2000-07-05 15:24:26 +04:00
/*
2002-01-30 09:08:46 +03:00
Unix SMB / CIFS implementation .
2000-07-05 15:24:26 +04:00
Winbind status program .
2002-05-13 04:46:28 +04:00
Copyright ( C ) Tim Potter 2000 - 2002
2002-01-10 14:28:14 +03:00
Copyright ( C ) Andrew Bartlett 2002
2000-07-05 15:24:26 +04:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 2 of the License , or
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program ; if not , write to the Free Software
Foundation , Inc . , 675 Mass Ave , Cambridge , MA 0213 9 , USA .
*/
# include "includes.h"
# include "winbindd.h"
# include "debug.h"
2002-07-15 14:35:28 +04:00
# undef DBGC_CLASS
# define DBGC_CLASS DBGC_WINBIND
2002-09-25 19:19:00 +04:00
extern int winbindd_fd ;
2000-07-05 15:24:26 +04:00
2002-03-20 06:54:47 +03:00
static char winbind_separator ( void )
2002-01-10 14:28:14 +03:00
{
struct winbindd_response response ;
2002-03-20 06:54:47 +03:00
static BOOL got_sep ;
static char sep ;
if ( got_sep )
return sep ;
2002-01-10 14:28:14 +03:00
ZERO_STRUCT ( response ) ;
/* Send off request */
if ( winbindd_request ( WINBINDD_INFO , NULL , & response ) ! =
NSS_STATUS_SUCCESS ) {
2002-04-04 10:47:20 +04:00
d_printf ( " could not obtain winbind separator! \n " ) ;
2002-02-15 16:28:59 +03:00
/* HACK: (this module should not call lp_ funtions) */
return * lp_winbind_separator ( ) ;
2002-01-10 14:28:14 +03:00
}
2002-03-20 06:54:47 +03:00
sep = response . data . info . winbind_separator ;
got_sep = True ;
2002-01-10 14:28:14 +03:00
2002-03-20 06:54:47 +03:00
if ( ! sep ) {
2002-03-01 04:13:42 +03:00
d_printf ( " winbind separator was NULL! \n " ) ;
2002-02-15 16:28:59 +03:00
/* HACK: (this module should not call lp_ funtions) */
2002-03-20 06:54:47 +03:00
sep = * lp_winbind_separator ( ) ;
2002-01-10 14:28:14 +03:00
}
2002-03-20 06:54:47 +03:00
return sep ;
2002-01-10 14:28:14 +03:00
}
2002-11-13 02:20:50 +03:00
static const char * get_winbind_domain ( void )
2002-01-26 12:55:38 +03:00
{
struct winbindd_response response ;
static fstring winbind_domain ;
ZERO_STRUCT ( response ) ;
/* Send off request */
if ( winbindd_request ( WINBINDD_DOMAIN_NAME , NULL , & response ) ! =
NSS_STATUS_SUCCESS ) {
2002-03-01 04:13:42 +03:00
d_printf ( " could not obtain winbind domain name! \n " ) ;
2002-02-15 16:28:59 +03:00
/* HACK: (this module should not call lp_ funtions) */
return lp_workgroup ( ) ;
2002-01-26 12:55:38 +03:00
}
fstrcpy ( winbind_domain , response . data . domain_name ) ;
return winbind_domain ;
}
2002-01-10 13:23:54 +03:00
/* Copy of parse_domain_user from winbindd_util.c. Parse a string of the
form DOMAIN / user into a domain and a user */
2002-03-20 06:54:47 +03:00
static BOOL parse_wbinfo_domain_user ( const char * domuser , fstring domain ,
fstring user )
2002-01-10 13:23:54 +03:00
{
2002-01-10 14:28:14 +03:00
2002-03-20 06:54:47 +03:00
char * p = strchr ( domuser , winbind_separator ( ) ) ;
2002-01-10 13:23:54 +03:00
2002-01-18 05:37:55 +03:00
if ( ! p ) {
fstrcpy ( user , domuser ) ;
2002-01-26 12:55:38 +03:00
fstrcpy ( domain , get_winbind_domain ( ) ) ;
2002-01-18 05:37:55 +03:00
return True ;
}
2002-01-10 13:23:54 +03:00
fstrcpy ( user , p + 1 ) ;
fstrcpy ( domain , domuser ) ;
domain [ PTR_DIFF ( p , domuser ) ] = 0 ;
2003-07-03 23:11:31 +04:00
strupper_m ( domain ) ;
2002-03-20 06:54:47 +03:00
2002-01-10 13:23:54 +03:00
return True ;
}
2000-10-13 09:19:57 +04:00
/* List groups a user is a member of */
2000-10-11 09:25:32 +04:00
static BOOL wbinfo_get_usergroups ( char * user )
{
struct winbindd_request request ;
struct winbindd_response response ;
2001-09-05 11:55:54 +04:00
NSS_STATUS result ;
int i ;
2000-10-11 09:25:32 +04:00
ZERO_STRUCT ( response ) ;
/* Send request */
fstrcpy ( request . data . username , user ) ;
2000-10-11 09:45:06 +04:00
result = winbindd_request ( WINBINDD_GETGROUPS , & request , & response ) ;
2000-10-11 09:25:32 +04:00
2002-01-11 06:49:51 +03:00
if ( result ! = NSS_STATUS_SUCCESS )
2000-10-11 09:25:32 +04:00
return False ;
2002-01-11 06:49:51 +03:00
