da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * CDDL HEADER START
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * The contents of this file are subject to the terms of the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Common Development and Distribution License (the "License").
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * You may not use this file except in compliance with the License.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * or http://www.opensolaris.org/os/licensing.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * See the License for the specific language governing permissions
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * and limitations under the License.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * When distributing Covered Code, include this CDDL HEADER in each
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * If applicable, add the following below this CDDL HEADER, with the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * fields enclosed by brackets "[]" replaced with your own identifying
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * information: Portions Copyright [yyyy] [name of copyright owner]
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * CDDL HEADER END
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
148c5f43199ca0b43fc8e3b643aab11cd66ea327Alan Wright
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
148c5f43199ca0b43fc8e3b643aab11cd66ea327Alan Wright * Copyright (c) 2007, 2010, Oracle and/or its affiliates. All rights reserved.
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * Copyright 2015 Nexenta Systems, Inc. All rights reserved.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NETR SamLogon and SamLogoff RPC client functions.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <stdio.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <strings.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <stdlib.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <time.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <alloca.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <unistd.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <netdb.h>
8d7e41661dc4633488e93b13363137523ce59977jose borrego#include <thread.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <smbsrv/libsmb.h>
8d7e41661dc4633488e93b13363137523ce59977jose borrego#include <smbsrv/libmlrpc.h>
8d7e41661dc4633488e93b13363137523ce59977jose borrego#include <smbsrv/libmlsvc.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <smbsrv/ndl/netlogon.ndl>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <smbsrv/netrauth.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <smbsrv/smbinfo.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw#include <smbsrv/smb_token.h>
8d7e41661dc4633488e93b13363137523ce59977jose borrego#include <mlsvc.h>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States#define NETLOGON_ATTEMPTS 2
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic uint32_t netlogon_logon(smb_logon_t *, smb_token_t *);
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t netr_server_samlogon(mlsvc_handle_t *, netr_info_t *, char *,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States smb_logon_t *, smb_token_t *);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwstatic void netr_invalidate_chain(void);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic void netr_interactive_samlogon(netr_info_t *, smb_logon_t *,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_logon_info1 *);
8d7e41661dc4633488e93b13363137523ce59977jose borregostatic void netr_network_samlogon(ndr_heap_t *, netr_info_t *,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States smb_logon_t *, struct netr_logon_info2 *);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic void netr_setup_identity(ndr_heap_t *, smb_logon_t *,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_logon_id_t *);
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic boolean_t netr_isadmin(struct netr_validation_info3 *);
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t netr_setup_domain_groups(struct netr_validation_info3 *,
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_ids_t *);
12b65585e720714b31036daaa2b30eb76014048eGordon Rossstatic uint32_t netr_setup_token_info3(struct netr_validation_info3 *,
12b65585e720714b31036daaa2b30eb76014048eGordon Ross smb_token_t *);
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t netr_setup_token_wingrps(struct netr_validation_info3 *,
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_token_t *);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Shared with netr_auth.c
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwextern netr_info_t netr_global_info;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic mutex_t netlogon_mutex;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic cond_t netlogon_cv;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic boolean_t netlogon_busy = B_FALSE;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesstatic boolean_t netlogon_abort = B_FALSE;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
12b65585e720714b31036daaa2b30eb76014048eGordon Ross/*
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * Helper for Kerberos authentication
12b65585e720714b31036daaa2b30eb76014048eGordon Ross */
12b65585e720714b31036daaa2b30eb76014048eGordon Rossuint32_t
12b65585e720714b31036daaa2b30eb76014048eGordon Rosssmb_decode_krb5_pac(smb_token_t *token, char *data, uint_t len)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross{
