xref: /minix3/crypto/external/bsd/heimdal/dist/lib/kadm5/iprop-log.c (revision 0a6a1f1d05b60e214de2f05a7310ddd1f0e590e7)
1*0a6a1f1dSLionel Sambuc /*	$NetBSD: iprop-log.c,v 1.1.1.2 2014/04/24 12:45:48 pettai Exp $	*/
2ebfedea0SLionel Sambuc 
3ebfedea0SLionel Sambuc /*
4ebfedea0SLionel Sambuc  * Copyright (c) 1997 - 2005 Kungliga Tekniska Högskolan
5ebfedea0SLionel Sambuc  * (Royal Institute of Technology, Stockholm, Sweden).
6ebfedea0SLionel Sambuc  * All rights reserved.
7ebfedea0SLionel Sambuc  *
8ebfedea0SLionel Sambuc  * Redistribution and use in source and binary forms, with or without
9ebfedea0SLionel Sambuc  * modification, are permitted provided that the following conditions
10ebfedea0SLionel Sambuc  * are met:
11ebfedea0SLionel Sambuc  *
12ebfedea0SLionel Sambuc  * 1. Redistributions of source code must retain the above copyright
13ebfedea0SLionel Sambuc  *    notice, this list of conditions and the following disclaimer.
14ebfedea0SLionel Sambuc  *
15ebfedea0SLionel Sambuc  * 2. Redistributions in binary form must reproduce the above copyright
16ebfedea0SLionel Sambuc  *    notice, this list of conditions and the following disclaimer in the
17ebfedea0SLionel Sambuc  *    documentation and/or other materials provided with the distribution.
18ebfedea0SLionel Sambuc  *
19ebfedea0SLionel Sambuc  * 3. Neither the name of the Institute nor the names of its contributors
20ebfedea0SLionel Sambuc  *    may be used to endorse or promote products derived from this software
21ebfedea0SLionel Sambuc  *    without specific prior written permission.
22ebfedea0SLionel Sambuc  *
23ebfedea0SLionel Sambuc  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
24ebfedea0SLionel Sambuc  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25ebfedea0SLionel Sambuc  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26ebfedea0SLionel Sambuc  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
27ebfedea0SLionel Sambuc  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28ebfedea0SLionel Sambuc  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29ebfedea0SLionel Sambuc  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30ebfedea0SLionel Sambuc  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31ebfedea0SLionel Sambuc  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32ebfedea0SLionel Sambuc  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33ebfedea0SLionel Sambuc  * SUCH DAMAGE.
34ebfedea0SLionel Sambuc  */
35ebfedea0SLionel Sambuc 
36ebfedea0SLionel Sambuc #include "iprop.h"
37ebfedea0SLionel Sambuc #include <krb5/sl.h>
38ebfedea0SLionel Sambuc #include <krb5/parse_time.h>
39ebfedea0SLionel Sambuc #include "iprop-commands.h"
40ebfedea0SLionel Sambuc 
41*0a6a1f1dSLionel Sambuc __RCSID("NetBSD");
42ebfedea0SLionel Sambuc 
43ebfedea0SLionel Sambuc static krb5_context context;
44ebfedea0SLionel Sambuc 
45ebfedea0SLionel Sambuc static kadm5_server_context *
get_kadmin_context(const char * config_file,char * realm)46ebfedea0SLionel Sambuc get_kadmin_context(const char *config_file, char *realm)
47ebfedea0SLionel Sambuc {
48ebfedea0SLionel Sambuc     kadm5_config_params conf;
49ebfedea0SLionel Sambuc     krb5_error_code ret;
