|
|
541bac |
From eea6a8071b5e5df74808903bb15b30acf820ce3f Mon Sep 17 00:00:00 2001
|
|
|
541bac |
From: Sumit Bose <sbose@redhat.com>
|
|
|
541bac |
Date: Fri, 23 Oct 2020 16:55:11 +0200
|
|
|
541bac |
Subject: [PATCH 3/7] enroll: use 'computer' or 'service' in debug messages
|
|
|
541bac |
|
|
|
541bac |
Use proper account type in debug messages.
|
|
|
541bac |
|
|
|
541bac |
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1854112
|
|
|
541bac |
---
|
|
|
541bac |
library/adenroll.c | 115 ++++++++++++++++++++++++++++-----------------
|
|
|
541bac |
1 file changed, 72 insertions(+), 43 deletions(-)
|
|
|
541bac |
|
|
|
541bac |
diff --git a/library/adenroll.c b/library/adenroll.c
|
|
|
541bac |
index dbfda36..9cdc79b 100644
|
|
|
541bac |
--- a/library/adenroll.c
|
|
|
541bac |
+++ b/library/adenroll.c
|
|
|
541bac |
@@ -155,6 +155,12 @@ struct _adcli_enroll {
|
|
|
541bac |
char *description;
|
|
|
541bac |
};
|
|
|
541bac |
|
|
|
541bac |
+static const char *
|
|
|
541bac |
+s_or_c (adcli_enroll *enroll)
|
|
|
541bac |
+{
|
|
|
541bac |
+ return enroll->is_service ? "service" : "computer";
|
|
|
541bac |
+}
|
|
|
541bac |
+
|
|
|
541bac |
static void
|
|
|
541bac |
check_if_service (adcli_enroll *enroll,
|
|
|
541bac |
LDAP *ldap,
|
|
|
541bac |
@@ -203,13 +209,15 @@ ensure_computer_name (adcli_result res,
|
|
|
541bac |
return res;
|
|
|
541bac |
|
|
|
541bac |
if (enroll->computer_name) {
|
|
|
541bac |
- _adcli_info ("Enrolling computer name: %s",
|
|
|
541bac |
+ _adcli_info ("Enrolling %s name: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_name);
|
|
|
541bac |
return ADCLI_SUCCESS;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
if (!enroll->host_fqdn) {
|
|
|
541bac |
- _adcli_err ("No host name from which to determine the computer name");
|
|
|
541bac |
+ _adcli_err ("No host name from which to determine the %s name",
|
|
|
541bac |
+ s_or_c (enroll));
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -603,7 +611,8 @@ lookup_computer_container (adcli_enroll *enroll,
|
|
|
541bac |
|
|
|
541bac |
} else if (ret != LDAP_SUCCESS) {
|
|
|
541bac |
return _adcli_ldap_handle_failure (ldap, ADCLI_ERR_DIRECTORY,
|
|
|
541bac |
- "Couldn't lookup computer container: %s", base);
|
|
|
541bac |
+ "Couldn't lookup %s container: %s",
|
|
|
541bac |
+ s_or_c (enroll), base);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
values = _adcli_ldap_parse_values (ldap, results, attrs[0]);
|
|
|
541bac |
@@ -614,8 +623,8 @@ lookup_computer_container (adcli_enroll *enroll,
|
|
|
541bac |
if (strncmp (values[i], prefix, prefix_len) == 0) {
|
|
|
541bac |
enroll->computer_container = strdup (values[i] + prefix_len);
|
|
|
541bac |
return_unexpected_if_fail (enroll->computer_container != NULL);
|
|
|
541bac |
- _adcli_info ("Found well known computer container at: %s",
|
|
|
541bac |
- enroll->computer_container);
|
|
|
541bac |
+ _adcli_info ("Found well known %s container at: %s",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_container);
|
|
|
541bac |
break;
|
|
|
541bac |
}
|
|
|
541bac |
}
|
|
|
541bac |
@@ -629,8 +638,9 @@ lookup_computer_container (adcli_enroll *enroll,
|
|
|
541bac |
if (ret == LDAP_SUCCESS) {
|
|
|
541bac |
enroll->computer_container = _adcli_ldap_parse_dn (ldap, results);
|
|
|
541bac |
if (enroll->computer_container) {
|
|
|
541bac |
- _adcli_info ("Well known computer container not "
