wmi-1.3.16 from opsview.com
This commit is contained in:
@@ -0,0 +1,117 @@
|
||||
dn: CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: 409
|
||||
name: 409
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=user-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: user-Display
|
||||
name: user-Display
|
||||
contextMenu: 0,{62AE1F9A-126A-11D0-A14B-0800361B1103}
|
||||
adminPropertyPages: 9,{FA3E1D55-16DF-446d-872E-BD04D4F39C93}
|
||||
adminPropertyPages: 8,{0910dd01-df8c-11d1-ae27-00c04fa35813}
|
||||
adminPropertyPages: 7,{8c5b1b50-d46e-11d1-8091-00a024c48131}
|
||||
adminPropertyPages: 6,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 5,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 4,{FD57D295-4FD9-11D1-854E-00C04FC31FD3}
|
||||
adminPropertyPages: 3,{B52C1E50-1DD2-11D1-BC43-00C04FC31FD3}
|
||||
adminPropertyPages: 1,{6dfe6485-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
shellPropertyPages: 2,{dde2c5e9-c8ae-11d0-bcdb-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f5d121ed-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 1,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
adminMultiselectPropertyPages: 1,{50d30564-9911-11d1-b9af-00c04fd8d5b0}
|
||||
|
||||
dn: CN=group-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: group-Display
|
||||
name: group-Display
|
||||
contextMenu: 0,{62AE1F9A-126A-11D0-A14B-0800361B1103}
|
||||
adminPropertyPages: 4,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 3,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 2,{6dfe648b-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 1,{6dfe6489-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
shellPropertyPages: 2,{dde2c5e9-c8ae-11d0-bcdb-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f5d121ee-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 1,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
|
||||
dn: CN=domainDNS-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: domainDNS-Display
|
||||
name: domainDNS-Display
|
||||
adminPropertyPages: 5,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 4,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 3,{6dfe648b-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 1,{6dfe648c-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
shellPropertyPages: 2,{dde2c5e9-c8ae-11d0-bcdb-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f5d121ef-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 2,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
adminContextMenu: 1,{6BA3F852-23C6-11D1-B91F-00A0C9A06D2D}
|
||||
|
||||
dn: CN=computer-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: computer-Display
|
||||
name: computer-Display
|
||||
contextMenu: 0,{62AE1F9A-126A-11D0-A14B-0800361B1103}
|
||||
adminPropertyPages: 10,{0F65B1BF-740F-11d1-BBE6-0060081692B3}
|
||||
adminPropertyPages: 7,{B52C1E50-1DD2-11D1-BC43-00C04FC31FD3}
|
||||
adminPropertyPages: 6,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 5,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 4,{6dfe648b-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 3,{77597368-7b15-11d0-a0c2-080036af3f03}
|
||||
adminPropertyPages: 1,{6dfe6492-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
shellPropertyPages: 2,{dde2c5e9-c8ae-11d0-bcdb-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f5d121f4-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 1,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
createWizardExt: 1,{D6D8C25A-4E83-11d2-8424-00C04FA372D4}
|
||||
|
||||
dn: CN=organizationalUnit-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: organizationalUnit-Display
|
||||
name: organizationalUnit-Display
|
||||
contextMenu: 0,{62AE1F9A-126A-11D0-A14B-0800361B1103}
|
||||
adminPropertyPages: 6,{FA3E1D55-16DF-446d-872E-BD04D4F39C93}
|
||||
adminPropertyPages: 5,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 4,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 3,{6dfe648b-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 1,{9da6fd63-c63b-11d0-b94d-00c04fd8d5b0}
|
||||
shellPropertyPages: 2,{dde2c5e9-c8ae-11d0-bcdb-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f2c3faae-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 2,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
adminContextMenu: 1,{6BA3F852-23C6-11D1-B91F-00A0C9A06D2D}
|
||||
|
||||
dn: CN=container-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: container-Display
|
||||
name: container-Display
|
||||
contextMenu: 0,{62AE1F9A-126A-11D0-A14B-0800361B1103}
|
||||
adminPropertyPages: 3,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 2,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 1,{5a96f2d8-736e-11d1-bd0d-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f2c3faae-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 4,{AB790AA1-CDC1-478a-9351-B2E05CFCAD09}
|
||||
adminContextMenu: 3,{EEBD2F15-87EE-4F93-856F-6AD7E31787B3}
|
||||
adminContextMenu: 2,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
adminContextMenu: 1,{6BA3F852-23C6-11D1-B91F-00A0C9A06D2D}
|
||||
|
||||
dn: CN=default-Display,CN=409,CN=DisplaySpecifiers,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: displaySpecifier
|
||||
cn: default-Display
|
||||
name: default-Display
|
||||
adminPropertyPages: 3,{4E40F770-369C-11d0-8922-00A024AB2DBB}
|
||||
adminPropertyPages: 2,{6dfe6488-a212-11d0-bcd5-00c04fd8d5b6}
|
||||
adminPropertyPages: 1,{6384e23e-736d-11d1-bd0d-00c04fd8d5b6}
|
||||
shellPropertyPages: 1,{f2c3faae-c8ac-11d0-bcdb-00c04fd8d5b6}
|
||||
adminContextMenu: 0,{08eb4fa6-6ffd-11d1-b0e0-00c04fd8dca6}
|
||||
adminMultiselectPropertyPages: 1,{50d30563-9911-11d1-b9af-00c04fd8d5b0}
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
dn: @INDEXLIST
|
||||
@IDXATTR: key
|
||||
|
||||
dn: @ATTRIBUTES
|
||||
key: CASE_INSENSITIVE
|
||||
value: CASE_INSENSITIVE
|
||||
|
||||
dn: key=control,key=currentcontrolset,key=system,hive=NONE
|
||||
key: control
|
||||
|
||||
dn: value=ProductType,key=productoptions,key=control,key=currentcontrolset,key=system,hive=NONE
|
||||
value: ProductType
|
||||
data: LanmanNT
|
||||
type: 1
|
||||
|
||||
dn: key=productoptions,key=control,key=currentcontrolset,key=system,hive=NONE
|
||||
key: productoptions
|
||||
|
||||
dn: key=system,hive=NONE
|
||||
key: system
|
||||
|
||||
dn: key=print,key=control,key=currentcontrolset,key=system,hive=NONE
|
||||
key: print
|
||||
|
||||
dn: key=currentcontrolset,key=system,hive=NONE
|
||||
key: currentcontrolset
|
||||
|
||||
dn: key=Terminal Server,key=control,key=currentcontrolset,key=system,hive=NONE
|
||||
key: Terminal Server
|
||||
|
||||
dn: key=Services,key=CurrentControlSet,key=System,hive=NONE
|
||||
key: Services
|
||||
|
||||
dn: key=Netlogon,key=Services,key=CurrentControlSet,key=System,hive=NONE
|
||||
key: Netlogon
|
||||
|
||||
dn: key=Parameters,key=Netlogon,key=Services,key=CurrentControlSet,key=System,hive=NONE
|
||||
key: Parameters
|
||||
|
||||
dn: value=RefusePasswordChange,key=Parameters,key=Netlogon,key=Services,key=CurrentControlSet,key=System,hive=NONE
|
||||
value: RefusePasswordChange
|
||||
type: 4
|
||||
data: 0
|
||||
Executable
+80
@@ -0,0 +1,80 @@
|
||||
#!/bin/sh
|
||||
exec smbscript "$0" ${1+"$@"}
|
||||
/*
|
||||
add a new user to a Samba4 server
|
||||
Copyright Andrew Tridgell 2005
|
||||
Released under the GNU GPL v2 or later
|
||||
*/
|
||||
|
||||
options = GetOptions(ARGV,
|
||||
"POPT_AUTOHELP",
|
||||
'username=s',
|
||||
'unixname=s',
|
||||
'password=s',
|
||||
"POPT_COMMON_SAMBA",
|
||||
"POPT_COMMON_VERSION",
|
||||
"POPT_COMMON_CREDENTIALS",
|
||||
'quiet');
|
||||
|
||||
if (options == undefined) {
|
||||
println("Failed to parse options");
