from __future__ import print_function
"""Tests for the Auth and AuthZ logging.
"""
-from samba import auth
import samba.tests
-from samba.messaging import Messaging
-from samba.dcerpc.messaging import MSG_AUTH_LOG, AUTH_EVENT_NAME
from samba.dcerpc import srvsvc, dnsserver
-import time
-import json
import os
from samba import smb
from samba.samdb import SamDB
import samba.tests.auth_log_base
-from samba.credentials import Credentials, DONT_USE_KERBEROS, MUST_USE_KERBEROS
+from samba.credentials import DONT_USE_KERBEROS, MUST_USE_KERBEROS
from samba import NTSTATUSError
from subprocess import call
from ldb import LdbError
+
class AuthLogTests(samba.tests.auth_log_base.AuthLogTestBase):
def setUp(self):
def tearDown(self):
super(AuthLogTests, self).tearDown()
-
-
def _test_rpc_ncacn_np(self, authTypes, creds, service,
binding, protection, checkFunction):
def isLastExpectedMessage(msg):
if service == "dnsserver":
x = dnsserver.dnsserver("ncacn_np:%s%s" % (self.server, binding),
- self.get_loadparm(),
- creds)
+ self.get_loadparm(),
+ creds)
elif service == "srvsvc":
x = srvsvc.srvsvc("ncacn_np:%s%s" % (self.server, binding),
self.get_loadparm(),
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("SMB",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[1], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[1],
+ msg["Authentication"]["authDescription"])
# Check the second message it should be an Authorization
msg = messages[1]
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertTrue(
- checkServiceDescription(msg["Authentication"]["serviceDescription"]))
+ checkServiceDescription(
+ msg["Authentication"]["serviceDescription"]))
- self.assertEquals(authTypes[3], msg["Authentication"]["authDescription"])
+ self.assertEquals(authTypes[3],
+ msg["Authentication"]["authDescription"])
- def rpc_ncacn_np_krb5_check(self, messages, authTypes, service, binding, protection):
+ def rpc_ncacn_np_krb5_check(
+ self,
+ messages,
+ authTypes,
+ service,
+ binding,
+ protection):
expected_messages = len(authTypes)
self.assertEquals(expected_messages,
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[1], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[1],
+ msg["Authentication"]["authDescription"])
# Check the second message it should be an Authentication
# This this the TCP Authentication in response to the message too big
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[2], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[2],
+ msg["Authentication"]["authDescription"])
# Check the third message it should be an Authorization
msg = messages[2]
self.assertEquals("SMB", msg["Authorization"]["transportProtection"])
self.assertTrue(self.is_guid(msg["Authorization"]["sessionId"]))
-
def test_rpc_ncacn_np_ntlm_dns_sign(self):
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=DONT_USE_KERBEROS)
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication",
"krb5"],
- creds, "dnsserver", "sign", "SIGN",
- self.rpc_ncacn_np_krb5_check)
+ creds, "dnsserver", "sign", "SIGN",
+ self.rpc_ncacn_np_krb5_check)
def test_rpc_ncacn_np_krb_srv_sign(self):
creds = self.insta_creds(template=self.get_credentials(),
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication",
"krb5"],
- creds, "srvsvc", "sign", "SIGN",
- self.rpc_ncacn_np_krb5_check)
+ creds, "srvsvc", "sign", "SIGN",
+ self.rpc_ncacn_np_krb5_check)
def test_rpc_ncacn_np_krb_dns(self):
creds = self.insta_creds(template=self.get_credentials(),
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=MUST_USE_KERBEROS)
self._test_rpc_ncacn_np(["ncacn_np",
