Home | History | Annotate | Line # | Download | only in krb5
      1 /*	$NetBSD: rd_rep.c,v 1.2 2017/01/28 21:31:49 christos Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 1997 - 2001 Kungliga Tekniska Hgskolan
      5  * (Royal Institute of Technology, Stockholm, Sweden).
      6  * All rights reserved.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * 1. Redistributions of source code must retain the above copyright
     13  *    notice, this list of conditions and the following disclaimer.
     14  *
     15  * 2. Redistributions in binary form must reproduce the above copyright
     16  *    notice, this list of conditions and the following disclaimer in the
     17  *    documentation and/or other materials provided with the distribution.
     18  *
     19  * 3. Neither the name of the Institute nor the names of its contributors
     20  *    may be used to endorse or promote products derived from this software
     21  *    without specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
     24  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     25  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     26  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
     27  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     28  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     29  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     30  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     31  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     32  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     33  * SUCH DAMAGE.
     34  */
     35 
     36 #include "krb5_locl.h"
     37 
     38 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
     39 krb5_rd_rep(krb5_context context,
     40 	    krb5_auth_context auth_context,
     41 	    const krb5_data *inbuf,
     42 	    krb5_ap_rep_enc_part **repl)
     43 {
     44     krb5_error_code ret;
     45     AP_REP ap_rep;
     46     size_t len;
     47     krb5_data data;
     48     krb5_crypto crypto;
     49 
     50     *repl = NULL;
     51     krb5_data_zero (&data);
     52 
     53     ret = decode_AP_REP(inbuf->data, inbuf->length, &ap_rep, &len);
     54     if (ret)
     55 	return ret;
     56     if (ap_rep.pvno != 5) {
     57 	ret = KRB5KRB_AP_ERR_BADVERSION;
     58 	krb5_clear_error_message (context);
     59 	goto out;
     60     }
     61     if (ap_rep.msg_type != krb_ap_rep) {
     62 	ret = KRB5KRB_AP_ERR_MSG_TYPE;
     63 	krb5_clear_error_message (context);
     64 	goto out;
     65     }
     66 
     67     ret = krb5_crypto_init(context, auth_context->keyblock, 0, &crypto);
     68     if (ret)
     69 	goto out;
     70     ret = krb5_decrypt_EncryptedData(context,
     71 				     crypto,
     72 				     KRB5_KU_AP_REQ_ENC_PART,
     73 				     &ap_rep.enc_part,
     74 				     &data);
     75     krb5_crypto_destroy(context, crypto);
     76     if (ret)
     77 	goto out;
     78 
     79     *repl = malloc(sizeof(**repl));
     80     if (*repl == NULL) {
     81 	ret = krb5_enomem(context);
     82 	goto out;
     83     }
     84     ret = decode_EncAPRepPart(data.data, data.length, *repl, &len);
     85     if (ret) {
     86 	krb5_set_error_message(context, ret, N_("Failed to decode EncAPRepPart", ""));
     87         goto out;
     88     }
     89 
     90     if (auth_context->flags & KRB5_AUTH_CONTEXT_DO_TIME) {
     91 	if ((*repl)->ctime != auth_context->authenticator->ctime ||
     92 	    (*repl)->cusec != auth_context->authenticator->cusec)
     93 	{
     94 	    ret = KRB5KRB_AP_ERR_MUT_FAIL;
     95 	    krb5_clear_error_message(context);
     96 	    goto out;
     97 	}
     98     }
     99     if ((*repl)->seq_number)
    100 	krb5_auth_con_setremoteseqnumber(context, auth_context,
    101 					 *((*repl)->seq_number));
    102     if ((*repl)->subkey)
    103 	krb5_auth_con_setremotesubkey(context, auth_context, (*repl)->subkey);
    104 
    105  out:
    106     if (ret) {
    107         krb5_free_ap_rep_enc_part(context, *repl);
    108         *repl = NULL;
    109     }
    110     krb5_data_free(&data);
    111     free_AP_REP(&ap_rep);
    112     return ret;
    113 }
    114 
    115 KRB5_LIB_FUNCTION void KRB5_LIB_CALL
    116 krb5_free_ap_rep_enc_part (krb5_context context,
    117 			   krb5_ap_rep_enc_part *val)
    118 {
    119     if (val) {
    120 	free_EncAPRepPart (val);
    121 	free (val);
    122     }
    123 }
    124