s4-kdc: don't ask for an extended DN for krbtgt_dn
authorAndrew Tridgell <tridge@samba.org>
Thu, 13 Jan 2011 06:40:29 +0000 (17:40 +1100)
committerAndrew Tridgell <tridge@samba.org>
Fri, 14 Jan 2011 05:39:33 +0000 (16:39 +1100)
otherwise msg->dn would be non-minimal and would fail in searches

Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>

source4/kdc/db-glue.c

index cdfec7b0b986cd29fcaaf9c92add65c3c2ca4ace..ed64685a4fc2cff11c8edcb68dd4901d9c594e52 100644 (file)
@@ -1730,7 +1730,7 @@ NTSTATUS samba_kdc_setup_db_ctx(TALLOC_CTX *mem_ctx, struct samba_kdc_base_conte
                ldb_ret = dsdb_search_one(kdc_db_ctx->samdb, kdc_db_ctx,
                                          &msg, NULL, LDB_SCOPE_SUBTREE,
                                          krbtgt_attrs,
-                                         DSDB_SEARCH_SHOW_EXTENDED_DN,
+                                         0,
                                          "(&(objectClass=user)(samAccountName=krbtgt))");
 
                if (ldb_ret != LDB_SUCCESS) {