- "ENC-TS Pre-authentication",
- "ENC-TS Pre-authentication",
- "krb5"],
+ "ENC-TS Pre-authentication",
+ "ENC-TS Pre-authentication",
+ "krb5"],
creds, "srvsvc", "", "SMB",
self.rpc_ncacn_np_krb5_check)
binding = "[%s]" % binding
if service == "dnsserver":
- conn = dnsserver.dnsserver("ncacn_ip_tcp:%s%s" % (self.server, binding),
- self.get_loadparm(),
- creds)
+ conn = dnsserver.dnsserver(
+ "ncacn_ip_tcp:%s%s" % (self.server, binding),
+ self.get_loadparm(),
+ creds)
elif service == "srvsvc":
conn = srvsvc.srvsvc("ncacn_ip_tcp:%s%s" % (self.server, binding),
self.get_loadparm(),
creds)
-
messages = self.waitForMessages(isLastExpectedMessage, conn)
checkFunction(messages, authTypes, service, binding, protection)
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("DCE/RPC",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[2], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[2],
+ msg["Authentication"]["authDescription"])
def rpc_ncacn_ip_tcp_krb5_check(self, messages, authTypes, service,
binding, protection):
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[2], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[2],
+ msg["Authentication"]["authDescription"])
# Check the third message it should be an Authentication
msg = messages[2]
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
- self.assertEquals(authTypes[2], msg["Authentication"]["authDescription"])
+ msg["Authentication"]["serviceDescription"])
+ self.assertEquals(authTypes[2],
+ msg["Authentication"]["authDescription"])
def test_rpc_ncacn_ip_tcp_ntlm_dns_sign(self):
creds = self.insta_creds(template=self.get_credentials(),
self._test_rpc_ncacn_ip_tcp(["NTLMSSP",
"ncacn_ip_tcp",
"NTLMSSP"],
- creds, "dnsserver", "sign", "SIGN",
- self.rpc_ncacn_ip_tcp_ntlm_check)
+ creds, "dnsserver", "sign", "SIGN",
+ self.rpc_ncacn_ip_tcp_ntlm_check)
def test_rpc_ncacn_ip_tcp_krb5_dns_sign(self):
creds = self.insta_creds(template=self.get_credentials(),
"ncacn_ip_tcp",
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication"],
- creds, "dnsserver", "sign", "SIGN",
- self.rpc_ncacn_ip_tcp_krb5_check)
+ creds, "dnsserver", "sign", "SIGN",
+ self.rpc_ncacn_ip_tcp_krb5_check)
def test_rpc_ncacn_ip_tcp_ntlm_dns(self):
creds = self.insta_creds(template=self.get_credentials(),
self._test_rpc_ncacn_ip_tcp(["NTLMSSP",
"ncacn_ip_tcp",
"NTLMSSP"],
- creds, "dnsserver", "", "SIGN",
- self.rpc_ncacn_ip_tcp_ntlm_check)
+ creds, "dnsserver", "", "SIGN",
+ self.rpc_ncacn_ip_tcp_ntlm_check)
def test_rpc_ncacn_ip_tcp_krb5_dns(self):
creds = self.insta_creds(template=self.get_credentials(),
"ncacn_ip_tcp",
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication"],
- creds, "dnsserver", "", "SIGN",
- self.rpc_ncacn_ip_tcp_krb5_check)
+ creds, "dnsserver", "", "SIGN",
+ self.rpc_ncacn_ip_tcp_krb5_check)
def test_rpc_ncacn_ip_tcp_ntlm_dns_connect(self):
creds = self.insta_creds(template=self.get_credentials(),
self._test_rpc_ncacn_ip_tcp(["NTLMSSP",
"ncacn_ip_tcp",
"NTLMSSP"],
- creds, "dnsserver", "connect", "NONE",
- self.rpc_ncacn_ip_tcp_ntlm_check)
+ creds, "dnsserver", "connect", "NONE",
+ self.rpc_ncacn_ip_tcp_ntlm_check)
def test_rpc_ncacn_ip_tcp_krb5_dns_connect(self):
creds = self.insta_creds(template=self.get_credentials(),
"ncacn_ip_tcp",
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication"],
- creds, "dnsserver", "connect", "NONE",
- self.rpc_ncacn_ip_tcp_krb5_check)
+ creds, "dnsserver", "connect", "NONE",
+ self.rpc_ncacn_ip_tcp_krb5_check)
def test_rpc_ncacn_ip_tcp_ntlm_dns_seal(self):
creds = self.insta_creds(template=self.get_credentials(),
