1 1.1 elric /* $NetBSD: aeap.c,v 1.2 2017/01/28 21:31:46 christos Exp $ */ 2 1.1 elric 3 1.1 elric /* 4 1.1 elric * Copyright (c) 2008 Kungliga Tekniska Hgskolan 5 1.1 elric * (Royal Institute of Technology, Stockholm, Sweden). 6 1.1 elric * All rights reserved. 7 1.1 elric * 8 1.1 elric * Redistribution and use in source and binary forms, with or without 9 1.1 elric * modification, are permitted provided that the following conditions 10 1.1 elric * are met: 11 1.1 elric * 12 1.1 elric * 1. Redistributions of source code must retain the above copyright 13 1.1 elric * notice, this list of conditions and the following disclaimer. 14 1.1 elric * 15 1.1 elric * 2. Redistributions in binary form must reproduce the above copyright 16 1.1 elric * notice, this list of conditions and the following disclaimer in the 17 1.1 elric * documentation and/or other materials provided with the distribution. 18 1.1 elric * 19 1.1 elric * 3. Neither the name of the Institute nor the names of its contributors 20 1.1 elric * may be used to endorse or promote products derived from this software 21 1.1 elric * without specific prior written permission. 22 1.1 elric * 23 1.1 elric * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 24 1.1 elric * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 25 1.1 elric * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 26 1.1 elric * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 27 1.1 elric * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 28 1.1 elric * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 29 1.1 elric * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 30 1.1 elric * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 31 1.1 elric * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 32 1.1 elric * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 33 1.1 elric * SUCH DAMAGE. 34 1.1 elric */ 35 1.1 elric 36 1.1 elric #include "gsskrb5_locl.h" 37 1.1 elric 38 1.1 elric #include <krb5/roken.h> 39 1.1 elric 40 1.1 elric OM_uint32 GSSAPI_CALLCONV 41 1.1 elric _gk_wrap_iov(OM_uint32 * minor_status, 42 1.1 elric gss_ctx_id_t context_handle, 43 1.1 elric int conf_req_flag, 44 1.1 elric gss_qop_t qop_req, 45 1.1 elric int * conf_state, 46 1.1 elric gss_iov_buffer_desc *iov, 47 1.1 elric int iov_count) 48 1.1 elric { 49 1.2 christos const gsskrb5_ctx ctx = (const gsskrb5_ctx) context_handle; 50 1.2 christos krb5_context context; 51 1.2 christos OM_uint32 ret; 52 1.2 christos krb5_keyblock *key; 53 1.2 christos krb5_keytype keytype; 54 1.1 elric 55 1.2 christos GSSAPI_KRB5_INIT (&context); 56 1.1 elric 57 1.2 christos if (ctx->more_flags & IS_CFX) 58 1.2 christos return _gssapi_wrap_cfx_iov(minor_status, ctx, context, 59 1.2 christos conf_req_flag, conf_state, 60 1.2 christos iov, iov_count); 61 1.2 christos 62 1.2 christos HEIMDAL_MUTEX_lock(&ctx->ctx_id_mutex); 63 1.2 christos ret = _gsskrb5i_get_token_key(ctx, context, &key); 64 1.2 christos HEIMDAL_MUTEX_unlock(&ctx->ctx_id_mutex); 65 1.2 christos if (ret) { 66 1.2 christos *minor_status = ret; 67 1.2 christos return GSS_S_FAILURE; 68 1.2 christos } 69 1.2 christos krb5_enctype_to_keytype(context, key->keytype, &keytype); 70 1.2 christos 71 1.2 christos switch (keytype) { 72 1.2 christos case KEYTYPE_ARCFOUR: 73 1.2 christos case KEYTYPE_ARCFOUR_56: 74 1.2 christos ret = _gssapi_wrap_iov_arcfour(minor_status, ctx, context, 75 1.2 christos conf_req_flag, conf_state, 76 1.2 christos iov, iov_count, key); 77 1.2 christos break; 78 1.2 christos 79 1.2 christos default: 80 1.2 christos ret = GSS_S_FAILURE; 81 1.2 christos break; 82 1.2 christos } 