xref: /freebsd/crypto/heimdal/lib/krb5/context.c (revision 23f282aa31e9b6fceacd449020e936e98d6f2298)
1 /*
2  * Copyright (c) 1997 - 2000 Kungliga Tekniska H�gskolan
3  * (Royal Institute of Technology, Stockholm, Sweden).
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  *
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  *
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  *
17  * 3. Neither the name of the Institute nor the names of its contributors
18  *    may be used to endorse or promote products derived from this software
19  *    without specific prior written permission.
20  *
21  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  */
33 
34 #include "krb5_locl.h"
35 
36 RCSID("$Id: context.c,v 1.53 2000/02/11 17:43:43 assar Exp $");
37 
38 #define INIT_FIELD(C, T, E, D, F)					\
39     (C)->E = krb5_config_get_ ## T ## _default ((C), NULL, (D), 	\
40 						"libdefaults", F, NULL)
41 
42 #ifdef KRB4
43 extern krb5_kt_ops krb4_fkt_ops;
44 #endif
45 
46 /*
47  * Set the list of etypes `ret_etypes' from the configuration variable
48  * `name'
49  */
50 
51 static krb5_error_code
52 set_etypes (krb5_context context,
53 	    const char *name,
54 	    krb5_enctype **ret_enctypes)
55 {
56     char **etypes_str;
57     krb5_enctype *etypes;
58 
59     etypes_str = krb5_config_get_strings(context, NULL, "libdefaults",
60 					 name, NULL);
61     if(etypes_str){
62 	int i, j, k;
63 	for(i = 0; etypes_str[i]; i++);
64 	etypes = malloc((i+1) * sizeof(*etypes));
65 	if (etypes == NULL) {
66 	    krb5_config_free_strings (etypes_str);
67 	    return ENOMEM;
68 	}
69 	for(j = 0, k = 0; j < i; j++) {
70 	    if(krb5_string_to_enctype(context, etypes_str[j], &etypes[k]) == 0)
71 		k++;
72 	}
73 	etypes[k] = ETYPE_NULL;
74 	krb5_config_free_strings(etypes_str);
75 	*ret_enctypes = etypes;
76     }
77     return 0;
78 }
79 
80 /*
81  * read variables from the configuration file and set in `context'
82  */
83 
84 static krb5_error_code
85 init_context_from_config_file(krb5_context context)
86 {
87     const char * tmp;
88     INIT_FIELD(context, time, max_skew, 5 * 60, "clockskew");
89     INIT_FIELD(context, time, kdc_timeout, 3, "kdc_timeout");
90     INIT_FIELD(context, int, max_retries, 3, "max_retries");
91 
92     context->http_proxy = krb5_config_get_string(context, NULL, "libdefaults",
93 					   "http_proxy", NULL);
94 
95     set_etypes (context, "default_etypes", &context->etypes);
96     set_etypes (context, "default_etypes_des", &context->etypes_des);
97 
98     /* default keytab name */
99     context->default_keytab = krb5_config_get_string(context, NULL,
100 					       "libdefaults",
101 					       "default_keytab_name",
102 					       NULL);
103     if(context->default_keytab == NULL)
104 	context->default_keytab = KEYTAB_DEFAULT;
105 
106     context->time_fmt = krb5_config_get_string(context, NULL, "libdefaults",
107 					 "time_format", NULL);
108     if(context->time_fmt == NULL)
109 	context->time_fmt = "%Y-%m-%dT%H:%M:%S";
110     context->log_utc = krb5_config_get_bool(context, NULL, "libdefaults",
111 					    "log_utc", NULL);
112 
113     /* init dns-proxy slime */
114     tmp = krb5_config_get_string(context, NULL, "libdefaults",
115 				 "dns_proxy", NULL);
116     if(tmp)
