1*ae771770SStanislav Sedov /*
2*ae771770SStanislav Sedov * Copyright (c) 2006 Kungliga Tekniska Högskolan
3*ae771770SStanislav Sedov * (Royal Institute of Technology, Stockholm, Sweden).
4*ae771770SStanislav Sedov * All rights reserved.
5*ae771770SStanislav Sedov *
6*ae771770SStanislav Sedov * Portions Copyright (c) 2009 - 2010 Apple Inc. All rights reserved.
7*ae771770SStanislav Sedov *
8*ae771770SStanislav Sedov * Redistribution and use in source and binary forms, with or without
9*ae771770SStanislav Sedov * modification, are permitted provided that the following conditions
10*ae771770SStanislav Sedov * are met:
11*ae771770SStanislav Sedov *
12*ae771770SStanislav Sedov * 1. Redistributions of source code must retain the above copyright
13*ae771770SStanislav Sedov * notice, this list of conditions and the following disclaimer.
14*ae771770SStanislav Sedov *
15*ae771770SStanislav Sedov * 2. Redistributions in binary form must reproduce the above copyright
16*ae771770SStanislav Sedov * notice, this list of conditions and the following disclaimer in the
17*ae771770SStanislav Sedov * documentation and/or other materials provided with the distribution.
18*ae771770SStanislav Sedov *
19*ae771770SStanislav Sedov * 3. Neither the name of KTH nor the names of its contributors may be
20*ae771770SStanislav Sedov * used to endorse or promote products derived from this software without
21*ae771770SStanislav Sedov * specific prior written permission.
22*ae771770SStanislav Sedov *
23*ae771770SStanislav Sedov * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
24*ae771770SStanislav Sedov * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*ae771770SStanislav Sedov * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
26*ae771770SStanislav Sedov * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
27*ae771770SStanislav Sedov * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
28*ae771770SStanislav Sedov * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
29*ae771770SStanislav Sedov * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
30*ae771770SStanislav Sedov * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
31*ae771770SStanislav Sedov * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
32*ae771770SStanislav Sedov * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
33*ae771770SStanislav Sedov * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34*ae771770SStanislav Sedov */
35*ae771770SStanislav Sedov
36*ae771770SStanislav Sedov #include <config.h>
37*ae771770SStanislav Sedov #include <roken.h>
38*ae771770SStanislav Sedov
39*ae771770SStanislav Sedov #include <stdio.h>
40*ae771770SStanislav Sedov #include <gssapi.h>
41*ae771770SStanislav Sedov #include <gssapi_krb5.h>
42*ae771770SStanislav Sedov #include <gssapi_spnego.h>
43*ae771770SStanislav Sedov #include <gssapi_ntlm.h>
44*ae771770SStanislav Sedov #include <err.h>
45*ae771770SStanislav Sedov #include <getarg.h>
46*ae771770SStanislav Sedov #include <rtbl.h>
47*ae771770SStanislav Sedov #include <gss-commands.h>
48*ae771770SStanislav Sedov
49*ae771770SStanislav Sedov
50*ae771770SStanislav Sedov static int version_flag = 0;
51*ae771770SStanislav Sedov static int help_flag = 0;
52*ae771770SStanislav Sedov
53*ae771770SStanislav Sedov static struct getargs args[] = {
54*ae771770SStanislav Sedov {"version", 0, arg_flag, &version_flag, "print version", NULL },
