1 | #!/usr/bin/env python
|
---|
2 | #
|
---|
3 | # Unix SMB/CIFS implementation.
|
---|
4 | # provision a Samba4 server
|
---|
5 | # Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2007-2008
|
---|
6 | # Copyright (C) Andrew Bartlett <abartlet@samba.org> 2008
|
---|
7 | #
|
---|
8 | # Based on the original in EJS:
|
---|
9 | # Copyright (C) Andrew Tridgell 2005
|
---|
10 | #
|
---|
11 | # This program is free software; you can redistribute it and/or modify
|
---|
12 | # it under the terms of the GNU General Public License as published by
|
---|
13 | # the Free Software Foundation; either version 3 of the License, or
|
---|
14 | # (at your option) any later version.
|
---|
15 | #
|
---|
16 | # This program is distributed in the hope that it will be useful,
|
---|
17 | # but WITHOUT ANY WARRANTY; without even the implied warranty of
|
---|
18 | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
---|
19 | # GNU General Public License for more details.
|
---|
20 | #
|
---|
21 | # You should have received a copy of the GNU General Public License
|
---|
22 | # along with this program. If not, see <http://www.gnu.org/licenses/>.
|
---|
23 | #
|
---|
24 |
|
---|
25 | import logging
|
---|
26 | import optparse
|
---|
27 | import sys
|
---|
28 | import tempfile
|
---|
29 |
|
---|
30 | # Find right directory when running from source tree
|
---|
31 | sys.path.insert(0, "bin/python")
|
---|
32 |
|
---|
33 | import samba
|
---|
34 | import samba.ntacls
|
---|
35 | from samba.credentials import DONT_USE_KERBEROS
|
---|
36 | from samba.auth import system_session
|
---|
37 | import samba.getopt as options
|
---|
38 | from samba.provision import provision, FILL_FULL, FILL_NT4SYNC, FILL_DRS, ProvisioningError
|
---|
39 | from samba.dsdb import (
|
---|
40 | DS_DOMAIN_FUNCTION_2000,
|
---|
41 | DS_DOMAIN_FUNCTION_2003,
|
---|
42 | DS_DOMAIN_FUNCTION_2008,
|
---|
43 | DS_DOMAIN_FUNCTION_2008_R2,
|
---|
44 | )
|
---|
45 |
|
---|
46 | # how do we make this case insensitive??
|
---|
47 |
|
---|
48 | parser = optparse.OptionParser("provision [options]")
|
---|
49 | sambaopts = options.SambaOptions(parser)
|
---|
50 | parser.add_option_group(sambaopts)
|
---|
51 | parser.add_option_group(options.VersionOptions(parser))
|
---|
52 | credopts = options.CredentialsOptions(parser)
|
---|
53 | parser.add_option_group(credopts)
|
---|
54 | parser.add_option("--interactive", help="Ask for names", action="store_true")
|
---|
55 | parser.add_option("--domain", type="string", metavar="DOMAIN",
|
---|
56 | help="set domain")
|
---|
57 | parser.add_option("--domain-guid", type="string", metavar="GUID",
|
---|
58 | help="set domainguid (otherwise random)")
|
---|
59 | parser.add_option("--domain-sid", type="string", metavar="SID",
|
---|
60 | help="set domainsid (otherwise random)")
|
---|
61 | parser.add_option("--ntds-guid", type="string", metavar="GUID",
|
---|
62 | help="set NTDS object GUID (otherwise random)")
|
---|
63 | parser.add_option("--invocationid", type="string", metavar="GUID",
|
---|
64 | help="set invocationid (otherwise random)")
|
---|
65 | parser.add_option("--host-name", type="string", metavar="HOSTNAME",
|
---|
66 | help="set hostname")
|
---|
67 | parser.add_option("--host-ip", type="string", metavar="IPADDRESS",
|
---|
68 | help="set IPv4 ipaddress")
|
---|
69 | parser.add_option("--host-ip6", type="string", metavar="IP6ADDRESS",
|
---|
70 | help="set IPv6 ipaddress")
|
---|
71 | parser.add_option("--adminpass", type="string", metavar="PASSWORD",
|
---|
72 | help="choose admin password (otherwise random)")
|
---|
73 | parser.add_option("--krbtgtpass", type="string", metavar="PASSWORD",
|
---|
74 | help="choose krbtgt password (otherwise random)")
|
---|
75 | parser.add_option("--machinepass", type="string", metavar="PASSWORD",
|
---|
