1998-11-12 07:06:48 +00:00
/*
2002-01-30 06:08:46 +00:00
Unix SMB / CIFS implementation .
1998-11-12 07:06:48 +00:00
SMB client password change routine
Copyright ( C ) Andrew Tridgell 1994 - 1998
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-09 19:25:36 +00:00
the Free Software Foundation ; either version 3 of the License , or
1998-11-12 07:06:48 +00:00
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
2007-07-10 00:52:41 +00:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
1998-11-12 07:06:48 +00:00
*/
# include "includes.h"
/*************************************************************
2005-09-30 17:13:37 +00:00
Change a password on a remote machine using IPC calls .
1998-11-12 07:06:48 +00:00
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2005-09-30 17:13:37 +00:00
2006-02-03 22:19:41 +00:00
NTSTATUS remote_password_change ( const char * remote_machine , const char * user_name ,
2007-11-23 12:04:35 +01:00
const char * old_passwd , const char * new_passwd ,
char * * err_str )
1998-11-12 07:06:48 +00:00
{
struct nmb_name calling , called ;
2006-07-11 18:01:26 +00:00
struct cli_state * cli ;
2005-09-30 17:13:37 +00:00
struct rpc_pipe_client * pipe_hnd ;
2007-10-24 14:16:54 -07:00
struct sockaddr_storage ss ;
2004-01-26 08:45:02 +00:00
NTSTATUS result ;
2007-10-18 17:40:25 -07:00
bool pass_must_change = False ;
1998-11-12 07:06:48 +00:00
2007-11-23 12:04:35 +01:00
* err_str = NULL ;
1999-12-13 13:27:58 +00:00
2007-10-24 14:16:54 -07:00
if ( ! resolve_name ( remote_machine , & ss , 0x20 ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " Unable to find an IP address for machine "
" %s. \n " , remote_machine ) ;
2006-02-03 22:19:41 +00:00
return NT_STATUS_UNSUCCESSFUL ;
1998-11-12 07:06:48 +00:00
}
2006-07-11 18:01:26 +00:00
cli = cli_initialise ( ) ;
if ( ! cli ) {
return NT_STATUS_NO_MEMORY ;
}
2007-10-24 14:16:54 -07:00
result = cli_connect ( cli , remote_machine , & ss ) ;
2007-06-20 17:38:42 +00:00
if ( ! NT_STATUS_IS_OK ( result ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " Unable to connect to SMB server on "
" machine %s. Error was : %s. \n " ,
remote_machine , nt_errstr ( result ) ) ;
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
return result ;
1998-11-12 07:06:48 +00:00
}
2002-11-12 23:20:50 +00:00
make_nmb_name ( & calling , global_myname ( ) , 0x0 ) ;
2000-01-07 06:55:36 +00:00
make_nmb_name ( & called , remote_machine , 0x20 ) ;
1998-11-12 07:06:48 +00:00
2006-07-11 18:01:26 +00:00
if ( ! cli_session_request ( cli , & calling , & called ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the session setup. "
" Error was : %s. \n " ,
remote_machine , cli_errstr ( cli ) ) ;
2006-07-11 18:01:26 +00:00
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
return result ;
1998-11-12 07:06:48 +00:00
}
2006-07-11 18:01:26 +00:00
cli - > protocol = PROTOCOL_NT1 ;
1998-11-12 07:06:48 +00:00
2006-07-11 18:01:26 +00:00
if ( ! cli_negprot ( cli ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the negotiate "
" protocol. Error was : %s. \n " ,
remote_machine , cli_errstr ( cli ) ) ;
2006-07-11 18:01:26 +00:00
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
1998-11-12 07:06:48 +00:00
}
2004-01-26 08:45:02 +00:00
/* Given things like SMB signing, restrict anonymous and the like,
try an authenticated connection first */
2006-08-16 17:14:16 +00:00
result = cli_session_setup ( cli , user_name ,
old_passwd , strlen ( old_passwd ) + 1 ,
old_passwd , strlen ( old_passwd ) + 1 , " " ) ;
2006-01-28 22:49:25 +00:00
2006-08-16 17:14:16 +00:00
if ( ! NT_STATUS_IS_OK ( result ) ) {
2006-01-28 22:49:25 +00:00
2006-11-06 19:21:44 +00:00
/* Password must change or Password expired are the only valid
* error conditions here from where we can proceed , the rest like
* account locked out or logon failure will lead to errors later
* anyway */
2006-01-28 22:49:25 +00:00
2006-11-06 19:21:44 +00:00
if ( ! NT_STATUS_EQUAL ( result , NT_STATUS_PASSWORD_MUST_CHANGE ) & &
! NT_STATUS_EQUAL ( result , NT_STATUS_PASSWORD_EXPIRED ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " Could not connect to machine %s: "
" %s \n " , remote_machine , cli_errstr ( cli ) ) ;
2006-08-16 17:14:16 +00:00
cli_shutdown ( cli ) ;
return result ;
2006-01-28 22:49:25 +00:00
}
2006-08-16 17:14:16 +00:00
pass_must_change = True ;
2004-01-26 08:45:02 +00:00
/*
* We should connect as the anonymous user here , in case
* the server has " must change password " checked . . .