|
||||
return -1;
|
||||
}
|
||||
|
||||
libinclude("base.js");
|
||||
libinclude("provision.js");
|
||||
|
||||
/*
|
||||
print a message if quiet is not set
|
||||
*/
|
||||
function message()
|
||||
{
|
||||
if (options["quiet"] == undefined) {
|
||||
print(vsprintf(arguments));
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
show some help
|
||||
*/
|
||||
function ShowHelp()
|
||||
{
|
||||
print("
|
||||
Samba4 newuser
|
||||
|
||||
newuser [options]
|
||||
--username USERNAME choose new username
|
||||
--unixname USERNAME choose unix name of new user
|
||||
--password PASSWORD set password
|
||||
|
||||
You must provide at least a username
|
||||
");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (options['username'] == undefined) {
|
||||
ShowHelp();
|
||||
}
|
||||
|
||||
if (options['password'] == undefined) {
|
||||
random_init(local);
|
||||
options.password = randpass(12);
|
||||
printf("chose random password %s\n", options.password);
|
||||
}
|
||||
if (options['unixname'] == undefined) {
|
||||
options.unixname = options.username;
|
||||
}
|
||||
|
||||
var nss = nss_init();
|
||||
if (nss.getpwnam(options.unixname) == undefined) {
|
||||
printf("ERROR: Unix user '%s' does not exist\n", options.unixname);
|
||||
exit(1);
|
||||
}
|
||||
|
||||
var creds = options.get_credentials();
|
||||
var system_session = system_session();
|
||||
|
||||
|
||||
newuser(options.username, options.unixname, options.password, message, system_session, creds);
|
||||
|
||||
return 0;
|
||||
Executable
+137
@@ -0,0 +1,137 @@
|
||||
#!/bin/sh
|
||||
exec smbscript "$0" ${1+"$@"}
|
||||
/*
|
||||
provision a Samba4 server
|
||||
Copyright Andrew Tridgell 2005
|
||||
Released under the GNU GPL v2 or later
|
||||
*/
|
||||
|
||||
options = GetOptions(ARGV,
|
||||
"POPT_AUTOHELP",
|
||||
"POPT_COMMON_SAMBA",
|
||||
"POPT_COMMON_VERSION",
|
||||
"POPT_COMMON_CREDENTIALS",
|
||||
'realm=s',
|
||||
'domain=s',
|
||||
'domain-guid=s',
|
||||
'domain-sid=s',
|
||||
'host-name=s',
|
||||
'host-ip=s',
|
||||
'host-guid=s',
|
||||
'invocationid=s',
|
||||
'adminpass=s',
|
||||
'krbtgtpass=s',
|
||||
'machinepass=s',
|
||||
'root=s',
|
||||
'nobody=s',
|
||||
'nogroup=s',
|
||||
'wheel=s',
|
||||
'users=s',
|
||||
'quiet',
|
||||
'blank',
|
||||
'ldap-base',
|
||||
'ldap-backend=s');
|
||||
|
||||
if (options == undefined) {
|
||||
println("Failed to parse options");
|
||||
return -1;
|
||||
}
|
||||
|
||||
libinclude("base.js");
|
||||
libinclude("provision.js");
|
||||
|
||||
/*
|
||||
print a message if quiet is not set
|
||||
*/
|
||||
function message()
|
||||
{
|
||||
if (options["quiet"] == undefined) {
|
||||
print(vsprintf(arguments));
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
show some help
|
||||
*/
|
||||
function ShowHelp()
|
||||
{
|
||||
print("
|
||||
Samba4 provisioning
|
||||
|
||||
provision [options]
|
||||
--realm REALM set realm
|
||||
--domain DOMAIN set domain
|
||||
--domain-guid GUID set domainguid (otherwise random)
|
||||
--domain-sid SID set domainsid (otherwise random)
|
||||
--host-name HOSTNAME set hostname
|
||||
--host-ip IPADDRESS set ipaddress
|
||||
--host-guid GUID set hostguid (otherwise random)
|
||||
--invocationid GUID set invocationid (otherwise random)
|
||||
--adminpass PASSWORD choose admin password (otherwise random)
|
||||
--krbtgtpass PASSWORD choose krbtgt password (otherwise random)
|
||||
--machinepass PASSWORD choose machine password (otherwise random)
|
||||
--root USERNAME choose 'root' unix username
|
||||
--nobody USERNAME choose 'nobody' user
|
||||
--nogroup GROUPNAME choose 'nogroup' group
|
||||
--wheel GROUPNAME choose 'wheel' privileged group
|
||||
--users GROUPNAME choose 'users' group
|
||||
--quiet Be quiet
|
||||
--blank do not add users or groups, just the structure
|
||||
--ldap-base output only an LDIF file, suitable for creating an LDAP baseDN
|
||||
--ldap-backend LDAPSERVER LDAP server to use for this provision
|
||||
|
||||
You must provide at least a realm and domain
|
||||
|
||||
");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (options['host-name'] == undefined) {
|
||||
options['host-name'] = hostname();
|
||||
}
|
||||
|
||||
/*
|
||||
main program
|
||||
*/
|
||||
if (options["realm"] == undefined ||
|
||||
options["domain"] == undefined ||
|
||||
options["host-name"] == undefined) {
|
||||
ShowHelp();
|
||||
}
|
||||
|
||||
/* cope with an initially blank smb.conf */
|
||||
var lp = loadparm_init();
|
||||
lp.set("realm", options.realm);
|
||||
lp.set("workgroup", options.domain);
|
||||
lp.reload();
|
||||
|
||||
var subobj = provision_guess();
|
||||
for (r in options) {
|
||||
var key = strupper(join("", split("-", r)));
|
||||
subobj[key] = options[r];
|
||||
}
|
||||
|
||||
if (options["ldap-backend"] != undefined) {
|
||||
subobj["LDAPMODULES"] = "entryUUID,paged_searches";
|
||||
}
|
||||
|
||||
var blank = (options["blank"] != undefined);
|
||||
var ldapbase = (options["ldap-base"] != undefined);
|
||||
|
||||
if (!provision_validate(subobj, message)) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
var system_session = system_session();
|
||||
var creds = options.get_credentials();
|
||||
var paths = provision_default_paths(subobj);
|
||||
message("Provisioning for %s in realm %s\n", subobj.DOMAIN, subobj.REALM);
|
||||
message("Using administrator password: %s\n", subobj.ADMINPASS);
|
||||
if (ldapbase) {
|
||||
provision_ldapbase(subobj, message, paths);
|
||||
} else {
|
||||
provision(subobj, message, blank, paths, system_session, creds);
|
||||
provision_dns(subobj, message, paths, system_session, creds);
|
||||
}
|
||||
message("All OK\n");
|
||||
return 0;
|
||||
@@ -0,0 +1,302 @@
|
||||
dn: CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Users
|
||||
description: Default container for upgraded user accounts
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: FALSE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
allowedChildClassesEffective: user
|
||||
allowedChildClassesEffective: group
|
||||
|
||||
dn: CN=Computers,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Computers
|
||||
description: Default container for upgraded computer accounts
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: FALSE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Domain Controllers,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Domain Controllers
|
||||
description: Default container for domain controllers
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: FALSE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=ForeignSecurityPrincipals,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: ForeignSecurityPrincipals
|
||||
description: Default container for security identifiers (SIDs) associated with objects from external, trusted domains
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: FALSE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=System,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: System
|
||||
description: Builtin system settings
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=RID Manager$,CN=System,${BASEDN}
|
||||
objectclass: top
|
||||
objectclass: rIDManager
|
||||
cn: RID Manager$
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=RID-Manager,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
fSMORoleOwner: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
rIDAvailablePool: 4611686014132423217
|
||||
|
||||
dn: CN=DomainUpdates,CN=System,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: DomainUpdates
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Windows2003Update,CN=DomainUpdates,CN=System,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Windows2003Update
