2 * Copyright (c) 1997 - 2002 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 #include "krb5_locl.h"
36 RCSID("$Id: auth_context.c 14452 2005-01-05 02:34:08Z lukeh $");
38 krb5_error_code KRB5_LIB_FUNCTION
39 krb5_auth_con_init(krb5_context context,
40 krb5_auth_context *auth_context)
46 krb5_set_error_string(context, "malloc: out of memory");
49 memset(p, 0, sizeof(*p));
50 ALLOC(p->authenticator, 1);
51 if (!p->authenticator) {
52 krb5_set_error_string(context, "malloc: out of memory");
56 memset (p->authenticator, 0, sizeof(*p->authenticator));
57 p->flags = KRB5_AUTH_CONTEXT_DO_TIME;
59 p->local_address = NULL;
60 p->remote_address = NULL;
63 p->keytype = KEYTYPE_NULL;
64 p->cksumtype = CKSUMTYPE_NONE;
69 krb5_error_code KRB5_LIB_FUNCTION
70 krb5_auth_con_free(krb5_context context,
71 krb5_auth_context auth_context)
73 if (auth_context != NULL) {
74 krb5_free_authenticator(context, &auth_context->authenticator);
75 if(auth_context->local_address){
76 free_HostAddress(auth_context->local_address);
77 free(auth_context->local_address);
79 if(auth_context->remote_address){
80 free_HostAddress(auth_context->remote_address);
81 free(auth_context->remote_address);
83 krb5_free_keyblock(context, auth_context->keyblock);
84 krb5_free_keyblock(context, auth_context->remote_subkey);
85 krb5_free_keyblock(context, auth_context->local_subkey);
91 krb5_error_code KRB5_LIB_FUNCTION
92 krb5_auth_con_setflags(krb5_context context,
93 krb5_auth_context auth_context,
96 auth_context->flags = flags;
101 krb5_error_code KRB5_LIB_FUNCTION
102 krb5_auth_con_getflags(krb5_context context,
103 krb5_auth_context auth_context,
106 *flags = auth_context->flags;
110 krb5_error_code KRB5_LIB_FUNCTION
111 krb5_auth_con_addflags(krb5_context context,
112 krb5_auth_context auth_context,
117 *flags = auth_context->flags;
118 auth_context->flags |= addflags;
122 krb5_error_code KRB5_LIB_FUNCTION
123 krb5_auth_con_removeflags(krb5_context context,
124 krb5_auth_context auth_context,
129 *flags = auth_context->flags;
130 auth_context->flags &= ~removeflags;
134 krb5_error_code KRB5_LIB_FUNCTION
135 krb5_auth_con_setaddrs(krb5_context context,
136 krb5_auth_context auth_context,
137 krb5_address *local_addr,
138 krb5_address *remote_addr)
141 if (auth_context->local_address)
142 krb5_free_address (context, auth_context->local_address);
144 auth_context->local_address = malloc(sizeof(krb5_address));
145 krb5_copy_address(context, local_addr, auth_context->local_address);
148 if (auth_context->remote_address)
149 krb5_free_address (context, auth_context->remote_address);
151 auth_context->remote_address = malloc(sizeof(krb5_address));
152 krb5_copy_address(context, remote_addr, auth_context->remote_address);
157 krb5_error_code KRB5_LIB_FUNCTION
158 krb5_auth_con_genaddrs(krb5_context context,
159 krb5_auth_context auth_context,
163 krb5_address local_k_address, remote_k_address;
164 krb5_address *lptr = NULL, *rptr = NULL;
165 struct sockaddr_storage ss_local, ss_remote;
166 struct sockaddr *local = (struct sockaddr *)&ss_local;
167 struct sockaddr *remote = (struct sockaddr *)&ss_remote;
170 if(flags & KRB5_AUTH_CONTEXT_GENERATE_LOCAL_ADDR) {
171 if (auth_context->local_address == NULL) {
172 len = sizeof(ss_local);
173 if(getsockname(fd, local, &len) < 0) {
175 krb5_set_error_string (context, "getsockname: %s",
179 ret = krb5_sockaddr2address (context, local, &local_k_address);
181 if(flags & KRB5_AUTH_CONTEXT_GENERATE_LOCAL_FULL_ADDR) {
182 krb5_sockaddr2port (context, local, &auth_context->local_port);
184 auth_context->local_port = 0;
185 lptr = &local_k_address;
188 if(flags & KRB5_AUTH_CONTEXT_GENERATE_REMOTE_ADDR) {
189 len = sizeof(ss_remote);
190 if(getpeername(fd, remote, &len) < 0) {
