From 10c60f237223f805566a66293418bd1cf04a8f5e Mon Sep 17 00:00:00 2001 From: Nadezhda Ivanova Date: Thu, 8 Jul 2010 15:38:16 +0300 Subject: [PATCH] Added a test to prove by default users can change each other's pass if the old is known --- source4/dsdb/tests/python/acl.py | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/source4/dsdb/tests/python/acl.py b/source4/dsdb/tests/python/acl.py index 31bcd31ae2..471335f342 100755 --- a/source4/dsdb/tests/python/acl.py +++ b/source4/dsdb/tests/python/acl.py @@ -1165,6 +1165,31 @@ userPassword: thatsAcomplPASS2 else: self.fail() + def test_change_password7(self): + """Try a password change operation without any CARs given""" + #users have change password by default - remove for negative testing + desc = self.read_desc(self.get_user_dn(self.user_with_wp)) + sddl = desc.as_sddl(self.domain_sid) + self.modify_desc(self.get_user_dn(self.user_with_wp), sddl) + #first change our own password + self.ldb_user2.modify_ldif(""" +dn: """ + self.get_user_dn(self.user_with_pc) + """ +changetype: modify +delete: unicodePwd +unicodePwd:: """ + base64.b64encode("\"samba123@\"".encode('utf-16-le')) + """ +add: unicodePwd +unicodePwd:: """ + base64.b64encode("\"thatsAcomplPASS1\"".encode('utf-16-le')) + """ +""") + #then someone else's + self.ldb_user2.modify_ldif(""" +dn: """ + self.get_user_dn(self.user_with_wp) + """ +changetype: modify +delete: unicodePwd +unicodePwd:: """ + base64.b64encode("\"samba123@\"".encode('utf-16-le')) + """ +add: unicodePwd +unicodePwd:: """ + base64.b64encode("\"thatsAcomplPASS2\"".encode('utf-16-le')) + """ +""") + def test_reset_password1(self): """Try a user password reset operation (unicodePwd) before and after granting CAR""" try: -- 2.34.1