2 * Implementation of the Local Security Authority API
4 * Copyright 1999 Juergen Schmied
5 * Copyright 2002 Andriy Palamarchuk
6 * Copyright 2004 Mike McCormack
7 * Copyright 2005 Hans Leidekker
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2.1 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
27 #define WIN32_NO_STATUS
33 #include "advapi32_misc.h"
35 #include "wine/debug.h"
37 WINE_DEFAULT_DEBUG_CHANNEL(advapi);
39 #define ADVAPI_ForceLocalComputer(ServerName, FailureCode) \
40 if (!ADVAPI_IsLocalComputer(ServerName)) \
42 FIXME("Action Implemented for local computer only. " \
43 "Requested for server %s\n", debugstr_w(ServerName)); \
47 static void dumpLsaAttributes(const LSA_OBJECT_ATTRIBUTES *oa)
51 TRACE("\n\tlength=%u, rootdir=%p, objectname=%s\n\tattr=0x%08x, sid=%s qos=%p\n",
52 oa->Length, oa->RootDirectory,
53 oa->ObjectName?debugstr_w(oa->ObjectName->Buffer):"null",
54 oa->Attributes, debugstr_sid(oa->SecurityDescriptor),
55 oa->SecurityQualityOfService);
59 static void* ADVAPI_GetDomainName(unsigned sz, unsigned ofs)
66 static const WCHAR wVNETSUP[] = {
67 'S','y','s','t','e','m','\\',
68 'C','u','r','r','e','n','t','C','o','n','t','r','o','l','S','e','t','\\',
69 'S','e','r','v','i','c','e','s','\\',
70 'V','x','D','\\','V','N','E','T','S','U','P','\0'};
72 ret = RegOpenKeyExW(HKEY_LOCAL_MACHINE, wVNETSUP, 0, KEY_READ, &key);
73 if (ret == ERROR_SUCCESS)
76 static const WCHAR wg[] = { 'W','o','r','k','g','r','o','u','p',0 };
78 ret = RegQueryValueExW(key, wg, NULL, NULL, NULL, &size);
79 if (ret == ERROR_MORE_DATA || ret == ERROR_SUCCESS)
81 ptr = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sz + size);
82 if (!ptr) return NULL;
83 ustr = (UNICODE_STRING*)(ptr + ofs);
84 ustr->MaximumLength = size;
85 ustr->Buffer = (WCHAR*)(ptr + sz);
86 ret = RegQueryValueExW(key, wg, NULL, NULL, (LPBYTE)ustr->Buffer, &size);
87 if (ret != ERROR_SUCCESS)
89 HeapFree(GetProcessHeap(), 0, ptr);
92 else ustr->Length = size - sizeof(WCHAR);
98 static const WCHAR wDomain[] = {'D','O','M','A','I','N','\0'};
99 ptr = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY,
100 sz + sizeof(wDomain));
101 if (!ptr) return NULL;
102 ustr = (UNICODE_STRING*)(ptr + ofs);
103 ustr->MaximumLength = sizeof(wDomain);
104 ustr->Buffer = (WCHAR*)(ptr + sz);
105 ustr->Length = sizeof(wDomain) - sizeof(WCHAR);
106 memcpy(ustr->Buffer, wDomain, sizeof(wDomain));
111 /******************************************************************************
112 * LsaAddAccountRights [ADVAPI32.@]
115 NTSTATUS WINAPI LsaAddAccountRights(
118 PLSA_UNICODE_STRING rights,
121 FIXME("(%p,%p,%p,0x%08x) stub\n", policy, sid, rights, count);
122 return STATUS_OBJECT_NAME_NOT_FOUND;
125 /******************************************************************************
126 * LsaClose [ADVAPI32.@]
128 * Closes a handle to a Policy or TrustedDomain.
131 * ObjectHandle [I] Handle to a Policy or TrustedDomain.
134 * Success: STATUS_SUCCESS.
135 * Failure: NTSTATUS code.