50ebfedea0SLionel Sambuc     void *kadm_handle;
51ebfedea0SLionel Sambuc     char **files;
52ebfedea0SLionel Sambuc 
53ebfedea0SLionel Sambuc     if (config_file == NULL) {
54ebfedea0SLionel Sambuc 	char *file;
55ebfedea0SLionel Sambuc 	asprintf(&file, "%s/kdc.conf", hdb_db_dir(context));
56ebfedea0SLionel Sambuc 	if (file == NULL)
57ebfedea0SLionel Sambuc 	    errx(1, "out of memory");
58ebfedea0SLionel Sambuc 	config_file = file;
59ebfedea0SLionel Sambuc     }
60ebfedea0SLionel Sambuc 
61ebfedea0SLionel Sambuc     ret = krb5_prepend_config_files_default(config_file, &files);
62ebfedea0SLionel Sambuc     if (ret)
63ebfedea0SLionel Sambuc 	krb5_err(context, 1, ret, "getting configuration files");
64ebfedea0SLionel Sambuc 
65ebfedea0SLionel Sambuc     ret = krb5_set_config_files(context, files);
66ebfedea0SLionel Sambuc     krb5_free_config_files(files);
67ebfedea0SLionel Sambuc     if (ret)
68ebfedea0SLionel Sambuc 	krb5_err(context, 1, ret, "reading configuration files");
69ebfedea0SLionel Sambuc 
70ebfedea0SLionel Sambuc     memset(&conf, 0, sizeof(conf));
71ebfedea0SLionel Sambuc     if(realm) {
72ebfedea0SLionel Sambuc 	conf.mask |= KADM5_CONFIG_REALM;
73ebfedea0SLionel Sambuc 	conf.realm = realm;
74ebfedea0SLionel Sambuc     }
75ebfedea0SLionel Sambuc 
76ebfedea0SLionel Sambuc     ret = kadm5_init_with_password_ctx (context,
77ebfedea0SLionel Sambuc 					KADM5_ADMIN_SERVICE,
78ebfedea0SLionel Sambuc 					NULL,
79ebfedea0SLionel Sambuc 					KADM5_ADMIN_SERVICE,
80ebfedea0SLionel Sambuc 					&conf, 0, 0,
81ebfedea0SLionel Sambuc 					&kadm_handle);
82ebfedea0SLionel Sambuc     if (ret)
83ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_init_with_password_ctx");
84ebfedea0SLionel Sambuc 
85ebfedea0SLionel Sambuc     return (kadm5_server_context *)kadm_handle;
86ebfedea0SLionel Sambuc }
87ebfedea0SLionel Sambuc 
88ebfedea0SLionel Sambuc /*
89ebfedea0SLionel Sambuc  * dump log
90ebfedea0SLionel Sambuc  */
91ebfedea0SLionel Sambuc 
92ebfedea0SLionel Sambuc static const char *op_names[] = {
93ebfedea0SLionel Sambuc     "get",
94ebfedea0SLionel Sambuc     "delete",
95ebfedea0SLionel Sambuc     "create",
96ebfedea0SLionel Sambuc     "rename",
97ebfedea0SLionel Sambuc     "chpass",
98ebfedea0SLionel Sambuc     "modify",
99ebfedea0SLionel Sambuc     "randkey",
100ebfedea0SLionel Sambuc     "get_privs",
101ebfedea0SLionel Sambuc     "get_princs",
102ebfedea0SLionel Sambuc     "chpass_with_key",
103ebfedea0SLionel Sambuc     "nop"
104ebfedea0SLionel Sambuc };
105ebfedea0SLionel Sambuc 
106ebfedea0SLionel Sambuc static void
print_entry(kadm5_server_context * server_context,uint32_t ver,time_t timestamp,enum kadm_ops op,uint32_t len,krb5_storage * sp,void * ctx)107ebfedea0SLionel Sambuc print_entry(kadm5_server_context *server_context,
108ebfedea0SLionel Sambuc 	    uint32_t ver,
109ebfedea0SLionel Sambuc 	    time_t timestamp,
110ebfedea0SLionel Sambuc 	    enum kadm_ops op,
111ebfedea0SLionel Sambuc 	    uint32_t len,
112ebfedea0SLionel Sambuc 	    krb5_storage *sp,
113ebfedea0SLionel Sambuc 	    void *ctx)
114ebfedea0SLionel Sambuc {
115ebfedea0SLionel Sambuc     char t[256];
116ebfedea0SLionel Sambuc     int32_t mask;
117ebfedea0SLionel Sambuc     hdb_entry ent;
