xref: /titanic_53/usr/src/uts/common/smbsrv/netrauth.h (revision 12b65585e720714b31036daaa2b30eb76014048e)
1da6c28aaSamw /*
2da6c28aaSamw  * CDDL HEADER START
3da6c28aaSamw  *
4da6c28aaSamw  * The contents of this file are subject to the terms of the
5da6c28aaSamw  * Common Development and Distribution License (the "License").
6da6c28aaSamw  * You may not use this file except in compliance with the License.
7da6c28aaSamw  *
8da6c28aaSamw  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9da6c28aaSamw  * or http://www.opensolaris.org/os/licensing.
10da6c28aaSamw  * See the License for the specific language governing permissions
11da6c28aaSamw  * and limitations under the License.
12da6c28aaSamw  *
13da6c28aaSamw  * When distributing Covered Code, include this CDDL HEADER in each
14da6c28aaSamw  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15da6c28aaSamw  * If applicable, add the following below this CDDL HEADER, with the
16da6c28aaSamw  * fields enclosed by brackets "[]" replaced with your own identifying
17da6c28aaSamw  * information: Portions Copyright [yyyy] [name of copyright owner]
18da6c28aaSamw  *
19da6c28aaSamw  * CDDL HEADER END
20da6c28aaSamw  */
21da6c28aaSamw /*
2277191e87SShawn Emery  * Copyright 2010 Sun Microsystems, Inc.  All rights reserved.
23da6c28aaSamw  * Use is subject to license terms.
24*12b65585SGordon Ross  *
25*12b65585SGordon Ross  * Copyright 2015 Nexenta Systems, Inc.  All rights reserved.
26da6c28aaSamw  */
27da6c28aaSamw 
28da6c28aaSamw #ifndef _SMBSRV_NETRAUTH_H
29da6c28aaSamw #define	_SMBSRV_NETRAUTH_H
30da6c28aaSamw 
31da6c28aaSamw /*
329fb67ea3Safshin salek ardakani - Sun Microsystems - Irvine United States  * NETR remote authentication and logon services.
33da6c28aaSamw  */
34da6c28aaSamw 
35da6c28aaSamw #include <sys/types.h>
36da6c28aaSamw #include <smbsrv/wintypes.h>
37b89a8333Snatalie li - Sun Microsystems - Irvine United States #include <smbsrv/netbios.h>
387f667e74Sjose borrego #include <smbsrv/smbinfo.h>
39da6c28aaSamw 
40da6c28aaSamw #ifdef __cplusplus
41da6c28aaSamw extern "C" {
42da6c28aaSamw #endif
43da6c28aaSamw 
44da6c28aaSamw /*
45da6c28aaSamw  * See also netlogon.ndl.
46da6c28aaSamw  */
47da6c28aaSamw #define	NETR_WKSTA_TRUST_ACCOUNT_TYPE		0x02
48da6c28aaSamw #define	NETR_DOMAIN_TRUST_ACCOUNT_TYPE		0x04
49da6c28aaSamw 
50da6c28aaSamw /*
51da6c28aaSamw  * Negotiation flags for challenge/response authentication.
52da6c28aaSamw  */
532c1b14e5Sjose borrego #define	NETR_NEGOTIATE_BASE_FLAGS		0x000001FF
542c1b14e5Sjose borrego #define	NETR_NEGOTIATE_STRONGKEY_FLAG		0x00004000
55da6c28aaSamw 
562c1b14e5Sjose borrego #define	NETR_SESSKEY64_SZ			8
572c1b14e5Sjose borrego #define	NETR_SESSKEY128_SZ			16
582c1b14e5Sjose borrego #define	NETR_SESSKEY_MAXSZ			NETR_SESSKEY128_SZ
59da6c28aaSamw #define	NETR_CRED_DATA_SZ			8
60da6c28aaSamw #define	NETR_OWF_PASSWORD_SZ			16
61da6c28aaSamw 
62da6c28aaSamw /*
63da6c28aaSamw  * SAM logon levels: interactive and network.
64da6c28aaSamw  */
65da6c28aaSamw #define	NETR_INTERACTIVE_LOGON			0x01
66da6c28aaSamw #define	NETR_NETWORK_LOGON			0x02
67da6c28aaSamw 
68da6c28aaSamw /*
69da6c28aaSamw  * SAM logon validation levels.
70da6c28aaSamw  */
71da6c28aaSamw #define	NETR_VALIDATION_LEVEL3			0x03
72da6c28aaSamw 
73da6c28aaSamw /*
74*12b65585SGordon Ross  * Most of these are from: "MSV1_0_LM20_LOGON structure"
75*12b65585SGordon Ross  * http://msdn.microsoft.com/en-us/library/windows/desktop/aa378762
76*12b65585SGordon Ross  * and a few are from the ntddk (ntmsv1_0.h) found many places.