|
|
|
541bac |
+ _adcli_info ("Well known %s container not "
|
|
|
541bac |
"found, but found suitable one at: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_container);
|
|
|
541bac |
}
|
|
|
541bac |
}
|
|
|
541bac |
@@ -646,7 +656,8 @@ lookup_computer_container (adcli_enroll *enroll,
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
if (!enroll->computer_container) {
|
|
|
541bac |
- _adcli_err ("Couldn't find location to create computer accounts");
|
|
|
541bac |
+ _adcli_err ("Couldn't find location to create %s accounts",
|
|
|
541bac |
+ s_or_c (enroll));
|
|
|
541bac |
return ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -674,7 +685,8 @@ calculate_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
if (asprintf (&enroll->computer_dn, "CN=%s,%s", enroll->computer_name, enroll->computer_container) < 0)
|
|
|
541bac |
return_unexpected_if_reached ();
|
|
|
541bac |
|
|
|
541bac |
- _adcli_info ("Calculated computer account: %s", enroll->computer_dn);
|
|
|
541bac |
+ _adcli_info ("Calculated %s account: %s",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_dn);
|
|
|
541bac |
return ADCLI_SUCCESS;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -861,7 +873,8 @@ create_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
- _adcli_info ("Created computer account: %s", enroll->computer_dn);
|
|
|
541bac |
+ _adcli_info ("Created %s account: %s", s_or_c (enroll),
|
|
|
541bac |
+ enroll->computer_dn);
|
|
|
541bac |
return ADCLI_SUCCESS;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -908,17 +921,17 @@ validate_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
assert (enroll->computer_dn != NULL);
|
|
|
541bac |
|
|
|
541bac |
if (already_exists && !allow_overwrite) {
|
|
|
541bac |
- _adcli_err ("The computer account %s already exists",
|
|
|
541bac |
- enroll->computer_name);
|
|
|
541bac |
+ _adcli_err ("The %s account %s already exists",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_name);
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
/* Do we have an explicitly requested ou? */
|
|
|
541bac |
if (enroll->domain_ou && enroll->domain_ou_explicit && already_exists) {
|
|
|
541bac |
if (!_adcli_ldap_dn_has_ancestor (enroll->computer_dn, enroll->domain_ou)) {
|
|
|
541bac |
- _adcli_err ("The computer account %s already exists, "
|
|
|
541bac |
+ _adcli_err ("The %s account %s already exists, "
|
|
|
541bac |
"but is not in the desired organizational unit.",
|
|
|
541bac |
- enroll->computer_name);
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_name);
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
}
|
|
|
541bac |
@@ -943,7 +956,8 @@ delete_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
"Couldn't delete computer account: %s",
|
|
|
541bac |
enroll->computer_dn);
|
|
|
541bac |
} else {
|
|
|
541bac |
- _adcli_info ("Deleted computer account at: %s", enroll->computer_dn);
|
|
|
541bac |
+ _adcli_info ("Deleted %s account at: %s", s_or_c (enroll),
|
|
|
541bac |
+ enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
return ADCLI_SUCCESS;
|
|
|
541bac |
@@ -992,20 +1006,21 @@ locate_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
free (enroll->computer_dn);
|
|
|
541bac |
enroll->computer_dn = strdup (dn);
|
|
|
541bac |
return_unexpected_if_fail (enroll->computer_dn != NULL);
|
|
|
541bac |
- _adcli_info ("Found computer account for %s at: %s",