55*ae771770SStanislav Sedov {"help", 0, arg_flag, &help_flag, NULL, NULL }
56*ae771770SStanislav Sedov };
57*ae771770SStanislav Sedov
58*ae771770SStanislav Sedov static void
usage(int ret)59*ae771770SStanislav Sedov usage (int ret)
60*ae771770SStanislav Sedov {
61*ae771770SStanislav Sedov arg_printusage (args, sizeof(args)/sizeof(*args),
62*ae771770SStanislav Sedov NULL, "service@host");
63*ae771770SStanislav Sedov exit (ret);
64*ae771770SStanislav Sedov }
65*ae771770SStanislav Sedov
66*ae771770SStanislav Sedov #define COL_OID "OID"
67*ae771770SStanislav Sedov #define COL_NAME "Name"
68*ae771770SStanislav Sedov #define COL_DESC "Description"
69*ae771770SStanislav Sedov #define COL_VALUE "Value"
70*ae771770SStanislav Sedov #define COL_MECH "Mech"
71*ae771770SStanislav Sedov #define COL_EXPIRE "Expire"
72*ae771770SStanislav Sedov #define COL_SASL "SASL"
73*ae771770SStanislav Sedov
74*ae771770SStanislav Sedov int
supported_mechanisms(void * argptr,int argc,char ** argv)75*ae771770SStanislav Sedov supported_mechanisms(void *argptr, int argc, char **argv)
76*ae771770SStanislav Sedov {
77*ae771770SStanislav Sedov OM_uint32 maj_stat, min_stat;
78*ae771770SStanislav Sedov gss_OID_set mechs;
79*ae771770SStanislav Sedov rtbl_t ct;
80*ae771770SStanislav Sedov size_t i;
81*ae771770SStanislav Sedov
82*ae771770SStanislav Sedov maj_stat = gss_indicate_mechs(&min_stat, &mechs);
83*ae771770SStanislav Sedov if (maj_stat != GSS_S_COMPLETE)
84*ae771770SStanislav Sedov errx(1, "gss_indicate_mechs failed");
85*ae771770SStanislav Sedov
86*ae771770SStanislav Sedov printf("Supported mechanisms:\n");
87*ae771770SStanislav Sedov
88*ae771770SStanislav Sedov ct = rtbl_create();
89*ae771770SStanislav Sedov if (ct == NULL)
90*ae771770SStanislav Sedov errx(1, "rtbl_create");
91*ae771770SStanislav Sedov
92*ae771770SStanislav Sedov rtbl_set_separator(ct, " ");
93*ae771770SStanislav Sedov rtbl_add_column(ct, COL_OID, 0);
94*ae771770SStanislav Sedov rtbl_add_column(ct, COL_NAME, 0);
95*ae771770SStanislav Sedov rtbl_add_column(ct, COL_DESC, 0);
96*ae771770SStanislav Sedov rtbl_add_column(ct, COL_SASL, 0);
97*ae771770SStanislav Sedov
98*ae771770SStanislav Sedov for (i = 0; i < mechs->count; i++) {
99*ae771770SStanislav Sedov gss_buffer_desc str, sasl_name, mech_name, mech_desc;
100*ae771770SStanislav Sedov
101*ae771770SStanislav Sedov maj_stat = gss_oid_to_str(&min_stat, &mechs->elements[i], &str);
102*ae771770SStanislav Sedov if (maj_stat != GSS_S_COMPLETE)
103*ae771770SStanislav Sedov errx(1, "gss_oid_to_str failed");
104*ae771770SStanislav Sedov
105*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_OID, "%.*s",
106*ae771770SStanislav Sedov (int)str.length, (char *)str.value);
107*ae771770SStanislav Sedov gss_release_buffer(&min_stat, &str);
108*ae771770SStanislav Sedov
109*ae771770SStanislav Sedov (void)gss_inquire_saslname_for_mech(&min_stat,
110*ae771770SStanislav Sedov &mechs->elements[i],
111*ae771770SStanislav Sedov &sasl_name,
112*ae771770SStanislav Sedov &mech_name,
113*ae771770SStanislav Sedov &mech_desc);
114*ae771770SStanislav Sedov
115*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_NAME, "%.*s",
116*ae771770SStanislav Sedov (int)mech_name.length, (char *)mech_name.value);
117*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_DESC, "%.*s",
118*ae771770SStanislav Sedov (int)mech_desc.length, (char *)mech_desc.value);
