xref: /freebsd/crypto/heimdal/lib/kadm5/marshall.c (revision 91db848212e3b95cc689a1e8133a1d550b524919)
1b528cefcSMark Murray /*
2ae771770SStanislav Sedov  * Copyright (c) 1997 - 1999 Kungliga Tekniska Högskolan
3b528cefcSMark Murray  * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray  * All rights reserved.
5b528cefcSMark Murray  *
6b528cefcSMark Murray  * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray  * modification, are permitted provided that the following conditions
8b528cefcSMark Murray  * are met:
9b528cefcSMark Murray  *
10b528cefcSMark Murray  * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray  *
13b528cefcSMark Murray  * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray  *    notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray  *    documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray  *
17b528cefcSMark Murray  * 3. Neither the name of the Institute nor the names of its contributors
18b528cefcSMark Murray  *    may be used to endorse or promote products derived from this software
19b528cefcSMark Murray  *    without specific prior written permission.
20b528cefcSMark Murray  *
21b528cefcSMark Murray  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22b528cefcSMark Murray  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24b528cefcSMark Murray  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25b528cefcSMark Murray  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26b528cefcSMark Murray  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27b528cefcSMark Murray  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28b528cefcSMark Murray  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29b528cefcSMark Murray  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30b528cefcSMark Murray  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31b528cefcSMark Murray  * SUCH DAMAGE.
32b528cefcSMark Murray  */
33b528cefcSMark Murray 
34b528cefcSMark Murray #include "kadm5_locl.h"
35b528cefcSMark Murray 
36ae771770SStanislav Sedov RCSID("$Id$");
37b528cefcSMark Murray 
38b528cefcSMark Murray kadm5_ret_t
39b528cefcSMark Murray kadm5_store_key_data(krb5_storage *sp,
40b528cefcSMark Murray 		     krb5_key_data *key)
41b528cefcSMark Murray {
42b528cefcSMark Murray     krb5_data c;
43b528cefcSMark Murray     krb5_store_int32(sp, key->key_data_ver);
44b528cefcSMark Murray     krb5_store_int32(sp, key->key_data_kvno);
45b528cefcSMark Murray     krb5_store_int32(sp, key->key_data_type[0]);
46b528cefcSMark Murray     c.length = key->key_data_length[0];
47b528cefcSMark Murray     c.data = key->key_data_contents[0];
48b528cefcSMark Murray     krb5_store_data(sp, c);
49b528cefcSMark Murray     krb5_store_int32(sp, key->key_data_type[1]);
50b528cefcSMark Murray     c.length = key->key_data_length[1];
51b528cefcSMark Murray     c.data = key->key_data_contents[1];
52b528cefcSMark Murray     krb5_store_data(sp, c);
53b528cefcSMark Murray     return 0;
54b528cefcSMark Murray }
55b528cefcSMark Murray 
56b528cefcSMark Murray kadm5_ret_t
57b528cefcSMark Murray kadm5_ret_key_data(krb5_storage *sp,
58b528cefcSMark Murray 		   krb5_key_data *key)
59b528cefcSMark Murray {
60b528cefcSMark Murray     krb5_data c;
61b528cefcSMark Murray     int32_t tmp;
62b528cefcSMark Murray     krb5_ret_int32(sp, &tmp);
63b528cefcSMark Murray     key->key_data_ver = tmp;
64b528cefcSMark Murray     krb5_ret_int32(sp, &tmp);
65b528cefcSMark Murray     key->key_data_kvno = tmp;
66b528cefcSMark Murray     krb5_ret_int32(sp, &tmp);
67b528cefcSMark Murray     key->key_data_type[0] = tmp;
68b528cefcSMark Murray     krb5_ret_data(sp, &c);
69b528cefcSMark Murray     key->key_data_length[0] = c.length;
70b528cefcSMark Murray     key->key_data_contents[0] = c.data;