for ( i = 0 ; i < response . data . num_entries ; i + + )
2002-03-01 04:13:42 +03:00
d_printf ( " %d \n " , ( int ) ( ( gid_t * ) response . extra_data ) [ i ] ) ;
2002-01-11 06:49:51 +03:00
SAFE_FREE ( response . extra_data ) ;
2000-10-11 09:25:32 +04:00
return True ;
}
2002-03-29 18:37:39 +03:00
/* Convert NetBIOS name to IP */
static BOOL wbinfo_wins_byname ( char * name )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
fstrcpy ( request . data . winsreq , name ) ;
if ( winbindd_request ( WINBINDD_WINS_BYNAME , & request , & response ) ! =
NSS_STATUS_SUCCESS ) {
return False ;
}
/* Display response */
printf ( " %s \n " , response . data . winsresp ) ;
return True ;
}
/* Convert IP to NetBIOS name */
static BOOL wbinfo_wins_byip ( char * ip )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
fstrcpy ( request . data . winsreq , ip ) ;
if ( winbindd_request ( WINBINDD_WINS_BYIP , & request , & response ) ! =
NSS_STATUS_SUCCESS ) {
return False ;
}
/* Display response */
printf ( " %s \n " , response . data . winsresp ) ;
return True ;
}
2000-07-05 15:24:26 +04:00
/* List trusted domains */
static BOOL wbinfo_list_domains ( void )
{
struct winbindd_response response ;
fstring name ;
ZERO_STRUCT ( response ) ;
/* Send request */
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_LIST_TRUSTDOM , NULL , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
if ( response . extra_data ) {
2002-11-13 02:20:50 +03:00
const char * extra_data = ( char * ) response . extra_data ;
2002-01-11 06:49:51 +03:00
while ( next_token ( & extra_data , name , " , " , sizeof ( fstring ) ) )
2002-03-01 04:13:42 +03:00
d_printf ( " %s \n " , name ) ;
2002-01-11 06:49:51 +03:00
SAFE_FREE ( response . extra_data ) ;
2000-07-05 15:24:26 +04:00
}
return True ;
}
2002-01-31 14:49:29 +03:00
/* show sequence numbers */
static BOOL wbinfo_show_sequence ( void )
{
struct winbindd_response response ;
ZERO_STRUCT ( response ) ;
/* Send request */
2002-03-20 06:54:47 +03:00
2002-01-31 14:49:29 +03:00
if ( winbindd_request ( WINBINDD_SHOW_SEQUENCE , NULL , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2002-01-31 14:49:29 +03:00
return False ;
/* Display response */
2002-03-20 06:54:47 +03:00
2002-01-31 14:49:29 +03:00
if ( response . extra_data ) {
char * extra_data = ( char * ) response . extra_data ;
2002-03-01 04:13:42 +03:00
d_printf ( " %s " , extra_data ) ;
2002-01-31 14:49:29 +03:00
SAFE_FREE ( response . extra_data ) ;
}
return True ;
}
2000-07-05 15:24:26 +04:00
/* Check trust account password */
static BOOL wbinfo_check_secret ( void )
{
2000-10-13 09:19:57 +04:00
struct winbindd_response response ;
2002-07-15 14:35:28 +04:00
NSS_STATUS result ;
2000-10-13 09:19:57 +04:00
ZERO_STRUCT ( response ) ;
2002-08-17 21:00:51 +04:00
result = winbindd_request ( WINBINDD_CHECK_MACHACC , NULL , & response ) ;
2002-07-15 14:35:28 +04:00
d_printf ( " checking the trust secret via RPC calls %s \n " ,
( result = = NSS_STATUS_SUCCESS ) ? " succeeded " : " failed " ) ;
2000-10-13 09:19:57 +04:00
2002-07-15 14:35:28 +04:00
if ( result ! = NSS_STATUS_SUCCESS )
d_printf ( " error code was %s (0x%x) \n " ,
response . data . auth . nt_status_string ,
response . data . auth . nt_status ) ;
return result = = NSS_STATUS_SUCCESS ;
2000-07-05 15:24:26 +04:00
}
/* Convert uid to sid */
static BOOL wbinfo_uid_to_sid ( uid_t uid )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
request . data . uid = uid ;
2002-03-20 06:54:47 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_UID_TO_SID , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " %s \n " , response . data . sid . sid ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
/* Convert gid to sid */
static BOOL wbinfo_gid_to_sid ( gid_t gid )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
request . data . gid = gid ;
2002-03-20 06:54:47 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_GID_TO_SID , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " %s \n " , response . data . sid . sid ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