self._test_rpc_ncacn_ip_tcp(["NTLMSSP",
"ncacn_ip_tcp",
"NTLMSSP"],
- creds, "dnsserver", "seal", "SEAL",
- self.rpc_ncacn_ip_tcp_ntlm_check)
+ creds, "dnsserver", "seal", "SEAL",
+ self.rpc_ncacn_ip_tcp_ntlm_check)
def test_rpc_ncacn_ip_tcp_krb5_dns_seal(self):
creds = self.insta_creds(template=self.get_credentials(),
"ncacn_ip_tcp",
"ENC-TS Pre-authentication",
"ENC-TS Pre-authentication"],
- creds, "dnsserver", "seal", "SEAL",
- self.rpc_ncacn_ip_tcp_krb5_check)
+ creds, "dnsserver", "seal", "SEAL",
+ self.rpc_ncacn_ip_tcp_krb5_check)
def test_ldap(self):
msg["Authorization"]["authType"] == "krb5")
self.samdb = SamDB(url="ldap://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=self.get_credentials())
messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("ENC-TS Pre-authentication",
- msg["Authentication"]["authDescription"])
+ msg["Authentication"]["authDescription"])
- # Check the first message it should be an Authentication
+ # Check the second message it should be an Authentication
msg = messages[1]
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("ENC-TS Pre-authentication",
- msg["Authentication"]["authDescription"])
+ msg["Authentication"]["authDescription"])
def test_ldap_ntlm(self):
msg["Authorization"]["authType"] == "NTLMSSP")
self.samdb = SamDB(url="ldap://%s" % os.environ["SERVER_IP"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=self.get_credentials())
messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("LDAP",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("NTLMSSP", msg["Authentication"]["authDescription"])
def test_ldap_simple_bind(self):
creds = self.insta_creds(template=self.get_credentials())
creds.set_bind_dn("%s\\%s" % (creds.get_domain(),
- creds.get_username()))
+ creds.get_username()))
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("LDAP",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("simple bind",
- msg["Authentication"]["authDescription"])
+ msg["Authentication"]["authDescription"])
def test_ldap_simple_bind_bad_password(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
msg["Authentication"]["serviceDescription"] == "LDAP" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
msg["Authentication"]["authDescription"] == "simple bind")
creds = self.insta_creds(template=self.get_credentials())
creds.set_password("badPassword")
creds.set_bind_dn("%s\\%s" % (creds.get_domain(),
- creds.get_username()))
+ creds.get_username()))
thrown = False
try:
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
except LdbError:
thrown = True
len(messages),
"Did not receive the expected number of messages")
-
def test_ldap_simple_bind_bad_user(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
msg["Authentication"]["serviceDescription"] == "LDAP" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
msg["Authentication"]["authDescription"] == "simple bind")
creds = self.insta_creds(template=self.get_credentials())
thrown = False
try:
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
except LdbError:
thrown = True
len(messages),
"Did not receive the expected number of messages")
-
def test_ldap_simple_bind_unparseable_user(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
msg["Authentication"]["serviceDescription"] == "LDAP" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
msg["Authentication"]["authDescription"] == "simple bind")
creds = self.insta_creds(template=self.get_credentials())
thrown = False
try:
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
except LdbError:
thrown = True
def test_ldap_anonymous_access_bind_only(self):
