2 * Unix SMB/CIFS implementation.
4 * Copyright (C) Guenther Deschner 2007-2008
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, see <http://www.gnu.org/licenses/>.
22 #include "librpc/gen_ndr/libnetapi.h"
23 #include "libcli/auth/libcli_auth.h"
24 #include "lib/netapi/netapi.h"
25 #include "lib/netapi/netapi_private.h"
26 #include "lib/netapi/libnetapi.h"
27 #include "librpc/gen_ndr/libnet_join.h"
28 #include "libnet/libnet_join.h"
29 #include "../librpc/gen_ndr/ndr_wkssvc_c.h"
30 #include "rpc_client/cli_pipe.h"
32 #include "libsmb/dsgetdcname.h"
34 /****************************************************************
35 ****************************************************************/
37 WERROR NetJoinDomain_l(struct libnetapi_ctx *mem_ctx,
38 struct NetJoinDomain *r)
40 struct libnet_JoinCtx *j = NULL;
41 struct libnetapi_private_ctx *priv;
44 priv = talloc_get_type_abort(mem_ctx->private_data,
45 struct libnetapi_private_ctx);
48 return WERR_INVALID_PARAMETER;
51 werr = libnet_init_JoinCtx(mem_ctx, &j);
52 W_ERROR_NOT_OK_RETURN(werr);
54 j->in.domain_name = talloc_strdup(mem_ctx, r->in.domain);
55 W_ERROR_HAVE_NO_MEMORY(j->in.domain_name);
57 if (r->in.join_flags & WKSSVC_JOIN_FLAGS_JOIN_TYPE) {
59 struct netr_DsRGetDCNameInfo *info = NULL;
60 const char *dc = NULL;
61 uint32_t flags = DS_DIRECTORY_SERVICE_REQUIRED |
62 DS_WRITABLE_REQUIRED |
64 status = dsgetdcname(mem_ctx, priv->msg_ctx, r->in.domain,
65 NULL, NULL, flags, &info);
66 if (!NT_STATUS_IS_OK(status)) {
67 libnetapi_set_error_string(mem_ctx,
68 "%s", get_friendly_nt_error_msg(status));
69 return ntstatus_to_werror(status);
72 dc = strip_hostname(info->dc_unc);
73 j->in.dc_name = talloc_strdup(mem_ctx, dc);
74 W_ERROR_HAVE_NO_MEMORY(j->in.dc_name);
77 if (r->in.account_ou) {
78 j->in.account_ou = talloc_strdup(mem_ctx, r->in.account_ou);
79 W_ERROR_HAVE_NO_MEMORY(j->in.account_ou);
83 j->in.admin_account = talloc_strdup(mem_ctx, r->in.account);
84 W_ERROR_HAVE_NO_MEMORY(j->in.admin_account);
88 j->in.admin_password = talloc_strdup(mem_ctx, r->in.password);
89 W_ERROR_HAVE_NO_MEMORY(j->in.admin_password);
92 j->in.join_flags = r->in.join_flags;
93 j->in.modify_config = true;
96 werr = libnet_Join(mem_ctx, j);
97 if (!W_ERROR_IS_OK(werr) && j->out.error_string) {
98 libnetapi_set_error_string(mem_ctx, "%s", j->out.error_string);
105 /****************************************************************
106 ****************************************************************/
108 WERROR NetJoinDomain_r(struct libnetapi_ctx *ctx,
109 struct NetJoinDomain *r)
111 struct rpc_pipe_client *pipe_cli = NULL;
112 struct wkssvc_PasswordBuffer *encrypted_password = NULL;
115 unsigned int old_timeout = 0;
116 struct dcerpc_binding_handle *b;
117 DATA_BLOB session_key;
120 return WERR_NERR_SETUPDOMAINCONTROLLER;
123 werr = libnetapi_open_pipe(ctx, r->in.server,
126 if (!W_ERROR_IS_OK(werr)) {
130 b = pipe_cli->binding_handle;
132 if (r->in.password) {
134 status = cli_get_session_key(talloc_tos(), pipe_cli, &session_key);