/* Convert sid to uid */
static BOOL wbinfo_sid_to_uid ( char * sid )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
fstrcpy ( request . data . sid , sid ) ;
2002-03-20 06:54:47 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_SID_TO_UID , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " %d \n " , ( int ) response . data . uid ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
static BOOL wbinfo_sid_to_gid ( char * sid )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send request */
fstrcpy ( request . data . sid , sid ) ;
2002-03-20 06:54:47 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_SID_TO_GID , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " %d \n " , ( int ) response . data . gid ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
/* Convert sid to string */
static BOOL wbinfo_lookupsid ( char * sid )
{
struct winbindd_request request ;
struct winbindd_response response ;
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
/* Send off request */
fstrcpy ( request . data . sid , sid ) ;
2002-03-20 06:54:47 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_LOOKUPSID , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-20 06:54:47 +03:00
d_printf ( " %s%c%s %d \n " , response . data . name . dom_name ,
winbind_separator ( ) , response . data . name . name ,
response . data . name . type ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
/* Convert string to sid */
static BOOL wbinfo_lookupname ( char * name )
{
struct winbindd_request request ;
struct winbindd_response response ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
2002-03-20 06:54:47 +03:00
parse_wbinfo_domain_user ( name , request . data . name . dom_name ,
request . data . name . name ) ;
2002-01-26 12:55:38 +03:00
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_LOOKUPNAME , & request , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " %s %d \n " , response . data . sid . sid , response . data . sid . type ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
2001-08-22 06:48:16 +04:00
/* Authenticate a user with a plaintext password */
static BOOL wbinfo_auth ( char * username )
{
struct winbindd_request request ;
struct winbindd_response response ;
2001-09-05 11:55:54 +04:00
NSS_STATUS result ;
2001-08-22 06:48:16 +04:00
char * p ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
p = strchr ( username , ' % ' ) ;
if ( p ) {
* p = 0 ;
fstrcpy ( request . data . auth . user , username ) ;
fstrcpy ( request . data . auth . pass , p + 1 ) ;
* p = ' % ' ;
} else
fstrcpy ( request . data . auth . user , username ) ;
result = winbindd_request ( WINBINDD_PAM_AUTH , & request , & response ) ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " plaintext password authentication %s \n " ,
2001-09-05 11:55:54 +04:00
( result = = NSS_STATUS_SUCCESS ) ? " succeeded " : " failed " ) ;
2001-08-22 06:48:16 +04:00
2002-09-25 19:19:00 +04:00
if ( response . data . auth . nt_status )
2003-04-07 11:32:51 +04:00
d_printf ( " error code was %s (0x%x) \n error messsage was: %s \n " ,
2002-09-25 19:19:00 +04:00
response . data . auth . nt_status_string ,
2003-04-07 11:32:51 +04:00
response . data . auth . nt_status ,
response . data . auth . error_string ) ;
2002-02-05 12:40:36 +03:00
2001-09-05 11:55:54 +04:00
return result = = NSS_STATUS_SUCCESS ;
2001-08-22 06:48:16 +04:00
}
/* Authenticate a user with a challenge/response */
static BOOL wbinfo_auth_crap ( char * username )
{
struct winbindd_request request ;
struct winbindd_response response ;
2001-09-05 11:55:54 +04:00
NSS_STATUS result ;
2002-01-10 13:23:54 +03:00
fstring name_user ;
fstring name_domain ;
2001-08-22 06:48:16 +04:00
fstring pass ;
char * p ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
p = strchr ( username , ' % ' ) ;
if ( p ) {
* p = 0 ;
fstrcpy ( pass , p + 1 ) ;
2002-01-10 13:23:54 +03:00
}
2002-01-10 14:28:14 +03:00
parse_wbinfo_domain_user ( username , name_domain , name_user ) ;
2002-01-10 13:23:54 +03:00
fstrcpy ( request . data . auth_crap . user , name_user ) ;
