2 * Copyright (c) 2010 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Portions Copyright (c) 2010 Apple Inc. All rights reserved.
7 * Portions Copyright (c) 2010 PADL Software Pty Ltd. All rights reserved.
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted provided that the following conditions
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
20 * 3. Neither the name of the Institute nor the names of its contributors
21 * may be used to endorse or promote products derived from this software
22 * without specific prior written permission.
24 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
25 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
28 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
29 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
30 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
31 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
32 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
33 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
37 #include "mech_locl.h"
39 #include <crypto-headers.h>
42 get_option_def(int def, gss_const_OID mech, gss_mo_desc *mo, gss_buffer_t value)
48 _gss_mo_get_option_1(gss_const_OID mech, gss_mo_desc *mo, gss_buffer_t value)
50 return get_option_def(1, mech, mo, value);
54 _gss_mo_get_option_0(gss_const_OID mech, gss_mo_desc *mo, gss_buffer_t value)
56 return get_option_def(0, mech, mo, value);
60 _gss_mo_get_ctx_as_string(gss_const_OID mech, gss_mo_desc *mo, gss_buffer_t value)
63 value->value = strdup((char *)mo->ctx);
64 if (value->value == NULL)
66 value->length = strlen((char *)mo->ctx);
68 return GSS_S_COMPLETE;
71 GSSAPI_LIB_FUNCTION int GSSAPI_LIB_CALL
72 gss_mo_set(gss_const_OID mech, gss_const_OID option,
73 int enable, gss_buffer_t value)
75 gssapi_mech_interface m;
78 if ((m = __gss_get_mechanism(mech)) == NULL)
79 return GSS_S_BAD_MECH;
81 for (n = 0; n < m->gm_mo_num; n++)
82 if (gss_oid_equal(option, m->gm_mo[n].option) && m->gm_mo[n].set)
83 return m->gm_mo[n].set(mech, &m->gm_mo[n], enable, value);
85 return GSS_S_UNAVAILABLE;
88 GSSAPI_LIB_FUNCTION int GSSAPI_LIB_CALL
89 gss_mo_get(gss_const_OID mech, gss_const_OID option, gss_buffer_t value)
91 gssapi_mech_interface m;
94 _mg_buffer_zero(value);
96 if ((m = __gss_get_mechanism(mech)) == NULL)
97 return GSS_S_BAD_MECH;
99 for (n = 0; n < m->gm_mo_num; n++)
100 if (gss_oid_equal(option, m->gm_mo[n].option) && m->gm_mo[n].get)
101 return m->gm_mo[n].get(mech, &m->gm_mo[n], value);
103 return GSS_S_UNAVAILABLE;
107 add_all_mo(gssapi_mech_interface m, gss_OID_set *options, OM_uint32 mask)
112 for (n = 0; n < m->gm_mo_num; n++)
113 if ((m->gm_mo[n].flags & mask) == mask)
114 gss_add_oid_set_member(&minor, m->gm_mo[n].option, options);
117 GSSAPI_LIB_FUNCTION void GSSAPI_LIB_CALL
118 gss_mo_list(gss_const_OID mech, gss_OID_set *options)
120 gssapi_mech_interface m;
121 OM_uint32 major, minor;
126 *options = GSS_C_NO_OID_SET;
128 if ((m = __gss_get_mechanism(mech)) == NULL)
131 major = gss_create_empty_oid_set(&minor, options);
132 if (major != GSS_S_COMPLETE)
135 add_all_mo(m, options, 0);
138 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
139 gss_mo_name(gss_const_OID mech, gss_const_OID option, gss_buffer_t name)
141 gssapi_mech_interface m;
145 return GSS_S_BAD_NAME;
147 if ((m = __gss_get_mechanism(mech)) == NULL)
148 return GSS_S_BAD_MECH;
150 for (n = 0; n < m->gm_mo_num; n++) {
151 if (gss_oid_equal(option, m->gm_mo[n].option)) {
153 * If there is no name, its because its a GSS_C_MA and
154 * there is already a table for that.