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
revision: 8
|
||||
|
||||
dn: CN=Infrastructure,${BASEDN}
|
||||
objectclass: top
|
||||
objectclass: infrastructureUpdate
|
||||
cn: Infrastructure
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Infrastructure-Update,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
fSMORoleOwner: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: builtinDomain
|
||||
cn: Builtin
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: FALSE
|
||||
forceLogoff: 9223372036854775808
|
||||
lockoutDuration: -18000000000
|
||||
lockOutObservationWindow: -18000000000
|
||||
lockoutThreshold: 0
|
||||
maxPwdAge: -37108517437440
|
||||
minPwdAge: 0
|
||||
minPwdLength: 0
|
||||
modifiedCountAtLastProm: 0
|
||||
nextRid: 1000
|
||||
pwdProperties: 0
|
||||
pwdHistoryLength: 0
|
||||
objectSid: S-1-5-32
|
||||
serverState: 1
|
||||
uASCompat: 1
|
||||
modifiedCount: 1
|
||||
objectCategory: CN=Builtin-Domain,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
###############################
|
||||
# Configuration Naming Context
|
||||
###############################
|
||||
dn: CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: configuration
|
||||
cn: Configuration
|
||||
instanceType: 13
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Configuration,CN=Schema,CN=Configuration,${BASEDN}
|
||||
subRefs: CN=Schema,CN=Configuration,${BASEDN}
|
||||
masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
msDs-masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Partitions,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: crossRefContainer
|
||||
cn: Partitions
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2147483648
|
||||
objectCategory: CN=Cross-Ref-Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
msDS-Behavior-Version: 0
|
||||
fSMORoleOwner: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Enterprise Configuration,CN=Partitions,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: crossRef
|
||||
cn: Enterprise Configuration
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 1
|
||||
objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
|
||||
nCName: CN=Configuration,${BASEDN}
|
||||
dnsRoot: ${DNSDOMAIN}
|
||||
|
||||
dn: CN=Enterprise Schema,CN=Partitions,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: crossRef
|
||||
cn: Enterprise Schema
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 1
|
||||
objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
|
||||
nCName: CN=Schema,CN=Configuration,${BASEDN}
|
||||
dnsRoot: ${DNSDOMAIN}
|
||||
|
||||
dn: CN=${DOMAIN},CN=Partitions,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: crossRef
|
||||
cn: ${DOMAIN}
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 3
|
||||
objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
|
||||
nCName: ${BASEDN}
|
||||
nETBIOSName: ${DOMAIN}
|
||||
dnsRoot: ${DNSDOMAIN}
|
||||
|
||||
dn: CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: sitesContainer
|
||||
cn: Sites
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2181038080
|
||||
objectCategory: CN=Sites-Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: site
|
||||
cn: ${DEFAULTSITE}
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2181038080
|
||||
objectCategory: CN=Site,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: serversContainer
|
||||
cn: Servers
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2181038080
|
||||
objectCategory: CN=Servers-Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: server
|
||||
cn: ${NETBIOSNAME}
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 1375731712
|
||||
objectCategory: CN=Server,CN=Schema,CN=Configuration,${BASEDN}
|
||||
dNSHostName: ${DNSNAME}
|
||||
serverReference: CN=${NETBIOSNAME},OU=Domain Controllers,${BASEDN}
|
||||
|
||||
dn: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: applicationSettings
|
||||
objectClass: nTDSDSA
|
||||
cn: NTDS Settings
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 33554432
|
||||
objectCategory: CN=NTDS-DSA,CN=Schema,CN=Configuration,${BASEDN}
|
||||
dMDLocation: CN=Schema,CN=Configuration,${BASEDN}
|
||||
objectGUID: ${INVOCATIONID}
|
||||
invocationId: ${INVOCATIONID}
|
||||
msDS-Behavior-Version: 2
|
||||
|
||||
dn: CN=Services,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Services
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2147483648
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Windows NT
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: nTDSService
|
||||
cn: Directory Service
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=NTDS-Service,CN=Schema,CN=Configuration,${BASEDN}
|
||||
sPNMappings: host=ldap,dns,cifs,http
|
||||
|
||||
dn: CN=Query-Policies,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Query-Policies
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=Default Query Policy,CN=Query-Policies,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: queryPolicy
|
||||
cn: Default Query Policy
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Query-Policy,CN=Schema,CN=Configuration,${BASEDN}
|
||||
lDAPAdminLimits: MaxValRange=1500
|
||||
lDAPAdminLimits: MaxReceiveBuffer=10485760
|
||||
lDAPAdminLimits: MaxDatagramRecv=4096
|
||||
lDAPAdminLimits: MaxPoolThreads=4
|
||||
lDAPAdminLimits: MaxResultSetSize=262144
|
||||
lDAPAdminLimits: MaxTempTableSize=10000
|
||||
lDAPAdminLimits: MaxQueryDuration=120
|
||||
lDAPAdminLimits: MaxPageSize=1000
|
||||
lDAPAdminLimits: MaxNotificationPerConn=5
|
||||
lDAPAdminLimits: MaxActiveQueries=20
|
||||
lDAPAdminLimits: MaxConnIdleTime=900
|
||||
lDAPAdminLimits: InitRecvTimeout=120
|
||||
lDAPAdminLimits: MaxConnections=5000
|
||||
|
||||
|
||||
###############################
|
||||
# Schema Naming Context
|
||||
###############################
|
||||
dn: CN=Schema,CN=Configuration,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: dMD
|
||||
cn: Schema
|
||||
instanceType: 13
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=DMD,CN=Schema,CN=Configuration,${BASEDN}
|
||||
masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
msDs-masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
fSMORoleOwner: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
|
||||
objectVersion: 30
|
||||
@@ -0,0 +1,7 @@
|
||||
[globals]
|
||||
netbios name = ${HOSTNAME}
|
||||
workgroup = ${DOMAIN}
|
||||
realm = ${REALM}
|
||||
server role = pdc
|
||||
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
; -*- zone -*-
|
||||
; generated by provision.pl
|
||||
$ORIGIN ${DNSDOMAIN}.
|
||||
$TTL 1W
|
||||
@ IN SOA @ hostmaster (
|
||||
${DATESTRING} ; serial
|
||||
2D ; refresh
|
||||
4H ; retry
|
||||
6W ; expiry
|
||||
1W ) ; minimum
|
||||
IN NS ${HOSTNAME}
|
||||
IN A ${HOSTIP}
|
||||
;
|
||||
${HOSTNAME} IN A ${HOSTIP}
|
||||
${HOSTGUID}._msdcs IN CNAME ${HOSTNAME}
|
||||
;
|
||||
; global catalog servers
|
||||
_gc._tcp IN SRV 0 100 3268 ${HOSTNAME}
|
||||
_ldap._tcp.gc._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
_ldap._tcp.${DEFAULTSITE}._sites.gc._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
;
|
||||
; ldap servers
|
||||
_ldap._tcp IN SRV 0 100 389 ${HOSTNAME}
|
||||
_ldap._tcp.dc._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
_ldap._tcp.pdc._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
_ldap._tcp.${DOMAINGUID}.domains._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
_ldap._tcp.${DEFAULTSITE}._sites.dc._msdcs IN SRV 0 100 389 ${HOSTNAME}
|
||||
;
|
||||
; krb5 servers
|
||||
_kerberos._tcp IN SRV 0 100 88 ${HOSTNAME}
|
||||
_kerberos._tcp.dc._msdcs IN SRV 0 100 88 ${HOSTNAME}
|
||||
