Allow KDC to always return the salt in the PA-ETYPE-INFO[2]
[heimdal.git] / lib / gssapi / test_cred.c
blob9eaabda0a21c4a0d024c26b4ed4a2f08124ca0a2
1 /*
2 * Copyright (c) 2003-2004 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
4 * All rights reserved.
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of KTH nor the names of its contributors may be
18 * used to endorse or promote products derived from this software without
19 * specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
22 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
24 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
25 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28 * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29 * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
30 * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
31 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34 #ifdef HAVE_CONFIG_H
35 #include <config.h>
36 #endif
38 #include <roken.h>
39 #include <stdio.h>
40 #include <stdlib.h>
41 #include <string.h>
42 #include <stdarg.h>
43 #include <gssapi.h>
44 #include <gssapi_krb5.h>
45 #include <gssapi_spnego.h>
46 #include <err.h>
47 #include <getarg.h>
49 static int anon_flag = 0;
51 static void
52 gss_print_errors (int min_stat)
54 OM_uint32 new_stat;
55 OM_uint32 msg_ctx = 0;
56 gss_buffer_desc status_string;
57 OM_uint32 ret;
59 do {
60 ret = gss_display_status (&new_stat,
61 min_stat,
62 GSS_C_MECH_CODE,
63 GSS_C_NO_OID,
64 &msg_ctx,
65 &status_string);
66 if (!GSS_ERROR(ret)) {
67 fprintf (stderr, "%.*s\n", (int)status_string.length,
68 (char *)status_string.value);
69 gss_release_buffer (&new_stat, &status_string);
71 } while (!GSS_ERROR(ret) && msg_ctx != 0);
74 static void
75 gss_err(int exitval, int status, const char *fmt, ...)
77 va_list args;
79 va_start(args, fmt);
80 vwarnx (fmt, args);
81 gss_print_errors (status);
82 va_end(args);
83 exit (exitval);
86 static void
87 acquire_release_loop(gss_name_t name, int counter, gss_cred_usage_t usage)
89 OM_uint32 maj_stat, min_stat;
90 gss_cred_id_t cred;
91 int i;
93 for (i = 0; i < counter; i++) {
94 maj_stat = gss_acquire_cred(&min_stat, name,
95 GSS_C_INDEFINITE,
96 GSS_C_NO_OID_SET,
97 usage,
98 &cred,
99 NULL,
100 NULL);
101 if (maj_stat != GSS_S_COMPLETE)
102 gss_err(1, min_stat, "aquire %d %d != GSS_S_COMPLETE",
103 i, (int)maj_stat);
105 maj_stat = gss_release_cred(&min_stat, &cred);
106 if (maj_stat != GSS_S_COMPLETE)
107 gss_err(1, min_stat, "release %d %d != GSS_S_COMPLETE",
108 i, (int)maj_stat);
113 static void
114 acquire_add_release_add(gss_name_t name, gss_cred_usage_t usage)
116 OM_uint32 maj_stat, min_stat;
117 gss_cred_id_t cred, cred2, cred3;
118 gss_OID mech_oid = anon_flag ? GSS_SANON_X25519_MECHANISM : GSS_KRB5_MECHANISM;
120 maj_stat = gss_acquire_cred(&min_stat, name,
121 GSS_C_INDEFINITE,
122 GSS_C_NO_OID_SET,
123 usage,
124 &cred,
125 NULL,
126 NULL);
127 if (maj_stat != GSS_S_COMPLETE)
128 gss_err(1, min_stat, "aquire %d != GSS_S_COMPLETE", (int)maj_stat);
130 maj_stat = gss_add_cred(&min_stat,
131 cred,
132 GSS_C_NO_NAME,
133 mech_oid,
134 usage,
135 GSS_C_INDEFINITE,
136 GSS_C_INDEFINITE,
137 &cred2,
138 NULL,
139 NULL,
140 NULL);
142 if (maj_stat != GSS_S_COMPLETE)
143 gss_err(1, min_stat, "add_cred %d != GSS_S_COMPLETE", (int)maj_stat);
145 maj_stat = gss_release_cred(&min_stat, &cred);
146 if (maj_stat != GSS_S_COMPLETE)
147 gss_err(1, min_stat, "release %d != GSS_S_COMPLETE", (int)maj_stat);
149 maj_stat = gss_add_cred(&min_stat,
150 cred2,
151 GSS_C_NO_NAME,
152 mech_oid,
153 GSS_C_BOTH,
154 GSS_C_INDEFINITE,
155 GSS_C_INDEFINITE,
156 &cred3,
157 NULL,
158 NULL,
159 NULL);
160 if (maj_stat != GSS_S_COMPLETE)
161 gss_err(1, min_stat, "add_cred 2 %d != GSS_S_COMPLETE", (int)maj_stat);
163 maj_stat = gss_release_cred(&min_stat, &cred2);
164 if (maj_stat != GSS_S_COMPLETE)
165 gss_err(1, min_stat, "release 2 %d != GSS_S_COMPLETE", (int)maj_stat);
167 maj_stat = gss_release_cred(&min_stat, &cred3);
168 if (maj_stat != GSS_S_COMPLETE)
169 gss_err(1, min_stat, "release 3 %d != GSS_S_COMPLETE", (int)maj_stat);
172 static int version_flag = 0;
173 static int help_flag = 0;
175 static struct getargs args[] = {
176 {"anonymous", 0, arg_flag, &anon_flag, "try anonymous creds", NULL },
177 {"version", 0, arg_flag, &version_flag, "print version", NULL },
178 {"help", 0, arg_flag, &help_flag, NULL, NULL }
181 static void
182 usage (int ret)
184 arg_printusage (args, sizeof(args)/sizeof(*args),
185 NULL, "service@host");
186 exit (ret);
191 main(int argc, char **argv)
193 struct gss_buffer_desc_struct name_buffer;
194 OM_uint32 maj_stat, min_stat;
195 gss_name_t name;
196 int optidx = 0;
198 setprogname(argv[0]);
199 if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx))
200 usage(1);
202 if (help_flag)
203 usage (0);
205 if(version_flag){
206 print_version(NULL);
207 exit(0);
210 argc -= optidx;
211 argv += optidx;
213 if (argc < 1)
214 errx(1, "argc < 1");
216 name_buffer.value = argv[0];
217 name_buffer.length = strlen(argv[0]);
219 maj_stat = gss_import_name(&min_stat, &name_buffer,
220 GSS_C_NT_HOSTBASED_SERVICE,
221 &name);
222 if (maj_stat != GSS_S_COMPLETE)
223 errx(1, "import name error");
225 acquire_release_loop(name, 100, GSS_C_ACCEPT);
226 acquire_release_loop(name, 100, GSS_C_INITIATE);
227 acquire_release_loop(name, 100, GSS_C_BOTH);
229 acquire_add_release_add(name, GSS_C_ACCEPT);
230 acquire_add_release_add(name, GSS_C_INITIATE);
231 acquire_add_release_add(name, GSS_C_BOTH);
233 gss_release_name(&min_stat, &name);
235 return 0;