12b65585e720714b31036daaa2b30eb76014048eGordon Ross struct krb5_validation_info info;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross ndr_buf_t *nbuf;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross uint32_t status = NT_STATUS_NO_MEMORY;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross int rc;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross bzero(&info, sizeof (info));
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross /* Need to keep this until we're done with &info */
12b65585e720714b31036daaa2b30eb76014048eGordon Ross nbuf = ndr_buf_init(&TYPEINFO(netr_interface));
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (nbuf == NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto out;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross rc = ndr_buf_decode(nbuf, NDR_PTYPE_PAC,
12b65585e720714b31036daaa2b30eb76014048eGordon Ross NETR_OPNUM_decode_krb5_pac, data, len, &info);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (rc != NDR_DRC_OK) {
12b65585e720714b31036daaa2b30eb76014048eGordon Ross status = RPC_NT_PROTOCOL_ERROR;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto out;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross }
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross status = netr_setup_token_info3(&info.info3, token);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross /* Deal with the "resource groups"? */
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Rossout:
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (nbuf != NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross ndr_buf_fini(nbuf);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross return (status);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross}
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross/*
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * Code factored out of netr_setup_token()
12b65585e720714b31036daaa2b30eb76014048eGordon Ross */
12b65585e720714b31036daaa2b30eb76014048eGordon Rossstatic uint32_t
12b65585e720714b31036daaa2b30eb76014048eGordon Rossnetr_setup_token_info3(struct netr_validation_info3 *info3,
12b65585e720714b31036daaa2b30eb76014048eGordon Ross smb_token_t *token)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross{
12b65585e720714b31036daaa2b30eb76014048eGordon Ross smb_sid_t *domsid;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross domsid = (smb_sid_t *)info3->LogonDomainId;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross token->tkn_user.i_sid = smb_sid_splice(domsid,
12b65585e720714b31036daaa2b30eb76014048eGordon Ross info3->UserId);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (token->tkn_user.i_sid == NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto errout;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross token->tkn_primary_grp.i_sid = smb_sid_splice(domsid,
12b65585e720714b31036daaa2b30eb76014048eGordon Ross info3->PrimaryGroupId);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (token->tkn_primary_grp.i_sid == NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto errout;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (info3->EffectiveName.str) {
12b65585e720714b31036daaa2b30eb76014048eGordon Ross token->tkn_account_name =
12b65585e720714b31036daaa2b30eb76014048eGordon Ross strdup((char *)info3->EffectiveName.str);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (token->tkn_account_name == NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto errout;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross }
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (info3->LogonDomainName.str) {
12b65585e720714b31036daaa2b30eb76014048eGordon Ross token->tkn_domain_name =
12b65585e720714b31036daaa2b30eb76014048eGordon Ross strdup((char *)info3->LogonDomainName.str);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if (token->tkn_domain_name == NULL)
12b65585e720714b31036daaa2b30eb76014048eGordon Ross goto errout;
12b65585e720714b31036daaa2b30eb76014048eGordon Ross }
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
12b65585e720714b31036daaa2b30eb76014048eGordon Ross return (netr_setup_token_wingrps(info3, token));
12b65585e720714b31036daaa2b30eb76014048eGordon Rosserrout:
12b65585e720714b31036daaa2b30eb76014048eGordon Ross return (NT_STATUS_INSUFF_SERVER_RESOURCES);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross}
12b65585e720714b31036daaa2b30eb76014048eGordon Ross
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States/*
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * Abort impending domain logon requests.
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States */
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesvoid
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statessmb_logon_abort(void)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States{
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_lock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (netlogon_busy && !netlogon_abort)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States syslog(LOG_DEBUG, "logon abort");
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netlogon_abort = B_TRUE;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) cond_broadcast(&netlogon_cv);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_unlock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States}
8d7e41661dc4633488e93b13363137523ce59977jose borrego
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * This is the entry point for authenticating domain users.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * If we are not going to attempt to authenticate the user,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * this function must return without updating the status.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * If the user is successfully authenticated, we build an
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * access token and the status will be NT_STATUS_SUCCESS.
