xref: /freebsd/sys/rpc/rpcsec_gss/rpcsec_gss_conf.c (revision fdafd315ad0d0f28a11b9fb4476a9ab059c62b92)
1a9148abdSDoug Rabson /*-
2*4d846d26SWarner Losh  * SPDX-License-Identifier: BSD-2-Clause
3fe267a55SPedro F. Giffuni  *
4a9148abdSDoug Rabson  * Copyright (c) 2008 Doug Rabson
5a9148abdSDoug Rabson  * All rights reserved.
6a9148abdSDoug Rabson  *
7a9148abdSDoug Rabson  * Redistribution and use in source and binary forms, with or without
8a9148abdSDoug Rabson  * modification, are permitted provided that the following conditions
9a9148abdSDoug Rabson  * are met:
10a9148abdSDoug Rabson  * 1. Redistributions of source code must retain the above copyright
11a9148abdSDoug Rabson  *    notice, this list of conditions and the following disclaimer.
12a9148abdSDoug Rabson  * 2. Redistributions in binary form must reproduce the above copyright
13a9148abdSDoug Rabson  *    notice, this list of conditions and the following disclaimer in the
14a9148abdSDoug Rabson  *    documentation and/or other materials provided with the distribution.
15a9148abdSDoug Rabson  *
16a9148abdSDoug Rabson  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17a9148abdSDoug Rabson  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18a9148abdSDoug Rabson  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19a9148abdSDoug Rabson  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20a9148abdSDoug Rabson  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21a9148abdSDoug Rabson  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22a9148abdSDoug Rabson  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23a9148abdSDoug Rabson  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24a9148abdSDoug Rabson  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25a9148abdSDoug Rabson  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26a9148abdSDoug Rabson  * SUCH DAMAGE.
27a9148abdSDoug Rabson  */
28a9148abdSDoug Rabson 
29a9148abdSDoug Rabson #include <sys/param.h>
30a9148abdSDoug Rabson #include <sys/systm.h>
31a9148abdSDoug Rabson #include <sys/kobj.h>
32a9148abdSDoug Rabson #include <sys/lock.h>
33a9148abdSDoug Rabson #include <sys/malloc.h>
34a9148abdSDoug Rabson #include <sys/mutex.h>
35a9148abdSDoug Rabson 
36a9148abdSDoug Rabson #include <rpc/rpc.h>
37a9148abdSDoug Rabson #include <rpc/rpcsec_gss.h>
38a9148abdSDoug Rabson 
39a9148abdSDoug Rabson #include "rpcsec_gss_int.h"
40a9148abdSDoug Rabson 
41a9148abdSDoug Rabson bool_t
rpc_gss_mech_to_oid(const char * mech,gss_OID * oid_ret)42a9148abdSDoug Rabson rpc_gss_mech_to_oid(const char *mech, gss_OID *oid_ret)
43a9148abdSDoug Rabson {
44a9148abdSDoug Rabson 	gss_OID oid = kgss_find_mech_by_name(mech);
45a9148abdSDoug Rabson 
46a9148abdSDoug Rabson 	if (oid) {
47a9148abdSDoug Rabson 		*oid_ret = oid;
48a9148abdSDoug Rabson 		return (TRUE);
49a9148abdSDoug Rabson 	}
50a9148abdSDoug Rabson 	_rpc_gss_set_error(RPC_GSS_ER_SYSTEMERROR, ENOENT);
51a9148abdSDoug Rabson 	return (FALSE);
52a9148abdSDoug Rabson }
53a9148abdSDoug Rabson 
54a9148abdSDoug Rabson bool_t
rpc_gss_oid_to_mech(gss_OID oid,const char ** mech_ret)55a9148abdSDoug Rabson rpc_gss_oid_to_mech(gss_OID oid, const char **mech_ret)
56a9148abdSDoug Rabson {
57a9148abdSDoug Rabson 	const char *name = kgss_find_mech_by_oid(oid);
58a9148abdSDoug Rabson 
59a9148abdSDoug Rabson 	if (name) {
60a9148abdSDoug Rabson 		*mech_ret = name;
61a9148abdSDoug Rabson 		return (TRUE);
62a9148abdSDoug Rabson 	}
63a9148abdSDoug Rabson 	_rpc_gss_set_error(RPC_GSS_ER_SYSTEMERROR, ENOENT);
64a9148abdSDoug Rabson 	return (FALSE);
65a9148abdSDoug Rabson }
66a9148abdSDoug Rabson 
67a9148abdSDoug Rabson bool_t
rpc_gss_qop_to_num(const char * qop,const char * mech,u_int * num_ret)68a9148abdSDoug Rabson rpc_gss_qop_to_num(const char *qop, const char *mech, u_int *num_ret)
69a9148abdSDoug Rabson {
70a9148abdSDoug Rabson 
71a9148abdSDoug Rabson 	if (!strcmp(qop, "default")) {