76 | help="choose machine password (otherwise random)")
|
---|
77 | parser.add_option("--dnspass", type="string", metavar="PASSWORD",
|
---|
78 | help="choose dns password (otherwise random)")
|
---|
79 | parser.add_option("--ldapadminpass", type="string", metavar="PASSWORD",
|
---|
80 | help="choose password to set between Samba and it's LDAP backend (otherwise random)")
|
---|
81 | parser.add_option("--root", type="string", metavar="USERNAME",
|
---|
82 | help="choose 'root' unix username")
|
---|
83 | parser.add_option("--nobody", type="string", metavar="USERNAME",
|
---|
84 | help="choose 'nobody' user")
|
---|
85 | parser.add_option("--wheel", type="string", metavar="GROUPNAME",
|
---|
86 | help="choose 'wheel' privileged group")
|
---|
87 | parser.add_option("--users", type="string", metavar="GROUPNAME",
|
---|
88 | help="choose 'users' group")
|
---|
89 | parser.add_option("--quiet", help="Be quiet", action="store_true")
|
---|
90 | parser.add_option("--blank", action="store_true",
|
---|
91 | help="do not add users or groups, just the structure")
|
---|
92 | parser.add_option("--ldap-backend-extra-port", type="int", metavar="LDAP-BACKEND-EXTRA-PORT",
|
---|
93 | help="Additional TCP port for LDAP backend server (to use for replication)")
|
---|
94 | parser.add_option("--ldap-backend-forced-uri", type="string", metavar="LDAP-BACKEND-FORCED-URI",
|
---|
95 | help="Force the LDAP backend connection to be to a particular URI. Use this ONLY for 'existing' backends, or when debugging the interaction with the LDAP backend and you need to intercept the LDAP traffic")
|
---|
96 | parser.add_option("--ldap-backend-type", type="choice", metavar="LDAP-BACKEND-TYPE",
|
---|
97 | help="LDAP backend type (fedora-ds or openldap)",
|
---|
98 | choices=["fedora-ds", "openldap"])
|
---|
99 | parser.add_option("--ldap-backend-nosync", help="Configure LDAP backend not to call fsync() (for performance in test environments)", action="store_true")
|
---|
100 | parser.add_option("--server-role", type="choice", metavar="ROLE",
|
---|
101 | choices=["domain controller", "dc", "member server", "member", "standalone"],
|
---|
102 | help="The server role (domain controller | dc | member server | member | standalone). Default is standalone.")
|
---|
103 | parser.add_option("--function-level", type="choice", metavar="FOR-FUN-LEVEL",
|
---|
104 | choices=["2000", "2003", "2008", "2008_R2"],
|
---|
105 | help="The domain and forest function level (2000 | 2003 | 2008 | 2008_R2 - always native). Default is (Windows) 2003 Native.")
|
---|
106 | parser.add_option("--next-rid", type="int", metavar="NEXTRID", default=1000,
|
---|
107 | help="The initial nextRid value (only needed for upgrades). Default is 1000.")
|
---|
108 | parser.add_option("--partitions-only",
|
---|
109 | help="Configure Samba's partitions, but do not modify them (ie, join a BDC)", action="store_true")
|
---|
110 | parser.add_option("--targetdir", type="string", metavar="DIR",
|
---|
111 | help="Set target directory")
|
---|
112 | parser.add_option("--ol-mmr-urls", type="string", metavar="LDAPSERVER",
|
---|
113 | help="List of LDAP-URLS [ ldap://<FQHN>:<PORT>/ (where <PORT> has to be different than 389!) ] separated with comma (\",\") for use with OpenLDAP-MMR (Multi-Master-Replication), e.g.: \"ldap://s4dc1:9000,ldap://s4dc2:9000\"")
|
---|
114 | parser.add_option("--slapd-path", type="string", metavar="SLAPD-PATH",
|
---|
115 | help="Path to slapd for LDAP backend [e.g.:'/usr/local/libexec/slapd']. Required for Setup with LDAP-Backend. OpenLDAP Version >= 2.4.17 should be used.")
|
---|
116 | parser.add_option("--setup-ds-path", type="string", metavar="SETUP_DS-PATH",
|
---|
117 | help="Path to setup-ds.pl script for Fedora DS LDAP backend [e.g.:'/usr/sbin/setup-ds.pl']. Required for Setup with Fedora DS backend.")
