xref: /freebsd-src/crypto/heimdal/lib/gssapi/gsstool.c (revision 6a068746777241722b2b32c5d0bc443a2a64d80b)
1*ae771770SStanislav Sedov /*
2*ae771770SStanislav Sedov  * Copyright (c) 2006 Kungliga Tekniska Högskolan
3*ae771770SStanislav Sedov  * (Royal Institute of Technology, Stockholm, Sweden).
4*ae771770SStanislav Sedov  * All rights reserved.
5*ae771770SStanislav Sedov  *
6*ae771770SStanislav Sedov  * Portions Copyright (c) 2009 - 2010 Apple Inc. All rights reserved.
7*ae771770SStanislav Sedov  *
8*ae771770SStanislav Sedov  * Redistribution and use in source and binary forms, with or without
9*ae771770SStanislav Sedov  * modification, are permitted provided that the following conditions
10*ae771770SStanislav Sedov  * are met:
11*ae771770SStanislav Sedov  *
12*ae771770SStanislav Sedov  * 1. Redistributions of source code must retain the above copyright
13*ae771770SStanislav Sedov  *    notice, this list of conditions and the following disclaimer.
14*ae771770SStanislav Sedov  *
15*ae771770SStanislav Sedov  * 2. Redistributions in binary form must reproduce the above copyright
16*ae771770SStanislav Sedov  *    notice, this list of conditions and the following disclaimer in the
17*ae771770SStanislav Sedov  *    documentation and/or other materials provided with the distribution.
18*ae771770SStanislav Sedov  *
19*ae771770SStanislav Sedov  * 3. Neither the name of KTH nor the names of its contributors may be
20*ae771770SStanislav Sedov  *    used to endorse or promote products derived from this software without
21*ae771770SStanislav Sedov  *    specific prior written permission.
22*ae771770SStanislav Sedov  *
23*ae771770SStanislav Sedov  * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
24*ae771770SStanislav Sedov  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*ae771770SStanislav Sedov  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
26*ae771770SStanislav Sedov  * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
27*ae771770SStanislav Sedov  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
28*ae771770SStanislav Sedov  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
29*ae771770SStanislav Sedov  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
30*ae771770SStanislav Sedov  * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
31*ae771770SStanislav Sedov  * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
32*ae771770SStanislav Sedov  * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
33*ae771770SStanislav Sedov  * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34*ae771770SStanislav Sedov  */
35*ae771770SStanislav Sedov 
36*ae771770SStanislav Sedov #include <config.h>
37*ae771770SStanislav Sedov #include <roken.h>
38*ae771770SStanislav Sedov 
39*ae771770SStanislav Sedov #include <stdio.h>
40*ae771770SStanislav Sedov #include <gssapi.h>
41*ae771770SStanislav Sedov #include <gssapi_krb5.h>
42*ae771770SStanislav Sedov #include <gssapi_spnego.h>
43*ae771770SStanislav Sedov #include <gssapi_ntlm.h>
44*ae771770SStanislav Sedov #include <err.h>
45*ae771770SStanislav Sedov #include <getarg.h>
46*ae771770SStanislav Sedov #include <rtbl.h>
47*ae771770SStanislav Sedov #include <gss-commands.h>
48*ae771770SStanislav Sedov 
49*ae771770SStanislav Sedov 
50*ae771770SStanislav Sedov static int version_flag = 0;
51*ae771770SStanislav Sedov static int help_flag	= 0;
52*ae771770SStanislav Sedov 
53*ae771770SStanislav Sedov static struct getargs args[] = {
54*ae771770SStanislav Sedov     {"version",	0,	arg_flag,	&version_flag, "print version", NULL },
