2011-02-09 08:05:54 +03:00
/*
2005-06-29 17:55:09 +04:00
Unix SMB / CIFS implementation .
Convert a server info struct into the form for PAC and NETLOGON replies
2011-07-18 16:26:31 +04:00
Copyright ( C ) Andrew Bartlett < abartlet @ samba . org > 2004 - 2011
2005-06-29 17:55:09 +04:00
Copyright ( C ) Stefan Metzmacher < metze @ samba . org > 2005
2011-02-09 08:05:54 +03:00
2005-06-29 17:55:09 +04:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-10 06:07:03 +04:00
the Free Software Foundation ; either version 3 of the License , or
2005-06-29 17:55:09 +04:00
( at your option ) any later version .
2011-02-09 08:05:54 +03:00
2005-06-29 17:55:09 +04:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2011-02-09 08:05:54 +03:00
2005-06-29 17:55:09 +04:00
You should have received a copy of the GNU General Public License
2007-07-10 06:07:03 +04:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2005-06-29 17:55:09 +04:00
*/
# include "includes.h"
2011-02-09 08:05:54 +03:00
# include "librpc/gen_ndr/auth.h"
2006-04-02 16:02:01 +04:00
# include "libcli/security/security.h"
2008-10-20 20:59:51 +04:00
# include "auth/auth_sam_reply.h"
2005-06-29 17:55:09 +04:00
2016-01-07 18:06:25 +03:00
static NTSTATUS auth_convert_user_info_dc_sambaseinfo ( TALLOC_CTX * mem_ctx ,
const struct auth_user_info_dc * user_info_dc ,
struct netr_SamBaseInfo * sam )
2005-06-29 17:55:09 +04:00
{
2011-01-20 15:39:37 +03:00
NTSTATUS status ;
2016-01-07 18:06:25 +03:00
const struct auth_user_info * info ;
ZERO_STRUCTP ( sam ) ;
2005-06-29 17:55:09 +04:00
2011-02-08 08:53:13 +03:00
if ( user_info_dc - > num_sids > PRIMARY_USER_SID_INDEX ) {
2022-09-27 05:13:12 +03:00
status = dom_sid_split_rid ( sam , & user_info_dc - > sids [ PRIMARY_USER_SID_INDEX ] . sid ,
2011-01-20 15:39:37 +03:00
& sam - > domain_sid , & sam - > rid ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return status ;
}
} else {
return NT_STATUS_INVALID_PARAMETER ;
}
2011-02-08 08:53:13 +03:00
if ( user_info_dc - > num_sids > PRIMARY_GROUP_SID_INDEX ) {
2022-09-27 05:13:12 +03:00
status = dom_sid_split_rid ( NULL , & user_info_dc - > sids [ PRIMARY_GROUP_SID_INDEX ] . sid ,
2011-01-20 15:39:37 +03:00
NULL , & sam - > primary_gid ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return status ;
}
} else {
/* if we have to encode something like SYSTEM (with no
* second SID in the token ) then this is the only
* choice */
sam - > primary_gid = sam - > rid ;
}
2005-10-24 11:11:40 +04:00
2011-02-08 08:53:13 +03:00
info = user_info_dc - > info ;
2011-10-22 00:10:43 +04:00
sam - > logon_time = info - > last_logon ;
sam - > logoff_time = info - > last_logoff ;
sam - > kickoff_time = info - > acct_expiry ;
2011-02-08 08:53:13 +03:00
sam - > last_password_change = info - > last_password_change ;
sam - > allow_password_change = info - > allow_password_change ;
sam - > force_password_change = info - > force_password_change ;
2016-01-07 17:46:10 +03:00
# define _COPY_STRING_TALLOC(src_name, dst_name) do { \
if ( info - > src_name ! = NULL ) { \
2016-01-07 18:06:25 +03:00
sam - > dst_name . string = talloc_strdup ( mem_ctx , info - > src_name ) ; \
2016-01-07 17:46:10 +03:00
if ( sam - > dst_name . string = = NULL ) { \
return NT_STATUS_NO_MEMORY ; \
} \
} \
} while ( 0 )
_COPY_STRING_TALLOC ( account_name , account_name ) ;
_COPY_STRING_TALLOC ( full_name , full_name ) ;
_COPY_STRING_TALLOC ( logon_script , logon_script ) ;
_COPY_STRING_TALLOC ( profile_path , profile_path ) ;
_COPY_STRING_TALLOC ( home_directory , home_directory ) ;
_COPY_STRING_TALLOC ( home_drive , home_drive ) ;
_COPY_STRING_TALLOC ( logon_server , logon_server ) ;
