blob: ce7cb5786dbb2477fb7571c5aeaaa605cb23ed18 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
|
#ifndef KRB5_UTIL_H
#define KRB5_UTIL_H
#include <krb5.h>
/*
* List of principals from our keytab that we
* will try to use to obtain credentials
* (known as a principal list entry (ple))
*/
struct gssd_k5_kt_princ {
struct gssd_k5_kt_princ *next;
krb5_principal princ;
char *ccname;
char *realm;
krb5_timestamp endtime;
};
void gssd_setup_krb5_user_gss_ccache(uid_t uid, char *servername);
int gssd_get_krb5_machine_cred_list(char ***list);
int gssd_refresh_krb5_machine_creds(void);
void gssd_free_krb5_machine_cred_list(char **list);
void gssd_setup_krb5_machine_gss_ccache(char *servername);
void gssd_destroy_krb5_machine_creds(void);
int gssd_refresh_krb5_machine_credential(char *hostname,
struct gssd_k5_kt_princ *ple);
#ifdef HAVE_SET_ALLOWABLE_ENCTYPES
int limit_krb5_enctypes(struct rpc_gss_sec *sec, uid_t uid);
#endif
/*
* Hide away some of the MIT vs. Heimdal differences
* here with macros...
*/
#ifdef HAVE_KRB5
#define k5_free_unparsed_name(ctx, name) krb5_free_unparsed_name((ctx), (name))
#define k5_free_default_realm(ctx, realm) krb5_free_default_realm((ctx), (realm))
#define k5_free_kt_entry(ctx, kte) krb5_free_keytab_entry_contents((ctx),(kte))
#else /* Heimdal */
#define k5_free_unparsed_name(ctx, name) free(name)
#define k5_free_default_realm(ctx, realm) free(realm)
#define k5_free_kt_entry(ctx, kte) krb5_kt_free_entry((ctx),(kte))
#endif
#endif /* KRB5_UTIL_H */
|