55*ae771770SStanislav Sedov     {"help",	0,	arg_flag,	&help_flag,  NULL, NULL }
56*ae771770SStanislav Sedov };
57*ae771770SStanislav Sedov 
58*ae771770SStanislav Sedov static void
usage(int ret)59*ae771770SStanislav Sedov usage (int ret)
60*ae771770SStanislav Sedov {
61*ae771770SStanislav Sedov     arg_printusage (args, sizeof(args)/sizeof(*args),
62*ae771770SStanislav Sedov 		    NULL, "service@host");
63*ae771770SStanislav Sedov     exit (ret);
64*ae771770SStanislav Sedov }
65*ae771770SStanislav Sedov 
66*ae771770SStanislav Sedov #define COL_OID		"OID"
67*ae771770SStanislav Sedov #define COL_NAME	"Name"
68*ae771770SStanislav Sedov #define COL_DESC	"Description"
69*ae771770SStanislav Sedov #define COL_VALUE	"Value"
70*ae771770SStanislav Sedov #define COL_MECH	"Mech"
71*ae771770SStanislav Sedov #define COL_EXPIRE	"Expire"
72*ae771770SStanislav Sedov #define COL_SASL	"SASL"
73*ae771770SStanislav Sedov 
74*ae771770SStanislav Sedov int
supported_mechanisms(void * argptr,int argc,char ** argv)75*ae771770SStanislav Sedov supported_mechanisms(void *argptr, int argc, char **argv)
76*ae771770SStanislav Sedov {
77*ae771770SStanislav Sedov     OM_uint32 maj_stat, min_stat;
78*ae771770SStanislav Sedov     gss_OID_set mechs;
79*ae771770SStanislav Sedov     rtbl_t ct;
80*ae771770SStanislav Sedov     size_t i;
81*ae771770SStanislav Sedov 
82*ae771770SStanislav Sedov     maj_stat = gss_indicate_mechs(&min_stat, &mechs);
83*ae771770SStanislav Sedov     if (maj_stat != GSS_S_COMPLETE)
84*ae771770SStanislav Sedov 	errx(1, "gss_indicate_mechs failed");
85*ae771770SStanislav Sedov 
86*ae771770SStanislav Sedov     printf("Supported mechanisms:\n");
87*ae771770SStanislav Sedov 
88*ae771770SStanislav Sedov     ct = rtbl_create();
89*ae771770SStanislav Sedov     if (ct == NULL)
90*ae771770SStanislav Sedov 	errx(1, "rtbl_create");
91*ae771770SStanislav Sedov 
92*ae771770SStanislav Sedov     rtbl_set_separator(ct, "  ");
93*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_OID, 0);
94*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_NAME, 0);
95*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_DESC, 0);
96*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_SASL, 0);
97*ae771770SStanislav Sedov 
98*ae771770SStanislav Sedov     for (i = 0; i < mechs->count; i++) {
99*ae771770SStanislav Sedov 	gss_buffer_desc str, sasl_name, mech_name, mech_desc;
100*ae771770SStanislav Sedov 
101*ae771770SStanislav Sedov 	maj_stat = gss_oid_to_str(&min_stat, &mechs->elements[i], &str);
102*ae771770SStanislav Sedov 	if (maj_stat != GSS_S_COMPLETE)
103*ae771770SStanislav Sedov 	    errx(1, "gss_oid_to_str failed");
104*ae771770SStanislav Sedov 
105*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_OID, "%.*s",
106*ae771770SStanislav Sedov 			       (int)str.length, (char *)str.value);
107*ae771770SStanislav Sedov 	gss_release_buffer(&min_stat, &str);
108*ae771770SStanislav Sedov 
109*ae771770SStanislav Sedov 	(void)gss_inquire_saslname_for_mech(&min_stat,
110*ae771770SStanislav Sedov 					    &mechs->elements[i],
111*ae771770SStanislav Sedov 					    &sasl_name,
112*ae771770SStanislav Sedov 					    &mech_name,
113*ae771770SStanislav Sedov 					    &mech_desc);
114*ae771770SStanislav Sedov 
115*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_NAME, "%.*s",
116*ae771770SStanislav Sedov 			       (int)mech_name.length, (char *)mech_name.value);
117*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_DESC, "%.*s",
118*ae771770SStanislav Sedov 			       (int)mech_desc.length, (char *)mech_desc.value);