# Should be no logging for anonymous bind
# so receiving any message indicates a failure.
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return True
creds = self.insta_creds(template=self.get_credentials())
creds.set_anonymous()
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals(0,
len(messages),
"Did not receive the expected number of messages")
def test_ldap_anonymous_access(self):
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authorization" and
msg["Authorization"]["serviceDescription"] == "LDAP" and
msg["Authorization"]["transportProtection"] == "TLS" and
creds.set_anonymous()
self.samdb = SamDB(url="ldaps://%s" % os.environ["SERVER"],
- lp = self.get_loadparm(),
+ lp=self.get_loadparm(),
credentials=creds)
try:
- res = self.samdb.search(base=self.samdb.domain_dn())
- self.fail( "Expected an LdbError exception")
+ self.samdb.search(base=self.samdb.domain_dn())
+ self.fail("Expected an LdbError exception")
except LdbError:
pass
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals(1,
len(messages),
"Did not receive the expected number of messages")
+
def test_smb(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authorization" and
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("ENC-TS Pre-authentication",
- msg["Authentication"]["authDescription"])
+ msg["Authentication"]["authDescription"])
# Check the second message it should be an Authentication
msg = messages[1]
self.assertEquals("Authentication", msg["type"])
self.assertEquals("NT_STATUS_OK", msg["Authentication"]["status"])
self.assertEquals("Kerberos KDC",
- msg["Authentication"]["serviceDescription"])
+ msg["Authentication"]["serviceDescription"])
self.assertEquals("ENC-TS Pre-authentication",
- msg["Authentication"]["authDescription"])
+ msg["Authentication"]["authDescription"])
def test_smb_bad_password(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "Kerberos KDC" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["authDescription"]
- == "ENC-TS Pre-authentication")
+ (msg["Authentication"]["serviceDescription"] ==
+ "Kerberos KDC") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["authDescription"] ==
+ "ENC-TS Pre-authentication"))
creds = self.insta_creds(template=self.get_credentials())
creds.set_password("badPassword")
len(messages),
"Did not receive the expected number of messages")
-
def test_smb_bad_user(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "Kerberos KDC" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
- msg["Authentication"]["authDescription"]
- == "ENC-TS Pre-authentication")
+ (msg["Authentication"]["serviceDescription"] ==
+ "Kerberos KDC") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
+ (msg["Authentication"]["authDescription"] ==
+ "ENC-TS Pre-authentication"))
creds = self.insta_creds(template=self.get_credentials())
creds.set_username("badUser")
msg["Authentication"]["serviceDescription"] == "SMB" and
msg["Authentication"]["authDescription"] == "NTLMSSP" and
msg["Authentication"]["passwordType"] == "NTLMv2" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD")
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD"))
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=DONT_USE_KERBEROS)
msg["Authentication"]["serviceDescription"] == "SMB" and
msg["Authentication"]["authDescription"] == "NTLMSSP" and
msg["Authentication"]["passwordType"] == "NTLMv2" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER")
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER"))
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=DONT_USE_KERBEROS)
msg["Authentication"]["serviceDescription"] == "SMB" and
msg["Authentication"]["authDescription"] == "bare-NTLM" and
msg["Authentication"]["passwordType"] == "NTLMv1" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD")
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD"))
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=DONT_USE_KERBEROS)
thrown = True
self.assertEquals(thrown, True)
-
messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals(1,
len(messages),
msg["Authentication"]["serviceDescription"] == "SMB" and
msg["Authentication"]["authDescription"] == "bare-NTLM" and
msg["Authentication"]["passwordType"] == "NTLMv1" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER")
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER"))
creds = self.insta_creds(template=self.get_credentials(),
kerberos_state=DONT_USE_KERBEROS)
thrown = True
self.assertEquals(thrown, True)
-
messages = self.waitForMessages(isLastExpectedMessage)
self.assertEquals(1,
len(messages),
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "interactive" and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] ==
+ "interactive") and
msg["Authentication"]["status"] == "NT_STATUS_OK" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = os.environ["PASSWORD"]
