Matthieu Patou
2cadfe8f2a
unit tests: debug to ease locating pb, remove dir if exists to avoid error
2010-08-19 15:59:05 +04:00
Matthias Dieter Wallnöfer
bbb9dc806e
s4:DSDB - rename the "DSDB_CONTROL_PASSWORD_CHANGE_OLD_PW_CHECKED_OID"
...
Rename it to "DSDB_CONTROL_PASSWORD_CHANGE_OID". This control will afterwards
contain a record with the specified old password as NT and/or LM hash.
2010-08-17 18:45:32 +02:00
Stefan Metzmacher
76e5d41d6a
s4:blackbox/newuser: use test specific user names
...
As this test doesn't delete the user accounts at the end,
we should use test specific user names. That lowers the
chance of conflicts with other tests.
metze
2010-07-31 11:35:31 +02:00
Matthieu Patou
d861ebbd81
s4 dsdb: create a new control: changereplmetadata
...
This control is designed to allow replmetadata to be specified
Signed-off-by: Andrew Bartlett <abartlet@samba.org>
2010-07-15 22:08:20 +10:00
Stefan Metzmacher
23f810041b
s4:provision: remove --policy-guid and --policy-guid-dc cmdline options
...
metze
2010-07-10 11:18:19 +02:00
Matthieu Patou
e962e7e956
s4 unittests: remove the provision directory before (re)generating
2010-07-10 11:18:18 +02:00
Matthieu Patou
cad04dabbb
s4 net: Add spn module to list/add/remove spn on objects
...
Signed-off-by: Stefan Metzmacher <metze@samba.org>
2010-07-10 11:18:17 +02:00
Stefan Metzmacher
6d7b9648e5
s4:dsdb: allocate DSDB_CONTROL_BYPASS_PASSWORD_HASH_OID
...
When importing users from Samba3 we need to control all values.
metze
2010-07-05 18:00:14 +02:00
Matthias Dieter Wallnöfer
43b0c314d8
s4:setup/provision_basedn_modify.ldif - set "minPwdAge" to the right value
...
Now we should have fixed all password related tests to cooperate with this value
2010-07-03 11:38:54 +02:00
Stefan Metzmacher
50da834f13
s4:provision: add entries for root dns servers
...
metze
2010-06-26 09:50:56 +02:00
Stefan Metzmacher
6ab234cec9
s4:provision: move Samba4 specific DNS stuff to its own file
...
metze
2010-06-26 09:50:56 +02:00
Stefan Metzmacher
c6b21931c6
s4:provision: add --next-rid option
...
Make it possible to provision a domain with a given next rid counter.
This will be useful for upgrades, where we want to import users
with already given SIDs.
metze
2010-06-26 09:50:55 +02:00
Stefan Metzmacher
712a149802
s4:provision: don't use hardcoded values for 'nextRid' and 'rIDAvailablePool'
...
On Windows dcpromo imports nextRid from the local SAM,
which means it's not hardcoded to 1000.
The initlal rIDAvailablePool starts at nextRid + 100.
I also found that the RID Set of the local dc
should be created via provision and not at runtime,
when the first rid is needed.
(Tested with dcpromo on w2k8r2, while disabling the DNS
check box).
After provision we should have this (assuming nextRid=1000):
rIDAllocationPool: 1100-1599
rIDPrevAllocationPool: 1100-1599
rIDUsedPool: 0
rIDNextRID: 1100
rIDAvailablePool: 1600-1073741823
Because provision sets rIDNextRid=1100, the first created account
(typically DNS related accounts) will get 1101 as rid!
metze
2010-06-26 09:50:54 +02:00
Matthias Dieter Wallnöfer
8ad01613f6
Revert "s4:provision.ldif - fix the number of available RIDs"
...
This reverts commit 41cdcd54b7b7e3fb70fdb220e74a1daf30e1891a.
As per request of metze revert this (cause written on the mailing list).
2010-06-24 15:13:40 +02:00
Matthias Dieter Wallnöfer
41cdcd54b7
s4:provision.ldif - fix the number of available RIDs
...
There should be 4611686014132422209 and not 4611686014132422109.
2010-06-24 10:04:53 +02:00
Matthias Dieter Wallnöfer
fec489bd87
s4:provision.ldif - this Win2003 revision level seems always to be "9" on Windows Server 2008 machines
2010-06-24 10:04:53 +02:00
Matthias Dieter Wallnöfer
64e19ef9fb
s4:provision_users.ldif - change a group description to be correct
2010-06-24 10:04:52 +02:00
Matthias Dieter Wallnöfer
e88f37daa0
s4:setup/provision.reg - raise version to Windows Server 2008 R2
2010-06-24 10:04:50 +02:00
Jelmer Vernooij
237ab66f6c
selftest: Use scripted testparm.
2010-06-20 14:14:47 +02:00
Lukasz Zalewski
e55c012acc
make test modules for net group set of commands and modification to the newuser to include additional parameters
...
Signed-off-by: Jelmer Vernooij <jelmer@samba.org>
2010-06-20 01:29:03 +02:00
Matthieu Patou
3ebe560622
ldb: add a new control bypassioperationnal
...
Signed-off-by: Jelmer Vernooij <jelmer@samba.org>
2010-06-20 00:43:08 +02:00
Andrew Bartlett
d523e946b1
s4:provision Add import for DS_DOMAIN_FUNCTION_2000
2010-06-16 09:57:51 +10:00
Andrew Bartlett
814cb8895d
s4:provision Allow functional level 2000 to be chosen
2010-06-16 09:57:51 +10:00
Andrew Bartlett
ecfce7365c
s4:dsdb Add control for signaling between repl_meta_data and linked_attributes
...