135 if (!NT_STATUS_IS_OK(status)) {
136 werr = ntstatus_to_werror(status);
140 encode_wkssvc_join_password_buffer(ctx,
143 &encrypted_password);
146 old_timeout = rpccli_set_timeout(pipe_cli, 600000);
148 status = dcerpc_wkssvc_NetrJoinDomain2(b, talloc_tos(),
156 if (!NT_STATUS_IS_OK(status)) {
157 werr = ntstatus_to_werror(status);
162 if (pipe_cli && old_timeout) {
163 rpccli_set_timeout(pipe_cli, old_timeout);
168 /****************************************************************
169 ****************************************************************/
171 WERROR NetUnjoinDomain_l(struct libnetapi_ctx *mem_ctx,
172 struct NetUnjoinDomain *r)
174 struct libnet_UnjoinCtx *u = NULL;
175 struct dom_sid domain_sid;
176 const char *domain = NULL;
178 struct libnetapi_private_ctx *priv;
179 const char *realm = lp_realm();
181 priv = talloc_get_type_abort(mem_ctx->private_data,
182 struct libnetapi_private_ctx);
184 if (!secrets_fetch_domain_sid(lp_workgroup(), &domain_sid)) {
185 return WERR_NERR_SETUPNOTJOINED;
188 werr = libnet_init_UnjoinCtx(mem_ctx, &u);
189 W_ERROR_NOT_OK_RETURN(werr);
191 if (realm[0] != '\0') {
194 domain = lp_workgroup();
197 if (r->in.server_name) {
198 u->in.dc_name = talloc_strdup(mem_ctx, r->in.server_name);
199 W_ERROR_HAVE_NO_MEMORY(u->in.dc_name);
202 struct netr_DsRGetDCNameInfo *info = NULL;
203 const char *dc = NULL;
204 uint32_t flags = DS_DIRECTORY_SERVICE_REQUIRED |
205 DS_WRITABLE_REQUIRED |
207 status = dsgetdcname(mem_ctx, priv->msg_ctx, domain,
208 NULL, NULL, flags, &info);
209 if (!NT_STATUS_IS_OK(status)) {
210 libnetapi_set_error_string(mem_ctx,
211 "failed to find DC for domain %s: %s",
213 get_friendly_nt_error_msg(status));
214 return ntstatus_to_werror(status);
217 dc = strip_hostname(info->dc_unc);
218 u->in.dc_name = talloc_strdup(mem_ctx, dc);
219 W_ERROR_HAVE_NO_MEMORY(u->in.dc_name);
221 u->in.domain_name = domain;
225 u->in.admin_account = talloc_strdup(mem_ctx, r->in.account);
226 W_ERROR_HAVE_NO_MEMORY(u->in.admin_account);
229 if (r->in.password) {
230 u->in.admin_password = talloc_strdup(mem_ctx, r->in.password);
231 W_ERROR_HAVE_NO_MEMORY(u->in.admin_password);
234 u->in.domain_name = domain;
235 u->in.unjoin_flags = r->in.unjoin_flags;
236 u->in.delete_machine_account = false;
237 u->in.modify_config = true;
240 u->in.domain_sid = &domain_sid;
242 werr = libnet_Unjoin(mem_ctx, u);
243 if (!W_ERROR_IS_OK(werr) && u->out.error_string) {
244 libnetapi_set_error_string(mem_ctx, "%s", u->out.error_string);
251 /****************************************************************
252 ****************************************************************/
254 WERROR NetUnjoinDomain_r(struct libnetapi_ctx *ctx,
255 struct NetUnjoinDomain *r)
257 struct rpc_pipe_client *pipe_cli = NULL;
258 struct wkssvc_PasswordBuffer *encrypted_password = NULL;
261 unsigned int old_timeout = 0;
262 struct dcerpc_binding_handle *b;
263 DATA_BLOB session_key;
265 werr = libnetapi_open_pipe(ctx, r->in.server_name,
