Stefan Metzmacher
35cd60b002
build with the new heimdal version
...
(This used to be commit 3817d653faecb70bfafb850fe7d6e83aaed7e6d1)
2008-08-01 16:11:00 +02:00
Stefan Metzmacher
a925f039ee
heimdal: update to lorikeet-heimdal rev 801
...
metze
(This used to be commit d6c54a66fb23c784ef221a3c1cf766b72bdb5a0b)
2008-08-01 16:11:00 +02:00
Stefan Metzmacher
cf875a5621
build: allow flex-2.34 together with bison-2.3
...
metze
(This used to be commit 8bd30a7b4392642ef5184f959d801716d2db20b2)
2008-08-01 16:10:59 +02:00
Stefan Metzmacher
d087545deb
auth/ntlmssp: don't crash when the backend give no challenge
...
metze
(This used to be commit c01fee80a79cd9e0f7bb295333bb03bd37328d05)
2008-08-01 16:10:59 +02:00
Stefan Metzmacher
f1cdce5963
auth_server: fix the logic of server_get_challenge()
...
metze
(This used to be commit 699e3cdb52acdf2524347d8c053730306c579dd9)
2008-08-01 15:54:57 +02:00
Stefan Metzmacher
5d68244a27
auth_server: fix segfault reported by Julien Kerihuel <j.kerihuel@openchange.org>
...
metze
(This used to be commit c2cc8ef943e8c2e02edb1eb20214de245cc6914c)
2008-08-01 15:22:25 +02:00
Stefan Metzmacher
7b4081da8f
Revert "Start implementind domain trusts in our KDC."
...
This reverts commit 736ce50afd9da9b5fbc3db777fd5341dfa4b721a.
This breaks the build...
metze
(This used to be commit afd07073b9caa4b5f7d2ad747e79afaec4203506)
2008-08-01 15:22:25 +02:00
Andrew Bartlett
43d2329da6
Update to a working trustAuthIncoming and trustAuthOutgoing parser.
...
This is based on the docs, as well as testing against a domain trust
in windows.
Clearly it needs to be more general - perhaps a non IDL parser?
Andrew Bartlett
(This used to be commit 816bb64a56a75d1eb5e879b4abf211af27243686)
2008-07-31 23:17:20 +10:00
Andrew Bartlett
358a11c6f3
Print trustAuthOutgoing and trustAuthIncoming in RPC-DSSYNC
...
(This used to be commit 6673a6e62399c4956a44a06685aa91ce8145b92a)
2008-07-31 21:23:48 +10:00
Andrew Bartlett
2cc32c4988
Use the cldap reply to avoid segfaulting in RPC-DSSYNC
...
Also don't fail the test if the server does not implement the NT4
changelog.
Andrew Bartlett
(This used to be commit 514d88580bee3bb17f1032262f5518e3ab2a349a)
2008-07-31 10:51:59 +10:00
Andrew Bartlett
2afd7d6d66
Don't fail if the domain has a trust already.
...
Andrew Bartlett
(This used to be commit c2df7ffa6d67dd9381d10397c679746547cd5e17)
2008-07-31 09:07:57 +10:00
Andrew Bartlett
337752cfd8
Merge branch 'v4-0-test' of ssh://git.samba.org/data/git/samba into 4-0-local
...
(This used to be commit 15d0951b74b46763024560f9cd012338473c5bc3)
2008-07-31 07:48:16 +10:00
Andrew Bartlett
2a0677e514
Start implementind domain trusts in our KDC.
...
Andrew Bartlett
(This used to be commit 736ce50afd9da9b5fbc3db777fd5341dfa4b721a)
2008-07-31 07:47:01 +10:00
Andrew Bartlett
2b0ed1832a
Update trustAuthInOutBlob in line with MS-ADTS 7.1.6.8.1
...
(This used to be commit 26c2a34dec26890230dfa86827804d8160061ce5)
2008-07-31 07:45:30 +10:00
Stefan Metzmacher
e45c3e127d
Revert "gensec_gssapi: use gsskrb5_get_subkey() to make smb2 signing with aes keys work"
...
This reverts commit 73964f069056f46f2f27fc690e42e5c91ae1fe19.
This breaks more than it gains:-( It seems to break the ncacn_np session key
metze
(This used to be commit 9678085f75b6cb0ed068e22f3d9f94247b200ce2)
2008-07-28 17:59:17 +02:00
Stefan Metzmacher
14900695da
rpc_server: remove unused variable
...
metze
(This used to be commit c2186d5d60aa2b57ecafaa57f9fd41f2a6717046)
2008-07-28 16:40:21 +02:00
Stefan Metzmacher
c4c79aa1b6
gensec_gssapi: use gsskrb5_get_subkey() to make smb2 signing with aes keys work
...