fstrcpy ( request . data . auth_crap . domain , name_domain ) ;
2001-08-22 06:48:16 +04:00
generate_random_buffer ( request . data . auth_crap . chal , 8 , False ) ;
2002-08-17 21:00:51 +04:00
SMBencrypt ( pass , request . data . auth_crap . chal ,
2001-09-05 11:55:54 +04:00
( uchar * ) request . data . auth_crap . lm_resp ) ;
2002-08-17 21:00:51 +04:00
SMBNTencrypt ( pass , request . data . auth_crap . chal ,
2001-09-05 11:55:54 +04:00
( uchar * ) request . data . auth_crap . nt_resp ) ;
2001-08-22 06:48:16 +04:00
request . data . auth_crap . lm_resp_len = 24 ;
request . data . auth_crap . nt_resp_len = 24 ;
result = winbindd_request ( WINBINDD_PAM_AUTH_CRAP , & request , & response ) ;
/* Display response */
2002-03-01 04:13:42 +03:00
d_printf ( " challenge/response password authentication %s \n " ,
2001-09-05 11:55:54 +04:00
( result = = NSS_STATUS_SUCCESS ) ? " succeeded " : " failed " ) ;
2001-08-22 06:48:16 +04:00
2002-09-25 19:19:00 +04:00
if ( response . data . auth . nt_status )
2003-04-07 11:32:51 +04:00
d_printf ( " error code was %s (0x%x) \n error messsage was: %s \n " ,
2002-09-25 19:19:00 +04:00
response . data . auth . nt_status_string ,
2003-04-07 11:32:51 +04:00
response . data . auth . nt_status ,
response . data . auth . error_string ) ;
2002-02-05 12:40:36 +03:00
2001-09-05 11:55:54 +04:00
return result = = NSS_STATUS_SUCCESS ;
2001-08-22 06:48:16 +04:00
}
2003-07-09 20:44:47 +04:00
/******************************************************************
create a winbindd user
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_create_user ( char * username )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
2003-07-11 09:33:40 +04:00
request . flags = WBFLAG_ALLOCATE_RID ;
2003-07-09 20:44:47 +04:00
fstrcpy ( request . data . acct_mgt . username , username ) ;
result = winbindd_request ( WINBINDD_CREATE_USER , & request , & response ) ;
2003-07-11 09:33:40 +04:00
if ( result = = NSS_STATUS_SUCCESS )
d_printf ( " New RID is %d \n " , response . data . rid ) ;
return result = = NSS_STATUS_SUCCESS ;
}
2003-07-09 20:44:47 +04:00
2003-07-11 09:33:40 +04:00
/******************************************************************
remove a winbindd user
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_delete_user ( char * username )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
fstrcpy ( request . data . acct_mgt . username , username ) ;
result = winbindd_request ( WINBINDD_DELETE_USER , & request , & response ) ;
2003-07-09 20:44:47 +04:00
return result = = NSS_STATUS_SUCCESS ;
}
/******************************************************************
create a winbindd group
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_create_group ( char * groupname )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
fstrcpy ( request . data . acct_mgt . groupname , groupname ) ;
result = winbindd_request ( WINBINDD_CREATE_GROUP , & request , & response ) ;
2003-07-11 09:33:40 +04:00
return result = = NSS_STATUS_SUCCESS ;
}
2003-07-09 20:44:47 +04:00
2003-07-11 09:33:40 +04:00
/******************************************************************
remove a winbindd group
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_delete_group ( char * groupname )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
fstrcpy ( request . data . acct_mgt . groupname , groupname ) ;
result = winbindd_request ( WINBINDD_DELETE_GROUP , & request , & response ) ;
2003-07-09 20:44:47 +04:00
return result = = NSS_STATUS_SUCCESS ;
}
/******************************************************************
parse a string in the form user : group
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL parse_user_group ( const char * string , fstring user , fstring group )
{
char * p ;
if ( ! string )
return False ;
if ( ! ( p = strchr ( string , ' : ' ) ) )
return False ;
* p = ' \0 ' ;
p + + ;
fstrcpy ( user , string ) ;
fstrcpy ( group , p ) ;
return True ;
}
/******************************************************************
add a user to a winbindd group
