1
0
mirror of https://github.com/samba-team/samba.git synced 2025-11-26 04:23:49 +03:00
Commit Graph

135 Commits

Author SHA1 Message Date
Jelmer Vernooij
3fd750bd54 idl: Use typedef rather than declare. 2008-01-12 01:18:53 +01:00
Jelmer Vernooij
6ac86f8be7 r26540: Revert my previous commit after concerns raised by Andrew. 2007-12-21 05:52:06 +01:00
Jelmer Vernooij
e53e79eebe r26539: Remove unnecessary statics. 2007-12-21 05:52:05 +01:00
Jelmer Vernooij
9d806da113 r26310: Remove more uses of global_loadparm. 2007-12-21 05:48:22 +01:00
Stefan Metzmacher
c2c2c991c7 r25738: always include config.h first.
this needs merging to heimdal and lorikeet-heimdal

metze
2007-12-21 05:43:36 +01:00
Stefan Metzmacher
cb3aec0d22 r25734: regenerate yacc output (parse.[ch] files)
metze
2007-12-21 05:43:34 +01:00
Stefan Metzmacher
9735715a0f r25732: import updated parse.y files from lorikeet-heimdal
I wonder why they're not updated as the parse.[ch]
are generated from the new versions already...

metze
2007-12-21 05:43:32 +01:00
Stefan Metzmacher
bfd8c275bb r25298: regenerate lex.c files with config.h as first include
this should help on aix 5.3.

metze
2007-10-10 15:07:08 -05:00
Andrew Bartlett
30e02747d5 r24614: Merge with current lorikeet-heimdal. This brings us one step closer
to an alpha release.

Andrew Bartlett
2007-10-10 15:02:25 -05:00
Stefan Metzmacher
8da4e9a9ac r23895: reapply rev 23493:
regenerate lex.c files with flex 2.5.33
this makes sure we include config.h as first header

hopefully fixes the build on SerNet-aix

abartlet: please don't revert that again with your next
          heimdal merge...:-)

metze
2007-10-10 15:01:08 -05:00
Andrew Tridgell
db92b76a00 r23799: updated old Franklin Street FSF addresses to new URL 2007-10-10 14:59:16 -05:00
Andrew Bartlett
14a4ddb131 r23678: Update to current lorikeet-heimdal (-r 767), which should fix the
panics on hosts without /dev/random.

Andrew Bartlett
2007-10-10 14:58:59 -05:00
Stefan Metzmacher
0149226ece r23493: regenerate lex.c files with flex 2.5.33
this makes sure we include config.h as first header

hopefully fixes the build on SerNet-aix

metze
2007-10-10 14:53:22 -05:00
Andrew Bartlett
ae0f81ab23 r23456: Update Samba4 to current lorikeet-heimdal.
Andrew Bartlett
2007-10-10 14:53:18 -05:00
Stefan Metzmacher
48eb20199e r23209: import getnameinfo.c, inet_ntop.c and inet_pton.c from
loikeet-heimdal

metze
2007-10-10 14:53:04 -05:00
Andrew Tridgell
59cd26b664 r23060: use #include <roken.h> consistently. Using "roken.h" in this directory
breaks Samba builds on some systems as they find the wrong roken.h
2007-10-10 14:52:46 -05:00
Andrew Bartlett
440b8d9e4b r22191: Add a samba4kinit binary to the build, so I can test using an existing
ccache, as well as PKINIT.

Andrew Bartlett
2007-10-10 14:50:02 -05:00
Andrew Bartlett
123ae858c7 r21746: We don't link in this file any more. 2007-10-10 14:49:23 -05:00
Andrew Tridgell
2694bfb143 r21620: commit updated versions (with correct paths) 2007-10-10 14:49:03 -05:00
Stefan Metzmacher
e4d69b83dc r21448: return the same error codes as a windows KDC
metze
2007-10-10 14:48:37 -05:00
Stefan Metzmacher
3e4ff2de9c r21447: make handling of replying e_data more generic
love: please merge this

metze
2007-10-10 14:48:37 -05:00
Stefan Metzmacher
ac347d7aa5 r21439: fix compiler warnings
metze
2007-10-10 14:48:35 -05:00
Stefan Metzmacher
b64abf9113 r21438: create the PAC element in the same order as w2k3,
maybe there's some broken code in windows which relies
on this...

love: can you merge this to heimdal?

metze
2007-10-10 14:48:35 -05:00
Stefan Metzmacher
5840f50d89 r21436: Choose the TGT session key enctype also by checking what enctypes
the krbtgt hdb entry provides.

