summaryrefslogtreecommitdiffstats
path: root/src/lib/krb5/krb/rd_rep.c
diff options
context:
space:
mode:
Diffstat (limited to 'src/lib/krb5/krb/rd_rep.c')
-rw-r--r--src/lib/krb5/krb/rd_rep.c86
1 files changed, 86 insertions, 0 deletions
diff --git a/src/lib/krb5/krb/rd_rep.c b/src/lib/krb5/krb/rd_rep.c
index 901de4338..1e6e0e1e8 100644
--- a/src/lib/krb5/krb/rd_rep.c
+++ b/src/lib/krb5/krb/rd_rep.c
@@ -26,6 +26,33 @@
*
* krb5_rd_rep()
*/
+/*
+ * Copyright (c) 2006-2008, Novell, Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions are met:
+ *
+ * * Redistributions of source code must retain the above copyright notice,
+ * this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ * * The copyright holder's name is not used to endorse or promote products
+ * derived from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
+ * POSSIBILITY OF SUCH DAMAGE.
+ */
#include "k5-int.h"
#include "auth_con.h"
@@ -102,6 +129,8 @@ krb5_rd_rep(krb5_context context, krb5_auth_context auth_context,
krb5_free_keyblock(context, auth_context->send_subkey);
auth_context->send_subkey = NULL;
}
+ /* not used for anything yet */
+ auth_context->negotiated_etype = (*repl)->subkey->enctype;
}
/* Get remote sequence number */
@@ -114,3 +143,60 @@ clean_scratch:
free(scratch.data);
return retval;
}
+
+krb5_error_code KRB5_CALLCONV
+krb5_rd_rep_dce(krb5_context context, krb5_auth_context auth_context,
+ const krb5_data *inbuf, krb5_ui_4 *nonce)
+{
+ krb5_error_code retval;
+ krb5_ap_rep * reply;
+ krb5_data scratch;
+ krb5_ap_rep_enc_part *repl;
+
+ if (!krb5_is_ap_rep(inbuf))
+ return KRB5KRB_AP_ERR_MSG_TYPE;
+
+ /* decode it */
+
+ if ((retval = decode_krb5_ap_rep(inbuf, &reply)))
+ return retval;
+
+ /* put together an eblock for this encryption */
+
+ scratch.length = reply->enc_part.ciphertext.length;
+ if (!(scratch.data = malloc(scratch.length))) {
+ krb5_free_ap_rep(context, reply);
+ return(ENOMEM);
+ }
+
+ if ((retval = krb5_c_decrypt(context, auth_context->keyblock,
+ KRB5_KEYUSAGE_AP_REP_ENCPART, 0,
+ &reply->enc_part, &scratch)))
+ goto clean_scratch;
+
+ /* now decode the decrypted stuff */
+ retval = decode_krb5_ap_rep_enc_part(&scratch, &repl);
+ if (retval)
+ goto clean_scratch;
+
+ *nonce = repl->seq_number;
+ if (*nonce != auth_context->local_seq_number) {
+ retval = KRB5_MUTUAL_FAILED;
+ goto clean_scratch;
+ }
+
+ /* Must be NULL to prevent echoing for client AP-REP */
+ if (repl->subkey != NULL) {
+ retval = KRB5_MUTUAL_FAILED;
+ goto clean_scratch;
+ }
+
+clean_scratch:
+ memset(scratch.data, 0, scratch.length);
+
+ if (repl != NULL)
+ krb5_free_ap_rep_enc_part(context, repl);
+ krb5_free_ap_rep(context, reply);
+ free(scratch.data);
+ return retval;
+}