156 if (m->gm_mo[n].name) {
157 name->value = strdup(m->gm_mo[n].name);
158 if (name->value == NULL)
159 return GSS_S_BAD_NAME;
160 name->length = strlen(m->gm_mo[n].name);
161 return GSS_S_COMPLETE;
164 return gss_display_mech_attr(&junk, option,
169 return GSS_S_BAD_NAME;
173 * Helper function to allow NULL name
177 mo_value(const gss_const_OID mech, gss_const_OID option, gss_buffer_t name)
180 return GSS_S_COMPLETE;
182 return gss_mo_get(mech, option, name);
185 /* code derived from draft-ietf-cat-sasl-gssapi-01 */
186 static char basis_32[] = "ABCDEFGHIJKLMNOPQRSTUVWXYZ234567";
189 make_sasl_name(OM_uint32 *minor, const gss_OID mech, char sasl_name[16])
193 u_char hdr[2], hash[20], *h = hash;
195 if (mech->length > 127)
196 return GSS_S_BAD_MECH;
199 hdr[1] = mech->length;
201 ctx = EVP_MD_CTX_create();
202 EVP_DigestInit_ex(ctx, EVP_sha1(), NULL);
203 EVP_DigestUpdate(ctx, hdr, 2);
204 EVP_DigestUpdate(ctx, mech->elements, mech->length);
205 EVP_DigestFinal_ex(ctx, hash, NULL);
206 EVP_MD_CTX_destroy(ctx);
208 memcpy(p, "GS2-", 4);
211 *p++ = basis_32[(h[0] >> 3)];
212 *p++ = basis_32[((h[0] & 7) << 2) | (h[1] >> 6)];
213 *p++ = basis_32[(h[1] & 0x3f) >> 1];
214 *p++ = basis_32[((h[1] & 1) << 4) | (h[2] >> 4)];
215 *p++ = basis_32[((h[2] & 0xf) << 1) | (h[3] >> 7)];
216 *p++ = basis_32[(h[3] & 0x7f) >> 2];
217 *p++ = basis_32[((h[3] & 3) << 3) | (h[4] >> 5)];
218 *p++ = basis_32[(h[4] & 0x1f)];
219 *p++ = basis_32[(h[5] >> 3)];
220 *p++ = basis_32[((h[5] & 7) << 2) | (h[6] >> 6)];
221 *p++ = basis_32[(h[6] & 0x3f) >> 1];
225 return GSS_S_COMPLETE;
229 * gss_inquire_saslname_for_mech() wrapper that uses MIT SPI
232 inquire_saslname_for_mech_compat(OM_uint32 *minor,
233 const gss_OID desired_mech,
234 gss_buffer_t sasl_mech_name,
235 gss_buffer_t mech_name,
236 gss_buffer_t mech_description)
238 struct gss_mech_compat_desc_struct *gmc;
239 gssapi_mech_interface m;
242 m = __gss_get_mechanism(desired_mech);
244 return GSS_S_BAD_MECH;
248 if (gmc != NULL && gmc->gmc_inquire_saslname_for_mech != NULL) {
249 major = gmc->gmc_inquire_saslname_for_mech(minor,
255 major = GSS_S_UNAVAILABLE;
262 * Returns different protocol names and description of the mechanism.
264 * @param minor_status minor status code
265 * @param desired_mech mech list query
266 * @param sasl_mech_name SASL GS2 protocol name
267 * @param mech_name gssapi protocol name
268 * @param mech_description description of gssapi mech
270 * @return returns GSS_S_COMPLETE or a error code.
275 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
276 gss_inquire_saslname_for_mech(OM_uint32 *minor_status,
277 const gss_OID desired_mech,
278 gss_buffer_t sasl_mech_name,
279 gss_buffer_t mech_name,
280 gss_buffer_t mech_description)
284 _mg_buffer_zero(sasl_mech_name);
285 _mg_buffer_zero(mech_name);
286 _mg_buffer_zero(mech_description);
291 if (desired_mech == NULL)
292 return GSS_S_BAD_MECH;
294 major = mo_value(desired_mech, GSS_C_MA_SASL_MECH_NAME, sasl_mech_name);
295 if (major == GSS_S_COMPLETE) {
297 major = mo_value(desired_mech, GSS_C_MA_MECH_NAME, mech_name);
298 if (GSS_ERROR(major))
301 major = mo_value(desired_mech, GSS_C_MA_MECH_DESCRIPTION, mech_description);
302 if (GSS_ERROR(major))
306 if (GSS_ERROR(major)) {
307 /* API-as-SPI compatibility */
308 major = inquire_saslname_for_mech_compat(minor_status,
315 if (GSS_ERROR(major)) {
316 /* Algorithmically dervied SASL mechanism name */
318 gss_buffer_desc tmp = { sizeof(buf) - 1, buf };
320 major = make_sasl_name(minor_status, desired_mech, buf);
321 if (GSS_ERROR(major))
324 major = _gss_copy_buffer(minor_status, &tmp, sasl_mech_name);
325 if (GSS_ERROR(major))
333 * Find a mech for a sasl name
335 * @param minor_status minor status code
336 * @param sasl_mech_name
339 * @return returns GSS_S_COMPLETE or an error code.