_COPY_STRING_TALLOC ( domain_name , logon_domain ) ;
# undef _COPY_STRING_TALLOC
2011-02-08 08:53:13 +03:00
sam - > logon_count = info - > logon_count ;
2011-02-09 02:46:21 +03:00
sam - > bad_password_count = info - > bad_password_count ;
2005-06-29 17:55:09 +04:00
sam - > groups . count = 0 ;
sam - > groups . rids = NULL ;
2019-04-03 19:45:02 +03:00
if ( user_info_dc - > num_sids > PRIMARY_GROUP_SID_INDEX ) {
2010-04-12 16:34:28 +04:00
size_t i ;
2016-01-07 18:06:25 +03:00
sam - > groups . rids = talloc_array ( mem_ctx , struct samr_RidWithAttribute ,
2011-02-08 08:53:13 +03:00
user_info_dc - > num_sids ) ;
2005-06-29 17:55:09 +04:00
if ( sam - > groups . rids = = NULL )
return NT_STATUS_NO_MEMORY ;
2019-04-03 19:45:02 +03:00
for ( i = PRIMARY_GROUP_SID_INDEX ; i < user_info_dc - > num_sids ; i + + ) {
2022-09-27 05:13:12 +03:00
struct auth_SidAttr * group_sid = & user_info_dc - > sids [ i ] ;
2022-09-27 04:51:54 +03:00
if ( group_sid - > attrs & SE_GROUP_RESOURCE ) {
/*
* Resource groups don ' t belong in the base
* RIDs , they ' re handled elsewhere .
*/
continue ;
}
2022-09-27 05:13:12 +03:00
if ( ! dom_sid_in_domain ( sam - > domain_sid , & group_sid - > sid ) ) {
2005-10-24 11:11:40 +04:00
/* We handle this elsewhere */
continue ;
}
2005-06-29 17:55:09 +04:00
sam - > groups . rids [ sam - > groups . count ] . rid =
2022-09-27 05:13:12 +03:00
group_sid - > sid . sub_auths [ group_sid - > sid . num_auths - 1 ] ;
2011-02-09 08:05:54 +03:00
2022-09-27 05:13:12 +03:00
sam - > groups . rids [ sam - > groups . count ] . attributes = group_sid - > attrs ;
2005-06-29 17:55:09 +04:00
sam - > groups . count + = 1 ;
}
}
2007-12-11 12:18:10 +03:00
sam - > user_flags = 0 ; /* w2k3 uses NETLOGON_EXTRA_SIDS | NETLOGON_NTLMV2_ENABLED */
2011-07-19 04:43:23 +04:00
if ( ! user_info_dc - > info - > authenticated ) {
sam - > user_flags | = NETLOGON_GUEST ;
}
2011-02-08 08:53:13 +03:00
sam - > acct_flags = user_info_dc - > info - > acct_flags ;
2011-10-22 00:10:43 +04:00
sam - > sub_auth_status = 0 ;
sam - > last_successful_logon = 0 ;
sam - > last_failed_logon = 0 ;
sam - > failed_logon_count = 0 ;
sam - > reserved = 0 ;
2005-06-29 17:55:09 +04:00
ZERO_STRUCT ( sam - > key ) ;
2011-02-08 08:53:13 +03:00
if ( user_info_dc - > user_session_key . length = = sizeof ( sam - > key . key ) ) {
memcpy ( sam - > key . key , user_info_dc - > user_session_key . data , sizeof ( sam - > key . key ) ) ;
2005-06-29 17:55:09 +04:00
}
ZERO_STRUCT ( sam - > LMSessKey ) ;
2011-02-08 08:53:13 +03:00
if ( user_info_dc - > lm_session_key . length = = sizeof ( sam - > LMSessKey . key ) ) {
memcpy ( sam - > LMSessKey . key , user_info_dc - > lm_session_key . data ,
2005-06-29 17:55:09 +04:00
sizeof ( sam - > LMSessKey . key ) ) ;
}
2011-02-09 08:05:54 +03:00
2005-06-29 17:55:09 +04:00
return NT_STATUS_OK ;
2011-02-09 08:05:54 +03:00
}
2005-06-29 17:55:09 +04:00
2016-01-07 17:15:14 +03:00
/* Note that the validity of the _sam6 structure is only as long as
2011-02-08 08:53:13 +03:00
* the user_info_dc it was generated from */
2016-01-07 17:15:14 +03:00
NTSTATUS auth_convert_user_info_dc_saminfo6 ( TALLOC_CTX * mem_ctx ,
const struct auth_user_info_dc * user_info_dc ,
2022-09-27 04:51:54 +03:00
enum auth_group_inclusion group_inclusion ,
2016-01-07 17:15:14 +03:00
struct netr_SamInfo6 * * _sam6 )
2005-07-05 14:57:39 +04:00
{
2005-10-24 11:11:40 +04:00
NTSTATUS status ;
2016-01-07 17:15:14 +03:00
struct netr_SamInfo6 * sam6 = NULL ;
2010-04-12 16:34:28 +04:00
size_t i ;
2005-07-05 14:57:39 +04:00
2016-01-07 17:15:14 +03:00
sam6 = talloc_zero ( mem_ctx , struct netr_SamInfo6 ) ;
if ( sam6 = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