118ebfedea0SLionel Sambuc     krb5_principal source;
119ebfedea0SLionel Sambuc     char *name1, *name2;
120ebfedea0SLionel Sambuc     krb5_data data;
121ebfedea0SLionel Sambuc     krb5_context scontext = server_context->context;
122ebfedea0SLionel Sambuc 
123ebfedea0SLionel Sambuc     off_t end = krb5_storage_seek(sp, 0, SEEK_CUR) + len;
124ebfedea0SLionel Sambuc 
125ebfedea0SLionel Sambuc     krb5_error_code ret;
126ebfedea0SLionel Sambuc 
127ebfedea0SLionel Sambuc     strftime(t, sizeof(t), "%Y-%m-%d %H:%M:%S", localtime(&timestamp));
128ebfedea0SLionel Sambuc 
129*0a6a1f1dSLionel Sambuc     if((int)op < (int)kadm_get || (int)op > (int)kadm_nop) {
130ebfedea0SLionel Sambuc 	printf("unknown op: %d\n", op);
131ebfedea0SLionel Sambuc 	krb5_storage_seek(sp, end, SEEK_SET);
132ebfedea0SLionel Sambuc 	return;
133ebfedea0SLionel Sambuc     }
134ebfedea0SLionel Sambuc 
135ebfedea0SLionel Sambuc     printf ("%s: ver = %u, timestamp = %s, len = %u\n",
136ebfedea0SLionel Sambuc 	    op_names[op], ver, t, len);
137ebfedea0SLionel Sambuc     switch(op) {
138ebfedea0SLionel Sambuc     case kadm_delete:
139ebfedea0SLionel Sambuc 	krb5_ret_principal(sp, &source);
140ebfedea0SLionel Sambuc 	krb5_unparse_name(scontext, source, &name1);
141ebfedea0SLionel Sambuc 	printf("    %s\n", name1);
142ebfedea0SLionel Sambuc 	free(name1);
143ebfedea0SLionel Sambuc 	krb5_free_principal(scontext, source);
144ebfedea0SLionel Sambuc 	break;
145ebfedea0SLionel Sambuc     case kadm_rename:
146ebfedea0SLionel Sambuc 	ret = krb5_data_alloc(&data, len);
147ebfedea0SLionel Sambuc 	if (ret)
148ebfedea0SLionel Sambuc 	    krb5_err (scontext, 1, ret, "kadm_rename: data alloc: %d", len);
149ebfedea0SLionel Sambuc 	krb5_ret_principal(sp, &source);
150ebfedea0SLionel Sambuc 	krb5_storage_read(sp, data.data, data.length);
151ebfedea0SLionel Sambuc 	hdb_value2entry(scontext, &data, &ent);
152ebfedea0SLionel Sambuc 	krb5_unparse_name(scontext, source, &name1);
153ebfedea0SLionel Sambuc 	krb5_unparse_name(scontext, ent.principal, &name2);
154ebfedea0SLionel Sambuc 	printf("    %s -> %s\n", name1, name2);
155ebfedea0SLionel Sambuc 	free(name1);
156ebfedea0SLionel Sambuc 	free(name2);
157ebfedea0SLionel Sambuc 	krb5_free_principal(scontext, source);
158ebfedea0SLionel Sambuc 	free_hdb_entry(&ent);
159ebfedea0SLionel Sambuc 	break;
160ebfedea0SLionel Sambuc     case kadm_create:
161ebfedea0SLionel Sambuc 	ret = krb5_data_alloc(&data, len);
162ebfedea0SLionel Sambuc 	if (ret)
163ebfedea0SLionel Sambuc 	    krb5_err (scontext, 1, ret, "kadm_create: data alloc: %d", len);
164ebfedea0SLionel Sambuc 	krb5_storage_read(sp, data.data, data.length);
165ebfedea0SLionel Sambuc 	ret = hdb_value2entry(scontext, &data, &ent);
166ebfedea0SLionel Sambuc 	if(ret)
167ebfedea0SLionel Sambuc 	    abort();
168ebfedea0SLionel Sambuc 	mask = ~0;
169ebfedea0SLionel Sambuc 	goto foo;
170ebfedea0SLionel Sambuc     case kadm_modify:
171ebfedea0SLionel Sambuc 	ret = krb5_data_alloc(&data, len);
172ebfedea0SLionel Sambuc 	if (ret)
173ebfedea0SLionel Sambuc 	    krb5_err (scontext, 1, ret, "kadm_modify: data alloc: %d", len);
174ebfedea0SLionel Sambuc 	krb5_ret_int32(sp, &mask);
175ebfedea0SLionel Sambuc 	krb5_storage_read(sp, data.data, data.length);
