xref: /freebsd-src/crypto/heimdal/appl/test/gssapi_client.c (revision 6a068746777241722b2b32c5d0bc443a2a64d80b)
1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov  * Copyright (c) 1997 - 2000 Kungliga Tekniska Högskolan
3b528cefcSMark Murray  * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray  * All rights reserved.
5b528cefcSMark Murray  *
6b528cefcSMark Murray  * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray  * modification, are permitted provided that the following conditions
8b528cefcSMark Murray  * are met:
9b528cefcSMark Murray  *
10b528cefcSMark Murray  * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray  *
13b528cefcSMark Murray  * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray  *    documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray  *
17b528cefcSMark Murray  * 3. Neither the name of the Institute nor the names of its contributors
18b528cefcSMark Murray  *    may be used to endorse or promote products derived from this software
19b528cefcSMark Murray  *    without specific prior written permission.
20b528cefcSMark Murray  *
21b528cefcSMark Murray  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22b528cefcSMark Murray  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24b528cefcSMark Murray  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25b528cefcSMark Murray  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26b528cefcSMark Murray  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27b528cefcSMark Murray  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28b528cefcSMark Murray  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29b528cefcSMark Murray  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30b528cefcSMark Murray  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31b528cefcSMark Murray  * SUCH DAMAGE.
32b528cefcSMark Murray  */
33b528cefcSMark Murray 
34b528cefcSMark Murray #include "test_locl.h"
35*ae771770SStanislav Sedov #include <gssapi/gssapi.h>
36*ae771770SStanislav Sedov #include <gssapi/gssapi_krb5.h>
37*ae771770SStanislav Sedov #include <gssapi/gssapi_spnego.h>
38b528cefcSMark Murray #include "gss_common.h"
39*ae771770SStanislav Sedov RCSID("$Id$");
40283d988cSMark Murray 
41283d988cSMark Murray static int
do_trans(int sock,gss_ctx_id_t context_hdl)42283d988cSMark Murray do_trans (int sock, gss_ctx_id_t context_hdl)
43283d988cSMark Murray {
44283d988cSMark Murray     OM_uint32 maj_stat, min_stat;
45283d988cSMark Murray     gss_buffer_desc real_input_token, real_output_token;
46283d988cSMark Murray     gss_buffer_t input_token = &real_input_token,
47283d988cSMark Murray 	output_token = &real_output_token;
48283d988cSMark Murray 
49283d988cSMark Murray     /* get_mic */
50283d988cSMark Murray 
51283d988cSMark Murray     input_token->length = 3;
52283d988cSMark Murray     input_token->value  = strdup("hej");
53283d988cSMark Murray 
54283d988cSMark Murray     maj_stat = gss_get_mic(&min_stat,
55283d988cSMark Murray 			   context_hdl,
56283d988cSMark Murray 			   GSS_C_QOP_DEFAULT,
57283d988cSMark Murray 			   input_token,
58283d988cSMark Murray 			   output_token);
59283d988cSMark Murray     if (GSS_ERROR(maj_stat))
60283d988cSMark Murray 	gss_err (1, min_stat, "gss_get_mic");
61283d988cSMark Murray 
62283d988cSMark Murray     write_token (sock, input_token);
63283d988cSMark Murray     write_token (sock, output_token);
64283d988cSMark Murray 
65283d988cSMark Murray     /* wrap */
66283d988cSMark Murray 
67283d988cSMark Murray     input_token->length = 7;
68283d988cSMark Murray     input_token->value  = "hemligt";
