get_s.c revision 55682
1210284Sjmallett/* 2232812Sjmallett * Copyright (c) 1997, 1998, 1999 Kungliga Tekniska H�gskolan 3215990Sjmallett * (Royal Institute of Technology, Stockholm, Sweden). 4210284Sjmallett * All rights reserved. 5210284Sjmallett * 6215990Sjmallett * Redistribution and use in source and binary forms, with or without 7215990Sjmallett * modification, are permitted provided that the following conditions 8215990Sjmallett * are met: 9210284Sjmallett * 10215990Sjmallett * 1. Redistributions of source code must retain the above copyright 11215990Sjmallett * notice, this list of conditions and the following disclaimer. 12210284Sjmallett * 13215990Sjmallett * 2. Redistributions in binary form must reproduce the above copyright 14215990Sjmallett * notice, this list of conditions and the following disclaimer in the 15215990Sjmallett * documentation and/or other materials provided with the distribution. 16215990Sjmallett * 17215990Sjmallett * 3. Neither the name of the Institute nor the names of its contributors 18232812Sjmallett * may be used to endorse or promote products derived from this software 19215990Sjmallett * without specific prior written permission. 20215990Sjmallett * 21215990Sjmallett * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 22215990Sjmallett * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23215990Sjmallett * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24215990Sjmallett * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 25215990Sjmallett * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26215990Sjmallett * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27215990Sjmallett * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28215990Sjmallett * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29232812Sjmallett * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30215990Sjmallett * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31215990Sjmallett * SUCH DAMAGE. 32215990Sjmallett */ 33215990Sjmallett 34215990Sjmallett#include "kadm5_locl.h" 35215990Sjmallett 36215990SjmallettRCSID("$Id: get_s.c,v 1.11 1999/12/26 19:38:23 assar Exp $"); 37215990Sjmallett 38210284Sjmallettkadm5_ret_t 39210284Sjmallettkadm5_s_get_principal(void *server_handle, 40210284Sjmallett krb5_principal princ, 41210284Sjmallett kadm5_principal_ent_t out, 42210284Sjmallett u_int32_t mask) 43210284Sjmallett{ 44210284Sjmallett kadm5_server_context *context = server_handle; 45215990Sjmallett kadm5_ret_t ret; 46210284Sjmallett hdb_entry ent; 47210284Sjmallett 48210284Sjmallett ent.principal = princ; 49210284Sjmallett ret = context->db->open(context->context, context->db, O_RDONLY, 0); 50210284Sjmallett if(ret) 51232812Sjmallett return ret; 52210284Sjmallett ret = context->db->fetch(context->context, context->db, 53210284Sjmallett HDB_F_DECRYPT, &ent); 54210284Sjmallett context->db->close(context->context, context->db); 55210284Sjmallett if(ret) 56210284Sjmallett return _kadm5_error_code(ret); 57232812Sjmallett 58232812Sjmallett memset(out, 0, sizeof(*out)); 59210284Sjmallett if(mask & KADM5_PRINCIPAL) 60210284Sjmallett ret = krb5_copy_principal(context->context, ent.principal, 61210284Sjmallett &out->principal); 62232812Sjmallett if(ret) 63232812Sjmallett goto out; 64232812Sjmallett if(mask & KADM5_PRINC_EXPIRE_TIME && ent.valid_end) 65232812Sjmallett out->princ_expire_time = *ent.valid_end; 66232812Sjmallett if(mask & KADM5_PW_EXPIRATION && ent.pw_end) 67232812Sjmallett out->pw_expiration = *ent.pw_end; 68232812Sjmallett if(mask & KADM5_LAST_PWD_CHANGE) 69232812Sjmallett /* XXX implement */; 70232812Sjmallett if(mask & KADM5_ATTRIBUTES){ 71232812Sjmallett out->attributes |= ent.flags.postdate ? 0 : KRB5_KDB_DISALLOW_POSTDATED; 72210284Sjmallett out->attributes |= ent.flags.forwardable ? 