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 1)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "interactive" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] ==
+ "interactive") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = "badPassword"
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 1)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "interactive" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] ==
+ "interactive") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = "badUser"
password = os.environ["PASSWORD"]
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 1)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ msg["Authentication"]["authDescription"] == "network" and
msg["Authentication"]["status"] == "NT_STATUS_OK" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = os.environ["PASSWORD"]
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 2)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
+ def isLastExpectedMessage(msg):
return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ msg["Authentication"]["authDescription"] == "network" and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = "badPassword"
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 2)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = "badUser"
- password = os.environ["PASSWORD"]
+ password = os.environ["PASSWORD"]
samlogon = "samlogon %s %s %s %d" % (user, password, workstation, 2)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"] == "NT_STATUS_OK" and
- msg["Authentication"]["passwordType"] == "MSCHAPv2" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] == "NT_STATUS_OK") and
+ (msg["Authentication"]["passwordType"] == "MSCHAPv2") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = os.environ["PASSWORD"]
- samlogon = "samlogon %s %s %s %d 0x00010000" % (user, password, workstation, 2)
-
+ samlogon = "samlogon %s %s %s %d 0x00010000" % (
+ user, password, workstation, 2)
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["passwordType"] == "MSCHAPv2" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["passwordType"] == "MSCHAPv2") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = "badPassword"
- samlogon = "samlogon %s %s %s %d 0x00010000" % (user, password, workstation, 2)
-
+ samlogon = "samlogon %s %s %s %d 0x00010000" % (
+ user, password, workstation, 2)
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
- msg["Authentication"]["passwordType"] == "MSCHAPv2" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
+ (msg["Authentication"]["passwordType"] == "MSCHAPv2") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = "badUser"
password = os.environ["PASSWORD"]
- samlogon = "samlogon %s %s %s %d 0x00010000" % (user, password, workstation, 2)
-
+ samlogon = "samlogon %s %s %s %d 0x00010000" % (
+ user, password, workstation, 2)
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"] == "NT_STATUS_OK" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] == "NT_STATUS_OK") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = os.environ["PASSWORD"]
samlogon = "schannel;samlogon %s %s %s" % (user, password, workstation)
-
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
msg["Authorization"]["serviceDescription"])
self.assertEquals("schannel", msg["Authorization"]["authType"])
self.assertEquals("SEAL", msg["Authorization"]["transportProtection"])
+ self.assertTrue(self.is_guid(msg["Authorization"]["sessionId"]))
# Signed logons get promoted to sealed, this test ensures that
- # this behaviour is not removed accidently
+ # this behaviour is not removed accidentally
def test_samlogon_schannel_sign(self):
workstation = "AuthLogTests"
- def isLastExpectedMessage( msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SamLogon" and
- msg["Authentication"]["authDescription"]
- == "network" and
- msg["Authentication"]["status"] == "NT_STATUS_OK" and
- msg["Authentication"]["workstation"]
- == r"\\%s" % workstation)
+ def isLastExpectedMessage(msg):
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SamLogon") and
+ (msg["Authentication"]["authDescription"] == "network") and
+ (msg["Authentication"]["status"] == "NT_STATUS_OK") and
+ (msg["Authentication"]["workstation"] ==
+ r"\\%s" % workstation))
server = os.environ["SERVER"]
user = os.environ["USERNAME"]
password = os.environ["PASSWORD"]
- samlogon = "schannelsign;samlogon %s %s %s" % (user, password, workstation)
-
+ samlogon = "schannelsign;samlogon %s %s %s" % (
+ user, password, workstation)
call(["bin/rpcclient", "-c", samlogon, "-U%", server])
- messages = self.waitForMessages( isLastExpectedMessage)
+ messages = self.waitForMessages(isLastExpectedMessage)
messages = self.remove_netlogon_messages(messages)
received = len(messages)
self.assertIs(True,
"""Tests for the Auth and AuthZ logging of password changes.
