|
|
deab74 |
From e683fb573bc09893ec541be29751560cea30ce3f Mon Sep 17 00:00:00 2001
|
|
|
deab74 |
From: Sumit Bose <sbose@redhat.com>
|
|
|
deab74 |
Date: Wed, 30 May 2018 13:10:57 +0200
|
|
|
deab74 |
Subject: [PATCH] Use current idmap options for smb.conf
|
|
|
deab74 |
|
|
|
deab74 |
Samba change some time ago the way how to configure id-mapping. With
|
|
|
deab74 |
this patch realmd will use the current supported options when creating
|
|
|
deab74 |
smb.conf.
|
|
|
deab74 |
|
|
|
deab74 |
A new option --legacy-samba-config is added to use the old options if
|
|
|
deab74 |
realmd is used with Samba 3.5 or earlier.
|
|
|
deab74 |
|
|
|
deab74 |
Related to https://bugzilla.redhat.com/show_bug.cgi?id=1484072
|
|
|
deab74 |
---
|
|
|
deab74 |
dbus/realm-dbus-constants.h | 1 +
|
|
|
deab74 |
doc/manual/realmd.conf.xml | 17 ++++++++++++
|
|
|
deab74 |
service/realm-samba-enroll.c | 2 +-
|
|
|
deab74 |
service/realm-samba-enroll.h | 3 +++
|
|
|
deab74 |
service/realm-samba-winbind.c | 63 ++++++++++++++++++++++++++++++++++---------
|
|
|
deab74 |
5 files changed, 72 insertions(+), 14 deletions(-)
|
|
|
deab74 |
|
|
|
deab74 |
diff --git a/dbus/realm-dbus-constants.h b/dbus/realm-dbus-constants.h
|
|
|
deab74 |
index 9cd30ef..40ffa2d 100644
|
|
|
deab74 |
--- a/dbus/realm-dbus-constants.h
|
|
|
deab74 |
+++ b/dbus/realm-dbus-constants.h
|
|
|
deab74 |
@@ -69,6 +69,7 @@ G_BEGIN_DECLS
|
|
|
deab74 |
#define REALM_DBUS_OPTION_COMPUTER_NAME "computer-name"
|
|
|
deab74 |
#define REALM_DBUS_OPTION_OS_NAME "os-name"
|
|
|
deab74 |
#define REALM_DBUS_OPTION_OS_VERSION "os-version"
|
|
|
deab74 |
+#define REALM_DBUS_OPTION_LEGACY_SMB_CONF "legacy-samba-config"
|
|
|
deab74 |
|
|
|
deab74 |
#define REALM_DBUS_IDENTIFIER_ACTIVE_DIRECTORY "active-directory"
|
|
|
deab74 |
#define REALM_DBUS_IDENTIFIER_WINBIND "winbind"
|
|
|
deab74 |
diff --git a/doc/manual/realmd.conf.xml b/doc/manual/realmd.conf.xml
|
|
|
deab74 |
index 7853230..a2b577c 100644
|
|
|
deab74 |
--- a/doc/manual/realmd.conf.xml
|
|
|
deab74 |
+++ b/doc/manual/realmd.conf.xml
|
|
|
deab74 |
@@ -192,6 +192,23 @@ automatic-install = no
|
|
|
deab74 |
</listitem>
|
|
|
deab74 |
</varlistentry>
|
|
|
deab74 |
|
|
|
deab74 |
+ <varlistentry>
|
|
|
deab74 |
+ <term><option>legacy-samba-config</option></term>
|
|
|
deab74 |
+ <listitem>
|
|
|
deab74 |
+ <para>Set this to <parameter>yes</parameter> to create a Samba
|
|
|
deab74 |
+ configuration file with id-mapping options used by Samba-3.5
|
|
|
deab74 |
+ and earlier version.</para>
|
|
|
deab74 |
+
|
|
|
deab74 |
+ <informalexample>
|
|
|
deab74 |
+<programlisting language="js">
|
|
|
deab74 |
+[service]
|
|
|
deab74 |
+legacy-samba-config = no
|
|
|
deab74 |
+# legacy-samba-config = yes
|
|
|
deab74 |
+</programlisting>
|
|
|
deab74 |
+ </informalexample>
|
|
|
deab74 |
+ </listitem>
|
|
|
deab74 |
+ </varlistentry>
|
|
|
deab74 |
+
|
|
|
deab74 |
</variablelist>
|
|
|
deab74 |
</refsect1>
|
|
|
deab74 |
|
|
|
deab74 |
diff --git a/service/realm-samba-enroll.c b/service/realm-samba-enroll.c
|
|
|
deab74 |
index c81aed2..76e7b79 100644
|
|