119*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_SASL, "%.*s",
120*ae771770SStanislav Sedov 			       (int)sasl_name.length, (char *)sasl_name.value);
121*ae771770SStanislav Sedov 
122*ae771770SStanislav Sedov 	gss_release_buffer(&min_stat, &mech_name);
123*ae771770SStanislav Sedov 	gss_release_buffer(&min_stat, &mech_desc);
124*ae771770SStanislav Sedov 	gss_release_buffer(&min_stat, &sasl_name);
125*ae771770SStanislav Sedov 
126*ae771770SStanislav Sedov     }
127*ae771770SStanislav Sedov     gss_release_oid_set(&min_stat, &mechs);
128*ae771770SStanislav Sedov 
129*ae771770SStanislav Sedov     rtbl_format(ct, stdout);
130*ae771770SStanislav Sedov     rtbl_destroy(ct);
131*ae771770SStanislav Sedov 
132*ae771770SStanislav Sedov     return 0;
133*ae771770SStanislav Sedov }
134*ae771770SStanislav Sedov 
135*ae771770SStanislav Sedov static void
print_mech_attr(const char * mechname,gss_const_OID mech,gss_OID_set set)136*ae771770SStanislav Sedov print_mech_attr(const char *mechname, gss_const_OID mech, gss_OID_set set)
137*ae771770SStanislav Sedov {
138*ae771770SStanislav Sedov     gss_buffer_desc name, desc;
139*ae771770SStanislav Sedov     OM_uint32 major, minor;
140*ae771770SStanislav Sedov     rtbl_t ct;
141*ae771770SStanislav Sedov     size_t n;
142*ae771770SStanislav Sedov 
143*ae771770SStanislav Sedov     ct = rtbl_create();
144*ae771770SStanislav Sedov     if (ct == NULL)
145*ae771770SStanislav Sedov 	errx(1, "rtbl_create");
146*ae771770SStanislav Sedov 
147*ae771770SStanislav Sedov     rtbl_set_separator(ct, "  ");
148*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_OID, 0);
149*ae771770SStanislav Sedov     rtbl_add_column(ct, COL_DESC, 0);
150*ae771770SStanislav Sedov     if (mech)
151*ae771770SStanislav Sedov 	rtbl_add_column(ct, COL_VALUE, 0);
152*ae771770SStanislav Sedov 
153*ae771770SStanislav Sedov     for (n = 0; n < set->count; n++) {
154*ae771770SStanislav Sedov 	major = gss_display_mech_attr(&minor, &set->elements[n], &name, &desc, NULL);
155*ae771770SStanislav Sedov 	if (major)
156*ae771770SStanislav Sedov 	    continue;
157*ae771770SStanislav Sedov 
158*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_OID, "%.*s",
159*ae771770SStanislav Sedov 			       (int)name.length, (char *)name.value);
160*ae771770SStanislav Sedov 	rtbl_add_column_entryv(ct, COL_DESC, "%.*s",
161*ae771770SStanislav Sedov 			       (int)desc.length, (char *)desc.value);
162*ae771770SStanislav Sedov 	if (mech) {
163*ae771770SStanislav Sedov 	    gss_buffer_desc value;
164*ae771770SStanislav Sedov 
165*ae771770SStanislav Sedov 	    if (gss_mo_get(mech, &set->elements[n], &value) != 0)
166*ae771770SStanislav Sedov 		value.length = 0;
167*ae771770SStanislav Sedov 
168*ae771770SStanislav Sedov 	    if (value.length)
169*ae771770SStanislav Sedov 		rtbl_add_column_entryv(ct, COL_VALUE, "%.*s",
170*ae771770SStanislav Sedov 				       (int)value.length, (char *)value.value);
171*ae771770SStanislav Sedov 	    else
172*ae771770SStanislav Sedov 		rtbl_add_column_entryv(ct, COL_VALUE, "<>");
173*ae771770SStanislav Sedov 	    gss_release_buffer(&minor, &value);
174*ae771770SStanislav Sedov 	}
175*ae771770SStanislav Sedov 
176*ae771770SStanislav Sedov 	gss_release_buffer(&minor, &name);
177*ae771770SStanislav Sedov 	gss_release_buffer(&minor, &desc);
178*ae771770SStanislav Sedov     }
179*ae771770SStanislav Sedov 
180*ae771770SStanislav Sedov     printf("attributes for: %s\n", mechname);
181*ae771770SStanislav Sedov     rtbl_format(ct, stdout);
182*ae771770SStanislav Sedov     rtbl_destroy(ct);