71b528cefcSMark Murray     krb5_ret_int32(sp, &tmp);
72b528cefcSMark Murray     key->key_data_type[1] = tmp;
73b528cefcSMark Murray     krb5_ret_data(sp, &c);
74b528cefcSMark Murray     key->key_data_length[1] = c.length;
75b528cefcSMark Murray     key->key_data_contents[1] = c.data;
76b528cefcSMark Murray     return 0;
77b528cefcSMark Murray }
78b528cefcSMark Murray 
79b528cefcSMark Murray kadm5_ret_t
80b528cefcSMark Murray kadm5_store_tl_data(krb5_storage *sp,
81b528cefcSMark Murray 		    krb5_tl_data *tl)
82b528cefcSMark Murray {
83b528cefcSMark Murray     krb5_data c;
84b528cefcSMark Murray     krb5_store_int32(sp, tl->tl_data_type);
85b528cefcSMark Murray     c.length = tl->tl_data_length;
86b528cefcSMark Murray     c.data = tl->tl_data_contents;
87b528cefcSMark Murray     krb5_store_data(sp, c);
88b528cefcSMark Murray     return 0;
89b528cefcSMark Murray }
90b528cefcSMark Murray 
91b528cefcSMark Murray kadm5_ret_t
92b528cefcSMark Murray kadm5_ret_tl_data(krb5_storage *sp,
93b528cefcSMark Murray 		  krb5_tl_data *tl)
94b528cefcSMark Murray {
95b528cefcSMark Murray     krb5_data c;
96b528cefcSMark Murray     int32_t tmp;
97b528cefcSMark Murray     krb5_ret_int32(sp, &tmp);
98b528cefcSMark Murray     tl->tl_data_type = tmp;
99b528cefcSMark Murray     krb5_ret_data(sp, &c);
100b528cefcSMark Murray     tl->tl_data_length = c.length;
101b528cefcSMark Murray     tl->tl_data_contents = c.data;
102b528cefcSMark Murray     return 0;
103b528cefcSMark Murray }
104b528cefcSMark Murray 
105b528cefcSMark Murray static kadm5_ret_t
106b528cefcSMark Murray store_principal_ent(krb5_storage *sp,
107b528cefcSMark Murray 		    kadm5_principal_ent_t princ,
108c19800e8SDoug Rabson 		    uint32_t mask)
109b528cefcSMark Murray {
110b528cefcSMark Murray     int i;
111b528cefcSMark Murray 
112b528cefcSMark Murray     if (mask & KADM5_PRINCIPAL)
113b528cefcSMark Murray 	krb5_store_principal(sp, princ->principal);
114b528cefcSMark Murray     if (mask & KADM5_PRINC_EXPIRE_TIME)
115b528cefcSMark Murray 	krb5_store_int32(sp, princ->princ_expire_time);
116b528cefcSMark Murray     if (mask & KADM5_PW_EXPIRATION)
117b528cefcSMark Murray 	krb5_store_int32(sp, princ->pw_expiration);
118b528cefcSMark Murray     if (mask & KADM5_LAST_PWD_CHANGE)
119b528cefcSMark Murray 	krb5_store_int32(sp, princ->last_pwd_change);
120b528cefcSMark Murray     if (mask & KADM5_MAX_LIFE)
121b528cefcSMark Murray 	krb5_store_int32(sp, princ->max_life);
122b528cefcSMark Murray     if (mask & KADM5_MOD_NAME) {
123b528cefcSMark Murray 	krb5_store_int32(sp, princ->mod_name != NULL);
124b528cefcSMark Murray 	if(princ->mod_name)
125b528cefcSMark Murray 	    krb5_store_principal(sp, princ->mod_name);
126b528cefcSMark Murray     }
127b528cefcSMark Murray     if (mask & KADM5_MOD_TIME)
128b528cefcSMark Murray 	krb5_store_int32(sp, princ->mod_date);
129b528cefcSMark Murray     if (mask & KADM5_ATTRIBUTES)
130b528cefcSMark Murray 	krb5_store_int32(sp, princ->attributes);
131b528cefcSMark Murray     if (mask & KADM5_KVNO)
132b528cefcSMark Murray 	krb5_store_int32(sp, princ->kvno);
133b528cefcSMark Murray     if (mask & KADM5_MKVNO)
134b528cefcSMark Murray 	krb5_store_int32(sp, princ->mkvno);
135b528cefcSMark Murray     if (mask & KADM5_POLICY) {
136b528cefcSMark Murray 	krb5_store_int32(sp, princ->policy != NULL);
137b528cefcSMark Murray 	if(princ->policy)
138b528cefcSMark Murray 	    krb5_store_string(sp, princ->policy);
139b528cefcSMark Murray     }
140b528cefcSMark Murray     if (mask & KADM5_AUX_ATTRIBUTES)
141b528cefcSMark Murray 	krb5_store_int32(sp, princ->aux_attributes);
142b528cefcSMark Murray     if (mask & KADM5_MAX_RLIFE)
143b528cefcSMark Murray 	krb5_store_int32(sp, princ->max_renewable_life);