342 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
343 gss_inquire_mech_for_saslname(OM_uint32 *minor_status,
344 const gss_buffer_t sasl_mech_name,
347 struct _gss_mech_switch *m;
348 gss_buffer_desc name;
349 OM_uint32 major, junk;
356 HEIM_TAILQ_FOREACH(m, &_gss_mechs, gm_link) {
357 struct gss_mech_compat_desc_struct *gmc;
360 major = mo_value(m->gm_mech_oid, GSS_C_MA_SASL_MECH_NAME, &name);
361 if (major == GSS_S_COMPLETE &&
362 name.length == sasl_mech_name->length &&
363 memcmp(name.value, sasl_mech_name->value, name.length) == 0) {
364 gss_release_buffer(&junk, &name);
365 *mech_type = m->gm_mech_oid;
366 return GSS_S_COMPLETE;
368 gss_release_buffer(&junk, &name);
370 if (GSS_ERROR(major)) {
371 /* API-as-SPI compatibility */
372 gmc = m->gm_mech.gm_compat;
373 if (gmc && gmc->gmc_inquire_mech_for_saslname) {
374 major = gmc->gmc_inquire_mech_for_saslname(minor_status,
377 if (major == GSS_S_COMPLETE)
378 return GSS_S_COMPLETE;
382 if (GSS_ERROR(major)) {
383 /* Algorithmically dervied SASL mechanism name */
384 if (sasl_mech_name->length == 16 &&
385 make_sasl_name(minor_status, m->gm_mech_oid, buf) == GSS_S_COMPLETE &&
386 memcmp(buf, sasl_mech_name->value, 16) == 0) {
387 *mech_type = m->gm_mech_oid;
388 return GSS_S_COMPLETE;
393 return GSS_S_BAD_MECH;
397 * Test mechanism against indicated attributes using both Heimdal and
401 test_mech_attrs(gssapi_mech_interface mi,
402 gss_const_OID_set mech_attrs,
403 gss_const_OID_set against_attrs,
409 if (against_attrs == GSS_C_NO_OID_SET)
412 for (n = 0; n < against_attrs->count; n++) {
413 for (m = 0; m < mi->gm_mo_num; m++) {
414 eq = gss_oid_equal(mi->gm_mo[m].option,
415 &against_attrs->elements[n]);
419 if (mech_attrs != GSS_C_NO_OID_SET) {
420 for (m = 0; m < mech_attrs->count; m++) {
421 eq = gss_oid_equal(&mech_attrs->elements[m],
422 &against_attrs->elements[n]);
435 * Return set of mechanism that fullfill the criteria
437 * @param minor_status minor status code
438 * @param desired_mech_attrs
439 * @param except_mech_attrs
440 * @param critical_mech_attrs
441 * @param mechs returned mechs, free with gss_release_oid_set().
443 * @return returns GSS_S_COMPLETE or an error code.
446 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
447 gss_indicate_mechs_by_attrs(OM_uint32 * minor_status,
448 gss_const_OID_set desired_mech_attrs,
449 gss_const_OID_set except_mech_attrs,
450 gss_const_OID_set critical_mech_attrs,
453 struct _gss_mech_switch *ms;
454 gss_OID_set mech_attrs = GSS_C_NO_OID_SET;
455 gss_OID_set known_mech_attrs = GSS_C_NO_OID_SET;
458 major = gss_create_empty_oid_set(minor_status, mechs);
459 if (GSS_ERROR(major))
464 HEIM_TAILQ_FOREACH(ms, &_gss_mechs, gm_link) {
465 gssapi_mech_interface mi = &ms->gm_mech;
466 struct gss_mech_compat_desc_struct *gmc = mi->gm_compat;
469 if (gmc && gmc->gmc_inquire_attrs_for_mech) {
470 major = gmc->gmc_inquire_attrs_for_mech(minor_status,
474 if (GSS_ERROR(major))
479 * Test mechanism supports all of desired_mech_attrs;
480 * none of except_mech_attrs;
481 * and knows of all critical_mech_attrs.
