Andrew Bartlett
d523e946b1
s4:provision Add import for DS_DOMAIN_FUNCTION_2000
2010-06-16 09:57:51 +10:00
Andrew Bartlett
814cb8895d
s4:provision Allow functional level 2000 to be chosen
2010-06-16 09:57:51 +10:00
Andrew Bartlett
ecfce7365c
s4:dsdb Add control for signaling between repl_meta_data and linked_attributes
...
This control will allow the linked_attributes module to know if
repl_meta_data has already handled the creation of forward and back
links.
Andrew Bartlett
2010-06-16 09:57:51 +10:00
Andrew Kroeger
352fb5c7e4
s4:provision: Make gc._msdcs DNS entries A/AAAA records
...
When adding an additional DC as a GC server, the new DC attempts to register its
own gc._msdcs records. If the existing gc._msdcs record is a CNAME, BIND fails
the update with the message "attempt to add non-CNAME alongside CNAME ignored",
and the new DC is not registered as a GC server.
The A & AAAA record types for gc._msdcs have been verified against the DNS
server of a W2K8 DC.
2010-06-14 12:14:46 +02:00
Matthias Dieter Wallnöfer
4b6ce8efc0
s4:fix allocated control OIDs for "password_hash" LDB module
...
The password hash module controls overlapped others. Sorry, but the
"schema_samba4.ldif" hasn't been kept up-to-date.
2010-06-13 18:35:19 +02:00
Jelmer Vernooij
74ed48aa1c
Friendlier message.
2010-06-13 18:19:03 +02:00
Jelmer Vernooij
d9d0d54475
upgradeprovision: Use logging infrastructure.
2010-06-13 18:19:03 +02:00
Jelmer Vernooij
956a256faa
s4-python: Start using standard python logging infrastructure rather
...
than simple messaging callbacks.
2010-06-13 18:19:03 +02:00
Matthias Dieter Wallnöfer
b8ea2e0757
s4:provision - fix typo in substitution variable
2010-06-06 20:42:19 +02:00
Matthias Dieter Wallnöfer
40ced1a3be
s4:setup/*.ldif - remove unneeded "cn" attributes
...
Should be generated automatically
2010-05-24 14:01:05 +02:00
Matthias Dieter Wallnöfer
38e9a7f577
s4:domain functional level - it is also specified in the domain object under partitions
...
Discovered by the "ldapcmp" tool
2010-05-13 15:14:06 +02:00
Matthias Dieter Wallnöfer
92aa194145
s4:provision_configuration.ldif - add more extended rights objects
2010-05-13 15:06:35 +02:00
Matthias Dieter Wallnöfer
9005227e72
s4:provision_users.ldif - fix up and reorder the well-known security principals
2010-05-13 14:51:10 +02:00
Matthias Dieter Wallnöfer
c715f6d3f9
s4:provision_configuration.ldif - add more Windows 2008 forest operations
2010-05-13 14:47:32 +02:00
Matthias Dieter Wallnöfer
eaea676916
s4:provision_configuration.ldif - the revision level of "Windows2003Update" should obviously be 10
...
Compared against my Windows Server 2008 and Zahari's output.
2010-05-13 14:47:31 +02:00
Matthias Dieter Wallnöfer
025eaceb5c
s4:provision_configuration.ldif - "CN=94fdebc6-8eeb-4640-80de-ec52b9ca17fa" operation is of version 3
2010-05-13 14:47:30 +02:00
Matthias Dieter Wallnöfer
47818b19fc
s4:provision*.ldif - always set the "msDS-NcType" attribute correctly
2010-05-13 14:47:30 +02:00
Matthias Dieter Wallnöfer
1885327b30
s4:provision_configuration.ldif - set the right schedule on the default site in the NTDS site settings
2010-05-13 14:47:29 +02:00
Matthias Dieter Wallnöfer
8acd8b97a6
s4:provision_configuration.ldif - The "NTDS Quotas" object is system-critical
2010-05-13 14:47:29 +02:00
Matthias Dieter Wallnöfer
79ac53eb3b
s4:provision_configuration.ldif - "sites" object
...
- The default site doesn't contain a licensing object
- Adequate two other values (a "showInAdvancedViewOnly" and a "systemFlags" one)
2010-05-13 14:10:02 +02:00
Matthias Dieter Wallnöfer
f57bcc92b5
s4:provision.ldif - add IP security objects as they exist on Windows Server
2010-05-13 13:03:47 +02:00
Matthias Dieter Wallnöfer
44e05dfb73
s4:provision.ldif - add more Windows 2008 domain operations
2010-05-13 13:03:46 +02:00
Matthias Dieter Wallnöfer
cc2bd1f777
s4:provision_users.ldif - On Windows Server >= 2008 security principal S-1-5-20 doesn't exist anymore
2010-05-13 13:03:45 +02:00
Matthias Dieter Wallnöfer
350c61922e
s4:provision.ldif - "passwordSettingsContainer" add "showInAdvancedViewOnly"
2010-05-13 13:03:44 +02:00
Matthias Dieter Wallnöfer
bbb5825a6f
s4:provision.ldif - fix up "NTDS Quotas" "systemFlags"
2010-05-13 13:03:43 +02:00
Matthias Dieter Wallnöfer
b2bd02e11e
s4:provision_users.ldif - fix up Administrator's "userAccountControl"
2010-05-13 13:03:43 +02:00
Matthias Dieter Wallnöfer
8c796715c1
s4:provision_basedn_modify.ldif - fix up "maxPwdAge"
2010-05-13 13:03:31 +02:00
Matthias Dieter Wallnöfer
5e4d91f7aa
s4:provision_users.ldif - Fix typos in user/group objects
2010-05-13 11:17:52 +02:00
Matthias Dieter Wallnöfer
726fb35f9f
s4:dsdb: add new controls
...
