1 /* $NetBSD: keys.c,v 1.2 2017/01/28 21:31:49 christos Exp $ */
2
3 /*
4 * Copyright (c) 1997 - 2000 Kungliga Tekniska Högskolan
5 * (Royal Institute of Technology, Stockholm, Sweden).
6 * All rights reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
10 * are met:
11 *
12 * 1. Redistributions of source code must retain the above copyright
13 * notice, this list of conditions and the following disclaimer.
14 *
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 *
19 * 3. Neither the name of the Institute nor the names of its contributors
20 * may be used to endorse or promote products derived from this software
21 * without specific prior written permission.
22 *
23 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * SUCH DAMAGE.
34 */
35
36 #include "kadm5_locl.h"
37
38 __RCSID("$NetBSD: keys.c,v 1.2 2017/01/28 21:31:49 christos Exp $");
39
40 /*
41 * free all the memory used by (len, keys)
42 */
43
44 void
_kadm5_free_keys(krb5_context context,int len,Key * keys)45 _kadm5_free_keys (krb5_context context,
46 int len, Key *keys)
47 {
48 hdb_free_keys(context, len, keys);
49 }
50
51 /*
52 * null-ify `len', `keys'
53 */
54
55 void
_kadm5_init_keys(Key * keys,int len)56 _kadm5_init_keys (Key *keys, int len)
57 {
58 int i;
59
60 for (i = 0; i < len; ++i) {
61 keys[i].mkvno = NULL;
62 keys[i].salt = NULL;
63 keys[i].key.keyvalue.length = 0;
64 keys[i].key.keyvalue.data = NULL;
65 }
66 }
67
68
69 /*
70 * return 1 if any key in `keys1, len1' exists in `keys2, len2'
71 */
72 static int
_kadm5_exists_keys(Key * keys1,int len1,Key * keys2,int len2)73 _kadm5_exists_keys(Key *keys1, int len1, Key *keys2, int len2)
74 {
75 size_t i, j;
76 size_t optimize;
77
78 for (i = 0; i < len1; ++i) {
79 optimize = 0;
80 for (j = 0; j < len2; j++) {
81 if ((keys1[i].salt != NULL && keys2[j].salt == NULL)
82 || (keys1[i].salt == NULL && keys2[j].salt != NULL))
83 continue;
84
85 if (keys1[i].salt != NULL) {
86 if (keys1[i].salt->type != keys2[j].salt->type)
87 continue;
88 if (keys1[i].salt->salt.length != keys2[j].salt->salt.length)
89 continue;
90 if (memcmp (keys1[i].salt->salt.data, keys2[j].salt->salt.data,
91 keys1[i].salt->salt.length) != 0)
92 continue;
93 }
94 if (keys1[i].key.keytype != keys2[j].key.keytype)
95 continue;
96 optimize = 1;
97 if (keys1[i].key.keyvalue.length != keys2[j].key.keyvalue.length)
98 continue;
99 if (memcmp (keys1[i].key.keyvalue.data, keys2[j].key.keyvalue.data,
100 keys1[i].key.keyvalue.length) != 0)
101 continue;
102
103 return 1;
104 }
105
106 /*
107 * Optimization: no need to check all of keys1[] if one there
108 * was one key in keys2[] with matching enctype and salt but not
109 * matching key. Assumption: all keys in keys1[] and keys2[]
110 * are output by string2key.
111 */
112 if (optimize)
113 return 0;
114 }
115 return 0;
116 }
117
118 /*
119 * return 1 if any key in `keys1, len1' exists in hist_keys
120 */
121 int
_kadm5_exists_keys_hist(Key * keys1,int len1,HDB_Ext_KeySet * hist_keys)122 _kadm5_exists_keys_hist(Key *keys1, int len1, HDB_Ext_KeySet *hist_keys)
123 {
124 size_t i;
125
126 for (i = 0; i < hist_keys->len; i++) {
127 if (_kadm5_exists_keys(keys1, len1,
128 hist_keys->val[i].keys.val,
129 hist_keys->val[i].keys.len))
130 return 1;
131 }
132
133 return 0;
134 }
135