192 krb5_set_error_string (context, "getpeername: %s", strerror(ret));
195 ret = krb5_sockaddr2address (context, remote, &remote_k_address);
197 if(flags & KRB5_AUTH_CONTEXT_GENERATE_REMOTE_FULL_ADDR) {
198 krb5_sockaddr2port (context, remote, &auth_context->remote_port);
200 auth_context->remote_port = 0;
201 rptr = &remote_k_address;
203 ret = krb5_auth_con_setaddrs (context,
209 krb5_free_address (context, lptr);
211 krb5_free_address (context, rptr);
216 krb5_error_code KRB5_LIB_FUNCTION
217 krb5_auth_con_setaddrs_from_fd (krb5_context context,
218 krb5_auth_context auth_context,
221 int fd = *(int*)p_fd;
223 if(auth_context->local_address == NULL)
224 flags |= KRB5_AUTH_CONTEXT_GENERATE_LOCAL_FULL_ADDR;
225 if(auth_context->remote_address == NULL)
226 flags |= KRB5_AUTH_CONTEXT_GENERATE_REMOTE_FULL_ADDR;
227 return krb5_auth_con_genaddrs(context, auth_context, fd, flags);
230 krb5_error_code KRB5_LIB_FUNCTION
231 krb5_auth_con_getaddrs(krb5_context context,
232 krb5_auth_context auth_context,
233 krb5_address **local_addr,
234 krb5_address **remote_addr)
237 krb5_free_address (context, *local_addr);
238 *local_addr = malloc (sizeof(**local_addr));
239 if (*local_addr == NULL) {
240 krb5_set_error_string(context, "malloc: out of memory");
243 krb5_copy_address(context,
244 auth_context->local_address,
248 krb5_free_address (context, *remote_addr);
249 *remote_addr = malloc (sizeof(**remote_addr));
250 if (*remote_addr == NULL) {
251 krb5_set_error_string(context, "malloc: out of memory");
252 krb5_free_address (context, *local_addr);
256 krb5_copy_address(context,
257 auth_context->remote_address,
262 static krb5_error_code
263 copy_key(krb5_context context,
268 return krb5_copy_keyblock(context, in, out);
269 *out = NULL; /* is this right? */
273 krb5_error_code KRB5_LIB_FUNCTION
274 krb5_auth_con_getkey(krb5_context context,
275 krb5_auth_context auth_context,
276 krb5_keyblock **keyblock)
278 return copy_key(context, auth_context->keyblock, keyblock);
281 krb5_error_code KRB5_LIB_FUNCTION
282 krb5_auth_con_getlocalsubkey(krb5_context context,
283 krb5_auth_context auth_context,
284 krb5_keyblock **keyblock)
286 return copy_key(context, auth_context->local_subkey, keyblock);
289 krb5_error_code KRB5_LIB_FUNCTION
290 krb5_auth_con_getremotesubkey(krb5_context context,
291 krb5_auth_context auth_context,
292 krb5_keyblock **keyblock)
294 return copy_key(context, auth_context->remote_subkey, keyblock);
297 krb5_error_code KRB5_LIB_FUNCTION
298 krb5_auth_con_setkey(krb5_context context,
299 krb5_auth_context auth_context,
300 krb5_keyblock *keyblock)
302 if(auth_context->keyblock)
303 krb5_free_keyblock(context, auth_context->keyblock);
304 return copy_key(context, keyblock, &auth_context->keyblock);
307 krb5_error_code KRB5_LIB_FUNCTION
308 krb5_auth_con_setlocalsubkey(krb5_context context,
309 krb5_auth_context auth_context,
310 krb5_keyblock *keyblock)
312 if(auth_context->local_subkey)
313 krb5_free_keyblock(context, auth_context->local_subkey);
314 return copy_key(context, keyblock, &auth_context->local_subkey);
317 krb5_error_code KRB5_LIB_FUNCTION
318 krb5_auth_con_generatelocalsubkey(krb5_context context,
319 krb5_auth_context auth_context,
323 krb5_keyblock *subkey;
325 ret = krb5_generate_subkey_extended (context, key,
326 auth_context->keytype,
330 if(auth_context->local_subkey)
331 krb5_free_keyblock(context, auth_context->local_subkey);
332 auth_context->local_subkey = subkey;
337 krb5_error_code KRB5_LIB_FUNCTION
338 krb5_auth_con_setremotesubkey(krb5_context context,
339 krb5_auth_context auth_context,
340 krb5_keyblock *keyblock)
342 if(auth_context->remote_subkey)
343 krb5_free_keyblock(context, auth_context->remote_subkey);
344 return copy_key(context, keyblock, &auth_context->remote_subkey);