* Thanks to < Nicholas . S . Jenkins @ cdc . com > for this fix .
*/
1998-11-12 07:06:48 +00:00
2006-08-16 17:14:16 +00:00
result = cli_session_setup ( cli , " " , " " , 0 , " " , 0 , " " ) ;
if ( ! NT_STATUS_IS_OK ( result ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the session "
" setup. Error was : %s. \n " ,
2006-07-11 18:01:26 +00:00
remote_machine , cli_errstr ( cli ) ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-01-26 08:45:02 +00:00
}
2006-07-11 18:01:26 +00:00
cli_init_creds ( cli , " " , " " , NULL ) ;
2004-01-26 08:45:02 +00:00
} else {
2006-07-11 18:01:26 +00:00
cli_init_creds ( cli , user_name , " " , old_passwd ) ;
2004-01-26 08:45:02 +00:00
}
1998-11-12 07:06:48 +00:00
2006-07-11 18:01:26 +00:00
if ( ! cli_send_tconX ( cli , " IPC$ " , " IPC " , " " , 1 ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the tconX on the IPC$ "
" share. Error was : %s. \n " ,
remote_machine , cli_errstr ( cli ) ) ;
2006-07-11 18:01:26 +00:00
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
1998-11-12 07:06:48 +00:00
}
2005-09-30 17:13:37 +00:00
/* Try not to give the password away too easily */
2004-01-26 08:45:02 +00:00
2006-01-28 22:49:25 +00:00
if ( ! pass_must_change ) {
2006-07-11 18:01:26 +00:00
pipe_hnd = cli_rpc_pipe_open_ntlmssp ( cli ,
2005-09-30 17:13:37 +00:00
PI_SAMR ,
PIPE_AUTH_LEVEL_PRIVACY ,
" " , /* what domain... ? */
user_name ,
old_passwd ,
& result ) ;
2006-01-28 22:49:25 +00:00
} else {
/*
* If the user password must be changed the ntlmssp bind will
* fail the same way as the session setup above did . The
* difference ist that with a pipe bind we don ' t get a good
* error message , the result will be that the rpc call below
* will just fail . So we do it anonymously , there ' s no other
* way .
