2 Unix SMB/CIFS implementation.
3 Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2009
5 This program is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 3 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License
16 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "param/pyparam.h"
22 #include "auth/gensec/gensec.h"
23 #include "libcli/util/pyerrors.h"
24 #include "scripting/python/modules.h"
25 #include "lib/talloc/pytalloc.h"
27 #include "librpc/rpc/pyrpc_util.h"
29 static PyObject *py_get_name_by_authtype(PyObject *self, PyObject *args)
33 struct gensec_security *security;
35 if (!PyArg_ParseTuple(args, "i", &type))
38 security = py_talloc_get_type(self, struct gensec_security);
40 name = gensec_get_name_by_authtype(security, type);
44 return PyString_FromString(name);
47 static struct gensec_settings *settings_from_object(TALLOC_CTX *mem_ctx, PyObject *object)
49 struct gensec_settings *s;
50 PyObject *py_hostname, *py_lp_ctx;
52 if (!PyDict_Check(object)) {
53 PyErr_SetString(PyExc_ValueError, "settings should be a dictionary");
57 s = talloc_zero(mem_ctx, struct gensec_settings);
60 py_hostname = PyDict_GetItemString(object, "target_hostname");
62 PyErr_SetString(PyExc_ValueError, "settings.target_hostname not found");
66 py_lp_ctx = PyDict_GetItemString(object, "lp_ctx");
68 PyErr_SetString(PyExc_ValueError, "settings.lp_ctx not found");
72 s->target_hostname = PyString_AsString(py_hostname);
73 s->lp_ctx = lpcfg_from_py_object(s, py_lp_ctx);
77 static PyObject *py_gensec_start_client(PyTypeObject *type, PyObject *args, PyObject *kwargs)
80 py_talloc_Object *self;
81 struct gensec_settings *settings;
82 const char *kwnames[] = { "settings", NULL };
83 PyObject *py_settings;
84 struct tevent_context *ev;
85 struct gensec_security *gensec;
87 if (!PyArg_ParseTupleAndKeywords(args, kwargs, "O", discard_const_p(char *, kwnames), &py_settings))
90 self = (py_talloc_Object*)type->tp_alloc(type, 0);
95 self->talloc_ctx = talloc_new(NULL);
96 if (self->talloc_ctx == NULL) {
101 settings = settings_from_object(self->talloc_ctx, py_settings);
102 if (settings == NULL) {
107 ev = tevent_context_init(self->talloc_ctx);
114 status = gensec_init(settings->lp_ctx);
115 if (!NT_STATUS_IS_OK(status)) {
116 PyErr_SetNTSTATUS(status);
121 status = gensec_client_start(self->talloc_ctx, &gensec, ev, settings);
122 if (!NT_STATUS_IS_OK(status)) {
123 PyErr_SetNTSTATUS(status);
130 return (PyObject *)self;
133 static PyObject *py_gensec_session_info(PyObject *self)
136 PyObject *py_session_info;
137 struct gensec_security *security = py_talloc_get_type(self, struct gensec_security);
138 struct auth_session_info *info;
139 if (security->ops == NULL) {
140 PyErr_SetString(PyExc_RuntimeError, "no mechanism selected");
143 status = gensec_session_info(security, &info);
144 if (NT_STATUS_IS_ERR(status)) {
145 PyErr_SetNTSTATUS(status);
149 py_session_info = py_return_ndr_struct("samba.auth", "session_info",
151 return py_session_info;
154 static PyObject *py_gensec_start_mech_by_name(PyObject *self, PyObject *args)
157 struct gensec_security *security = py_talloc_get_type(self, struct gensec_security);
160 if (!PyArg_ParseTuple(args, "s", &name))
163 status = gensec_start_mech_by_name(security, name);
164 if (!NT_STATUS_IS_OK(status)) {
165 PyErr_SetNTSTATUS(status);
172 static PyObject *py_gensec_start_mech_by_authtype(PyObject *self, PyObject *args)
175 struct gensec_security *security = py_talloc_get_type(self, struct gensec_security);
177 if (!PyArg_ParseTuple(args, "ii", &authtype, &level))
180 status = gensec_start_mech_by_authtype(security, authtype, level);
181 if (!NT_STATUS_IS_OK(status)) {
182 PyErr_SetNTSTATUS(status);
189 static PyMethodDef py_gensec_security_methods[] = {
190 { "start_client", (PyCFunction)py_gensec_start_client, METH_VARARGS|METH_KEYWORDS|METH_CLASS,
191 "S.start_client(settings) -> gensec" },
192 /* { "start_server", (PyCFunction)py_gensec_start_server, METH_VARARGS|METH_KEYWORDS|METH_CLASS,
193 "S.start_server(auth_ctx, settings) -> gensec" },*/
194 { "session_info", (PyCFunction)py_gensec_session_info, METH_NOARGS,
195 "S.session_info() -> info" },
196 { "start_mech_by_name", (PyCFunction)py_gensec_start_mech_by_name, METH_VARARGS,
197 "S.start_mech_by_name(name)" },
198 { "start_mech_by_authtype", (PyCFunction)py_gensec_start_mech_by_authtype, METH_VARARGS, "S.start_mech_by_authtype(authtype, level)" },
199 { "get_name_by_authtype", (PyCFunction)py_get_name_by_authtype, METH_VARARGS,
200 "S.get_name_by_authtype(authtype) -> name\nLookup an auth type." },
204 static PyTypeObject Py_Security = {
205 .tp_name = "Security",
206 .tp_flags = Py_TPFLAGS_DEFAULT,
207 .tp_methods = py_gensec_security_methods,
208 .tp_basicsize = sizeof(py_talloc_Object),
211 void initgensec(void)
215 Py_Security.tp_base = PyTalloc_GetObjectType();
216 if (Py_Security.tp_base == NULL)
219 if (PyType_Ready(&Py_Security) < 0)
222 m = Py_InitModule3("gensec", NULL, "Generic Security Interface.");
226 PyModule_AddObject(m, "FEATURE_SESSION_KEY", PyInt_FromLong(GENSEC_FEATURE_SESSION_KEY));
227 PyModule_AddObject(m, "FEATURE_SIGN", PyInt_FromLong(GENSEC_FEATURE_SIGN));
228 PyModule_AddObject(m, "FEATURE_SEAL", PyInt_FromLong(GENSEC_FEATURE_SEAL));
229 PyModule_AddObject(m, "FEATURE_DCE_STYLE", PyInt_FromLong(GENSEC_FEATURE_DCE_STYLE));
230 PyModule_AddObject(m, "FEATURE_ASYNC_REPLIES", PyInt_FromLong(GENSEC_FEATURE_ASYNC_REPLIES));
231 PyModule_AddObject(m, "FEATURE_DATAGRAM_MODE", PyInt_FromLong(GENSEC_FEATURE_DATAGRAM_MODE));
232 PyModule_AddObject(m, "FEATURE_SIGN_PKT_HEADER", PyInt_FromLong(GENSEC_FEATURE_SIGN_PKT_HEADER));
233 PyModule_AddObject(m, "FEATURE_NEW_SPNEGO", PyInt_FromLong(GENSEC_FEATURE_NEW_SPNEGO));
235 Py_INCREF(&Py_Security);
236 PyModule_AddObject(m, "Security", (PyObject *)&Py_Security);