176ebfedea0SLionel Sambuc 	ret = hdb_value2entry(scontext, &data, &ent);
177ebfedea0SLionel Sambuc 	if(ret)
178ebfedea0SLionel Sambuc 	    abort();
179ebfedea0SLionel Sambuc     foo:
180ebfedea0SLionel Sambuc 	if(ent.principal /* mask & KADM5_PRINCIPAL */) {
181ebfedea0SLionel Sambuc 	    krb5_unparse_name(scontext, ent.principal, &name1);
182ebfedea0SLionel Sambuc 	    printf("    principal = %s\n", name1);
183ebfedea0SLionel Sambuc 	    free(name1);
184ebfedea0SLionel Sambuc 	}
185ebfedea0SLionel Sambuc 	if(mask & KADM5_PRINC_EXPIRE_TIME) {
186ebfedea0SLionel Sambuc 	    if(ent.valid_end == NULL) {
187ebfedea0SLionel Sambuc 		strlcpy(t, "never", sizeof(t));
188ebfedea0SLionel Sambuc 	    } else {
189ebfedea0SLionel Sambuc 		strftime(t, sizeof(t), "%Y-%m-%d %H:%M:%S",
190ebfedea0SLionel Sambuc 			 localtime(ent.valid_end));
191ebfedea0SLionel Sambuc 	    }
192ebfedea0SLionel Sambuc 	    printf("    expires = %s\n", t);
193ebfedea0SLionel Sambuc 	}
194ebfedea0SLionel Sambuc 	if(mask & KADM5_PW_EXPIRATION) {
195ebfedea0SLionel Sambuc 	    if(ent.pw_end == NULL) {
196ebfedea0SLionel Sambuc 		strlcpy(t, "never", sizeof(t));
197ebfedea0SLionel Sambuc 	    } else {
198ebfedea0SLionel Sambuc 		strftime(t, sizeof(t), "%Y-%m-%d %H:%M:%S",
199ebfedea0SLionel Sambuc 			 localtime(ent.pw_end));
200ebfedea0SLionel Sambuc 	    }
201ebfedea0SLionel Sambuc 	    printf("    password exp = %s\n", t);
202ebfedea0SLionel Sambuc 	}
203ebfedea0SLionel Sambuc 	if(mask & KADM5_LAST_PWD_CHANGE) {
204ebfedea0SLionel Sambuc 	}
205ebfedea0SLionel Sambuc 	if(mask & KADM5_ATTRIBUTES) {
206ebfedea0SLionel Sambuc 	    unparse_flags(HDBFlags2int(ent.flags),
207ebfedea0SLionel Sambuc 			  asn1_HDBFlags_units(), t, sizeof(t));
208ebfedea0SLionel Sambuc 	    printf("    attributes = %s\n", t);
209ebfedea0SLionel Sambuc 	}
210ebfedea0SLionel Sambuc 	if(mask & KADM5_MAX_LIFE) {
211ebfedea0SLionel Sambuc 	    if(ent.max_life == NULL)
212ebfedea0SLionel Sambuc 		strlcpy(t, "for ever", sizeof(t));
213ebfedea0SLionel Sambuc 	    else
214ebfedea0SLionel Sambuc 		unparse_time(*ent.max_life, t, sizeof(t));
215ebfedea0SLionel Sambuc 	    printf("    max life = %s\n", t);
216ebfedea0SLionel Sambuc 	}
217ebfedea0SLionel Sambuc 	if(mask & KADM5_MAX_RLIFE) {
218ebfedea0SLionel Sambuc 	    if(ent.max_renew == NULL)
219ebfedea0SLionel Sambuc 		strlcpy(t, "for ever", sizeof(t));
220ebfedea0SLionel Sambuc 	    else
221ebfedea0SLionel Sambuc 		unparse_time(*ent.max_renew, t, sizeof(t));
222ebfedea0SLionel Sambuc 	    printf("    max rlife = %s\n", t);
223ebfedea0SLionel Sambuc 	}
224ebfedea0SLionel Sambuc 	if(mask & KADM5_MOD_TIME) {
225ebfedea0SLionel Sambuc 	    printf("    mod time\n");
226ebfedea0SLionel Sambuc 	}
227ebfedea0SLionel Sambuc 	if(mask & KADM5_MOD_NAME) {
228ebfedea0SLionel Sambuc 	    printf("    mod name\n");
229ebfedea0SLionel Sambuc 	}
230ebfedea0SLionel Sambuc 	if(mask & KADM5_KVNO) {
231ebfedea0SLionel Sambuc 	    printf("    kvno = %d\n", ent.kvno);
232ebfedea0SLionel Sambuc 	}
233ebfedea0SLionel Sambuc 	if(mask & KADM5_MKVNO) {
234ebfedea0SLionel Sambuc 	    printf("    mkvno\n");
235ebfedea0SLionel Sambuc 	}