|
|
|
541bac |
- enroll->computer_sam, dn);
|
|
|
541bac |
+ _adcli_info ("Found %s account for %s at: %s",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_sam, dn);
|
|
|
541bac |
ldap_memfree (dn);
|
|
|
541bac |
|
|
|
541bac |
} else {
|
|
|
541bac |
ldap_msgfree (results);
|
|
|
541bac |
results = NULL;
|
|
|
541bac |
- _adcli_info ("Computer account for %s does not exist",
|
|
|
541bac |
- enroll->computer_sam);
|
|
|
541bac |
+ _adcli_info ("A %s account for %s does not exist",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_sam);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
} else {
|
|
|
541bac |
return _adcli_ldap_handle_failure (ldap, ADCLI_ERR_DIRECTORY,
|
|
|
541bac |
- "Couldn't lookup computer account: %s",
|
|
|
541bac |
+ "Couldn't lookup %s account: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1039,7 +1054,9 @@ load_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
if (ret == LDAP_SUCCESS) {
|
|
|
541bac |
entry = ldap_first_entry (ldap, results);
|
|
|
541bac |
if (entry) {
|
|
|
541bac |
- _adcli_info ("Found computer account for %s at: %s",
|
|
|
541bac |
+ check_if_service (enroll, ldap, results);
|
|
|
541bac |
+ _adcli_info ("Found %s account for %s at: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam, enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1146,7 +1163,8 @@ set_password_with_user_creds (adcli_enroll *enroll)
|
|
|
541bac |
&result_code_string, &result_string);
|
|
|
541bac |
|
|
|
541bac |
if (code != 0) {
|
|
|
541bac |
- _adcli_err ("Couldn't set password for computer account: %s: %s",
|
|
|
541bac |
+ _adcli_err ("Couldn't set password for %s account: %s: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam, krb5_get_error_message (k5, code));
|
|
|
541bac |
/* TODO: Parse out these values */
|
|
|
541bac |
res = ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
@@ -1160,7 +1178,8 @@ set_password_with_user_creds (adcli_enroll *enroll)
|
|
|
541bac |
if (result_string.length)
|
|
|
541bac |
message = _adcli_str_dupn (result_string.data, result_string.length);
|
|
|
541bac |
#endif
|
|
|
541bac |
- _adcli_err ("Cannot set computer password: %.*s%s%s",
|
|
|
541bac |
+ _adcli_err ("Cannot set %s password: %.*s%s%s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
(int)result_code_string.length, result_code_string.data,
|
|
|
541bac |
message ? ": " : "", message ? message : "");
|
|
|
541bac |
res = ADCLI_ERR_CREDENTIALS;
|
|
|
541bac |
@@ -1170,7 +1189,7 @@ set_password_with_user_creds (adcli_enroll *enroll)
|
|
|
541bac |
free (message);
|
|
|
541bac |
#endif
|
|
|
541bac |
} else {
|
|
|
541bac |
- _adcli_info ("Set computer password");
|
|
|
541bac |
+ _adcli_info ("Set %s password", s_or_c (enroll));
|
|
|
541bac |
if (enroll->kvno > 0) {
|
|
|
541bac |
enroll->kvno++;
|
|
|
541bac |
_adcli_info ("kvno incremented to %d", enroll->kvno);
|
|
|
541bac |
@@ -1203,7 +1222,8 @@ set_password_with_computer_creds (adcli_enroll *enroll)
|
|
|
541bac |
|
|
|
541bac |
code = _adcli_kinit_computer_creds (enroll->conn, "kadmin/changepw", NULL, &creds);
|
|
|
541bac |
if (code != 0) {
|
|
|
541bac |
- _adcli_err ("Couldn't get change password ticket for computer account: %s: %s",
|
|
|
541bac |
+ _adcli_err ("Couldn't get change password ticket for %s account: %s: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam, krb5_get_error_message (k5, code));