_kerberos._tcp.${DEFAULTSITE}._sites.dc._msdcs IN SRV 0 100 88 ${HOSTNAME}
|
||||
_kerberos._udp IN SRV 0 100 88 ${HOSTNAME}
|
||||
; MIT kpasswd likes to lookup this name on password change
|
||||
_kerberos-master._tcp IN SRV 0 100 88 ${HOSTNAME}
|
||||
_kerberos-master._udp IN SRV 0 100 88 ${HOSTNAME}
|
||||
;
|
||||
; kpasswd
|
||||
_kpasswd._tcp IN SRV 0 100 464 ${HOSTNAME}
|
||||
_kpasswd._udp IN SRV 0 100 464 ${HOSTNAME}
|
||||
;
|
||||
; heimdal 'find realm for host' hack
|
||||
_kerberos IN TXT ${REALM}
|
||||
@@ -0,0 +1,10 @@
|
||||
################################
|
||||
## Domain Naming Context
|
||||
################################
|
||||
dn: ${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: domain
|
||||
objectClass: domainDNS
|
||||
${EXTENSIBLEOBJECT}
|
||||
dc: ${RDN_DC}
|
||||
|
||||
@@ -0,0 +1,80 @@
|
||||
###############################
|
||||
# Domain Naming Context
|
||||
###############################
|
||||
dn: ${BASEDN}
|
||||
changetype: modify
|
||||
replace: dnsDomain
|
||||
dnsDomain: ${DNSDOMAIN}
|
||||
-
|
||||
replace: dc
|
||||
dc: ${RDN_DC}
|
||||
-
|
||||
replace: forceLogoff
|
||||
forceLogoff: 9223372036854775808
|
||||
-
|
||||
replace: lockoutDuration
|
||||
lockoutDuration: -18000000000
|
||||
-
|
||||
replace: lockOutObservationWindow
|
||||
lockOutObservationWindow: -18000000000
|
||||
-
|
||||
replace: lockoutThreshold
|
||||
lockoutThreshold: 0
|
||||
-
|
||||
replace: maxPwdAge
|
||||
maxPwdAge: -37108517437440
|
||||
-
|
||||
replace: minPwdAge
|
||||
minPwdAge: 0
|
||||
-
|
||||
replace: minPwdLength
|
||||
minPwdLength: 7
|
||||
-
|
||||
replace: modifiedCountAtLastProm
|
||||
modifiedCountAtLastProm: 0
|
||||
-
|
||||
replace: nextRid
|
||||
nextRid: 1000
|
||||
-
|
||||
replace: pwdProperties
|
||||
pwdProperties: 1
|
||||
-
|
||||
replace: pwdHistoryLength
|
||||
pwdHistoryLength: 24
|
||||
-
|
||||
replace: objectSid
|
||||
objectSid: ${DOMAINSID}
|
||||
-
|
||||
replace: oEMInformation
|
||||
oEMInformation: Provisioned by Samba4: ${LDAPTIME}
|
||||
-
|
||||
replace: serverState
|
||||
serverState: 1
|
||||
-
|
||||
replace: nTMixedDomain
|
||||
nTMixedDomain: 1
|
||||
-
|
||||
replace: msDS-Behavior-Version
|
||||
msDS-Behavior-Version: 0
|
||||
-
|
||||
replace: ridManagerReference
|
||||
ridManagerReference: CN=RID Manager$,CN=System,${BASEDN}
|
||||
-
|
||||
replace: uASCompat
|
||||
uASCompat: 1
|
||||
-
|
||||
replace: modifiedCount
|
||||
modifiedCount: 1
|
||||
-
|
||||
replace: objectCategory
|
||||
objectCategory: CN=Domain-DNS,CN=Schema,CN=Configuration,${BASEDN}
|
||||
-
|
||||
replace: isCriticalSystemObject
|
||||
isCriticalSystemObject: TRUE
|
||||
-
|
||||
replace: subRefs
|
||||
subRefs: CN=Configuration,${BASEDN}
|
||||
subRefs: CN=Schema,CN=Configuration,${BASEDN}
|
||||
-
|
||||
${DOMAINGUID_MOD}
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
dn: @INDEXLIST
|
||||
@IDXATTR: name
|
||||
@IDXATTR: sAMAccountName
|
||||
@IDXATTR: objectSid
|
||||
@IDXATTR: objectCategory
|
||||
@IDXATTR: member
|
||||
@IDXATTR: uidNumber
|
||||
@IDXATTR: gidNumber
|
||||
@IDXATTR: unixName
|
||||
@IDXATTR: privilege
|
||||
@IDXATTR: nCName
|
||||
@IDXATTR: lDAPDisplayName
|
||||
@IDXATTR: subClassOf
|
||||
@IDXATTR: dnsRoot
|
||||
@IDXATTR: nETBIOSName
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
dn: @ATTRIBUTES
|
||||
userPrincipalName: CASE_INSENSITIVE
|
||||
servicePrincipalName: CASE_INSENSITIVE
|
||||
dnsDomain: CASE_INSENSITIVE
|
||||
dnsRoot: CASE_INSENSITIVE
|
||||
nETBIOSName: CASE_INSENSITIVE
|
||||
cn: CASE_INSENSITIVE
|
||||
dc: CASE_INSENSITIVE
|
||||
name: CASE_INSENSITIVE
|
||||
dn: CASE_INSENSITIVE
|
||||
sAMAccountName: CASE_INSENSITIVE
|
||||
objectClass: CASE_INSENSITIVE
|
||||
sambaPassword: HIDDEN
|
||||
krb5Key: HIDDEN
|
||||
ntPwdHash: HIDDEN
|
||||
sambaNTPwdHistory: HIDDEN
|
||||
lmPwdHash: HIDDEN
|
||||
sambaLMPwdHistory: HIDDEN
|
||||
createTimestamp: HIDDEN
|
||||
modifyTimestamp: HIDDEN
|
||||
groupType: INTEGER
|
||||
sAMAccountType: INTEGER
|
||||
systemFlags: INTEGER
|
||||
userAccountControl: INTEGER
|
||||
|
||||
dn: @SUBCLASSES
|
||||
top: domain
|
||||
top: person
|
||||
top: group
|
||||
domain: domainDNS
|
||||
person: organizationalPerson
|
||||
organizationalPerson: user
|
||||
user: computer
|
||||
template: userTemplate
|
||||
template: groupTemplate
|
||||
|
||||
dn: @KLUDGEACL
|
||||
passwordAttribute: sambaPassword
|
||||
passwordAttribute: ntPwdHash
|
||||
passwordAttribute: sambaNTPwdHistory
|
||||
passwordAttribute: lmPwdHash
|
||||
passwordAttribute: sambaLMPwdHistory
|
||||
passwordAttribute: krb5key
|
||||
|
||||
# the rootDSE module looks in this record for its base data
|
||||
dn: cn=ROOTDSE
|
||||
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,${BASEDN}
|
||||
dsServiceName: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,${BASEDN}
|
||||
defaultNamingContext: ${BASEDN}
|
||||
rootDomainNamingContext: ${BASEDN}
|
||||
configurationNamingContext: CN=Configuration,${BASEDN}
|
||||
schemaNamingContext: CN=Schema,CN=Configuration,${BASEDN}
|
||||
supportedLDAPVersion: 3
|
||||
dnsHostName: ${DNSNAME}
|
||||
ldapServiceName: ${DNSDOMAIN}:${NETBIOSNAME}$@${REALM}
|
||||
serverName: CN=${NETBIOSNAME},CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,${BASEDN}
|
||||
domainFunctionality: 0
|
||||
forestFunctionality: 0
|
||||
domainControllerFunctionality: 2
|
||||
isSynchronized: TRUE
|
||||
vendorName: Samba Team (http://samba.org)
|
||||
vendorVersion: ${VERSION}
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
dn: @PARTITION
|
||||
partition: CN=Schema,CN=Configuration,${BASEDN}:schema.ldb
|
||||
partition: CN=Configuration,${BASEDN}:configuration.ldb
|
||||
partition: ${BASEDN}:${LDAPBACKEND}
|
||||
replicateEntries: @SUBCLASSES
|
||||
replicateEntries: @ATTRIBUTES
|
||||
replicateEntries: @INDEXLIST
|
||||
modules:CN=Schema,CN=Configuration,${BASEDN}:objectguid
|
||||
modules:CN=Configuration,${BASEDN}:objectguid
|
||||
modules:${BASEDN}:${LDAPMODULES}
|
||||
|
||||
#Add modules to the list to activate them by default
|
||||
#beware often order is important
|
||||
#
|
||||
# Some Known ordering constraints:
|
||||
# - rootdse must be first, as it makes redirects from "" -> cn=rootdse
|
||||
# - samldb must be before password_hash, because password_hash checks that the objectclass is of type person (filled in by samldb)
|
||||
# - partition must be last
|
||||
|
||||
dn: @MODULES
|
||||
@LIST: rootdse,kludge_acl,paged_results,server_sort,extended_dn,asq,samldb,password_hash,operational,objectclass,rdn_name,partition
|
||||
@@ -0,0 +1,124 @@
|
||||
dn: CN=Templates
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Templates
|
||||
description: Container for SAM account templates
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
systemFlags: 2348810240
|
||||
objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
###
|
||||
# note! the template users must not match normal searches. Be careful
|
||||
# with what classes you put them in
|
||||
###
|
||||
|
||||
dn: CN=TemplateUser,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: person
|
||||
objectClass: organizationalPerson
|
||||
objectClass: Template
|
||||
objectClass: userTemplate
|
||||
cn: TemplateUser
|
||||
instanceType: 4
|
||||
userAccountControl: 514
|
||||
badPwdCount: 0
|
||||
codePage: 0
|
||||
countryCode: 0
|
||||
badPasswordTime: 0
|
||||
lastLogoff: 0
|
||||
lastLogon: 0
|
||||
pwdLastSet: 0
|
||||
primaryGroupID: 513
|
||||
accountExpires: -1
|
||||
logonCount: 0
|
||||
sAMAccountType: 805306368
|
||||
objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=TemplateComputer,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: person
