1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov * Copyright (c) 1997 - 2000 Kungliga Tekniska Högskolan
3b528cefcSMark Murray * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray * All rights reserved.
5b528cefcSMark Murray *
6b528cefcSMark Murray * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray * modification, are permitted provided that the following conditions
8b528cefcSMark Murray * are met:
9b528cefcSMark Murray *
10b528cefcSMark Murray * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray * notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray *
13b528cefcSMark Murray * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray * notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray * documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray *
17b528cefcSMark Murray * 3. Neither the name of the Institute nor the names of its contributors
18b528cefcSMark Murray * may be used to endorse or promote products derived from this software
19b528cefcSMark Murray * without specific prior written permission.
20b528cefcSMark Murray *
21b528cefcSMark Murray * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22b528cefcSMark Murray * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24b528cefcSMark Murray * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25b528cefcSMark Murray * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26b528cefcSMark Murray * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27b528cefcSMark Murray * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28b528cefcSMark Murray * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29b528cefcSMark Murray * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30b528cefcSMark Murray * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31b528cefcSMark Murray * SUCH DAMAGE.
32b528cefcSMark Murray */
33b528cefcSMark Murray
34b528cefcSMark Murray #include "test_locl.h"
35*ae771770SStanislav Sedov #include <gssapi/gssapi.h>
36*ae771770SStanislav Sedov #include <gssapi/gssapi_krb5.h>
37*ae771770SStanislav Sedov #include <gssapi/gssapi_spnego.h>
38b528cefcSMark Murray #include "gss_common.h"
39*ae771770SStanislav Sedov RCSID("$Id$");
40283d988cSMark Murray
41283d988cSMark Murray static int
do_trans(int sock,gss_ctx_id_t context_hdl)42283d988cSMark Murray do_trans (int sock, gss_ctx_id_t context_hdl)
43283d988cSMark Murray {
44283d988cSMark Murray OM_uint32 maj_stat, min_stat;
45283d988cSMark Murray gss_buffer_desc real_input_token, real_output_token;
46283d988cSMark Murray gss_buffer_t input_token = &real_input_token,
47283d988cSMark Murray output_token = &real_output_token;
48283d988cSMark Murray
49283d988cSMark Murray /* get_mic */
50283d988cSMark Murray
51283d988cSMark Murray input_token->length = 3;
52283d988cSMark Murray input_token->value = strdup("hej");
53283d988cSMark Murray
54283d988cSMark Murray maj_stat = gss_get_mic(&min_stat,
55283d988cSMark Murray context_hdl,
56283d988cSMark Murray GSS_C_QOP_DEFAULT,
57283d988cSMark Murray input_token,
58283d988cSMark Murray output_token);
59283d988cSMark Murray if (GSS_ERROR(maj_stat))
60283d988cSMark Murray gss_err (1, min_stat, "gss_get_mic");
61283d988cSMark Murray
62283d988cSMark Murray write_token (sock, input_token);
63283d988cSMark Murray write_token (sock, output_token);
64283d988cSMark Murray
65283d988cSMark Murray /* wrap */
