1 /* $NetBSD: test_kcred.c,v 1.1.1.1 2011/04/13 18:14:44 elric Exp $ */ 2 3 /* 4 * Copyright (c) 2003-2004 Kungliga Tekniska Högskolan 5 * (Royal Institute of Technology, Stockholm, Sweden). 6 * All rights reserved. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 15 * 2. Redistributions in binary form must reproduce the above copyright 16 * notice, this list of conditions and the following disclaimer in the 17 * documentation and/or other materials provided with the distribution. 18 * 19 * 3. Neither the name of KTH nor the names of its contributors may be 20 * used to endorse or promote products derived from this software without 21 * specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY 24 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 26 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE 27 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 28 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 29 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR 30 * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, 31 * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR 32 * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF 33 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 34 */ 35 36 #ifdef HAVE_CONFIG_H 37 #include <config.h> 38 #endif 39 40 #include <krb5/roken.h> 41 #include <stdio.h> 42 #include <stdlib.h> 43 #include <string.h> 44 #include <stdarg.h> 45 #include <gssapi/gssapi.h> 46 #include <gssapi/gssapi_krb5.h> 47 #include <gssapi/gssapi_spnego.h> 48 #include <krb5/krb5.h> 49 #include <err.h> 50 #include <krb5/getarg.h> 51 52 static int version_flag = 0; 53 static int help_flag = 0; 54 55 static void 56 copy_import(void) 57 { 58 gss_cred_id_t cred1, cred2; 59 OM_uint32 maj_stat, min_stat; 60 gss_name_t name1, name2; 61 OM_uint32 lifetime1, lifetime2; 62 gss_cred_usage_t usage1, usage2; 63 gss_OID_set mechs1, mechs2; 64 krb5_ccache id; 65 krb5_error_code ret; 66 krb5_context context; 67 int equal; 68 69 maj_stat = gss_acquire_cred(&min_stat, GSS_C_NO_NAME, GSS_C_INDEFINITE, 70 GSS_C_NO_OID_SET, GSS_C_INITIATE, 71 &cred1, NULL, NULL); 72 if (maj_stat != GSS_S_COMPLETE) 73 errx(1, "gss_acquire_cred"); 74 75 maj_stat = gss_inquire_cred(&min_stat, cred1, &name1, &lifetime1, 76 &usage1, &mechs1); 77 if (maj_stat != GSS_S_COMPLETE) 78 errx(1, "gss_inquire_cred"); 79 80 ret = krb5_init_context(&context); 81 if (ret) 82 errx(1, "krb5_init_context"); 83 84 ret = krb5_cc_new_unique(context, krb5_cc_type_memory, NULL, &id); 85 if (ret) 86 krb5_err(context, 1, ret, "krb5_cc_new_unique"); 87 88 maj_stat = gss_krb5_copy_ccache(&min_stat, cred1, id); 89 if (maj_stat != GSS_S_COMPLETE) 90 errx(1, "gss_krb5_copy_ccache"); 91 92 maj_stat = gss_krb5_import_cred(&min_stat, id, NULL, NULL, &cred2); 93 if (maj_stat != GSS_S_COMPLETE) 94 errx(1, "gss_krb5_import_cred"); 95 96 maj_stat = gss_inquire_cred(&min_stat, cred2, &name2, &lifetime2, 97 &usage2, &mechs2); 98 if (maj_stat != GSS_S_COMPLETE) 99 errx(1, "gss_inquire_cred 2"); 100 101 maj_stat = gss_compare_name(&min_stat, name1, name2, &equal); 102 if (maj_stat != GSS_S_COMPLETE) 103 errx(1, "gss_compare_name"); 104 if (!equal) 105 errx(1, "names not equal"); 106 107 if (lifetime1 != lifetime2) 108 errx(1, "lifetime not equal %lu != %lu", 109 (unsigned long)lifetime1, (unsigned long)lifetime2); 110 111 if (usage1 != usage2) { 112 /* as long any of them is both are everything it ok */ 113 if (usage1 != GSS_C_BOTH && usage2 != GSS_C_BOTH) 114 errx(1, "usages disjoined"); 115 } 116 117 gss_release_name(&min_stat, &name2); 118 gss_release_oid_set(&min_stat, &mechs2); 119 120 maj_stat = gss_inquire_cred(&min_stat, cred2, &name2, &lifetime2, 121 &usage2, &mechs2); 122 if (maj_stat != GSS_S_COMPLETE) 123 errx(1, "gss_inquire_cred"); 124 125 maj_stat = gss_compare_name(&min_stat, name1, name2, &equal); 126 if (maj_stat != GSS_S_COMPLETE) 127 errx(1, "gss_compare_name"); 128 if (!equal) 129 errx(1, "names not equal"); 130 131 if (lifetime1 != lifetime2) 132 errx(1, "lifetime not equal %lu != %lu", 133 (unsigned long)lifetime1, (unsigned long)lifetime2); 134 135 gss_release_cred(&min_stat, &cred1); 136 gss_release_cred(&min_stat, &cred2); 137 138 gss_release_name(&min_stat, &name1); 139 gss_release_name(&min_stat, &name2); 140 141 #if 0 142 compare(mechs1, mechs2); 143 #endif 144 145 gss_release_oid_set(&min_stat, &mechs1); 146 gss_release_oid_set(&min_stat, &mechs2); 147 148 krb5_cc_destroy(context, id); 149 krb5_free_context(context); 150 } 151 152 static struct getargs args[] = { 153 {"version", 0, arg_flag, &version_flag, "print version", NULL }, 154 {"help", 0, arg_flag, &help_flag, NULL, NULL } 155 }; 156 157 static void 158 usage (int ret) 159 { 160 arg_printusage (args, sizeof(args)/sizeof(*args), 161 NULL, ""); 162 exit (ret); 163 } 164 165 int 166 main(int argc, char **argv) 167 { 168 int optidx = 0; 169 170 setprogname(argv[0]); 171 if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx)) 172 usage(1); 173 174 if (help_flag) 175 usage (0); 176 177 if(version_flag){ 178 print_version(NULL); 179 exit(0); 180 } 181 182 argc -= optidx; 183 argv += optidx; 184 185 copy_import(); 186 187 return 0; 188 } 189