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States * Otherwise, the token contents are invalid.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesvoid
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statessmb_logon_domain(smb_logon_t *user_info, smb_token_t *token)
8d7e41661dc4633488e93b13363137523ce59977jose borrego{
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States uint32_t status;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States int i;
8d7e41661dc4633488e93b13363137523ce59977jose borrego
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (user_info->lg_secmode != SMB_SECMODE_DOMAIN)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States return;
8d7e41661dc4633488e93b13363137523ce59977jose borrego
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (user_info->lg_domain_type == SMB_DOMAIN_LOCAL)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States return;
8d7e41661dc4633488e93b13363137523ce59977jose borrego
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States for (i = 0; i < NETLOGON_ATTEMPTS; ++i) {
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_lock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States while (netlogon_busy && !netlogon_abort)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) cond_wait(&netlogon_cv, &netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (netlogon_abort) {
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_unlock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_status = NT_STATUS_REQUEST_ABORTED;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States return;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States }
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netlogon_busy = B_TRUE;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_unlock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States status = netlogon_logon(user_info, token);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_lock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netlogon_busy = B_FALSE;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (netlogon_abort)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States status = NT_STATUS_REQUEST_ABORTED;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) cond_signal(&netlogon_cv);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States (void) mutex_unlock(&netlogon_mutex);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (status != NT_STATUS_CANT_ACCESS_DOMAIN_INFO)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States break;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States }
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if (status != NT_STATUS_SUCCESS)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States syslog(LOG_INFO, "logon[%s\\%s]: %s", user_info->lg_e_domain,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_e_username, xlate_nt_status(status));
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_status = status;
8d7e41661dc4633488e93b13363137523ce59977jose borrego}
8d7e41661dc4633488e93b13363137523ce59977jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesnetlogon_logon(smb_logon_t *user_info, smb_token_t *token)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw char resource_domain[SMB_PI_MAX_DOMAIN];
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross char server[MAXHOSTNAMELEN];
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw mlsvc_handle_t netr_handle;
a0aa776e20803c84edd153d9cb584fd67163aef3Alan Wright smb_domainex_t di;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t status;
1fdeec650620e8498c06f832ea4bd2292f7e9632joyce mcintosh int retries = 0;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
dc20a3024900c47dd2ee44b9707e6df38f7d62a5as (void) smb_getdomainname(resource_domain, SMB_PI_MAX_DOMAIN);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
380acbbe9da7dc2cbab5b6db169ec6968dd927faGordon Ross /* Avoid interfering with DC discovery. */
380acbbe9da7dc2cbab5b6db169ec6968dd927faGordon Ross if (smb_ddiscover_wait() != 0 ||
380acbbe9da7dc2cbab5b6db169ec6968dd927faGordon Ross !smb_domain_getinfo(&di)) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_invalidate_chain();
dc20a3024900c47dd2ee44b9707e6df38f7d62a5as return (NT_STATUS_CANT_ACCESS_DOMAIN_INFO);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw do {
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross if (netr_open(di.d_dci.dc_name, di.d_primary.di_nbname,
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross &netr_handle) != 0)
b1352070d318187b41b088da3533692976f3f225Alan Wright return (NT_STATUS_OPEN_FAILED);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross if (di.d_dci.dc_name[0] != '\0' &&
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross (*netr_global_info.server != '\0')) {
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego (void) snprintf(server, sizeof (server),
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross "\\\\%s", di.d_dci.dc_name);
1fdeec650620e8498c06f832ea4bd2292f7e9632joyce mcintosh if (strncasecmp(netr_global_info.server,
1fdeec650620e8498c06f832ea4bd2292f7e9632joyce mcintosh server, strlen(server)) != 0)
1fdeec650620e8498c06f832ea4bd2292f7e9632joyce mcintosh netr_invalidate_chain();
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego }
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego
1fdeec650620e8498c06f832ea4bd2292f7e9632joyce mcintosh if ((netr_global_info.flags & NETR_FLG_VALID) == 0 ||
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb !smb_match_netlogon_seqnum()) {
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross status = netlogon_auth(di.d_dci.dc_name, &netr_handle,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw NETR_FLG_NULL);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (status != 0) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) netr_close(&netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_LOGON_FAILURE);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_global_info.flags |= NETR_FLG_VALID;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw status = netr_server_samlogon(&netr_handle,
b3700b074e637f8c6991b70754c88a2cfffb246bGordon Ross &netr_global_info, di.d_dci.dc_name, user_info, token);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) netr_close(&netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } while (status == NT_STATUS_INSUFFICIENT_LOGON_INFO && retries++ < 3);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (retries >= 3)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw status = NT_STATUS_LOGON_FAILURE;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (status);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesnetr_setup_token(struct netr_validation_info3 *info3, smb_logon_t *user_info,
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego netr_info_t *netr_info, smb_token_t *token)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw char *username, *domain;
8c10a8659ac31335ed870a1711c0182623f72fd6as unsigned char rc4key[SMBAUTH_SESSION_KEY_SZ];
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_sid_t *domsid;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t status;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego char nbdomain[NETBIOS_NAME_SZ];
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego domsid = (smb_sid_t *)info3->LogonDomainId;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego token->tkn_user.i_sid = smb_sid_splice(domsid, info3->UserId);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (token->tkn_user.i_sid == NULL)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_NO_MEMORY);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego token->tkn_primary_grp.i_sid = smb_sid_splice(domsid,
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego info3->PrimaryGroupId);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (token->tkn_primary_grp.i_sid == NULL)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_NO_MEMORY);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw username = (info3->EffectiveName.str)
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ? (char *)info3->EffectiveName.str : user_info->lg_e_username;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (info3->LogonDomainName.str) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego domain = (char *)info3->LogonDomainName.str;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States } else if (*user_info->lg_e_domain != '\0') {
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States domain = user_info->lg_e_domain;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego } else {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego (void) smb_getdomainname(nbdomain, sizeof (nbdomain));
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego domain = nbdomain;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (username)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego token->tkn_account_name = strdup(username);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (domain)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego token->tkn_domain_name = strdup(domain);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (token->tkn_account_name == NULL || token->tkn_domain_name == NULL)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_NO_MEMORY);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego status = netr_setup_token_wingrps(info3, token);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (status != NT_STATUS_SUCCESS)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (status);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
8c10a8659ac31335ed870a1711c0182623f72fd6as /*
8c10a8659ac31335ed870a1711c0182623f72fd6as * The UserSessionKey in NetrSamLogon RPC is obfuscated using the
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego * session key obtained in the NETLOGON credential chain.
