mirror of
https://github.com/samba-team/samba.git
synced 2025-02-26 21:57:41 +03:00
winbind: check for allowed domains in winbindd_pam_auth_pac_verify()
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14602 Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
This commit is contained in:
parent
88e92faace
commit
da474ddd13
@ -1,2 +0,0 @@
|
||||
^samba3.blackbox.winbind_ignore_domain.test_winbind_ignore_domains_fail_ntlm_fqdn\(ad_member_idmap_ad:local\)
|
||||
^samba3.blackbox.winbind_ignore_domain.test_winbind_ignore_domains_fail_krb5\(ad_member_idmap_ad:local\)
|
@ -3325,6 +3325,14 @@ NTSTATUS winbindd_pam_auth_pac_verify(struct winbindd_cli_state *state,
|
||||
return result;
|
||||
}
|
||||
|
||||
if (!is_allowed_domain(info6->base.logon_domain.string)) {
|
||||
DBG_NOTICE("Authentication failed for user [%s] "
|
||||
"from firewalled domain [%s]\n",
|
||||
info6->base.account_name.string,
|
||||
info6->base.logon_domain.string);
|
||||
return NT_STATUS_AUTHENTICATION_FIREWALL_FAILED;
|
||||
}
|
||||
|
||||
result = map_info6_to_validation(state->mem_ctx,
|
||||
info6,
|
||||
&validation_level,
|
||||
|
Loading…
x
Reference in New Issue
Block a user