2016-01-07 18:06:25 +03:00
status = auth_convert_user_info_dc_sambaseinfo ( sam6 ,
user_info_dc ,
& sam6 - > base ) ;
2005-10-24 11:11:40 +04:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2016-01-07 17:15:14 +03:00
TALLOC_FREE ( sam6 ) ;
2005-10-24 11:11:40 +04:00
return status ;
2005-08-04 03:14:38 +04:00
}
2011-02-09 08:05:54 +03:00
2016-01-07 17:15:14 +03:00
sam6 - > sids = talloc_array ( sam6 , struct netr_SidAttr ,
2011-02-08 08:53:13 +03:00
user_info_dc - > num_sids ) ;
2016-01-07 17:15:14 +03:00
if ( sam6 - > sids = = NULL ) {
TALLOC_FREE ( sam6 ) ;
2014-02-13 08:51:11 +04:00
return NT_STATUS_NO_MEMORY ;
}
2011-01-20 15:39:37 +03:00
/* We don't put the user and group SIDs in there */
2011-02-08 08:53:13 +03:00
for ( i = 2 ; i < user_info_dc - > num_sids ; i + + ) {
2022-09-27 04:51:54 +03:00
if ( user_info_dc - > sids [ i ] . attrs & SE_GROUP_RESOURCE ) {
/*
* If it ' s a resource group , check whether it should be
* included or filtered out .
*/
switch ( group_inclusion ) {
case AUTH_INCLUDE_RESOURCE_GROUPS :
/* Include it. */
break ;
case AUTH_EXCLUDE_RESOURCE_GROUPS :
/* Ignore it. */
continue ;
}
} else if ( dom_sid_in_domain ( sam6 - > base . domain_sid , & user_info_dc - > sids [ i ] . sid ) ) {
2005-10-24 11:11:40 +04:00
continue ;
2005-07-05 14:57:39 +04:00
}
2022-09-27 05:13:12 +03:00
sam6 - > sids [ sam6 - > sidcount ] . sid = dom_sid_dup ( sam6 - > sids , & user_info_dc - > sids [ i ] . sid ) ;
2016-01-07 17:15:14 +03:00
if ( sam6 - > sids [ sam6 - > sidcount ] . sid = = NULL ) {
TALLOC_FREE ( sam6 ) ;
2014-02-13 08:51:11 +04:00
return NT_STATUS_NO_MEMORY ;
}
2022-09-27 05:13:12 +03:00
sam6 - > sids [ sam6 - > sidcount ] . attributes = user_info_dc - > sids [ i ] . attrs ;
2016-01-07 17:15:14 +03:00
sam6 - > sidcount + = 1 ;
2005-10-24 11:11:40 +04:00
}
2016-01-07 17:15:14 +03:00
if ( sam6 - > sidcount ) {
sam6 - > base . user_flags | = NETLOGON_EXTRA_SIDS ;
2005-10-24 11:11:40 +04:00
} else {
2016-01-07 17:15:14 +03:00
sam6 - > sids = NULL ;
2005-07-05 14:57:39 +04:00
}
2016-01-07 17:15:14 +03:00
if ( user_info_dc - > info - > dns_domain_name ! = NULL ) {
sam6 - > dns_domainname . string = talloc_strdup ( sam6 ,
user_info_dc - > info - > dns_domain_name ) ;
if ( sam6 - > dns_domainname . string = = NULL ) {
TALLOC_FREE ( sam6 ) ;
return NT_STATUS_NO_MEMORY ;
}
}
if ( user_info_dc - > info - > user_principal_name ! = NULL ) {
sam6 - > principal_name . string = talloc_strdup ( sam6 ,
user_info_dc - > info - > user_principal_name ) ;
if ( sam6 - > principal_name . string = = NULL ) {
TALLOC_FREE ( sam6 ) ;
return NT_STATUS_NO_MEMORY ;
}
}
* _sam6 = sam6 ;
return NT_STATUS_OK ;
}
2016-01-07 17:23:56 +03:00
/* Note that the validity of the _sam2 structure is only as long as
* the user_info_dc it was generated from */
NTSTATUS auth_convert_user_info_dc_saminfo2 ( TALLOC_CTX * mem_ctx ,
const struct auth_user_info_dc * user_info_dc ,
2022-09-27 04:51:54 +03:00
enum auth_group_inclusion group_inclusion ,
2016-01-07 17:23:56 +03:00
struct netr_SamInfo2 * * _sam2 )
{
NTSTATUS status ;
struct netr_SamInfo6 * sam6 = NULL ;
struct netr_SamInfo2 * sam2 = NULL ;
sam2 = talloc_zero ( mem_ctx , struct netr_SamInfo2 ) ;
if ( sam2 = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
2022-09-27 04:51:54 +03:00
status = auth_convert_user_info_dc_saminfo6 ( sam2 , user_info_dc ,
group_inclusion , & sam6 ) ;
2016-01-07 17:23:56 +03:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
TALLOC_FREE ( sam2 ) ;
return status ;
}
sam2 - > base = sam6 - > base ;
* _sam2 = sam2 ;
return NT_STATUS_OK ;
}
2016-01-07 17:15:14 +03:00
