| 1 | #!/usr/bin/env python
 | 
|---|
| 2 | #
 | 
|---|
| 3 | # Unix SMB/CIFS implementation.
 | 
|---|
| 4 | # provision a Samba4 server
 | 
|---|
| 5 | # Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2007-2008
 | 
|---|
| 6 | # Copyright (C) Andrew Bartlett <abartlet@samba.org> 2008
 | 
|---|
| 7 | #
 | 
|---|
| 8 | # Based on the original in EJS:
 | 
|---|
| 9 | # Copyright (C) Andrew Tridgell 2005
 | 
|---|
| 10 | #   
 | 
|---|
| 11 | # This program is free software; you can redistribute it and/or modify
 | 
|---|
| 12 | # it under the terms of the GNU General Public License as published by
 | 
|---|
| 13 | # the Free Software Foundation; either version 3 of the License, or
 | 
|---|
| 14 | # (at your option) any later version.
 | 
|---|
| 15 | #   
 | 
|---|
| 16 | # This program is distributed in the hope that it will be useful,
 | 
|---|
| 17 | # but WITHOUT ANY WARRANTY; without even the implied warranty of
 | 
|---|
| 18 | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | 
|---|
| 19 | # GNU General Public License for more details.
 | 
|---|
| 20 | #   
 | 
|---|
| 21 | # You should have received a copy of the GNU General Public License
 | 
|---|
| 22 | # along with this program.  If not, see <http://www.gnu.org/licenses/>.
 | 
|---|
| 23 | #
 | 
|---|
| 24 | 
 | 
|---|
| 25 | import logging
 | 
|---|
| 26 | import optparse
 | 
|---|
| 27 | import sys
 | 
|---|
| 28 | import tempfile
 | 
|---|
| 29 | 
 | 
|---|
| 30 | # Find right directory when running from source tree
 | 
|---|
| 31 | sys.path.insert(0, "bin/python")
 | 
|---|
| 32 | 
 | 
|---|
| 33 | import samba
 | 
|---|
| 34 | import samba.ntacls
 | 
|---|
| 35 | from samba.credentials import DONT_USE_KERBEROS
 | 
|---|
| 36 | from samba.auth import system_session
 | 
|---|
| 37 | import samba.getopt as options
 | 
|---|
| 38 | from samba.provision import provision, FILL_FULL, FILL_NT4SYNC, FILL_DRS, ProvisioningError
 | 
|---|
| 39 | from samba.dsdb import (
 | 
|---|
| 40 |         DS_DOMAIN_FUNCTION_2000,
 | 
|---|
| 41 |         DS_DOMAIN_FUNCTION_2003,
 | 
|---|
| 42 |         DS_DOMAIN_FUNCTION_2008,
 | 
|---|
| 43 |         DS_DOMAIN_FUNCTION_2008_R2,
 | 
|---|
| 44 |         )
 | 
|---|
| 45 | 
 | 
|---|
| 46 | # how do we make this case insensitive??
 | 
|---|
| 47 | 
 | 
|---|
| 48 | parser = optparse.OptionParser("provision [options]")
 | 
|---|
| 49 | sambaopts = options.SambaOptions(parser)
 | 
|---|
| 50 | parser.add_option_group(sambaopts)
 | 
|---|
| 51 | parser.add_option_group(options.VersionOptions(parser))
 | 
|---|
| 52 | credopts = options.CredentialsOptions(parser)
 | 
|---|
| 53 | parser.add_option_group(credopts)
 | 
|---|
| 54 | parser.add_option("--interactive", help="Ask for names", action="store_true")
 | 
|---|
| 55 | parser.add_option("--domain", type="string", metavar="DOMAIN",
 | 
|---|
| 56 |                                   help="set domain")
 | 
|---|
| 57 | parser.add_option("--domain-guid", type="string", metavar="GUID", 
 | 
|---|
| 58 |                 help="set domainguid (otherwise random)")
 | 
|---|
| 59 | parser.add_option("--domain-sid", type="string", metavar="SID", 
 | 
|---|
| 60 |                 help="set domainsid (otherwise random)")
 | 
|---|
| 61 | parser.add_option("--ntds-guid", type="string", metavar="GUID", 
 | 
|---|
| 62 |                   help="set NTDS object GUID (otherwise random)")
 | 
|---|
| 63 | parser.add_option("--invocationid", type="string", metavar="GUID", 
 | 
|---|
| 64 |                   help="set invocationid (otherwise random)")
