba secrets database stores any generated, private information
such as the local SID and machine trust password */
# include "includes.h"
2004-11-02 06:14:15 +00:00
# include "secrets.h"
2006-03-20 00:28:12 +00:00
# include "param/param.h"
2005-02-10 05:09:35 +00:00
# include "system/filesys.h"
2012-03-10 21:33:11 +01:00
# include "lib/tdb_wrap/tdb_wrap.h"
2010-06-23 21:15:43 +10:00
# include "lib/ldb-samba/ldb_wrap.h"
2011-02-10 14:12:51 +11:00
# include <ldb.h>
2008-10-11 21:31:42 +02:00
# include "../lib/util/util_tdb.h"
2007-12-06 21:16:40 +01:00
# include "librpc/gen_ndr/ndr_security.h"
2010-02-18 10:54:53 +11:00
# include "dsdb/samdb/samdb.h"
2003-08-13 01:53:07 +00:00
2007-11-26 02:31:53 +01:00
/**
connect to the secrets ldb
2005-01-11 14:04:58 +00:00
*/
2008-06-14 11:24:17 -04:00
struct ldb_context * secrets_db_connect ( TALLOC_CTX * mem_ctx ,
struct loadparm_context * lp_ctx )
2005-01-11 14:04:58 +00:00
{
2011-06-02 15:47:44 +10:00
return ldb_wrap_connect ( mem_ctx , NULL , lp_ctx , " secrets.ldb " ,
2010-06-23 21:15:43 +10:00
NULL , NULL , 0 ) ;
2005-01-11 14:04:58 +00:00
}
2007-11-26 02:31:53 +01:00
/**
* Retrieve the domain SID from the secrets database .
* @ return pointer to a SID object if the SID could be obtained , NULL otherwise
*/
2005-09-25 21:01:56 +00:00
struct dom_sid * secrets_get_domain_sid ( TALLOC_CTX * mem_ctx ,
2007-12-03 15:53:17 +01:00
struct loadparm_context * lp_ctx ,
2010-02-18 10:54:53 +11:00
const char * domain ,
2010-09-13 12:15:52 +10:00
enum netr_SchannelType * sec_channel_type ,
2010-02-18 10:54:53 +11:00
char * * errstring )
2005-09-25 21:01:56 +00:00
{
struct ldb_context * ldb ;
2010-02-18 10:54:53 +11:00
struct ldb_message * msg ;
2005-09-25 21:01:56 +00:00
int ldb_ret ;
2010-09-13 12:15:52 +10:00
const char * attrs [ ] = { " objectSid " , " secureChannelType " , NULL } ;
2005-09-25 21:01:56 +00:00
struct dom_sid * result = NULL ;
2007-12-06 21:16:40 +01:00
const struct ldb_val * v ;
enum ndr_err_code ndr_err ;
2010-09-13 12:15:52 +10:00
2010-02-18 10:54:53 +11:00
* errstring = NULL ;
2005-09-25 21:01:56 +00:00
2010-10-11 16:43:07 +11:00
ldb = secrets_db_connect ( mem_ctx , lp_ctx ) ;
2005-09-25 21:01:56 +00:00
if ( ldb = = NULL ) {
DEBUG ( 5 , ( " secrets_db_connect failed \n " ) ) ;
2006-07-07 01:59:43 +00:00
return NULL ;
2005-09-25 21:01:56 +00:00
}
2010-02-18 10:54:53 +11:00
ldb_ret = dsdb_search_one ( ldb , ldb , & msg ,
ldb_dn_new ( mem_ctx , ldb , SECRETS_PRIMARY_DOMAIN_DN ) ,
LDB_SCOPE_ONELEVEL ,
attrs , 0 , SECRETS_PRIMARY_DOMAIN_FILTER , domain ) ;
2005-09-25 21:01:56 +00:00
2010-02-18 10:54:53 +11:00
if ( ldb_ret ! = LDB_SUCCESS ) {
2010-02-19 11:14:15 +11:00
