diff options
author | dfr <dfr@FreeBSD.org> | 2008-05-07 13:39:42 +0000 |
---|---|---|
committer | dfr <dfr@FreeBSD.org> | 2008-05-07 13:39:42 +0000 |
commit | 51b6601db456e699ea5d4843cbc7239ee92d9c13 (patch) | |
tree | 4dbb862199a916e3ffe75f1cb08703ec0e662ffc /crypto/heimdal/kuser/kgetcred.c | |
parent | 2565fa13487d5bfc858144e431e3dfd7ffa5200e (diff) | |
download | FreeBSD-src-51b6601db456e699ea5d4843cbc7239ee92d9c13.zip FreeBSD-src-51b6601db456e699ea5d4843cbc7239ee92d9c13.tar.gz |
Vendor import of Heimdal 1.1
Diffstat (limited to 'crypto/heimdal/kuser/kgetcred.c')
-rw-r--r-- | crypto/heimdal/kuser/kgetcred.c | 147 |
1 files changed, 127 insertions, 20 deletions
diff --git a/crypto/heimdal/kuser/kgetcred.c b/crypto/heimdal/kuser/kgetcred.c index 6707455..a842e00 100644 --- a/crypto/heimdal/kuser/kgetcred.c +++ b/crypto/heimdal/kuser/kgetcred.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 1997 - 2000 Kungliga Tekniska Högskolan + * Copyright (c) 1997 - 2007 Kungliga Tekniska Högskolan * (Royal Institute of Technology, Stockholm, Sweden). * All rights reserved. * @@ -33,15 +33,34 @@ #include "kuser_locl.h" -RCSID("$Id: kgetcred.c,v 1.5 2001/02/20 01:44:51 assar Exp $"); +RCSID("$Id: kgetcred.c 22276 2007-12-12 02:42:31Z lha $"); +static char *cache_str; +static char *out_cache_str; +static char *delegation_cred_str; static char *etype_str; +static int transit_flag = 1; +static int forwardable_flag; +static char *impersonate_str; +static char *nametype_str; static int version_flag; static int help_flag; struct getargs args[] = { + { "cache", 'c', arg_string, &cache_str, + "credential cache to use", "cache"}, + { "out-cache", 0, arg_string, &out_cache_str, + "credential cache to store credential in", "cache"}, + { "delegation-credential-cache",0,arg_string, &delegation_cred_str, + "where to find the ticket use for delegation", "cache"}, + { "forwardable", 0, arg_flag, &forwardable_flag, + "forwardable ticket requested"}, + { "transit-check", 0, arg_negative_flag, &transit_flag }, { "enctype", 'e', arg_string, &etype_str, "encryption type to use", "enctype"}, + { "impersonate", 0, arg_string, &impersonate_str, + "client to impersonate", "principal"}, + { "name-type", 0, arg_string, &nametype_str }, { "version", 0, arg_flag, &version_flag }, { "help", 0, arg_flag, &help_flag } }; @@ -62,8 +81,11 @@ main(int argc, char **argv) krb5_error_code ret; krb5_context context; krb5_ccache cache; - krb5_creds in, *out; - int optind = 0; + krb5_creds *out; + int optidx = 0; + krb5_get_creds_opt opt; + krb5_principal server; + krb5_principal impersonate = NULL; setprogname (argv[0]); @@ -71,7 +93,7 @@ main(int argc, char **argv) if (ret) errx(1, "krb5_init_context failed: %d", ret); - if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optind)) + if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx)) usage(1); if (help_flag) @@ -82,17 +104,25 @@ main(int argc, char **argv) exit(0); } - argc -= optind; - argv += optind; + argc -= optidx; + argv += optidx; if (argc != 1) usage (1); - ret = krb5_cc_default(context, &cache); - if (ret) - krb5_err (context, 1, ret, "krb5_cc_default"); + if(cache_str) { + ret = krb5_cc_resolve(context, cache_str, &cache); + if (ret) + krb5_err (context, 1, ret, "%s", cache_str); + } else { + ret = krb5_cc_default (context, &cache); + if (ret) + krb5_err (context, 1, ret, "krb5_cc_resolve"); + } - memset(&in, 0, sizeof(in)); + ret = krb5_get_creds_opt_alloc(context, &opt); + if (ret) + krb5_err (context, 1, ret, "krb5_get_creds_opt_alloc"); if (etype_str) { krb5_enctype enctype; @@ -100,22 +130,99 @@ main(int argc, char **argv) ret = krb5_string_to_enctype(context, etype_str, &enctype); if (ret) krb5_errx (context, 1, "unrecognized enctype: %s", etype_str); - in.session.keytype = enctype; + krb5_get_creds_opt_set_enctype(context, opt, enctype); } - ret = krb5_cc_get_principal(context, cache, &in.client); - if (ret) - krb5_err (context, 1, ret, "krb5_cc_get_principal"); + if (impersonate_str) { + ret = krb5_parse_name(context, impersonate_str, &impersonate); + if (ret) + krb5_err (context, 1, ret, "krb5_parse_name %s", impersonate_str); + krb5_get_creds_opt_set_impersonate(context, opt, impersonate); + krb5_get_creds_opt_add_options(context, opt, KRB5_GC_NO_STORE); + } + + if (out_cache_str) + krb5_get_creds_opt_add_options(context, opt, KRB5_GC_NO_STORE); + + if (forwardable_flag) + krb5_get_creds_opt_add_options(context, opt, KRB5_GC_FORWARDABLE); + if (!transit_flag) + krb5_get_creds_opt_add_options(context, opt, KRB5_GC_NO_TRANSIT_CHECK); + + if (delegation_cred_str) { + krb5_ccache id; + krb5_creds c, mc; + Ticket ticket; + + krb5_cc_clear_mcred(&mc); + ret = krb5_cc_get_principal(context, cache, &mc.server); + if (ret) + krb5_err (context, 1, ret, "krb5_cc_get_principal"); + + ret = krb5_cc_resolve(context, delegation_cred_str, &id); + if(ret) + krb5_err (context, 1, ret, "krb5_cc_resolve"); + + ret = krb5_cc_retrieve_cred(context, id, 0, &mc, &c); + if(ret) + krb5_err (context, 1, ret, "krb5_cc_retrieve_cred"); - ret = krb5_parse_name(context, argv[0], &in.server); + ret = decode_Ticket(c.ticket.data, c.ticket.length, &ticket, NULL); + if (ret) { + krb5_clear_error_string(context); + krb5_err (context, 1, ret, "decode_Ticket"); + } + krb5_free_cred_contents(context, &c); + + ret = krb5_get_creds_opt_set_ticket(context, opt, &ticket); + if(ret) + krb5_err (context, 1, ret, "krb5_get_creds_opt_set_ticket"); + free_Ticket(&ticket); + + krb5_cc_close (context, id); + krb5_free_principal(context, mc.server); + + krb5_get_creds_opt_add_options(context, opt, + KRB5_GC_CONSTRAINED_DELEGATION); + } + + ret = krb5_parse_name(context, argv[0], &server); if (ret) krb5_err (context, 1, ret, "krb5_parse_name %s", argv[0]); - in.times.endtime = 0; - ret = krb5_get_credentials(context, 0, cache, &in, &out); + if (nametype_str) { + ret = krb5_parse_nametype(context, nametype_str, + &server->name.name_type); + if (ret) + krb5_err(context, 1, ret, "krb5_parse_nametype"); + } + + ret = krb5_get_creds(context, opt, cache, server, &out); if (ret) - krb5_err (context, 1, ret, "krb5_get_credentials"); + krb5_err (context, 1, ret, "krb5_get_creds"); + + if (out_cache_str) { + krb5_ccache id; + + ret = krb5_cc_resolve(context, out_cache_str, &id); + if(ret) + krb5_err (context, 1, ret, "krb5_cc_resolve"); + + ret = krb5_cc_initialize(context, id, out->client); + if(ret) + krb5_err (context, 1, ret, "krb5_cc_initialize"); + + ret = krb5_cc_store_cred(context, id, out); + if(ret) + krb5_err (context, 1, ret, "krb5_cc_store_cred"); + krb5_cc_close (context, id); + } + + krb5_free_creds(context, out); + krb5_free_principal(context, server); + krb5_get_creds_opt_free(context, opt); + krb5_cc_close (context, cache); + krb5_free_context (context); - krb5_free_creds_contents(context, out); return 0; } |