 | 
|---|
| 65 | parser.add_option("--host-name", type="string", metavar="HOSTNAME", 
 | 
|---|
| 66 |                 help="set hostname")
 | 
|---|
| 67 | parser.add_option("--host-ip", type="string", metavar="IPADDRESS", 
 | 
|---|
| 68 |                 help="set IPv4 ipaddress")
 | 
|---|
| 69 | parser.add_option("--host-ip6", type="string", metavar="IP6ADDRESS", 
 | 
|---|
| 70 |                 help="set IPv6 ipaddress")
 | 
|---|
| 71 | parser.add_option("--adminpass", type="string", metavar="PASSWORD", 
 | 
|---|
| 72 |                 help="choose admin password (otherwise random)")
 | 
|---|
| 73 | parser.add_option("--krbtgtpass", type="string", metavar="PASSWORD", 
 | 
|---|
| 74 |                 help="choose krbtgt password (otherwise random)")
 | 
|---|
| 75 | parser.add_option("--machinepass", type="string", metavar="PASSWORD", 
 | 
|---|
| 76 |                 help="choose machine password (otherwise random)")
 | 
|---|
| 77 | parser.add_option("--dnspass", type="string", metavar="PASSWORD", 
 | 
|---|
| 78 |                 help="choose dns password (otherwise random)")
 | 
|---|
| 79 | parser.add_option("--ldapadminpass", type="string", metavar="PASSWORD", 
 | 
|---|
| 80 |                 help="choose password to set between Samba and it's LDAP backend (otherwise random)")
 | 
|---|
| 81 | parser.add_option("--root", type="string", metavar="USERNAME", 
 | 
|---|
| 82 |                 help="choose 'root' unix username")
 | 
|---|
| 83 | parser.add_option("--nobody", type="string", metavar="USERNAME", 
 | 
|---|
| 84 |                 help="choose 'nobody' user")
 | 
|---|
| 85 | parser.add_option("--wheel", type="string", metavar="GROUPNAME", 
 | 
|---|
| 86 |                 help="choose 'wheel' privileged group")
 | 
|---|
| 87 | parser.add_option("--users", type="string", metavar="GROUPNAME", 
 | 
|---|
| 88 |                 help="choose 'users' group")
 | 
|---|
| 89 | parser.add_option("--quiet", help="Be quiet", action="store_true")
 | 
|---|
| 90 | parser.add_option("--blank", action="store_true",
 | 
|---|
| 91 |                 help="do not add users or groups, just the structure")
 | 
|---|
| 92 | parser.add_option("--ldap-backend-extra-port", type="int", metavar="LDAP-BACKEND-EXTRA-PORT", 
 | 
|---|
| 93 |                 help="Additional TCP port for LDAP backend server (to use for replication)")
 | 
|---|
| 94 | parser.add_option("--ldap-backend-forced-uri", type="string", metavar="LDAP-BACKEND-FORCED-URI", 
 | 
|---|
| 95 |                 help="Force the LDAP backend connection to be to a particular URI.  Use this ONLY for 'existing' backends, or when debugging the interaction with the LDAP backend and you need to intercept the LDAP traffic")
 | 
|---|
| 96 | parser.add_option("--ldap-backend-type", type="choice", metavar="LDAP-BACKEND-TYPE", 
 | 
|---|
| 97 |                 help="LDAP backend type (fedora-ds or openldap)",
 | 
|---|
| 98 |                 choices=["fedora-ds", "openldap"])
 | 
|---|
| 99 | parser.add_option("--ldap-backend-nosync", help="Configure LDAP backend not to call fsync() (for performance in test environments)", action="store_true")
 | 
|---|
| 100 | parser.add_option("--server-role", type="choice", metavar="ROLE",
 | 
|---|
| 101 |                   choices=["domain controller", "dc", "member server", "member", "standalone"],
 | 
|---|
| 102 |                 help="The server role (domain controller | dc | member server | member | standalone). Default is standalone.")
