1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov * Copyright (c) 1997 - 2000, 2007 Kungliga Tekniska Högskolan
3b528cefcSMark Murray * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray * All rights reserved.
5b528cefcSMark Murray *
6b528cefcSMark Murray * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray * modification, are permitted provided that the following conditions
8b528cefcSMark Murray * are met:
9b528cefcSMark Murray *
10b528cefcSMark Murray * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray * notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray *
13b528cefcSMark Murray * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray * notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray * documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray *
17b528cefcSMark Murray * 3. Neither the name of the Institute nor the names of its contributors
18b528cefcSMark Murray * may be used to endorse or promote products derived from this software
19b528cefcSMark Murray * without specific prior written permission.
20b528cefcSMark Murray *
21b528cefcSMark Murray * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22b528cefcSMark Murray * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24b528cefcSMark Murray * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25b528cefcSMark Murray * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26b528cefcSMark Murray * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27b528cefcSMark Murray * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28b528cefcSMark Murray * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29b528cefcSMark Murray * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30b528cefcSMark Murray * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31b528cefcSMark Murray * SUCH DAMAGE.
32b528cefcSMark Murray */
33b528cefcSMark Murray
34b528cefcSMark Murray #include "test_locl.h"
35*ae771770SStanislav Sedov RCSID("$Id$");
36b528cefcSMark Murray
37b528cefcSMark Murray krb5_context context;
38b528cefcSMark Murray
39b528cefcSMark Murray static int
proto(int sock,const char * service)40b528cefcSMark Murray proto (int sock, const char *service)
41b528cefcSMark Murray {
42b528cefcSMark Murray struct sockaddr_in remote, local;
435e9cd1aeSAssar Westerlund socklen_t addrlen;
44b528cefcSMark Murray krb5_address remote_addr, local_addr;
45b528cefcSMark Murray krb5_ccache ccache;
46b528cefcSMark Murray krb5_auth_context auth_context;
47b528cefcSMark Murray krb5_error_code status;
48b528cefcSMark Murray krb5_data packet;
49b528cefcSMark Murray krb5_data data;
50b528cefcSMark Murray krb5_data client_name;
51b528cefcSMark Murray krb5_creds in_creds, *out_creds;
52b528cefcSMark Murray
53b528cefcSMark Murray addrlen = sizeof(local);
54b528cefcSMark Murray if (getsockname (sock, (struct sockaddr *)&local, &addrlen) < 0
55b528cefcSMark Murray || addrlen != sizeof(local))
56b528cefcSMark Murray err (1, "getsockname)");
57b528cefcSMark Murray
58b528cefcSMark Murray addrlen = sizeof(remote);
59b528cefcSMark Murray if (getpeername (sock, (struct sockaddr *)&remote, &addrlen) < 0
60b528cefcSMark Murray || addrlen != sizeof(remote))
61b528cefcSMark Murray err (1, "getpeername");
62b528cefcSMark Murray
63b528cefcSMark Murray status = krb5_auth_con_init (context, &auth_context);
64b528cefcSMark Murray if (status)
65*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_auth_con_init");
66b528cefcSMark Murray
67b528cefcSMark Murray local_addr.addr_type = AF_INET;
68b528cefcSMark Murray local_addr.address.length = sizeof(local.sin_addr);
69b528cefcSMark Murray local_addr.address.data = &local.sin_addr;
70b528cefcSMark Murray
71b528cefcSMark Murray remote_addr.addr_type = AF_INET;
72b528cefcSMark Murray remote_addr.address.length = sizeof(remote.sin_addr);
73b528cefcSMark Murray remote_addr.address.data = &remote.sin_addr;
74b528cefcSMark Murray
75b528cefcSMark Murray status = krb5_auth_con_setaddrs (context,
76b528cefcSMark Murray auth_context,
77b528cefcSMark Murray &local_addr,
78b528cefcSMark Murray &remote_addr);
79b528cefcSMark Murray if (status)
80*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_auth_con_setaddr");
81b528cefcSMark Murray
82b528cefcSMark Murray status = krb5_read_message(context, &sock, &client_name);
83b528cefcSMark Murray if(status)
84b528cefcSMark Murray krb5_err(context, 1, status, "krb5_read_message");
85b528cefcSMark Murray
86b528cefcSMark Murray memset(&in_creds, 0, sizeof(in_creds));
87b528cefcSMark Murray status = krb5_cc_default(context, &ccache);
88*ae771770SStanislav Sedov if(status)
89*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_cc_default");
90b528cefcSMark Murray status = krb5_cc_get_principal(context, ccache, &in_creds.client);
91*ae771770SStanislav Sedov if(status)
92*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_cc_get_principal");
93b528cefcSMark Murray
94b528cefcSMark Murray status = krb5_read_message(context, &sock, &in_creds.second_ticket);
95b528cefcSMark Murray if(status)
96b528cefcSMark Murray krb5_err(context, 1, status, "krb5_read_message");
97b528cefcSMark Murray
