summaryrefslogtreecommitdiffstats
path: root/src/lib/krb5/keytab
diff options
context:
space:
mode:
Diffstat (limited to 'src/lib/krb5/keytab')
-rw-r--r--src/lib/krb5/keytab/ktfns.c23
-rw-r--r--src/lib/krb5/keytab/t_keytab.c6
2 files changed, 29 insertions, 0 deletions
diff --git a/src/lib/krb5/keytab/ktfns.c b/src/lib/krb5/keytab/ktfns.c
index ecf0acfc5..e0c411efe 100644
--- a/src/lib/krb5/keytab/ktfns.c
+++ b/src/lib/krb5/keytab/ktfns.c
@@ -98,6 +98,29 @@ krb5_kt_end_seq_get(krb5_context context, krb5_keytab keytab,
return krb5_x((keytab)->ops->end_get,(context, keytab, cursor));
}
+krb5_error_code KRB5_CALLCONV
+krb5_kt_have_content(krb5_context context, krb5_keytab keytab)
+{
+ krb5_keytab_entry entry;
+ krb5_kt_cursor cursor;
+ krb5_error_code ret;
+
+ /* If the keytab is not iterable, assume that it has content. */
+ if (keytab->ops->start_seq_get == NULL)
+ return 0;
+
+ /* See if we can get at least one entry via iteration. */
+ ret = krb5_kt_start_seq_get(context, keytab, &cursor);
+ if (ret)
+ return KRB5_KT_NOTFOUND;
+ ret = krb5_kt_next_entry(context, keytab, &entry, &cursor);
+ krb5_kt_end_seq_get(context, keytab, &cursor);
+ if (ret)
+ return KRB5_KT_NOTFOUND;
+ krb5_kt_free_entry(context, &entry);
+ return 0;
+}
+
/*
* In a couple of places we need to get a principal name from a keytab: when
* verifying credentials against a keytab, and when querying the name of a
diff --git a/src/lib/krb5/keytab/t_keytab.c b/src/lib/krb5/keytab/t_keytab.c
index 6b64d52f4..80a94eafe 100644
--- a/src/lib/krb5/keytab/t_keytab.c
+++ b/src/lib/krb5/keytab/t_keytab.c
@@ -132,6 +132,9 @@ kt_test(krb5_context context, const char *name)
CHECK_ERR(kret, KRB5_KT_NOTFOUND, "Getting non-existent entry");
}
+ kret = krb5_kt_have_content(context, kt);
+ CHECK_ERR(kret, KRB5_KT_NOTFOUND, "Checking for keytab content (empty)");
+
/* =================== Add entries to keytab ================= */
/*
@@ -169,6 +172,9 @@ kt_test(krb5_context context, const char *name)
/* ============== Test iterating over contents of keytab ========= */
+ kret = krb5_kt_have_content(context, kt);
+ CHECK(kret, "Checking for keytab content (full)");
+
kret = krb5_kt_start_seq_get(context, kt, &cursor);
CHECK(kret, "Start sequence get");