 | 
|---|
| 103 | parser.add_option("--function-level", type="choice", metavar="FOR-FUN-LEVEL",
 | 
|---|
| 104 |                   choices=["2000", "2003", "2008", "2008_R2"],
 | 
|---|
| 105 |                 help="The domain and forest function level (2000 | 2003 | 2008 | 2008_R2 - always native). Default is (Windows) 2003 Native.")
 | 
|---|
| 106 | parser.add_option("--next-rid", type="int", metavar="NEXTRID", default=1000,
 | 
|---|
| 107 |                 help="The initial nextRid value (only needed for upgrades).  Default is 1000.")
 | 
|---|
| 108 | parser.add_option("--partitions-only", 
 | 
|---|
| 109 |                 help="Configure Samba's partitions, but do not modify them (ie, join a BDC)", action="store_true")
 | 
|---|
| 110 | parser.add_option("--targetdir", type="string", metavar="DIR", 
 | 
|---|
| 111 |                           help="Set target directory")
 | 
|---|
| 112 | parser.add_option("--ol-mmr-urls", type="string", metavar="LDAPSERVER",
 | 
|---|
| 113 |                 help="List of LDAP-URLS [ ldap://<FQHN>:<PORT>/  (where <PORT> has to be different than 389!) ] separated with comma (\",\") for use with OpenLDAP-MMR (Multi-Master-Replication), e.g.: \"ldap://s4dc1:9000,ldap://s4dc2:9000\"")
 | 
|---|
| 114 | parser.add_option("--slapd-path", type="string", metavar="SLAPD-PATH", 
 | 
|---|
| 115 |                 help="Path to slapd for LDAP backend [e.g.:'/usr/local/libexec/slapd']. Required for Setup with LDAP-Backend. OpenLDAP Version >= 2.4.17 should be used.") 
 | 
|---|
| 116 | parser.add_option("--setup-ds-path", type="string", metavar="SETUP_DS-PATH", 
 | 
|---|
| 117 |                 help="Path to setup-ds.pl script for Fedora DS LDAP backend [e.g.:'/usr/sbin/setup-ds.pl']. Required for Setup with Fedora DS backend.") 
 | 
|---|
| 118 | parser.add_option("--use-xattrs", type="choice", choices=["yes","no","auto"], help="Define if we should use the native fs capabilities or a tdb file for storing attributes likes ntacl, auto tries to make an inteligent guess based on the user rights and system capabilities", default="auto")
 | 
|---|
| 119 | parser.add_option("--ldap-dryrun-mode", help="Configure LDAP backend, but do not run any binaries and exit early.  Used only for the test environment.  DO NOT USE", action="store_true")
 | 
|---|
| 120 | 
 | 
|---|
| 121 | opts = parser.parse_args()[0]
 | 
|---|
| 122 | 
 | 
|---|
| 123 | logger = logging.getLogger("provision")
 | 
|---|
| 124 | logger.addHandler(logging.StreamHandler(sys.stdout))
 | 
|---|
| 125 | if opts.quiet:
 | 
|---|
| 126 |         logger.setLevel(logging.WARNING)
 | 
|---|
| 127 | else:
 | 
|---|
| 128 |         logger.setLevel(logging.INFO)
 | 
|---|
| 129 | 
 | 
|---|
| 130 | if len(sys.argv) == 1:
 | 
|---|
| 131 |         opts.interactive = True
 | 
|---|
| 132 | 
 | 
|---|
| 133 | if opts.interactive:
 | 
|---|
| 134 |         from getpass import getpass
 | 
|---|
| 135 |         import socket
 | 
|---|
| 136 |         def ask(prompt, default=None):
 | 
|---|
| 137 |                 if default is not None:
 | 
|---|
| 138 |                         print "%s [%s]: " % (prompt,default),
 | 
|---|
| 139 |                 else:
 | 
|---|
| 140 |                         print "%s: " % (prompt,),
 | 
|---|
| 141 |                 return sys.stdin.readline().rstrip("\n") or default
 | 
|---|
| 142 |         try:
 | 
|---|
| 143 |                 default = socket.getfqdn().split(".", 1)[1].upper()
 | 
|---|
| 144 |         except IndexError:
 | 
|---|
| 145 |                 default = None
 | 
|---|
| 146 |         opts.realm = ask("Realm", default)
 | 
|---|
| 147 |         if opts.realm in (None, ""):
 | 
|---|
| 148 |                 print >>sys.stderr, "No realm set!"