|
deab74 |
--- a/service/realm-samba-enroll.c
|
|
|
deab74 |
+++ b/service/realm-samba-enroll.c
|
|
|
deab74 |
@@ -69,7 +69,7 @@ join_closure_free (gpointer data)
|
|
|
deab74 |
g_free (join);
|
|
|
deab74 |
}
|
|
|
deab74 |
|
|
|
deab74 |
-static gchar *
|
|
|
deab74 |
+gchar *
|
|
|
deab74 |
fallback_workgroup (const gchar *realm)
|
|
|
deab74 |
{
|
|
|
deab74 |
const gchar *pos;
|
|
|
deab74 |
diff --git a/service/realm-samba-enroll.h b/service/realm-samba-enroll.h
|
|
|
deab74 |
index 84e8b2f..310ec65 100644
|
|
|
deab74 |
--- a/service/realm-samba-enroll.h
|
|
|
deab74 |
+++ b/service/realm-samba-enroll.h
|
|
|
deab74 |
@@ -46,6 +46,9 @@ void realm_samba_enroll_leave_async (RealmDisco *disco,
|
|
|
deab74 |
gboolean realm_samba_enroll_leave_finish (GAsyncResult *result,
|
|
|
deab74 |
GError **error);
|
|
|
deab74 |
|
|
|
deab74 |
+gchar *
|
|
|
deab74 |
+fallback_workgroup (const gchar *realm);
|
|
|
deab74 |
+
|
|
|
deab74 |
G_END_DECLS
|
|
|
deab74 |
|
|
|
deab74 |
#endif /* __REALM_SAMBA_ENROLL_H__ */
|
|
|
deab74 |
diff --git a/service/realm-samba-winbind.c b/service/realm-samba-winbind.c
|
|
|
deab74 |
index a7ddec3..9335e26 100644
|
|
|
deab74 |
--- a/service/realm-samba-winbind.c
|
|
|
deab74 |
+++ b/service/realm-samba-winbind.c
|
|
|
deab74 |
@@ -21,8 +21,10 @@
|
|
|
deab74 |
#include "realm-options.h"
|
|
|
deab74 |
#include "realm-samba-config.h"
|
|
|
deab74 |
#include "realm-samba-winbind.h"
|
|
|
deab74 |
+#include "realm-samba-enroll.h"
|
|
|
deab74 |
#include "realm-settings.h"
|
|
|
deab74 |
#include "realm-service.h"
|
|
|
deab74 |
+#include "dbus/realm-dbus-constants.h"
|
|
|
deab74 |
|
|
|
deab74 |
#include <glib/gstdio.h>
|
|
|
deab74 |
|
|
|
deab74 |
@@ -80,6 +82,10 @@ realm_samba_winbind_configure_async (RealmIniConfig *config,
|
|
|
deab74 |
RealmIniConfig *pwc;
|
|
|
deab74 |
GTask *task;
|
|
|
deab74 |
GError *error = NULL;
|
|
|
deab74 |
+ gchar *workgroup = NULL;
|
|
|
deab74 |
+ gchar *idmap_config_backend = NULL;
|
|
|
deab74 |
+ gchar *idmap_config_range = NULL;
|
|
|
deab74 |
+ gchar *idmap_config_schema_mode = NULL;
|
|
|
deab74 |
|
|
|
deab74 |
g_return_if_fail (config != NULL);
|
|
|
deab74 |
g_return_if_fail (invocation != NULL || G_IS_DBUS_METHOD_INVOCATION (invocation));
|
|
|
deab74 |
@@ -100,23 +106,54 @@ realm_samba_winbind_configure_async (RealmIniConfig *config,
|
|
|
deab74 |
"template shell", realm_settings_string ("users", "default-shell"),
|
|
|
deab74 |
NULL);
|
|
|
deab74 |
|
|
|
deab74 |
- if (realm_options_automatic_mapping (options, domain_name)) {
|
|
|
deab74 |
- realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
- "idmap uid", "10000-2000000",
|
|
|
deab74 |
- "idmap gid", "10000-2000000",
|
|
|
deab74 |
- "idmap backend", "tdb",
|
|
|
deab74 |
- "idmap schema", NULL,
|
|
|
deab74 |
- NULL);
|
|
|
deab74 |
+ if (realm_settings_boolean ("service", REALM_DBUS_OPTION_LEGACY_SMB_CONF, FALSE)) {
|
|
|
deab74 |
+ if (realm_options_automatic_mapping (options, domain_name)) {
|
|
|
deab74 |
+ realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
+ "idmap uid", "10000-2000000",
