diff options
Diffstat (limited to 'proxy')
-rw-r--r-- | proxy/Makefile.am | 1 | ||||
-rw-r--r-- | proxy/src/client/gpm_wrap.c | 123 | ||||
-rw-r--r-- | proxy/src/client/gssapi_gpm.h | 8 |
3 files changed, 131 insertions, 1 deletions
diff --git a/proxy/Makefile.am b/proxy/Makefile.am index 472c714..4f393bf 100644 --- a/proxy/Makefile.am +++ b/proxy/Makefile.am @@ -93,6 +93,7 @@ GP_MECHGLUE_OBJ = \ src/client/gpm_inquire_context.c \ src/client/gpm_get_mic.c \ src/client/gpm_verify_mic.c \ + src/client/gpm_wrap.c \ src/client/gpm_common.c dist_noinst_HEADERS = \ diff --git a/proxy/src/client/gpm_wrap.c b/proxy/src/client/gpm_wrap.c new file mode 100644 index 0000000..87db78d --- /dev/null +++ b/proxy/src/client/gpm_wrap.c @@ -0,0 +1,123 @@ +/* + GSS-PROXY + + Copyright (C) 2011 Red Hat, Inc. + Copyright (C) 2011 Simo Sorce <simo.sorce@redhat.com> + Copyright (C) 2012 Guenther Deschner <guenther.deschner@redhat.com> + + Permission is hereby granted, free of charge, to any person obtaining a + copy of this software and associated documentation files (the "Software"), + to deal in the Software without restriction, including without limitation + the rights to use, copy, modify, merge, publish, distribute, sublicense, + and/or sell copies of the Software, and to permit persons to whom the + Software is furnished to do so, subject to the following conditions: + + The above copyright notice and this permission notice shall be included in + all copies or substantial portions of the Software. + + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL + THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING + FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER + DEALINGS IN THE SOFTWARE. +*/ + +#include "gssapi_gpm.h" +#include "src/gp_conv.h" + +OM_uint32 gpm_wrap(OM_uint32 *minor_status, + gssx_ctx *context_handle, + int conf_req_flag, + gss_qop_t qop_req, + const gss_buffer_t input_message_buffer, + int *conf_state, + gss_buffer_t output_message_buffer) +{ + union gp_rpc_arg uarg; + union gp_rpc_res ures; + gssx_arg_wrap *arg = &uarg.wrap; + gssx_res_wrap *res = &ures.wrap; + uint32_t ret_min = 0; + uint32_t ret_maj = 0; + int ret = 0; + gssx_buffer message_buffer; + + memset(&uarg, 0, sizeof(union gp_rpc_arg)); + memset(&ures, 0, sizeof(union gp_rpc_res)); + + if (!context_handle) { + return GSS_S_CALL_INACCESSIBLE_READ; + } + + /* format request */ + /* NOTE: the final free will also release the old context */ + arg->context_handle = *context_handle; + arg->conf_req = conf_req_flag; + arg->qop_state = qop_req; + + ret = gp_conv_buffer_to_gssx(input_message_buffer, &message_buffer); + if (ret) { + ret_maj = GSS_S_FAILURE; + ret_min = ret; + goto done; + } + arg->message_buffer.message_buffer_val = calloc(1, sizeof(gssx_buffer)); + if (!arg->message_buffer.message_buffer_val) { + ret_maj = GSS_S_FAILURE; + ret_min = ENOMEM; + goto done; + } + + arg->message_buffer.message_buffer_val[0] = message_buffer; + arg->message_buffer.message_buffer_len = 1; + + /* execute proxy request */ + ret = gpm_make_call(GSSX_WRAP, &uarg, &ures); + if (ret) { + ret_maj = GSS_S_FAILURE; + ret_min = ret; + goto done; + } + + /* format reply */ + if (res->status.major_status) { + gpm_save_status(&res->status); + ret_min = res->status.minor_status; + ret_maj = res->status.major_status; + goto done; + } + + if (conf_state) { + *conf_state = *res->conf_state; + } + + if (res->token_buffer.token_buffer_len > 0) { + ret = gp_copy_gssx_to_buffer(&res->token_buffer.token_buffer_val[0], + output_message_buffer); + if (ret) { + ret_maj = GSS_S_FAILURE; + ret_min = ret; + goto done; + } + } + +done: + /* Steal the new context if available. + * NOTE: We do not want it to be freed by xdr_free, so copy the contents + * and cear up the structure to be freed so contents are not freed. */ + if (res->context_handle) { + *context_handle = *res->context_handle; + memset(res->context_handle, 0, sizeof(gssx_ctx)); + } else { + /* prevent the contexthandle from being destroyed in case of server + * error. */ + memset(&arg->context_handle, 0, sizeof(gssx_ctx)); + } + + gpm_free_xdrs(GSSX_WRAP, &uarg, &ures); + *minor_status = ret_min; + return ret_maj; +} + diff --git a/proxy/src/client/gssapi_gpm.h b/proxy/src/client/gssapi_gpm.h index 2747663..da7c992 100644 --- a/proxy/src/client/gssapi_gpm.h +++ b/proxy/src/client/gssapi_gpm.h @@ -196,5 +196,11 @@ OM_uint32 gpm_verify_mic(OM_uint32 *minor_status, gss_buffer_t message_buffer, gss_buffer_t message_token, gss_qop_t *qop_state); - +OM_uint32 gpm_wrap(OM_uint32 *minor_status, + gssx_ctx *context_handle, + int conf_req_flag, + gss_qop_t qop_req, + const gss_buffer_t input_message_buffer, + int *conf_state, + gss_buffer_t output_message_buffer); #endif /* _GSSAPI_GPM_H_ */ |