- Add a new control for getting status informations (domain informations,
password change status) directly from the module
- Add a new control for allowing direct hash changes
- Introduce an addtional control "change_old password checked" for the password
2010-05-10 17:54:15 +02:00
Stefan Metzmacher
1913e03bd4
s4:setup: mark DSDB_CONTROL_DN_STORAGE_FORMAT_OID 1.3.6.1.4.1.7165.4.3.4 as allocated
...
metze
2010-05-10 17:54:15 +02:00
Stefan Metzmacher
6ee53309a1
s4:blackbox password tests - more complex passwords
2010-05-10 12:20:26 +02:00
Matthias Dieter Wallnöfer
e4ce727c8d
s3:provision_basedn_modify.ldif - add "msDS-NcType" attribute and fix comments
2010-05-10 09:21:17 +02:00
Marcel Ritter
e6f59613fe
Install spn_update_list to setup/ dir
...
Signed-off-by: Matthias Dieter Wallnöfer <mdw@samba.org>
2010-04-27 21:05:00 +02:00
Andrew Tridgell
fa26383884
s4-dsdb: added samba_spnupdate
...
this script adds all our required servicePrincipalName entries at
runtime. The admin can add more entries to spn_update_list as needed
2010-04-27 19:27:18 +10:00
Andrew Tridgell
570c89287e
s4-dns: explain what the file is for
2010-04-27 19:27:18 +10:00
Andrew Tridgell
be35a40e03
s4-dns: fixed dc.dc duplication in DNS update list
2010-04-27 11:01:23 +10:00
Andrew Bartlett
bd08249d68
s4:provision Remove moduleload for 'hdb' (wrong name).
...
The backends are not normally modules anyway
2010-04-22 19:55:06 +10:00
Andrew Bartlett
e11f92ba73
s4:provision Make OpenLDAP backend more robust
...
With the extra moduleload lines (which succeed if it's already
staticly linked), we now work with OpenLDAP overlays as modules.
Andrew Bartlett
2010-04-22 18:37:19 +10:00
Andrew Bartlett
466fbe278a
s4:provison Pass nosync in for the OpenLDAP cn=config too
2010-04-22 18:37:19 +10:00
Andrew Bartlett
cbb818222a
s4:OpenLDAP-backend Use the new rdnval module in OpenLDAP
...
This is rather than rdn_name, which tries to do the job on the client
side. We need to leave this module in the stack for Fedora DS (and of
course the LDB backend).
Andrew Bartlett
2010-04-22 18:37:18 +10:00
Andrew Bartlett
a50f6aad85
s4:provision Use more reasonable values for DB_CONFIG
...
With the OpenLDAP backend, the old DB_CONFIG caused OpenLDAP to abort
on startup, and was very inefficient. This new one, kindly supplied
by Matthew Backes <mbackes@symas.com> uses a more reasonable set of
buffer sizes.
Andrew Bartlett
2010-04-22 18:37:18 +10:00
Andrew Tridgell
5e695dec2a
s4-upgradeprovision: fixed --realm option duplicate in upgrade_from_s3
2010-04-21 13:35:56 +10:00
Andrew Tridgell
8fdfcde56c
s4-provision: cope with --realm being in getopt.py
...
we still need to allow for interactive querying of the realm
Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>
2010-04-21 13:35:56 +10:00
Matthieu Patou
b8d6f1ce89
s4 provision: Remove hard coded ACL for GPO objects
...
It is no longer needed to hard code ACL for GPO object as we have now code
that calculate ACL from defaultSecurityDescriptor and inheritance correctly.
In fact the resulting ACL returned by this hard coded value is a bit wrong as
some ACE are duplicated.
Signed-off-by: Jelmer Vernooij <jelmer@samba.org>
2010-04-15 18:45:40 +02:00
Stefan Metzmacher
f1ecdb980b
s4:setup/wscript_build: install dns_update_list into ${SETUPDIR}
...
metze
2010-04-15 18:37:40 +02:00
Jelmer Vernooij
dd4ef4e106
s4-python: More cleanups.
2010-04-08 23:20:36 +02:00
Jelmer Vernooij
d7a46ee129
s4-python: Simplify code, improve formatting.
2010-04-08 23:20:36 +02:00
Thomas Nagy
7f3116a63d
build: allow the waf build to work with python 3.0 and 3.1
...
Python 3.x is a bit fussier about print statements and indentation.
Signed-off-by: Andrew Tridgell <tridge@samba.org>
2010-04-08 07:46:39 +10:00
Andrew Tridgell
f9eae32f4b
s4-waf: mark the wscript files as python so vim/emacs knows how to highlight them
2010-04-06 20:27:11 +10:00
Andrew Tridgell
bd7bf0e1a9
s4-waf: install the rest of our python files
2010-04-06 20:27:10 +10:00