|
|
|
deab74 |
+ "idmap gid", "10000-2000000",
|
|
|
deab74 |
+ "idmap backend", "tdb",
|
|
|
deab74 |
+ "idmap schema", NULL,
|
|
|
deab74 |
+ NULL);
|
|
|
deab74 |
+ } else {
|
|
|
deab74 |
+ realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
+ "idmap uid", "500-4294967296",
|
|
|
deab74 |
+ "idmap gid", "500-4294967296",
|
|
|
deab74 |
+ "idmap backend", "ad",
|
|
|
deab74 |
+ "idmap schema", "rfc2307",
|
|
|
deab74 |
+ NULL);
|
|
|
deab74 |
+ }
|
|
|
deab74 |
} else {
|
|
|
deab74 |
- realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
- "idmap uid", "500-4294967296",
|
|
|
deab74 |
- "idmap gid", "500-4294967296",
|
|
|
deab74 |
- "idmap backend", "ad",
|
|
|
deab74 |
- "idmap schema", "rfc2307",
|
|
|
deab74 |
- NULL);
|
|
|
deab74 |
+ workgroup = realm_ini_config_get (config, REALM_SAMBA_CONFIG_GLOBAL, "workgroup");
|
|
|
deab74 |
+ if (workgroup == NULL) {
|
|
|
deab74 |
+ workgroup = fallback_workgroup (domain_name);
|
|
|
deab74 |
+ }
|
|
|
deab74 |
+ idmap_config_backend = g_strdup_printf ("idmap config %s : backend", workgroup != NULL ? workgroup : "PLEASE_REPLACE");
|
|
|
deab74 |
+ idmap_config_range = g_strdup_printf ("idmap config %s : range", workgroup != NULL ? workgroup : "PLEASE_REPLACE");
|
|
|
deab74 |
+ idmap_config_schema_mode = g_strdup_printf ("idmap config %s : schema_mode", workgroup != NULL ? workgroup : "PLEASE_REPLACE");
|
|
|
deab74 |
+ g_free (workgroup);
|
|
|
deab74 |
+
|
|
|
deab74 |
+ if (realm_options_automatic_mapping (options, domain_name)) {
|
|
|
deab74 |
+ realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
+ "idmap config * : backend", "tdb",
|
|
|
deab74 |
+ "idmap config * : range", "10000-999999",
|
|
|
deab74 |
+ idmap_config_backend != NULL ? idmap_config_backend : "idmap config PLEASE_REPLACE : backend", "rid",
|
|
|
deab74 |
+ idmap_config_range != NULL ? idmap_config_range: "idmap config PLEASE_REPLACE : range", "2000000-2999999",
|
|
|
deab74 |
+ idmap_config_schema_mode != NULL ? idmap_config_schema_mode: "idmap config PLEASE_REPLACE : schema_mode", NULL,
|
|
|
deab74 |
+ NULL);
|
|
|
deab74 |
+ } else {
|
|
|
deab74 |
+ realm_ini_config_set (config, REALM_SAMBA_CONFIG_GLOBAL,
|
|
|
deab74 |
+ "idmap config * : backend", "tdb",
|
|
|
deab74 |
+ "idmap config * : range", "10000000-10999999",
|
|
|
deab74 |
+ idmap_config_backend != NULL ? idmap_config_backend : "idmap config PLEASE_REPLACE : backend", "ad",
|
|
|
deab74 |
+ idmap_config_range != NULL ? idmap_config_range: "idmap config PLEASE_REPLACE : range", "500-999999",
|
|
|
deab74 |
+ idmap_config_schema_mode != NULL ? idmap_config_schema_mode: "idmap config PLEASE_REPLACE : schema_mode", "rfc2307",
|
|
|
deab74 |
+ NULL);
|
|
|
deab74 |
+ }
|
|
|
deab74 |
}
|
|
|
deab74 |
|
|
|
deab74 |
realm_ini_config_finish_change (config, &error);
|
|
|
deab74 |
+ g_free (idmap_config_backend);
|
|
|
deab74 |
+ g_free (idmap_config_range);
|
|
|
deab74 |
}
|
|
|
deab74 |
|
|
|
deab74 |
/* Setup pam_winbind.conf with decent defaults matching our expectations */
|
|
|
deab74 |
--
|
|
|
deab74 |
2.14.4
|
|
|
deab74 |
|