137 NTSTATUS WINAPI LsaClose(IN LSA_HANDLE ObjectHandle)
139 FIXME("(%p) stub\n", ObjectHandle);
140 return STATUS_SUCCESS;
143 /******************************************************************************
144 * LsaCreateTrustedDomainEx [ADVAPI32.@]
147 NTSTATUS WINAPI LsaCreateTrustedDomainEx(
149 PTRUSTED_DOMAIN_INFORMATION_EX domain_info,
150 PTRUSTED_DOMAIN_AUTH_INFORMATION auth_info,
154 FIXME("(%p,%p,%p,0x%08x,%p) stub\n", policy, domain_info, auth_info,
156 return STATUS_SUCCESS;
159 /******************************************************************************
160 * LsaDeleteTrustedDomain [ADVAPI32.@]
163 NTSTATUS WINAPI LsaDeleteTrustedDomain(LSA_HANDLE policy, PSID sid)
165 FIXME("(%p,%p) stub\n", policy, sid);
166 return STATUS_SUCCESS;
169 /******************************************************************************
170 * LsaEnumerateAccountRights [ADVAPI32.@]
173 NTSTATUS WINAPI LsaEnumerateAccountRights(
176 PLSA_UNICODE_STRING *rights,
179 FIXME("(%p,%p,%p,%p) stub\n", policy, sid, rights, count);
182 return STATUS_OBJECT_NAME_NOT_FOUND;
185 /******************************************************************************
186 * LsaEnumerateAccountsWithUserRight [ADVAPI32.@]
189 NTSTATUS WINAPI LsaEnumerateAccountsWithUserRight(
191 PLSA_UNICODE_STRING rights,
195 FIXME("(%p,%p,%p,%p) stub\n", policy, rights, buffer, count);
196 return STATUS_NO_MORE_ENTRIES;
199 /******************************************************************************
200 * LsaEnumerateTrustedDomains [ADVAPI32.@]
202 * Returns the names and SIDs of trusted domains.
205 * PolicyHandle [I] Handle to a Policy object.
206 * EnumerationContext [I] Pointer to an enumeration handle.
207 * Buffer [O] Contains the names and SIDs of trusted domains.
208 * PreferredMaximumLength[I] Preferred maximum size in bytes of Buffer.
209 * CountReturned [O] Number of elements in Buffer.
212 * Success: STATUS_SUCCESS,
213 * STATUS_MORE_ENTRIES,
214 * STATUS_NO_MORE_ENTRIES
215 * Failure: NTSTATUS code.
218 * LsaEnumerateTrustedDomains can be called multiple times to enumerate
219 * all trusted domains.
221 NTSTATUS WINAPI LsaEnumerateTrustedDomains(
222 IN LSA_HANDLE PolicyHandle,
223 IN PLSA_ENUMERATION_HANDLE EnumerationContext,
225 IN ULONG PreferredMaximumLength,
226 OUT PULONG CountReturned)
228 FIXME("(%p,%p,%p,0x%08x,%p) stub\n", PolicyHandle, EnumerationContext,
229 Buffer, PreferredMaximumLength, CountReturned);
231 if (CountReturned) *CountReturned = 0;
232 return STATUS_SUCCESS;
235 /******************************************************************************
236 * LsaEnumerateTrustedDomainsEx [ADVAPI32.@]
239 NTSTATUS WINAPI LsaEnumerateTrustedDomainsEx(
241 PLSA_ENUMERATION_HANDLE context,
246 FIXME("(%p,%p,%p,0x%08x,%p) stub\n", policy, context, buffer, length, count);
248 if (count) *count = 0;
249 return STATUS_SUCCESS;
252 /******************************************************************************
253 * LsaFreeMemory [ADVAPI32.@]
255 * Frees memory allocated by a LSA function.
258 * Buffer [I] Memory buffer to free.
261 * Success: STATUS_SUCCESS.
262 * Failure: NTSTATUS code.
264 NTSTATUS WINAPI LsaFreeMemory(IN PVOID Buffer)
266 TRACE("(%p)\n", Buffer);
268 HeapFree(GetProcessHeap(), 0, Buffer);
269 return STATUS_SUCCESS;
272 /******************************************************************************
273 * LsaLookupNames [ADVAPI32.@]
275 * Returns the SIDs of an array of user, group, or local group names.
278 * PolicyHandle [I] Handle to a Policy object.
279 * Count [I] Number of names in Names.
280 * Names [I] Array of names to lookup.
281 * ReferencedDomains [O] Array of domains where the names were found.
282 * Sids [O] Array of SIDs corresponding to Names.
285 * Success: STATUS_SUCCESS,
286 * STATUS_SOME_NOT_MAPPED
287 * Failure: STATUS_NONE_MAPPED or NTSTATUS code.