236ebfedea0SLionel Sambuc 	if(mask & KADM5_AUX_ATTRIBUTES) {
237ebfedea0SLionel Sambuc 	    printf("    aux attributes\n");
238ebfedea0SLionel Sambuc 	}
239ebfedea0SLionel Sambuc 	if(mask & KADM5_POLICY) {
240ebfedea0SLionel Sambuc 	    printf("    policy\n");
241ebfedea0SLionel Sambuc 	}
242ebfedea0SLionel Sambuc 	if(mask & KADM5_POLICY_CLR) {
243ebfedea0SLionel Sambuc 	    printf("    mod time\n");
244ebfedea0SLionel Sambuc 	}
245ebfedea0SLionel Sambuc 	if(mask & KADM5_LAST_SUCCESS) {
246ebfedea0SLionel Sambuc 	    printf("    last success\n");
247ebfedea0SLionel Sambuc 	}
248ebfedea0SLionel Sambuc 	if(mask & KADM5_LAST_FAILED) {
249ebfedea0SLionel Sambuc 	    printf("    last failed\n");
250ebfedea0SLionel Sambuc 	}
251ebfedea0SLionel Sambuc 	if(mask & KADM5_FAIL_AUTH_COUNT) {
252ebfedea0SLionel Sambuc 	    printf("    fail auth count\n");
253ebfedea0SLionel Sambuc 	}
254ebfedea0SLionel Sambuc 	if(mask & KADM5_KEY_DATA) {
255ebfedea0SLionel Sambuc 	    printf("    key data\n");
256ebfedea0SLionel Sambuc 	}
257ebfedea0SLionel Sambuc 	if(mask & KADM5_TL_DATA) {
258ebfedea0SLionel Sambuc 	    printf("    tl data\n");
259ebfedea0SLionel Sambuc 	}
260ebfedea0SLionel Sambuc 	free_hdb_entry(&ent);
261ebfedea0SLionel Sambuc 	break;
262ebfedea0SLionel Sambuc     case kadm_nop :
263ebfedea0SLionel Sambuc 	break;
264ebfedea0SLionel Sambuc     default:
265ebfedea0SLionel Sambuc 	abort();
266ebfedea0SLionel Sambuc     }
267ebfedea0SLionel Sambuc     krb5_storage_seek(sp, end, SEEK_SET);
268ebfedea0SLionel Sambuc }
269ebfedea0SLionel Sambuc 
270ebfedea0SLionel Sambuc int
iprop_dump(struct dump_options * opt,int argc,char ** argv)271ebfedea0SLionel Sambuc iprop_dump(struct dump_options *opt, int argc, char **argv)
272ebfedea0SLionel Sambuc {
273ebfedea0SLionel Sambuc     kadm5_server_context *server_context;
274ebfedea0SLionel Sambuc     krb5_error_code ret;
275ebfedea0SLionel Sambuc 
276ebfedea0SLionel Sambuc     server_context = get_kadmin_context(opt->config_file_string,
277ebfedea0SLionel Sambuc 					opt->realm_string);
278ebfedea0SLionel Sambuc 
279ebfedea0SLionel Sambuc     ret = kadm5_log_init (server_context);
280ebfedea0SLionel Sambuc     if (ret)
281ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_log_init");
282ebfedea0SLionel Sambuc 
283ebfedea0SLionel Sambuc     ret = kadm5_log_foreach (server_context, print_entry, NULL);
284ebfedea0SLionel Sambuc     if(ret)
285ebfedea0SLionel Sambuc 	krb5_warn(context, ret, "kadm5_log_foreach");
286ebfedea0SLionel Sambuc 
287ebfedea0SLionel Sambuc     ret = kadm5_log_end (server_context);
288ebfedea0SLionel Sambuc     if (ret)
289ebfedea0SLionel Sambuc 	krb5_warn(context, ret, "kadm5_log_end");
290ebfedea0SLionel Sambuc     return 0;
291ebfedea0SLionel Sambuc }
292ebfedea0SLionel Sambuc 
293ebfedea0SLionel Sambuc int
iprop_truncate(struct truncate_options * opt,int argc,char ** argv)294ebfedea0SLionel Sambuc iprop_truncate(struct truncate_options *opt, int argc, char **argv)
295ebfedea0SLionel Sambuc {
296ebfedea0SLionel Sambuc     kadm5_server_context *server_context;
297ebfedea0SLionel Sambuc     krb5_error_code ret;
298ebfedea0SLionel Sambuc 
299ebfedea0SLionel Sambuc     server_context = get_kadmin_context(opt->config_file_string,