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego * An 8 byte session key is zero extended to 16 bytes. This 16 byte
8c10a8659ac31335ed870a1711c0182623f72fd6as * key is the key to the RC4 algorithm. The RC4 byte stream is
8c10a8659ac31335ed870a1711c0182623f72fd6as * exclusively ored with the 16 byte UserSessionKey to recover
8c10a8659ac31335ed870a1711c0182623f72fd6as * the the clear form.
8c10a8659ac31335ed870a1711c0182623f72fd6as */
12b65585e720714b31036daaa2b30eb76014048eGordon Ross if ((token->tkn_ssnkey.val = malloc(SMBAUTH_SESSION_KEY_SZ)) == NULL)
8c10a8659ac31335ed870a1711c0182623f72fd6as return (NT_STATUS_NO_MEMORY);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross token->tkn_ssnkey.len = SMBAUTH_SESSION_KEY_SZ;
8c10a8659ac31335ed870a1711c0182623f72fd6as bzero(rc4key, SMBAUTH_SESSION_KEY_SZ);
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego bcopy(netr_info->session_key.key, rc4key, netr_info->session_key.len);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross bcopy(info3->UserSessionKey.data, token->tkn_ssnkey.val,
8c10a8659ac31335ed870a1711c0182623f72fd6as SMBAUTH_SESSION_KEY_SZ);
12b65585e720714b31036daaa2b30eb76014048eGordon Ross rand_hash((unsigned char *)token->tkn_ssnkey.val,
8c10a8659ac31335ed870a1711c0182623f72fd6as SMBAUTH_SESSION_KEY_SZ, rc4key, SMBAUTH_SESSION_KEY_SZ);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_SUCCESS);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_server_samlogon
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NetrServerSamLogon RPC: interactive or network. It is assumed that
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * we have already authenticated with the PDC. If everything works,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * we build a user info structure and return it, where the caller will
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * probably build an access token.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Returns an NT status. There are numerous possibilities here.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * For example:
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_INVALID_INFO_CLASS
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_INVALID_PARAMETER
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_ACCESS_DENIED
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_PASSWORD_MUST_CHANGE
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_NO_SUCH_USER
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_WRONG_PASSWORD
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_LOGON_FAILURE
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_ACCOUNT_RESTRICTION
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_INVALID_LOGON_HOURS
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_INVALID_WORKSTATION
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_INTERNAL_ERROR
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_PASSWORD_EXPIRED
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NT_STATUS_ACCOUNT_DISABLED
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
7f667e74610492ddbce8ce60f52ece95d2401949jose borregouint32_t
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwnetr_server_samlogon(mlsvc_handle_t *netr_handle, netr_info_t *netr_info,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States char *server, smb_logon_t *user_info, smb_token_t *token)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_SamLogon arg;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_authenticator auth;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_authenticator ret_auth;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_logon_info1 info1;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_logon_info2 info2;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_validation_info3 *info3;
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_heap_t *heap;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw int opnum;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw int rc, len;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t status;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(&arg, sizeof (struct netr_SamLogon));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw opnum = NETR_OPNUM_SamLogon;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Should we get the server and hostname from netr_info?