144b528cefcSMark Murray     if (mask & KADM5_LAST_SUCCESS)
145b528cefcSMark Murray 	krb5_store_int32(sp, princ->last_success);
146b528cefcSMark Murray     if (mask & KADM5_LAST_FAILED)
147b528cefcSMark Murray 	krb5_store_int32(sp, princ->last_failed);
148b528cefcSMark Murray     if (mask & KADM5_FAIL_AUTH_COUNT)
149b528cefcSMark Murray 	krb5_store_int32(sp, princ->fail_auth_count);
150b528cefcSMark Murray     if (mask & KADM5_KEY_DATA) {
151b528cefcSMark Murray 	krb5_store_int32(sp, princ->n_key_data);
152b528cefcSMark Murray 	for(i = 0; i < princ->n_key_data; i++)
153b528cefcSMark Murray 	    kadm5_store_key_data(sp, &princ->key_data[i]);
154b528cefcSMark Murray     }
155b528cefcSMark Murray     if (mask & KADM5_TL_DATA) {
156b528cefcSMark Murray 	krb5_tl_data *tp;
157b528cefcSMark Murray 
158b528cefcSMark Murray 	krb5_store_int32(sp, princ->n_tl_data);
159b528cefcSMark Murray 	for(tp = princ->tl_data; tp; tp = tp->tl_data_next)
160b528cefcSMark Murray 	    kadm5_store_tl_data(sp, tp);
161b528cefcSMark Murray     }
162b528cefcSMark Murray     return 0;
163b528cefcSMark Murray }
164b528cefcSMark Murray 
165b528cefcSMark Murray 
166b528cefcSMark Murray kadm5_ret_t
167b528cefcSMark Murray kadm5_store_principal_ent(krb5_storage *sp,
168b528cefcSMark Murray 			  kadm5_principal_ent_t princ)
169b528cefcSMark Murray {
170b528cefcSMark Murray     return store_principal_ent (sp, princ, ~0);
171b528cefcSMark Murray }
172b528cefcSMark Murray 
173b528cefcSMark Murray kadm5_ret_t
174b528cefcSMark Murray kadm5_store_principal_ent_mask(krb5_storage *sp,
175b528cefcSMark Murray 			       kadm5_principal_ent_t princ,
176c19800e8SDoug Rabson 			       uint32_t mask)
177b528cefcSMark Murray {
178b528cefcSMark Murray     krb5_store_int32(sp, mask);
179b528cefcSMark Murray     return store_principal_ent (sp, princ, mask);
180b528cefcSMark Murray }
181b528cefcSMark Murray 
182b528cefcSMark Murray static kadm5_ret_t
183b528cefcSMark Murray ret_principal_ent(krb5_storage *sp,
184b528cefcSMark Murray 		  kadm5_principal_ent_t princ,
185c19800e8SDoug Rabson 		  uint32_t mask)
186b528cefcSMark Murray {
187b528cefcSMark Murray     int i;
188b528cefcSMark Murray     int32_t tmp;
189b528cefcSMark Murray 
190b528cefcSMark Murray     if (mask & KADM5_PRINCIPAL)
191b528cefcSMark Murray 	krb5_ret_principal(sp, &princ->principal);
192b528cefcSMark Murray 
193b528cefcSMark Murray     if (mask & KADM5_PRINC_EXPIRE_TIME) {
194b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
195b528cefcSMark Murray 	princ->princ_expire_time = tmp;
196b528cefcSMark Murray     }
197b528cefcSMark Murray     if (mask & KADM5_PW_EXPIRATION) {
198b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
199b528cefcSMark Murray 	princ->pw_expiration = tmp;
200b528cefcSMark Murray     }
201b528cefcSMark Murray     if (mask & KADM5_LAST_PWD_CHANGE) {
202b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
203b528cefcSMark Murray 	princ->last_pwd_change = tmp;
204b528cefcSMark Murray     }
205b528cefcSMark Murray     if (mask & KADM5_MAX_LIFE) {
206b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
207b528cefcSMark Murray 	princ->max_life = tmp;
208b528cefcSMark Murray     }
209b528cefcSMark Murray     if (mask & KADM5_MOD_NAME) {
210b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
211b528cefcSMark Murray 	if(tmp)
212b528cefcSMark Murray 	    krb5_ret_principal(sp, &princ->mod_name);
213b528cefcSMark Murray 	else
214b528cefcSMark Murray 	    princ->mod_name = NULL;
215b528cefcSMark Murray     }
216b528cefcSMark Murray     if (mask & KADM5_MOD_TIME) {
217b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
218b528cefcSMark Murray 	princ->mod_date = tmp;
219b528cefcSMark Murray     }
