mirror of
https://github.com/samba-team/samba.git
synced 2024-12-22 13:34:15 +03:00
tests/krb5: Don’t expect groups if we’re expecting an error
Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
This commit is contained in:
parent
a8a186868e
commit
1712449aa6
@ -2396,7 +2396,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
|
|
||||||
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2412,7 +2411,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2428,7 +2426,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
self._tgs(f'Member_of SID({self.aa_asserted_identity})',
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2445,7 +2442,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2510,7 +2506,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
|
|
||||||
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2526,7 +2521,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2542,7 +2536,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
self._tgs(f'Member_of SID({self.service_asserted_identity})',
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2559,7 +2552,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2624,7 +2616,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
|
|
||||||
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2640,7 +2631,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=KDC_ERR_POLICY,
|
code=KDC_ERR_POLICY,
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2656,7 +2646,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
self._tgs(f'Member_of SID({security.SID_CLAIMS_VALID})',
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
@ -2673,7 +2662,6 @@ class ConditionalAceTests(ConditionalAceBaseTests):
|
|||||||
client_from_rodc=True,
|
client_from_rodc=True,
|
||||||
device_from_rodc=True,
|
device_from_rodc=True,
|
||||||
client_sids=client_sids,
|
client_sids=client_sids,
|
||||||
expected_groups=client_sids,
|
|
||||||
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
code=(KDC_ERR_POLICY, CRASHES_WINDOWS),
|
||||||
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
status=ntstatus.NT_STATUS_AUTHENTICATION_FIREWALL_FAILED,
|
||||||
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
event=AuditEvent.KERBEROS_SERVER_RESTRICTION,
|
||||||
|
Loading…
Reference in New Issue
Block a user