|
||||
objectClass: organizationalPerson
|
||||
objectClass: Template
|
||||
objectClass: userTemplate
|
||||
cn: TemplateComputer
|
||||
instanceType: 4
|
||||
userAccountControl: 4098
|
||||
badPwdCount: 0
|
||||
codePage: 0
|
||||
countryCode: 0
|
||||
badPasswordTime: 0
|
||||
lastLogoff: 0
|
||||
lastLogon: 0
|
||||
pwdLastSet: 0
|
||||
primaryGroupID: 513
|
||||
accountExpires: -1
|
||||
logonCount: 0
|
||||
sAMAccountType: 805306369
|
||||
objectCategory: CN=Computer,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=TemplateTrustingDomain,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: Template
|
||||
objectClass: userTemplate
|
||||
cn: TemplateTrustingDomain
|
||||
instanceType: 4
|
||||
userAccountControl: 2080
|
||||
badPwdCount: 0
|
||||
codePage: 0
|
||||
countryCode: 0
|
||||
badPasswordTime: 0
|
||||
lastLogoff: 0
|
||||
lastLogon: 0
|
||||
primaryGroupID: 513
|
||||
accountExpires: -1
|
||||
logonCount: 0
|
||||
sAMAccountType: 805306370
|
||||
|
||||
dn: CN=TemplateGroup,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: Template
|
||||
objectClass: groupTemplate
|
||||
cn: TemplateGroup
|
||||
instanceType: 4
|
||||
groupType: -2147483646
|
||||
sAMAccountType: 268435456
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
# Currently this isn't used, we don't have a way to detect it different from an incoming alias
|
||||
#
|
||||
# dn: CN=TemplateAlias,CN=Templates
|
||||
# objectClass: top
|
||||
# objectClass: Template
|
||||
# objectClass: aliasTemplate
|
||||
# cn: TemplateAlias
|
||||
# instanceType: 4
|
||||
# groupType: -2147483644
|
||||
# sAMAccountType: 268435456
|
||||
|
||||
dn: CN=TemplateForeignSecurityPrincipal,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: Template
|
||||
objectClass: foreignSecurityPrincipalTemplate
|
||||
cn: TemplateForeignSecurityPrincipal
|
||||
instanceType: 4
|
||||
showInAdvancedViewOnly: TRUE
|
||||
objectCategory: CN=Foreign-Security-Principal,CN=Schema,CN=Configuration,${BASEDN}
|
||||
|
||||
dn: CN=TemplateSecret,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: leaf
|
||||
objectClass: Template
|
||||
objectClass: secretTemplate
|
||||
cn: TemplateSecret
|
||||
instanceType: 4
|
||||
|
||||
dn: CN=TemplateTrustedDomain,CN=Templates
|
||||
objectClass: top
|
||||
objectClass: leaf
|
||||
objectClass: Template
|
||||
objectClass: trustedDomainTemplate
|
||||
cn: TemplateTrustedDomain
|
||||
instanceType: 4
|
||||
|
||||
@@ -0,0 +1,388 @@
|
||||
dn: CN=Administrator,CN=Users,${BASEDN}
|
||||
objectClass: user
|
||||
cn: Administrator
|
||||
description: Built-in account for administering the computer/domain
|
||||
memberOf: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
|
||||
memberOf: CN=Domain Admins,CN=Users,${BASEDN}
|
||||
memberOf: CN=Enterprise Admins,CN=Users,${BASEDN}
|
||||
memberOf: CN=Schema Admins,CN=Users,${BASEDN}
|
||||
memberOf: CN=Administrators,CN=Builtin,${BASEDN}
|
||||
userAccountControl: 66048
|
||||
objectSid: ${DOMAINSID}-500
|
||||
adminCount: 1
|
||||
accountExpires: -1
|
||||
sAMAccountName: Administrator
|
||||
isCriticalSystemObject: TRUE
|
||||
sambaPassword: ${ADMINPASS}
|
||||
|
||||
dn: CN=Guest,CN=Users,${BASEDN}
|
||||
objectClass: user
|
||||
cn: Guest
|
||||
description: Built-in account for guest access to the computer/domain
|
||||
memberOf: CN=Guests,CN=Builtin,${BASEDN}
|
||||
userAccountControl: 66082
|
||||
primaryGroupID: 514
|
||||
objectSid: ${DOMAINSID}-501
|
||||
sAMAccountName: Guest
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Administrators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Administrators
|
||||
description: Administrators have complete and unrestricted access to the computer/domain
|
||||
member: CN=Domain Admins,CN=Users,${BASEDN}
|
||||
member: CN=Enterprise Admins,CN=Users,${BASEDN}
|
||||
member: CN=Administrator,CN=Users,${BASEDN}
|
||||
objectSid: S-1-5-32-544
|
||||
adminCount: 1
|
||||
sAMAccountName: Administrators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
privilege: SeSecurityPrivilege
|
||||
privilege: SeBackupPrivilege
|
||||
privilege: SeRestorePrivilege
|
||||
privilege: SeSystemtimePrivilege
|
||||
privilege: SeShutdownPrivilege
|
||||
privilege: SeRemoteShutdownPrivilege
|
||||
privilege: SeTakeOwnershipPrivilege
|
||||
privilege: SeDebugPrivilege
|
||||
privilege: SeSystemEnvironmentPrivilege
|
||||
privilege: SeSystemProfilePrivilege
|
||||
privilege: SeProfileSingleProcessPrivilege
|
||||
privilege: SeIncreaseBasePriorityPrivilege
|
||||
privilege: SeLoadDriverPrivilege
|
||||
privilege: SeCreatePagefilePrivilege
|
||||
privilege: SeIncreaseQuotaPrivilege
|
||||
privilege: SeChangeNotifyPrivilege
|
||||
privilege: SeUndockPrivilege
|
||||
privilege: SeManageVolumePrivilege
|
||||
privilege: SeImpersonatePrivilege
|
||||
privilege: SeCreateGlobalPrivilege
|
||||
privilege: SeEnableDelegationPrivilege
|
||||
privilege: SeInteractiveLogonRight
|
||||
privilege: SeNetworkLogonRight
|
||||
privilege: SeRemoteInteractiveLogonRight
|
||||
|
||||
|
||||
dn: CN=${NETBIOSNAME},CN=Domain Controllers,${BASEDN}
|
||||
objectClass: computer
|
||||
cn: ${NETBIOSNAME}
|
||||
userAccountControl: 532480
|
||||
localPolicyFlags: 0
|
||||
primaryGroupID: 516
|
||||
accountExpires: 9223372036854775807
|
||||
sAMAccountName: ${NETBIOSNAME}$
|
||||
sAMAccountType: 805306369
|
||||
operatingSystem: Samba
|
||||
operatingSystemVersion: 4.0
|
||||
dNSHostName: ${DNSNAME}
|
||||
isCriticalSystemObject: TRUE
|
||||
sambaPassword: ${MACHINEPASS}
|
||||
servicePrincipalName: HOST/${DNSNAME}
|
||||
servicePrincipalName: HOST/${NETBIOSNAME}
|
||||
servicePrincipalName: HOST/${DNSNAME}/${REALM}
|
||||
servicePrincipalName: HOST/${NETBIOSNAME}/${REALM}
|
||||
servicePrincipalName: HOST/${DNSNAME}/${DOMAIN}
|
||||
servicePrincipalName: HOST/${NETBIOSNAME}/${DOMAIN}
|
||||
${HOSTGUID_ADD}
|
||||
|
||||
dn: CN=Users,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Users
|
||||
description: Users are prevented from making accidental or intentional system-wide changes. Thus, Users can run certified applications, but not most legacy applications
|
||||
member: CN=Domain Users,CN=Users,${BASEDN}
|
||||
objectSid: S-1-5-32-545
|
||||
sAMAccountName: Users
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Guests,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Guests
|
||||
description: Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
|
||||
member: CN=Domain Guests,CN=Users,${BASEDN}
|
||||
member: CN=Guest,CN=Users,${BASEDN}
|
||||
objectSid: S-1-5-32-546
|
||||
sAMAccountName: Guests
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Print Operators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Print Operators
|
||||
description: Members can administer domain printers
|
||||
objectSid: S-1-5-32-550
|
||||
adminCount: 1
|
||||
sAMAccountName: Print Operators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
privilege: SeLoadDriverPrivilege
|
||||
privilege: SeShutdownPrivilege
|
||||
privilege: SeInteractiveLogonRight
|
||||
|
||||
dn: CN=Backup Operators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Backup Operators
|
||||
description: Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
|
||||
objectSid: S-1-5-32-551
|
||||
adminCount: 1
|
||||
sAMAccountName: Backup Operators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
privilege: SeBackupPrivilege
|
||||
privilege: SeRestorePrivilege
|
||||
privilege: SeShutdownPrivilege
|
||||
privilege: SeInteractiveLogonRight
|
||||
|
||||
dn: CN=Replicator,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Replicator
|
||||
description: Supports file replication in a domain
|