|
---|
118 | parser.add_option("--use-xattrs", type="choice", choices=["yes","no","auto"], help="Define if we should use the native fs capabilities or a tdb file for storing attributes likes ntacl, auto tries to make an inteligent guess based on the user rights and system capabilities", default="auto")
|
---|
119 | parser.add_option("--ldap-dryrun-mode", help="Configure LDAP backend, but do not run any binaries and exit early. Used only for the test environment. DO NOT USE", action="store_true")
|
---|
120 |
|
---|
121 | opts = parser.parse_args()[0]
|
---|
122 |
|
---|
123 | logger = logging.getLogger("provision")
|
---|
124 | logger.addHandler(logging.StreamHandler(sys.stdout))
|
---|
125 | if opts.quiet:
|
---|
126 | logger.setLevel(logging.WARNING)
|
---|
127 | else:
|
---|
128 | logger.setLevel(logging.INFO)
|
---|
129 |
|
---|
130 | if len(sys.argv) == 1:
|
---|
131 | opts.interactive = True
|
---|
132 |
|
---|
133 | if opts.interactive:
|
---|
134 | from getpass import getpass
|
---|
135 | import socket
|
---|
136 | def ask(prompt, default=None):
|
---|
137 | if default is not None:
|
---|
138 | print "%s [%s]: " % (prompt,default),
|
---|
139 | else:
|
---|
140 | print "%s: " % (prompt,),
|
---|
141 | return sys.stdin.readline().rstrip("\n") or default
|
---|
142 | try:
|
---|
143 | default = socket.getfqdn().split(".", 1)[1].upper()
|
---|
144 | except IndexError:
|
---|
145 | default = None
|
---|
146 | opts.realm = ask("Realm", default)
|
---|
147 | if opts.realm in (None, ""):
|
---|
148 | print >>sys.stderr, "No realm set!"
|
---|
149 | sys.exit(1)
|
---|
150 |
|
---|
151 | try:
|
---|
152 | default = opts.realm.split(".")[0]
|
---|
153 | except IndexError:
|
---|
154 | default = None
|
---|
155 | opts.domain = ask("Domain", default)
|
---|
156 | if opts.domain is None:
|
---|
157 | print >> sys.stderr, "No domain set!"
|
---|
158 | sys.exit(1)
|
---|
159 |
|
---|
160 | opts.server_role = ask("Server Role (dc, member, standalone)", "dc")
|
---|
161 | for i in range(3):
|
---|
162 | opts.adminpass = getpass("Administrator password: ")
|
---|
163 | if not opts.adminpass:
|
---|
164 | print >>sys.stderr, "Invalid administrator password."
|
---|
165 | else:
|
---|
166 | break
|
---|
167 | else:
|
---|
168 | if opts.realm in (None, ""):
|
---|
169 | opts.realm = sambaopts._lp.get('realm')
|
---|
170 | if opts.realm is None or opts.domain is None:
|
---|
171 | if opts.realm is None:
|
---|
172 | print >>sys.stderr, "No realm set!"
|
---|
173 | if opts.domain is None:
|
---|
174 | print >> sys.stderr, "No domain set!"
|
---|
175 | parser.print_usage()
|
---|
176 | sys.exit(1)
|
---|
177 |
|
---|
178 | if not opts.adminpass:
|
---|
179 | logger.info("Administrator password will be set randomly!")
