mirror of
https://github.com/samba-team/samba.git
synced 2025-03-10 12:58:35 +03:00
needs to be renamed (operation_add?). This allows me to match the behaviour and substitute with the entryUUID module for remote LDAP connections. Andrew Bartlett (This used to be commit af02b4d7c631bb15bf5a5f73f9fdc23075d50f60)
140 lines
3.3 KiB
Plaintext
Executable File
140 lines
3.3 KiB
Plaintext
Executable File
#!/bin/sh
|
|
exec smbscript "$0" ${1+"$@"}
|
|
/*
|
|
provision a Samba4 server
|
|
Copyright Andrew Tridgell 2005
|
|
Released under the GNU GPL v2 or later
|
|
*/
|
|
|
|
options = GetOptions(ARGV,
|
|
"POPT_AUTOHELP",
|
|
"POPT_COMMON_SAMBA",
|
|
"POPT_COMMON_VERSION",
|
|
"POPT_COMMON_CREDENTIALS",
|
|
'realm=s',
|
|
'domain=s',
|
|
'domain-guid=s',
|
|
'domain-sid=s',
|
|
'host-name=s',
|
|
'host-ip=s',
|
|
'host-guid=s',
|
|
'invocationid=s',
|
|
'adminpass=s',
|
|
'krbtgtpass=s',
|
|
'machinepass=s',
|
|
'root=s',
|
|
'nobody=s',
|
|
'nogroup=s',
|
|
'wheel=s',
|
|
'users=s',
|
|
'quiet',
|
|
'blank',
|
|
'ldap-base',
|
|
'ldap-backend=s');
|
|
|
|
if (options == undefined) {
|
|
println("Failed to parse options");
|
|
return -1;
|
|
}
|
|
|
|
libinclude("base.js");
|
|
libinclude("provision.js");
|
|
|
|
/*
|
|
print a message if quiet is not set
|
|
*/
|
|
function message()
|
|
{
|
|
if (options["quiet"] == undefined) {
|
|
print(vsprintf(arguments));
|
|
}
|
|
}
|
|
|
|
/*
|
|
show some help
|
|
*/
|
|
function ShowHelp()
|
|
{
|
|
print("
|
|
Samba4 provisioning
|
|
|
|
provision [options]
|
|
--realm REALM set realm
|
|
--domain DOMAIN set domain
|
|
--domain-guid GUID set domainguid (otherwise random)
|
|
--domain-sid SID set domainsid (otherwise random)
|
|
--host-name HOSTNAME set hostname
|
|
--host-ip IPADDRESS set ipaddress
|
|
--host-guid GUID set hostguid (otherwise random)
|
|
--invocationid GUID set invocationid (otherwise random)
|
|
--adminpass PASSWORD choose admin password (otherwise random)
|
|
--krbtgtpass PASSWORD choose krbtgt password (otherwise random)
|
|
--machinepass PASSWORD choose machine password (otherwise random)
|
|
--root USERNAME choose 'root' unix username
|
|
--nobody USERNAME choose 'nobody' user
|
|
--nogroup GROUPNAME choose 'nogroup' group
|
|
--wheel GROUPNAME choose 'wheel' privileged group
|
|
--users GROUPNAME choose 'users' group
|
|
--quiet Be quiet
|
|
--blank do not add users or groups, just the structure
|
|
--ldap-base output only an LDIF file, suitable for creating an LDAP baseDN
|
|
--ldap-backend LDAPSERVER LDAP server to use for this provision
|
|
|
|
You must provide at least a realm and domain
|
|
|
|
");
|
|
exit(1);
|
|
}
|
|
|
|
if (options['host-name'] == undefined) {
|
|
options['host-name'] = hostname();
|
|
}
|
|
|
|
/*
|
|
main program
|
|
*/
|
|
if (options["realm"] == undefined ||
|
|
options["domain"] == undefined ||
|
|
options["host-name"] == undefined) {
|
|
ShowHelp();
|
|
}
|
|
|
|
/* cope with an initially blank smb.conf */
|
|
var lp = loadparm_init();
|
|
lp.set("realm", options.realm);
|
|
lp.set("workgroup", options.domain);
|
|
lp.reload();
|
|
|
|
var subobj = provision_guess();
|
|
for (r in options) {
|
|
var key = strupper(join("", split("-", r)));
|
|
subobj[key] = options[r];
|
|
}
|
|
|
|
if (options["ldap-backend"] != undefined) {
|
|
subobj["LDAPMODULES"] = "entryUUID";
|
|
} else {
|
|
subobj["LDAPMODULES"] = "objectguid";
|
|
}
|
|
|
|
var blank = (options["blank"] != undefined);
|
|
var ldapbase = (options["ldap-base"] != undefined);
|
|
|
|
if (!provision_validate(subobj, message)) {
|
|
return -1;
|
|
}
|
|
|
|
var system_session = system_session();
|
|
var creds = options.get_credentials();
|
|
var paths = provision_default_paths(subobj);
|
|
message("Provisioning for %s in realm %s\n", subobj.DOMAIN, subobj.REALM);
|
|
message("Using administrator password: %s\n", subobj.ADMINPASS);
|
|
if (ldapbase) {
|
|
provision_ldapbase(subobj, message, paths);
|
|
} else {
|
|
provision(subobj, message, blank, paths, system_session, creds);
|
|
provision_dns(subobj, message, paths, system_session, creds);
|
|
}
|
|
message("All OK\n");
|
|
return 0;
|