117 	roken_gethostby_setup(context->http_proxy, tmp);
118     context->default_realms = NULL;
119 
120     {
121 	krb5_addresses addresses;
122 	char **adr, **a;
123 	adr = krb5_config_get_strings(context, NULL,
124 				      "libdefaults",
125 				      "extra_addresses",
126 				      NULL);
127 	memset(&addresses, 0, sizeof(addresses));
128 	for(a = adr; a && *a; a++) {
129 	    krb5_parse_address(context, *a, &addresses);
130 	    krb5_add_extra_addresses(context, &addresses);
131 	    krb5_free_addresses(context, &addresses);
132 	}
133 	krb5_config_free_strings(adr);
134     }
135 
136     INIT_FIELD(context, bool, scan_interfaces, TRUE, "scan_interfaces");
137     INIT_FIELD(context, bool, srv_lookup, TRUE, "srv_lookup");
138     INIT_FIELD(context, bool, srv_try_txt, FALSE, "srv_try_txt");
139     INIT_FIELD(context, bool, srv_try_rfc2052, TRUE, "srv_try_rfc2052");
140     INIT_FIELD(context, int, fcache_vno, 0, "fcache_version");
141 
142     context->cc_ops       = NULL;
143     context->num_cc_ops	  = 0;
144     krb5_cc_register(context, &krb5_fcc_ops, TRUE);
145     krb5_cc_register(context, &krb5_mcc_ops, TRUE);
146 
147     context->num_kt_types = 0;
148     context->kt_types     = NULL;
149     krb5_kt_register (context, &krb5_fkt_ops);
150     krb5_kt_register (context, &krb5_mkt_ops);
151 #ifdef KRB4
152     krb5_kt_register (context, &krb4_fkt_ops);
153 #endif
154     krb5_kt_register (context, &krb5_akf_ops);
155     return 0;
156 }
157 
158 krb5_error_code
159 krb5_init_context(krb5_context *context)
160 {
161     krb5_context p;
162     const char *config_file = NULL;
163     krb5_config_section *tmp_cf;
164     krb5_error_code ret;
165 
166     ALLOC(p, 1);
167     if(!p)
168 	return ENOMEM;
169     memset(p, 0, sizeof(krb5_context_data));
170 
171     /* init error tables */
172     krb5_init_ets(p);
173 
174     if(!issuid())
175 	config_file = getenv("KRB5_CONFIG");
176     if (config_file == NULL)
177 	config_file = krb5_config_file;
178 
179     ret = krb5_config_parse_file (config_file, &tmp_cf);
180 
181     if (ret == 0)
182 	p->cf = tmp_cf;
183 #if 0
184     else
185 	krb5_warnx (p, "Unable to parse config file %s.  Ignoring.",
186 		    config_file); /* XXX */
187 #endif
188 
189     ret = init_context_from_config_file(p);
190     if(ret)
191 	return ret;
192 
193     *context = p;
194     return 0;
195 }
196 
197 void
198 krb5_free_context(krb5_context context)
199 {
200   int i;
201 
202   free(context->etypes);
203   free(context->etypes_des);
204   krb5_free_host_realm (context, context->default_realms);
205   krb5_config_file_free (context, context->cf);
206   free_error_table (context->et_list);
207   for(i = 0; i < context->num_cc_ops; ++i)
208     free(context->cc_ops[i].prefix);
209   free(context->cc_ops);
210   free(context->kt_types);
211   free(context);
212 }
213 
214 static krb5_error_code
215 default_etypes(krb5_enctype **etype)
216 {
217     krb5_enctype p[] = {
218 	ETYPE_DES3_CBC_SHA1,
219 	ETYPE_DES3_CBC_MD5,
220 	ETYPE_DES_CBC_MD5,
221 	ETYPE_DES_CBC_MD4,
222 	ETYPE_DES_CBC_CRC,
223 	ETYPE_NULL
224     };
225     *etype = malloc(sizeof(p));
226     if(*etype == NULL)
227 	return ENOMEM;
228     memcpy(*etype, p, sizeof(p));
229     return 0;
230 }
231 
232 krb5_error_code
