2 Unix SMB/CIFS implementation.
4 implement the DRSUpdateRefs call
6 Copyright (C) Andrew Tridgell 2009
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
23 #include "rpc_server/dcerpc_server.h"
24 #include "dsdb/samdb/samdb.h"
25 #include "rpc_server/drsuapi/dcesrv_drsuapi.h"
26 #include "libcli/security/security.h"
27 #include "auth/session.h"
31 struct repsFromToBlob *r;
35 add a replication destination for a given partition GUID
37 static WERROR uref_add_dest(struct ldb_context *sam_ctx, TALLOC_CTX *mem_ctx,
38 struct ldb_dn *dn, struct repsFromTo1 *dest,
45 werr = dsdb_loadreps(sam_ctx, mem_ctx, dn, "repsTo", &reps.r, &reps.count);
46 if (!W_ERROR_IS_OK(werr)) {
50 for (i=0; i<reps.count; i++) {
51 if (GUID_compare(&dest->source_dsa_obj_guid,
52 &reps.r[i].ctr.ctr1.source_dsa_obj_guid) == 0) {
53 if (options & DRSUAPI_DRS_GETCHG_CHECK) {
56 return WERR_DS_DRA_REF_ALREADY_EXISTS;
61 reps.r = talloc_realloc(mem_ctx, reps.r, struct repsFromToBlob, reps.count+1);
63 return WERR_DS_DRA_INTERNAL_ERROR;
65 ZERO_STRUCT(reps.r[reps.count]);
66 reps.r[reps.count].version = 1;
67 reps.r[reps.count].ctr.ctr1 = *dest;
70 werr = dsdb_savereps(sam_ctx, mem_ctx, dn, "repsTo", reps.r, reps.count);
71 if (!W_ERROR_IS_OK(werr)) {
79 delete a replication destination for a given partition GUID
81 static WERROR uref_del_dest(struct ldb_context *sam_ctx, TALLOC_CTX *mem_ctx,
82 struct ldb_dn *dn, struct GUID *dest_guid,
90 werr = dsdb_loadreps(sam_ctx, mem_ctx, dn, "repsTo", &reps.r, &reps.count);
91 if (!W_ERROR_IS_OK(werr)) {
95 for (i=0; i<reps.count; i++) {
96 if (GUID_compare(dest_guid, &reps.r[i].ctr.ctr1.source_dsa_obj_guid) == 0) {
97 if (i+1 < reps.count) {
98 memmove(&reps.r[i], &reps.r[i+1], sizeof(reps.r[i])*(reps.count-(i+1)));
105 werr = dsdb_savereps(sam_ctx, mem_ctx, dn, "repsTo", reps.r, reps.count);
106 if (!W_ERROR_IS_OK(werr)) {
111 !(options & DRSUAPI_DRS_GETCHG_CHECK) &&
112 !(options & DRSUAPI_DRS_ADD_REF)) {
113 return WERR_DS_DRA_REF_NOT_FOUND;
120 drsuapi_DsReplicaUpdateRefs - a non RPC version callable from getncchanges
122 WERROR drsuapi_UpdateRefs(struct drsuapi_bind_state *b_state, TALLOC_CTX *mem_ctx,
123 struct drsuapi_DsReplicaUpdateRefsRequest1 *req)
128 DEBUG(4,("DsReplicaUpdateRefs for host '%s' with GUID %s options 0x%08x nc=%s\n",
129 req->dest_dsa_dns_name, GUID_string(mem_ctx, &req->dest_dsa_guid),
131 drs_ObjectIdentifier_to_string(mem_ctx, req->naming_context)));
133 dn = ldb_dn_new(mem_ctx, b_state->sam_ctx, req->naming_context->dn);
135 return WERR_DS_INVALID_DN_SYNTAX;
138 if (ldb_transaction_start(b_state->sam_ctx) != LDB_SUCCESS) {
139 DEBUG(0,(__location__ ": Failed to start transaction on samdb\n"));
140 return WERR_DS_DRA_INTERNAL_ERROR;
143 if (req->options & DRSUAPI_DRS_DEL_REF) {
144 werr = uref_del_dest(b_state->sam_ctx, mem_ctx, dn, &req->dest_dsa_guid, req->options);
145 if (!W_ERROR_IS_OK(werr)) {
146 DEBUG(0,("Failed to delete repsTo for %s\n",
147 GUID_string(mem_ctx, &req->dest_dsa_guid)));
152 if (req->options & DRSUAPI_DRS_ADD_REF) {
153 struct repsFromTo1 dest;
154 struct repsFromTo1OtherInfo oi;
159 oi.dns_name = req->dest_dsa_dns_name;
160 dest.other_info = &oi;
161 dest.source_dsa_obj_guid = req->dest_dsa_guid;
162 dest.replica_flags = req->options;
164 werr = uref_add_dest(b_state->sam_ctx, mem_ctx, dn, &dest, req->options);
165 if (!W_ERROR_IS_OK(werr)) {
166 DEBUG(0,("Failed to add repsTo for %s\n",
167 GUID_string(mem_ctx, &dest.source_dsa_obj_guid)));
172 if (ldb_transaction_commit(b_state->sam_ctx) != LDB_SUCCESS) {
173 DEBUG(0,(__location__ ": Failed to commit transaction on samdb\n"));
174 return WERR_DS_DRA_INTERNAL_ERROR;
180 ldb_transaction_cancel(b_state->sam_ctx);
185 drsuapi_DsReplicaUpdateRefs
187 WERROR dcesrv_drsuapi_DsReplicaUpdateRefs(struct dcesrv_call_state *dce_call, TALLOC_CTX *mem_ctx,
188 struct drsuapi_DsReplicaUpdateRefs *r)
190 struct dcesrv_handle *h;
191 struct drsuapi_bind_state *b_state;
192 struct drsuapi_DsReplicaUpdateRefsRequest1 *req;
195 enum security_user_level security_level;
197 DCESRV_PULL_HANDLE_WERR(h, r->in.bind_handle, DRSUAPI_BIND_HANDLE);
200 werr = drs_security_level_check(dce_call, "DsReplicaUpdateRefs", SECURITY_RO_DOMAIN_CONTROLLER,
201 samdb_domain_sid(b_state->sam_ctx));
202 if (!W_ERROR_IS_OK(werr)) {
206 if (r->in.level != 1) {
207 DEBUG(0,("DrReplicUpdateRefs - unsupported level %u\n", r->in.level));
208 return WERR_DS_DRA_INVALID_PARAMETER;
211 req = &r->in.req.req1;
213 security_level = security_session_user_level(dce_call->conn->auth_state.session_info, NULL);
214 if (security_level < SECURITY_ADMINISTRATOR) {
215 /* check that they are using an DSA objectGUID that they own */
216 ret = dsdb_validate_dsa_guid(b_state->sam_ctx,
218 &dce_call->conn->auth_state.session_info->security_token->sids[PRIMARY_USER_SID_INDEX]);
219 if (ret != LDB_SUCCESS) {
220 DEBUG(0,(__location__ ": Refusing DsReplicaUpdateRefs for sid %s with GUID %s\n",
221 dom_sid_string(mem_ctx,
222 &dce_call->conn->auth_state.session_info->security_token->sids[PRIMARY_USER_SID_INDEX]),
223 GUID_string(mem_ctx, &req->dest_dsa_guid)));
224 return WERR_DS_DRA_ACCESS_DENIED;
228 return drsuapi_UpdateRefs(b_state, mem_ctx, req);