119*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_SASL, "%.*s",
120*ae771770SStanislav Sedov (int)sasl_name.length, (char *)sasl_name.value);
121*ae771770SStanislav Sedov
122*ae771770SStanislav Sedov gss_release_buffer(&min_stat, &mech_name);
123*ae771770SStanislav Sedov gss_release_buffer(&min_stat, &mech_desc);
124*ae771770SStanislav Sedov gss_release_buffer(&min_stat, &sasl_name);
125*ae771770SStanislav Sedov
126*ae771770SStanislav Sedov }
127*ae771770SStanislav Sedov gss_release_oid_set(&min_stat, &mechs);
128*ae771770SStanislav Sedov
129*ae771770SStanislav Sedov rtbl_format(ct, stdout);
130*ae771770SStanislav Sedov rtbl_destroy(ct);
131*ae771770SStanislav Sedov
132*ae771770SStanislav Sedov return 0;
133*ae771770SStanislav Sedov }
134*ae771770SStanislav Sedov
135*ae771770SStanislav Sedov static void
print_mech_attr(const char * mechname,gss_const_OID mech,gss_OID_set set)136*ae771770SStanislav Sedov print_mech_attr(const char *mechname, gss_const_OID mech, gss_OID_set set)
137*ae771770SStanislav Sedov {
138*ae771770SStanislav Sedov gss_buffer_desc name, desc;
139*ae771770SStanislav Sedov OM_uint32 major, minor;
140*ae771770SStanislav Sedov rtbl_t ct;
141*ae771770SStanislav Sedov size_t n;
142*ae771770SStanislav Sedov
143*ae771770SStanislav Sedov ct = rtbl_create();
144*ae771770SStanislav Sedov if (ct == NULL)
145*ae771770SStanislav Sedov errx(1, "rtbl_create");
146*ae771770SStanislav Sedov
147*ae771770SStanislav Sedov rtbl_set_separator(ct, " ");
148*ae771770SStanislav Sedov rtbl_add_column(ct, COL_OID, 0);
149*ae771770SStanislav Sedov rtbl_add_column(ct, COL_DESC, 0);
150*ae771770SStanislav Sedov if (mech)
151*ae771770SStanislav Sedov rtbl_add_column(ct, COL_VALUE, 0);
152*ae771770SStanislav Sedov
153*ae771770SStanislav Sedov for (n = 0; n < set->count; n++) {
154*ae771770SStanislav Sedov major = gss_display_mech_attr(&minor, &set->elements[n], &name, &desc, NULL);
155*ae771770SStanislav Sedov if (major)
156*ae771770SStanislav Sedov continue;
157*ae771770SStanislav Sedov
158*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_OID, "%.*s",
159*ae771770SStanislav Sedov (int)name.length, (char *)name.value);
160*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_DESC, "%.*s",
161*ae771770SStanislav Sedov (int)desc.length, (char *)desc.value);
162*ae771770SStanislav Sedov if (mech) {
163*ae771770SStanislav Sedov gss_buffer_desc value;
164*ae771770SStanislav Sedov
165*ae771770SStanislav Sedov if (gss_mo_get(mech, &set->elements[n], &value) != 0)
166*ae771770SStanislav Sedov value.length = 0;
167*ae771770SStanislav Sedov
168*ae771770SStanislav Sedov if (value.length)
169*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_VALUE, "%.*s",
170*ae771770SStanislav Sedov (int)value.length, (char *)value.value);
171*ae771770SStanislav Sedov else
172*ae771770SStanislav Sedov rtbl_add_column_entryv(ct, COL_VALUE, "<>");
173*ae771770SStanislav Sedov gss_release_buffer(&minor, &value);
174*ae771770SStanislav Sedov }
175*ae771770SStanislav Sedov
176*ae771770SStanislav Sedov gss_release_buffer(&minor, &name);
177*ae771770SStanislav Sedov gss_release_buffer(&minor, &desc);
178*ae771770SStanislav Sedov }
179*ae771770SStanislav Sedov
180*ae771770SStanislav Sedov printf("attributes for: %s\n", mechname);
181*ae771770SStanislav Sedov rtbl_format(ct, stdout);
182*ae771770SStanislav Sedov rtbl_destroy(ct);
183*ae771770SStanislav Sedov }