We need to make sure other KDC's with the same hdb backend data
can accept the TGT. (w2k and w2k3 don't support aes256-cts-hmac-sha1-96 (18)
session keys.)

Love: I'm not sure if this is the correct way of doing it...

metze
2007-10-10 14:48:34 -05:00
Andrew Bartlett
a50bbde81b r20988: Call out to Heimdal's krb5.conf processing to configure many aspects
of KDC behaviour.  This should allow PKINIT to be turned on and
managed with reasonable sanity.

This also means that the krb5.conf in the same directory as the
smb.conf will always have priority in Samba4, which I think will be
useful.

Andrew Bartlett
2007-10-10 14:44:18 -05:00
Jelmer Vernooij
42bb335bd5 r20786: Fix the build. 2007-10-10 14:40:55 -05:00
Andrew Tridgell
b3e2d49087 r20650: revert a bunch of code I didn't mean to commit yet 2007-10-10 14:37:26 -05:00
Andrew Bartlett
a4051a2d65 r20648: Closer to a build... Add missing header file. 2007-10-10 14:37:24 -05:00
Andrew Tridgell
5870830b99 r20647: add cluster code 2007-10-10 14:37:24 -05:00
Andrew Bartlett
12953ee765 r20643: Remove generated files accidentilly committed.
Andrew Bartlett
2007-10-10 14:37:23 -05:00
Andrew Bartlett
9e7124cc85 r20642: This bit of autoconf causes us pain. Revert back to how we had things
before the last merge.

Andrew Bartlett
2007-10-10 14:37:22 -05:00
Andrew Bartlett
351f7040f7 r20640: Commit part 2/2
Update Heimdal to match current lorikeet-heimdal.  This includes
integrated PAC hooks, so Samba doesn't have to handle this any more.

This also brings in the PKINIT code, hence so many new files.

Andrew Bartlett
2007-10-10 14:37:20 -05:00
Stefan Metzmacher
75c037cae2 r20139: only add GSS_C_CONF_FLAG and GSS_C_INTEG_FLAG if the caller requested it!
this is needed to create plain, singed or sealed LDAP connections.

this should go into lorikeet and main heimdal...

metze
2007-10-10 14:29:13 -05:00
Andrew Bartlett
05421f45ed r19681: Update to current lorikeet-heimdal. I'm looking at using the realm
lookup plugin, the new PAC validation code as well as Heimdal's SPNEGO
implementation.

Andrew Bartlett
2007-10-10 14:25:31 -05:00
Stefan Metzmacher
dcec6eebf1 r19663: merge changes from lorikeet heimdal:
support for netbios domain based realms

metze
2007-10-10 14:25:26 -05:00
Andrew Bartlett
476452e143 r19650: Allow Samba to use Heimdal's SPNEGO code. Currently this can only
negotiate krb5, but if this works, I'll add NTLM as a GSSAPI backend
by some means or other.

Andrew Bartlett
2007-10-10 14:25:25 -05:00
Andrew Bartlett
8117e76d2a r19644: Merge up to current lorikeet-heimdal, incling adding
gsskrb5_set_default_realm(), which should fix mimir's issues.

Andrew Bartlett
2007-10-10 14:25:24 -05:00
Andrew Bartlett
13c9df1d4f r19633: Merge to lorikeet-heimdal, removing krb5_rd_req_return_keyblock in favour of a more tasteful replacement.
Remove kerberos_verify.c, as we don't need that code any more.
Replace with code for using the new krb5_rd_req_ctx() borrowed from
Heimdal's accecpt_sec_context.c

Andrew Bartlett
2007-10-10 14:25:21 -05:00
Andrew Bartlett
12dc157dae r19632: This got missed in the heimdal merge. Without this, we don't keep the
full database name.  The existing code (needed for when we use the HDB
as a keytab, such as for the kpasswd service) only works for HDB
keytabs not prefixed with a type.