||||
objectSid: S-1-5-32-552
|
||||
adminCount: 1
|
||||
sAMAccountName: Replicator
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Remote Desktop Users,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Remote Desktop Users
|
||||
description: Members in this group are granted the right to logon remotely
|
||||
objectSid: S-1-5-32-555
|
||||
sAMAccountName: Remote Desktop Users
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Network Configuration Operators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Network Configuration Operators
|
||||
description: Members in this group can have some administrative privileges to manage configuration of networking features
|
||||
objectSid: S-1-5-32-556
|
||||
sAMAccountName: Network Configuration Operators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Performance Monitor Users,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Performance Monitor Users
|
||||
description: Members of this group have remote access to monitor this computer
|
||||
objectSid: S-1-5-32-558
|
||||
sAMAccountName: Performance Monitor Users
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Performance Log Users,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Performance Log Users
|
||||
description: Members of this group have remote access to schedule logging of performance counters on this computer
|
||||
objectSid: S-1-5-32-559
|
||||
sAMAccountName: Performance Log Users
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=krbtgt,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: person
|
||||
objectClass: organizationalPerson
|
||||
objectClass: user
|
||||
cn: krbtgt
|
||||
description: Key Distribution Center Service Account
|
||||
showInAdvancedViewOnly: TRUE
|
||||
userAccountControl: 514
|
||||
objectSid: ${DOMAINSID}-502
|
||||
adminCount: 1
|
||||
accountExpires: 9223372036854775807
|
||||
sAMAccountName: krbtgt
|
||||
sAMAccountType: 805306368
|
||||
servicePrincipalName: kadmin/changepw
|
||||
isCriticalSystemObject: TRUE
|
||||
sambaPassword: ${KRBTGTPASS}
|
||||
|
||||
dn: CN=Domain Computers,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Domain Computers
|
||||
description: All workstations and servers joined to the domain
|
||||
objectSid: ${DOMAINSID}-515
|
||||
sAMAccountName: Domain Computers
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Domain Controllers,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Domain Controllers
|
||||
description: All domain controllers in the domain
|
||||
objectSid: ${DOMAINSID}-516
|
||||
adminCount: 1
|
||||
sAMAccountName: Domain Controllers
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Schema Admins,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Schema Admins
|
||||
description: Designated administrators of the schema
|
||||
member: CN=Administrator,CN=Users,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-518
|
||||
adminCount: 1
|
||||
sAMAccountName: Schema Admins
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Enterprise Admins,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Enterprise Admins
|
||||
description: Designated administrators of the enterprise
|
||||
member: CN=Administrator,CN=Users,${BASEDN}
|
||||
memberOf: CN=Administrators,CN=Builtin,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-519
|
||||
adminCount: 1
|
||||
sAMAccountName: Enterprise Admins
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Cert Publishers,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Cert Publishers
|
||||
description: Members of this group are permitted to publish certificates to the Active Directory
|
||||
groupType: 2147483652
|
||||
sAMAccountType: 536870912
|
||||
objectSid: ${DOMAINSID}-517
|
||||
sAMAccountName: Cert Publishers
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Domain Admins,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Domain Admins
|
||||
description: Designated administrators of the domain
|
||||
member: CN=Administrator,CN=Users,${BASEDN}
|
||||
memberOf: CN=Administrators,CN=Builtin,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-512
|
||||
adminCount: 1
|
||||
sAMAccountName: Domain Admins
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Domain Users,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Domain Users
|
||||
description: All domain users
|
||||
memberOf: CN=Users,CN=Builtin,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-513
|
||||
sAMAccountName: Domain Users
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Domain Guests,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Domain Guests
|
||||
description: All domain guests
|
||||
memberOf: CN=Guests,CN=Builtin,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-514
|
||||
sAMAccountName: Domain Guests
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Group Policy Creator Owners
|
||||
description: Members in this group can modify group policy for the domain
|
||||
member: CN=Administrator,CN=Users,${BASEDN}
|
||||
objectSid: ${DOMAINSID}-520
|
||||
sAMAccountName: Group Policy Creator Owners
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=RAS and IAS Servers,CN=Users,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: RAS and IAS Servers
|
||||
description: Servers in this group can access remote access properties of users
|
||||
instanceType: 4
|
||||
objectSid: ${DOMAINSID}-553
|
||||
sAMAccountName: RAS and IAS Servers
|
||||
sAMAccountType: 536870912
|
||||
groupType: 2147483652
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
|
||||
dn: CN=Server Operators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Server Operators
|
||||
description: Members can administer domain servers
|
||||
instanceType: 4
|
||||
objectSid: S-1-5-32-549
|
||||
adminCount: 1
|
||||
sAMAccountName: Server Operators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
privilege: SeBackupPrivilege
|
||||
privilege: SeSystemtimePrivilege
|
||||
privilege: SeRemoteShutdownPrivilege
|
||||
privilege: SeRestorePrivilege
|
||||
privilege: SeShutdownPrivilege
|
||||
privilege: SeInteractiveLogonRight
|
||||
|
||||
dn: CN=Account Operators,CN=Builtin,${BASEDN}
|
||||
objectClass: top
|
||||
objectClass: group
|
||||
cn: Account Operators
|
||||
description: Members can administer domain user and group accounts
|
||||
instanceType: 4
|
||||
objectSid: S-1-5-32-548
|
||||
adminCount: 1
|
||||
sAMAccountName: Account Operators
|
||||
sAMAccountType: 536870912
|
||||
systemFlags: 2348810240
|
||||
groupType: 2147483653
|
||||
objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
|
||||
isCriticalSystemObject: TRUE
|
||||
privilege: SeInteractiveLogonRight
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
#Standard OpenLDAP attributes
|
||||
name
|
||||
objectClasses
|
||||
createTimeStamp
|
||||
attributeTypes
|
||||
objectClass
|
||||
userPassword
|
||||
seeAlso
|
||||
modifyTimeStamp
|
||||
distinguishedName
|
||||
description
|
||||
cn
|
||||
dITContentRules
|
||||
top
|
||||
#Skip ObjectClasses
|
||||
#
|
||||
#MiddleName has a conflicting OID
|
||||
2.16.840.1.113730.3.1.34:1.3.6.1.4.1.7165.4.255.1
|
||||
#defaultGroup has a conflicting OID
|
||||
1.2.840.113556.1.4.480:1.3.6.1.4.1.7165.4.255.2
|
||||
#This large integer format is unimplemented in OpenLDAP 2.3
|
||||
1.2.840.113556.1.4.906:1.3.6.1.4.1.1466.115.121.1.27
|
||||
#This case insensitive string isn't available
|
||||
1.2.840.113556.1.4.905:1.3.6.1.4.1.1466.115.121.1.15
|
||||
#This type of DN isn't in OpenLDAP
|
||||
1.2.840.113556.1.4.903:1.3.6.1.4.1.1466.115.121.1.12
|
||||
#Treat Security Descriptors as binary
|
||||
1.2.840.113556.1.4.907:1.3.6.1.4.1.1466.115.121.1.40
|
||||
