1*d3273b5bSchristos /* $NetBSD: iter_cred.c,v 1.2 2017/01/28 21:31:47 christos Exp $ */
2ca1c9b0cSelric
3ca1c9b0cSelric /*
4ca1c9b0cSelric * Copyright (c) 2006 Kungliga Tekniska H�gskolan
5ca1c9b0cSelric * (Royal Institute of Technology, Stockholm, Sweden).
6ca1c9b0cSelric * All rights reserved.
7ca1c9b0cSelric *
8ca1c9b0cSelric * Portions Copyright (c) 2009 Apple Inc. All rights reserved.
9ca1c9b0cSelric *
10ca1c9b0cSelric * Redistribution and use in source and binary forms, with or without
11ca1c9b0cSelric * modification, are permitted provided that the following conditions
12ca1c9b0cSelric * are met:
13ca1c9b0cSelric *
14ca1c9b0cSelric * 1. Redistributions of source code must retain the above copyright
15ca1c9b0cSelric * notice, this list of conditions and the following disclaimer.
16ca1c9b0cSelric *
17ca1c9b0cSelric * 2. Redistributions in binary form must reproduce the above copyright
18ca1c9b0cSelric * notice, this list of conditions and the following disclaimer in the
19ca1c9b0cSelric * documentation and/or other materials provided with the distribution.
20ca1c9b0cSelric *
21ca1c9b0cSelric * 3. Neither the name of the Institute nor the names of its contributors
22ca1c9b0cSelric * may be used to endorse or promote products derived from this software
23ca1c9b0cSelric * without specific prior written permission.
24ca1c9b0cSelric *
25ca1c9b0cSelric * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
26ca1c9b0cSelric * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
27ca1c9b0cSelric * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
28ca1c9b0cSelric * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
29ca1c9b0cSelric * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
30ca1c9b0cSelric * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
31ca1c9b0cSelric * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
32ca1c9b0cSelric * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
33ca1c9b0cSelric * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
34ca1c9b0cSelric * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
35ca1c9b0cSelric * SUCH DAMAGE.
36ca1c9b0cSelric */
37ca1c9b0cSelric
38ca1c9b0cSelric #include "ntlm.h"
39ca1c9b0cSelric
404f77a458Spettai void GSSAPI_CALLCONV
_gss_ntlm_iter_creds_f(OM_uint32 flags,void * userctx,void (* cred_iter)(void *,gss_OID,gss_cred_id_t))41ca1c9b0cSelric _gss_ntlm_iter_creds_f(OM_uint32 flags,
42ca1c9b0cSelric void *userctx ,
43ca1c9b0cSelric void (*cred_iter)(void *, gss_OID, gss_cred_id_t))
44ca1c9b0cSelric {
454f77a458Spettai #ifdef HAVE_KCM
46ca1c9b0cSelric krb5_error_code ret;
47ca1c9b0cSelric krb5_context context = NULL;
48ca1c9b0cSelric krb5_storage *request, *response;
49ca1c9b0cSelric krb5_data response_data;
50ca1c9b0cSelric
51ca1c9b0cSelric ret = krb5_init_context(&context);
52ca1c9b0cSelric if (ret)
53ca1c9b0cSelric goto done;
54ca1c9b0cSelric
55ca1c9b0cSelric ret = krb5_kcm_storage_request(context, KCM_OP_GET_NTLM_USER_LIST, &request);
56ca1c9b0cSelric if (ret)
57ca1c9b0cSelric goto done;
58ca1c9b0cSelric
59ca1c9b0cSelric ret = krb5_kcm_call(context, request, &response, &response_data);
60ca1c9b0cSelric krb5_storage_free(request);
61ca1c9b0cSelric if (ret)
62ca1c9b0cSelric goto done;
63ca1c9b0cSelric
64ca1c9b0cSelric while (1) {
65ca1c9b0cSelric uint32_t morep;
66ca1c9b0cSelric char *user = NULL, *domain = NULL;
67ca1c9b0cSelric ntlm_cred dn;
68ca1c9b0cSelric
69ca1c9b0cSelric ret = krb5_ret_uint32(response, &morep);
70ca1c9b0cSelric if (ret) goto out;
71ca1c9b0cSelric
72ca1c9b0cSelric if (!morep) goto out;
73ca1c9b0cSelric
74ca1c9b0cSelric ret = krb5_ret_stringz(response, &user);
75ca1c9b0cSelric if (ret) goto out;
76ca1c9b0cSelric ret = krb5_ret_stringz(response, &domain);
77ca1c9b0cSelric if (ret) {
78ca1c9b0cSelric free(user);
79ca1c9b0cSelric goto out;
80ca1c9b0cSelric }
81ca1c9b0cSelric
82ca1c9b0cSelric dn = calloc(1, sizeof(*dn));
83ca1c9b0cSelric if (dn == NULL) {
84ca1c9b0cSelric free(user);
85ca1c9b0cSelric free(domain);
86ca1c9b0cSelric goto out;
87ca1c9b0cSelric }
88ca1c9b0cSelric dn->username = user;
89ca1c9b0cSelric dn->domain = domain;
90ca1c9b0cSelric
91ca1c9b0cSelric cred_iter(userctx, GSS_NTLM_MECHANISM, (gss_cred_id_t)dn);
92ca1c9b0cSelric }
93ca1c9b0cSelric out:
94ca1c9b0cSelric krb5_storage_free(response);
95ca1c9b0cSelric krb5_data_free(&response_data);
96ca1c9b0cSelric done:
97ca1c9b0cSelric if (context)
98ca1c9b0cSelric krb5_free_context(context);
994f77a458Spettai #endif /* HAVE_KCM */
100ca1c9b0cSelric (*cred_iter)(userctx, NULL, NULL);
101ca1c9b0cSelric }
102