xref: /netbsd-src/crypto/external/bsd/heimdal/dist/lib/kadm5/keys.c (revision d3273b5b76f5afaafe308cead5511dbb8df8c5e9)
1 /*	$NetBSD: keys.c,v 1.2 2017/01/28 21:31:49 christos Exp $	*/
2 
3 /*
4  * Copyright (c) 1997 - 2000 Kungliga Tekniska Högskolan
5  * (Royal Institute of Technology, Stockholm, Sweden).
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions
10  * are met:
11  *
12  * 1. Redistributions of source code must retain the above copyright
13  *    notice, this list of conditions and the following disclaimer.
14  *
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * 3. Neither the name of the Institute nor the names of its contributors
20  *    may be used to endorse or promote products derived from this software
21  *    without specific prior written permission.
22  *
23  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33  * SUCH DAMAGE.
34  */
35 
36 #include "kadm5_locl.h"
37 
38 __RCSID("$NetBSD: keys.c,v 1.2 2017/01/28 21:31:49 christos Exp $");
39 
40 /*
41  * free all the memory used by (len, keys)
42  */
43 
44 void
_kadm5_free_keys(krb5_context context,int len,Key * keys)45 _kadm5_free_keys (krb5_context context,
46 		  int len, Key *keys)
47 {
48     hdb_free_keys(context, len, keys);
49 }
50 
51 /*
52  * null-ify `len', `keys'
53  */
54 
55 void
_kadm5_init_keys(Key * keys,int len)56 _kadm5_init_keys (Key *keys, int len)
57 {
58     int i;
59 
60     for (i = 0; i < len; ++i) {
61 	keys[i].mkvno               = NULL;
62 	keys[i].salt                = NULL;
63 	keys[i].key.keyvalue.length = 0;
64 	keys[i].key.keyvalue.data   = NULL;
65     }
66 }
67 
68 
69 /*
70  * return 1 if any key in `keys1, len1' exists in `keys2, len2'
71  */
72 static int
_kadm5_exists_keys(Key * keys1,int len1,Key * keys2,int len2)73 _kadm5_exists_keys(Key *keys1, int len1, Key *keys2, int len2)
74 {
75     size_t i, j;
76     size_t optimize;
77 
78     for (i = 0; i < len1; ++i) {
79 	optimize = 0;
80 	for (j = 0; j < len2; j++) {
81 	    if ((keys1[i].salt != NULL && keys2[j].salt == NULL)
82 		|| (keys1[i].salt == NULL && keys2[j].salt != NULL))
83 		continue;
84 
85 	    if (keys1[i].salt != NULL) {
86 		if (keys1[i].salt->type != keys2[j].salt->type)
87 		    continue;
88 		if (keys1[i].salt->salt.length != keys2[j].salt->salt.length)
89 		    continue;
90 		if (memcmp (keys1[i].salt->salt.data, keys2[j].salt->salt.data,
91 			    keys1[i].salt->salt.length) != 0)
92 		    continue;
93 	    }
94 	    if (keys1[i].key.keytype != keys2[j].key.keytype)
95 		continue;
96 	    optimize = 1;
97 	    if (keys1[i].key.keyvalue.length != keys2[j].key.keyvalue.length)
98 		continue;
99 	    if (memcmp (keys1[i].key.keyvalue.data, keys2[j].key.keyvalue.data,
100 			keys1[i].key.keyvalue.length) != 0)
101 		continue;
102 
103 	    return 1;
104 	}
105 
106 	/*
107 	 * Optimization: no need to check all of keys1[] if one there
108 	 * was one key in keys2[] with matching enctype and salt but not
109 	 * matching key.  Assumption: all keys in keys1[] and keys2[]
110 	 * are output by string2key.
111 	 */
112 	if (optimize)
113 	    return 0;
114     }
115     return 0;
116 }
117 
118 /*
119  * return 1 if any key in `keys1, len1' exists in hist_keys
120  */
121 int
_kadm5_exists_keys_hist(Key * keys1,int len1,HDB_Ext_KeySet * hist_keys)122 _kadm5_exists_keys_hist(Key *keys1, int len1, HDB_Ext_KeySet *hist_keys)
123 {
124     size_t i;
125 
126     for (i = 0; i < hist_keys->len; i++) {
127 	if (_kadm5_exists_keys(keys1, len1,
128 			       hist_keys->val[i].keys.val,
129 			       hist_keys->val[i].keys.len))
130 	    return 1;
131     }
132 
133     return 0;
134 }
135