/* Note that the validity of the _sam3 structure is only as long as
* the user_info_dc it was generated from */
NTSTATUS auth_convert_user_info_dc_saminfo3 ( TALLOC_CTX * mem_ctx ,
const struct auth_user_info_dc * user_info_dc ,
2022-09-27 04:51:54 +03:00
enum auth_group_inclusion group_inclusion ,
2016-01-07 17:15:14 +03:00
struct netr_SamInfo3 * * _sam3 )
{
NTSTATUS status ;
struct netr_SamInfo6 * sam6 = NULL ;
struct netr_SamInfo3 * sam3 = NULL ;
sam3 = talloc_zero ( mem_ctx , struct netr_SamInfo3 ) ;
if ( sam3 = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
2022-09-27 04:51:54 +03:00
status = auth_convert_user_info_dc_saminfo6 ( sam3 , user_info_dc ,
group_inclusion , & sam6 ) ;
2016-01-07 17:15:14 +03:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
TALLOC_FREE ( sam3 ) ;
return status ;
}
sam3 - > base = sam6 - > base ;
sam3 - > sidcount = sam6 - > sidcount ;
sam3 - > sids = sam6 - > sids ;
* _sam3 = sam3 ;
2005-07-05 14:57:39 +04:00
return NT_STATUS_OK ;
2011-02-09 08:05:54 +03:00
}
2005-07-05 14:57:39 +04:00
2011-07-18 07:55:20 +04:00
/**
* Make a user_info struct from the info3 or similar returned by a domain logon .
*
* The netr_SamInfo3 is also a key structure in the source3 auth subsystem
*/
NTSTATUS make_user_info_SamBaseInfo ( TALLOC_CTX * mem_ctx ,
const char * account_name ,
2016-01-07 16:50:27 +03:00
const struct netr_SamBaseInfo * base ,
2011-07-18 07:55:20 +04:00
bool authenticated ,
struct auth_user_info * * _user_info )
{
struct auth_user_info * info ;
info = talloc_zero ( mem_ctx , struct auth_user_info ) ;
NT_STATUS_HAVE_NO_MEMORY ( info ) ;
if ( base - > account_name . string ) {
2011-07-18 08:00:14 +04:00
info - > account_name = talloc_strdup ( info , base - > account_name . string ) ;
2011-07-18 07:55:20 +04:00
} else {
info - > account_name = talloc_strdup ( info , account_name ) ;
}
2011-07-18 08:00:14 +04:00
NT_STATUS_HAVE_NO_MEMORY ( info - > account_name ) ;
2011-07-18 07:55:20 +04:00
2011-10-22 00:10:43 +04:00
if ( base - > logon_domain . string ) {
info - > domain_name = talloc_strdup ( info , base - > logon_domain . string ) ;
2011-07-18 08:00:14 +04:00
NT_STATUS_HAVE_NO_MEMORY ( info - > domain_name ) ;
}
if ( base - > full_name . string ) {
info - > full_name = talloc_strdup ( info , base - > full_name . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > full_name ) ;
}
if ( base - > logon_script . string ) {
info - > logon_script = talloc_strdup ( info , base - > logon_script . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > logon_script ) ;
}
if ( base - > profile_path . string ) {
info - > profile_path = talloc_strdup ( info , base - > profile_path . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > profile_path ) ;
}
if ( base - > home_directory . string ) {
info - > home_directory = talloc_strdup ( info , base - > home_directory . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > home_directory ) ;
}
if ( base - > home_drive . string ) {
info - > home_drive = talloc_strdup ( info , base - > home_drive . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > home_drive ) ;
}
if ( base - > logon_server . string ) {
info - > logon_server = talloc_strdup ( info , base - > logon_server . string ) ;
NT_STATUS_HAVE_NO_MEMORY ( info - > logon_server ) ;
}
2011-10-22 00:10:43 +04:00
info - > last_logon = base - > logon_time ;
info - > last_logoff = base - > logoff_time ;
info - > acct_expiry = base - > kickoff_time ;
2011-07-18 07:55:20 +04:00
info - > last_password_change = base - > last_password_change ;
info - > allow_password_change = base - > allow_password_change ;
info - > force_password_change = base - > force_password_change ;