|
---|
180 |
|
---|
181 | lp = sambaopts.get_loadparm()
|
---|
182 | smbconf = lp.configfile
|
---|
183 |
|
---|
184 | if opts.server_role == "dc":
|
---|
185 | server_role = "domain controller"
|
---|
186 | elif opts.server_role == "member":
|
---|
187 | server_role = "member server"
|
---|
188 | else:
|
---|
189 | server_role = opts.server_role
|
---|
190 |
|
---|
191 | if opts.function_level is None:
|
---|
192 | dom_for_fun_level = None
|
---|
193 | elif opts.function_level == "2000":
|
---|
194 | dom_for_fun_level = DS_DOMAIN_FUNCTION_2000
|
---|
195 | elif opts.function_level == "2003":
|
---|
196 | dom_for_fun_level = DS_DOMAIN_FUNCTION_2003
|
---|
197 | elif opts.function_level == "2008":
|
---|
198 | dom_for_fun_level = DS_DOMAIN_FUNCTION_2008
|
---|
199 | elif opts.function_level == "2008_R2":
|
---|
200 | dom_for_fun_level = DS_DOMAIN_FUNCTION_2008_R2
|
---|
201 |
|
---|
202 | creds = credopts.get_credentials(lp)
|
---|
203 |
|
---|
204 | creds.set_kerberos_state(DONT_USE_KERBEROS)
|
---|
205 |
|
---|
206 | samdb_fill = FILL_FULL
|
---|
207 | if opts.blank:
|
---|
208 | samdb_fill = FILL_NT4SYNC
|
---|
209 | elif opts.partitions_only:
|
---|
210 | samdb_fill = FILL_DRS
|
---|
211 |
|
---|
212 | eadb = True
|
---|
213 | if opts.use_xattrs == "yes":
|
---|
214 | eadb = False
|
---|
215 | elif opts.use_xattrs == "auto" and not lp.get("posix:eadb"):
|
---|
216 | file = tempfile.NamedTemporaryFile()
|
---|
217 | try:
|
---|
218 | samba.ntacls.setntacl(lp, file.name,
|
---|
219 | "O:S-1-5-32G:S-1-5-32", "S-1-5-32", "native")
|
---|
220 | eadb = False
|
---|
221 | except:
|
---|
222 | logger.info("You are not root or your system do not support xattr, using tdb backend for attributes. "
|
---|
223 | "If you intend to use this provision in production, rerun the script as root on a system supporting xattrs.")
|
---|
224 | file.close()
|
---|
225 |
|
---|
226 |
|
---|
227 | if opts.ldap_backend_type == "existing":
|
---|
228 | if opts.ldap_backend_forced_uri is not None:
|
---|
229 | logger.warn("You have specified to use an existing LDAP server as the backend, please make sure an LDAP server is running at %s" % opts.ldap_backend_forced_uri)
|
---|
230 | else:
|
---|
231 | logger.info("You have specified to use an existing LDAP server as the backend, please make sure an LDAP server is running at the default location")
|
---|
232 | else:
|
---|
233 | if opts.ldap_backend_forced_uri is not None:
|
---|
234 | logger.warn("You have specified to use an fixed URI %s for connecting to your LDAP server backend. This is NOT RECOMMENDED, as our default communiation over ldapi:// is more secure and much less prone to unexpected failure or interaction" % opts.ldap_backend_forced_uri)
|
---|
235 |
|
---|
236 | session = system_session()
|
---|
237 | try:
|
---|
238 | provision(logger,
|
---|
239 | session, creds, smbconf=smbconf, targetdir=opts.targetdir,
|
---|
240 | samdb_fill=samdb_fill, realm=opts.realm, domain=opts.domain,
|
---|
241 | domainguid=opts.domain_guid, domainsid=opts.domain_sid,
|
---|
242 | hostname=opts.host_name,
|
---|
243 | hostip=opts.host_ip, hostip6=opts.host_ip6,
|
---|
244 | ntdsguid=opts.ntds_guid,
|
---|
245 | invocationid=opts.invocationid, adminpass=opts.adminpass,
|
---|
246 | krbtgtpass=opts.krbtgtpass, machinepass=opts.machinepass,
|
---|
247 | dnspass=opts.dnspass, root=opts.root, nobody=opts.nobody,
|
---|
248 | wheel=opts.wheel, users=opts.users,
|
---|
249 | serverrole=server_role, dom_for_fun_level=dom_for_fun_level,
|
---|
250 | ldap_backend_extra_port=opts.ldap_backend_extra_port,
|
---|
251 | ldap_backend_forced_uri=opts.ldap_backend_forced_uri,
|
---|
252 | backend_type=opts.ldap_backend_type,
|
---|
253 | ldapadminpass=opts.ldapadminpass, ol_mmr_urls=opts.ol_mmr_urls,
|
---|
254 | slapd_path=opts.slapd_path, setup_ds_path=opts.setup_ds_path,
|
---|
255 | nosync=opts.ldap_backend_nosync, ldap_dryrun_mode=opts.ldap_dryrun_mode,
|
---|
256 | useeadb=eadb, next_rid=opts.next_rid, lp=lp)
|
---|
257 | except ProvisioningError, e:
|
---|
258 | print str(e)
|
---|
259 | exit(1)
|
---|