66283d988cSMark Murray
67283d988cSMark Murray input_token->length = 7;
68283d988cSMark Murray input_token->value = "hemligt";
69283d988cSMark Murray
70c19800e8SDoug Rabson maj_stat = gss_wrap (&min_stat,
71c19800e8SDoug Rabson context_hdl,
72c19800e8SDoug Rabson 0,
73c19800e8SDoug Rabson GSS_C_QOP_DEFAULT,
74c19800e8SDoug Rabson input_token,
75c19800e8SDoug Rabson NULL,
76c19800e8SDoug Rabson output_token);
77c19800e8SDoug Rabson if (GSS_ERROR(maj_stat))
78c19800e8SDoug Rabson gss_err (1, min_stat, "gss_wrap");
79c19800e8SDoug Rabson
80c19800e8SDoug Rabson write_token (sock, output_token);
81283d988cSMark Murray
82283d988cSMark Murray maj_stat = gss_wrap (&min_stat,
83283d988cSMark Murray context_hdl,
84283d988cSMark Murray 1,
85283d988cSMark Murray GSS_C_QOP_DEFAULT,
86283d988cSMark Murray input_token,
87283d988cSMark Murray NULL,
88283d988cSMark Murray output_token);
89283d988cSMark Murray if (GSS_ERROR(maj_stat))
90283d988cSMark Murray gss_err (1, min_stat, "gss_wrap");
91283d988cSMark Murray
92283d988cSMark Murray write_token (sock, output_token);
93283d988cSMark Murray
94283d988cSMark Murray return 0;
95283d988cSMark Murray }
96b528cefcSMark Murray
97*ae771770SStanislav Sedov extern char *password;
98*ae771770SStanislav Sedov
99b528cefcSMark Murray static int
proto(int sock,const char * hostname,const char * service)100b528cefcSMark Murray proto (int sock, const char *hostname, const char *service)
101b528cefcSMark Murray {
102*ae771770SStanislav Sedov struct sockaddr_storage remote, local;
1035e9cd1aeSAssar Westerlund socklen_t addrlen;
104b528cefcSMark Murray
105b528cefcSMark Murray int context_established = 0;
106b528cefcSMark Murray gss_ctx_id_t context_hdl = GSS_C_NO_CONTEXT;
107*ae771770SStanislav Sedov gss_cred_id_t cred = GSS_C_NO_CREDENTIAL;
108b528cefcSMark Murray gss_buffer_desc real_input_token, real_output_token;
109283d988cSMark Murray gss_buffer_t input_token = &real_input_token,
110283d988cSMark Murray output_token = &real_output_token;
111b528cefcSMark Murray OM_uint32 maj_stat, min_stat;
112b528cefcSMark Murray gss_name_t server;
113b528cefcSMark Murray gss_buffer_desc name_token;
1145e9cd1aeSAssar Westerlund u_char init_buf[4];
1155e9cd1aeSAssar Westerlund u_char acct_buf[4];
116c19800e8SDoug Rabson gss_OID mech_oid;
117c19800e8SDoug Rabson char *str;
118b528cefcSMark Murray
119c19800e8SDoug Rabson mech_oid = select_mech(mech);
120c19800e8SDoug Rabson
121c19800e8SDoug Rabson name_token.length = asprintf (&str,
122b528cefcSMark Murray "%s@%s", service, hostname);
123c19800e8SDoug Rabson if (str == NULL)
124c19800e8SDoug Rabson errx(1, "malloc - out of memory");
125c19800e8SDoug Rabson name_token.value = str;
126b528cefcSMark Murray
127b528cefcSMark Murray maj_stat = gss_import_name (&min_stat,
128b528cefcSMark Murray &name_token,
129b528cefcSMark Murray GSS_C_NT_HOSTBASED_SERVICE,
130b528cefcSMark Murray &server);
131b528cefcSMark Murray if (GSS_ERROR(maj_stat))
132b528cefcSMark Murray gss_err (1, min_stat,
133b528cefcSMark Murray "Error importing name `%s@%s':\n", service, hostname);
134b528cefcSMark Murray
135*ae771770SStanislav Sedov if (password) {
136*ae771770SStanislav Sedov gss_buffer_desc pw;
137*ae771770SStanislav Sedov
138*ae771770SStanislav Sedov pw.value = password;
139*ae771770SStanislav Sedov pw.length = strlen(password);
140*ae771770SStanislav Sedov
