1c0b9f4feSDoug Rabson.\" -*- nroff -*- 2c0b9f4feSDoug Rabson.\" 3c0b9f4feSDoug Rabson.\" Copyright (c) 2005 Doug Rabson 4c0b9f4feSDoug Rabson.\" All rights reserved. 5c0b9f4feSDoug Rabson.\" 6c0b9f4feSDoug Rabson.\" Redistribution and use in source and binary forms, with or without 7c0b9f4feSDoug Rabson.\" modification, are permitted provided that the following conditions 8c0b9f4feSDoug Rabson.\" are met: 9c0b9f4feSDoug Rabson.\" 1. Redistributions of source code must retain the above copyright 10c0b9f4feSDoug Rabson.\" notice, this list of conditions and the following disclaimer. 11c0b9f4feSDoug Rabson.\" 2. Redistributions in binary form must reproduce the above copyright 12c0b9f4feSDoug Rabson.\" notice, this list of conditions and the following disclaimer in the 13c0b9f4feSDoug Rabson.\" documentation and/or other materials provided with the distribution. 14c0b9f4feSDoug Rabson.\" 15c0b9f4feSDoug Rabson.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 16c0b9f4feSDoug Rabson.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 17c0b9f4feSDoug Rabson.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 18c0b9f4feSDoug Rabson.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 19c0b9f4feSDoug Rabson.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 20c0b9f4feSDoug Rabson.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 21c0b9f4feSDoug Rabson.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 22c0b9f4feSDoug Rabson.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 23c0b9f4feSDoug Rabson.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 24c0b9f4feSDoug Rabson.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 25c0b9f4feSDoug Rabson.\" SUCH DAMAGE. 26c0b9f4feSDoug Rabson.\" 27c0b9f4feSDoug Rabson.\" $FreeBSD$ 28c0b9f4feSDoug Rabson.\" 29c0b9f4feSDoug Rabson.\" The following commands are required for all man pages. 30c0b9f4feSDoug Rabson.Dd November 12, 2005 31c0b9f4feSDoug Rabson.Os 32c0b9f4feSDoug Rabson.Dt GSS_INQUIRE_CONTEXT 3 PRM 33c0b9f4feSDoug Rabson.Sh NAME 34c0b9f4feSDoug Rabson.Nm gss_inquire_context 35c0b9f4feSDoug Rabson.Nd Obtain information about a security context 36c0b9f4feSDoug Rabson.\" This next command is for sections 2 and 3 only. 37c0b9f4feSDoug Rabson.\" .Sh LIBRARY 38c0b9f4feSDoug Rabson.Sh SYNOPSIS 39c0b9f4feSDoug Rabson.In "gssapi/gssapi.h" 40c0b9f4feSDoug Rabson.Ft OM_uint32 41c0b9f4feSDoug Rabson.Fo gss_inquire_context 42c0b9f4feSDoug Rabson.Fa "OM_uint32 *minor_status" 43c0b9f4feSDoug Rabson.Fa "const gss_ctx_id_t context_handle" 44c0b9f4feSDoug Rabson.Fa "gss_name_t *src_name" 45c0b9f4feSDoug Rabson.Fa "gss_name_t *targ_name" 46c0b9f4feSDoug Rabson.Fa "OM_uint32 *lifetime_rec" 47c0b9f4feSDoug Rabson.Fa "gss_OID *mech_type" 48c0b9f4feSDoug Rabson.Fa "OM_uint32 *ctx_flags" 49c0b9f4feSDoug Rabson.Fa "int *locally_initiated" 50c0b9f4feSDoug Rabson.Fa "int *open" 51c0b9f4feSDoug Rabson.Fc 52c0b9f4feSDoug Rabson.Sh DESCRIPTION 53c0b9f4feSDoug RabsonObtains information about a security context. 