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_add_user_to_group ( char * string )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
if ( ! parse_user_group ( string , request . data . acct_mgt . username ,
request . data . acct_mgt . groupname ) )
{
d_printf ( " Can't parse user:group from %s \n " , string ) ;
return False ;
}
result = winbindd_request ( WINBINDD_ADD_USER_TO_GROUP , & request , & response ) ;
return result = = NSS_STATUS_SUCCESS ;
}
/******************************************************************
remove a user from a winbindd group
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static BOOL wbinfo_remove_user_from_group ( char * string )
{
struct winbindd_request request ;
struct winbindd_response response ;
NSS_STATUS result ;
/* Send off request */
ZERO_STRUCT ( request ) ;
ZERO_STRUCT ( response ) ;
if ( ! parse_user_group ( string , request . data . acct_mgt . username ,
request . data . acct_mgt . groupname ) )
{
d_printf ( " Can't parse user:group from %s \n " , string ) ;
return False ;
}
result = winbindd_request ( WINBINDD_REMOVE_USER_FROM_GROUP , & request , & response ) ;
return result = = NSS_STATUS_SUCCESS ;
}
2000-07-05 15:24:26 +04:00
/* Print domain users */
static BOOL print_domain_users ( void )
{
struct winbindd_response response ;
2002-11-13 02:20:50 +03:00
const char * extra_data ;
2000-07-05 15:24:26 +04:00
fstring name ;
/* Send request to winbind daemon */
ZERO_STRUCT ( response ) ;
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_LIST_USERS , NULL , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Look through extra data */
2002-01-11 06:49:51 +03:00
if ( ! response . extra_data )
2000-07-05 15:24:26 +04:00
return False ;
2002-11-13 02:20:50 +03:00
extra_data = ( const char * ) response . extra_data ;
2002-01-11 06:49:51 +03:00
while ( next_token ( & extra_data , name , " , " , sizeof ( fstring ) ) )
2002-03-01 04:13:42 +03:00
d_printf ( " %s \n " , name ) ;
2000-07-05 15:24:26 +04:00
2002-01-11 06:49:51 +03:00
SAFE_FREE ( response . extra_data ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
/* Print domain groups */
static BOOL print_domain_groups ( void )
{
struct winbindd_response response ;
2002-11-13 02:20:50 +03:00
const char * extra_data ;
2000-07-05 15:24:26 +04:00
fstring name ;
ZERO_STRUCT ( response ) ;
2001-09-05 11:55:54 +04:00
if ( winbindd_request ( WINBINDD_LIST_GROUPS , NULL , & response ) ! =
2002-03-20 06:54:47 +03:00
NSS_STATUS_SUCCESS )
2000-07-05 15:24:26 +04:00
return False ;
/* Look through extra data */
2002-01-11 06:49:51 +03:00
if ( ! response . extra_data )
2000-07-05 15:24:26 +04:00
return False ;
2002-11-13 02:20:50 +03:00
extra_data = ( const char * ) response . extra_data ;
2002-01-11 06:49:51 +03:00
while ( next_token ( & extra_data , name , " , " , sizeof ( fstring ) ) )
2002-03-01 04:13:42 +03:00
d_printf ( " %s \n " , name ) ;
2002-01-11 06:49:51 +03:00
SAFE_FREE ( response . extra_data ) ;
2000-07-05 15:24:26 +04:00
return True ;
}
2001-12-11 08:18:36 +03:00
/* Set the authorised user for winbindd access in secrets.tdb */
static BOOL wbinfo_set_auth_user ( char * username )
{
2003-01-08 05:18:49 +03:00
char * password ;
2002-02-15 16:28:59 +03:00
fstring user , domain ;
2001-12-11 08:18:36 +03:00
/* Separate into user and password */
2002-02-15 16:28:59 +03:00
parse_wbinfo_domain_user ( username , domain , user ) ;
password = strchr ( user , ' % ' ) ;
2001-12-11 08:18:36 +03:00
if ( password ) {
* password = 0 ;
password + + ;
} else
password = " " ;
2002-11-02 04:51:53 +03:00
/* Store or remove DOMAIN\username%password in secrets.tdb */
secrets_init ( ) ;
if ( user [ 0 ] ) {
if ( ! secrets_store ( SECRETS_AUTH_USER , user ,
strlen ( user ) + 1 ) ) {
d_fprintf ( stderr , " error storing username \n " ) ;
return False ;
}
/* We always have a domain name added by the
parse_wbinfo_domain_user ( ) function . */
if ( ! secrets_store ( SECRETS_AUTH_DOMAIN , domain ,
strlen ( domain ) + 1 ) ) {
d_fprintf ( stderr , " error storing domain name \n " ) ;
return False ;
}
} else {