300ebfedea0SLionel Sambuc 					opt->realm_string);
301ebfedea0SLionel Sambuc 
302ebfedea0SLionel Sambuc     ret = kadm5_log_truncate (server_context);
303ebfedea0SLionel Sambuc     if (ret)
304ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_log_truncate");
305ebfedea0SLionel Sambuc 
306ebfedea0SLionel Sambuc     return 0;
307ebfedea0SLionel Sambuc }
308ebfedea0SLionel Sambuc 
309ebfedea0SLionel Sambuc int
last_version(struct last_version_options * opt,int argc,char ** argv)310ebfedea0SLionel Sambuc last_version(struct last_version_options *opt, int argc, char **argv)
311ebfedea0SLionel Sambuc {
312ebfedea0SLionel Sambuc     kadm5_server_context *server_context;
313ebfedea0SLionel Sambuc     krb5_error_code ret;
314ebfedea0SLionel Sambuc     uint32_t version;
315ebfedea0SLionel Sambuc 
316ebfedea0SLionel Sambuc     server_context = get_kadmin_context(opt->config_file_string,
317ebfedea0SLionel Sambuc 					opt->realm_string);
318ebfedea0SLionel Sambuc 
319ebfedea0SLionel Sambuc     ret = kadm5_log_init (server_context);
320ebfedea0SLionel Sambuc     if (ret)
321ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_log_init");
322ebfedea0SLionel Sambuc 
323ebfedea0SLionel Sambuc     ret = kadm5_log_get_version (server_context, &version);
324ebfedea0SLionel Sambuc     if (ret)
325ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_log_get_version");
326ebfedea0SLionel Sambuc 
327ebfedea0SLionel Sambuc     ret = kadm5_log_end (server_context);
328ebfedea0SLionel Sambuc     if (ret)
329ebfedea0SLionel Sambuc 	krb5_warn(context, ret, "kadm5_log_end");
330ebfedea0SLionel Sambuc 
331ebfedea0SLionel Sambuc     printf("version: %lu\n", (unsigned long)version);
332ebfedea0SLionel Sambuc 
333ebfedea0SLionel Sambuc     return 0;
334ebfedea0SLionel Sambuc }
335ebfedea0SLionel Sambuc 
336ebfedea0SLionel Sambuc /*
337ebfedea0SLionel Sambuc  * Replay log
338ebfedea0SLionel Sambuc  */
339ebfedea0SLionel Sambuc 
340ebfedea0SLionel Sambuc int start_version = -1;
341ebfedea0SLionel Sambuc int end_version = -1;
342ebfedea0SLionel Sambuc 
343ebfedea0SLionel Sambuc static void
apply_entry(kadm5_server_context * server_context,uint32_t ver,time_t timestamp,enum kadm_ops op,uint32_t len,krb5_storage * sp,void * ctx)344ebfedea0SLionel Sambuc apply_entry(kadm5_server_context *server_context,
345ebfedea0SLionel Sambuc 	    uint32_t ver,
346ebfedea0SLionel Sambuc 	    time_t timestamp,
347ebfedea0SLionel Sambuc 	    enum kadm_ops op,
348ebfedea0SLionel Sambuc 	    uint32_t len,
349ebfedea0SLionel Sambuc 	    krb5_storage *sp,
350ebfedea0SLionel Sambuc 	    void *ctx)
351ebfedea0SLionel Sambuc {
352ebfedea0SLionel Sambuc     struct replay_options *opt = ctx;
353ebfedea0SLionel Sambuc     krb5_error_code ret;
354ebfedea0SLionel Sambuc 
355*0a6a1f1dSLionel Sambuc     if((opt->start_version_integer != -1 && ver < (uint32_t)opt->start_version_integer) ||
356*0a6a1f1dSLionel Sambuc        (opt->end_version_integer != -1 && ver > (uint32_t)opt->end_version_integer)) {
357ebfedea0SLionel Sambuc 	/* XXX skip this entry */
358ebfedea0SLionel Sambuc 	krb5_storage_seek(sp, len, SEEK_CUR);
359ebfedea0SLionel Sambuc 	return;
360ebfedea0SLionel Sambuc     }