268 if (!W_ERROR_IS_OK(werr)) {
272 b = pipe_cli->binding_handle;
274 if (r->in.password) {
276 status = cli_get_session_key(talloc_tos(), pipe_cli, &session_key);
277 if (!NT_STATUS_IS_OK(status)) {
278 werr = ntstatus_to_werror(status);
282 encode_wkssvc_join_password_buffer(ctx,
285 &encrypted_password);
288 old_timeout = rpccli_set_timeout(pipe_cli, 60000);
290 status = dcerpc_wkssvc_NetrUnjoinDomain2(b, talloc_tos(),
296 if (!NT_STATUS_IS_OK(status)) {
297 werr = ntstatus_to_werror(status);
302 if (pipe_cli && old_timeout) {
303 rpccli_set_timeout(pipe_cli, old_timeout);
309 /****************************************************************
310 ****************************************************************/
312 WERROR NetGetJoinInformation_r(struct libnetapi_ctx *ctx,
313 struct NetGetJoinInformation *r)
315 struct rpc_pipe_client *pipe_cli = NULL;
318 const char *buffer = NULL;
319 struct dcerpc_binding_handle *b;
321 werr = libnetapi_open_pipe(ctx, r->in.server_name,
324 if (!W_ERROR_IS_OK(werr)) {
328 b = pipe_cli->binding_handle;
330 status = dcerpc_wkssvc_NetrGetJoinInformation(b, talloc_tos(),
333 (enum wkssvc_NetJoinStatus *)r->out.name_type,
335 if (!NT_STATUS_IS_OK(status)) {
336 werr = ntstatus_to_werror(status);
340 if (!W_ERROR_IS_OK(werr)) {
344 *r->out.name_buffer = talloc_strdup(ctx, buffer);
345 W_ERROR_HAVE_NO_MEMORY(*r->out.name_buffer);
351 /****************************************************************
352 ****************************************************************/
354 WERROR NetGetJoinInformation_l(struct libnetapi_ctx *ctx,
355 struct NetGetJoinInformation *r)
357 const char *realm = lp_realm();
359 if ((lp_security() == SEC_ADS) && realm[0] != '\0') {
360 *r->out.name_buffer = talloc_strdup(ctx, realm);
362 *r->out.name_buffer = talloc_strdup(ctx, lp_workgroup());
364 if (!*r->out.name_buffer) {
365 return WERR_NOT_ENOUGH_MEMORY;
368 switch (lp_server_role()) {
369 case ROLE_DOMAIN_MEMBER:
370 case ROLE_DOMAIN_PDC:
371 case ROLE_DOMAIN_BDC:
372 *r->out.name_type = NetSetupDomainName;
374 case ROLE_STANDALONE:
376 *r->out.name_type = NetSetupWorkgroupName;
383 /****************************************************************
384 ****************************************************************/
386 WERROR NetGetJoinableOUs_l(struct libnetapi_ctx *ctx,
387 struct NetGetJoinableOUs *r)
391 ADS_STATUS ads_status;
392 ADS_STRUCT *ads = NULL;
393 struct netr_DsRGetDCNameInfo *info = NULL;
394 const char *dc = NULL;
395 uint32_t flags = DS_DIRECTORY_SERVICE_REQUIRED |
397 struct libnetapi_private_ctx *priv;
401 priv = talloc_get_type_abort(ctx->private_data,
402 struct libnetapi_private_ctx);
404 status = dsgetdcname(ctx, priv->msg_ctx, r->in.domain,
405 NULL, NULL, flags, &info);
406 if (!NT_STATUS_IS_OK(status)) {
407 libnetapi_set_error_string(ctx, "%s",
408 get_friendly_nt_error_msg(status));
409 return ntstatus_to_werror(status);
412 dc = strip_hostname(info->dc_unc);