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
8d7e41661dc4633488e93b13363137523ce59977jose borrego
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw len = strlen(server) + 4;
8d7e41661dc4633488e93b13363137523ce59977jose borrego arg.servername = ndr_rpc_malloc(netr_handle, len);
8d7e41661dc4633488e93b13363137523ce59977jose borrego arg.hostname = ndr_rpc_malloc(netr_handle, NETBIOS_NAME_SZ);
8d7e41661dc4633488e93b13363137523ce59977jose borrego if (arg.servername == NULL || arg.hostname == NULL) {
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
8d7e41661dc4633488e93b13363137523ce59977jose borrego return (NT_STATUS_INTERNAL_ERROR);
8d7e41661dc4633488e93b13363137523ce59977jose borrego }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
8d7e41661dc4633488e93b13363137523ce59977jose borrego (void) snprintf((char *)arg.servername, len, "\\\\%s", server);
8d7e41661dc4633488e93b13363137523ce59977jose borrego if (smb_getnetbiosname((char *)arg.hostname, NETBIOS_NAME_SZ) != 0) {
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_INTERNAL_ERROR);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw rc = netr_setup_authenticator(netr_info, &auth, &ret_auth);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (rc != SMBAUTH_SUCCESS) {
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_INTERNAL_ERROR);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw arg.auth = &auth;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw arg.ret_auth = &ret_auth;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw arg.validation_level = NETR_VALIDATION_LEVEL3;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States arg.logon_info.logon_level = user_info->lg_level;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States arg.logon_info.switch_value = user_info->lg_level;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
8d7e41661dc4633488e93b13363137523ce59977jose borrego heap = ndr_rpc_get_heap(netr_handle);
8d7e41661dc4633488e93b13363137523ce59977jose borrego
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States switch (user_info->lg_level) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw case NETR_INTERACTIVE_LOGON:
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netr_setup_identity(heap, user_info, &info1.identity);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netr_interactive_samlogon(netr_info, user_info, &info1);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw arg.logon_info.ru.info1 = &info1;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw break;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw case NETR_NETWORK_LOGON:
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com if (user_info->lg_challenge_key.len < 8 ||
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com user_info->lg_challenge_key.val == NULL) {
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com ndr_rpc_release(netr_handle);
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com return (NT_STATUS_INVALID_PARAMETER);
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com }
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netr_setup_identity(heap, user_info, &info2.identity);
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States netr_network_samlogon(heap, netr_info, user_info, &info2);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw arg.logon_info.ru.info2 = &info2;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw break;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw default:
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_INVALID_PARAMETER);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
8d7e41661dc4633488e93b13363137523ce59977jose borrego rc = ndr_rpc_call(netr_handle, opnum, &arg);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (rc != 0) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(netr_info, sizeof (netr_info_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw status = NT_STATUS_INVALID_PARAMETER;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } else if (arg.status != 0) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw status = NT_SC_VALUE(arg.status);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * We need to validate the chain even though we have
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * a non-zero status. If the status is ACCESS_DENIED
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * this will trigger a new credential chain. However,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * a valid credential is returned with some status
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * codes; for example, WRONG_PASSWORD.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) netr_validate_chain(netr_info, arg.ret_auth);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } else {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw status = netr_validate_chain(netr_info, arg.ret_auth);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (status == NT_STATUS_INSUFFICIENT_LOGON_INFO) {
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (status);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw info3 = arg.ru.info3;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States status = netr_setup_token(info3, user_info, netr_info, token);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
8d7e41661dc4633488e93b13363137523ce59977jose borrego ndr_rpc_release(netr_handle);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (status);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_interactive_samlogon
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Set things up for an interactive SamLogon. Copy the NT and LM
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * passwords to the logon structure and hash them with the session
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * key.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwstatic void
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesnetr_interactive_samlogon(netr_info_t *netr_info, smb_logon_t *user_info,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_logon_info1 *info1)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw BYTE key[NETR_OWF_PASSWORD_SZ];
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) memcpy(&info1->lm_owf_password,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_lm_password.val, sizeof (netr_owf_password_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) memcpy(&info1->nt_owf_password,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_nt_password.val, sizeof (netr_owf_password_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (void) memset(key, 0, NETR_OWF_PASSWORD_SZ);
