]> git.ipfire.org Git - thirdparty/samba.git/commitdiff
s4:auth_sam: allow logons with an empty domain name
authorStefan Metzmacher <metze@samba.org>
Tue, 9 Jan 2018 07:54:11 +0000 (08:54 +0100)
committerAndrew Bartlett <abartlet@samba.org>
Fri, 23 Feb 2018 03:08:26 +0000 (04:08 +0100)
It turns out that an empty domain name maps to the local SAM.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=13206

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
Autobuild-User(master): Andrew Bartlett <abartlet@samba.org>
Autobuild-Date(master): Fri Feb 23 04:08:26 CET 2018 on sn-devel-144

selftest/knownfail.d/empty-domain-bind [deleted file]
selftest/knownfail.d/empty-domain-samlogon [deleted file]
source4/auth/ntlm/auth_sam.c

diff --git a/selftest/knownfail.d/empty-domain-bind b/selftest/knownfail.d/empty-domain-bind
deleted file mode 100644 (file)
index 99d71c1..0000000
+++ /dev/null
@@ -1 +0,0 @@
-^samba4.ldap.bind\(fl2008r2dc\).__main__.BindTests.test_user_account_bind_no_domain.*
diff --git a/selftest/knownfail.d/empty-domain-samlogon b/selftest/knownfail.d/empty-domain-samlogon
deleted file mode 100644 (file)
index 925a03a..0000000
+++ /dev/null
@@ -1 +0,0 @@
-^samba.tests.py_credentials.samba.tests.py_credentials.PyCredentialsTests.test_SamLogonEx_no_domain
index 5e2a5843fc43a1ba576c649753495ce70a123cd7..8c5ebd747e79bd16623e5db7d7f75662c774f441 100644 (file)
@@ -739,6 +739,10 @@ static NTSTATUS authsam_want_check(struct auth_method_context *ctx,
                return NT_STATUS_NOT_IMPLEMENTED;
        }
 
+       if (effective_domain == NULL) {
+               effective_domain = "";
+       }
+
        is_local_name = lpcfg_is_myname(ctx->auth_ctx->lp_ctx,
                                        effective_domain);
 
@@ -784,7 +788,7 @@ static NTSTATUS authsam_want_check(struct auth_method_context *ctx,
                return NT_STATUS_NOT_IMPLEMENTED;
        }
 
-       if (effective_domain != NULL && !strequal(effective_domain, "")) {
+       if (!strequal(effective_domain, "")) {
                DBG_DEBUG("%s is not one domain name (DC)\n",
                          effective_domain);
                return NT_STATUS_NOT_IMPLEMENTED;
@@ -792,11 +796,11 @@ static NTSTATUS authsam_want_check(struct auth_method_context *ctx,
 
        p = strchr_m(user_info->mapped.account_name, '@');
        if (p == NULL) {
-               if (effective_domain == NULL) {
-                       return NT_STATUS_OK;
-               }
-               DEBUG(6,("authsam_check_password: '' without upn not handled (DC)\n"));
-               return NT_STATUS_NOT_IMPLEMENTED;
+               /*
+                * An empty to domain name should be handled
+                * as the local domain name.
+                */
+               return NT_STATUS_OK;
        }
 
        effective_domain = p + 1;