54c0b9f4feSDoug RabsonThe caller must already have obtained a handle that refers to the 55c0b9f4feSDoug Rabsoncontext, 56c0b9f4feSDoug Rabsonalthough the context need not be fully established. 57c0b9f4feSDoug Rabson.Sh PARAMETERS 58c0b9f4feSDoug Rabson.Bl -tag 59c0b9f4feSDoug Rabson.It minor_status 60c0b9f4feSDoug RabsonMechanism specific status code. 61c0b9f4feSDoug Rabson.It context_handle 62c0b9f4feSDoug RabsonA handle that refers to the security context. 63c0b9f4feSDoug Rabson.It src_name 64c0b9f4feSDoug RabsonThe name of the context initiator. 65c0b9f4feSDoug RabsonIf the context was established using anonymous authentication, 66c0b9f4feSDoug Rabsonand if the application invoking 67c0b9f4feSDoug Rabson.Fn gss_inquire_context 68c0b9f4feSDoug Rabsonis the context acceptor, 69c0b9f4feSDoug Rabsonan anonymous name will be returned. 70c0b9f4feSDoug RabsonStorage associated with this name must be freed by the application 71c0b9f4feSDoug Rabsonafter use with a call to 72c0b9f4feSDoug Rabson.Fn gss_release_name . 73c0b9f4feSDoug RabsonSpecify 74c0b9f4feSDoug Rabson.Dv NULL 75c0b9f4feSDoug Rabsonif not required. 76c0b9f4feSDoug Rabson.It targ_name 77c0b9f4feSDoug RabsonThe name of the context acceptor. 78c0b9f4feSDoug RabsonStorage associated with this name must be freed by the application 79c0b9f4feSDoug Rabsonafter use with a call to 80c0b9f4feSDoug Rabson.Fn gss_release_name . 81c0b9f4feSDoug RabsonIf the context acceptor did not authenticate itself, 82c0b9f4feSDoug Rabsonand if the initiator did not specify a target name in its call to 83c0b9f4feSDoug Rabson.Fn gss_init_sec_context , 84c0b9f4feSDoug Rabsonthe value 85c0b9f4feSDoug Rabson.Dv GSS_C_NO_NAME 86c0b9f4feSDoug Rabsonwill be returned. 87c0b9f4feSDoug RabsonSpecify 88c0b9f4feSDoug Rabson.Dv NULL 89c0b9f4feSDoug Rabsonif not required. 90c0b9f4feSDoug Rabson.It lifetime_rec 91c0b9f4feSDoug RabsonThe number of seconds for which the context will remain valid. 92c0b9f4feSDoug RabsonIf the context has expired, 93c0b9f4feSDoug Rabsonthis parameter will be set to zero. 94c0b9f4feSDoug RabsonIf the implementation does not support context expiration, 95c0b9f4feSDoug Rabsonthe value 96c0b9f4feSDoug Rabson.Dv GSS_C_INDEFINITE 97c0b9f4feSDoug Rabsonwill be returned. 98c0b9f4feSDoug RabsonSpecify 99c0b9f4feSDoug Rabson.Dv NULL 100c0b9f4feSDoug Rabsonif not required. 101c0b9f4feSDoug Rabson.It mech_type 102c0b9f4feSDoug RabsonThe security mechanism providing the context. 103c0b9f4feSDoug RabsonThe returned OID will be a pointer to static storage that should be 104c0b9f4feSDoug Rabsontreated as read-only by the application; 105c0b9f4feSDoug Rabsonin particular the application should not attempt to free it. 106c0b9f4feSDoug RabsonSpecify 107c0b9f4feSDoug Rabson.Dv NULL 108c0b9f4feSDoug Rabsonif not required. 