|
|
|
541bac |
return ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
}
|
|
|
541bac |
@@ -1214,7 +1234,8 @@ set_password_with_computer_creds (adcli_enroll *enroll)
|
|
|
541bac |
krb5_free_cred_contents (k5, &creds);
|
|
|
541bac |
|
|
|
541bac |
if (code != 0) {
|
|
|
541bac |
- _adcli_err ("Couldn't change password for computer account: %s: %s",
|
|
|
541bac |
+ _adcli_err ("Couldn't change password for %s account: %s: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam, krb5_get_error_message (k5, code));
|
|
|
541bac |
/* TODO: Parse out these values */
|
|
|
541bac |
res = ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
@@ -1284,7 +1305,8 @@ retrieve_computer_account (adcli_enroll *enroll)
|
|
|
541bac |
|
|
|
541bac |
if (ret != LDAP_SUCCESS) {
|
|
|
541bac |
return _adcli_ldap_handle_failure (ldap, ADCLI_ERR_DIRECTORY,
|
|
|
541bac |
- "Couldn't retrieve computer account info: %s",
|
|
|
541bac |
+ "Couldn't retrieve %s account info: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1294,15 +1316,15 @@ retrieve_computer_account (adcli_enroll *enroll)
|
|
|
541bac |
if (value != NULL) {
|
|
|
541bac |
kvno = strtoul (value, &end, 10);
|
|
|
541bac |
if (end == NULL || *end != '\0') {
|
|
|
541bac |
- _adcli_err ("Invalid kvno '%s' for computer account in directory: %s",
|
|
|
541bac |
- value, enroll->computer_dn);
|
|
|
541bac |
+ _adcli_err ("Invalid kvno '%s' for %s account in directory: %s",
|
|
|
541bac |
+ value, s_or_c (enroll), enroll->computer_dn);
|
|
|
541bac |
res = ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
|
|
|
541bac |
} else {
|
|
|
541bac |
enroll->kvno = kvno;
|
|
|
541bac |
|
|
|
541bac |
- _adcli_info ("Retrieved kvno '%s' for computer account in directory: %s",
|
|
|
541bac |
- value, enroll->computer_dn);
|
|
|
541bac |
+ _adcli_info ("Retrieved kvno '%s' for %s account in directory: %s",
|
|
|
541bac |
+ value, s_or_c (enroll), enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
free (value);
|
|
|
541bac |
@@ -1311,8 +1333,8 @@ retrieve_computer_account (adcli_enroll *enroll)
|
|
|
541bac |
/* Apparently old AD didn't have this attribute, use zero */
|
|
|
541bac |
enroll->kvno = 0;
|
|
|
541bac |
|
|
|
541bac |
- _adcli_info ("No kvno found for computer account in directory: %s",
|
|
|
541bac |
- enroll->computer_dn);
|
|
|
541bac |
+ _adcli_info ("No kvno found for %s account in directory: %s",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1353,12 +1375,14 @@ update_and_calculate_enctypes (adcli_enroll *enroll)
|
|
|
541bac |
|
|
|
541bac |
if (ret == LDAP_INSUFFICIENT_ACCESS) {
|
|
|
541bac |
return _adcli_ldap_handle_failure (ldap, ADCLI_ERR_CREDENTIALS,
|
|
|
541bac |
- "Insufficient permissions to set encryption types on computer account: %s",
|
|
|
541bac |
+ "Insufficient permissions to set encryption types on %s account: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_dn);
|
|
|
541bac |
|
|
|
541bac |
} else if (ret != LDAP_SUCCESS) {
|
|
|
541bac |
return _adcli_ldap_handle_failure (ldap, ADCLI_ERR_DIRECTORY,
|
|
|
541bac |
- "Couldn't set encryption types on computer account: %s",
|
|
|
541bac |
+ "Couldn't set encryption types on %s account: %s",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_dn);
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1381,13 +1405,14 @@ update_computer_attribute (adcli_enroll *enroll,
|
|
|
541bac |
