1 /* 2 * Copyright (c) 1997 - 2001 Kungliga Tekniska H�gskolan 3 * (Royal Institute of Technology, Stockholm, Sweden). 4 * All rights reserved. 5 * 6 * Redistribution and use in source and binary forms, with or without 7 * modification, are permitted provided that the following conditions 8 * are met: 9 * 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 13 * 2. Redistributions in binary form must reproduce the above copyright 14 * notice, this list of conditions and the following disclaimer in the 15 * documentation and/or other materials provided with the distribution. 16 * 17 * 3. Neither the name of the Institute nor the names of its contributors 18 * may be used to endorse or promote products derived from this software 19 * without specific prior written permission. 20 * 21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31 * SUCH DAMAGE. 32 */ 33 34 #include "ktutil_locl.h" 35 36 RCSID("$Id: copy.c,v 1.7 2001/05/11 00:54:01 assar Exp $"); 37 38 39 static krb5_boolean 40 compare_keyblock(const krb5_keyblock *a, const krb5_keyblock *b) 41 { 42 if(a->keytype != b->keytype || 43 a->keyvalue.length != b->keyvalue.length || 44 memcmp(a->keyvalue.data, b->keyvalue.data, a->keyvalue.length) != 0) 45 return FALSE; 46 return TRUE; 47 } 48 49 static int 50 kt_copy_int (const char *from, const char *to) 51 { 52 krb5_error_code ret; 53 krb5_keytab src_keytab, dst_keytab; 54 krb5_kt_cursor cursor; 55 krb5_keytab_entry entry, dummy; 56 57 ret = krb5_kt_resolve (context, from, &src_keytab); 58 if (ret) { 59 krb5_warn (context, ret, "resolving src keytab `%s'", from); 60 return 1; 61 } 62 63 ret = krb5_kt_resolve (context, to, &dst_keytab); 64 if (ret) { 65 krb5_kt_close (context, src_keytab); 66 krb5_warn (context, ret, "resolving dst keytab `%s'", to); 67 return 1; 68 } 69 70 ret = krb5_kt_start_seq_get (context, src_keytab, &cursor); 71 if (ret) { 72 krb5_warn (context, ret, "krb5_kt_start_seq_get %s", keytab_string); 73 goto out; 74 } 75 76 if (verbose_flag) 77 fprintf(stderr, "copying %s to %s\n", from, to); 78 79 while((ret = krb5_kt_next_entry(context, src_keytab, 80 &entry, &cursor)) == 0) { 81 char *name_str; 82 char *etype_str; 83 krb5_unparse_name (context, entry.principal, &name_str); 84 krb5_enctype_to_string(context, entry.keyblock.keytype, &etype_str); 85 ret = krb5_kt_get_entry(context, dst_keytab, 86 entry.principal, 87 entry.vno, 88 entry.keyblock.keytype, 89 &dummy); 90 if(ret == 0) { 91 /* this entry is already in the new keytab, so no need to 92 copy it; if the keyblocks are not the same, something 93 is weird, so complain about that */ 94 if(!compare_keyblock(&entry.keyblock, &dummy.keyblock)) { 95 krb5_warnx(context, "entry with different keyvalue " 96 "already exists for %s, keytype %s, kvno %d", 97 name_str, etype_str, entry.vno); 98 } 99 krb5_kt_free_entry(context, &dummy); 100 krb5_kt_free_entry (context, &entry); 101 free(name_str); 102 free(etype_str); 103 continue; 104 } else if(ret != KRB5_KT_NOTFOUND) { 105 krb5_warn(context, ret, "krb5_kt_get_entry(%s)", name_str); 106 krb5_kt_free_entry (context, &entry); 107 