]> git.ipfire.org Git - thirdparty/samba.git/commitdiff
s3:winbindd: fix "allow trusted domains = no" regression
authorStefan Metzmacher <metze@samba.org>
Tue, 9 Nov 2021 19:50:20 +0000 (20:50 +0100)
committerStefan Metzmacher <metze@samba.org>
Wed, 10 Nov 2021 11:21:31 +0000 (11:21 +0000)
add_trusted_domain() should only reject domains
based on is_allowed_domain(), which now also
checks "allow trusted domains = no", if we don't
have an explicit trust to the domain (SEC_CHAN_NULL).

We use at least SEC_CHAN_LOCAL for local domains like
BUILTIN.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=14899

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Autobuild-User(master): Stefan Metzmacher <metze@samba.org>
Autobuild-Date(master): Wed Nov 10 11:21:31 UTC 2021 on sn-devel-184

source3/winbindd/winbindd_util.c

index fe68adec534a2f42cb18d0938634fee36d14812d..a8c510fafc675c1090341c413736ba92ca2bfd2a 100644 (file)
@@ -135,7 +135,7 @@ static NTSTATUS add_trusted_domain(const char *domain_name,
                return NT_STATUS_INVALID_PARAMETER;
        }
 
-       if (!is_allowed_domain(domain_name)) {
+       if (secure_channel_type == SEC_CHAN_NULL && !is_allowed_domain(domain_name)) {
                return NT_STATUS_NO_SUCH_DOMAIN;
        }