#NumbericString is not supported in Fedora DS 1.0, map to a directory string
|
||||
1.3.6.1.4.1.1466.115.121.1.36:1.3.6.1.4.1.1466.115.121.1.15
|
||||
@@ -0,0 +1,33 @@
|
||||
#Standard OpenLDAP attributes
|
||||
name
|
||||
labeledURI
|
||||
objectClasses
|
||||
createTimeStamp
|
||||
attributeTypes
|
||||
objectClass
|
||||
userPassword
|
||||
seeAlso
|
||||
uid
|
||||
subSchemaSubEntry
|
||||
structuralObjectClass
|
||||
modifyTimeStamp
|
||||
distinguishedName
|
||||
description
|
||||
cn
|
||||
dITContentRules
|
||||
top
|
||||
#Skip ObjectClasses
|
||||
subSchema
|
||||
#
|
||||
#MiddleName has a conflicting OID
|
||||
2.16.840.1.113730.3.1.34:1.3.6.1.4.1.7165.4.255.1
|
||||
#defaultGroup has a conflicting OID
|
||||
1.2.840.113556.1.4.480:1.3.6.1.4.1.7165.4.255.2
|
||||
#This large integer format is unimplemented in OpenLDAP 2.3
|
||||
1.2.840.113556.1.4.906:1.3.6.1.4.1.1466.115.121.1.27
|
||||
#This case insensitive string isn't available
|
||||
1.2.840.113556.1.4.905:1.3.6.1.4.1.1466.115.121.1.44
|
||||
#This type of DN isn't in OpenLDAP
|
||||
1.2.840.113556.1.4.903:1.3.6.1.4.1.1466.115.121.1.12
|
||||
#Treat Security Descriptors as binary
|
||||
1.2.840.113556.1.4.907:1.3.6.1.4.1.1466.115.121.1.40
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,151 @@
|
||||
#
|
||||
# Schema elements which do not exist in AD, but which we use in Samba4
|
||||
#
|
||||
## Samba4 OID allocation from Samba3's examples/LDAP/samba.schema
|
||||
## 1.3.6.1.4.1.7165.4.1.x - attributetypes
|
||||
## 1.3.6.1.4.1.7165.4.2.x - objectclasses
|
||||
## 1.3.6.1.4.1.7165.4.255.x - mapped OIDs due to conflicts between AD and standards-track
|
||||
#
|
||||
#
|
||||
|
||||
|
||||
dn: cn=ntpwdHash,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: ntpwdHash
|
||||
name: NTPWDHash
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: ntpwdhash
|
||||
isSingleValued: TRUE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: E961130F-5084-458C-9E9C-DEC16DA08592
|
||||
adminDisplayName: NT-PWD-Hash
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.1
|
||||
attributeSyntax: 2.5.5.10
|
||||
oMSyntax: 4
|
||||
|
||||
dn: cn=lmpwdHash,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: lmpwdHash
|
||||
name: lmpwdHash
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: lmpwdhash
|
||||
isSingleValued: TRUE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: CBD0D18C-9C54-4A77-87C4-5CEEAF781253
|
||||
adminDisplayName: LM-PWD-Hash
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.2
|
||||
attributeSyntax: 2.5.5.10
|
||||
oMSyntax: 4
|
||||
|
||||
dn: cn=sambaNtPwdHistory,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: sambaNtPwdHistory
|
||||
name: sambaNtPwdHistory
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: sambaNtPwdHistory
|
||||
isSingleValued: TRUE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: 8CCD7658-C574-4435-A38C-99572E349E6B
|
||||
adminDisplayName: SAMBA-NT-PWD-History
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.3
|
||||
attributeSyntax: 2.5.5.10
|
||||
oMSyntax: 4
|
||||
|
||||
dn: cn=sambaLmPwdHistory,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: sambaLmPwdHistory
|
||||
name: sambaLmPwdHistory
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: sambaLmPwdHistory
|
||||
isSingleValued: FALSE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: 0EAFE3DD-0F53-495E-8A34-97BB28AF17A4
|
||||
adminDisplayName: SAMBA-LM-PWDHistory
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.4
|
||||
attributeSyntax: 2.5.5.10
|
||||
oMSyntax: 4
|
||||
|
||||
dn: cn=sambaPassword,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: sambaPassword
|
||||
name: sambaPassword
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: sambaPassword
|
||||
isSingleValued: FALSE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: 87F10301-229A-4E69-B63A-998339ADA37A
|
||||
adminDisplayName: SAMBA-Password
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.5
|
||||
attributeSyntax: 2.5.5.5
|
||||
oMSyntax: 22
|
||||
|
||||
dn: cn=dnsDomain,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: dnsDomain
|
||||
name: dnsDomain
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: dnsDomain
|
||||
isSingleValued: FALSE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: A40165E6-5E45-44A7-A8FA-186C94333018
|
||||
adminDisplayName: SAMBA-Password
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.6
|
||||
attributeSyntax: 2.5.5.4
|
||||
oMSyntax: 20
|
||||
|
||||
dn: cn=privilege,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: privilege
|
||||
name: privilege
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: privilege
|
||||
isSingleValued: FALSE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: 7429BC94-CC6A-4481-8B2C-A97E316EB182
|
||||
adminDisplayName: Privilege
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.7
|
||||
attributeSyntax: 2.5.5.4
|
||||
oMSyntax: 20
|
||||
|
||||
|
||||
dn: CN=unixName,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: unixName
|
||||
name: unixName
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: unixName
|
||||
isSingleValued: TRUE
|
||||
systemFlags: 16
|
||||
systemOnly: FALSE
|
||||
schemaIDGUID: bf9679f2-0de6-11d0-a285-00aa003049e2
|
||||
adminDisplayName: Unix-Name
|
||||
attributeID: 1.3.6.1.4.1.7165.4.1.9
|
||||
attributeSyntax: 2.5.5.4
|
||||
oMSyntax: 20
|
||||
|
||||
dn: cn=krb5Key,CN=Schema,CN=Configuration,${BASEDN}
|
||||
cn: krb5Key
|
||||
name: krb5Key
|
||||
objectClass: top
|
||||
objectClass: attributeSchema
|
||||
lDAPDisplayName: krb5Key
|
||||
isSingleValued: FALSE
|
||||
systemFlags: 17
|
||||
systemOnly: TRUE
|
||||
schemaIDGUID: 0EAFE3DD-0F53-495E-8A34-97BB28AF17A4
|
||||
adminDisplayName: krb5-Key
|
||||
attributeID: 1.3.6.1.4.1.5322.10.1.10
|
||||
attributeSyntax: 2.5.5.10
|
||||
oMSyntax: 4
|
||||
|
||||
|
||||
#Allocated: (middleName) attributeID: 1.3.6.1.4.1.7165.4.255.1
|
||||
|
||||
#Allocated: (defaultGroup) attributeID: 1.3.6.1.4.1.7165.4.255.2
|
||||
@@ -0,0 +1,55 @@
|
||||
dn: @INDEXLIST
|
||||
@IDXATTR: cn
|
||||
@IDXATTR: flatname
|
||||
@IDXATTR: realm
|
||||
|
||||
dn: @ATTRIBUTES
|
||||
realm: CASE_INSENSITIVE
|
||||
flatname: CASE_INSENSITIVE
|
||||
sAMAccountName: CASE_INSENSITIVE
|
||||
|
||||
#Add modules to the list to activate them by default
|
||||
#beware often order is important
|
||||
dn: @MODULES
|
||||
@LIST: operational
|
||||
|
||||
dn: CN=LSA Secrets
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: LSA Secrets
|
||||
|
||||
dn: CN=Primary Domains
|
||||
objectClass: top
|
||||
objectClass: container
|
||||
cn: Primary Domains
|
||||
|
||||
dn: flatname=${DOMAIN},CN=Primary Domains
|
||||
objectClass: top
|
||||
objectClass: primaryDomain
|
||||
objectClass: kerberosSecret
|
||||
flatname: ${DOMAIN}
|
||||
realm: ${REALM}
|
||||
secret: ${MACHINEPASS}
|
||||
secureChannelType: 6
|
||||
sAMAccountName: ${NETBIOSNAME}$
|
||||
whenCreated: ${LDAPTIME}
|
||||
whenChanged: ${LDAPTIME}
|
||||
msDS-KeyVersionNumber: 1
|
||||
objectSid: ${DOMAINSID}
|
||||
privateKeytab: secrets.keytab
|
||||
|
||||
# A hook from our credentials system into HDB, as we must be on a KDC,
|
||||
# we can look directly into the database.
|
||||
dn: samAccountName=krbtgt,flatname=${DOMAIN},CN=Principals
|
||||
objectClass: top
|
||||
objectClass: secret
|
||||
objectClass: kerberosSecret
|
||||
flatname: ${DOMAIN}
|
||||
realm: ${REALM}
|
||||
sAMAccountName: krbtgt
|
||||
whenCreated: ${LDAPTIME}
|
||||
whenChanged: ${LDAPTIME}
|
||||
objectSid: ${DOMAINSID}
|
||||
servicePrincipalName: kadmin/changepw
|
||||
krb5Keytab: HDB:ldb:sam.ldb:
|
||||
#The trailing : here is a HACK, but it matches the Heimdal format.