109c0b9f4feSDoug Rabson.It ctx_flags 110c0b9f4feSDoug RabsonContains various independent flags, 111c0b9f4feSDoug Rabsoneach of which indicates that the context supports 112c0b9f4feSDoug Rabson(or is expected to support, if 113c0b9f4feSDoug Rabson.Fa open 114c0b9f4feSDoug Rabsonis false) 115c0b9f4feSDoug Rabsona specific service option. 116c0b9f4feSDoug RabsonIf not needed, specify 117c0b9f4feSDoug Rabson.Dv NULL . 118c0b9f4feSDoug RabsonSymbolic names are provided for each flag, 119c0b9f4feSDoug Rabsonand the symbolic names corresponding to the required flags should be 120c0b9f4feSDoug Rabsonlogically-ANDed with the 121c0b9f4feSDoug Rabson.Fa ctx_flags 122c0b9f4feSDoug Rabsonvalue to test whether a given option is supported by the context. 123c0b9f4feSDoug RabsonThe flags are: 124c0b9f4feSDoug Rabson.Bl -tag -width "WW" 125c0b9f4feSDoug Rabson.It GSS_C_DELEG_FLAG 126c0b9f4feSDoug Rabson.Bl -tag -width "False" 127c0b9f4feSDoug Rabson.It True 128c0b9f4feSDoug RabsonCredentials were delegated from the initiator to the acceptor. 129c0b9f4feSDoug Rabson.It False 130c0b9f4feSDoug RabsonNo credentials were delegated. 131c0b9f4feSDoug Rabson.El 132c0b9f4feSDoug Rabson.It GSS_C_MUTUAL_FLAG 133c0b9f4feSDoug Rabson.Bl -tag -width "False" 134c0b9f4feSDoug Rabson.It True 135c0b9f4feSDoug RabsonThe acceptor was authenticated to the initiator. 136c0b9f4feSDoug Rabson.It False 137c0b9f4feSDoug RabsonThe acceptor did not authenticate itself. 138c0b9f4feSDoug Rabson.El 139c0b9f4feSDoug Rabson.It GSS_C_REPLAY_FLAG 140c0b9f4feSDoug Rabson.Bl -tag -width "False" 141c0b9f4feSDoug Rabson.It True 142c0b9f4feSDoug RabsonReplay of protected messages will be detected. 143c0b9f4feSDoug Rabson.It False 144c0b9f4feSDoug RabsonReplayed messages will not be detected. 145c0b9f4feSDoug Rabson.El 146c0b9f4feSDoug Rabson.It GSS_C_SEQUENCE_FLAG 147c0b9f4feSDoug Rabson.Bl -tag -width "False" 148c0b9f4feSDoug Rabson.It True 149c0b9f4feSDoug RabsonOut-of-sequence protected messages will be detected. 150c0b9f4feSDoug Rabson.It False 151c0b9f4feSDoug RabsonOut-of-sequence messages will not be detected. 152c0b9f4feSDoug Rabson.El 153c0b9f4feSDoug Rabson.It GSS_C_CONF_FLAG 154c0b9f4feSDoug Rabson.Bl -tag -width "False" 155c0b9f4feSDoug Rabson.It True 156c0b9f4feSDoug RabsonConfidentiality service may be invoked by calling 157c0b9f4feSDoug Rabson.Fn gss_wrap 158c0b9f4feSDoug Rabsonroutine. 159c0b9f4feSDoug Rabson.It False 160c0b9f4feSDoug RabsonNo confidentiality service 161c0b9f4feSDoug Rabson(via 162c0b9f4feSDoug Rabson.Fn gss_wrap ) 163c0b9f4feSDoug Rabsonavailable. 164c0b9f4feSDoug Rabson.Fn gss_wrap 165c0b9f4feSDoug Rabsonwill provide message encapsulation, 166c0b9f4feSDoug Rabsondata-origin authentication and integrity services only. 167c0b9f4feSDoug Rabson.El 168c0b9f4feSDoug Rabson.It GSS_C_INTEG_FLAG 169c0b9f4feSDoug Rabson.Bl -tag -width "False" 170c0b9f4feSDoug Rabson.It True 171c0b9f4feSDoug RabsonIntegrity service may be invoked by calling either 172c0b9f4feSDoug Rabson.Fn gss_get_mic 173c0b9f4feSDoug Rabsonor 174c0b9f4feSDoug Rabson.Fn gss_wrap 175c0b9f4feSDoug Rabsonroutines. 