info - > logon_count = base - > logon_count ;
info - > bad_password_count = base - > bad_password_count ;
info - > acct_flags = base - > acct_flags ;
2011-07-19 04:51:08 +04:00
/* Only set authenticated if both NETLOGON_GUEST is not set, and authenticated is set */
info - > authenticated = ( authenticated & & ( ! ( base - > user_flags & NETLOGON_GUEST ) ) ) ;
2011-07-18 07:55:20 +04:00
* _user_info = info ;
return NT_STATUS_OK ;
}
2018-03-06 18:38:10 +03:00
struct auth_user_info * auth_user_info_copy ( TALLOC_CTX * mem_ctx ,
const struct auth_user_info * src )
{
struct auth_user_info * dst = NULL ;
dst = talloc_zero ( mem_ctx , struct auth_user_info ) ;
if ( dst = = NULL ) {
return NULL ;
}
* dst = * src ;
# define _COPY_STRING(_mem, _str) do { \
if ( ( _str ) ! = NULL ) { \
( _str ) = talloc_strdup ( ( _mem ) , ( _str ) ) ; \
if ( ( _str ) = = NULL ) { \
TALLOC_FREE ( dst ) ; \
return NULL ; \
} \
} \
} while ( 0 )
_COPY_STRING ( dst , dst - > account_name ) ;
_COPY_STRING ( dst , dst - > user_principal_name ) ;
_COPY_STRING ( dst , dst - > domain_name ) ;
_COPY_STRING ( dst , dst - > dns_domain_name ) ;
_COPY_STRING ( dst , dst - > full_name ) ;
_COPY_STRING ( dst , dst - > logon_script ) ;
_COPY_STRING ( dst , dst - > profile_path ) ;
_COPY_STRING ( dst , dst - > home_directory ) ;
_COPY_STRING ( dst , dst - > home_drive ) ;
_COPY_STRING ( dst , dst - > logon_server ) ;
# undef _COPY_STRING
return dst ;
}
2009-01-21 12:43:15 +03:00
/**
2011-02-08 08:53:13 +03:00
* Make a user_info_dc struct from the info3 returned by a domain logon
2009-01-21 12:43:15 +03:00
*/
2011-02-08 08:53:13 +03:00
NTSTATUS make_user_info_dc_netlogon_validation ( TALLOC_CTX * mem_ctx ,
2009-01-21 12:43:15 +03:00
const char * account_name ,
uint16_t validation_level ,
2016-01-07 16:50:27 +03:00
const union netr_Validation * validation ,
2011-07-18 07:55:20 +04:00
bool authenticated ,
2011-02-08 08:53:13 +03:00
struct auth_user_info_dc * * _user_info_dc )
2009-01-21 12:43:15 +03:00
{
2011-07-18 07:55:20 +04:00
NTSTATUS status ;
2016-01-07 17:06:46 +03:00
struct auth_user_info_dc * user_info_dc = NULL ;
const struct netr_SamBaseInfo * base = NULL ;
uint32_t sidcount = 0 ;
const struct netr_SidAttr * sids = NULL ;
const char * dns_domainname = NULL ;
const char * principal = NULL ;
2010-04-12 16:34:28 +04:00
uint32_t i ;
2009-01-21 12:43:15 +03:00
switch ( validation_level ) {
case 2 :
if ( ! validation | | ! validation - > sam2 ) {
return NT_STATUS_INVALID_PARAMETER ;
}
base = & validation - > sam2 - > base ;
break ;
case 3 :
if ( ! validation | | ! validation - > sam3 ) {
return NT_STATUS_INVALID_PARAMETER ;
}
base = & validation - > sam3 - > base ;
2016-01-07 17:06:46 +03:00
sidcount = validation - > sam3 - > sidcount ;
sids = validation - > sam3 - > sids ;
2009-01-21 12:43:15 +03:00
break ;
case 6 :
if ( ! validation | | ! validation - > sam6 ) {
return NT_STATUS_INVALID_PARAMETER ;
}
base = & validation - > sam6 - > base ;
2016-01-07 17:06:46 +03:00
sidcount = validation - > sam6 - > sidcount ;
sids = validation - > sam6 - > sids ;
dns_domainname = validation - > sam6 - > dns_domainname . string ;
principal = validation - > sam6 - > principal_name . string ;
2009-01-21 12:43:15 +03:00
break ;
default :
return NT_STATUS_INVALID_LEVEL ;
}
2022-06-10 10:18:07 +03:00
user_info_dc = talloc_zero ( mem_ctx , struct auth_user_info_dc ) ;
2011-02-08 08:53:13 +03:00
NT_STATUS_HAVE_NO_MEMORY ( user_info_dc ) ;
2009-01-21 12:43:15 +03:00
/*
Here is where we should check the list of
2011-02-09 08:05:54 +03:00
trusted domains , and verify that the SID
2009-01-21 12:43:15 +03:00
matches .