77*12b65585SGordon Ross  */
78*12b65585SGordon Ross #define	MSV1_0_CLEARTEXT_PASSWORD_ALLOWED	0x00000002
79*12b65585SGordon Ross #define	MSV1_0_UPDATE_LOGON_STATISTICS		0x00000004
80*12b65585SGordon Ross #define	MSV1_0_RETURN_USER_PARAMETERS		0x00000008
81*12b65585SGordon Ross #define	MSV1_0_DONT_TRY_GUEST_ACCOUNT		0x00000010
82*12b65585SGordon Ross #define	MSV1_0_ALLOW_SERVER_TRUST_ACCOUNT	0x00000020
83*12b65585SGordon Ross #define	MSV1_0_RETURN_PASSWORD_EXPIRY		0x00000040
84*12b65585SGordon Ross /*
85*12b65585SGordon Ross  * MSV1_0_USE_CLIENT_CHALLENGE means the LM response field contains the
86*12b65585SGordon Ross  * "client challenge" in the first 8 bytes instead of the LM response.
87*12b65585SGordon Ross  */
88*12b65585SGordon Ross #define	MSV1_0_USE_CLIENT_CHALLENGE		0x00000080
89*12b65585SGordon Ross #define	MSV1_0_TRY_GUEST_ACCOUNT_ONLY		0x00000100
90*12b65585SGordon Ross #define	MSV1_0_RETURN_PROFILE_PATH		0x00000200
91*12b65585SGordon Ross #define	MSV1_0_TRY_SPECIFIED_DOMAIN_ONLY	0x00000400
92*12b65585SGordon Ross #define	MSV1_0_ALLOW_WORKSTATION_TRUST_ACCOUNT	0x00000800
93*12b65585SGordon Ross #define	MSV1_0_DISABLE_PERSONAL_FALLBACK	0x00001000
94*12b65585SGordon Ross #define	MSV1_0_ALLOW_FORCE_GUEST		0x00002000
95*12b65585SGordon Ross #define	MSV1_0_CLEARTEXT_PASSWORD_SUPPLIED	0x00004000
96*12b65585SGordon Ross #define	MSV1_0_USE_DOMAIN_FOR_ROUTING_ONLY	0x00008000
97*12b65585SGordon Ross #define	MSV1_0_SUBAUTHENTICATION_DLL_EX		0x00100000
98*12b65585SGordon Ross 
99*12b65585SGordon Ross /*
100da6c28aaSamw  * This is a duplicate of the netr_credential
101da6c28aaSamw  * from netlogon.ndl.
102da6c28aaSamw  */
103da6c28aaSamw typedef struct netr_cred {
104da6c28aaSamw 	BYTE data[NETR_CRED_DATA_SZ];
105da6c28aaSamw } netr_cred_t;
106da6c28aaSamw 
1072c1b14e5Sjose borrego typedef struct netr_session_key {
1082c1b14e5Sjose borrego 	BYTE key[NETR_SESSKEY_MAXSZ];
1092c1b14e5Sjose borrego 	short len;
1102c1b14e5Sjose borrego } netr_session_key_t;
111da6c28aaSamw 
112da6c28aaSamw #define	NETR_FLG_NULL		0x00000001
113da6c28aaSamw #define	NETR_FLG_VALID		0x00000001
114da6c28aaSamw #define	NETR_FLG_INIT		0x00000002
115da6c28aaSamw 
1168d7e4166Sjose borrego /*
11777191e87SShawn Emery  * 120-byte machine account password (null-terminated)
1188d7e4166Sjose borrego  */
11977191e87SShawn Emery #define	NETR_MACHINE_ACCT_PASSWD_MAX	120 + 1
120da6c28aaSamw 
121da6c28aaSamw typedef struct netr_info {
122da6c28aaSamw 	DWORD flags;
123b89a8333Snatalie li - Sun Microsystems - Irvine United States 	char server[NETBIOS_NAME_SZ * 2];
124b89a8333Snatalie li - Sun Microsystems - Irvine United States 	char hostname[NETBIOS_NAME_SZ * 2];
125da6c28aaSamw 	netr_cred_t client_challenge;
126da6c28aaSamw 	netr_cred_t server_challenge;
127da6c28aaSamw 	netr_cred_t client_credential;
128da6c28aaSamw 	netr_cred_t server_credential;
1292c1b14e5Sjose borrego 	netr_session_key_t session_key;
1308d7e4166Sjose borrego 	BYTE password[NETR_MACHINE_ACCT_PASSWD_MAX];
131da6c28aaSamw 	time_t timestamp;
132da6c28aaSamw } netr_info_t;
133da6c28aaSamw 
134da6c28aaSamw /*
135da6c28aaSamw  * NETLOGON private interface.
136da6c28aaSamw  */
1372c1b14e5Sjose borrego int netr_gen_skey64(netr_info_t *);
1382c1b14e5Sjose borrego int netr_gen_skey128(netr_info_t *);
139da6c28aaSamw 
1402c1b14e5Sjose borrego int netr_gen_credentials(BYTE *, netr_cred_t *, DWORD, netr_cred_t *);
141da6c28aaSamw 
142da6c28aaSamw 
143da6c28aaSamw #define	NETR_A2H(c) (isdigit(c)) ? ((c) - '0') : ((c) - 'A' + 10)
144da6c28aaSamw 
145da6c28aaSamw #ifdef __cplusplus
146da6c28aaSamw }
147da6c28aaSamw #endif
148da6c28aaSamw 
149da6c28aaSamw #endif /* _SMBSRV_NETRAUTH_H */
150