98b528cefcSMark Murray status = krb5_parse_name(context, client_name.data, &in_creds.server);
99b528cefcSMark Murray if(status)
100b528cefcSMark Murray krb5_err(context, 1, status, "krb5_parse_name");
101b528cefcSMark Murray
102b528cefcSMark Murray status = krb5_get_credentials(context, KRB5_GC_USER_USER, ccache,
103b528cefcSMark Murray &in_creds, &out_creds);
104b528cefcSMark Murray if(status)
105b528cefcSMark Murray krb5_err(context, 1, status, "krb5_get_credentials");
106b528cefcSMark Murray
107b528cefcSMark Murray status = krb5_cc_default(context, &ccache);
108*ae771770SStanislav Sedov if(status)
109*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_cc_default");
110b528cefcSMark Murray
111b528cefcSMark Murray status = krb5_sendauth(context,
112b528cefcSMark Murray &auth_context,
113b528cefcSMark Murray &sock,
114b528cefcSMark Murray VERSION,
115b528cefcSMark Murray in_creds.client,
116b528cefcSMark Murray in_creds.server,
117b528cefcSMark Murray AP_OPTS_USE_SESSION_KEY,
118b528cefcSMark Murray NULL,
119b528cefcSMark Murray out_creds,
120b528cefcSMark Murray ccache,
121b528cefcSMark Murray NULL,
122b528cefcSMark Murray NULL,
123b528cefcSMark Murray NULL);
124b528cefcSMark Murray
125b528cefcSMark Murray if (status)
126b528cefcSMark Murray krb5_err(context, 1, status, "krb5_sendauth");
127b528cefcSMark Murray
128c19800e8SDoug Rabson {
129c19800e8SDoug Rabson char *str;
130c19800e8SDoug Rabson krb5_unparse_name(context, in_creds.server, &str);
131c19800e8SDoug Rabson printf ("User is `%s'\n", str);
132c19800e8SDoug Rabson free(str);
133c19800e8SDoug Rabson krb5_unparse_name(context, in_creds.client, &str);
134c19800e8SDoug Rabson printf ("Server is `%s'\n", str);
135c19800e8SDoug Rabson free(str);
136c19800e8SDoug Rabson }
137b528cefcSMark Murray
138b528cefcSMark Murray krb5_data_zero (&data);
139b528cefcSMark Murray krb5_data_zero (&packet);
140b528cefcSMark Murray
141b528cefcSMark Murray status = krb5_read_message(context, &sock, &packet);
142b528cefcSMark Murray if(status)
143b528cefcSMark Murray krb5_err(context, 1, status, "krb5_read_message");
144b528cefcSMark Murray
145b528cefcSMark Murray status = krb5_rd_safe (context,
146b528cefcSMark Murray auth_context,
147b528cefcSMark Murray &packet,
148b528cefcSMark Murray &data,
149b528cefcSMark Murray NULL);
150b528cefcSMark Murray if (status)
151*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_rd_safe");
152b528cefcSMark Murray
153c19800e8SDoug Rabson printf ("safe packet: %.*s\n", (int)data.length,
154b528cefcSMark Murray (char *)data.data);
155b528cefcSMark Murray
156b528cefcSMark Murray status = krb5_read_message(context, &sock, &packet);
157b528cefcSMark Murray if(status)
158b528cefcSMark Murray krb5_err(context, 1, status, "krb5_read_message");
159b528cefcSMark Murray
160b528cefcSMark Murray status = krb5_rd_priv (context,
161b528cefcSMark Murray auth_context,
162b528cefcSMark Murray &packet,
163b528cefcSMark Murray &data,
164b528cefcSMark Murray NULL);
165b528cefcSMark Murray if (status)
166*ae771770SStanislav Sedov krb5_err(context, 1, status, "krb5_rd_priv");
167b528cefcSMark Murray
168c19800e8SDoug Rabson printf ("priv packet: %.*s\n", (int)data.length,
169b528cefcSMark Murray (char *)data.data);
170b528cefcSMark Murray
171b528cefcSMark Murray return 0;
172b528cefcSMark Murray }
173b528cefcSMark Murray
174b528cefcSMark Murray static int
doit(int port,const char * service)175b528cefcSMark Murray doit (int port, const char *service)
176b528cefcSMark Murray {
177b528cefcSMark Murray int sock, sock2;
178b528cefcSMark Murray struct sockaddr_in my_addr;
179b528cefcSMark Murray int one = 1;
180b528cefcSMark Murray
181b528cefcSMark Murray sock = socket (AF_INET, SOCK_STREAM, 0);
182b528cefcSMark Murray if (sock < 0)
183b528cefcSMark Murray err (1, "socket");
184b528cefcSMark Murray
185b528cefcSMark Murray memset (&my_addr, 0, sizeof(my_addr));
186b528cefcSMark Murray my_addr.sin_family = AF_INET;
187b528cefcSMark Murray my_addr.sin_port = port;
188b528cefcSMark Murray my_addr.sin_addr.s_addr = INADDR_ANY;
189b528cefcSMark Murray
190b528cefcSMark Murray if (setsockopt (sock, SOL_SOCKET, SO_REUSEADDR,
191b528cefcSMark Murray (void *)&one, sizeof(one)) < 0)
192b528cefcSMark Murray warn ("setsockopt SO_REUSEADDR");
193b528cefcSMark Murray
194b528cefcSMark Murray if (bind (sock, (struct sockaddr *)&my_addr, sizeof(my_addr)) < 0)
195b528cefcSMark Murray err (1, "bind");
196b528cefcSMark Murray
197b528cefcSMark Murray if (listen (sock, 1) < 0)
198b528cefcSMark Murray err (1, "listen");
199b528cefcSMark Murray
200b528cefcSMark Murray sock2 = accept (sock, NULL, NULL);
201b528cefcSMark Murray if (sock2 < 0)
202b528cefcSMark Murray err (1, "accept");
203b528cefcSMark Murray
204b528cefcSMark Murray return proto (sock2, service);
205b528cefcSMark Murray }
206b528cefcSMark Murray
207b528cefcSMark Murray int
main(int argc,char ** argv)208b528cefcSMark Murray main(int argc, char **argv)
209b528cefcSMark Murray {
210b528cefcSMark Murray int port = server_setup(&context, argc, argv);
211b528cefcSMark Murray return doit (port, service);
212b528cefcSMark Murray }
213