|
||||
@@ -0,0 +1,122 @@
|
||||
#!/bin/sh
|
||||
exec smbscript "$0" ${1+"$@"}
|
||||
/*
|
||||
set a user's password on a Samba4 server
|
||||
Copyright Andrew Tridgell 2005
|
||||
Copyright Andrew Bartlett 2006
|
||||
Released under the GNU GPL v2 or later
|
||||
*/
|
||||
|
||||
options = GetOptions(ARGV,
|
||||
"POPT_AUTOHELP",
|
||||
'username=s',
|
||||
'filter=s',
|
||||
'newpassword=s',
|
||||
"POPT_COMMON_SAMBA",
|
||||
"POPT_COMMON_VERSION",
|
||||
"POPT_COMMON_CREDENTIALS",
|
||||
'quiet');
|
||||
|
||||
if (options == undefined) {
|
||||
println("Failed to parse options");
|
||||
return -1;
|
||||
}
|
||||
|
||||
libinclude("base.js");
|
||||
libinclude("provision.js");
|
||||
|
||||
/*
|
||||
print a message if quiet is not set
|
||||
*/
|
||||
function message()
|
||||
{
|
||||
if (options["quiet"] == undefined) {
|
||||
print(vsprintf(arguments));
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
show some help
|
||||
*/
|
||||
function ShowHelp()
|
||||
{
|
||||
print("
|
||||
Samba4 newuser
|
||||
|
||||
newuser [options]
|
||||
--username USERNAME username
|
||||
--filter LDAPFILTER LDAP Filter to set password on
|
||||
--newpassword PASSWORD set password
|
||||
|
||||
You must provide either a filter or a username, as well as password
|
||||
");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (options['username'] == undefined && options['filter'] == undefined) {
|
||||
ShowHelp();
|
||||
}
|
||||
|
||||
if (options['newpassword'] == undefined) {
|
||||
ShowHelp();
|
||||
}
|
||||
|
||||
var lp = loadparm_init();
|
||||
var samdb = lp.get("sam database");
|
||||
var ldb = ldb_init();
|
||||
random_init(local);
|
||||
ldb.session_info = system_session();
|
||||
ldb.credentials = options.get_credentials();
|
||||
|
||||
/* connect to the sam */
|
||||
var ok = ldb.connect(samdb);
|
||||
assert(ok);
|
||||
|
||||
ldb.transaction_start();
|
||||
|
||||
/* find the DNs for the domain and the domain users group */
|
||||
var attrs = new Array("defaultNamingContext");
|
||||
var attrs2 = new Array("cn");
|
||||
res = ldb.search("defaultNamingContext=*", "", ldb.SCOPE_BASE, attrs);
|
||||
assert(res.length == 1 && res[0].defaultNamingContext != undefined);
|
||||
var domain_dn = res[0].defaultNamingContext;
|
||||
assert(domain_dn != undefined);
|
||||
|
||||
if (options['filter'] != undefined) {
|
||||
var res = ldb.search(options['filter'],
|
||||
domain_dn, ldb.SCOPE_SUBTREE, attrs2);
|
||||
if (res.length != 1) {
|
||||
message("Failed to find record for filter %s\n", options['filter']);
|
||||
exit(1);
|
||||
}
|
||||
} else {
|
||||
var res = ldb.search(sprintf("samAccountName=%s", options['username']),
|
||||
domain_dn, ldb.SCOPE_SUBTREE, attrs2);
|
||||
if (res.length != 1) {
|
||||
message("Failed to find record for user %s\n", options['username']);
|
||||
exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
var mod = sprintf("
|
||||
dn: %s
|
||||
changetype: modify
|
||||
replace: sambaPassword
|
||||
sambaPassword: %s
|
||||
",
|
||||
res[0].dn, options['newpassword']);
|
||||
var ok = ldb.modify(mod);
|
||||
if (!ok) {
|
||||
message("set password for %s failed - %s\n",
|
||||
res[0].dn, ldb.errstring());
|
||||
ldb.transaction_cancel();
|
||||
exit(1);
|
||||
} else {
|
||||
message("set password for %s (%s) succeded\n",
|
||||
res[0].dn, res[0].cn);
|
||||
|
||||
ldb.transaction_commit();
|
||||
}
|
||||
|
||||
|
||||
return 0;
|
||||
@@ -0,0 +1,46 @@
|
||||
dn: @INDEXLIST
|
||||
@IDXATTR: name
|
||||
|
||||
dn: @ATTRIBUTES
|
||||
cn: CASE_INSENSITIVE
|
||||
dc: CASE_INSENSITIVE
|
||||
name: CASE_INSENSITIVE
|
||||
dn: CASE_INSENSITIVE
|
||||
objectClass: CASE_INSENSITIVE
|
||||
|
||||
### Shares basedn
|
||||
dn: CN=Shares
|
||||
objectClass: top
|
||||
objectClass: organizationalUnit
|
||||
cn: Shares
|
||||
|
||||
### Default IPC$ Share
|
||||
dn: CN=IPC$,CN=Shares
|
||||
objectClass: top
|
||||
objectClass: share
|
||||
cn: IPC$
|
||||
name: IPC$
|
||||
type: IPC
|
||||
path: /tmp
|
||||
comment: Remote IPC
|
||||
max-connections: -1
|
||||
available: True
|
||||
readonly: True
|
||||
browseable: False
|
||||
ntvfs-handler: default
|
||||
|
||||
### Default ADMIN$ Share
|
||||
dn: CN=ADMIN$,CN=Shares
|
||||
objectClass: top
|
||||
objectClass: share
|
||||
cn: ADMIN$
|
||||
name: ADMIN$
|
||||
type: DISK
|
||||
path: /tmp
|
||||
comment: Remote Admin
|
||||
max-connections: -1
|
||||
available: True
|
||||
readonly: True
|
||||
browseable: False
|
||||
ntvfs-handler: default
|
||||
|
||||
Executable
+114
@@ -0,0 +1,114 @@
|
||||
#!/bin/sh
|
||||
exec smbscript "$0" ${1+"$@"}
|
||||
/*
|
||||
Upgrade from Samba3
|
||||
Copyright Jelmer Vernooij 2005
|
||||
Released under the GNU GPL v2 or later
|
||||
*/
|
||||
|
||||
options = GetOptions(ARGV,
|
||||
"POPT_AUTOHELP",
|
||||
"POPT_COMMON_SAMBA",
|
||||
"POPT_COMMON_VERSION",
|
||||
"POPT_COMMON_CREDENTIALS",
|
||||
'verify',
|
||||
'targetdir=s',
|
||||
'quiet',
|
||||
'realm',
|
||||
'blank');
|
||||
|
||||
if (options == undefined) {
|
||||
println("Failed to parse options");
|
||||
return -1;
|
||||
}
|
||||
|
||||
libinclude("base.js");
|
||||
libinclude("provision.js");
|
||||
libinclude("upgrade.js");
|
||||
|
||||
/*
|
||||
print a message if quiet is not set
|
||||
*/
|
||||
function message()
|
||||
{
|
||||
if (options["quiet"] == undefined) {
|
||||
print(vsprintf(arguments));
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
show some help
|
||||
*/
|
||||
function ShowHelp()
|
||||
{
|
||||
print("
|
||||
Samba4 import tool
|
||||
|
||||
provision [options] <libdir> <smbconf>
|
||||
--targetdir=DIR Output to specified directory
|
||||
--quiet Be quiet
|
||||
--blank Do not add users or groups, just the structure
|
||||
--realm=REALM Override realm to use
|
||||
|
||||
");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if (options.ARGV.length != 2) {
|
||||
ShowHelp();
|
||||
exit(1);
|
||||
}
|
||||
|
||||
var lp = loadparm_init();
|
||||
|
||||
message("Reading Samba3 databases and smb.conf\n");
|
||||
var samba3 = samba3_read(options.ARGV[0], options.ARGV[1]);
|
||||
|
||||
if (samba3 == undefined) {
|
||||
println("Error reading Samba3 data");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
|
||||
|
||||
message("Provisioning\n");
|
||||
var subobj = upgrade_provision(samba3);
|
||||
var paths;
|
||||
if (options.targetdir != undefined) {
|
||||
paths = new Object();
|
||||
paths.smbconf = sprintf("%s/smb.conf", options.targetdir);
|
||||
var ldbs = new Array("hklm","hkcr","hku","hkcu","hkpd","hkpt","samdb","rootdse","secrets","wins");
|
||||
for (var i in ldbs) {
|
||||
var n = ldbs[i];
|
||||
paths[n] = sprintf("tdb://%s/%s.ldb", options.targetdir, n);
|
||||
}
|
||||
paths.dns = options.targetdir+"/dns.zone";
|
||||
} else {
|
||||
paths = provision_default_paths(subobj);;
|
||||
}
|
||||
|
||||
var creds = options.get_credentials();
|
||||
var system_session = system_session();
|
||||
var paths = provision_default_paths(subobj);
|
||||
|
||||
if (options.realm != undefined) {
|
||||
subobj.REALM = options.realm;
|
||||
}
|
||||
|
||||
provision(subobj, message, options.blank, paths, system_session, creds);
|
||||
|
||||
var ret = upgrade(subobj,samba3,message,paths, system_session, creds);
|
||||
if (ret > 0) {
|
||||
message("Failed to import %d entries\n", ret);
|
||||
} else {
|
||||
provision_dns(subobj, message, paths, system_session, creds);
|
||||
|
||||
message("All OK\n");
|
||||
}
|
||||
|
||||
if (options.verify != undefined) {
|
||||
message("Verifying...\n");
|
||||
ret = upgrade_verify(subobj, samba3,paths,message);
|
||||
}
|
||||
|
||||
return ret;
|
||||
Reference in New Issue
Block a user