361ebfedea0SLionel Sambuc     printf ("ver %u... ", ver);
362ebfedea0SLionel Sambuc     fflush (stdout);
363ebfedea0SLionel Sambuc 
364ebfedea0SLionel Sambuc     ret = kadm5_log_replay (server_context,
365ebfedea0SLionel Sambuc 			    op, ver, len, sp);
366ebfedea0SLionel Sambuc     if (ret)
367ebfedea0SLionel Sambuc 	krb5_warn (server_context->context, ret, "kadm5_log_replay");
368ebfedea0SLionel Sambuc 
369ebfedea0SLionel Sambuc     printf ("done\n");
370ebfedea0SLionel Sambuc }
371ebfedea0SLionel Sambuc 
372ebfedea0SLionel Sambuc int
iprop_replay(struct replay_options * opt,int argc,char ** argv)373ebfedea0SLionel Sambuc iprop_replay(struct replay_options *opt, int argc, char **argv)
374ebfedea0SLionel Sambuc {
375ebfedea0SLionel Sambuc     kadm5_server_context *server_context;
376ebfedea0SLionel Sambuc     krb5_error_code ret;
377ebfedea0SLionel Sambuc 
378ebfedea0SLionel Sambuc     server_context = get_kadmin_context(opt->config_file_string,
379ebfedea0SLionel Sambuc 					opt->realm_string);
380ebfedea0SLionel Sambuc 
381ebfedea0SLionel Sambuc     ret = server_context->db->hdb_open(context,
382ebfedea0SLionel Sambuc 				       server_context->db,
383ebfedea0SLionel Sambuc 				       O_RDWR | O_CREAT, 0600);
384ebfedea0SLionel Sambuc     if (ret)
385ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "db->open");
386ebfedea0SLionel Sambuc 
387ebfedea0SLionel Sambuc     ret = kadm5_log_init (server_context);
388ebfedea0SLionel Sambuc     if (ret)
389ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "kadm5_log_init");
390ebfedea0SLionel Sambuc 
391ebfedea0SLionel Sambuc     ret = kadm5_log_foreach (server_context, apply_entry, opt);
392ebfedea0SLionel Sambuc     if(ret)
393ebfedea0SLionel Sambuc 	krb5_warn(context, ret, "kadm5_log_foreach");
394ebfedea0SLionel Sambuc     ret = kadm5_log_end (server_context);
395ebfedea0SLionel Sambuc     if (ret)
396ebfedea0SLionel Sambuc 	krb5_warn(context, ret, "kadm5_log_end");
397ebfedea0SLionel Sambuc     ret = server_context->db->hdb_close (context, server_context->db);
398ebfedea0SLionel Sambuc     if (ret)
399ebfedea0SLionel Sambuc 	krb5_err (context, 1, ret, "db->close");
400ebfedea0SLionel Sambuc 
401ebfedea0SLionel Sambuc     return 0;
402ebfedea0SLionel Sambuc }
403ebfedea0SLionel Sambuc 
404ebfedea0SLionel Sambuc static int help_flag;
405ebfedea0SLionel Sambuc static int version_flag;
406ebfedea0SLionel Sambuc 
407ebfedea0SLionel Sambuc static struct getargs args[] = {
408ebfedea0SLionel Sambuc     { "version", 	0,	arg_flag, 	&version_flag,
409ebfedea0SLionel Sambuc       NULL,		NULL
410ebfedea0SLionel Sambuc     },
411ebfedea0SLionel Sambuc     { "help", 	'h', 	arg_flag, 	&help_flag,
412ebfedea0SLionel Sambuc       NULL, NULL
413ebfedea0SLionel Sambuc     }
414ebfedea0SLionel Sambuc };
415ebfedea0SLionel Sambuc 
416ebfedea0SLionel Sambuc static int num_args = sizeof(args) / sizeof(args[0]);
417ebfedea0SLionel Sambuc 
418ebfedea0SLionel Sambuc int
help(void * opt,int argc,char ** argv)419ebfedea0SLionel Sambuc help(void *opt, int argc, char **argv)
420ebfedea0SLionel Sambuc {
421ebfedea0SLionel Sambuc     if(argc == 0) {
422ebfedea0SLionel Sambuc 	sl_help(commands, 1, argv - 1 /* XXX */);
423ebfedea0SLionel Sambuc     } else {