free(name_str); 108 free(etype_str); 109 break; 110 } 111 if (verbose_flag) 112 fprintf (stderr, "copying %s, keytype %s, kvno %d\n", name_str, 113 etype_str, entry.vno); 114 ret = krb5_kt_add_entry (context, dst_keytab, &entry); 115 krb5_kt_free_entry (context, &entry); 116 if (ret) { 117 krb5_warn (context, ret, "krb5_kt_add_entry(%s)", name_str); 118 free(name_str); 119 free(etype_str); 120 break; 121 } 122 free(name_str); 123 free(etype_str); 124 } 125 krb5_kt_end_seq_get (context, src_keytab, &cursor); 126 127 out: 128 krb5_kt_close (context, src_keytab); 129 krb5_kt_close (context, dst_keytab); 130 return 0; 131 } 132 133 int 134 kt_copy (int argc, char **argv) 135 { 136 int help_flag = 0; 137 int optind = 0; 138 139 struct getargs args[] = { 140 { "help", 'h', arg_flag, NULL} 141 }; 142 143 int num_args = sizeof(args) / sizeof(args[0]); 144 int i = 0; 145 146 args[i++].value = &help_flag; 147 args[i++].value = &verbose_flag; 148 149 if(getarg(args, num_args, argc, argv, &optind)) { 150 arg_printusage(args, num_args, "ktutil copy", 151 "keytab-src keytab-dest"); 152 return 1; 153 } 154 if (help_flag) { 155 arg_printusage(args, num_args, "ktutil copy", 156 "keytab-src keytab-dest"); 157 return 1; 158 } 159 160 argv += optind; 161 argc -= optind; 162 163 if (argc != 2) { 164 arg_printusage(args, num_args, "ktutil copy", 165 "keytab-src keytab-dest"); 166 return 1; 167 } 168 169 return kt_copy_int(argv[0], argv[1]); 170 } 171 172 #ifndef KEYFILE 173 #define KEYFILE "/etc/srvtab" 174 #endif 175 176 /* copy to from v4 srvtab, just short for copy */ 177 static int 178 conv(int srvconv, int argc, char **argv) 179 { 180 int help_flag = 0; 181 char *srvtab = KEYFILE; 182 int optind = 0; 183 char kt4[1024], kt5[1024]; 184 185 char *name; 186 187 struct getargs args[] = { 188 { "srvtab", 's', arg_string, NULL}, 189 { "help", 'h', arg_flag, NULL} 190 }; 191 192 int num_args = sizeof(args) / sizeof(args[0]); 193 int i = 0; 194 195 args[i++].value = &srvtab; 196 args[i++].value = &help_flag; 197 198 if(srvconv) 199 name = "ktutil srvconvert"; 200 else 201 name = "ktutil srvcreate"; 202 203 if(getarg(args, num_args, argc, argv, &optind)){ 204 arg_printusage(args, num_args, name, ""); 205 return 1; 206 } 207 if(help_flag){ 208 arg_printusage(args, num_args, name, ""); 209 return 0; 210 } 211 212 argc -= optind; 213 argv += optind; 214 215 if (argc != 0) { 216 arg_printusage(args, num_args, name, ""); 217 return 1; 218 } 219 220 snprintf(kt4, sizeof(kt4), "krb4:%s", srvtab); 221 222 if(srvconv) { 223 if(keytab_string != NULL) 224 return kt_copy_int(kt4, keytab_string); 225 else { 226 krb5_kt_default_modify_name(context, kt5, sizeof(kt5)); 227 return kt_copy_int(kt4, kt5); 228 } 229 } else { 230 if(keytab_string != NULL) 231 return kt_copy_int(keytab_string, kt4); 232 233 krb5_kt_default_name(context, kt5, sizeof(kt5)); 234 return kt_copy_int(kt5, kt4); 235 } 236 } 237 238 int 239 srvconv(int argc, char **argv) 240 { 241 return conv(1, argc, argv); 242 } 243 244 int 245 srvcreate(int argc, char **argv) 246 { 247 return conv(0, argc, argv); 248 } 249