"""
-from samba import auth
import samba.tests
-from samba.messaging import Messaging
from samba.samdb import SamDB
from samba.auth import system_session
-import json
import os
import samba.tests.auth_log_base
from samba.tests import delete_force
from samba.net import Net
-from samba import ntstatus
import samba
from subprocess import call
from ldb import LdbError
USER_NAME = "authlogtestuser"
-USER_PASS = samba.generate_random_password(32,32)
+USER_PASS = samba.generate_random_password(32, 32)
+
class AuthLogPassChangeTests(samba.tests.auth_log_base.AuthLogTestBase):
base_dn = self.ldb.domain_dn()
print("base_dn %s" % base_dn)
- # Gets back the configuration basedn
- configuration_dn = self.ldb.get_config_basedn().get_linearized()
-
# Get the old "dSHeuristics" if it was set
dsheuristics = self.ldb.get_dsheuristics()
# (Re)adds the test user USER_NAME with password USER_PASS
delete_force(self.ldb, "cn=" + USER_NAME + ",cn=users," + self.base_dn)
self.ldb.add({
- "dn": "cn=" + USER_NAME + ",cn=users," + self.base_dn,
- "objectclass": "user",
- "sAMAccountName": USER_NAME,
- "userPassword": USER_PASS
+ "dn": "cn=" + USER_NAME + ",cn=users," + self.base_dn,
+ "objectclass": "user",
+ "sAMAccountName": USER_NAME,
+ "userPassword": USER_PASS
})
# discard any auth log messages for the password setup
def tearDown(self):
super(AuthLogPassChangeTests, self).tearDown()
-
def test_admin_change_password(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_OK" and
- msg["Authentication"]["serviceDescription"]
- == "SAMR Password Change" and
- msg["Authentication"]["authDescription"]
- == "samr_ChangePasswordUser3")
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] == "NT_STATUS_OK") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SAMR Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "samr_ChangePasswordUser3"))
- creds = self.insta_creds(template = self.get_credentials())
+ creds = self.insta_creds(template=self.get_credentials())
lp = self.get_loadparm()
net = Net(creds, lp, server=self.server_ip)
username=USER_NAME,
oldpassword=USER_PASS)
-
messages = self.waitForMessages(isLastExpectedMessage)
print("Received %d messages" % len(messages))
self.assertEquals(8,
def test_admin_change_password_new_password_fails_restriction(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_PASSWORD_RESTRICTION" and
- msg["Authentication"]["serviceDescription"]
- == "SAMR Password Change" and
- msg["Authentication"]["authDescription"]
- == "samr_ChangePasswordUser3")
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_PASSWORD_RESTRICTION") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SAMR Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "samr_ChangePasswordUser3"))
creds = self.insta_creds(template=self.get_credentials())
net.change_password(newpassword=password.encode('utf-8'),
oldpassword=USER_PASS,
username=USER_NAME)
- except Exception as msg:
+ except Exception:
exception_thrown = True
self.assertEquals(True, exception_thrown,
"Expected exception not thrown")
def test_admin_change_password_unknown_user(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_NO_SUCH_USER" and
- msg["Authentication"]["serviceDescription"]
- == "SAMR Password Change" and
- msg["Authentication"]["authDescription"]
- == "samr_ChangePasswordUser3")
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_NO_SUCH_USER") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SAMR Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "samr_ChangePasswordUser3"))
creds = self.insta_creds(template=self.get_credentials())
net.change_password(newpassword=password.encode('utf-8'),
oldpassword=USER_PASS,
username="badUser")
- except Exception as msg:
+ except Exception:
exception_thrown = True
self.assertEquals(True, exception_thrown,
"Expected exception not thrown")
def test_admin_change_password_bad_original_password(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["serviceDescription"]
- == "SAMR Password Change" and
- msg["Authentication"]["authDescription"]
- == "samr_ChangePasswordUser3")
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SAMR Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "samr_ChangePasswordUser3"))
creds = self.insta_creds(template=self.get_credentials())
net.change_password(newpassword=password.encode('utf-8'),
oldpassword="badPassword",
username=USER_NAME)
- except Exception as msg:
+ except Exception:
exception_thrown = True
self.assertEquals(True, exception_thrown,
"Expected exception not thrown")