289 NTSTATUS WINAPI LsaLookupNames(
290 IN LSA_HANDLE PolicyHandle,
292 IN PLSA_UNICODE_STRING Names,
293 OUT PLSA_REFERENCED_DOMAIN_LIST* ReferencedDomains,
294 OUT PLSA_TRANSLATED_SID* Sids)
296 FIXME("(%p,0x%08x,%p,%p,%p) stub\n", PolicyHandle, Count, Names,
297 ReferencedDomains, Sids);
299 return STATUS_NONE_MAPPED;
302 /******************************************************************************
303 * LsaLookupNames2 [ADVAPI32.@]
306 NTSTATUS WINAPI LsaLookupNames2(
310 PLSA_UNICODE_STRING names,
311 PLSA_REFERENCED_DOMAIN_LIST *domains,
312 PLSA_TRANSLATED_SID2 *sids)
314 FIXME("(%p,0x%08x,0x%08x,%p,%p,%p) stub\n", policy, flags, count, names, domains, sids);
315 return STATUS_NONE_MAPPED;
318 /******************************************************************************
319 * LsaLookupSids [ADVAPI32.@]
321 * Looks up the names that correspond to an array of SIDs.
324 * PolicyHandle [I] Handle to a Policy object.
325 * Count [I] Number of SIDs in the Sids array.
326 * Sids [I] Array of SIDs to lookup.
327 * ReferencedDomains [O] Array of domains where the sids were found.
328 * Names [O] Array of names corresponding to Sids.
331 * Success: STATUS_SUCCESS,
332 * STATUS_SOME_NOT_MAPPED
333 * Failure: STATUS_NONE_MAPPED or NTSTATUS code.
335 NTSTATUS WINAPI LsaLookupSids(
336 IN LSA_HANDLE PolicyHandle,
339 OUT PLSA_REFERENCED_DOMAIN_LIST *ReferencedDomains,
340 OUT PLSA_TRANSLATED_NAME *Names )
342 FIXME("(%p,%u,%p,%p,%p) stub\n", PolicyHandle, Count, Sids,
343 ReferencedDomains, Names);
345 return STATUS_NONE_MAPPED;
348 /******************************************************************************
349 * LsaNtStatusToWinError [ADVAPI32.@]
351 * Converts an LSA NTSTATUS code to a Windows error code.
354 * Status [I] NTSTATUS code.
357 * Success: Corresponding Windows error code.
358 * Failure: ERROR_MR_MID_NOT_FOUND.
360 ULONG WINAPI LsaNtStatusToWinError(NTSTATUS Status)
362 return RtlNtStatusToDosError(Status);
365 /******************************************************************************
366 * LsaOpenPolicy [ADVAPI32.@]
368 * Opens a handle to the Policy object on a local or remote system.
371 * SystemName [I] Name of the target system.
372 * ObjectAttributes [I] Connection attributes.
373 * DesiredAccess [I] Requested access rights.
374 * PolicyHandle [I/O] Handle to the Policy object.
377 * Success: STATUS_SUCCESS.
378 * Failure: NTSTATUS code.
381 * Set SystemName to NULL to open the local Policy object.
383 NTSTATUS WINAPI LsaOpenPolicy(
384 IN PLSA_UNICODE_STRING SystemName,
385 IN PLSA_OBJECT_ATTRIBUTES ObjectAttributes,
386 IN ACCESS_MASK DesiredAccess,
387 IN OUT PLSA_HANDLE PolicyHandle)
389 FIXME("(%s,%p,0x%08x,%p) stub\n",
390 SystemName?debugstr_w(SystemName->Buffer):"(null)",
391 ObjectAttributes, DesiredAccess, PolicyHandle);
393 ADVAPI_ForceLocalComputer(SystemName ? SystemName->Buffer : NULL,
394 STATUS_ACCESS_VIOLATION);
395 dumpLsaAttributes(ObjectAttributes);
397 if(PolicyHandle) *PolicyHandle = (LSA_HANDLE)0xcafe;
398 return STATUS_SUCCESS;
401 /******************************************************************************
402 * LsaOpenTrustedDomainByName [ADVAPI32.@]
405 NTSTATUS WINAPI LsaOpenTrustedDomainByName(
407 PLSA_UNICODE_STRING name,
411 FIXME("(%p,%p,0x%08x,%p) stub\n", policy, name, access, handle);
412 return STATUS_OBJECT_NAME_NOT_FOUND;
415 /******************************************************************************
416 * LsaQueryInformationPolicy [ADVAPI32.@]
418 * Returns information about a Policy object.
421 * PolicyHandle [I] Handle to a Policy object.
422 * InformationClass [I] Type of information to retrieve.
423 * Buffer [O] Pointer to the requested information.
426 * Success: STATUS_SUCCESS.
427 * Failure: NTSTATUS code.