* errstring = talloc_asprintf ( mem_ctx , " Failed to find record for %s in %s: %s: %s " ,
2010-04-06 14:52:38 +02:00
domain , ( char * ) ldb_get_opaque ( ldb , " ldb_url " ) ,
2010-02-19 11:14:15 +11:00
ldb_strerror ( ldb_ret ) , ldb_errstring ( ldb ) ) ;
2006-07-07 01:59:43 +00:00
return NULL ;
2005-09-25 21:01:56 +00:00
}
2010-02-18 10:54:53 +11:00
v = ldb_msg_find_ldb_val ( msg , " objectSid " ) ;
2007-12-06 21:16:40 +01:00
if ( v = = NULL ) {
2010-02-19 11:14:15 +11:00
* errstring = talloc_asprintf ( mem_ctx , " Failed to find a SID on record for %s in %s " ,
2010-04-06 14:52:38 +02:00
domain , ( char * ) ldb_get_opaque ( ldb , " ldb_url " ) ) ;
2007-12-06 21:16:40 +01:00
return NULL ;
}
2010-09-13 12:15:52 +10:00
if ( sec_channel_type ) {
2010-09-14 13:12:00 +10:00
int t ;
t = ldb_msg_find_attr_as_int ( msg , " secureChannelType " , - 1 ) ;
if ( t = = - 1 ) {
2010-09-13 12:15:52 +10:00
* errstring = talloc_asprintf ( mem_ctx , " Failed to find secureChannelType for %s in %s " ,
domain , ( char * ) ldb_get_opaque ( ldb , " ldb_url " ) ) ;
return NULL ;
}
2010-09-14 13:12:00 +10:00
* sec_channel_type = t ;
2010-09-13 12:15:52 +10:00
}
2007-12-06 21:16:40 +01:00
result = talloc ( mem_ctx , struct dom_sid ) ;
if ( result = = NULL ) {
talloc_free ( ldb ) ;
return NULL ;
}
2010-05-09 17:20:01 +02:00
ndr_err = ndr_pull_struct_blob ( v , result , result ,
2007-12-06 21:16:40 +01:00
( ndr_pull_flags_fn_t ) ndr_pull_dom_sid ) ;
if ( ! NDR_ERR_CODE_IS_SUCCESS ( ndr_err ) ) {
2010-02-19 11:14:15 +11:00
* errstring = talloc_asprintf ( mem_ctx , " Failed to parse SID on record for %s in %s " ,
2010-04-06 14:52:38 +02:00
domain , ( char * ) ldb_get_opaque ( ldb , " ldb_url " ) ) ;
2007-12-06 21:16:40 +01:00
talloc_free ( result ) ;
2006-07-07 01:59:43 +00:00
talloc_free ( ldb ) ;
return NULL ;
2005-09-25 21:01:56 +00:00
}
return result ;
}
2010-09-23 17:01:44 +10:00
char * keytab_name_from_msg ( TALLOC_CTX * mem_ctx , struct ldb_context * ldb , struct ldb_message * msg )
{
const char * krb5keytab = ldb_msg_find_attr_as_string ( msg , " krb5Keytab " , NULL ) ;
if ( krb5keytab ) {
return talloc_strdup ( mem_ctx , krb5keytab ) ;
} else {
char * file_keytab ;
char * relative_path ;
const char * privateKeytab = ldb_msg_find_attr_as_string ( msg , " privateKeytab " , NULL ) ;
if ( ! privateKeytab ) {
return NULL ;
}
2010-10-10 23:45:23 +02:00
relative_path = ldb_relative_path ( ldb , mem_ctx , privateKeytab ) ;
2010-09-23 17:01:44 +10:00
if ( ! relative_path ) {
return NULL ;
}
file_keytab = talloc_asprintf ( mem_ctx , " FILE:%s " , relative_path ) ;
talloc_free ( relative_path ) ;
return file_keytab ;
}
return NULL ;
}