diff options
author | Sam Hartman <hartmans@mit.edu> | 2010-09-15 17:13:41 +0000 |
---|---|---|
committer | Sam Hartman <hartmans@mit.edu> | 2010-09-15 17:13:41 +0000 |
commit | d100b4410ab933e21b4f3390f1b2f27d4e872442 (patch) | |
tree | bdec7d4a785c027a6991f2639e13748d3bf57dc5 /src/clients/kinit/kinit_kdb.c | |
parent | 41f6fee5e77e49732ae7c71808204aeb77aa1013 (diff) | |
download | krb5-d100b4410ab933e21b4f3390f1b2f27d4e872442.tar.gz krb5-d100b4410ab933e21b4f3390f1b2f27d4e872442.tar.xz krb5-d100b4410ab933e21b4f3390f1b2f27d4e872442.zip |
kinit: add KDB keytab support
This implements
http://k5wiki.kerberos.org/Projects/What_does_God_need_with_a_password.
If the KDB keytab is selected by command line options, then kinit will
register the KDB keytab and open the database. This permits an
administrator to obtain tickets as a user without knowing that user's
password.
As a result kinit links against libkadm5srv and libkdb5. Discussion is
ongoing about whether this is desirable or about whether two versions
of kinit are required.
ticket: 6779
git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@24316 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/clients/kinit/kinit_kdb.c')
-rw-r--r-- | src/clients/kinit/kinit_kdb.c | 70 |
1 files changed, 70 insertions, 0 deletions
diff --git a/src/clients/kinit/kinit_kdb.c b/src/clients/kinit/kinit_kdb.c new file mode 100644 index 0000000000..972983a161 --- /dev/null +++ b/src/clients/kinit/kinit_kdb.c @@ -0,0 +1,70 @@ +/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +/* + * clients/kinit/kinit_kdb.c + * + * Copyright (C) 2010 by the Massachusetts Institute of Technology. + * All rights reserved. + * + * Export of this software from the United States of America may + * require a specific license from the United States Government. + * It is the responsibility of any person or organization contemplating + * export to obtain such a license before exporting. + * + * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and + * distribute this software and its documentation for any purpose and + * without fee is hereby granted, provided that the above copyright + * notice appear in all copies and that both that copyright notice and + * this permission notice appear in supporting documentation, and that + * the name of M.I.T. not be used in advertising or publicity pertaining + * to distribution of the software without specific, written prior + * permission. Furthermore if you modify this software you must label + * your software as modified software and not distribute it in such a + * fashion that it might be confused with the original M.I.T. software. + * M.I.T. makes no representations about the suitability of + * this software for any purpose. It is provided "as is" without express + * or implied warranty. + * + * + */ +/** + * @file kinit_kdb.c + * Operations to open the KDB and make the KDB key table available + * for kinit. + */ + + +#include <k5-int.h> +#include <kadm5/admin.h> +#include <kdb_kt.h> +#include "extern.h" + +/**Server handle*/ +static void * server_handle; + +/** + *@internal Initialize KDB for given realm + * @param context pointer to context that will be re-initialized + * @@param realm name of realm to initialize + */ +krb5_error_code +kinit_kdb_init (krb5_context *pcontext, char *realm) +{ + kadm5_config_params config; + krb5_error_code retval = 0; + if (*pcontext) + krb5_free_context(*pcontext); + memset(&config, 0, sizeof config); + retval = kadm5_init_krb5_context(pcontext); + if (retval) + return retval; + config.mask = KADM5_CONFIG_REALM; + config.realm = realm; + retval = kadm5_init(*pcontext, "kinit", NULL /*pass*/, + "kinit", &config, + KADM5_STRUCT_VERSION, KADM5_API_VERSION_3, NULL, + &server_handle); + if (retval) + return retval; + retval = krb5_kt_register(*pcontext, &krb5_kt_kdb_ops); + return retval; +} |