*/
2011-01-20 15:39:37 +03:00
if ( ! base - > domain_sid ) {
DEBUG ( 0 , ( " Cannot operate on a Netlogon Validation without a domain SID " ) ) ;
return NT_STATUS_INVALID_PARAMETER ;
}
2009-01-21 12:43:15 +03:00
2011-01-20 15:39:37 +03:00
/* The IDL layer would be a better place to check this, but to
* guard the integer addition below , we double - check */
if ( base - > groups . count > 65535 ) {
return NT_STATUS_INVALID_PARAMETER ;
}
2009-01-21 12:43:15 +03:00
2011-02-08 08:53:13 +03:00
user_info_dc - > num_sids = 2 ;
2009-01-21 12:43:15 +03:00
2022-09-27 05:13:12 +03:00
user_info_dc - > sids = talloc_array ( user_info_dc , struct auth_SidAttr , user_info_dc - > num_sids + base - > groups . count ) ;
2011-02-08 08:53:13 +03:00
NT_STATUS_HAVE_NO_MEMORY ( user_info_dc - > sids ) ;
2011-01-20 15:39:37 +03:00
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ PRIMARY_USER_SID_INDEX ] . sid = * base - > domain_sid ;
if ( ! sid_append_rid ( & user_info_dc - > sids [ PRIMARY_USER_SID_INDEX ] . sid , base - > rid ) ) {
2011-01-20 15:39:37 +03:00
return NT_STATUS_INVALID_PARAMETER ;
}
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ PRIMARY_USER_SID_INDEX ] . attrs
= SE_GROUP_MANDATORY | SE_GROUP_ENABLED_BY_DEFAULT | SE_GROUP_ENABLED ;
2011-01-20 15:39:37 +03:00
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ PRIMARY_GROUP_SID_INDEX ] . sid = * base - > domain_sid ;
if ( ! sid_append_rid ( & user_info_dc - > sids [ PRIMARY_GROUP_SID_INDEX ] . sid , base - > primary_gid ) ) {
2011-01-20 15:39:37 +03:00
return NT_STATUS_INVALID_PARAMETER ;
2009-01-21 12:43:15 +03:00
}
2022-09-27 05:13:12 +03:00
/*
* This attribute value might be wrong if the primary group is a
* resource group . But a resource group is not meant to be in a primary
* group in the first place , and besides , these attributes will never
* make their way into a PAC .
*/
user_info_dc - > sids [ PRIMARY_GROUP_SID_INDEX ] . attrs
= SE_GROUP_MANDATORY | SE_GROUP_ENABLED_BY_DEFAULT | SE_GROUP_ENABLED ;
2009-01-21 12:43:15 +03:00
for ( i = 0 ; i < base - > groups . count ; i + + ) {
2019-04-03 19:45:02 +03:00
/* Skip primary group, already added above */
if ( base - > groups . rids [ i ] . rid = = base - > primary_gid ) {
continue ;
}
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ user_info_dc - > num_sids ] . sid = * base - > domain_sid ;
if ( ! sid_append_rid ( & user_info_dc - > sids [ user_info_dc - > num_sids ] . sid , base - > groups . rids [ i ] . rid ) ) {
2011-01-20 15:39:37 +03:00
return NT_STATUS_INVALID_PARAMETER ;
}
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ user_info_dc - > num_sids ] . attrs = base - > groups . rids [ i ] . attributes ;
2011-02-08 08:53:13 +03:00
user_info_dc - > num_sids + + ;
2009-01-21 12:43:15 +03:00
}
/* Copy 'other' sids. We need to do sid filtering here to
2011-02-09 08:05:54 +03:00
prevent possible elevation of privileges . See :
2009-01-21 12:43:15 +03:00
http : //www.microsoft.com/windows2000/techinfo/administration/security/sidfilter.asp
*/
2016-01-07 17:06:46 +03:00
/*
* The IDL layer would be a better place to check this , but to
* guard the integer addition below , we double - check
*/
if ( sidcount > UINT16_MAX ) {
return NT_STATUS_INVALID_PARAMETER ;
}
if ( sidcount > 0 ) {
2022-09-27 05:13:12 +03:00
struct auth_SidAttr * dgrps = user_info_dc - > sids ;
2016-01-07 17:06:46 +03:00