string = _adcli_ldap_mods_to_string (mods);
|
|
|
541bac |
return_unexpected_if_fail (string != NULL);
|
|
|
541bac |
|
|
|
541bac |
- _adcli_info ("Modifying computer account: %s", string);
|
|
|
541bac |
+ _adcli_info ("Modifying %s account: %s", s_or_c (enroll), string);
|
|
|
541bac |
|
|
|
541bac |
ret = ldap_modify_ext_s (ldap, enroll->computer_dn, mods, NULL, NULL);
|
|
|
541bac |
|
|
|
541bac |
if (ret != LDAP_SUCCESS) {
|
|
|
541bac |
- _adcli_warn ("Couldn't set %s on computer account: %s: %s",
|
|
|
541bac |
- string, enroll->computer_dn, ldap_err2string (ret));
|
|
|
541bac |
+ _adcli_warn ("Couldn't set %s on %s account: %s: %s",
|
|
|
541bac |
+ string, s_or_c (enroll), enroll->computer_dn,
|
|
|
541bac |
+ ldap_err2string (ret));
|
|
|
541bac |
res = ADCLI_ERR_DIRECTORY;
|
|
|
541bac |
}
|
|
|
541bac |
|
|
|
541bac |
@@ -1411,8 +1436,8 @@ static char *get_user_account_control (adcli_enroll *enroll)
|
|
|
541bac |
|
|
|
541bac |
attr_val = strtoul (uac_str, &end, 10);
|
|
|
541bac |
if (*end != '\0' || attr_val > UINT32_MAX) {
|
|
|
541bac |
- _adcli_warn ("Invalid userAccountControl '%s' for computer account in directory: %s, assuming 0",
|
|
|
541bac |
- uac_str, enroll->computer_dn);
|
|
|
541bac |
+ _adcli_warn ("Invalid userAccountControl '%s' for %s account in directory: %s, assuming 0",
|
|
|
541bac |
+ uac_str, s_or_c (enroll), enroll->computer_dn);
|
|
|
541bac |
} else {
|
|
|
541bac |
uac = attr_val;
|
|
|
541bac |
}
|
|
|
541bac |
@@ -1653,7 +1678,8 @@ load_keytab_entry (krb5_context k5,
|
|
|
541bac |
_adcli_str_has_suffix (name, "$") && !strchr (name, '/')) {
|
|
|
541bac |
enroll->computer_name = name;
|
|
|
541bac |
name[len - 1] = '\0';
|
|
|
541bac |
- _adcli_info ("Found computer name in keytab: %s", name);
|
|
|
541bac |
+ _adcli_info ("Found %s name in keytab: %s",
|
|
|
541bac |
+ s_or_c (enroll), name);
|
|
|
541bac |
adcli_conn_set_computer_name (enroll->conn,
|
|
|
541bac |
enroll->computer_name);
|
|
|
541bac |
name = NULL;
|
|
|
541bac |
@@ -2348,7 +2374,8 @@ adcli_enroll_read_computer_account (adcli_enroll *enroll,
|
|
|
541bac |
if (res != ADCLI_SUCCESS)
|
|
|
541bac |
return res;
|
|
|
541bac |
if (!enroll->computer_dn) {
|
|
|
541bac |
- _adcli_err ("No computer account for %s exists", enroll->computer_sam);
|
|
|
541bac |
+ _adcli_err ("No %s account for %s exists",
|
|
|
541bac |
+ s_or_c (enroll), enroll->computer_sam);
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
}
|
|
|
541bac |
@@ -2460,7 +2487,8 @@ adcli_enroll_delete (adcli_enroll *enroll,
|
|
|
541bac |
if (res != ADCLI_SUCCESS)
|
|
|
541bac |
return res;
|
|
|
541bac |
if (!enroll->computer_dn) {
|
|
|
541bac |
- _adcli_err ("No computer account for %s exists",
|
|
|
541bac |
+ _adcli_err ("No %s account for %s exists",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam);
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
@@ -2503,7 +2531,8 @@ adcli_enroll_password (adcli_enroll *enroll,
|
|
|
541bac |
if (res != ADCLI_SUCCESS)
|
|
|
541bac |
return res;
|
|
|
541bac |
if (!enroll->computer_dn) {
|
|
|
541bac |
- _adcli_err ("No computer account for %s exists",
|
|
|
541bac |
+ _adcli_err ("No %s account for %s exists",
|
|
|
541bac |
+ s_or_c (enroll),
|
|
|
541bac |
enroll->computer_sam);
|
|
|
541bac |
return ADCLI_ERR_CONFIG;
|
|
|
541bac |
}
|
|
|
541bac |
--
|
|
|
541bac |
2.28.0
|
|
|
541bac |
|