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego (void) memcpy(key, netr_info->session_key.key,
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego netr_info->session_key.len);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw rand_hash((unsigned char *)&info1->lm_owf_password,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw NETR_OWF_PASSWORD_SZ, key, NETR_OWF_PASSWORD_SZ);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw rand_hash((unsigned char *)&info1->nt_owf_password,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw NETR_OWF_PASSWORD_SZ, key, NETR_OWF_PASSWORD_SZ);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_network_samlogon
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Set things up for a network SamLogon. We provide a copy of the random
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * challenge, that we sent to the client, to the domain controller. This
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * is the key that the client will have used to encrypt the NT and LM
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * passwords. Note that Windows 9x clients may not provide both passwords.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*ARGSUSED*/
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwstatic void
8d7e41661dc4633488e93b13363137523ce59977jose borregonetr_network_samlogon(ndr_heap_t *heap, netr_info_t *netr_info,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States smb_logon_t *user_info, struct netr_logon_info2 *info2)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego uint32_t len;
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com if (user_info->lg_challenge_key.len >= 8 &&
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com user_info->lg_challenge_key.val != 0) {
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com bcopy(user_info->lg_challenge_key.val,
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com info2->lm_challenge.data, 8);
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com } else {
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com bzero(info2->lm_challenge.data, 8);
f9bc6dadd79442185db5c8eb201c7475554fc7d7Dmitry.Savitsky@nexenta.com }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if ((len = user_info->lg_nt_password.len) != 0) {
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ndr_heap_mkvcb(heap, user_info->lg_nt_password.val, len,
8d7e41661dc4633488e93b13363137523ce59977jose borrego (ndr_vcbuf_t *)&info2->nt_response);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } else {
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego bzero(&info2->nt_response, sizeof (netr_vcbuf_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States if ((len = user_info->lg_lm_password.len) != 0) {
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ndr_heap_mkvcb(heap, user_info->lg_lm_password.val, len,
8d7e41661dc4633488e93b13363137523ce59977jose borrego (ndr_vcbuf_t *)&info2->lm_response);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } else {
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego bzero(&info2->lm_response, sizeof (netr_vcbuf_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_setup_authenticator
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Set up the request and return authenticators. A new credential is
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * generated from the session key, the current client credential and
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * the current time, i.e.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NewCredential = Cred(SessionKey, OldCredential, time);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * The timestamp, which is used as a random seed, is stored in both
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * the request and return authenticators.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * If any difficulties occur using the cryptographic framework, the
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * function returns SMBAUTH_FAILURE. Otherwise SMBAUTH_SUCCESS is
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * returned.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwint
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwnetr_setup_authenticator(netr_info_t *netr_info,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw struct netr_authenticator *auth, struct netr_authenticator *ret_auth)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(auth, sizeof (struct netr_authenticator));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
55bf511df53aad0fdb7eb3fa349f0308cc05234cas netr_info->timestamp = time(0);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw auth->timestamp = netr_info->timestamp;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego if (netr_gen_credentials(netr_info->session_key.key,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw &netr_info->client_credential,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_info->timestamp,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw (netr_cred_t *)&auth->credential) != SMBAUTH_SUCCESS)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (SMBAUTH_FAILURE);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (ret_auth) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(ret_auth, sizeof (struct netr_authenticator));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw ret_auth->timestamp = netr_info->timestamp;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (SMBAUTH_SUCCESS);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Validate the returned credentials and update the credential chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * The server returns an updated client credential rather than a new
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * server credential. The server uses (timestamp + 1) when generating
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * the credential.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Generate the new seed for the credential chain. The new seed is
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * formed by adding (timestamp + 1) to the current client credential.