183*ae771770SStanislav Sedov }
184*ae771770SStanislav Sedov 
185*ae771770SStanislav Sedov 
186*ae771770SStanislav Sedov int
attrs_for_mech(struct attrs_for_mech_options * opt,int argc,char ** argv)187*ae771770SStanislav Sedov attrs_for_mech(struct attrs_for_mech_options *opt, int argc, char **argv)
188*ae771770SStanislav Sedov {
189*ae771770SStanislav Sedov     gss_OID_set mech_attr = NULL, known_mech_attrs = NULL;
190*ae771770SStanislav Sedov     gss_OID mech = GSS_C_NO_OID;
191*ae771770SStanislav Sedov     OM_uint32 major, minor;
192*ae771770SStanislav Sedov 
193*ae771770SStanislav Sedov     if (opt->mech_string) {
194*ae771770SStanislav Sedov 	mech = gss_name_to_oid(opt->mech_string);
195*ae771770SStanislav Sedov 	if (mech == NULL)
196*ae771770SStanislav Sedov 	    errx(1, "mech %s is unknown", opt->mech_string);
197*ae771770SStanislav Sedov     }
198*ae771770SStanislav Sedov 
199*ae771770SStanislav Sedov     major = gss_inquire_attrs_for_mech(&minor, mech, &mech_attr, &known_mech_attrs);
200*ae771770SStanislav Sedov     if (major)
201*ae771770SStanislav Sedov 	errx(1, "gss_inquire_attrs_for_mech");
202*ae771770SStanislav Sedov 
203*ae771770SStanislav Sedov     if (mech) {
204*ae771770SStanislav Sedov 	print_mech_attr(opt->mech_string, mech, mech_attr);
205*ae771770SStanislav Sedov     }
206*ae771770SStanislav Sedov 
207*ae771770SStanislav Sedov     if (opt->all_flag) {
208*ae771770SStanislav Sedov 	print_mech_attr("all mechs", NULL, known_mech_attrs);
209*ae771770SStanislav Sedov     }
210*ae771770SStanislav Sedov 
211*ae771770SStanislav Sedov     gss_release_oid_set(&minor, &mech_attr);
212*ae771770SStanislav Sedov     gss_release_oid_set(&minor, &known_mech_attrs);
213*ae771770SStanislav Sedov 
214*ae771770SStanislav Sedov     return 0;
215*ae771770SStanislav Sedov }
216*ae771770SStanislav Sedov 
217*ae771770SStanislav Sedov 
218*ae771770SStanislav Sedov /*
219*ae771770SStanislav Sedov  *
220*ae771770SStanislav Sedov  */
221*ae771770SStanislav Sedov 
222*ae771770SStanislav Sedov int
help(void * opt,int argc,char ** argv)223*ae771770SStanislav Sedov help(void *opt, int argc, char **argv)
224*ae771770SStanislav Sedov {
225*ae771770SStanislav Sedov     sl_slc_help(commands, argc, argv);
226*ae771770SStanislav Sedov     return 0;
227*ae771770SStanislav Sedov }
228*ae771770SStanislav Sedov 
229*ae771770SStanislav Sedov int
main(int argc,char ** argv)230*ae771770SStanislav Sedov main(int argc, char **argv)
231*ae771770SStanislav Sedov {
232*ae771770SStanislav Sedov     int optidx = 0;
233*ae771770SStanislav Sedov 
234*ae771770SStanislav Sedov     setprogname(argv[0]);
235*ae771770SStanislav Sedov     if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx))
236*ae771770SStanislav Sedov 	usage(1);
237*ae771770SStanislav Sedov 
238*ae771770SStanislav Sedov     if (help_flag)
239*ae771770SStanislav Sedov 	usage (0);
240*ae771770SStanislav Sedov 
241*ae771770SStanislav Sedov     if(version_flag){
242*ae771770SStanislav Sedov 	print_version(NULL);
243*ae771770SStanislav Sedov 	exit(0);
244*ae771770SStanislav Sedov     }
245*ae771770SStanislav Sedov 
246*ae771770SStanislav Sedov     argc -= optidx;
247*ae771770SStanislav Sedov     argv += optidx;
248*ae771770SStanislav Sedov 
249*ae771770SStanislav Sedov     if (argc == 0) {
250*ae771770SStanislav Sedov 	help(NULL, argc, argv);
251*ae771770SStanislav Sedov 	return 1;
252*ae771770SStanislav Sedov     }
253*ae771770SStanislav Sedov 
254*ae771770SStanislav Sedov     return sl_command (commands, argc, argv);
255*ae771770SStanislav Sedov }
256