176c0b9f4feSDoug Rabson.It False 177c0b9f4feSDoug RabsonPer-message integrity service unavailable. 178c0b9f4feSDoug Rabson.El 179c0b9f4feSDoug Rabson.It GSS_C_ANON_FLAG 180c0b9f4feSDoug Rabson.Bl -tag -width "False" 181c0b9f4feSDoug Rabson.It True 182c0b9f4feSDoug RabsonThe initiator's identity will not be revealed to the acceptor. 183c0b9f4feSDoug RabsonThe 184c0b9f4feSDoug Rabson.Fa src_name 185c0b9f4feSDoug Rabsonparameter (if requested) contains an anonymous internal name. 186c0b9f4feSDoug Rabson.It False 187c0b9f4feSDoug RabsonThe initiator has been authenticated normally. 188c0b9f4feSDoug Rabson.El 189c0b9f4feSDoug Rabson.It GSS_C_PROT_READY_FLAG 190c0b9f4feSDoug Rabson.Bl -tag -width "False" 191c0b9f4feSDoug Rabson.It True 192c0b9f4feSDoug RabsonProtection services 193c0b9f4feSDoug Rabson(as specified by the states of the 194c0b9f4feSDoug Rabson.Dv GSS_C_CONF_FLAG 195c0b9f4feSDoug Rabsonand 196c0b9f4feSDoug Rabson.Dv GSS_C_INTEG_FLAG ) 197c0b9f4feSDoug Rabsonare available for use. 198c0b9f4feSDoug Rabson.It False 199c0b9f4feSDoug RabsonProtection services 200c0b9f4feSDoug Rabson(as specified by the states of the 201c0b9f4feSDoug Rabson.Dv GSS_C_CONF_FLAG 202c0b9f4feSDoug Rabsonand 203c0b9f4feSDoug Rabson.Dv GSS_C_INTEG_FLAG ) 204c0b9f4feSDoug Rabsonare available only if the context is fully established 205c0b9f4feSDoug Rabson(i.e. if the 206c0b9f4feSDoug Rabson.Fa open 207c0b9f4feSDoug Rabsonparameter is non-zero). 208c0b9f4feSDoug Rabson.El 209c0b9f4feSDoug Rabson.It GSS_C_TRANS_FLAG 210c0b9f4feSDoug Rabson.Bl -tag -width "False" 211c0b9f4feSDoug Rabson.It True 212c0b9f4feSDoug RabsonThe security context may be transferred to other processes via a call to 213c0b9f4feSDoug Rabson.Fn gss_export_sec_context . 214c0b9f4feSDoug Rabson.It False 215c0b9f4feSDoug RabsonThe security context is not transferable. 216c0b9f4feSDoug Rabson.El 217c0b9f4feSDoug Rabson.El 218c0b9f4feSDoug Rabson.It locally_initiated 219c0b9f4feSDoug RabsonNon-zero if the invoking application is the context initiator. 220c0b9f4feSDoug RabsonSpecify 221c0b9f4feSDoug Rabson.Dv NULL 222c0b9f4feSDoug Rabsonif not required. 223c0b9f4feSDoug Rabson.It open 224c0b9f4feSDoug RabsonNon-zero if the context is fully established; 225c0b9f4feSDoug RabsonZero if a context-establishment token is expected from the peer 226c0b9f4feSDoug Rabsonapplication. 227c0b9f4feSDoug RabsonSpecify 228c0b9f4feSDoug Rabson.Dv NULL 229c0b9f4feSDoug Rabsonif not required. 