414 ads = ads_init(info->domain_name, info->domain_name, dc);
416 return WERR_GEN_FAILURE;
419 SAFE_FREE(ads->auth.user_name);
421 ads->auth.user_name = SMB_STRDUP(r->in.account);
422 } else if (ctx->username) {
423 ads->auth.user_name = SMB_STRDUP(ctx->username);
426 SAFE_FREE(ads->auth.password);
427 if (r->in.password) {
428 ads->auth.password = SMB_STRDUP(r->in.password);
429 } else if (ctx->password) {
430 ads->auth.password = SMB_STRDUP(ctx->password);
433 ads_status = ads_connect_user_creds(ads);
434 if (!ADS_ERR_OK(ads_status)) {
436 return WERR_NERR_DEFAULTJOINREQUIRED;
439 ads_status = ads_get_joinable_ous(ads, ctx, &p, &s);
440 if (!ADS_ERR_OK(ads_status)) {
442 return WERR_NERR_DEFAULTJOINREQUIRED;
444 *r->out.ous = discard_const_p(const char *, p);
445 *r->out.ou_count = s;
450 return WERR_NOT_SUPPORTED;
454 /****************************************************************
455 ****************************************************************/
457 WERROR NetGetJoinableOUs_r(struct libnetapi_ctx *ctx,
458 struct NetGetJoinableOUs *r)
460 struct rpc_pipe_client *pipe_cli = NULL;
461 struct wkssvc_PasswordBuffer *encrypted_password = NULL;
464 struct dcerpc_binding_handle *b;
465 DATA_BLOB session_key;
467 werr = libnetapi_open_pipe(ctx, r->in.server_name,
470 if (!W_ERROR_IS_OK(werr)) {
474 b = pipe_cli->binding_handle;
476 if (r->in.password) {
478 status = cli_get_session_key(talloc_tos(), pipe_cli, &session_key);
479 if (!NT_STATUS_IS_OK(status)) {
480 werr = ntstatus_to_werror(status);
484 encode_wkssvc_join_password_buffer(ctx,
487 &encrypted_password);
490 status = dcerpc_wkssvc_NetrGetJoinableOus2(b, talloc_tos(),
498 if (!NT_STATUS_IS_OK(status)) {
499 werr = ntstatus_to_werror(status);
507 /****************************************************************
508 ****************************************************************/
510 WERROR NetRenameMachineInDomain_r(struct libnetapi_ctx *ctx,
511 struct NetRenameMachineInDomain *r)
513 struct rpc_pipe_client *pipe_cli = NULL;
514 struct wkssvc_PasswordBuffer *encrypted_password = NULL;
517 struct dcerpc_binding_handle *b;
518 DATA_BLOB session_key;
520 werr = libnetapi_open_pipe(ctx, r->in.server_name,
523 if (!W_ERROR_IS_OK(werr)) {
527 b = pipe_cli->binding_handle;
529 if (r->in.password) {
531 status = cli_get_session_key(talloc_tos(), pipe_cli, &session_key);
532 if (!NT_STATUS_IS_OK(status)) {
533 werr = ntstatus_to_werror(status);
537 encode_wkssvc_join_password_buffer(ctx,
540 &encrypted_password);
543 status = dcerpc_wkssvc_NetrRenameMachineInDomain2(b, talloc_tos(),
545 r->in.new_machine_name,
548 r->in.rename_options,
550 if (!NT_STATUS_IS_OK(status)) {
551 werr = ntstatus_to_werror(status);
559 /****************************************************************
560 ****************************************************************/
562 WERROR NetRenameMachineInDomain_l(struct libnetapi_ctx *ctx,
563 struct NetRenameMachineInDomain *r)
565 LIBNETAPI_REDIRECT_TO_LOCALHOST(ctx, r, NetRenameMachineInDomain);