429 NTSTATUS WINAPI LsaQueryInformationPolicy(
430 IN LSA_HANDLE PolicyHandle,
431 IN POLICY_INFORMATION_CLASS InformationClass,
434 TRACE("(%p,0x%08x,%p)\n", PolicyHandle, InformationClass, Buffer);
436 if(!Buffer) return STATUS_INVALID_PARAMETER;
437 switch (InformationClass)
439 case PolicyAuditEventsInformation: /* 2 */
441 PPOLICY_AUDIT_EVENTS_INFO p = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY,
442 sizeof(POLICY_AUDIT_EVENTS_INFO));
443 p->AuditingMode = FALSE; /* no auditing */
447 case PolicyPrimaryDomainInformation: /* 3 */
449 /* Only the domain name is valid for the local computer.
450 * All other fields are zero.
452 PPOLICY_PRIMARY_DOMAIN_INFO pinfo;
454 pinfo = ADVAPI_GetDomainName(sizeof(*pinfo), offsetof(POLICY_PRIMARY_DOMAIN_INFO, Name));
456 TRACE("setting domain to %s\n", debugstr_w(pinfo->Name.Buffer));
461 case PolicyAccountDomainInformation: /* 5 */
465 POLICY_ACCOUNT_DOMAIN_INFO info;
468 WCHAR domain[MAX_COMPUTERNAME_LENGTH + 1];
471 DWORD dwSize = MAX_COMPUTERNAME_LENGTH + 1;
472 struct di * xdi = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, sizeof(*xdi));
474 xdi->info.DomainName.MaximumLength = dwSize * sizeof(WCHAR);
475 xdi->info.DomainName.Buffer = xdi->domain;
476 if (GetComputerNameW(xdi->info.DomainName.Buffer, &dwSize))
477 xdi->info.DomainName.Length = dwSize * sizeof(WCHAR);
479 TRACE("setting name to %s\n", debugstr_w(xdi->info.DomainName.Buffer));
481 xdi->info.DomainSid = &xdi->sid;
483 /* read the computer SID from the registry */
484 if (!ADVAPI_GetComputerSid(&xdi->sid))
486 HeapFree(GetProcessHeap(), 0, xdi);
488 WARN("Computer SID not found\n");
490 return STATUS_UNSUCCESSFUL;
493 TRACE("setting SID to %s\n", debugstr_sid(&xdi->sid));
498 case PolicyDnsDomainInformation: /* 12 (0xc) */
500 /* Only the domain name is valid for the local computer.
501 * All other fields are zero.
503 PPOLICY_DNS_DOMAIN_INFO pinfo;
505 pinfo = ADVAPI_GetDomainName(sizeof(*pinfo), offsetof(POLICY_DNS_DOMAIN_INFO, Name));
507 TRACE("setting domain to %s\n", debugstr_w(pinfo->Name.Buffer));
512 case PolicyAuditLogInformation:
513 case PolicyPdAccountInformation:
514 case PolicyLsaServerRoleInformation:
515 case PolicyReplicaSourceInformation:
516 case PolicyDefaultQuotaInformation:
517 case PolicyModificationInformation:
518 case PolicyAuditFullSetInformation:
519 case PolicyAuditFullQueryInformation:
521 FIXME("category %d not implemented\n", InformationClass);
522 return STATUS_UNSUCCESSFUL;
525 return STATUS_SUCCESS;
528 /******************************************************************************
529 * LsaQueryTrustedDomainInfo [ADVAPI32.@]
532 NTSTATUS WINAPI LsaQueryTrustedDomainInfo(
535 TRUSTED_INFORMATION_CLASS class,
538 FIXME("(%p,%p,%d,%p) stub\n", policy, sid, class, buffer);
539 return STATUS_OBJECT_NAME_NOT_FOUND;
542 /******************************************************************************
543 * LsaQueryTrustedDomainInfoByName [ADVAPI32.@]
546 NTSTATUS WINAPI LsaQueryTrustedDomainInfoByName(
548 PLSA_UNICODE_STRING name,
549 TRUSTED_INFORMATION_CLASS class,
552 FIXME("(%p,%p,%d,%p) stub\n", policy, name, class, buffer);
553 return STATUS_OBJECT_NAME_NOT_FOUND;
556 /******************************************************************************
557 * LsaRegisterPolicyChangeNotification [ADVAPI32.@]
560 NTSTATUS WINAPI LsaRegisterPolicyChangeNotification(
561 POLICY_NOTIFICATION_INFORMATION_CLASS class,
564 FIXME("(%d,%p) stub\n", class, event);
565 return STATUS_UNSUCCESSFUL;
568 /******************************************************************************
569 * LsaRemoveAccountRights [ADVAPI32.@]
572 NTSTATUS WINAPI LsaRemoveAccountRights(
576 PLSA_UNICODE_STRING rights,
579 FIXME("(%p,%p,%d,%p,0x%08x) stub\n", policy, sid, all, rights, count);
580 return STATUS_SUCCESS;
583 /******************************************************************************
584 * LsaRetrievePrivateData [ADVAPI32.@]
586 * Retrieves data stored by LsaStorePrivateData.
