xref: /titanic_41/usr/src/cmd/krb5/krb5kdc/policy.c (revision 56a424cca6b3f91f31bdab72a4626c48c779fe8b)
1 /*
2  * kdc/policy.c
3  *
4  * Copyright 1990 by the Massachusetts Institute of Technology.
5  *
6  * Export of this software from the United States of America may
7  *   require a specific license from the United States Government.
8  *   It is the responsibility of any person or organization contemplating
9  *   export to obtain such a license before exporting.
10  *
11  * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
12  * distribute this software and its documentation for any purpose and
13  * without fee is hereby granted, provided that the above copyright
14  * notice appear in all copies and that both that copyright notice and
15  * this permission notice appear in supporting documentation, and that
16  * the name of M.I.T. not be used in advertising or publicity pertaining
17  * to distribution of the software without specific, written prior
18  * permission.  Furthermore if you modify this software you must label
19  * your software as modified software and not distribute it in such a
20  * fashion that it might be confused with the original M.I.T. software.
21  * M.I.T. makes no representations about the suitability of
22  * this software for any purpose.  It is provided "as is" without express
23  * or implied warranty.
24  *
25  *
26  * Policy decision routines for KDC.
27  */
28 
29 #pragma ident	"%Z%%M%	%I%	%E% SMI"
30 
31 
32 #include "k5-int.h"
33 #include "kdc_util.h"
34 
35 int
against_local_policy_as(register krb5_kdc_req * request,krb5_db_entry client,krb5_db_entry server,krb5_timestamp kdc_time,const char ** status)36 against_local_policy_as(register krb5_kdc_req *request, krb5_db_entry client,
37 			krb5_db_entry server, krb5_timestamp kdc_time,
38 			const char **status)
39 {
40 #if 0
41      /* An AS request must include the addresses field */
42     if (request->addresses == 0) {
43 	*status = "NO ADDRESS";
44 	return KRB5KDC_ERR_POLICY;
45     }
46 #endif
47 
48     return 0;			/* not against policy */
49 }
50 
51 /*
52  * This is where local policy restrictions for the TGS should placed.
53  */
54 krb5_error_code
against_local_policy_tgs(register krb5_kdc_req * request,krb5_db_entry server,krb5_ticket * ticket,const char ** status)55 against_local_policy_tgs(register krb5_kdc_req *request, krb5_db_entry server,
56 			 krb5_ticket *ticket, const char **status)
57 {
58 #if 0
59     /*
60      * For example, if your site wants to disallow ticket forwarding,
61      * you might do something like this:
62      */
63 
64     if (isflagset(request->kdc_options, KDC_OPT_FORWARDED)) {
65 	*status = "FORWARD POLICY";
66 	return KRB5KDC_ERR_POLICY;
67     }
68 #endif
69 
70     return 0;				/* not against policy */
71 }
72 
73 
74 
75 
76 
77 
78 
79