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * The only quirk is the uint32_t style addition.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Returns NT_STATUS_INSUFFICIENT_LOGON_INFO if auth->credential is a
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * NULL pointer. The Authenticator field of the SamLogon response packet
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * sent by the Samba 3 PDC always return NULL pointer if the received
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * SamLogon request is not immediately followed by the ServerReqChallenge
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * and ServerAuthenticate2 requests.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Returns NT_STATUS_SUCCESS if the server returned a valid credential.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Otherwise we retirm NT_STATUS_UNSUCCESSFUL.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
7f667e74610492ddbce8ce60f52ece95d2401949jose borregouint32_t
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwnetr_validate_chain(netr_info_t *netr_info, struct netr_authenticator *auth)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_cred_t cred;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t result = NT_STATUS_SUCCESS;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t *dwp;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw ++netr_info->timestamp;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
2c1b14e51525da2c09064641416fc4aed457c72fjose borrego if (netr_gen_credentials(netr_info->session_key.key,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw &netr_info->client_credential,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_info->timestamp, &cred) != SMBAUTH_SUCCESS)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_INTERNAL_ERROR);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (&auth->credential == 0) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * If the validation fails, destroy the credential chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * This should trigger a new authentication chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(netr_info, sizeof (netr_info_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (NT_STATUS_INSUFFICIENT_LOGON_INFO);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw result = memcmp(&cred, &auth->credential, sizeof (netr_cred_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (result != 0) {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * If the validation fails, destroy the credential chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * This should trigger a new authentication chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw bzero(netr_info, sizeof (netr_info_t));
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw result = NT_STATUS_UNSUCCESSFUL;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw } else {
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Otherwise generate the next step in the chain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*LINTED E_BAD_PTR_CAST_ALIGN*/
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego dwp = (uint32_t *)&netr_info->client_credential;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw dwp[0] += netr_info->timestamp;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_info->flags |= NETR_FLG_VALID;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw }
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw return (result);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_invalidate_chain
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Mark the credential chain as invalid so that it will be recreated
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * on the next attempt.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwstatic void
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwnetr_invalidate_chain(void)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_global_info.flags &= ~NETR_FLG_VALID;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw/*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * netr_setup_identity
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Set up the client identity information. All of this information is
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * specifically related to the client user and workstation attempting
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * to access this system. It may not be in our primary domain.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw *
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * I don't know what logon_id is, it seems to be a unique identifier.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Increment it before each use.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amwstatic void
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United Statesnetr_setup_identity(ndr_heap_t *heap, smb_logon_t *user_info,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw netr_logon_id_t *identity)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw{
8d7e41661dc4633488e93b13363137523ce59977jose borrego static mutex_t logon_id_mutex;
8d7e41661dc4633488e93b13363137523ce59977jose borrego static uint32_t logon_id;
8d7e41661dc4633488e93b13363137523ce59977jose borrego
8d7e41661dc4633488e93b13363137523ce59977jose borrego (void) mutex_lock(&logon_id_mutex);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw if (logon_id == 0)
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw logon_id = 0xDCD0;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw ++logon_id;
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States user_info->lg_logon_id = logon_id;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
8d7e41661dc4633488e93b13363137523ce59977jose borrego (void) mutex_unlock(&logon_id_mutex);
8d7e41661dc4633488e93b13363137523ce59977jose borrego
12b65585e720714b31036daaa2b30eb76014048eGordon Ross /*
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * [MS-APDS] 3.1.5.2 "NTLM Network Logon" says to set
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * ParameterControl to the 'E' + 'K' bits. Those are:
12b65585e720714b31036daaa2b30eb76014048eGordon Ross * (1 << 5) | (1 << 11), a.k.a
12b65585e720714b31036daaa2b30eb76014048eGordon Ross */
12b65585e720714b31036daaa2b30eb76014048eGordon Ross identity->parameter_control =
12b65585e720714b31036daaa2b30eb76014048eGordon Ross MSV1_0_ALLOW_SERVER_TRUST_ACCOUNT |
12b65585e720714b31036daaa2b30eb76014048eGordon Ross MSV1_0_ALLOW_WORKSTATION_TRUST_ACCOUNT;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw identity->logon_id.LowPart = logon_id;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw identity->logon_id.HighPart = 0;
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ndr_heap_mkvcs(heap, user_info->lg_domain,
8d7e41661dc4633488e93b13363137523ce59977jose borrego (ndr_vcstr_t *)&identity->domain_name);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ndr_heap_mkvcs(heap, user_info->lg_username,
8d7e41661dc4633488e93b13363137523ce59977jose borrego (ndr_vcstr_t *)&identity->username);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw /*
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * Some systems prefix the client workstation name with \\.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * It doesn't seem to make any difference whether it's there
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw * or not.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw */
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States ndr_heap_mkvcs(heap, user_info->lg_workstation,
8d7e41661dc4633488e93b13363137523ce59977jose borrego (ndr_vcstr_t *)&identity->workstation);
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw}
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego/*
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * Sets up domain, local and well-known group membership for the given