 | 
|---|
| 149 |                 sys.exit(1)
 | 
|---|
| 150 | 
 | 
|---|
| 151 |         try:
 | 
|---|
| 152 |                 default = opts.realm.split(".")[0]
 | 
|---|
| 153 |         except IndexError:
 | 
|---|
| 154 |                 default = None
 | 
|---|
| 155 |         opts.domain = ask("Domain", default)
 | 
|---|
| 156 |         if opts.domain is None:
 | 
|---|
| 157 |                 print >> sys.stderr, "No domain set!"
 | 
|---|
| 158 |                 sys.exit(1)
 | 
|---|
| 159 | 
 | 
|---|
| 160 |         opts.server_role = ask("Server Role (dc, member, standalone)", "dc")
 | 
|---|
| 161 |         for i in range(3):
 | 
|---|
| 162 |                 opts.adminpass = getpass("Administrator password: ")
 | 
|---|
| 163 |                 if not opts.adminpass:
 | 
|---|
| 164 |                         print >>sys.stderr, "Invalid administrator password."
 | 
|---|
| 165 |                 else:
 | 
|---|
| 166 |                         break
 | 
|---|
| 167 | else:
 | 
|---|
| 168 |         if opts.realm in (None, ""):
 | 
|---|
| 169 |                 opts.realm = sambaopts._lp.get('realm')
 | 
|---|
| 170 |         if opts.realm is None or opts.domain is None:
 | 
|---|
| 171 |                 if opts.realm is None:
 | 
|---|
| 172 |                         print >>sys.stderr, "No realm set!"
 | 
|---|
| 173 |                 if opts.domain is None:
 | 
|---|
| 174 |                         print >> sys.stderr, "No domain set!"
 | 
|---|
| 175 |                 parser.print_usage()
 | 
|---|
| 176 |                 sys.exit(1)
 | 
|---|
| 177 | 
 | 
|---|
| 178 | if not opts.adminpass:
 | 
|---|
| 179 |         logger.info("Administrator password will be set randomly!")
 | 
|---|
| 180 | 
 | 
|---|
| 181 | lp = sambaopts.get_loadparm()
 | 
|---|
| 182 | smbconf = lp.configfile
 | 
|---|
| 183 | 
 | 
|---|
| 184 | if opts.server_role == "dc":
 | 
|---|
| 185 |         server_role = "domain controller"
 | 
|---|
| 186 | elif opts.server_role == "member":
 | 
|---|
| 187 |         server_role = "member server"
 | 
|---|
| 188 | else:
 | 
|---|
| 189 |         server_role = opts.server_role
 | 
|---|
| 190 | 
 | 
|---|
| 191 | if opts.function_level is None:
 | 
|---|
| 192 |         dom_for_fun_level = None
 | 
|---|
| 193 | elif opts.function_level == "2000":
 | 
|---|
| 194 |         dom_for_fun_level = DS_DOMAIN_FUNCTION_2000
 | 
|---|
| 195 | elif opts.function_level == "2003":
 | 
|---|
| 196 |         dom_for_fun_level = DS_DOMAIN_FUNCTION_2003
 | 
|---|
| 197 | elif opts.function_level == "2008":
 | 
|---|
| 198 |         dom_for_fun_level = DS_DOMAIN_FUNCTION_2008
 | 
|---|
| 199 | elif opts.function_level == "2008_R2":
 | 
|---|
| 200 |         dom_for_fun_level = DS_DOMAIN_FUNCTION_2008_R2
 | 
|---|
| 201 | 
 | 
|---|
| 202 | creds = credopts.get_credentials(lp)
 | 
|---|
| 203 | 
 | 
|---|
| 204 | creds.set_kerberos_state(DONT_USE_KERBEROS)
 | 
|---|
| 205 | 
 | 
|---|
| 206 | samdb_fill = FILL_FULL
 | 
|---|
| 207 | if opts.blank:
 | 
|---|
| 208 |     samdb_fill = FILL_NT4SYNC
 | 
|---|
| 209 | elif opts.partitions_only:
 | 
|---|
| 210 |     samdb_fill = FILL_DRS
 | 
|---|
| 211 | 
 | 
|---|
| 212 | eadb = True
 | 
|---|
| 213 | if opts.use_xattrs == "yes":
 | 
|---|
| 214 |         eadb = False
 | 
|---|
| 215 | elif opts.use_xattrs == "auto" and not lp.get("posix:eadb"):
 | 
|---|
| 216 |         file = tempfile.NamedTemporaryFile()
 | 
|---|
| 217 |         try:
 | 
|---|
| 218 |                 samba.ntacls.setntacl(lp, file.name, 
 | 
|---|
| 219 |                         "O:S-1-5-32G:S-1-5-32", "S-1-5-32", "native")
 | 
|---|
| 220 |                 eadb = False
 | 
|---|
| 221 |         except:
 | 
|---|
| 222 |                 logger.info("You are not root or your system do not support xattr, using tdb backend for attributes. "
 | 
|---|
| 223 |                             "If you intend to use this provision in production, rerun the script as root on a system supporting xattrs.")