83 1.1 elric 84 1.2 christos krb5_free_keyblock(context, key); 85 1.2 christos return ret; 86 1.1 elric } 87 1.1 elric 88 1.1 elric OM_uint32 GSSAPI_CALLCONV 89 1.1 elric _gk_unwrap_iov(OM_uint32 *minor_status, 90 1.1 elric gss_ctx_id_t context_handle, 91 1.1 elric int *conf_state, 92 1.1 elric gss_qop_t *qop_state, 93 1.1 elric gss_iov_buffer_desc *iov, 94 1.1 elric int iov_count) 95 1.1 elric { 96 1.1 elric const gsskrb5_ctx ctx = (const gsskrb5_ctx) context_handle; 97 1.1 elric krb5_context context; 98 1.2 christos OM_uint32 ret; 99 1.2 christos krb5_keytype keytype; 100 1.2 christos krb5_keyblock *key; 101 1.1 elric 102 1.1 elric GSSAPI_KRB5_INIT (&context); 103 1.2 christos 104 1.1 elric if (ctx->more_flags & IS_CFX) 105 1.1 elric return _gssapi_unwrap_cfx_iov(minor_status, ctx, context, 106 1.1 elric conf_state, qop_state, iov, iov_count); 107 1.2 christos 108 1.2 christos HEIMDAL_MUTEX_lock(&ctx->ctx_id_mutex); 109 1.2 christos ret = _gsskrb5i_get_token_key(ctx, context, &key); 110 1.2 christos HEIMDAL_MUTEX_unlock(&ctx->ctx_id_mutex); 111 1.2 christos if (ret) { 112 1.2 christos *minor_status = ret; 113 1.2 christos return GSS_S_FAILURE; 114 1.2 christos } 115 1.2 christos krb5_enctype_to_keytype(context, key->keytype, &keytype); 116 1.2 christos 117 1.2 christos switch (keytype) { 118 1.2 christos case KEYTYPE_ARCFOUR: 119 1.2 christos case KEYTYPE_ARCFOUR_56: 120 1.2 christos ret = _gssapi_unwrap_iov_arcfour(minor_status, ctx, context, 121 1.2 christos conf_state, qop_state, 122 1.2 christos iov, iov_count, key); 123 1.2 christos break; 124 1.2 christos 125 1.2 christos default: 126 1.2 christos ret = GSS_S_FAILURE; 127 1.2 christos break; 128 1.2 christos } 129 1.2 christos 130 1.2 christos krb5_free_keyblock(context, key); 131 1.2 christos return ret; 132 1.1 elric } 133 1.1 elric 134 1.1 elric OM_uint32 GSSAPI_CALLCONV 135 1.1 elric _gk_wrap_iov_length(OM_uint32 * minor_status, 136 1.1 elric gss_ctx_id_t context_handle, 137 1.1 elric int conf_req_flag, 138 1.1 elric gss_qop_t qop_req, 139 1.1 elric int *conf_state, 140 1.1 elric gss_iov_buffer_desc *iov, 141 1.1 elric int iov_count) 142 1.1 elric { 143 1.1 elric const gsskrb5_ctx ctx = (const gsskrb5_ctx) context_handle; 144 1.1 elric krb5_context context; 145 1.2 christos OM_uint32 ret; 146 1.2 christos krb5_keytype keytype; 147 1.2 christos krb5_keyblock *key; 148 1.2 christos 149 1.1 elric GSSAPI_KRB5_INIT (&context); 150 1.2 christos 151 1.1 elric if (ctx->more_flags & IS_CFX) 152 1.1 elric return _gssapi_wrap_iov_length_cfx(minor_status, ctx, context, 153 1.1 elric conf_req_flag, qop_req, conf_state, 154 1.1 elric iov, iov_count); 155 1.2 christos 156 1.2 christos HEIMDAL_MUTEX_lock(&ctx->ctx_id_mutex); 157 1.2 christos ret = _gsskrb5i_get_token_key(ctx, context, &key); 158 1.2 christos HEIMDAL_MUTEX_unlock(&ctx->ctx_id_mutex); 159 1.2 christos if (ret) { 160 1.2 christos *minor_status = ret; 161 1.2 christos return GSS_S_FAILURE; 162 1.2 christos } 163 1.2 christos krb5_enctype_to_keytype(context, key->keytype, &keytype); 164 1.2 christos 165 1.2 christos switch (keytype) { 166 1.2 christos case KEYTYPE_ARCFOUR: 167 1.2 christos case KEYTYPE_ARCFOUR_56: 168 1.2 christos ret = _gssapi_wrap_iov_length_arcfour(minor_status, ctx, context, 169 1.2 christos conf_req_flag, qop_req, conf_state, 170 1.2 christos iov, iov_count); 171 1.2 christos break; 172 1.2 christos 173 1.2 christos default: 174 1.2 christos ret = GSS_S_FAILURE; 175 1.2 christos break; 176 1.2 christos } 177 1.2 christos 178 1.2 christos krb5_free_keyblock(context, key); 179 1.2 christos return ret; 180 1.1 elric } 181