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * token. Two assumptions have been made here:
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego *
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * a) token already contains a valid user SID so that group
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * memberships can be established
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego *
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * b) token belongs to a domain user
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego */
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t
7f667e74610492ddbce8ce60f52ece95d2401949jose borregonetr_setup_token_wingrps(struct netr_validation_info3 *info3,
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_token_t *token)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego{
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_ids_t tkn_grps;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego uint32_t status;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego tkn_grps.i_cnt = 0;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego tkn_grps.i_ids = NULL;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego status = netr_setup_domain_groups(info3, &tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (status != NT_STATUS_SUCCESS) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_ids_free(&tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (status);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego status = smb_sam_usr_groups(token->tkn_user.i_sid, &tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (status != NT_STATUS_SUCCESS) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_ids_free(&tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (status);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
29bd28862cfb8abbd3a0f0a4b17e08bbc3652836Alan Wright if (netr_isadmin(info3))
29bd28862cfb8abbd3a0f0a4b17e08bbc3652836Alan Wright token->tkn_flags |= SMB_ATF_ADMIN;
29bd28862cfb8abbd3a0f0a4b17e08bbc3652836Alan Wright
29bd28862cfb8abbd3a0f0a4b17e08bbc3652836Alan Wright status = smb_wka_token_groups(token->tkn_flags, &tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (status == NT_STATUS_SUCCESS)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego token->tkn_win_grps = tkn_grps;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego else
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_ids_free(&tkn_grps);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (status);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego}
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego/*
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * Converts groups information in the returned structure by domain controller
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * (info3) to an internal representation (gids)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego */
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic uint32_t
7f667e74610492ddbce8ce60f52ece95d2401949jose borregonetr_setup_domain_groups(struct netr_validation_info3 *info3, smb_ids_t *gids)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego{
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_sid_t *domain_sid;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego smb_id_t *ids;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego int i, total_cnt;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if ((i = info3->GroupCount) == 0)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego i++;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego i += info3->SidCount;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego total_cnt = gids->i_cnt + i;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego gids->i_ids = realloc(gids->i_ids, total_cnt * sizeof (smb_id_t));
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (gids->i_ids == NULL)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (NT_STATUS_NO_MEMORY);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego domain_sid = (smb_sid_t *)info3->LogonDomainId;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids = gids->i_ids + gids->i_cnt;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego for (i = 0; i < info3->GroupCount; i++, gids->i_cnt++, ids++) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_sid = smb_sid_splice(domain_sid, info3->GroupIds[i].rid);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (ids->i_sid == NULL)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (NT_STATUS_NO_MEMORY);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_attrs = info3->GroupIds[i].attributes;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (info3->GroupCount == 0) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego /*
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * if there's no global group should add the primary group.
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego */
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_sid = smb_sid_splice(domain_sid, info3->PrimaryGroupId);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (ids->i_sid == NULL)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (NT_STATUS_NO_MEMORY);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_attrs = 0x7;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego gids->i_cnt++;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids++;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego /* Add the extra SIDs */
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego for (i = 0; i < info3->SidCount; i++, gids->i_cnt++, ids++) {
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_sid = smb_sid_dup((smb_sid_t *)info3->ExtraSids[i].sid);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (ids->i_sid == NULL)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (NT_STATUS_NO_MEMORY);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego ids->i_attrs = info3->ExtraSids[i].attributes;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego }
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (NT_STATUS_SUCCESS);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego}
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego/*
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * Determines if the given user is the domain Administrator or a
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego * member of Domain Admins
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego */
7f667e74610492ddbce8ce60f52ece95d2401949jose borregostatic boolean_t
7f667e74610492ddbce8ce60f52ece95d2401949jose borregonetr_isadmin(struct netr_validation_info3 *info3)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego{
a0aa776e20803c84edd153d9cb584fd67163aef3Alan Wright smb_domain_t di;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego int i;
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
a0aa776e20803c84edd153d9cb584fd67163aef3Alan Wright if (!smb_domain_lookup_sid((smb_sid_t *)info3->LogonDomainId, &di))
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (B_FALSE);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
a0aa776e20803c84edd153d9cb584fd67163aef3Alan Wright if (di.di_type != SMB_DOMAIN_PRIMARY)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (B_FALSE);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if ((info3->UserId == DOMAIN_USER_RID_ADMIN) ||
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego (info3->PrimaryGroupId == DOMAIN_GROUP_RID_ADMINS))
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (B_TRUE);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego for (i = 0; i < info3->GroupCount; i++)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego if (info3->GroupIds[i].rid == DOMAIN_GROUP_RID_ADMINS)
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (B_TRUE);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego return (B_FALSE);
7f667e74610492ddbce8ce60f52ece95d2401949jose borrego}