347 krb5_error_code KRB5_LIB_FUNCTION
348 krb5_auth_con_setcksumtype(krb5_context context,
349 krb5_auth_context auth_context,
350 krb5_cksumtype cksumtype)
352 auth_context->cksumtype = cksumtype;
356 krb5_error_code KRB5_LIB_FUNCTION
357 krb5_auth_con_getcksumtype(krb5_context context,
358 krb5_auth_context auth_context,
359 krb5_cksumtype *cksumtype)
361 *cksumtype = auth_context->cksumtype;
365 krb5_error_code KRB5_LIB_FUNCTION
366 krb5_auth_con_setkeytype (krb5_context context,
367 krb5_auth_context auth_context,
368 krb5_keytype keytype)
370 auth_context->keytype = keytype;
374 krb5_error_code KRB5_LIB_FUNCTION
375 krb5_auth_con_getkeytype (krb5_context context,
376 krb5_auth_context auth_context,
377 krb5_keytype *keytype)
379 *keytype = auth_context->keytype;
384 krb5_error_code KRB5_LIB_FUNCTION
385 krb5_auth_con_setenctype(krb5_context context,
386 krb5_auth_context auth_context,
389 if(auth_context->keyblock)
390 krb5_free_keyblock(context, auth_context->keyblock);
391 ALLOC(auth_context->keyblock, 1);
392 if(auth_context->keyblock == NULL)
394 auth_context->keyblock->keytype = etype;
398 krb5_error_code KRB5_LIB_FUNCTION
399 krb5_auth_con_getenctype(krb5_context context,
400 krb5_auth_context auth_context,
403 krb5_abortx(context, "unimplemented krb5_auth_getenctype called");
407 krb5_error_code KRB5_LIB_FUNCTION
408 krb5_auth_con_getlocalseqnumber(krb5_context context,
409 krb5_auth_context auth_context,
412 *seqnumber = auth_context->local_seqnumber;
416 krb5_error_code KRB5_LIB_FUNCTION
417 krb5_auth_con_setlocalseqnumber (krb5_context context,
418 krb5_auth_context auth_context,
421 auth_context->local_seqnumber = seqnumber;
425 krb5_error_code KRB5_LIB_FUNCTION
426 krb5_auth_getremoteseqnumber(krb5_context context,
427 krb5_auth_context auth_context,
430 *seqnumber = auth_context->remote_seqnumber;
434 krb5_error_code KRB5_LIB_FUNCTION
435 krb5_auth_con_setremoteseqnumber (krb5_context context,
436 krb5_auth_context auth_context,
439 auth_context->remote_seqnumber = seqnumber;
444 krb5_error_code KRB5_LIB_FUNCTION
445 krb5_auth_con_getauthenticator(krb5_context context,
446 krb5_auth_context auth_context,
447 krb5_authenticator *authenticator)
449 *authenticator = malloc(sizeof(**authenticator));
450 if (*authenticator == NULL) {
451 krb5_set_error_string(context, "malloc: out of memory");
455 copy_Authenticator(auth_context->authenticator,
461 void KRB5_LIB_FUNCTION
462 krb5_free_authenticator(krb5_context context,
463 krb5_authenticator *authenticator)
465 free_Authenticator (*authenticator);
466 free (*authenticator);
467 *authenticator = NULL;
471 krb5_error_code KRB5_LIB_FUNCTION
472 krb5_auth_con_setuserkey(krb5_context context,
473 krb5_auth_context auth_context,
474 krb5_keyblock *keyblock)
476 if(auth_context->keyblock)
477 krb5_free_keyblock(context, auth_context->keyblock);
478 return krb5_copy_keyblock(context, keyblock, &auth_context->keyblock);
481 krb5_error_code KRB5_LIB_FUNCTION
482 krb5_auth_con_getrcache(krb5_context context,
483 krb5_auth_context auth_context,
486 *rcache = auth_context->rcache;
490 krb5_error_code KRB5_LIB_FUNCTION
491 krb5_auth_con_setrcache(krb5_context context,
492 krb5_auth_context auth_context,
495 auth_context->rcache = rcache;
499 #if 0 /* not implemented */
501 krb5_error_code KRB5_LIB_FUNCTION
502 krb5_auth_con_initivector(krb5_context context,
503 krb5_auth_context auth_context)
505 krb5_abortx(context, "unimplemented krb5_auth_con_initivector called");
509 krb5_error_code KRB5_LIB_FUNCTION
510 krb5_auth_con_setivector(krb5_context context,
511 krb5_auth_context auth_context,
512 krb5_pointer ivector)
514 krb5_abortx(context, "unimplemented krb5_auth_con_setivector called");
517 #endif /* not implemented */