233 krb5_set_default_in_tkt_etypes(krb5_context context,
234 			       const krb5_enctype *etypes)
235 {
236     int i;
237     krb5_enctype *p = NULL;
238 
239     if(etypes) {
240 	i = 0;
241 	while(etypes[i])
242 	    if(!krb5_enctype_valid(context, etypes[i++]))
243 		return KRB5_PROG_ETYPE_NOSUPP;
244 	++i;
245 	ALLOC(p, i);
246 	if(!p)
247 	    return ENOMEM;
248 	memmove(p, etypes, i * sizeof(krb5_enctype));
249     }
250     if(context->etypes)
251 	free(context->etypes);
252     context->etypes = p;
253     return 0;
254 }
255 
256 
257 krb5_error_code
258 krb5_get_default_in_tkt_etypes(krb5_context context,
259 			       krb5_enctype **etypes)
260 {
261   krb5_enctype *p;
262   int i;
263 
264   if(context->etypes) {
265     for(i = 0; context->etypes[i]; i++);
266     ++i;
267     ALLOC(p, i);
268     if(!p)
269       return ENOMEM;
270     memmove(p, context->etypes, i * sizeof(krb5_enctype));
271   } else
272     if(default_etypes(&p))
273       return ENOMEM;
274   *etypes = p;
275   return 0;
276 }
277 
278 const char *
279 krb5_get_err_text(krb5_context context, krb5_error_code code)
280 {
281     const char *p = com_right(context->et_list, code);
282     if(p == NULL)
283 	p = strerror(code);
284     return p;
285 }
286 
287 void
288 krb5_init_ets(krb5_context context)
289 {
290     if(context->et_list == NULL){
291 	initialize_krb5_error_table_r(&context->et_list);
292 	initialize_asn1_error_table_r(&context->et_list);
293 	initialize_heim_error_table_r(&context->et_list);
294     }
295 }
296 
297 void
298 krb5_set_use_admin_kdc (krb5_context context, krb5_boolean flag)
299 {
300     context->use_admin_kdc = flag;
301 }
302 
303 krb5_boolean
304 krb5_get_use_admin_kdc (krb5_context context)
305 {
306     return context->use_admin_kdc;
307 }
308 
309 krb5_error_code
310 krb5_add_extra_addresses(krb5_context context, krb5_addresses *addresses)
311 {
312 
313     if(context->extra_addresses)
314 	return krb5_append_addresses(context,
315 				     context->extra_addresses, addresses);
316     else
317 	return krb5_set_extra_addresses(context, addresses);
318 }
319 
320 krb5_error_code
321 krb5_set_extra_addresses(krb5_context context, const krb5_addresses *addresses)
322 {
323     if(context->extra_addresses) {
324 	krb5_free_addresses(context, context->extra_addresses);
325 	free(context->extra_addresses);
326     }
327     if(context->extra_addresses == NULL) {
328 	context->extra_addresses = malloc(sizeof(*context->extra_addresses));
329 	if(context->extra_addresses == NULL)
330 	    return ENOMEM;
331     }
332     return krb5_copy_addresses(context, addresses, context->extra_addresses);
333 }
334 
335 krb5_error_code
336 krb5_get_extra_addresses(krb5_context context, krb5_addresses *addresses)
337 {
338     if(context->extra_addresses == NULL) {
339 	memset(addresses, 0, sizeof(*addresses));
340 	return 0;
341     }
342     return copy_HostAddresses(context->extra_addresses, addresses);
343 }
344 
345 krb5_error_code
346 krb5_set_fcache_version(krb5_context context, int version)
347 {
348     context->fcache_vno = version;
349     return 0;
350 }
351 
352 krb5_error_code
353 krb5_get_fcache_version(krb5_context context, int *version)
354 {
355     *version = context->fcache_vno;
356     return 0;
357 }
358