secrets_delete ( SECRETS_AUTH_USER ) ;
secrets_delete ( SECRETS_AUTH_DOMAIN ) ;
2001-12-11 08:18:36 +03:00
}
2002-11-02 04:51:53 +03:00
if ( password [ 0 ] ) {
if ( ! secrets_store ( SECRETS_AUTH_PASSWORD , password ,
strlen ( password ) + 1 ) ) {
d_fprintf ( stderr , " error storing password \n " ) ;
return False ;
}
} else
secrets_delete ( SECRETS_AUTH_PASSWORD ) ;
2001-12-11 08:18:36 +03:00
return True ;
}
2002-11-02 04:51:53 +03:00
static void wbinfo_get_auth_user ( void )
{
char * user , * domain , * password ;
/* Lift data from secrets file */
secrets_init ( ) ;
user = secrets_fetch ( SECRETS_AUTH_USER , NULL ) ;
domain = secrets_fetch ( SECRETS_AUTH_DOMAIN , NULL ) ;
password = secrets_fetch ( SECRETS_AUTH_PASSWORD , NULL ) ;
if ( ! user & & ! domain & & ! password ) {
d_printf ( " No authorised user configured \n " ) ;
return ;
}
/* Pretty print authorised user info */
d_printf ( " %s%s%s%s%s \n " , domain ? domain : " " , domain ? " \\ " : " " ,
user , password ? " % " : " " , password ? password : " " ) ;
SAFE_FREE ( user ) ;
SAFE_FREE ( domain ) ;
SAFE_FREE ( password ) ;
}
2002-01-10 13:23:54 +03:00
static BOOL wbinfo_ping ( void )
{
NSS_STATUS result ;
2002-09-25 19:19:00 +04:00
2002-01-10 13:23:54 +03:00
result = winbindd_request ( WINBINDD_PING , NULL , NULL ) ;
/* Display response */
2003-03-18 09:07:50 +03:00
d_printf ( " Ping to winbindd %s on fd %d \n " ,
2002-09-25 19:19:00 +04:00
( result = = NSS_STATUS_SUCCESS ) ? " succeeded " : " failed " , winbindd_fd ) ;
2002-01-10 13:23:54 +03:00
return result = = NSS_STATUS_SUCCESS ;
}
2000-07-05 15:24:26 +04:00
/* Main program */
2001-12-11 08:18:36 +03:00
enum {
2002-03-20 06:54:47 +03:00
OPT_SET_AUTH_USER = 1000 ,
2002-11-02 04:51:53 +03:00
OPT_GET_AUTH_USER ,
2002-07-15 14:35:28 +04:00
OPT_SEQUENCE
2001-12-11 08:18:36 +03:00
} ;
2000-07-05 15:24:26 +04:00
int main ( int argc , char * * argv )
{
int opt ;
2001-12-11 08:18:36 +03:00
poptContext pc ;
2001-12-11 21:08:48 +03:00
static char * string_arg ;
static int int_arg ;
2001-12-11 08:18:36 +03:00
BOOL got_command = False ;
2002-04-04 10:40:17 +04:00
int result = 1 ;
2001-12-11 08:18:36 +03:00
struct poptOption long_options [ ] = {
2002-09-25 19:19:00 +04:00
POPT_AUTOHELP
2001-12-11 08:18:36 +03:00
2002-03-20 06:54:47 +03:00
/* longName, shortName, argInfo, argPtr, value, descrip,
argDesc */
2002-09-25 19:19:00 +04:00
{ " domain-users " , ' u ' , POPT_ARG_NONE , 0 , ' u ' , " Lists all domain users " } ,
{ " domain-groups " , ' g ' , POPT_ARG_NONE , 0 , ' g ' , " Lists all domain groups " } ,
2003-03-18 09:07:50 +03:00
{ " WINS-by-name " , ' N ' , POPT_ARG_STRING , & string_arg , ' N ' , " Converts NetBIOS name to IP " , " NETBIOS-NAME " } ,
{ " WINS-by-ip " , ' I ' , POPT_ARG_STRING , & string_arg , ' I ' , " Converts IP address to NetBIOS name " , " IP " } ,
2002-10-29 20:36:50 +03:00
{ " name-to-sid " , ' n ' , POPT_ARG_STRING , & string_arg , ' n ' , " Converts name to sid " , " NAME " } ,
{ " sid-to-name " , ' s ' , POPT_ARG_STRING , & string_arg , ' s ' , " Converts sid to name " , " SID " } ,
{ " uid-to-sid " , ' U ' , POPT_ARG_INT , & int_arg , ' U ' , " Converts uid to sid " , " UID " } ,
{ " gid-to-sid " , ' G ' , POPT_ARG_INT , & int_arg , ' G ' , " Converts gid to sid " , " GID " } ,
{ " sid-to-uid " , ' S ' , POPT_ARG_STRING , & string_arg , ' S ' , " Converts sid to uid " , " SID " } ,
{ " sid-to-gid " , ' Y ' , POPT_ARG_STRING , & string_arg , ' Y ' , " Converts sid to gid " , " SID " } ,
2003-07-09 20:44:47 +04:00
{ " create-user " , ' c ' , POPT_ARG_STRING , & string_arg , ' c ' , " Create a local user account " , " name " } ,
2003-07-11 09:33:40 +04:00
{ " delete-user " , ' x ' , POPT_ARG_STRING , & string_arg , ' x ' , " Delete a local user account " , " name " } ,
2003-07-09 20:44:47 +04:00
{ " create-group " , ' C ' , POPT_ARG_STRING , & string_arg , ' C ' , " Create a local group " , " name " } ,
2003-07-11 09:33:40 +04:00
{ " delete-group " , ' X ' , POPT_ARG_STRING , & string_arg , ' X ' , " Delete a local group " , " name " } ,