220b528cefcSMark Murray     if (mask & KADM5_ATTRIBUTES) {
221b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
222b528cefcSMark Murray 	princ->attributes = tmp;
223b528cefcSMark Murray     }
224b528cefcSMark Murray     if (mask & KADM5_KVNO) {
225b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
226b528cefcSMark Murray 	princ->kvno = tmp;
227b528cefcSMark Murray     }
228b528cefcSMark Murray     if (mask & KADM5_MKVNO) {
229b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
230b528cefcSMark Murray 	princ->mkvno = tmp;
231b528cefcSMark Murray     }
232b528cefcSMark Murray     if (mask & KADM5_POLICY) {
233b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
234b528cefcSMark Murray 	if(tmp)
235b528cefcSMark Murray 	    krb5_ret_string(sp, &princ->policy);
236b528cefcSMark Murray 	else
237b528cefcSMark Murray 	    princ->policy = NULL;
238b528cefcSMark Murray     }
239b528cefcSMark Murray     if (mask & KADM5_AUX_ATTRIBUTES) {
240b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
241b528cefcSMark Murray 	princ->aux_attributes = tmp;
242b528cefcSMark Murray     }
243b528cefcSMark Murray     if (mask & KADM5_MAX_RLIFE) {
244b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
245b528cefcSMark Murray 	princ->max_renewable_life = tmp;
246b528cefcSMark Murray     }
247b528cefcSMark Murray     if (mask & KADM5_LAST_SUCCESS) {
248b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
249b528cefcSMark Murray 	princ->last_success = tmp;
250b528cefcSMark Murray     }
251b528cefcSMark Murray     if (mask & KADM5_LAST_FAILED) {
252b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
253b528cefcSMark Murray 	princ->last_failed = tmp;
254b528cefcSMark Murray     }
255b528cefcSMark Murray     if (mask & KADM5_FAIL_AUTH_COUNT) {
256b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
257b528cefcSMark Murray 	princ->fail_auth_count = tmp;
258b528cefcSMark Murray     }
259b528cefcSMark Murray     if (mask & KADM5_KEY_DATA) {
260b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
261b528cefcSMark Murray 	princ->n_key_data = tmp;
262b528cefcSMark Murray 	princ->key_data = malloc(princ->n_key_data * sizeof(*princ->key_data));
263ae771770SStanislav Sedov 	if (princ->key_data == NULL && princ->n_key_data != 0)
264c19800e8SDoug Rabson 	    return ENOMEM;
265b528cefcSMark Murray 	for(i = 0; i < princ->n_key_data; i++)
266b528cefcSMark Murray 	    kadm5_ret_key_data(sp, &princ->key_data[i]);
267b528cefcSMark Murray     }
268b528cefcSMark Murray     if (mask & KADM5_TL_DATA) {
269b528cefcSMark Murray 	krb5_ret_int32(sp, &tmp);
270b528cefcSMark Murray 	princ->n_tl_data = tmp;
271b528cefcSMark Murray 	princ->tl_data = NULL;
272b528cefcSMark Murray 	for(i = 0; i < princ->n_tl_data; i++){
273b528cefcSMark Murray 	    krb5_tl_data *tp = malloc(sizeof(*tp));
274c19800e8SDoug Rabson 	    if (tp == NULL)
275c19800e8SDoug Rabson 		return ENOMEM;
276b528cefcSMark Murray 	    kadm5_ret_tl_data(sp, tp);
277b528cefcSMark Murray 	    tp->tl_data_next = princ->tl_data;
278b528cefcSMark Murray 	    princ->tl_data = tp;
279b528cefcSMark Murray 	}
280b528cefcSMark Murray     }
281b528cefcSMark Murray     return 0;
282b528cefcSMark Murray }
283b528cefcSMark Murray 
284b528cefcSMark Murray kadm5_ret_t
285b528cefcSMark Murray kadm5_ret_principal_ent(krb5_storage *sp,
286b528cefcSMark Murray 			kadm5_principal_ent_t princ)
287b528cefcSMark Murray {
288b528cefcSMark Murray     return ret_principal_ent (sp, princ, ~0);
289b528cefcSMark Murray }
290b528cefcSMark Murray 
291b528cefcSMark Murray kadm5_ret_t
292b528cefcSMark Murray kadm5_ret_principal_ent_mask(krb5_storage *sp,
293b528cefcSMark Murray 			     kadm5_principal_ent_t princ,
294c19800e8SDoug Rabson 			     uint32_t *mask)
