1*0Sstevel@tonic-gate /* 2*0Sstevel@tonic-gate * CDDL HEADER START 3*0Sstevel@tonic-gate * 4*0Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5*0Sstevel@tonic-gate * Common Development and Distribution License, Version 1.0 only 6*0Sstevel@tonic-gate * (the "License"). You may not use this file except in compliance 7*0Sstevel@tonic-gate * with the License. 8*0Sstevel@tonic-gate * 9*0Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 10*0Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 11*0Sstevel@tonic-gate * See the License for the specific language governing permissions 12*0Sstevel@tonic-gate * and limitations under the License. 13*0Sstevel@tonic-gate * 14*0Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 15*0Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 16*0Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 17*0Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 18*0Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 19*0Sstevel@tonic-gate * 20*0Sstevel@tonic-gate * CDDL HEADER END 21*0Sstevel@tonic-gate */ 22*0Sstevel@tonic-gate /* 23*0Sstevel@tonic-gate * Copyright 1999-2003 Sun Microsystems, Inc. All rights reserved. 24*0Sstevel@tonic-gate * Use is subject to license terms. 25*0Sstevel@tonic-gate */ 26*0Sstevel@tonic-gate 27*0Sstevel@tonic-gate /* Copyright (c) 1984, 1986, 1987, 1988, 1989 AT&T */ 28*0Sstevel@tonic-gate /* All Rights Reserved */ 29*0Sstevel@tonic-gate 30*0Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 31*0Sstevel@tonic-gate 32*0Sstevel@tonic-gate #include <stdlib.h> 33*0Sstevel@tonic-gate #include <string.h> 34*0Sstevel@tonic-gate #include <libintl.h> 35*0Sstevel@tonic-gate #include <locale.h> 36*0Sstevel@tonic-gate #include <errno.h> 37*0Sstevel@tonic-gate #include <unistd.h> 38*0Sstevel@tonic-gate #include <ctype.h> 39*0Sstevel@tonic-gate #include <syslog.h> 40*0Sstevel@tonic-gate #include <sys/time.h> 41*0Sstevel@tonic-gate #include "ns_sldap.h" 42*0Sstevel@tonic-gate #include "ns_internal.h" 43*0Sstevel@tonic-gate /* EXPORT DELETE START */ 44*0Sstevel@tonic-gate #include <crypt.h> 45*0Sstevel@tonic-gate 46*0Sstevel@tonic-gate #define NS_DOMESTIC 1 47*0Sstevel@tonic-gate 48*0Sstevel@tonic-gate static char t1[ROTORSIZE]; 49*0Sstevel@tonic-gate static char t2[ROTORSIZE]; 50*0Sstevel@tonic-gate static char t3[ROTORSIZE]; 51*0Sstevel@tonic-gate static char hexdig[] = "0123456789abcdef"; 52*0Sstevel@tonic-gate 53*0Sstevel@tonic-gate static mutex_t ns_crypt_lock = DEFAULTMUTEX; 54*0Sstevel@tonic-gate static boolean_t crypt_inited = B_FALSE; 55*0Sstevel@tonic-gate 56*0Sstevel@tonic-gate static int 57*0Sstevel@tonic-gate is_cleartext(const char *pwd) 58*0Sstevel@tonic-gate { 59*0Sstevel@tonic-gate if (0 == strncmp(pwd, CRYPTMARK, strlen(CRYPTMARK))) 60*0Sstevel@tonic-gate return (FALSE); 61*0Sstevel@tonic-gate return (TRUE); 62*0Sstevel@tonic-gate } 63*0Sstevel@tonic-gate 64*0Sstevel@tonic-gate 65*0Sstevel@tonic-gate static char * 66*0Sstevel@tonic-gate hex2ascii(char *aString, int aLen) 67*0Sstevel@tonic-gate { 68*0Sstevel@tonic-gate char *res; 69*0Sstevel@tonic-gate int i = 0; 70*0Sstevel@tonic-gate 71*0Sstevel@tonic-gate if ((res = (char *)calloc(aLen*2 + 1, 1)) == NULL) { 72*0Sstevel@tonic-gate return (NULL); 73*0Sstevel@tonic-gate } 74*0Sstevel@tonic-gate for (;;) { 75*0Sstevel@tonic-gate if (aLen < 1) 76*0Sstevel@tonic-gate break; 77*0Sstevel@tonic-gate res[i] = hexdig[(*aString & 0xf0) >> 4]; 78*0Sstevel@tonic-gate res[i + 1] = hexdig[*aString & 0x0f]; 79*0Sstevel@tonic-gate i += 2; 80*0Sstevel@tonic-gate aLen--; 81*0Sstevel@tonic-gate aString++; 82*0Sstevel@tonic-gate } 83*0Sstevel@tonic-gate return (res); 84*0Sstevel@tonic-gate } 85*0Sstevel@tonic-gate 86*0Sstevel@tonic-gate 87*0Sstevel@tonic-gate static int 88*0Sstevel@tonic-gate unhex(char c) 89*0Sstevel@tonic-gate { 90*0Sstevel@tonic-gate return (c >= '0' && c <= '9' ? c - '0' 91*0Sstevel@tonic-gate : c >= 'A' && c <= 'F' ? c - 'A' + 10 92*0Sstevel@tonic-gate : c - 'a' + 10); 93*0Sstevel@tonic-gate } 94*0Sstevel@tonic-gate 95*0Sstevel@tonic-gate 96*0Sstevel@tonic-gate static char * 97*0Sstevel@tonic-gate ascii2hex(char *anHexaStr, int *aResLen) 98*0Sstevel@tonic-gate { 99*0Sstevel@tonic-gate int theLen = 0; 100*0Sstevel@tonic-gate char *theRes = malloc(strlen(anHexaStr) /2 + 1); 101*0Sstevel@tonic-gate 102*0Sstevel@tonic-gate if (theRes == NULL) 103*0Sstevel@tonic-gate return (NULL); 104*0Sstevel@tonic-gate while (isxdigit(*anHexaStr)) { 105*0Sstevel@tonic-gate theRes[theLen] = unhex(*anHexaStr) << 4; 106*0Sstevel@tonic-gate if (++anHexaStr != '\0') { 107*0Sstevel@tonic-gate theRes[theLen] += unhex(*anHexaStr); 108*0Sstevel@tonic-gate anHexaStr++; 109*0Sstevel@tonic-gate } 110*0Sstevel@tonic-gate theLen++; 111*0Sstevel@tonic-gate } 112*0Sstevel@tonic-gate theRes[theLen] = '\0'; 113*0Sstevel@tonic-gate *aResLen = theLen; 114*0Sstevel@tonic-gate return (theRes); 115*0Sstevel@tonic-gate } 116*0Sstevel@tonic-gate /* EXPORT DELETE END */ 117*0Sstevel@tonic-gate 118*0Sstevel@tonic-gate 119*0Sstevel@tonic-gate static void 120*0Sstevel@tonic-gate c_setup() 121*0Sstevel@tonic-gate { 122*0Sstevel@tonic-gate /* EXPORT DELETE START */ 123*0Sstevel@tonic-gate int ic, i, k, temp; 124*0Sstevel@tonic-gate unsigned random; 125*0Sstevel@tonic-gate char buf[13]; 126*0Sstevel@tonic-gate int seed; 127*0Sstevel@tonic-gate 128*0Sstevel@tonic-gate (void) mutex_lock(&ns_crypt_lock); 129*0Sstevel@tonic-gate if (crypt_inited) { 130*0Sstevel@tonic-gate (void) mutex_unlock(&ns_crypt_lock); 131*0Sstevel@tonic-gate return; 132*0Sstevel@tonic-gate } 133*0Sstevel@tonic-gate (void) strcpy(buf, "Homer J"); 134*0Sstevel@tonic-gate buf[8] = buf[0]; 135*0Sstevel@tonic-gate buf[9] = buf[1]; 136*0Sstevel@tonic-gate (void) strncpy(buf, (char *)crypt(buf, &buf[8]), 13); 137*0Sstevel@tonic-gate seed = 123; 138*0Sstevel@tonic-gate for (i = 0; i < 13; i++) 139*0Sstevel@tonic-gate seed = seed*buf[i] + i; 140*0Sstevel@tonic-gate for (i = 0; i < ROTORSIZE; i++) { 141*0Sstevel@tonic-gate t1[i] = i; 142*0Sstevel@tonic-gate t3[i] = 0; 143*0Sstevel@tonic-gate } 144*0Sstevel@tonic-gate for (i = 0; i < ROTORSIZE; i++) { 145*0Sstevel@tonic-gate seed = 5*seed + buf[i%13]; 146*0Sstevel@tonic-gate random = seed % 65521; 147*0Sstevel@tonic-gate k = ROTORSIZE-1 - i; 148*0Sstevel@tonic-gate ic = (random&MASK)%(k+1); 149*0Sstevel@tonic-gate random >>= 8; 150*0Sstevel@tonic-gate temp = t1[k]; 151*0Sstevel@tonic-gate t1[k] = t1[ic]; 152*0Sstevel@tonic-gate t1[ic] = temp; 153*0Sstevel@tonic-gate if (t3[k] != 0) continue; 154*0Sstevel@tonic-gate ic = (random&MASK) % k; 155*0Sstevel@tonic-gate while (t3[ic] != 0) ic = (ic + 1) % k; 156*0Sstevel@tonic-gate t3[k] = ic; 157*0Sstevel@tonic-gate t3[ic] = k; 158*0Sstevel@tonic-gate } 159*0Sstevel@tonic-gate for (i = 0; i < ROTORSIZE; i++) 160*0Sstevel@tonic-gate t2[t1[i]&MASK] = i; 161*0Sstevel@tonic-gate crypt_inited = B_TRUE; 162*0Sstevel@tonic-gate (void) mutex_unlock(&ns_crypt_lock); 163*0Sstevel@tonic-gate } 164*0Sstevel@tonic-gate 165*0Sstevel@tonic-gate 166*0Sstevel@tonic-gate static char * 167*0Sstevel@tonic-gate modvalue(char *str, int len, int *mod_len) 168*0Sstevel@tonic-gate { 169*0Sstevel@tonic-gate int i, n1, n2; 170*0Sstevel@tonic-gate char *s; 171*0Sstevel@tonic-gate 172*0Sstevel@tonic-gate if (!crypt_inited) 173*0Sstevel@tonic-gate c_setup(); 174*0Sstevel@tonic-gate i = 0; 175*0Sstevel@tonic-gate n1 = 0; 176*0Sstevel@tonic-gate n2 = 0; 177*0Sstevel@tonic-gate if ((s = (char *)malloc(2 * len + 1)) != NULL) { 178*0Sstevel@tonic-gate while (i < len) { 179*0Sstevel@tonic-gate s[i] = t2[(t3[(t1[(str[i]+n1)&MASK]+n2)&MASK]-n2)&MASK]-n1; 180*0Sstevel@tonic-gate i++; 181*0Sstevel@tonic-gate n1++; 182*0Sstevel@tonic-gate if (n1 == ROTORSIZE) { 183*0Sstevel@tonic-gate n1 = 0; 184*0Sstevel@tonic-gate n2++; 185*0Sstevel@tonic-gate if (n2 == ROTORSIZE) n2 = 0; 186*0Sstevel@tonic-gate } 187*0Sstevel@tonic-gate } 188*0Sstevel@tonic-gate s[i] = '\0'; 189*0Sstevel@tonic-gate if (mod_len != NULL) 190*0Sstevel@tonic-gate *mod_len = i; 191*0Sstevel@tonic-gate } 192*0Sstevel@tonic-gate return (s); 193*0Sstevel@tonic-gate /* EXPORT DELETE END */ 194*0Sstevel@tonic-gate } 195*0Sstevel@tonic-gate 196*0Sstevel@tonic-gate 