72a9148abdSDoug Rabson 		*num_ret = GSS_C_QOP_DEFAULT;
73a9148abdSDoug Rabson 		return (TRUE);
74a9148abdSDoug Rabson 	}
75a9148abdSDoug Rabson 	_rpc_gss_set_error(RPC_GSS_ER_SYSTEMERROR, ENOENT);
76a9148abdSDoug Rabson 	return (FALSE);
77a9148abdSDoug Rabson }
78a9148abdSDoug Rabson 
79a9148abdSDoug Rabson const char *
_rpc_gss_num_to_qop(const char * mech,u_int num)80a9148abdSDoug Rabson _rpc_gss_num_to_qop(const char *mech, u_int num)
81a9148abdSDoug Rabson {
82a9148abdSDoug Rabson 
83a9148abdSDoug Rabson 	if (num == GSS_C_QOP_DEFAULT)
84a9148abdSDoug Rabson 		return "default";
85a9148abdSDoug Rabson 
86a9148abdSDoug Rabson 	return (NULL);
87a9148abdSDoug Rabson }
88a9148abdSDoug Rabson 
89a9148abdSDoug Rabson const char **
rpc_gss_get_mechanisms(void)90a9148abdSDoug Rabson rpc_gss_get_mechanisms(void)
91a9148abdSDoug Rabson {
92a9148abdSDoug Rabson 	static const char **mech_names = NULL;
93a9148abdSDoug Rabson 	struct kgss_mech *km;
94a9148abdSDoug Rabson 	int count;
95a9148abdSDoug Rabson 
96a9148abdSDoug Rabson 	if (mech_names)
97a9148abdSDoug Rabson 		return (mech_names);
98a9148abdSDoug Rabson 
99a9148abdSDoug Rabson 	count = 0;
100a9148abdSDoug Rabson 	LIST_FOREACH(km, &kgss_mechs, km_link) {
101a9148abdSDoug Rabson 		count++;
102a9148abdSDoug Rabson 	}
103a9148abdSDoug Rabson 	count++;
104a9148abdSDoug Rabson 
105a9148abdSDoug Rabson 	mech_names = malloc(count * sizeof(const char *), M_RPC, M_WAITOK);
106a9148abdSDoug Rabson 	count = 0;
107a9148abdSDoug Rabson 	LIST_FOREACH(km, &kgss_mechs, km_link) {
108a9148abdSDoug Rabson 		mech_names[count++] = km->km_mech_name;
109a9148abdSDoug Rabson 	}
110a9148abdSDoug Rabson 	mech_names[count++] = NULL;
111a9148abdSDoug Rabson 
112a9148abdSDoug Rabson 	return (mech_names);
113a9148abdSDoug Rabson }
114a9148abdSDoug Rabson 
115a9148abdSDoug Rabson #if 0
116a9148abdSDoug Rabson const char **
117a9148abdSDoug Rabson rpc_gss_get_mech_info(const char *mech, rpc_gss_service_t *service)
118a9148abdSDoug Rabson {
119a9148abdSDoug Rabson 	struct mech_info *info;
120a9148abdSDoug Rabson 
121a9148abdSDoug Rabson 	_rpc_gss_load_mech();
122a9148abdSDoug Rabson 	_rpc_gss_load_qop();
123a9148abdSDoug Rabson 	SLIST_FOREACH(info, &mechs, link) {
124a9148abdSDoug Rabson 		if (!strcmp(mech, info->name)) {
125a9148abdSDoug Rabson 			/*
126a9148abdSDoug Rabson 			 * I'm not sure what to do with service
127a9148abdSDoug Rabson 			 * here. The Solaris manpages are not clear on
128a9148abdSDoug Rabson 			 * the subject and the OpenSolaris code just
129a9148abdSDoug Rabson 			 * sets it to rpc_gss_svc_privacy
130a9148abdSDoug Rabson 			 * unconditionally with a comment noting that
131a9148abdSDoug Rabson 			 * it is bogus.
132a9148abdSDoug Rabson 			 */
133a9148abdSDoug Rabson 			*service = rpc_gss_svc_privacy;
134a9148abdSDoug Rabson 			return info->qops;
135a9148abdSDoug Rabson 		}
136a9148abdSDoug Rabson 	}
137a9148abdSDoug Rabson 
138a9148abdSDoug Rabson 	_rpc_gss_set_error(RPC_GSS_ER_SYSTEMERROR, ENOENT);
139a9148abdSDoug Rabson 	return (NULL);
140a9148abdSDoug Rabson }
141a9148abdSDoug Rabson #endif
142a9148abdSDoug Rabson 
143a9148abdSDoug Rabson bool_t
rpc_gss_get_versions(u_int * vers_hi,u_int * vers_lo)144a9148abdSDoug Rabson rpc_gss_get_versions(u_int *vers_hi, u_int *vers_lo)
145a9148abdSDoug Rabson {
146a9148abdSDoug Rabson 
147a9148abdSDoug Rabson 	*vers_hi = 1;
148a9148abdSDoug Rabson 	*vers_lo = 1;
149a9148abdSDoug Rabson 	return (TRUE);
150a9148abdSDoug Rabson }
151a9148abdSDoug Rabson 
152a9148abdSDoug Rabson bool_t
rpc_gss_is_installed(const char * mech)153a9148abdSDoug Rabson rpc_gss_is_installed(const char *mech)
154a9148abdSDoug Rabson {
155a9148abdSDoug Rabson 	gss_OID oid = kgss_find_mech_by_name(mech);
156a9148abdSDoug Rabson 
157a9148abdSDoug Rabson 	if (oid)
158a9148abdSDoug Rabson 		return (TRUE);
159a9148abdSDoug Rabson 	else
160a9148abdSDoug Rabson 		return (FALSE);
161a9148abdSDoug Rabson }
162a9148abdSDoug Rabson 
163