1*7c478bd9Sstevel@tonic-gate /* 2*7c478bd9Sstevel@tonic-gate * CDDL HEADER START 3*7c478bd9Sstevel@tonic-gate * 4*7c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5*7c478bd9Sstevel@tonic-gate * Common Development and Distribution License, Version 1.0 only 6*7c478bd9Sstevel@tonic-gate * (the "License"). You may not use this file except in compliance 7*7c478bd9Sstevel@tonic-gate * with the License. 8*7c478bd9Sstevel@tonic-gate * 9*7c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 10*7c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 11*7c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 12*7c478bd9Sstevel@tonic-gate * and limitations under the License. 13*7c478bd9Sstevel@tonic-gate * 14*7c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 15*7c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 16*7c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 17*7c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 18*7c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 19*7c478bd9Sstevel@tonic-gate * 20*7c478bd9Sstevel@tonic-gate * CDDL HEADER END 21*7c478bd9Sstevel@tonic-gate */ 22*7c478bd9Sstevel@tonic-gate /* 23*7c478bd9Sstevel@tonic-gate * Copyright 2005 Sun Microsystems, Inc. All rights reserved. 24*7c478bd9Sstevel@tonic-gate * Use is subject to license terms. 25*7c478bd9Sstevel@tonic-gate */ 26*7c478bd9Sstevel@tonic-gate /* Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T */ 27*7c478bd9Sstevel@tonic-gate /* All Rights Reserved */ 28*7c478bd9Sstevel@tonic-gate /* 29*7c478bd9Sstevel@tonic-gate * Portions of this source code were derived from Berkeley 30*7c478bd9Sstevel@tonic-gate * 4.3 BSD under license from the Regents of the University of 31*7c478bd9Sstevel@tonic-gate * California. 32*7c478bd9Sstevel@tonic-gate */ 33*7c478bd9Sstevel@tonic-gate 34*7c478bd9Sstevel@tonic-gate #ifndef _RPC_SVC_AUTH_H 35*7c478bd9Sstevel@tonic-gate #define _RPC_SVC_AUTH_H 36*7c478bd9Sstevel@tonic-gate 37*7c478bd9Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 38*7c478bd9Sstevel@tonic-gate 39*7c478bd9Sstevel@tonic-gate /* 40*7c478bd9Sstevel@tonic-gate * svc_auth.h, Service side of rpc authentication. 41*7c478bd9Sstevel@tonic-gate */ 42*7c478bd9Sstevel@tonic-gate #include <rpc/rpcsec_gss.h> 43*7c478bd9Sstevel@tonic-gate #include <rpc/rpc_msg.h> 44*7c478bd9Sstevel@tonic-gate 45*7c478bd9Sstevel@tonic-gate #ifdef __cplusplus 46*7c478bd9Sstevel@tonic-gate extern "C" { 47*7c478bd9Sstevel@tonic-gate #endif 48*7c478bd9Sstevel@tonic-gate 49*7c478bd9Sstevel@tonic-gate /* 50*7c478bd9Sstevel@tonic-gate * Server side authenticator 51*7c478bd9Sstevel@tonic-gate */ 52*7c478bd9Sstevel@tonic-gate #ifdef _KERNEL 53*7c478bd9Sstevel@tonic-gate /* 54*7c478bd9Sstevel@tonic-gate * Copy of GSS parameters, needed for MT operation 55*7c478bd9Sstevel@tonic-gate */ 56*7c478bd9Sstevel@tonic-gate typedef struct { 57*7c478bd9Sstevel@tonic-gate bool_t established; 58*7c478bd9Sstevel@tonic-gate rpc_gss_service_t service; 59*7c478bd9Sstevel@tonic-gate uint_t qop_rcvd; 60*7c478bd9Sstevel@tonic-gate void *context; 61*7c478bd9Sstevel@tonic-gate uint_t seq_num; 62*7c478bd9Sstevel@tonic-gate } svc_rpc_gss_parms_t; 63*7c478bd9Sstevel@tonic-gate 64*7c478bd9Sstevel@tonic-gate /* 65*7c478bd9Sstevel@tonic-gate * sec_svc_control() commands 66*7c478bd9Sstevel@tonic-gate */ 67*7c478bd9Sstevel@tonic-gate #define RPC_SVC_SET_GSS_CALLBACK 1 /* set rpcsec_gss callback routine */ 68*7c478bd9Sstevel@tonic-gate extern bool_t sec_svc_control(); 69*7c478bd9Sstevel@tonic-gate 70*7c478bd9Sstevel@tonic-gate /* 71*7c478bd9Sstevel@tonic-gate * Interface to server-side authentication flavors, may change on 72*7c478bd9Sstevel@tonic-gate * each request. 