1 /* $NetBSD: windc.c,v 1.1.1.1 2011/04/13 18:14:38 elric Exp $ */ 2 3 /* 4 * Copyright (c) 2007 Kungliga Tekniska Högskolan 5 * (Royal Institute of Technology, Stockholm, Sweden). 6 * All rights reserved. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 15 * 2. Redistributions in binary form must reproduce the above copyright 16 * notice, this list of conditions and the following disclaimer in the 17 * documentation and/or other materials provided with the distribution. 18 * 19 * 3. Neither the name of the Institute nor the names of its contributors 20 * may be used to endorse or promote products derived from this software 21 * without specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 26 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 33 * SUCH DAMAGE. 34 */ 35 36 #include "kdc_locl.h" 37 38 static krb5plugin_windc_ftable *windcft; 39 static void *windcctx; 40 41 /* 42 * Pick the first WINDC module that we find. 43 */ 44 45 krb5_error_code 46 krb5_kdc_windc_init(krb5_context context) 47 { 48 struct krb5_plugin *list = NULL, *e; 49 krb5_error_code ret; 50 51 ret = _krb5_plugin_find(context, PLUGIN_TYPE_DATA, "windc", &list); 52 if(ret != 0 || list == NULL) 53 return 0; 54 55 for (e = list; e != NULL; e = _krb5_plugin_get_next(e)) { 56 57 windcft = _krb5_plugin_get_symbol(e); 58 if (windcft->minor_version < KRB5_WINDC_PLUGIN_MINOR) 59 continue; 60 61 (*windcft->init)(context, &windcctx); 62 break; 63 } 64 _krb5_plugin_free(list); 65 if (e == NULL) { 66 krb5_set_error_message(context, ENOENT, "Did not find any WINDC plugin"); 67 windcft = NULL; 68 return ENOENT; 69 } 70 71 return 0; 72 } 73 74 75 krb5_error_code 76 _kdc_pac_generate(krb5_context context, 77 hdb_entry_ex *client, 78 krb5_pac *pac) 79 { 80 *pac = NULL; 81 if (windcft == NULL) 82 return 0; 83 return (windcft->pac_generate)(windcctx, context, client, pac); 84 } 85 86 krb5_error_code 87 _kdc_pac_verify(krb5_context context, 88 const krb5_principal client_principal, 89 hdb_entry_ex *client, 90 hdb_entry_ex *server, 91 hdb_entry_ex *krbtgt, 92 krb5_pac *pac, 93 int *verified) 94 { 95 krb5_error_code ret; 96 97 if (windcft == NULL) 98 return 0; 99 100 ret = windcft->pac_verify(windcctx, context, 101 client_principal, client, server, krbtgt, pac); 102 if (ret == 0) 103 *verified = 1; 104 return ret; 105 } 106 107 krb5_error_code 108 _kdc_check_access(krb5_context context, 109 krb5_kdc_configuration *config, 110 hdb_entry_ex *client_ex, const char *client_name, 111 hdb_entry_ex *server_ex, const char *server_name, 112 KDC_REQ *req, 113 krb5_data *e_data) 114 { 115 if (windcft == NULL) 116 return kdc_check_flags(context, config, 117 client_ex, client_name, 118 server_ex, server_name, 119 req->msg_type == krb_as_req); 120 121 return (windcft->client_access)(windcctx, 122 context, config, 123 client_ex, client_name, 124 server_ex, server_name, 125 req, e_data); 126 } 127