69283d988cSMark Murray 
70c19800e8SDoug Rabson     maj_stat = gss_wrap (&min_stat,
71c19800e8SDoug Rabson 			 context_hdl,
72c19800e8SDoug Rabson 			 0,
73c19800e8SDoug Rabson 			 GSS_C_QOP_DEFAULT,
74c19800e8SDoug Rabson 			 input_token,
75c19800e8SDoug Rabson 			 NULL,
76c19800e8SDoug Rabson 			 output_token);
77c19800e8SDoug Rabson     if (GSS_ERROR(maj_stat))
78c19800e8SDoug Rabson 	gss_err (1, min_stat, "gss_wrap");
79c19800e8SDoug Rabson 
80c19800e8SDoug Rabson     write_token (sock, output_token);
81283d988cSMark Murray 
82283d988cSMark Murray     maj_stat = gss_wrap (&min_stat,
83283d988cSMark Murray 			 context_hdl,
84283d988cSMark Murray 			 1,
85283d988cSMark Murray 			 GSS_C_QOP_DEFAULT,
86283d988cSMark Murray 			 input_token,
87283d988cSMark Murray 			 NULL,
88283d988cSMark Murray 			 output_token);
89283d988cSMark Murray     if (GSS_ERROR(maj_stat))
90283d988cSMark Murray 	gss_err (1, min_stat, "gss_wrap");
91283d988cSMark Murray 
92283d988cSMark Murray     write_token (sock, output_token);
93283d988cSMark Murray 
94283d988cSMark Murray     return 0;
95283d988cSMark Murray }
96b528cefcSMark Murray 
97*ae771770SStanislav Sedov extern char *password;
98*ae771770SStanislav Sedov 
99b528cefcSMark Murray static int
proto(int sock,const char * hostname,const char * service)100b528cefcSMark Murray proto (int sock, const char *hostname, const char *service)
101b528cefcSMark Murray {
102*ae771770SStanislav Sedov     struct sockaddr_storage remote, local;
1035e9cd1aeSAssar Westerlund     socklen_t addrlen;
104b528cefcSMark Murray 
105b528cefcSMark Murray     int context_established = 0;
106b528cefcSMark Murray     gss_ctx_id_t context_hdl = GSS_C_NO_CONTEXT;
107*ae771770SStanislav Sedov     gss_cred_id_t cred = GSS_C_NO_CREDENTIAL;
108b528cefcSMark Murray     gss_buffer_desc real_input_token, real_output_token;
109283d988cSMark Murray     gss_buffer_t input_token = &real_input_token,
110283d988cSMark Murray 	output_token = &real_output_token;
111b528cefcSMark Murray     OM_uint32 maj_stat, min_stat;
112b528cefcSMark Murray     gss_name_t server;
113b528cefcSMark Murray     gss_buffer_desc name_token;
1145e9cd1aeSAssar Westerlund     u_char init_buf[4];
1155e9cd1aeSAssar Westerlund     u_char acct_buf[4];
116c19800e8SDoug Rabson     gss_OID mech_oid;
117c19800e8SDoug Rabson     char *str;
118b528cefcSMark Murray 
119c19800e8SDoug Rabson     mech_oid = select_mech(mech);
120c19800e8SDoug Rabson 
121c19800e8SDoug Rabson     name_token.length = asprintf (&str,
122b528cefcSMark Murray 				  "%s@%s", service, hostname);
123c19800e8SDoug Rabson     if (str == NULL)
124c19800e8SDoug Rabson 	errx(1, "malloc - out of memory");
125c19800e8SDoug Rabson     name_token.value = str;
126b528cefcSMark Murray 
127b528cefcSMark Murray     maj_stat = gss_import_name (&min_stat,
128b528cefcSMark Murray 				&name_token,
129b528cefcSMark Murray 				GSS_C_NT_HOSTBASED_SERVICE,
130b528cefcSMark Murray 				&server);
131b528cefcSMark Murray     if (GSS_ERROR(maj_stat))
132b528cefcSMark Murray 	gss_err (1, min_stat,
133b528cefcSMark Murray 		 "Error importing name `%s@%s':\n", service, hostname);
134b528cefcSMark Murray 
135*ae771770SStanislav Sedov     if (password) {
136*ae771770SStanislav Sedov         gss_buffer_desc pw;
137*ae771770SStanislav Sedov 
138*ae771770SStanislav Sedov         pw.value = password;
139*ae771770SStanislav Sedov         pw.length = strlen(password);
140*ae771770SStanislav Sedov 
141*ae771770SStanislav Sedov         maj_stat = gss_acquire_cred_with_password(&min_stat,
142*ae771770SStanislav Sedov 						  GSS_C_NO_NAME,