424ebfedea0SLionel Sambuc 	SL_cmd *c = sl_match (commands, argv[0], 0);
425ebfedea0SLionel Sambuc  	if(c == NULL) {
426ebfedea0SLionel Sambuc 	    fprintf (stderr, "No such command: %s. "
427ebfedea0SLionel Sambuc 		     "Try \"help\" for a list of commands\n",
428ebfedea0SLionel Sambuc 		     argv[0]);
429ebfedea0SLionel Sambuc 	} else {
430ebfedea0SLionel Sambuc 	    if(c->func) {
431*0a6a1f1dSLionel Sambuc 		static char shelp[] = "--help";
432*0a6a1f1dSLionel Sambuc 		char *fake[3];
433ebfedea0SLionel Sambuc 		fake[0] = argv[0];
434*0a6a1f1dSLionel Sambuc 		fake[1] = shelp;
435*0a6a1f1dSLionel Sambuc 		fake[2] = NULL;
436ebfedea0SLionel Sambuc 		(*c->func)(2, fake);
437ebfedea0SLionel Sambuc 		fprintf(stderr, "\n");
438ebfedea0SLionel Sambuc 	    }
439ebfedea0SLionel Sambuc 	    if(c->help && *c->help)
440ebfedea0SLionel Sambuc 		fprintf (stderr, "%s\n", c->help);
441ebfedea0SLionel Sambuc 	    if((++c)->name && c->func == NULL) {
442ebfedea0SLionel Sambuc 		int f = 0;
443ebfedea0SLionel Sambuc 		fprintf (stderr, "Synonyms:");
444ebfedea0SLionel Sambuc 		while (c->name && c->func == NULL) {
445ebfedea0SLionel Sambuc 		    fprintf (stderr, "%s%s", f ? ", " : " ", (c++)->name);
446ebfedea0SLionel Sambuc 		    f = 1;
447ebfedea0SLionel Sambuc 		}
448ebfedea0SLionel Sambuc 		fprintf (stderr, "\n");
449ebfedea0SLionel Sambuc 	    }
450ebfedea0SLionel Sambuc 	}
451ebfedea0SLionel Sambuc     }
452ebfedea0SLionel Sambuc     return 0;
453ebfedea0SLionel Sambuc }
454ebfedea0SLionel Sambuc 
455ebfedea0SLionel Sambuc static void
usage(int status)456ebfedea0SLionel Sambuc usage(int status)
457ebfedea0SLionel Sambuc {
458ebfedea0SLionel Sambuc     arg_printusage(args, num_args, NULL, "command");
459ebfedea0SLionel Sambuc     exit(status);
460ebfedea0SLionel Sambuc }
461ebfedea0SLionel Sambuc 
462ebfedea0SLionel Sambuc int
main(int argc,char ** argv)463ebfedea0SLionel Sambuc main(int argc, char **argv)
464ebfedea0SLionel Sambuc {
465ebfedea0SLionel Sambuc     int optidx = 0;
466ebfedea0SLionel Sambuc     krb5_error_code ret;
467ebfedea0SLionel Sambuc 
468ebfedea0SLionel Sambuc     setprogname(argv[0]);
469ebfedea0SLionel Sambuc 
470ebfedea0SLionel Sambuc     if(getarg(args, num_args, argc, argv, &optidx))
471ebfedea0SLionel Sambuc 	usage(1);
472ebfedea0SLionel Sambuc     if(help_flag)
473ebfedea0SLionel Sambuc 	usage(0);
474ebfedea0SLionel Sambuc     if(version_flag) {
475ebfedea0SLionel Sambuc 	print_version(NULL);
476ebfedea0SLionel Sambuc 	exit(0);
477ebfedea0SLionel Sambuc     }
478ebfedea0SLionel Sambuc     argc -= optidx;
479ebfedea0SLionel Sambuc     argv += optidx;
480ebfedea0SLionel Sambuc     if(argc == 0)
481ebfedea0SLionel Sambuc 	usage(1);
482ebfedea0SLionel Sambuc 
483ebfedea0SLionel Sambuc     ret = krb5_init_context(&context);
484ebfedea0SLionel Sambuc     if (ret)
485ebfedea0SLionel Sambuc 	errx(1, "krb5_init_context failed with: %d\n", ret);
486ebfedea0SLionel Sambuc 
487ebfedea0SLionel Sambuc     ret = sl_command(commands, argc, argv);
488ebfedea0SLionel Sambuc     if(ret == -1)
489ebfedea0SLionel Sambuc 	warnx ("unrecognized command: %s", argv[0]);
490ebfedea0SLionel Sambuc     return ret;
491ebfedea0SLionel Sambuc }
492