size_t dgrps_count ;
2011-01-20 15:39:37 +03:00
2016-01-07 17:06:46 +03:00
dgrps_count = user_info_dc - > num_sids + sidcount ;
2022-09-27 05:13:12 +03:00
dgrps = talloc_realloc ( user_info_dc , dgrps , struct auth_SidAttr ,
2016-01-07 17:06:46 +03:00
dgrps_count ) ;
if ( dgrps = = NULL ) {
return NT_STATUS_NO_MEMORY ;
2011-01-20 15:39:37 +03:00
}
2009-01-21 12:43:15 +03:00
2016-01-07 17:06:46 +03:00
for ( i = 0 ; i < sidcount ; i + + ) {
if ( sids [ i ] . sid ) {
2022-09-27 05:13:12 +03:00
dgrps [ user_info_dc - > num_sids ] . sid = * sids [ i ] . sid ;
dgrps [ user_info_dc - > num_sids ] . attrs = sids [ i ] . attributes ;
2016-01-07 17:06:46 +03:00
user_info_dc - > num_sids + + ;
2009-01-21 12:43:15 +03:00
}
}
2011-02-08 08:53:13 +03:00
user_info_dc - > sids = dgrps ;
2009-01-21 12:43:15 +03:00
/* Where are the 'global' sids?... */
}
2011-07-18 07:55:20 +04:00
status = make_user_info_SamBaseInfo ( user_info_dc , account_name , base , authenticated , & user_info_dc - > info ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return status ;
2009-01-21 12:43:15 +03:00
}
2016-01-07 17:06:46 +03:00
if ( dns_domainname ! = NULL ) {
user_info_dc - > info - > dns_domain_name = talloc_strdup ( user_info_dc - > info ,
dns_domainname ) ;
if ( user_info_dc - > info - > dns_domain_name = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
}
if ( principal ! = NULL ) {
user_info_dc - > info - > user_principal_name = talloc_strdup ( user_info_dc - > info ,
principal ) ;
if ( user_info_dc - > info - > user_principal_name = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
}
2009-01-21 12:43:15 +03:00
/* ensure we are never given NULL session keys */
if ( all_zero ( base - > key . key , sizeof ( base - > key . key ) ) ) {
2011-02-08 08:53:13 +03:00
user_info_dc - > user_session_key = data_blob ( NULL , 0 ) ;
2009-01-21 12:43:15 +03:00
} else {
2011-02-08 08:53:13 +03:00
user_info_dc - > user_session_key = data_blob_talloc ( user_info_dc , base - > key . key , sizeof ( base - > key . key ) ) ;
NT_STATUS_HAVE_NO_MEMORY ( user_info_dc - > user_session_key . data ) ;
2009-01-21 12:43:15 +03:00
}
if ( all_zero ( base - > LMSessKey . key , sizeof ( base - > LMSessKey . key ) ) ) {
2011-02-08 08:53:13 +03:00
user_info_dc - > lm_session_key = data_blob ( NULL , 0 ) ;
2009-01-21 12:43:15 +03:00
} else {
2011-02-08 08:53:13 +03:00
user_info_dc - > lm_session_key = data_blob_talloc ( user_info_dc , base - > LMSessKey . key , sizeof ( base - > LMSessKey . key ) ) ;
NT_STATUS_HAVE_NO_MEMORY ( user_info_dc - > lm_session_key . data ) ;
2009-01-21 12:43:15 +03:00
}
2011-02-08 08:53:13 +03:00
* _user_info_dc = user_info_dc ;
2009-01-21 12:43:15 +03:00
return NT_STATUS_OK ;
}
2010-10-01 23:09:42 +04:00
/**
2011-02-08 08:53:13 +03:00
* Make a user_info_dc struct from the PAC_LOGON_INFO supplied in the krb5 logon
2010-10-01 23:09:42 +04:00
*/
2011-02-08 08:53:13 +03:00
NTSTATUS make_user_info_dc_pac ( TALLOC_CTX * mem_ctx ,
2016-01-07 16:50:27 +03:00
const struct PAC_LOGON_INFO * pac_logon_info ,
2016-01-07 16:55:07 +03:00
const struct PAC_UPN_DNS_INFO * pac_upn_dns_info ,
2011-02-08 08:53:13 +03:00
struct auth_user_info_dc * * _user_info_dc )
2010-10-01 23:09:42 +04:00
{
uint32_t i ;
NTSTATUS nt_status ;
union netr_Validation validation ;
2011-02-08 08:53:13 +03:00
struct auth_user_info_dc * user_info_dc ;
2016-05-20 15:16:35 +03:00
