public void DomainTrustProcessor_EnumerateDomainTrusts_HappyPath()
        {
            var mockUtils     = new Mock <MockLDAPUtils>();
            var searchResults = new[]
            {
                new MockSearchResultEntry("CN\u003dexternal.local,CN\u003dSystem,DC\u003dtestlab,DC\u003dlocal",
                                          new Dictionary <string, object>
                {
                    { "trustdirection", "3" },
                    { "trusttype", "2" },
                    { "trustattributes", 0x24.ToString() },
                    { "cn", "external.local" },
                    { "securityidentifier", Helpers.B64ToBytes("AQQAAAAAAAUVAAAA7JjftxhaHTnafGWh") }
                }, "", Label.Domain)
            };

            mockUtils.Setup(x => x.QueryLDAP(It.IsAny <string>(), It.IsAny <SearchScope>(), It.IsAny <string[]>(),
                                             It.IsAny <string>(), It.IsAny <bool>(), It.IsAny <bool>(), It.IsAny <string>(), It.IsAny <bool>(),
                                             It.IsAny <bool>())).Returns(searchResults);
            var processor = new DomainTrustProcessor(mockUtils.Object);
            var test      = processor.EnumerateDomainTrusts("testlab.local").ToArray();

            Assert.Single(test);
            var trust = test.First();

            Assert.Equal(TrustDirection.Bidirectional, trust.TrustDirection);
            Assert.Equal("EXTERNAL.LOCAL", trust.TargetDomainName);
            Assert.Equal("S-1-5-21-3084884204-958224920-2707782874", trust.TargetDomainSid);
            Assert.True(trust.IsTransitive);
            Assert.Equal(TrustType.ParentChild, trust.TrustType);
            Assert.True(trust.SidFilteringEnabled);
        }
예제 #2
0
        private async Task <Domain> ProcessDomainObject(ISearchResultEntry entry,
                                                        ResolvedSearchResult resolvedSearchResult)
        {
            var ret = new Domain
            {
                ObjectIdentifier = resolvedSearchResult.ObjectId
            };

            ret.Properties.Add("domain", resolvedSearchResult.Domain);
            ret.Properties.Add("name", resolvedSearchResult.DisplayName);
            ret.Properties.Add("distinguishedname", entry.DistinguishedName.ToUpper());
            ret.Properties.Add("domainsid", resolvedSearchResult.DomainSid);
            ret.Properties.Add("highvalue", true);

            if ((_methods & ResolvedCollectionMethod.ACL) != 0)
            {
                ret.Aces           = _aclProcessor.ProcessACL(resolvedSearchResult, entry).ToArray();
                ret.IsACLProtected = _aclProcessor.IsACLProtected(entry);
            }

            if ((_methods & ResolvedCollectionMethod.Trusts) != 0)
            {
                ret.Trusts = _domainTrustProcessor.EnumerateDomainTrusts(resolvedSearchResult.Domain).ToArray();
            }

            if ((_methods & ResolvedCollectionMethod.ObjectProps) != 0)
            {
                ret.Properties = ContextUtils.Merge(ret.Properties, LDAPPropertyProcessor.ReadDomainProperties(entry));
                if (_context.Flags.CollectAllProperties)
                {
                    ret.Properties = ContextUtils.Merge(_ldapPropertyProcessor.ParseAllProperties(entry),
                                                        ret.Properties);
                }
            }

            if ((_methods & ResolvedCollectionMethod.Container) != 0)
            {
                ret.ChildObjects = _containerProcessor.GetContainerChildObjects(resolvedSearchResult, entry).ToArray();
                ret.Links        = _containerProcessor.ReadContainerGPLinks(resolvedSearchResult, entry).ToArray();
            }

            if ((_methods & ResolvedCollectionMethod.GPOLocalGroup) != 0)
            {
                var gplink = entry.GetProperty(LDAPProperties.GPLink);
                ret.GPOChanges = await _gpoLocalGroupProcessor.ReadGPOLocalGroups(gplink, entry.DistinguishedName);
            }

            return(ret);
        }
        public void DomainTrustProcessor_EnumerateDomainTrusts_SadPaths()
        {
            var mockUtils     = new Mock <MockLDAPUtils>();
            var searchResults = new[]
            {
                new MockSearchResultEntry("CN\u003dexternal.local,CN\u003dSystem,DC\u003dtestlab,DC\u003dlocal",
                                          new Dictionary <string, object>
                {
                    { "trustdirection", "3" },
                    { "trusttype", "2" },
                    { "trustattributes", 0x24.ToString() },
                    { "cn", "external.local" },
                    { "securityIdentifier", Array.Empty <byte>() }
                }, "", Label.Domain),
                new MockSearchResultEntry("CN\u003dexternal.local,CN\u003dSystem,DC\u003dtestlab,DC\u003dlocal",
                                          new Dictionary <string, object>
                {
                    { "trustdirection", "3" },
                    { "trusttype", "2" },
                    { "trustattributes", 0x24.ToString() },
                    { "cn", "external.local" },
                    { "securityIdentifier", Helpers.B64ToBytes("QQQAAAAAAAUVAAAA7JjftxhaHTnafGWh") }
                }, "", Label.Domain),
                new MockSearchResultEntry("CN\u003dexternal.local,CN\u003dSystem,DC\u003dtestlab,DC\u003dlocal",
                                          new Dictionary <string, object>
                {
                    { "trusttype", "2" },
                    { "trustattributes", 0x24.ToString() },
                    { "cn", "external.local" },
                    { "securityIdentifier", Helpers.B64ToBytes("AQQAAAAAAAUVAAAA7JjftxhaHTnafGWh") }
                }, "", Label.Domain),
                new MockSearchResultEntry("CN\u003dexternal.local,CN\u003dSystem,DC\u003dtestlab,DC\u003dlocal",
                                          new Dictionary <string, object>
                {
                    { "trustdirection", "3" },
                    { "trusttype", "2" },
                    { "cn", "external.local" },
                    { "securityIdentifier", Helpers.B64ToBytes("AQQAAAAAAAUVAAAA7JjftxhaHTnafGWh") }
                }, "", Label.Domain)
            };

            mockUtils.Setup(x => x.QueryLDAP(It.IsAny <string>(), It.IsAny <SearchScope>(), It.IsAny <string[]>(),
                                             It.IsAny <string>(), It.IsAny <bool>(), It.IsAny <bool>(), It.IsAny <string>(), It.IsAny <bool>(),
                                             It.IsAny <bool>())).Returns(searchResults);
            var processor = new DomainTrustProcessor(mockUtils.Object);
            var test      = processor.EnumerateDomainTrusts("testlab.local");

            Assert.Empty(test);
        }