2003-07-09 20:44:47 +04:00
{ " add-to-group " , ' o ' , POPT_ARG_STRING , & string_arg , ' o ' , " Add user to group " , " user:group " } ,
{ " del-from-group " , ' O ' , POPT_ARG_STRING , & string_arg , ' O ' , " Remove user from group " , " user:group " } ,
2002-09-25 19:19:00 +04:00
{ " check-secret " , ' t ' , POPT_ARG_NONE , 0 , ' t ' , " Check shared secret " } ,
{ " trusted-domains " , ' m ' , POPT_ARG_NONE , 0 , ' m ' , " List trusted domains " } ,
2003-03-18 09:07:50 +03:00
{ " sequence " , 0 , POPT_ARG_NONE , 0 , OPT_SEQUENCE , " Show sequence numbers of all domains " } ,
2002-10-29 20:36:50 +03:00
{ " user-groups " , ' r ' , POPT_ARG_STRING , & string_arg , ' r ' , " Get user groups " , " USER " } ,
2002-09-25 19:19:00 +04:00
{ " authenticate " , ' a ' , POPT_ARG_STRING , & string_arg , ' a ' , " authenticate user " , " user%password " } ,
2003-06-18 18:20:23 +04:00
{ " set-auth-user " , 0 , POPT_ARG_STRING , & string_arg , OPT_SET_AUTH_USER , " Store user and password used by winbindd (root only) " , " user%password " } ,
2002-11-02 04:51:53 +03:00
{ " get-auth-user " , 0 , POPT_ARG_NONE , NULL , OPT_GET_AUTH_USER , " Retrieve user and password used by winbindd (root only) " , NULL } ,
2003-03-18 09:07:50 +03:00
{ " ping " , ' p ' , POPT_ARG_NONE , 0 , ' p ' , " Ping winbindd to see if it is alive " } ,
2003-04-14 06:38:21 +04:00
POPT_COMMON_VERSION
POPT_TABLEEND
2001-12-11 08:18:36 +03:00
} ;
2000-07-05 15:24:26 +04:00
/* Samba client initialisation */
2001-11-19 05:49:53 +03:00
if ( ! lp_load ( dyn_CONFIGFILE , True , False , False ) ) {
2002-03-01 04:13:42 +03:00
d_fprintf ( stderr , " wbinfo: error opening config file %s. Error was %s \n " ,
2001-12-05 00:30:52 +03:00
dyn_CONFIGFILE , strerror ( errno ) ) ;
2000-07-05 15:24:26 +04:00
exit ( 1 ) ;
}
2002-01-10 14:28:14 +03:00
2002-11-13 02:20:50 +03:00
if ( ! init_names ( ) )
return 1 ;
2000-07-05 15:24:26 +04:00
load_interfaces ( ) ;
2002-09-25 19:19:00 +04:00
/* Parse options */
pc = poptGetContext ( " wbinfo " , argc , ( const char * * ) argv , long_options , 0 ) ;
2000-07-05 15:24:26 +04:00
/* Parse command line options */
if ( argc = = 1 ) {
2002-09-25 19:19:00 +04:00
poptPrintHelp ( pc , stderr , 0 ) ;
2000-07-05 15:24:26 +04:00
return 1 ;
}
2001-12-11 08:18:36 +03:00
while ( ( opt = poptGetNextOpt ( pc ) ) ! = - 1 ) {
if ( got_command ) {
2002-03-20 06:54:47 +03:00
d_fprintf ( stderr , " No more than one command may be specified at once. \n " ) ;
2001-12-11 08:18:36 +03:00
exit ( 1 ) ;
}
got_command = True ;
}
2002-04-04 10:40:17 +04:00
poptFreeContext ( pc ) ;
2001-12-11 08:18:36 +03:00
pc = poptGetContext ( NULL , argc , ( const char * * ) argv , long_options ,
POPT_CONTEXT_KEEP_FIRST ) ;
while ( ( opt = poptGetNextOpt ( pc ) ) ! = - 1 ) {
2000-07-05 15:24:26 +04:00
switch ( opt ) {
case ' u ' :
if ( ! print_domain_users ( ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Error looking up domain users \n " ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' g ' :
if ( ! print_domain_groups ( ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Error looking up domain groups \n " ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' s ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_lookupsid ( string_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not lookup sid %s \n " , string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' n ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_lookupname ( string_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not lookup name %s \n " , string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
2002-03-29 18:37:39 +03:00
case ' N ' :
if ( ! wbinfo_wins_byname ( string_arg ) ) {
d_printf ( " Could not lookup WINS by name %s \n " , string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2002-03-29 18:37:39 +03:00
}
break ;
case ' I ' :
if ( ! wbinfo_wins_byip ( string_arg ) ) {
d_printf ( " Could not lookup WINS by IP %s \n " , string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2002-03-29 18:37:39 +03:00
}
break ;