SMB signing with aes doesn't work, but still works with
arcfour-hmac-md5, des-cbc-md5 and des-cbc-crc.
metze
(This used to be commit 73964f069056f46f2f27fc690e42e5c91ae1fe19)
2008-07-28 16:15:23 +02:00
Stefan Metzmacher
2d2911c788
libcli/smb2: the session key for SMB2 signing is truncated to 16 bytes
...
To make that work (as a client) with aes128 and aes256 krb5 keys
we need to use gsskrb5_get_subkey().
metze
(This used to be commit 0c6d988f2083067e1ac7b07a492f88cefd3ba906)
2008-07-28 16:15:23 +02:00
Stefan Metzmacher
0251096a89
smb2srv: sign SMB2 Logoff replies
...
metze
(This used to be commit 2844e361730a6bc640ea89d0e10059deca1ca867)
2008-07-28 14:09:46 +02:00
Stefan Metzmacher
8623e2cc4c
smb2srv: correctly hold the signing state per session
...
metze
(This used to be commit 5b3ba3f3556e8031133128853cd2324ee3852aa1)
2008-07-28 14:09:45 +02:00
Stefan Metzmacher
35bd7a6378
libcli/smb2: fix per session signing state
...
metze
(This used to be commit 8bc12dc77a59e792830d96e84a4e8d1b2c651505)
2008-07-28 14:09:45 +02:00
Stefan Metzmacher
1a4f4d2cf0
SMB2-CONNECT: remove reference to req->session before calling smb2_logoff_recv() on the invalid session
...
metze
(This used to be commit 93203e8e318dd10b9e7096e586187eb271d42134)
2008-07-28 14:09:45 +02:00
Stefan Metzmacher
4355b31730
libcli/smb2: sign SMB2 Logoff requests
...
metze
(This used to be commit 35ee165b146b9157b0cff49e1139a0cb37d98926)
2008-07-28 14:09:45 +02:00
Andrew Bartlett
e80115deb9
We don't use EXTENSIBLEOBJECT any more.
...
(This used to be commit 4b137085c8b89773d4639372bbffd516a41dfc8f)
2008-07-28 20:51:02 +10:00
Andrew Bartlett
08795db6d6
Make it even clearer what to do next in the LDAP backend setup
...
(This used to be commit bace931ad674b5071d53bf9c99c383f1d8957e1b)
2008-07-28 20:26:14 +10:00
Andrew Bartlett
45d60f5bd9
Always print the slapd startup command
...
(This used to be commit b1d05e7d14c65133e8ab0ff9d41a26fa7e3d41d3)
2008-07-28 20:18:17 +10:00
Andrew Bartlett
ade9b6c455
Merge branch 'v4-0-test' of ssh://git.samba.org/data/git/samba into 4-0-abartlet
...
(This used to be commit 486891bb5167034e54b7477ba09e8f5f914b93e4)
2008-07-28 18:39:37 +10:00
Stefan Metzmacher
0299edbc02
auth/credentials: explain why we need to the enctypes for the gssapi layer
...
metze
(This used to be commit 88970c4d4192635544cf63e79e929e9bb05ecb5f)
2008-07-28 09:29:42 +02:00
Andrew Bartlett
da9ab5756e
Remove unused variable
...
(This used to be commit 31a303c099e26423160010c48b305434d4cbea25)
2008-07-28 08:04:43 +10:00
Andrew Bartlett
cff30c6da6
Remove unused function and make sensitive directories private.
...
(This used to be commit e23333d16397606d38e90684d2d916b5b967cde4)
2008-07-28 08:04:15 +10:00
Andrew Bartlett
5971fd6b9c
Fix warnings in new prefixMap code
...
(This used to be commit b8770a4fd8408473593fa4c6600bce056183958d)
2008-07-28 08:02:18 +10:00
Jelmer Vernooij
72d2bea916
Merge branch 'v4-0-test' of ssh://git.samba.org/data/git/samba into manpage
...
(This used to be commit 7e90cc197c4fb2884f368cd72f391d0d8016fb96)
2008-07-27 19:57:27 +02:00
Jelmer Vernooij
8d8ccc57e9
Fix location of manpages.
...