const struct PAC_DOMAIN_GROUP_MEMBERSHIP * rg = NULL ;
size_t sidcount ;
rg = & pac_logon_info - > resource_groups ;
2010-10-01 23:09:42 +04:00
2016-01-07 16:50:27 +03:00
validation . sam3 = discard_const_p ( struct netr_SamInfo3 , & pac_logon_info - > info3 ) ;
2010-10-01 23:09:42 +04:00
2011-07-18 07:55:20 +04:00
nt_status = make_user_info_dc_netlogon_validation ( mem_ctx , " " , 3 , & validation ,
true , /* This user was authenticated */
& user_info_dc ) ;
2010-10-01 23:09:42 +04:00
if ( ! NT_STATUS_IS_OK ( nt_status ) ) {
return nt_status ;
}
2016-05-20 15:16:35 +03:00
if ( pac_logon_info - > info3 . base . user_flags & NETLOGON_RESOURCE_GROUPS ) {
rg = & pac_logon_info - > resource_groups ;
}
2022-11-07 09:37:12 +03:00
if ( rg ! = NULL & & rg - > groups . count > 0 ) {
2011-01-20 15:39:37 +03:00
/* The IDL layer would be a better place to check this, but to
* guard the integer addition below , we double - check */
2016-05-20 15:16:35 +03:00
if ( rg - > groups . count > 65535 ) {
2011-02-08 08:53:13 +03:00
talloc_free ( user_info_dc ) ;
2011-01-20 15:39:37 +03:00
return NT_STATUS_INVALID_PARAMETER ;
}
/*
Here is where we should check the list of
trusted domains , and verify that the SID
matches .
*/
2016-05-20 15:16:35 +03:00
if ( rg - > domain_sid = = NULL ) {
talloc_free ( user_info_dc ) ;
2011-01-20 15:39:37 +03:00
DEBUG ( 0 , ( " Cannot operate on a PAC without a resource domain SID " ) ) ;
return NT_STATUS_INVALID_PARAMETER ;
}
2016-05-20 15:16:35 +03:00
sidcount = user_info_dc - > num_sids + rg - > groups . count ;
2011-02-08 08:53:13 +03:00
user_info_dc - > sids
2022-09-27 05:13:12 +03:00
= talloc_realloc ( user_info_dc , user_info_dc - > sids , struct auth_SidAttr , sidcount ) ;
2014-02-13 08:51:11 +04:00
if ( user_info_dc - > sids = = NULL ) {
TALLOC_FREE ( user_info_dc ) ;
return NT_STATUS_NO_MEMORY ;
}
2010-10-01 23:09:42 +04:00
2016-05-20 15:16:35 +03:00
for ( i = 0 ; i < rg - > groups . count ; i + + ) {
bool ok ;
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ user_info_dc - > num_sids ] . sid = * rg - > domain_sid ;
ok = sid_append_rid ( & user_info_dc - > sids [ user_info_dc - > num_sids ] . sid ,
2016-05-20 15:16:35 +03:00
rg - > groups . rids [ i ] . rid ) ;
if ( ! ok ) {
2011-01-20 15:39:37 +03:00
return NT_STATUS_INVALID_PARAMETER ;
}
2022-09-27 05:13:12 +03:00
user_info_dc - > sids [ user_info_dc - > num_sids ] . attrs = rg - > groups . rids [ i ] . attributes ;
2011-02-08 08:53:13 +03:00
user_info_dc - > num_sids + + ;
2010-10-01 23:09:42 +04:00
}
}
2016-01-07 16:55:07 +03:00
if ( pac_upn_dns_info ! = NULL ) {
2022-02-22 04:15:43 +03:00
if ( pac_upn_dns_info - > upn_name ! = NULL ) {
user_info_dc - > info - > user_principal_name =
talloc_strdup ( user_info_dc - > info ,
pac_upn_dns_info - > upn_name ) ;
if ( user_info_dc - > info - > user_principal_name = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
2016-01-07 16:55:07 +03:00
}
user_info_dc - > info - > dns_domain_name =
talloc_strdup ( user_info_dc - > info ,
pac_upn_dns_info - > dns_domain_name ) ;
if ( user_info_dc - > info - > dns_domain_name = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
if ( pac_upn_dns_info - > flags & PAC_UPN_DNS_FLAG_CONSTRUCTED ) {
user_info_dc - > info - > user_principal_constructed = true ;
}
}
2011-02-08 08:53:13 +03:00
* _user_info_dc = user_info_dc ;
2010-10-01 23:09:42 +04:00
return NT_STATUS_OK ;
}