143*ae771770SStanislav Sedov 						  &pw,
144*ae771770SStanislav Sedov 						  GSS_C_INDEFINITE,
145*ae771770SStanislav Sedov 						  GSS_C_NO_OID_SET,
146*ae771770SStanislav Sedov 						  GSS_C_INITIATE,
147*ae771770SStanislav Sedov 						  &cred,
148*ae771770SStanislav Sedov 						  NULL,
149*ae771770SStanislav Sedov 						  NULL);
150*ae771770SStanislav Sedov         if (GSS_ERROR(maj_stat))
151*ae771770SStanislav Sedov             gss_err (1, min_stat,
152*ae771770SStanislav Sedov                      "Error acquiring default initiator credentials");
153*ae771770SStanislav Sedov     }
154*ae771770SStanislav Sedov 
155b528cefcSMark Murray     addrlen = sizeof(local);
156b528cefcSMark Murray     if (getsockname (sock, (struct sockaddr *)&local, &addrlen) < 0
157*ae771770SStanislav Sedov 	|| addrlen > sizeof(local))
158b528cefcSMark Murray 	err (1, "getsockname(%s)", hostname);
159b528cefcSMark Murray 
160b528cefcSMark Murray     addrlen = sizeof(remote);
161b528cefcSMark Murray     if (getpeername (sock, (struct sockaddr *)&remote, &addrlen) < 0
162*ae771770SStanislav Sedov 	|| addrlen > sizeof(remote))
163b528cefcSMark Murray 	err (1, "getpeername(%s)", hostname);
164b528cefcSMark Murray 
165b528cefcSMark Murray     input_token->length = 0;
166b528cefcSMark Murray     output_token->length = 0;
167b528cefcSMark Murray 
168*ae771770SStanislav Sedov #if 0
169*ae771770SStanislav Sedov     struct gss_channel_bindings_struct input_chan_bindings;
170*ae771770SStanislav Sedov 
1715e9cd1aeSAssar Westerlund     input_chan_bindings.initiator_addrtype = GSS_C_AF_INET;
1725e9cd1aeSAssar Westerlund     input_chan_bindings.initiator_address.length = 4;
1735e9cd1aeSAssar Westerlund     init_buf[0] = (local.sin_addr.s_addr >> 24) & 0xFF;
1745e9cd1aeSAssar Westerlund     init_buf[1] = (local.sin_addr.s_addr >> 16) & 0xFF;
1755e9cd1aeSAssar Westerlund     init_buf[2] = (local.sin_addr.s_addr >>  8) & 0xFF;
1765e9cd1aeSAssar Westerlund     init_buf[3] = (local.sin_addr.s_addr >>  0) & 0xFF;
1775e9cd1aeSAssar Westerlund     input_chan_bindings.initiator_address.value = init_buf;
1785e9cd1aeSAssar Westerlund 
1795e9cd1aeSAssar Westerlund     input_chan_bindings.acceptor_addrtype = GSS_C_AF_INET;
1805e9cd1aeSAssar Westerlund     input_chan_bindings.acceptor_address.length = 4;
1815e9cd1aeSAssar Westerlund     acct_buf[0] = (remote.sin_addr.s_addr >> 24) & 0xFF;
1825e9cd1aeSAssar Westerlund     acct_buf[1] = (remote.sin_addr.s_addr >> 16) & 0xFF;
1835e9cd1aeSAssar Westerlund     acct_buf[2] = (remote.sin_addr.s_addr >>  8) & 0xFF;
1845e9cd1aeSAssar Westerlund     acct_buf[3] = (remote.sin_addr.s_addr >>  0) & 0xFF;
1855e9cd1aeSAssar Westerlund     input_chan_bindings.acceptor_address.value = acct_buf;
1865e9cd1aeSAssar Westerlund 
1875e9cd1aeSAssar Westerlund     input_chan_bindings.application_data.value = emalloc(4);
1885e9cd1aeSAssar Westerlund     * (unsigned short*)input_chan_bindings.application_data.value = local.sin_port;
1895e9cd1aeSAssar Westerlund     * ((unsigned short *)input_chan_bindings.application_data.value + 1) = remote.sin_port;
1905e9cd1aeSAssar Westerlund     input_chan_bindings.application_data.length = 4;
191*ae771770SStanislav Sedov 
1925e9cd1aeSAssar Westerlund     input_chan_bindings.application_data.length = 0;
1935e9cd1aeSAssar Westerlund     input_chan_bindings.application_data.value = NULL;
1945e9cd1aeSAssar Westerlund #endif
1955e9cd1aeSAssar Westerlund 
196b528cefcSMark Murray     while(!context_established) {
197b528cefcSMark Murray 	maj_stat =
