4 Copyright (c) 2010, Simo Sorce <idra@samba.org>
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "param/param.h"
22 #include "dsdb/samdb/samdb.h"
23 #include "auth/auth.h"
24 #include "auth/credentials/credentials.h"
25 #include "system/kerberos.h"
27 #include "mit_samba_interface.h"
28 #include "auth/kerberos/kerberos.h"
29 #include "kdc/samba_kdc.h"
30 #include "kdc/pac-glue.h"
31 #include "kdc/db-glue.h"
33 const int mit_samba_interface_version
= MIT_SAMBA_INTERFACE_VERSION
;
35 struct mit_samba_context
{
36 struct auth_session_info
*session_info
;
38 /* for compat with hdb plugin common code */
40 struct samba_kdc_db_context
*db_ctx
;
43 static void mit_samba_context_free(struct mit_samba_context
*ctx
)
45 /* free heimdal's krb5_context */
47 krb5_free_context(ctx
->context
);
50 /* then free everything else */
54 static int mit_samba_context_init(struct mit_samba_context
**_ctx
)
56 struct mit_samba_context
*ctx
;
57 const char *s4_conf_file
;
61 ctx
= talloc(NULL
, struct mit_samba_context
);
67 ctx
->db_ctx
= talloc_zero(ctx
, struct samba_kdc_db_context
);
73 ctx
->db_ctx
->ev_ctx
= tevent_context_init(ctx
);
74 if (!ctx
->db_ctx
->ev_ctx
) {
78 ctx
->db_ctx
->lp_ctx
= loadparm_init(ctx
);
79 if (!ctx
->db_ctx
->lp_ctx
) {
84 /* init s4 configuration */
85 s4_conf_file
= lp_configfile(ctx
->db_ctx
->lp_ctx
);
87 lp_load(ctx
->db_ctx
->lp_ctx
, s4_conf_file
);
89 lp_load_default(ctx
->db_ctx
->lp_ctx
);
92 ctx
->session_info
= system_session(ctx
->db_ctx
->lp_ctx
);
93 if (!ctx
->session_info
) {
98 cli_credentials_set_kerberos_state(ctx
->session_info
->credentials
,
99 CRED_DONT_USE_KERBEROS
);
101 ctx
->db_ctx
->ic_ctx
= lp_iconv_convenience(ctx
->db_ctx
->lp_ctx
);
103 ctx
->db_ctx
->samdb
= samdb_connect(ctx
,
107 if (!ctx
->db_ctx
->samdb
) {
112 /* init heimdal's krb_context and log facilities */
113 ret
= smb_krb5_init_context_basic(ctx
,
125 mit_samba_context_free(ctx
);
133 static int mit_samba_get_principal(struct mit_samba_context
*ctx
,
134 char *principal_string
,
136 hdb_entry_ex
**_hentry
)
138 krb5_principal principal
;
139 hdb_entry_ex
*hentry
;
142 hentry
= talloc(ctx
, hdb_entry_ex
);
147 ret
= krb5_parse_name(ctx
->context
, principal_string
, &principal
);
152 ret
= samba_kdc_fetch(ctx
->context
, ctx
->db_ctx
,
153 principal
, flags
, hentry
);
155 krb5_free_principal(ctx
->context
, principal
);
161 talloc_steal(hentry
->ctx
, hentry
);
167 static int mit_samba_get_firstkey(struct mit_samba_context
*ctx
,
168 hdb_entry_ex
**_hentry
)
170 hdb_entry_ex
*hentry
;
173 hentry
= talloc(ctx
, hdb_entry_ex
);
178 ret
= samba_kdc_firstkey(ctx
->context
, ctx
->db_ctx
, hentry
);
183 talloc_steal(hentry
->ctx
, hentry
);
189 static int mit_samba_get_nextkey(struct mit_samba_context
*ctx
,
190 hdb_entry_ex
**_hentry
)
192 hdb_entry_ex
*hentry
;
195 hentry
= talloc(ctx
, hdb_entry_ex
);
200 ret
= samba_kdc_nextkey(ctx
->context
, ctx
->db_ctx
, hentry
);
205 talloc_steal(hentry
