xref: /titanic_54/usr/src/uts/common/smbsrv/netrauth.h (revision 12b65585e720714b31036daaa2b30eb76014048e)
1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://www.opensolaris.org/os/licensing.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright 2010 Sun Microsystems, Inc.  All rights reserved.
23  * Use is subject to license terms.
24  *
25  * Copyright 2015 Nexenta Systems, Inc.  All rights reserved.
26  */
27 
28 #ifndef _SMBSRV_NETRAUTH_H
29 #define	_SMBSRV_NETRAUTH_H
30 
31 /*
32  * NETR remote authentication and logon services.
33  */
34 
35 #include <sys/types.h>
36 #include <smbsrv/wintypes.h>
37 #include <smbsrv/netbios.h>
38 #include <smbsrv/smbinfo.h>
39 
40 #ifdef __cplusplus
41 extern "C" {
42 #endif
43 
44 /*
45  * See also netlogon.ndl.
46  */
47 #define	NETR_WKSTA_TRUST_ACCOUNT_TYPE		0x02
48 #define	NETR_DOMAIN_TRUST_ACCOUNT_TYPE		0x04
49 
50 /*
51  * Negotiation flags for challenge/response authentication.
52  */
53 #define	NETR_NEGOTIATE_BASE_FLAGS		0x000001FF
54 #define	NETR_NEGOTIATE_STRONGKEY_FLAG		0x00004000
55 
56 #define	NETR_SESSKEY64_SZ			8
57 #define	NETR_SESSKEY128_SZ			16
58 #define	NETR_SESSKEY_MAXSZ			NETR_SESSKEY128_SZ
59 #define	NETR_CRED_DATA_SZ			8
60 #define	NETR_OWF_PASSWORD_SZ			16
61 
62 /*
63  * SAM logon levels: interactive and network.
64  */
65 #define	NETR_INTERACTIVE_LOGON			0x01
66 #define	NETR_NETWORK_LOGON			0x02
67 
68 /*
69  * SAM logon validation levels.
70  */
71 #define	NETR_VALIDATION_LEVEL3			0x03
72 
73 /*
74  * Most of these are from: "MSV1_0_LM20_LOGON structure"
75  * http://msdn.microsoft.com/en-us/library/windows/desktop/aa378762
76  * and a few are from the ntddk (ntmsv1_0.h) found many places.
77  */
78 #define	MSV1_0_CLEARTEXT_PASSWORD_ALLOWED	0x00000002
79 #define	MSV1_0_UPDATE_LOGON_STATISTICS		0x00000004
80 #define	MSV1_0_RETURN_USER_PARAMETERS		0x00000008
81 #define	MSV1_0_DONT_TRY_GUEST_ACCOUNT		0x00000010
82 #define	MSV1_0_ALLOW_SERVER_TRUST_ACCOUNT	0x00000020
83 #define	MSV1_0_RETURN_PASSWORD_EXPIRY		0x00000040
84 /*
85  * MSV1_0_USE_CLIENT_CHALLENGE means the LM response field contains the
86  * "client challenge" in the first 8 bytes instead of the LM response.
87  */
88 #define	MSV1_0_USE_CLIENT_CHALLENGE		0x00000080
89 #define	MSV1_0_TRY_GUEST_ACCOUNT_ONLY		0x00000100
90 #define	MSV1_0_RETURN_PROFILE_PATH		0x00000200
91 #define	MSV1_0_TRY_SPECIFIED_DOMAIN_ONLY	0x00000400
92 #define	MSV1_0_ALLOW_WORKSTATION_TRUST_ACCOUNT	0x00000800
93 #define	MSV1_0_DISABLE_PERSONAL_FALLBACK	0x00001000
94 #define	MSV1_0_ALLOW_FORCE_GUEST		0x00002000
95 #define	MSV1_0_CLEARTEXT_PASSWORD_SUPPLIED	0x00004000
96 #define	MSV1_0_USE_DOMAIN_FOR_ROUTING_ONLY	0x00008000
97 #define	MSV1_0_SUBAUTHENTICATION_DLL_EX		0x00100000
98 
99 /*
100  * This is a duplicate of the netr_credential
101  * from netlogon.ndl.
102  */
103 typedef struct netr_cred {
104 	BYTE data[NETR_CRED_DATA_SZ];
105 } netr_cred_t;
106 
107 typedef struct netr_session_key {
108 	BYTE key[NETR_SESSKEY_MAXSZ];
109 	short len;
110 } netr_session_key_t;
111 
112 #define	NETR_FLG_NULL		0x00000001
113 #define	NETR_FLG_VALID		0x00000001
114 #define	NETR_FLG_INIT		0x00000002
115 
116 /*
117  * 120-byte machine account password (null-terminated)
118  */
119 #define	NETR_MACHINE_ACCT_PASSWD_MAX	120 + 1
120 
121 typedef struct netr_info {
122 	DWORD flags;
123 	char server[NETBIOS_NAME_SZ * 2];
124 	char hostname[NETBIOS_NAME_SZ * 2];
125 	netr_cred_t client_challenge;
126 	netr_cred_t server_challenge;
127 	netr_cred_t client_credential;
128 	netr_cred_t server_credential;
129 	netr_session_key_t session_key;
130 	BYTE password[NETR_MACHINE_ACCT_PASSWD_MAX];
131 	time_t timestamp;
132 } netr_info_t;
133 
134 /*
135  * NETLOGON private interface.
136  */
137 int netr_gen_skey64(netr_info_t *);
138 int netr_gen_skey128(netr_info_t *);
139 
140 int netr_gen_credentials(BYTE *, netr_cred_t *, DWORD, netr_cred_t *);
141 
142 
143 #define	NETR_A2H(c) (isdigit(c)) ? ((c) - '0') : ((c) - 'A' + 10)
144 
145 #ifdef __cplusplus
146 }
147 #endif
148 
149 #endif /* _SMBSRV_NETRAUTH_H */
150