This control will allow the linked_attributes module to know if
repl_meta_data has already handled the creation of forward and back
links.
Andrew Bartlett
2010-06-16 09:57:51 +10:00
Andrew Kroeger
352fb5c7e4
s4:provision: Make gc._msdcs DNS entries A/AAAA records
...
When adding an additional DC as a GC server, the new DC attempts to register its
own gc._msdcs records. If the existing gc._msdcs record is a CNAME, BIND fails
the update with the message "attempt to add non-CNAME alongside CNAME ignored",
and the new DC is not registered as a GC server.
The A & AAAA record types for gc._msdcs have been verified against the DNS
server of a W2K8 DC.
2010-06-14 12:14:46 +02:00
Matthias Dieter Wallnöfer
4b6ce8efc0
s4:fix allocated control OIDs for "password_hash" LDB module
...
The password hash module controls overlapped others. Sorry, but the
"schema_samba4.ldif" hasn't been kept up-to-date.
2010-06-13 18:35:19 +02:00
Jelmer Vernooij
74ed48aa1c
Friendlier message.
2010-06-13 18:19:03 +02:00
Jelmer Vernooij
d9d0d54475
upgradeprovision: Use logging infrastructure.
2010-06-13 18:19:03 +02:00
Jelmer Vernooij
956a256faa
s4-python: Start using standard python logging infrastructure rather
...
than simple messaging callbacks.
2010-06-13 18:19:03 +02:00
Matthias Dieter Wallnöfer
b8ea2e0757
s4:provision - fix typo in substitution variable
2010-06-06 20:42:19 +02:00
Matthias Dieter Wallnöfer
40ced1a3be
s4:setup/*.ldif - remove unneeded "cn" attributes
...
Should be generated automatically
2010-05-24 14:01:05 +02:00
Matthias Dieter Wallnöfer
38e9a7f577
s4:domain functional level - it is also specified in the domain object under partitions
...
Discovered by the "ldapcmp" tool
2010-05-13 15:14:06 +02:00
Matthias Dieter Wallnöfer
92aa194145
s4:provision_configuration.ldif - add more extended rights objects
2010-05-13 15:06:35 +02:00
Matthias Dieter Wallnöfer
9005227e72
s4:provision_users.ldif - fix up and reorder the well-known security principals
2010-05-13 14:51:10 +02:00
Matthias Dieter Wallnöfer
c715f6d3f9
s4:provision_configuration.ldif - add more Windows 2008 forest operations
2010-05-13 14:47:32 +02:00
Matthias Dieter Wallnöfer
eaea676916
s4:provision_configuration.ldif - the revision level of "Windows2003Update" should obviously be 10
...
Compared against my Windows Server 2008 and Zahari's output.
2010-05-13 14:47:31 +02:00
Matthias Dieter Wallnöfer
025eaceb5c
s4:provision_configuration.ldif - "CN=94fdebc6-8eeb-4640-80de-ec52b9ca17fa" operation is of version 3
2010-05-13 14:47:30 +02:00
Matthias Dieter Wallnöfer
47818b19fc
s4:provision*.ldif - always set the "msDS-NcType" attribute correctly
2010-05-13 14:47:30 +02:00
Matthias Dieter Wallnöfer
1885327b30
s4:provision_configuration.ldif - set the right schedule on the default site in the NTDS site settings
2010-05-13 14:47:29 +02:00
Matthias Dieter Wallnöfer
8acd8b97a6
s4:provision_configuration.ldif - The "NTDS Quotas" object is system-critical
2010-05-13 14:47:29 +02:00
Matthias Dieter Wallnöfer
79ac53eb3b
s4:provision_configuration.ldif - "sites" object
...
- The default site doesn't contain a licensing object
- Adequate two other values (a "showInAdvancedViewOnly" and a "systemFlags" one)
2010-05-13 14:10:02 +02:00
Matthias Dieter Wallnöfer
f57bcc92b5
s4:provision.ldif - add IP security objects as they exist on Windows Server
2010-05-13 13:03:47 +02:00
Matthias Dieter Wallnöfer
44e05dfb73
s4:provision.ldif - add more Windows 2008 domain operations
2010-05-13 13:03:46 +02:00
Matthias Dieter Wallnöfer
cc2bd1f777
s4:provision_users.ldif - On Windows Server >= 2008 security principal S-1-5-20 doesn't exist anymore
2010-05-13 13:03:45 +02:00
Matthias Dieter Wallnöfer
350c61922e
s4:provision.ldif - "passwordSettingsContainer" add "showInAdvancedViewOnly"
2010-05-13 13:03:44 +02:00
Matthias Dieter Wallnöfer
bbb5825a6f
s4:provision.ldif - fix up "NTDS Quotas" "systemFlags"
2010-05-13 13:03:43 +02:00
Matthias Dieter Wallnöfer
b2bd02e11e
s4:provision_users.ldif - fix up Administrator's "userAccountControl"
2010-05-13 13:03:43 +02:00
Matthias Dieter Wallnöfer
8c796715c1
s4:provision_basedn_modify.ldif - fix up "maxPwdAge"
2010-05-13 13:03:31 +02:00
Matthias Dieter Wallnöfer
5e4d91f7aa
s4:provision_users.ldif - Fix typos in user/group objects
2010-05-13 11:17:52 +02:00
Matthias Dieter Wallnöfer
726fb35f9f
s4:dsdb: add new controls
...
- Add a new control for getting status informations (domain informations,
password change status) directly from the module
- Add a new control for allowing direct hash changes
- Introduce an addtional control "change_old password checked" for the password
2010-05-10 17:54:15 +02:00