141*ae771770SStanislav Sedov maj_stat = gss_acquire_cred_with_password(&min_stat,
142*ae771770SStanislav Sedov GSS_C_NO_NAME,
143*ae771770SStanislav Sedov &pw,
144*ae771770SStanislav Sedov GSS_C_INDEFINITE,
145*ae771770SStanislav Sedov GSS_C_NO_OID_SET,
146*ae771770SStanislav Sedov GSS_C_INITIATE,
147*ae771770SStanislav Sedov &cred,
148*ae771770SStanislav Sedov NULL,
149*ae771770SStanislav Sedov NULL);
150*ae771770SStanislav Sedov if (GSS_ERROR(maj_stat))
151*ae771770SStanislav Sedov gss_err (1, min_stat,
152*ae771770SStanislav Sedov "Error acquiring default initiator credentials");
153*ae771770SStanislav Sedov }
154*ae771770SStanislav Sedov
155b528cefcSMark Murray addrlen = sizeof(local);
156b528cefcSMark Murray if (getsockname (sock, (struct sockaddr *)&local, &addrlen) < 0
157*ae771770SStanislav Sedov || addrlen > sizeof(local))
158b528cefcSMark Murray err (1, "getsockname(%s)", hostname);
159b528cefcSMark Murray
160b528cefcSMark Murray addrlen = sizeof(remote);
161b528cefcSMark Murray if (getpeername (sock, (struct sockaddr *)&remote, &addrlen) < 0
162*ae771770SStanislav Sedov || addrlen > sizeof(remote))
163b528cefcSMark Murray err (1, "getpeername(%s)", hostname);
164b528cefcSMark Murray
165b528cefcSMark Murray input_token->length = 0;
166b528cefcSMark Murray output_token->length = 0;
167b528cefcSMark Murray
168*ae771770SStanislav Sedov #if 0
169*ae771770SStanislav Sedov struct gss_channel_bindings_struct input_chan_bindings;
170*ae771770SStanislav Sedov
1715e9cd1aeSAssar Westerlund input_chan_bindings.initiator_addrtype = GSS_C_AF_INET;
1725e9cd1aeSAssar Westerlund input_chan_bindings.initiator_address.length = 4;
1735e9cd1aeSAssar Westerlund init_buf[0] = (local.sin_addr.s_addr >> 24) & 0xFF;
1745e9cd1aeSAssar Westerlund init_buf[1] = (local.sin_addr.s_addr >> 16) & 0xFF;
1755e9cd1aeSAssar Westerlund init_buf[2] = (local.sin_addr.s_addr >> 8) & 0xFF;
1765e9cd1aeSAssar Westerlund init_buf[3] = (local.sin_addr.s_addr >> 0) & 0xFF;
1775e9cd1aeSAssar Westerlund input_chan_bindings.initiator_address.value = init_buf;
1785e9cd1aeSAssar Westerlund
1795e9cd1aeSAssar Westerlund input_chan_bindings.acceptor_addrtype = GSS_C_AF_INET;
1805e9cd1aeSAssar Westerlund input_chan_bindings.acceptor_address.length = 4;
1815e9cd1aeSAssar Westerlund acct_buf[0] = (remote.sin_addr.s_addr >> 24) & 0xFF;
1825e9cd1aeSAssar Westerlund acct_buf[1] = (remote.sin_addr.s_addr >> 16) & 0xFF;
1835e9cd1aeSAssar Westerlund acct_buf[2] = (remote.sin_addr.s_addr >> 8) & 0xFF;
1845e9cd1aeSAssar Westerlund acct_buf[3] = (remote.sin_addr.s_addr >> 0) & 0xFF;
1855e9cd1aeSAssar Westerlund input_chan_bindings.acceptor_address.value = acct_buf;
1865e9cd1aeSAssar Westerlund
1875e9cd1aeSAssar Westerlund input_chan_bindings.application_data.value = emalloc(4);
1885e9cd1aeSAssar Westerlund * (unsigned short*)input_chan_bindings.application_data.value = local.sin_port;
1895e9cd1aeSAssar Westerlund * ((unsigned short *)input_chan_bindings.application_data.value + 1) = remote.sin_port;
1905e9cd1aeSAssar Westerlund input_chan_bindings.application_data.length = 4;
191*ae771770SStanislav Sedov
1925e9cd1aeSAssar Westerlund input_chan_bindings.application_data.length = 0;
1935e9cd1aeSAssar Westerlund input_chan_bindings.application_data.value = NULL;
1945e9cd1aeSAssar Westerlund #endif
1955e9cd1aeSAssar Westerlund
196b528cefcSMark Murray while(!context_established) {