2000-07-05 15:24:26 +04:00
case ' U ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_uid_to_sid ( int_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not convert uid %d to sid \n " , int_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' G ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_gid_to_sid ( int_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not convert gid %d to sid \n " ,
2001-12-11 08:18:36 +03:00
int_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' S ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_sid_to_uid ( string_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not convert sid %s to uid \n " ,
2001-12-11 08:18:36 +03:00
string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' Y ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_sid_to_gid ( string_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not convert sid %s to gid \n " ,
2001-12-11 08:18:36 +03:00
string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' t ' :
if ( ! wbinfo_check_secret ( ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not check secret \n " ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
case ' m ' :
if ( ! wbinfo_list_domains ( ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not list trusted domains \n " ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
break ;
2002-01-31 14:49:29 +03:00
case OPT_SEQUENCE :
if ( ! wbinfo_show_sequence ( ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not show sequence numbers \n " ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2002-01-31 14:49:29 +03:00
}
break ;
2000-10-11 09:25:32 +04:00
case ' r ' :
2001-12-11 08:18:36 +03:00
if ( ! wbinfo_get_usergroups ( string_arg ) ) {
2002-03-01 04:13:42 +03:00
d_printf ( " Could not get groups for user %s \n " ,
2001-12-11 08:18:36 +03:00
string_arg ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-10-11 09:25:32 +04:00
}
break ;
2002-10-29 20:36:50 +03:00
case ' a ' : {
2003-07-08 07:16:28 +04:00
BOOL got_error = False ;
if ( ! wbinfo_auth ( string_arg ) ) {
d_printf ( " Could not authenticate user %s with "
" plaintext password \n " , string_arg ) ;
got_error = True ;
}
if ( ! wbinfo_auth_crap ( string_arg ) ) {
d_printf ( " Could not authenticate user %s with "
" challenge/response \n " , string_arg ) ;
got_error = True ;
}
if ( got_error )
goto done ;
break ;
}
2003-07-09 20:44:47 +04:00
case ' c ' :
if ( ! wbinfo_create_user ( string_arg ) ) {
d_printf ( " Could not create user account \n " ) ;
goto done ;
}
break ;
case ' C ' :
if ( ! wbinfo_create_group ( string_arg ) ) {
d_printf ( " Could not create group \n " ) ;
goto done ;
}
break ;
case ' o ' :
if ( ! wbinfo_add_user_to_group ( string_arg ) ) {
d_printf ( " Could not add user to group \n " ) ;
goto done ;
}
break ;
case ' O ' :
if ( ! wbinfo_remove_user_from_group ( string_arg ) ) {
d_printf ( " Could not remove user kfrom group \n " ) ;
goto done ;
}
break ;
2003-07-11 09:33:40 +04:00
case ' x ' :
if ( ! wbinfo_delete_user ( string_arg ) ) {
d_printf ( " Could not delete user account \n " ) ;
goto done ;
}
break ;
case ' X ' :
if ( ! wbinfo_delete_group ( string_arg ) ) {
d_printf ( " Could not delete group \n " ) ;
goto done ;
}
break ;
2003-07-25 05:18:10 +04:00
case ' p ' :
2003-07-08 07:16:28 +04:00
if ( ! wbinfo_ping ( ) ) {
d_printf ( " could not ping winbindd! \n " ) ;
goto done ;
}
break ;
2001-12-11 08:18:36 +03:00
case OPT_SET_AUTH_USER :
2002-11-02 04:51:53 +03:00
wbinfo_set_auth_user ( string_arg ) ;
break ;
case OPT_GET_AUTH_USER :
wbinfo_get_auth_user ( ) ;
2001-12-11 08:18:36 +03:00
break ;
2000-07-05 15:24:26 +04:00
default :
2002-03-01 04:13:42 +03:00
d_fprintf ( stderr , " Invalid option \n " ) ;
2002-09-25 19:19:00 +04:00
poptPrintHelp ( pc , stderr , 0 ) ;
2002-04-04 10:40:17 +04:00
goto done ;
2000-07-05 15:24:26 +04:00
}
}
2001-12-11 08:18:36 +03:00
2002-04-04 10:40:17 +04:00
result = 0 ;
/* Exit code */
2000-07-05 15:24:26 +04:00
2002-04-04 10:40:17 +04:00
done :
poptFreeContext ( pc ) ;
return result ;
2000-07-05 15:24:26 +04:00
}