1 /* 2 * Copyright (c) 2003-2004 Kungliga Tekniska Högskolan 3 * (Royal Institute of Technology, Stockholm, Sweden). 4 * All rights reserved. 5 * 6 * Redistribution and use in source and binary forms, with or without 7 * modification, are permitted provided that the following conditions 8 * are met: 9 * 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 13 * 2. Redistributions in binary form must reproduce the above copyright 14 * notice, this list of conditions and the following disclaimer in the 15 * documentation and/or other materials provided with the distribution. 16 * 17 * 3. Neither the name of KTH nor the names of its contributors may be 18 * used to endorse or promote products derived from this software without 19 * specific prior written permission. 20 * 21 * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY 22 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 24 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE 25 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 26 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 27 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR 28 * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, 29 * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR 30 * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF 31 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 32 */ 33 34 #ifdef HAVE_CONFIG_H 35 #include <config.h> 36 #endif 37 38 #include <roken.h> 39 #include <stdio.h> 40 #include <stdlib.h> 41 #include <string.h> 42 #include <stdarg.h> 43 #include <gssapi.h> 44 #include <gssapi_krb5.h> 45 #include <gssapi_spnego.h> 46 #include <krb5.h> 47 #include <err.h> 48 #include <getarg.h> 49 50 static int version_flag = 0; 51 static int help_flag = 0; 52 53 static void 54 copy_import(void) 55 { 56 gss_cred_id_t cred1, cred2; 57 OM_uint32 maj_stat, min_stat; 58 gss_name_t name1, name2; 59 OM_uint32 lifetime1, lifetime2; 60 gss_cred_usage_t usage1, usage2; 61 gss_OID_set mechs1, mechs2; 62 krb5_ccache id; 63 krb5_error_code ret; 64 krb5_context context; 65 int equal; 66 67 maj_stat = gss_acquire_cred(&min_stat, GSS_C_NO_NAME, GSS_C_INDEFINITE, 68 GSS_C_NO_OID_SET, GSS_C_INITIATE, 69 &cred1, NULL, NULL); 70 if (maj_stat != GSS_S_COMPLETE) 71 errx(1, "gss_acquire_cred"); 72 73 maj_stat = gss_inquire_cred(&min_stat, cred1, &name1, &lifetime1, 74 &usage1, &mechs1); 75 if (maj_stat != GSS_S_COMPLETE) 76 errx(1, "gss_inquire_cred"); 77 78 ret = krb5_init_context(&context); 79 if (ret) 80 errx(1, "krb5_init_context"); 81 82 ret = krb5_cc_new_unique(context, krb5_cc_type_memory, NULL, &id); 83 if (ret) 84 krb5_err(context, 1, ret, "krb5_cc_new_unique"); 85 86 maj_stat = gss_krb5_copy_ccache(&min_stat, cred1, id); 87 if (maj_stat != GSS_S_COMPLETE) 88 errx(1, "gss_krb5_copy_ccache"); 89 90 maj_stat = gss_krb5_import_cred(&min_stat, id, NULL, NULL, &cred2); 91 if (maj_stat != GSS_S_COMPLETE) 92 errx(1, "gss_krb5_import_cred"); 93 94 maj_stat = gss_inquire_cred(&min_stat, cred2, &name2, &lifetime2, 95 &usage2, &mechs2); 96 if (maj_stat != GSS_S_COMPLETE) 97 errx(1, "gss_inquire_cred 2"); 98 99 maj_stat = gss_compare_name(&min_stat, name1, name2, &equal); 100 if (maj_stat != GSS_S_COMPLETE) 101 errx(1, "gss_compare_name"); 102 if (!equal) 103 errx(1, "names not equal"); 104 105 if (lifetime1 != lifetime2) 106 errx(1, "lifetime not equal %lu != %lu", 107 (unsigned long)lifetime1, (unsigned long)lifetime2); 108 109 if (usage1 != usage2) { 110 /* as long any of them is both are everything it ok */ 111 if (usage1 != GSS_C_BOTH && usage2 != GSS_C_BOTH) 112 errx(1, "usages disjoined"); 113 } 114 115 gss_release_name(&min_stat, &name2); 116 gss_release_oid_set(&min_stat, &mechs2); 117 118 maj_stat = gss_inquire_cred(&min_stat, cred2, &name2, &lifetime2, 119 &usage2, &mechs2); 120 if (maj_stat != GSS_S_COMPLETE) 121 errx(1, "gss_inquire_cred"); 122 123 maj_stat = gss_compare_name(&min_stat, name1, name2, &equal); 124 if (maj_stat != GSS_S_COMPLETE) 125 errx(1, "gss_compare_name"); 126 if (!equal) 127 errx(1, "names not equal"); 128 129 if (lifetime1 != lifetime2) 130 errx(1, "lifetime not equal %lu != %lu", 131 (unsigned long)lifetime1, (unsigned long)lifetime2); 132 133 gss_release_cred(&min_stat, &cred1); 134 gss_release_cred(&min_stat, &cred2); 135 136 gss_release_name(&min_stat, &name1); 137 gss_release_name(&min_stat, &name2); 138 139 #if 0 140 compare(mechs1, mechs2); 141 #endif 142 143 gss_release_oid_set(&min_stat, &mechs1); 144 gss_release_oid_set(&min_stat, &mechs2); 145 146 krb5_cc_destroy(context, id); 147 krb5_free_context(context); 148 } 149 150 static struct getargs args[] = { 151 {"version", 0, arg_flag, &version_flag, "print version", NULL }, 152 {"help", 0, arg_flag, &help_flag, NULL, NULL } 153 }; 154 155 static void 156 usage (int ret) 157 { 158 arg_printusage (args, sizeof(args)/sizeof(*args), 159 NULL, ""); 160 exit (ret); 161 } 162 163 int 164 main(int argc, char **argv) 165 { 166 int optidx = 0; 167 168 setprogname(argv[0]); 169 if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx)) 170 usage(1); 171 172 if (help_flag) 173 usage (0); 174 175 if(version_flag){ 176 print_version(NULL); 177 exit(0); 178 } 179 180 argc -= optidx; 181 argv += optidx; 182 183 copy_import(); 184 185 return 0; 186 } 187