 | 
|---|
| 224 |         file.close()
 | 
|---|
| 225 | 
 | 
|---|
| 226 | 
 | 
|---|
| 227 | if opts.ldap_backend_type == "existing":
 | 
|---|
| 228 |         if opts.ldap_backend_forced_uri is not None:
 | 
|---|
| 229 |                 logger.warn("You have specified to use an existing LDAP server as the backend, please make sure an LDAP server is running at %s" % opts.ldap_backend_forced_uri)
 | 
|---|
| 230 |         else:
 | 
|---|
| 231 |                 logger.info("You have specified to use an existing LDAP server as the backend, please make sure an LDAP server is running at the default location")
 | 
|---|
| 232 | else:
 | 
|---|
| 233 |         if opts.ldap_backend_forced_uri is not None:
 | 
|---|
| 234 |                 logger.warn("You have specified to use an fixed URI %s for connecting to your LDAP server backend.  This is NOT RECOMMENDED, as our default communiation over ldapi:// is more secure and much less prone to unexpected failure or interaction" % opts.ldap_backend_forced_uri)
 | 
|---|
| 235 |         
 | 
|---|
| 236 | session = system_session()
 | 
|---|
| 237 | try:
 | 
|---|
| 238 |         provision(logger,
 | 
|---|
| 239 |                   session, creds, smbconf=smbconf, targetdir=opts.targetdir,
 | 
|---|
| 240 |                   samdb_fill=samdb_fill, realm=opts.realm, domain=opts.domain,
 | 
|---|
| 241 |                   domainguid=opts.domain_guid, domainsid=opts.domain_sid,
 | 
|---|
| 242 |                   hostname=opts.host_name,
 | 
|---|
| 243 |                   hostip=opts.host_ip, hostip6=opts.host_ip6,
 | 
|---|
| 244 |                   ntdsguid=opts.ntds_guid,
 | 
|---|
| 245 |                   invocationid=opts.invocationid, adminpass=opts.adminpass,
 | 
|---|
| 246 |                   krbtgtpass=opts.krbtgtpass, machinepass=opts.machinepass,
 | 
|---|
| 247 |                   dnspass=opts.dnspass, root=opts.root, nobody=opts.nobody,
 | 
|---|
| 248 |                   wheel=opts.wheel, users=opts.users,
 | 
|---|
| 249 |                   serverrole=server_role, dom_for_fun_level=dom_for_fun_level,
 | 
|---|
| 250 |                   ldap_backend_extra_port=opts.ldap_backend_extra_port,
 | 
|---|
| 251 |                   ldap_backend_forced_uri=opts.ldap_backend_forced_uri,
 | 
|---|
| 252 |                   backend_type=opts.ldap_backend_type,
 | 
|---|
| 253 |                   ldapadminpass=opts.ldapadminpass, ol_mmr_urls=opts.ol_mmr_urls,
 | 
|---|
| 254 |                   slapd_path=opts.slapd_path, setup_ds_path=opts.setup_ds_path,
 | 
|---|
| 255 |                   nosync=opts.ldap_backend_nosync, ldap_dryrun_mode=opts.ldap_dryrun_mode, 
 | 
|---|
| 256 |                   useeadb=eadb, next_rid=opts.next_rid, lp=lp)
 | 
|---|
| 257 | except ProvisioningError, e:
 | 
|---|
| 258 |         print str(e)
 | 
|---|
| 259 |         exit(1)
 | 
|---|