73*7c478bd9Sstevel@tonic-gate */ 74*7c478bd9Sstevel@tonic-gate typedef struct { 75*7c478bd9Sstevel@tonic-gate struct svc_auth_ops { 76*7c478bd9Sstevel@tonic-gate int (*svc_ah_wrap)(); 77*7c478bd9Sstevel@tonic-gate int (*svc_ah_unwrap)(); 78*7c478bd9Sstevel@tonic-gate } svc_ah_ops; 79*7c478bd9Sstevel@tonic-gate caddr_t svc_ah_private; 80*7c478bd9Sstevel@tonic-gate svc_rpc_gss_parms_t svc_gss_parms; 81*7c478bd9Sstevel@tonic-gate rpc_gss_rawcred_t raw_cred; 82*7c478bd9Sstevel@tonic-gate } SVCAUTH; 83*7c478bd9Sstevel@tonic-gate 84*7c478bd9Sstevel@tonic-gate #define SVCAUTH_GSSPARMS(auth) ((svc_rpc_gss_parms_t *)&(auth)->svc_gss_parms) 85*7c478bd9Sstevel@tonic-gate 86*7c478bd9Sstevel@tonic-gate /* 87*7c478bd9Sstevel@tonic-gate * Auth flavors can now apply a transformation in addition to simple XDR 88*7c478bd9Sstevel@tonic-gate * on the body of a call/response in ways that depend on the flavor being 89*7c478bd9Sstevel@tonic-gate * used. These interfaces provide a generic interface between the 90*7c478bd9Sstevel@tonic-gate * internal RPC frame and the auth flavor specific code to allow the 91*7c478bd9Sstevel@tonic-gate * auth flavor to encode (WRAP) or decode (UNWRAP) the body. 92*7c478bd9Sstevel@tonic-gate */ 93*7c478bd9Sstevel@tonic-gate #define SVCAUTH_WRAP(auth, xdrs, xfunc, xwhere) \ 94*7c478bd9Sstevel@tonic-gate ((*((auth)->svc_ah_ops.svc_ah_wrap))(auth, xdrs, xfunc, xwhere)) 95*7c478bd9Sstevel@tonic-gate #define SVCAUTH_UNWRAP(auth, xdrs, xfunc, xwhere) \ 96*7c478bd9Sstevel@tonic-gate ((*((auth)->svc_ah_ops.svc_ah_unwrap))(auth, xdrs, xfunc, xwhere)) 97*7c478bd9Sstevel@tonic-gate 98*7c478bd9Sstevel@tonic-gate /* 99*7c478bd9Sstevel@tonic-gate * Server side authenticator 100*7c478bd9Sstevel@tonic-gate */ 101*7c478bd9Sstevel@tonic-gate #ifdef __STDC__ 102*7c478bd9Sstevel@tonic-gate extern enum auth_stat sec_svc_msg(struct svc_req *, struct rpc_msg *, 103*7c478bd9Sstevel@tonic-gate bool_t *); 104*7c478bd9Sstevel@tonic-gate #else 105*7c478bd9Sstevel@tonic-gate extern enum auth_stat sec_svc_msg(); 106*7c478bd9Sstevel@tonic-gate #endif /* __STDC__ */ 107*7c478bd9Sstevel@tonic-gate 108*7c478bd9Sstevel@tonic-gate #else 109*7c478bd9Sstevel@tonic-gate 110*7c478bd9Sstevel@tonic-gate #ifdef __STDC__ 111*7c478bd9Sstevel@tonic-gate extern enum auth_stat __gss_authenticate(struct svc_req *, struct rpc_msg *, 112*7c478bd9Sstevel@tonic-gate bool_t *); 113*7c478bd9Sstevel@tonic-gate extern enum auth_stat __authenticate(struct svc_req *, struct rpc_msg *); 114*7c478bd9Sstevel@tonic-gate #else 115*7c478bd9Sstevel@tonic-gate extern enum auth_stat __gss_authenticate(); 116*7c478bd9Sstevel@tonic-gate extern enum auth_stat __authenticate(); 117*7c478bd9Sstevel@tonic-gate #endif /* __STDC__ */ 118*7c478bd9Sstevel@tonic-gate 119*7c478bd9Sstevel@tonic-gate #endif /* _KERNEL */ 120*7c478bd9Sstevel@tonic-gate 121*7c478bd9Sstevel@tonic-gate #ifdef __cplusplus 122*7c478bd9Sstevel@tonic-gate } 123*7c478bd9Sstevel@tonic-gate #endif 124*7c478bd9Sstevel@tonic-gate 125*7c478bd9Sstevel@tonic-gate #endif /* _RPC_SVC_AUTH_H */ 126