483 if (test_mech_attrs(mi, mech_attrs, desired_mech_attrs, 0) &&
484 test_mech_attrs(mi, mech_attrs, except_mech_attrs, 1) &&
485 test_mech_attrs(mi, known_mech_attrs, critical_mech_attrs, 0)) {
486 major = gss_add_oid_set_member(minor_status, &mi->gm_mech_oid, mechs);
489 gss_release_oid_set(&tmp, &mech_attrs);
490 gss_release_oid_set(&tmp, &known_mech_attrs);
492 if (GSS_ERROR(major))
500 * List support attributes for a mech and/or all mechanisms.
502 * @param minor_status minor status code
503 * @param mech given together with mech_attr will return the list of
504 * attributes for mechanism, can optionally be GSS_C_NO_OID.
505 * @param mech_attr see mech parameter, can optionally be NULL,
506 * release with gss_release_oid_set().
507 * @param known_mech_attrs all attributes for mechanisms supported,
508 * release with gss_release_oid_set().
513 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
514 gss_inquire_attrs_for_mech(OM_uint32 * minor_status,
516 gss_OID_set *mech_attr,
517 gss_OID_set *known_mech_attrs)
519 OM_uint32 major, junk;
521 if (known_mech_attrs)
522 *known_mech_attrs = GSS_C_NO_OID_SET;
524 if (mech_attr && mech) {
525 gssapi_mech_interface m;
526 struct gss_mech_compat_desc_struct *gmc;
528 if ((m = __gss_get_mechanism(mech)) == NULL) {
530 return GSS_S_BAD_MECH;
535 if (gmc && gmc->gmc_inquire_attrs_for_mech) {
536 major = gmc->gmc_inquire_attrs_for_mech(minor_status,
541 major = gss_create_empty_oid_set(minor_status, mech_attr);
542 if (major == GSS_S_COMPLETE)
543 add_all_mo(m, mech_attr, GSS_MO_MA);
545 if (GSS_ERROR(major))
549 if (known_mech_attrs) {
550 struct _gss_mech_switch *m;
552 if (*known_mech_attrs == GSS_C_NO_OID_SET) {
553 major = gss_create_empty_oid_set(minor_status, known_mech_attrs);
554 if (GSS_ERROR(major)) {
556 gss_release_oid_set(&junk, mech_attr);
563 HEIM_TAILQ_FOREACH(m, &_gss_mechs, gm_link)
564 add_all_mo(&m->gm_mech, known_mech_attrs, GSS_MO_MA);
568 return GSS_S_COMPLETE;
572 * Return names and descriptions of mech attributes
574 * @param minor_status minor status code
580 * @return returns GSS_S_COMPLETE or an error code.
583 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
584 gss_display_mech_attr(OM_uint32 * minor_status,
585 gss_const_OID mech_attr,
587 gss_buffer_t short_desc,
588 gss_buffer_t long_desc)
590 struct _gss_oid_name_table *ma = NULL;
594 _mg_buffer_zero(name);
595 _mg_buffer_zero(short_desc);
596 _mg_buffer_zero(long_desc);
601 for (n = 0; ma == NULL && _gss_ont_ma[n].oid; n++)
602 if (gss_oid_equal(mech_attr, _gss_ont_ma[n].oid))
603 ma = &_gss_ont_ma[n];
606 return GSS_S_BAD_MECH_ATTR;
610 bd.value = rk_UNCONST(ma->name);
611 bd.length = strlen(ma->name);
612 major = _gss_copy_buffer(minor_status, &bd, name);
613 if (major != GSS_S_COMPLETE)
619 bd.value = rk_UNCONST(ma->short_desc);
620 bd.length = strlen(ma->short_desc);
621 major = _gss_copy_buffer(minor_status, &bd, short_desc);
622 if (major != GSS_S_COMPLETE)
628 bd.value = rk_UNCONST(ma->long_desc);
629 bd.length = strlen(ma->long_desc);
630 major = _gss_copy_buffer(minor_status, &bd, long_desc);
631 if (major != GSS_S_COMPLETE)
635 return GSS_S_COMPLETE;