Andrew Bartlett
2007-10-10 14:25:21 -05:00
Stefan Metzmacher
0a52e11a9c r19616: the heimdal spnego mech doesn't seem to use roken.h and isn't portable
(it doesn't compile on suse 10.1 because gethostname() isn't found,
 unistd.h isn't included...)

as we don't need the spnego mech, disable it till it gets fixed in heimdal

metze
2007-10-10 14:25:06 -05:00
Stefan Metzmacher
497543a17e r19615: include roken.h.in as this still includes the ifdef's we need in samba4
this should fix the portability of samba4

metze
2007-10-10 14:25:06 -05:00
Stefan Metzmacher
bec1783c4c r19613: remove diff between samba4 and lorikeet
metze
2007-10-10 14:25:05 -05:00
Stefan Metzmacher
704fe73940 r19612: fix the build with auto dependencies
the samba4 heimdal copy should do not need to use socket_wrapper

metze
2007-10-10 14:25:05 -05:00
Andrew Bartlett
7b7e1fe153 r19606: Remove generated files
Andrew Bartlett
2007-10-10 14:25:03 -05:00
Andrew Bartlett
4826f17351 r19604: This is a massive commit, and I appologise in advance for it's size.
This merges Samba4 with lorikeet-heimdal, which itself has been
tracking Heimdal CVS for the past couple of weeks.

This is such a big change because Heimdal reorganised it's internal
structures, with the mechglue merge, and because many of our 'wishes' have been granted:  we now have DCE_STYLE GSSAPI, send_to_kdc hooks and many other features merged into the mainline code.  We have adapted to upstream's choice of API in these cases.

In gensec_gssapi and gensec_krb5, we either expect a valid PAC, or NO
PAC.  This matches windows behavour.  We also have an option to
require the PAC to be present (which allows us to automate the testing
of this code).

This also includes a restructure of how the kerberos dependencies are
handled, due to the fallout of the merge.

Andrew Bartlett
2007-10-10 14:25:03 -05:00
Andrew Tridgell
248f3265e6 r19325: leak fix from lha 2007-10-10 14:21:09 -05:00
Andrew Bartlett
90b01b8af2 r18826: Allow 'enterprise' principal names to log in.
These principals do not need to be in the same realm as the rest of
the ticket, the full principal name is in the first componet of the
ASN.1.

Samba4's backend will handle getting this to the 'right' place.

Andrew Bartlett
2007-10-10 14:19:14 -05:00
Andrew Tridgell
95455b5789 r18528: work around what appears to be a compiler bug in gcc on irix. It
caused the RPC-SECRETS test to crash smbd in an inlined version of
this memcmp() call. This patch should have absolutely no effect at
all, but in fact it prevents the crash.

Disassembling at the point of the crash, it shows that gcc is inlining
the memcmp(). I don't know enough MIPS assembler to actually spot the
bug. In case anyone reading this does know MIPS assembler, here is the
gcc generated code that crashes:

0x105e0218 <gssapi_krb5_verify_header+168>:     lw      $t1,52($sp)
0x105e021c <gssapi_krb5_verify_header+172>:     lw      $t1,0($t1)
0x105e0220 <gssapi_krb5_verify_header+176>:     lhu     $t1,0($t1)
0x105e0224 <gssapi_krb5_verify_header+180>:     lw      $t2,68($sp)
0x105e0228 <gssapi_krb5_verify_header+184>:     lhu     $t2,0($t2)
0x105e022c <gssapi_krb5_verify_header+188>:     subu    $t1,$t1,$t2

it gets a segv at 0x105e0220.

lha, what do you think of this? The change should be innocuous on all
other platforms, apart from making the code harder to read :(
2007-10-10 14:18:42 -05:00
Andrew Tridgell
9034238e27 r18322: fixed a compilation problem on AIX caused by lex not putting config.h
first. That leads to a conflicting define for lseek() due to
_LARGE_FILES being defined after standards headers are included
2007-10-10 14:18:08 -05:00
Andrew Tridgell
3697cd6597 r18308: get this right .... 2007-10-10 14:18:06 -05:00