295b528cefcSMark Murray {
296b528cefcSMark Murray     int32_t tmp;
297b528cefcSMark Murray 
298b528cefcSMark Murray     krb5_ret_int32 (sp, &tmp);
299b528cefcSMark Murray     *mask = tmp;
300b528cefcSMark Murray     return ret_principal_ent (sp, princ, *mask);
301b528cefcSMark Murray }
302b528cefcSMark Murray 
303b528cefcSMark Murray kadm5_ret_t
304b528cefcSMark Murray _kadm5_marshal_params(krb5_context context,
305b528cefcSMark Murray 		      kadm5_config_params *params,
306b528cefcSMark Murray 		      krb5_data *out)
307b528cefcSMark Murray {
308b528cefcSMark Murray     krb5_storage *sp = krb5_storage_emem();
309b528cefcSMark Murray 
310b528cefcSMark Murray     krb5_store_int32(sp, params->mask & (KADM5_CONFIG_REALM));
311b528cefcSMark Murray 
312b528cefcSMark Murray     if(params->mask & KADM5_CONFIG_REALM)
313b528cefcSMark Murray 	krb5_store_string(sp, params->realm);
314b528cefcSMark Murray     krb5_storage_to_data(sp, out);
315b528cefcSMark Murray     krb5_storage_free(sp);
316b528cefcSMark Murray 
317b528cefcSMark Murray     return 0;
318b528cefcSMark Murray }
319b528cefcSMark Murray 
320b528cefcSMark Murray kadm5_ret_t
321b528cefcSMark Murray _kadm5_unmarshal_params(krb5_context context,
322b528cefcSMark Murray 			krb5_data *in,
323b528cefcSMark Murray 			kadm5_config_params *params)
324b528cefcSMark Murray {
325ae771770SStanislav Sedov     krb5_error_code ret;
326ae771770SStanislav Sedov     krb5_storage *sp;
327c19800e8SDoug Rabson     int32_t mask;
328b528cefcSMark Murray 
329ae771770SStanislav Sedov     sp = krb5_storage_from_data(in);
330ae771770SStanislav Sedov     if (sp == NULL)
331ae771770SStanislav Sedov 	return ENOMEM;
332ae771770SStanislav Sedov 
333ae771770SStanislav Sedov     ret = krb5_ret_int32(sp, &mask);
334ae771770SStanislav Sedov     if (ret)
335ae771770SStanislav Sedov 	goto out;
336*91db8482SCy Schubert     if (mask & KADM5_CONFIG_REALM & KADM5_CONFIG_DBNAME
337*91db8482SCy Schubert 	& KADM5_CONFIG_ACL_FILE & KADM5_CONFIG_STASH_FILE) {
338*91db8482SCy Schubert 	    ret = EINVAL;
339*91db8482SCy Schubert 	    goto out;
340*91db8482SCy Schubert     }
341c19800e8SDoug Rabson     params->mask = mask;
342b528cefcSMark Murray 
34305bc50bdSCy Schubert     if (params->mask & KADM5_CONFIG_REALM) {
344ae771770SStanislav Sedov 	ret = krb5_ret_string(sp, &params->realm);
34505bc50bdSCy Schubert 	if (params->realm == NULL) {
34605bc50bdSCy Schubert 	    ret = EINVAL;
347*91db8482SCy Schubert 	    goto out;
348*91db8482SCy Schubert 	}
349*91db8482SCy Schubert     }
350*91db8482SCy Schubert     if (params->mask & KADM5_CONFIG_DBNAME) {
351*91db8482SCy Schubert 	ret = krb5_ret_string(sp, &params->dbname);
352*91db8482SCy Schubert 	if (params->dbname == NULL) {
353*91db8482SCy Schubert 	    ret = EINVAL;
354*91db8482SCy Schubert 	    goto out;
355*91db8482SCy Schubert 	}
356*91db8482SCy Schubert     }
357*91db8482SCy Schubert     if (params->mask & KADM5_CONFIG_ACL_FILE) {
358*91db8482SCy Schubert 	ret = krb5_ret_string(sp, &params->acl_file);
359*91db8482SCy Schubert 	if (params->acl_file == NULL) {
360*91db8482SCy Schubert 	    ret = EINVAL;
361*91db8482SCy Schubert 	    goto out;
362*91db8482SCy Schubert 	}
363*91db8482SCy Schubert     }
364*91db8482SCy Schubert     if (params->mask & KADM5_CONFIG_STASH_FILE) {
365*91db8482SCy Schubert 	ret = krb5_ret_string(sp, &params->stash_file);
366*91db8482SCy Schubert 	if (params->stash_file == NULL) {
367*91db8482SCy Schubert 	    ret = EINVAL;
36805bc50bdSCy Schubert 	}
36905bc50bdSCy Schubert     }
370ae771770SStanislav Sedov  out:
371b528cefcSMark Murray     krb5_storage_free(sp);
372b528cefcSMark Murray 
373ae771770SStanislav Sedov     return ret;
374b528cefcSMark Murray }
375