198b528cefcSMark Murray 	    gss_init_sec_context(&min_stat,
199*ae771770SStanislav Sedov 				 cred,
200b528cefcSMark Murray 				 &context_hdl,
201b528cefcSMark Murray 				 server,
202c19800e8SDoug Rabson 				 mech_oid,
203*ae771770SStanislav Sedov 				 GSS_C_MUTUAL_FLAG | GSS_C_SEQUENCE_FLAG,
204b528cefcSMark Murray 				 0,
205*ae771770SStanislav Sedov 				 NULL,
206b528cefcSMark Murray 				 input_token,
207b528cefcSMark Murray 				 NULL,
208b528cefcSMark Murray 				 output_token,
209b528cefcSMark Murray 				 NULL,
210b528cefcSMark Murray 				 NULL);
211b528cefcSMark Murray 	if (GSS_ERROR(maj_stat))
212b528cefcSMark Murray 	    gss_err (1, min_stat, "gss_init_sec_context");
213b528cefcSMark Murray 	if (output_token->length != 0)
214b528cefcSMark Murray 	    write_token (sock, output_token);
215b528cefcSMark Murray 	if (GSS_ERROR(maj_stat)) {
216b528cefcSMark Murray 	    if (context_hdl != GSS_C_NO_CONTEXT)
217b528cefcSMark Murray 		gss_delete_sec_context (&min_stat,
218b528cefcSMark Murray 					&context_hdl,
219b528cefcSMark Murray 					GSS_C_NO_BUFFER);
220b528cefcSMark Murray 	    break;
221b528cefcSMark Murray 	}
222b528cefcSMark Murray 	if (maj_stat & GSS_S_CONTINUE_NEEDED) {
223b528cefcSMark Murray 	    read_token (sock, input_token);
224b528cefcSMark Murray 	} else {
225b528cefcSMark Murray 	    context_established = 1;
226b528cefcSMark Murray 	}
227b528cefcSMark Murray 
228b528cefcSMark Murray     }
229283d988cSMark Murray     if (fork_flag) {
230283d988cSMark Murray 	pid_t pid;
231283d988cSMark Murray 	int pipefd[2];
232b528cefcSMark Murray 
233283d988cSMark Murray 	if (pipe (pipefd) < 0)
234283d988cSMark Murray 	    err (1, "pipe");
235b528cefcSMark Murray 
236283d988cSMark Murray 	pid = fork ();
237283d988cSMark Murray 	if (pid < 0)
238283d988cSMark Murray 	    err (1, "fork");
239283d988cSMark Murray 	if (pid != 0) {
240283d988cSMark Murray 	    gss_buffer_desc buf;
241b528cefcSMark Murray 
242283d988cSMark Murray 	    maj_stat = gss_export_sec_context (&min_stat,
243283d988cSMark Murray 					       &context_hdl,
244283d988cSMark Murray 					       &buf);
245b528cefcSMark Murray 	    if (GSS_ERROR(maj_stat))
246283d988cSMark Murray 		gss_err (1, min_stat, "gss_export_sec_context");
247283d988cSMark Murray 	    write_token (pipefd[1], &buf);
248283d988cSMark Murray 	    exit (0);
249283d988cSMark Murray 	} else {
250283d988cSMark Murray 	    gss_ctx_id_t context_hdl;
251283d988cSMark Murray 	    gss_buffer_desc buf;
252b528cefcSMark Murray 
253283d988cSMark Murray 	    close (pipefd[1]);
254283d988cSMark Murray 	    read_token (pipefd[0], &buf);
255283d988cSMark Murray 	    close (pipefd[0]);
256283d988cSMark Murray 	    maj_stat = gss_import_sec_context (&min_stat, &buf, &context_hdl);
257b528cefcSMark Murray 	    if (GSS_ERROR(maj_stat))
258283d988cSMark Murray 		gss_err (1, min_stat, "gss_import_sec_context");
259283d988cSMark Murray 	    gss_release_buffer (&min_stat, &buf);
260283d988cSMark Murray 	    return do_trans (sock, context_hdl);
261283d988cSMark Murray 	}
262283d988cSMark Murray     } else {
263283d988cSMark Murray 	return do_trans (sock, context_hdl);
264283d988cSMark Murray     }
265b528cefcSMark Murray }
266b528cefcSMark Murray 
267b528cefcSMark Murray int
main(int argc,char ** argv)268b528cefcSMark Murray main(int argc, char **argv)
269b528cefcSMark Murray {
270b528cefcSMark Murray     krb5_context context; /* XXX */
271b528cefcSMark Murray     int port = client_setup(&context, &argc, argv);
272b528cefcSMark Murray     return client_doit (argv[argc], port, service, proto);
273b528cefcSMark Murray }
274