589 * PolicyHandle [I] Handle to a Policy object.
590 * KeyName [I] Name of the key where the data is stored.
591 * PrivateData [O] Pointer to the private data.
594 * Success: STATUS_SUCCESS.
595 * Failure: STATUS_OBJECT_NAME_NOT_FOUND or NTSTATUS code.
597 NTSTATUS WINAPI LsaRetrievePrivateData(
598 IN LSA_HANDLE PolicyHandle,
599 IN PLSA_UNICODE_STRING KeyName,
600 OUT PLSA_UNICODE_STRING* PrivateData)
602 FIXME("(%p,%p,%p) stub\n", PolicyHandle, KeyName, PrivateData);
603 return STATUS_OBJECT_NAME_NOT_FOUND;
606 /******************************************************************************
607 * LsaSetInformationPolicy [ADVAPI32.@]
609 * Modifies information in a Policy object.
612 * PolicyHandle [I] Handle to a Policy object.
613 * InformationClass [I] Type of information to set.
614 * Buffer [I] Pointer to the information to set.
617 * Success: STATUS_SUCCESS.
618 * Failure: NTSTATUS code.
620 NTSTATUS WINAPI LsaSetInformationPolicy(
621 IN LSA_HANDLE PolicyHandle,
622 IN POLICY_INFORMATION_CLASS InformationClass,
625 FIXME("(%p,0x%08x,%p) stub\n", PolicyHandle, InformationClass, Buffer);
627 return STATUS_UNSUCCESSFUL;
630 /******************************************************************************
631 * LsaSetSecret [ADVAPI32.@]
633 * Set old and new values on a secret handle
636 * SecretHandle [I] Handle to a secret object.
637 * EncryptedCurrentValue [I] Pointer to encrypted new value, can be NULL
638 * EncryptedOldValue [I] Pointer to encrypted old value, can be NULL
641 * Success: STATUS_SUCCESS
642 * Failure: NTSTATUS code.
644 NTSTATUS WINAPI LsaSetSecret(
645 IN LSA_HANDLE SecretHandle,
646 IN PLSA_UNICODE_STRING EncryptedCurrentValue,
647 IN PLSA_UNICODE_STRING EncryptedOldValue)
649 FIXME("(%p,%p,%p) stub\n", SecretHandle, EncryptedCurrentValue,
651 return STATUS_SUCCESS;
654 /******************************************************************************
655 * LsaSetTrustedDomainInfoByName [ADVAPI32.@]
658 NTSTATUS WINAPI LsaSetTrustedDomainInfoByName(
660 PLSA_UNICODE_STRING name,
661 TRUSTED_INFORMATION_CLASS class,
664 FIXME("(%p,%p,%d,%p) stub\n", policy, name, class, buffer);
665 return STATUS_SUCCESS;
668 /******************************************************************************
669 * LsaSetTrustedDomainInformation [ADVAPI32.@]
672 NTSTATUS WINAPI LsaSetTrustedDomainInformation(
675 TRUSTED_INFORMATION_CLASS class,
678 FIXME("(%p,%p,%d,%p) stub\n", policy, sid, class, buffer);
679 return STATUS_SUCCESS;
682 /******************************************************************************
683 * LsaStorePrivateData [ADVAPI32.@]
685 * Stores or deletes a Policy object's data under the specified reg key.
688 * PolicyHandle [I] Handle to a Policy object.
689 * KeyName [I] Name of the key where the data will be stored.
690 * PrivateData [O] Pointer to the private data.
693 * Success: STATUS_SUCCESS.
694 * Failure: STATUS_OBJECT_NAME_NOT_FOUND or NTSTATUS code.
696 NTSTATUS WINAPI LsaStorePrivateData(
697 IN LSA_HANDLE PolicyHandle,
698 IN PLSA_UNICODE_STRING KeyName,
699 IN PLSA_UNICODE_STRING PrivateData)
701 FIXME("(%p,%p,%p) stub\n", PolicyHandle, KeyName, PrivateData);
702 return STATUS_OBJECT_NAME_NOT_FOUND;
705 /******************************************************************************
706 * LsaUnregisterPolicyChangeNotification [ADVAPI32.@]
709 NTSTATUS WINAPI LsaUnregisterPolicyChangeNotification(
710 POLICY_NOTIFICATION_INFORMATION_CLASS class,
713 FIXME("(%d,%p) stub\n", class, event);
714 return STATUS_SUCCESS;