2 * Copyright (c) 1997 - 2005 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 /* $Id: hdb.h,v 1.38 2006/04/28 07:37:11 lha Exp $ */
41 #include <heim_asn1.h>
44 enum hdb_lockop{ HDB_RLOCK, HDB_WLOCK };
46 /* flags for various functions */
47 #define HDB_F_DECRYPT 1 /* decrypt keys */
48 #define HDB_F_REPLACE 2 /* replace entry */
49 #define HDB_F_GET_CLIENT 4 /* fetch client */
50 #define HDB_F_GET_SERVER 8 /* fetch server */
51 #define HDB_F_GET_KRBTGT 16 /* fetch krbtgt */
52 #define HDB_F_GET_ANY 28 /* fetch any of client,server,krbtgt */
54 /* key usage for master key */
55 #define HDB_KU_MKEY 0x484442
57 typedef struct hdb_master_key_data *hdb_master_key;
59 typedef struct hdb_entry_ex {
62 void (*free_entry)(krb5_context, struct hdb_entry_ex *);
63 krb5_error_code (*check_client_access)(krb5_context, struct hdb_entry_ex *,
65 krb5_error_code (*authz_data_as_req)(krb5_context,
66 struct hdb_entry_ex *,
67 METHOD_DATA* pa_data_seq,
69 const EncryptionKey *tgtkey,
70 const EncryptionKey *sessionkey,
71 AuthorizationData **out);
72 krb5_error_code (*authz_data_tgs_req)(krb5_context,
73 struct hdb_entry_ex *,
74 krb5_principal client,
75 AuthorizationData *in,
77 const EncryptionKey *tgtkey,
78 const EncryptionKey *servicekey,
79 const EncryptionKey *sessionkey,
80 AuthorizationData **out);
88 int hdb_master_key_set;
89 hdb_master_key hdb_master_key;
92 krb5_error_code (*hdb_open)(krb5_context,
96 krb5_error_code (*hdb_close)(krb5_context,
98 void (*hdb_free)(krb5_context,
101 krb5_error_code (*hdb_fetch)(krb5_context,
103 krb5_const_principal,
106 krb5_error_code (*hdb_store)(krb5_context,
110 krb5_error_code (*hdb_remove)(krb5_context,
112 krb5_const_principal);
113 krb5_error_code (*hdb_firstkey)(krb5_context,
117 krb5_error_code (*hdb_nextkey)(krb5_context,
121 krb5_error_code (*hdb_lock)(krb5_context,
124 krb5_error_code (*hdb_unlock)(krb5_context,
126 krb5_error_code (*hdb_rename)(krb5_context,
129 krb5_error_code (*hdb__get)(krb5_context,
133 krb5_error_code (*hdb__put)(krb5_context,
138 krb5_error_code (*hdb__del)(krb5_context,
141 krb5_error_code (*hdb_destroy)(krb5_context,
145 #define HDB_INTERFACE_VERSION 4
147 struct hdb_so_method {
150 krb5_error_code (*create)(krb5_context, HDB **, const char *filename);
153 #define HDB_DB_DIR "/var/heimdal"
154 #define HDB_DEFAULT_DB HDB_DB_DIR "/heimdal"
155 #define HDB_DB_FORMAT_ENTRY "hdb/db-format"
157 typedef krb5_error_code (*hdb_foreach_func_t)(krb5_context, HDB*,
158 hdb_entry_ex*, void*);
159 extern krb5_kt_ops hdb_kt_ops;
161 #include <hdb-protos.h>
163 #endif /* __HDB_H__ */