230c0b9f4feSDoug Rabson.El 231c0b9f4feSDoug Rabson.Sh RETURN VALUES 232c0b9f4feSDoug Rabson.Bl -tag 233c0b9f4feSDoug Rabson.It GSS_S_COMPLETE 234c0b9f4feSDoug RabsonSuccessful completion 235c0b9f4feSDoug Rabson.It GSS_S_NO_CONTEXT 236c0b9f4feSDoug RabsonThe referenced context could not be accessed 237c0b9f4feSDoug Rabson.El 238c0b9f4feSDoug Rabson.Sh SEE ALSO 239c0b9f4feSDoug Rabson.Xr gss_release_name 3 , 240c0b9f4feSDoug Rabson.Xr gss_init_sec_context 3 , 241c0b9f4feSDoug Rabson.Xr gss_wrap 3 , 242c0b9f4feSDoug Rabson.Xr gss_get_mic 3 , 243c0b9f4feSDoug Rabson.Xr gss_export_sec_context 3 244c0b9f4feSDoug Rabson.Sh STANDARDS 245c0b9f4feSDoug Rabson.Bl -tag 246c0b9f4feSDoug Rabson.It RFC 2743 247c0b9f4feSDoug RabsonGeneric Security Service Application Program Interface Version 2, Update 1 248c0b9f4feSDoug Rabson.It RFC 2744 249c0b9f4feSDoug RabsonGeneric Security Service API Version 2 : C-bindings 250c0b9f4feSDoug Rabson.\" .Sh HISTORY 251c0b9f4feSDoug Rabson.El 252c0b9f4feSDoug Rabson.Sh HISTORY 253c0b9f4feSDoug RabsonThe 254c0b9f4feSDoug Rabson.Nm 255c0b9f4feSDoug Rabsonmanual page example first appeared in 256c0b9f4feSDoug Rabson.Fx 7.0 . 257c0b9f4feSDoug Rabson.Sh AUTHORS 258c0b9f4feSDoug RabsonJohn Wray, Iris Associates 25960b9f20aSDoug Rabson.Sh COPYRIGHT 26060b9f20aSDoug RabsonCopyright (C) The Internet Society (2000). All Rights Reserved. 26160b9f20aSDoug Rabson.Pp 26260b9f20aSDoug RabsonThis document and translations of it may be copied and furnished to 26360b9f20aSDoug Rabsonothers, and derivative works that comment on or otherwise explain it 26460b9f20aSDoug Rabsonor assist in its implementation may be prepared, copied, published 26560b9f20aSDoug Rabsonand distributed, in whole or in part, without restriction of any 26660b9f20aSDoug Rabsonkind, provided that the above copyright notice and this paragraph are 26760b9f20aSDoug Rabsonincluded on all such copies and derivative works. However, this 26860b9f20aSDoug Rabsondocument itself may not be modified in any way, such as by removing 26960b9f20aSDoug Rabsonthe copyright notice or references to the Internet Society or other 27060b9f20aSDoug RabsonInternet organizations, except as needed for the purpose of 27160b9f20aSDoug Rabsondeveloping Internet standards in which case the procedures for 27260b9f20aSDoug Rabsoncopyrights defined in the Internet Standards process must be 27360b9f20aSDoug Rabsonfollowed, or as required to translate it into languages other than 27460b9f20aSDoug RabsonEnglish. 27560b9f20aSDoug Rabson.Pp 27660b9f20aSDoug RabsonThe limited permissions granted above are perpetual and will not be 27760b9f20aSDoug Rabsonrevoked by the Internet Society or its successors or assigns. 27860b9f20aSDoug Rabson.Pp 27960b9f20aSDoug RabsonThis document and the information contained herein is provided on an 28060b9f20aSDoug Rabson"AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING 28160b9f20aSDoug RabsonTASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING 28260b9f20aSDoug RabsonBUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION 28360b9f20aSDoug RabsonHEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF 28460b9f20aSDoug RabsonMERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. 285