(This used to be commit 6f5b4ef1d0380d265ce27c882072c759ce19c7c3)
2008-07-27 19:56:20 +02:00
Stefan Metzmacher
55ea54ec64
gensec_gssapi: add support for signing RPC messages
...
metze
(This used to be commit dc2847c0acb0adaede4db72a7517046b93221162)
2008-07-26 21:48:32 +02:00
Stefan Metzmacher
9437adf68b
lib/ldb/tools: allow -W and --realm when build from samba4
...
metze
(This used to be commit 0aa6d63ec571b0ca05fbfe14d2b4e9ba3e1082e9)
2008-07-26 21:46:53 +02:00
Stefan Metzmacher
21592142c3
auth/credentials: use the same enctypes when getting a TGT and a TGS
...
metze
(This used to be commit 9fc5750156467f579ea8d7755987d091f5b579c2)
2008-07-26 21:46:43 +02:00
Stefan Metzmacher
c0ad44f354
dsdb: add a comment about the parameter to DSDB_EXTENDED_SCHEMA_UPDATE_NOW_OID
...
metze
(This used to be commit 2f06fbe06be2e1b77ea013ddba853ce819e58e88)
2008-07-26 21:45:29 +02:00
Stefan Metzmacher
2385e33095
dsdb/schema: make more clear where we create the value for the new prefix mapping
...
metze
(This used to be commit c92eb8b776c17f12622837daeb1786862f380269)
2008-07-26 21:45:22 +02:00
Stefan Metzmacher
118ecc54ba
dsdb/schema: dsdb_write_prefixes_to_ldb() should do the reverse of dsdb_read_prefixes_to_ldb()
...
metze
(This used to be commit 34ea9d4a0b1270a27412bf939d7e897a5d68d0a6)
2008-07-26 21:45:15 +02:00
Stefan Metzmacher
7a633ed96b
dcerpc.idl: add DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag
...
metze
(This used to be commit 131a1cfdc9a1228d9263c77bcd31b05d2946fd50)
2008-07-26 21:44:30 +02:00
Stefan Metzmacher
934cfb9880
mamachinepw: add better error handling
...
metze
(This used to be commit 7ac424137f62ceacf44e477f4e3805267013005b)
2008-07-26 20:45:47 +02:00
Volker Lendecke
998b0fef11
Add "mymachinepw" to fetch our machine password out of secrets.ldb
...
(This used to be commit 4fbe16deb0e06e145f643568a699b80b431d4f42)
2008-07-26 20:45:47 +02:00
Stefan Metzmacher
460356c976
smbtorture: add --extra-user option
...
This can we used to pass additional credentials to torture tests
(it can be used multiple times.
metze
(This used to be commit 4d80dbfac27659046e0986a2af3d06999e2cb2f2)
2008-07-26 20:11:09 +02:00
Brad Hards
a05c9ab939
Define HAVE_ASM_BYTEORDER at all times
...
(This used to be commit 396ea14732d667960091f4a2570341059914ecb6)
2008-07-25 17:43:21 +10:00
Andrew Bartlett
c09fa19d13
Per feedback, remove epoch and ldconfig requires.
...
See https://bugzilla.redhat.com/show_bug.cgi?id=453083
(This used to be commit 97d02730e8fde56de27aeb51612a4777c2953c9f)
2008-07-25 14:15:22 +10:00
Andrew Bartlett
552fd06ded
Make a new define to ensure the accoc_group_id we use is always in common.
...
(This used to be commit b62490e3e21b606b66e0737a403b0d170b64cddd)
2008-07-25 14:11:18 +10:00
Andrew Bartlett
1f285560bc
Merge branch 'v4-0-test' of ssh://git.samba.org/data/git/samba into 4-0-local
...
(This used to be commit b12dd8ee5443ebfc204d1684f541d68ffb351197)
2008-07-25 11:58:51 +10:00
Andrew Bartlett
404846d887
Try to avoid a memory leak if we re-set the global schema
...
However, try also not to pull a schema out from under a running ldb
session.
Andrew Bartlett
(This used to be commit 7cf9b9dd0bb35835a7c6e9897ea99951a33c63c7)
2008-07-25 11:58:24 +10:00
Andrew Bartlett
11798902dc
Complain if we are told to use an ldap backend, without the type
...
(This used to be commit e9c3c9ad8289ee48efa998ab6b486250dcd40b52)
2008-07-25 08:45:16 +10:00
Andrew Bartlett
d65f89f7b9
Clarify how we are doing the 'this is a rootdse query' check.
...
(This used to be commit 8dfba3160cc4bc518f3ad8570d104e5baae784ca)
2008-07-25 08:44:00 +10:00