# correctly, so we just check it triggers the wrong password path.
def test_rap_change_password(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["serviceDescription"]
- == "SAMR Password Change" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["authDescription"]
- == "OemChangePasswordUser2")
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "SAMR Password Change") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["authDescription"] ==
+ "OemChangePasswordUser2"))
username = os.environ["USERNAME"]
server = os.environ["SERVER"]
password = os.environ["PASSWORD"]
server_param = "--server=%s" % server
- creds = "-U%s%%%s" % (username,password)
+ creds = "-U%s%%%s" % (username, password)
call(["bin/net", "rap", server_param,
"password", USER_NAME, "notMyPassword", "notGoingToBeMyPassword",
server, creds, "--option=client ipc max protocol=nt1"])
def test_ldap_change_password(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_OK" and
- msg["Authentication"]["serviceDescription"]
- == "LDAP Password Change" and
- msg["Authentication"]["authDescription"]
- == "LDAP Modify")
-
- new_password = samba.generate_random_password(32,32)
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] == "NT_STATUS_OK") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "LDAP Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "LDAP Modify"))
+
+ new_password = samba.generate_random_password(32, 32)
self.ldb.modify_ldif(
"dn: cn=" + USER_NAME + ",cn=users," + self.base_dn + "\n" +
"changetype: modify\n" +
"delete: userPassword\n" +
"userPassword: " + USER_PASS + "\n" +
"add: userPassword\n" +
- "userPassword: " + new_password + "\n"
- )
+ "userPassword: " + new_password + "\n")
messages = self.waitForMessages(isLastExpectedMessage)
print("Received %d messages" % len(messages))
def test_ldap_change_password_bad_user(self):
def isLastExpectedMessage(msg):
return (msg["type"] == "Authorization" and
- msg["Authorization"]["serviceDescription"]
- == "LDAP" and
+ msg["Authorization"]["serviceDescription"] == "LDAP" and
msg["Authorization"]["authType"] == "krb5")
- new_password = samba.generate_random_password(32,32)
+ new_password = samba.generate_random_password(32, 32)
try:
self.ldb.modify_ldif(
"dn: cn=" + "badUser" + ",cn=users," + self.base_dn + "\n" +
"delete: userPassword\n" +
"userPassword: " + USER_PASS + "\n" +
"add: userPassword\n" +
- "userPassword: " + new_password + "\n"
- )
+ "userPassword: " + new_password + "\n")
self.fail()
except LdbError as e:
(num, msg) = e.args
def test_ldap_change_password_bad_original_password(self):
def isLastExpectedMessage(msg):
- return (msg["type"] == "Authentication" and
- msg["Authentication"]["status"]
- == "NT_STATUS_WRONG_PASSWORD" and
- msg["Authentication"]["serviceDescription"]
- == "LDAP Password Change" and
- msg["Authentication"]["authDescription"]
- == "LDAP Modify")
-
- new_password = samba.generate_random_password(32,32)
+ return ((msg["type"] == "Authentication") and
+ (msg["Authentication"]["status"] ==
+ "NT_STATUS_WRONG_PASSWORD") and
+ (msg["Authentication"]["serviceDescription"] ==
+ "LDAP Password Change") and
+ (msg["Authentication"]["authDescription"] ==
+ "LDAP Modify"))
+
+ new_password = samba.generate_random_password(32, 32)
try:
self.ldb.modify_ldif(
"dn: cn=" + USER_NAME + ",cn=users," + self.base_dn + "\n" +
"delete: userPassword\n" +
"userPassword: " + "badPassword" + "\n" +
"add: userPassword\n" +
- "userPassword: " + new_password + "\n"
- )
+ "userPassword: " + new_password + "\n")
self.fail()
except LdbError as e1:
(num, msg) = e1.args