197*0Sstevel@tonic-gate char * 198*0Sstevel@tonic-gate evalue(char *ptr) 199*0Sstevel@tonic-gate { 200*0Sstevel@tonic-gate /* EXPORT DELETE START */ 201*0Sstevel@tonic-gate char *modv, *str, *ev; 202*0Sstevel@tonic-gate int modv_len; 203*0Sstevel@tonic-gate size_t len; 204*0Sstevel@tonic-gate 205*0Sstevel@tonic-gate /* 206*0Sstevel@tonic-gate * if not cleartext, return a copy of what ptr 207*0Sstevel@tonic-gate * points to as that is what evalue does below. 208*0Sstevel@tonic-gate */ 209*0Sstevel@tonic-gate if (FALSE == is_cleartext(ptr)) { 210*0Sstevel@tonic-gate str = strdup(ptr); 211*0Sstevel@tonic-gate return (str); 212*0Sstevel@tonic-gate } 213*0Sstevel@tonic-gate 214*0Sstevel@tonic-gate modv = modvalue(ptr, strlen(ptr), &modv_len); 215*0Sstevel@tonic-gate str = hex2ascii(modv, modv_len); 216*0Sstevel@tonic-gate free(modv); 217*0Sstevel@tonic-gate modv = NULL; 218*0Sstevel@tonic-gate len = strlen(str) + strlen(CRYPTMARK) + 1; 219*0Sstevel@tonic-gate ev = malloc(len); 220*0Sstevel@tonic-gate if (ev == NULL) { 221*0Sstevel@tonic-gate free(str); 222*0Sstevel@tonic-gate return (NULL); 223*0Sstevel@tonic-gate } 224*0Sstevel@tonic-gate (void) snprintf(ev, len, CRYPTMARK "%s", str); 225*0Sstevel@tonic-gate free(str); 226*0Sstevel@tonic-gate str = NULL; 227*0Sstevel@tonic-gate return (ev); 228*0Sstevel@tonic-gate #ifndef NS_DOMESTIC 229*0Sstevel@tonic-gate /* EXPORT DELETE END */ 230*0Sstevel@tonic-gate return (strdup(ptr)); 231*0Sstevel@tonic-gate /* EXPORT DELETE START */ 232*0Sstevel@tonic-gate #endif 233*0Sstevel@tonic-gate /* EXPORT DELETE END */ 234*0Sstevel@tonic-gate } 235*0Sstevel@tonic-gate 236*0Sstevel@tonic-gate 237*0Sstevel@tonic-gate char * 238*0Sstevel@tonic-gate dvalue(char *ptr) 239*0Sstevel@tonic-gate { 240*0Sstevel@tonic-gate /* EXPORT DELETE START */ 241*0Sstevel@tonic-gate char *modv, *str, *sb; 242*0Sstevel@tonic-gate int len; 243*0Sstevel@tonic-gate 244*0Sstevel@tonic-gate /* if cleartext return NULL (error!) */ 245*0Sstevel@tonic-gate if (TRUE == is_cleartext(ptr)) 246*0Sstevel@tonic-gate return (NULL); 247*0Sstevel@tonic-gate 248*0Sstevel@tonic-gate sb = strchr(ptr, '}'); 249*0Sstevel@tonic-gate sb++; 250*0Sstevel@tonic-gate len = strlen(sb); 251*0Sstevel@tonic-gate str = ascii2hex(sb, &len); 252*0Sstevel@tonic-gate modv = modvalue(str, len, NULL); 253*0Sstevel@tonic-gate free(str); 254*0Sstevel@tonic-gate str = NULL; 255*0Sstevel@tonic-gate return (modv); 256*0Sstevel@tonic-gate #ifndef NS_DOMESTIC 257*0Sstevel@tonic-gate /* EXPORT DELETE END */ 258*0Sstevel@tonic-gate return (strdup(ptr)); 259*0Sstevel@tonic-gate /* EXPORT DELETE START */ 260*0Sstevel@tonic-gate #endif 261*0Sstevel@tonic-gate /* EXPORT DELETE END */ 262*0Sstevel@tonic-gate } 263