184*ae771770SStanislav Sedov
185*ae771770SStanislav Sedov
186*ae771770SStanislav Sedov int
attrs_for_mech(struct attrs_for_mech_options * opt,int argc,char ** argv)187*ae771770SStanislav Sedov attrs_for_mech(struct attrs_for_mech_options *opt, int argc, char **argv)
188*ae771770SStanislav Sedov {
189*ae771770SStanislav Sedov gss_OID_set mech_attr = NULL, known_mech_attrs = NULL;
190*ae771770SStanislav Sedov gss_OID mech = GSS_C_NO_OID;
191*ae771770SStanislav Sedov OM_uint32 major, minor;
192*ae771770SStanislav Sedov
193*ae771770SStanislav Sedov if (opt->mech_string) {
194*ae771770SStanislav Sedov mech = gss_name_to_oid(opt->mech_string);
195*ae771770SStanislav Sedov if (mech == NULL)
196*ae771770SStanislav Sedov errx(1, "mech %s is unknown", opt->mech_string);
197*ae771770SStanislav Sedov }
198*ae771770SStanislav Sedov
199*ae771770SStanislav Sedov major = gss_inquire_attrs_for_mech(&minor, mech, &mech_attr, &known_mech_attrs);
200*ae771770SStanislav Sedov if (major)
201*ae771770SStanislav Sedov errx(1, "gss_inquire_attrs_for_mech");
202*ae771770SStanislav Sedov
203*ae771770SStanislav Sedov if (mech) {
204*ae771770SStanislav Sedov print_mech_attr(opt->mech_string, mech, mech_attr);
205*ae771770SStanislav Sedov }
206*ae771770SStanislav Sedov
207*ae771770SStanislav Sedov if (opt->all_flag) {
208*ae771770SStanislav Sedov print_mech_attr("all mechs", NULL, known_mech_attrs);
209*ae771770SStanislav Sedov }
210*ae771770SStanislav Sedov
211*ae771770SStanislav Sedov gss_release_oid_set(&minor, &mech_attr);
212*ae771770SStanislav Sedov gss_release_oid_set(&minor, &known_mech_attrs);
213*ae771770SStanislav Sedov
214*ae771770SStanislav Sedov return 0;
215*ae771770SStanislav Sedov }
216*ae771770SStanislav Sedov
217*ae771770SStanislav Sedov
218*ae771770SStanislav Sedov /*
219*ae771770SStanislav Sedov *
220*ae771770SStanislav Sedov */
221*ae771770SStanislav Sedov
222*ae771770SStanislav Sedov int
help(void * opt,int argc,char ** argv)223*ae771770SStanislav Sedov help(void *opt, int argc, char **argv)
224*ae771770SStanislav Sedov {
225*ae771770SStanislav Sedov sl_slc_help(commands, argc, argv);
226*ae771770SStanislav Sedov return 0;
227*ae771770SStanislav Sedov }
228*ae771770SStanislav Sedov
229*ae771770SStanislav Sedov int
main(int argc,char ** argv)230*ae771770SStanislav Sedov main(int argc, char **argv)
231*ae771770SStanislav Sedov {
232*ae771770SStanislav Sedov int optidx = 0;
233*ae771770SStanislav Sedov
234*ae771770SStanislav Sedov setprogname(argv[0]);
235*ae771770SStanislav Sedov if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx))
236*ae771770SStanislav Sedov usage(1);
237*ae771770SStanislav Sedov
238*ae771770SStanislav Sedov if (help_flag)
239*ae771770SStanislav Sedov usage (0);
240*ae771770SStanislav Sedov
241*ae771770SStanislav Sedov if(version_flag){
242*ae771770SStanislav Sedov print_version(NULL);
243*ae771770SStanislav Sedov exit(0);
244*ae771770SStanislav Sedov }
245*ae771770SStanislav Sedov
246*ae771770SStanislav Sedov argc -= optidx;
247*ae771770SStanislav Sedov argv += optidx;
248*ae771770SStanislav Sedov
249*ae771770SStanislav Sedov if (argc == 0) {
250*ae771770SStanislav Sedov help(NULL, argc, argv);
251*ae771770SStanislav Sedov return 1;
252*ae771770SStanislav Sedov }
253*ae771770SStanislav Sedov
254*ae771770SStanislav Sedov return sl_command (commands, argc, argv);
255*ae771770SStanislav Sedov }
256