->ctx
, hentry
);
211 static int mit_samba_get_pac_data(struct mit_samba_context
*ctx
,
212 hdb_entry_ex
*client
,
219 tmp_ctx
= talloc_named(ctx
, 0, "mit_samba_get_pac_data context");
224 nt_status
= samba_kdc_get_pac_blob(tmp_ctx
, client
, &pac_blob
);
225 if (!NT_STATUS_IS_OK(nt_status
)) {
226 talloc_free(tmp_ctx
);
230 data
->data
= (uint8_t *)malloc(pac_blob
->length
);
232 talloc_free(tmp_ctx
);
235 memcpy(data
->data
, pac_blob
->data
, pac_blob
->length
);
236 data
->length
= pac_blob
->length
;
238 talloc_free(tmp_ctx
);
242 static int mit_samba_update_pac_data(struct mit_samba_context
*ctx
,
243 hdb_entry_ex
*client
,
245 DATA_BLOB
*logon_data
)
248 DATA_BLOB
*logon_blob
;
249 krb5_error_code code
;
254 /* The user account may be set not to want the PAC */
255 if (client
&& !samba_princ_needs_pac(client
)) {
259 tmp_ctx
= talloc_named(ctx
, 0, "mit_samba_update_pac_data context");
264 logon_blob
= talloc_zero(tmp_ctx
, DATA_BLOB
);
270 code
= krb5_pac_parse(ctx
->context
,
271 pac_data
->data
, pac_data
->length
, &pac
);
277 nt_status
= samba_kdc_update_pac_blob(tmp_ctx
, ctx
->context
,
280 if (!NT_STATUS_IS_OK(nt_status
)) {
281 DEBUG(0, ("Building PAC failed: %s\n",
282 nt_errstr(nt_status
)));
287 logon_data
->data
= (uint8_t *)malloc(logon_blob
->length
);
288 if (!logon_data
->data
) {
292 memcpy(logon_data
->data
, logon_blob
->data
, logon_blob
->length
);
293 logon_data
->length
= logon_blob
->length
;
298 if (pac
) krb5_pac_free(ctx
->context
, pac
);
299 talloc_free(tmp_ctx
);
303 static int mit_samba_check_client_access(struct mit_samba_context
*ctx
,
304 hdb_entry_ex
*client
,
305 const char *client_name
,
306 hdb_entry_ex
*server
,
307 const char *server_name
,
308 const char *netbios_name
,
309 bool password_change
,
312 struct samba_kdc_entry
*kdc_entry
;
315 kdc_entry
= talloc_get_type(client
->ctx
, struct samba_kdc_entry
);
317 nt_status
= samba_kdc_check_client_access(kdc_entry
,
322 if (!NT_STATUS_IS_OK(nt_status
)) {
323 if (NT_STATUS_EQUAL(nt_status
, NT_STATUS_NO_MEMORY
)) {
327 samba_kdc_build_edata_reply(nt_status
, e_data
);
329 return samba_kdc_map_policy_err(nt_status
);
335 static int mit_samba_check_s4u2proxy(struct mit_samba_context
*ctx
,
337 const char *target_name
,
338 bool is_nt_enterprise_name
)
340 krb5_principal target_principal
;
344 if (is_nt_enterprise_name
) {
345 flags
= KRB5_PRINCIPAL_PARSE_ENTERPRISE
;
348 ret
= krb5_parse_name_flags(ctx
->context
, target_name
,
349 flags
, &target_principal
);
354 ret
= samba_kdc_check_constrained_delegation(ctx
->context
,
359 krb5_free_principal(ctx
->context
, target_principal
);
364 struct mit_samba_function_table mit_samba_function_table
= {
365 mit_samba_context_init
,
366 mit_samba_context_free
,
367 mit_samba_get_principal
,
368 mit_samba_get_firstkey
,
369 mit_samba_get_nextkey
,
370 mit_samba_get_pac_data
,
371 mit_samba_update_pac_data
,
372 mit_samba_check_client_access
,
373 mit_samba_check_s4u2proxy