*/
2006-07-11 18:01:26 +00:00
pipe_hnd = cli_rpc_pipe_open_noauth ( cli , PI_SAMR , & result ) ;
2006-01-28 22:49:25 +00:00
}
2005-09-30 17:13:37 +00:00
if ( ! pipe_hnd ) {
2004-01-26 08:45:02 +00:00
if ( lp_client_lanman_auth ( ) ) {
2005-09-30 17:13:37 +00:00
/* Use the old RAP method. */
2006-07-11 18:01:26 +00:00
if ( ! cli_oem_change_password ( cli , user_name , new_passwd , old_passwd ) ) {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the "
" password change: Error was : %s. \n " ,
2006-07-11 18:01:26 +00:00
remote_machine , cli_errstr ( cli ) ) ;
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-01-26 08:45:02 +00:00
}
} else {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " SAMR connection to machine %s "
" failed. Error was %s, but LANMAN password "
" changed are disabled \n " ,
nt_errstr ( result ) , remote_machine ) ;
2006-07-11 18:01:26 +00:00
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-01-26 08:45:02 +00:00
}
}
2008-04-19 18:17:13 +02:00
result = rpccli_samr_chgpasswd_user ( pipe_hnd , talloc_tos ( ) ,
user_name , new_passwd , old_passwd ) ;
if ( NT_STATUS_IS_OK ( result ) ) {
2004-04-12 11:18:32 +00:00
/* Great - it all worked! */
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return NT_STATUS_OK ;
2004-04-12 11:18:32 +00:00
} else if ( ! ( NT_STATUS_EQUAL ( result , NT_STATUS_ACCESS_DENIED )
| | NT_STATUS_EQUAL ( result , NT_STATUS_UNSUCCESSFUL ) ) ) {
/* it failed, but for reasons such as wrong password, too short etc ... */
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the password change: "
" Error was : %s. \n " ,
2004-04-12 11:18:32 +00:00
remote_machine , get_friendly_nt_error_msg ( result ) ) ;
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-04-12 11:18:32 +00:00
}
/* OK, that failed, so try again... */
2008-04-20 13:51:46 +02:00
TALLOC_FREE ( pipe_hnd ) ;
2004-04-12 11:18:32 +00:00
/* Try anonymous NTLMSSP... */
2006-07-11 18:01:26 +00:00
cli_init_creds ( cli , " " , " " , NULL ) ;
2004-04-12 11:18:32 +00:00
result = NT_STATUS_UNSUCCESSFUL ;
2005-09-30 17:13:37 +00:00
/* OK, this is ugly, but... try an anonymous pipe. */
2006-07-11 18:01:26 +00:00
pipe_hnd = cli_rpc_pipe_open_noauth ( cli , PI_SAMR , & result ) ;
2005-09-30 17:13:37 +00:00
if ( pipe_hnd & &
2008-04-19 18:17:13 +02:00
( NT_STATUS_IS_OK ( result = rpccli_samr_chgpasswd_user (
pipe_hnd , talloc_tos ( ) , user_name ,
new_passwd , old_passwd ) ) ) ) {
2004-04-12 11:18:32 +00:00
/* Great - it all worked! */
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return NT_STATUS_OK ;
2004-04-12 11:18:32 +00:00
} else {
if ( ! ( NT_STATUS_EQUAL ( result , NT_STATUS_ACCESS_DENIED )
| | NT_STATUS_EQUAL ( result , NT_STATUS_UNSUCCESSFUL ) ) ) {
/* it failed, but again it was due to things like new password too short */
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the "
" (anonymous) password change: Error was : "
" %s. \n " , remote_machine ,
get_friendly_nt_error_msg ( result ) ) ;
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-04-12 11:18:32 +00:00
}
/* We have failed to change the user's password, and we think the server
just might not support SAMR password changes , so fall back */
if ( lp_client_lanman_auth ( ) ) {
2005-09-30 17:13:37 +00:00
/* Use the old RAP method. */
2006-07-11 18:01:26 +00:00
if ( cli_oem_change_password ( cli , user_name , new_passwd , old_passwd ) ) {
2004-04-12 11:18:32 +00:00
/* SAMR failed, but the old LanMan protocol worked! */
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return NT_STATUS_OK ;
2004-01-26 08:45:02 +00:00
}
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " machine %s rejected the password "
" change: Error was : %s. \n " ,
2006-07-11 18:01:26 +00:00
remote_machine , cli_errstr ( cli ) ) ;
result = cli_nt_error ( cli ) ;
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return result ;
2004-01-26 08:45:02 +00:00
} else {
2007-11-23 12:04:35 +01:00
asprintf ( err_str , " SAMR connection to machine %s "
" failed. Error was %s, but LANMAN password "
" changed are disabled \n " ,
2005-09-30 17:13:37 +00:00
nt_errstr ( result ) , remote_machine ) ;
2006-07-11 18:01:26 +00:00
cli_shutdown ( cli ) ;
2006-02-03 22:19:41 +00:00
return NT_STATUS_UNSUCCESSFUL ;
2004-01-26 08:45:02 +00:00
}
}
1998-11-12 07:06:48 +00:00
}