197b528cefcSMark Murray maj_stat =
198b528cefcSMark Murray gss_init_sec_context(&min_stat,
199*ae771770SStanislav Sedov cred,
200b528cefcSMark Murray &context_hdl,
201b528cefcSMark Murray server,
202c19800e8SDoug Rabson mech_oid,
203*ae771770SStanislav Sedov GSS_C_MUTUAL_FLAG | GSS_C_SEQUENCE_FLAG,
204b528cefcSMark Murray 0,
205*ae771770SStanislav Sedov NULL,
206b528cefcSMark Murray input_token,
207b528cefcSMark Murray NULL,
208b528cefcSMark Murray output_token,
209b528cefcSMark Murray NULL,
210b528cefcSMark Murray NULL);
211b528cefcSMark Murray if (GSS_ERROR(maj_stat))
212b528cefcSMark Murray gss_err (1, min_stat, "gss_init_sec_context");
213b528cefcSMark Murray if (output_token->length != 0)
214b528cefcSMark Murray write_token (sock, output_token);
215b528cefcSMark Murray if (GSS_ERROR(maj_stat)) {
216b528cefcSMark Murray if (context_hdl != GSS_C_NO_CONTEXT)
217b528cefcSMark Murray gss_delete_sec_context (&min_stat,
218b528cefcSMark Murray &context_hdl,
219b528cefcSMark Murray GSS_C_NO_BUFFER);
220b528cefcSMark Murray break;
221b528cefcSMark Murray }
222b528cefcSMark Murray if (maj_stat & GSS_S_CONTINUE_NEEDED) {
223b528cefcSMark Murray read_token (sock, input_token);
224b528cefcSMark Murray } else {
225b528cefcSMark Murray context_established = 1;
226b528cefcSMark Murray }
227b528cefcSMark Murray
228b528cefcSMark Murray }
229283d988cSMark Murray if (fork_flag) {
230283d988cSMark Murray pid_t pid;
231283d988cSMark Murray int pipefd[2];
232b528cefcSMark Murray
233283d988cSMark Murray if (pipe (pipefd) < 0)
234283d988cSMark Murray err (1, "pipe");
235b528cefcSMark Murray
236283d988cSMark Murray pid = fork ();
237283d988cSMark Murray if (pid < 0)
238283d988cSMark Murray err (1, "fork");
239283d988cSMark Murray if (pid != 0) {
240283d988cSMark Murray gss_buffer_desc buf;
241b528cefcSMark Murray
242283d988cSMark Murray maj_stat = gss_export_sec_context (&min_stat,
243283d988cSMark Murray &context_hdl,
244283d988cSMark Murray &buf);
245b528cefcSMark Murray if (GSS_ERROR(maj_stat))
246283d988cSMark Murray gss_err (1, min_stat, "gss_export_sec_context");
247283d988cSMark Murray write_token (pipefd[1], &buf);
248283d988cSMark Murray exit (0);
249283d988cSMark Murray } else {
250283d988cSMark Murray gss_ctx_id_t context_hdl;
251283d988cSMark Murray gss_buffer_desc buf;
252b528cefcSMark Murray
253283d988cSMark Murray close (pipefd[1]);
254283d988cSMark Murray read_token (pipefd[0], &buf);
255283d988cSMark Murray close (pipefd[0]);
256283d988cSMark Murray maj_stat = gss_import_sec_context (&min_stat, &buf, &context_hdl);
257b528cefcSMark Murray if (GSS_ERROR(maj_stat))
258283d988cSMark Murray gss_err (1, min_stat, "gss_import_sec_context");
259283d988cSMark Murray gss_release_buffer (&min_stat, &buf);
260283d988cSMark Murray return do_trans (sock, context_hdl);
261283d988cSMark Murray }
262283d988cSMark Murray } else {
263283d988cSMark Murray return do_trans (sock, context_hdl);
264283d988cSMark Murray }
265b528cefcSMark Murray }
266b528cefcSMark Murray
267b528cefcSMark Murray int
main(int argc,char ** argv)268b528cefcSMark Murray main(int argc, char **argv)
269b528cefcSMark Murray {
270b528cefcSMark Murray krb5_context context; /* XXX */
271b528cefcSMark Murray int port = client_setup(&context, &argc, argv);
272b528cefcSMark Murray return client_doit (argv[argc], port, service, proto);
273b528cefcSMark Murray }
274