0 : KRB5_KDB_DISALLOW_FORWARDABLE; 73210284Sjmallett out->attributes |= ent.flags.initial ? KRB5_KDB_DISALLOW_TGT_BASED : 0; 74210284Sjmallett out->attributes |= ent.flags.renewable ? 0 : KRB5_KDB_DISALLOW_RENEWABLE; 75210284Sjmallett out->attributes |= ent.flags.proxiable ? 0 : KRB5_KDB_DISALLOW_PROXIABLE; 76210284Sjmallett out->attributes |= ent.flags.invalid ? KRB5_KDB_DISALLOW_ALL_TIX : 0; 77210284Sjmallett out->attributes |= ent.flags.require_preauth ? KRB5_KDB_REQUIRES_PRE_AUTH : 0; 78210284Sjmallett out->attributes |= ent.flags.server ? 0 : KRB5_KDB_DISALLOW_SVR; 79210284Sjmallett out->attributes |= ent.flags.change_pw ? KRB5_KDB_PWCHANGE_SERVICE : 0; 80210284Sjmallett } 81210284Sjmallett if(mask & KADM5_MAX_LIFE && ent.max_life) 82210284Sjmallett out->max_life = *ent.max_life; 83210284Sjmallett if(mask & KADM5_MOD_TIME) { 84210284Sjmallett if(ent.modified_by) 85210284Sjmallett out->mod_date = ent.modified_by->time; 86210284Sjmallett else 87210284Sjmallett out->mod_date = ent.created_by.time; 88210284Sjmallett } 89210284Sjmallett if(mask & KADM5_MOD_NAME) { 90210284Sjmallett if(ent.modified_by) { 91210284Sjmallett if (ent.modified_by->principal != NULL) 92210284Sjmallett ret = krb5_copy_principal(context->context, 93210284Sjmallett ent.modified_by->principal, 94210284Sjmallett &out->mod_name); 95210284Sjmallett } else 96210284Sjmallett ret = krb5_copy_principal(context->context, 97210284Sjmallett ent.created_by.principal, 98210284Sjmallett &out->mod_name); 99210284Sjmallett } 100210284Sjmallett if(ret) 101210284Sjmallett goto out; 102210284Sjmallett 103210284Sjmallett if(mask & KADM5_KVNO) 104210284Sjmallett out->kvno = ent.kvno; 105210284Sjmallett if(mask & KADM5_MKVNO) { 106210284Sjmallett int n; 107210284Sjmallett out->mkvno = 0; /* XXX */ 108210284Sjmallett for(n = 0; n < ent.keys.len; n++) 109210284Sjmallett if(ent.keys.val[n].mkvno) { 110210284Sjmallett out->mkvno = *ent.keys.val[n].mkvno; /* XXX this isn't right */ 111210284Sjmallett break; 112210284Sjmallett } 113210284Sjmallett } 114210284Sjmallett if(mask & KADM5_AUX_ATTRIBUTES) 115210284Sjmallett /* XXX implement */; 116210284Sjmallett if(mask & KADM5_POLICY) 117210284Sjmallett out->policy = NULL; 118210284Sjmallett if(mask & KADM5_MAX_RLIFE && ent.max_renew) 119210284Sjmallett out->max_renewable_life = *ent.max_renew; 120210284Sjmallett if(mask & KADM5_LAST_SUCCESS) 121210284Sjmallett /* XXX implement */; 122210284Sjmallett if(mask & KADM5_LAST_FAILED) 123210284Sjmallett /* XXX implement */; 124210284Sjmallett if(mask & KADM5_FAIL_AUTH_COUNT) 125210284Sjmallett /* XXX implement */; 126210284Sjmallett if(mask & KADM5_KEY_DATA){ 127210284Sjmallett int i; 128210284Sjmallett Key *key; 129210284Sjmallett krb5_key_data *kd; 130210284Sjmallett krb5_salt salt; 131210284Sjmallett krb5_data *sp; 132210284Sjmallett krb5_get_pw_salt(context->context, ent.principal, &salt); 133210284Sjmallett out->key_data = malloc(ent.keys.len * sizeof(*out->key_data)); 134210284Sjmallett for(i = 0; i < ent.keys.len; i++){ 135210284Sjmallett key = &ent.keys.val[i]; 136210284Sjmallett kd = &out->key_data[i]; 137210284Sjmallett kd->key_data_ver = 2; 138210284Sjmallett kd->key_data_kvno = ent.kvno; 139210284Sjmallett kd->key_data_type[0] = key->key.keytype; 140232812Sjmallett if(key->salt) 141232812Sjmallett kd->key_data_type[1] = key->salt->type; 142232812Sjmallett else 143232812Sjmallett kd->key_data_type[1] = pa_pw_salt; 144232812Sjmallett /* setup key */ 145232812Sjmallett kd->key_data_length[0] = key->key.keyvalue.length; 146232812Sjmallett kd->key_data_contents[0] = malloc(kd->key_data_length[0]); 147232812Sjmallett if(kd->key_data_contents[0] == NULL){ 148232812Sjmallett ret = ENOMEM; 149232812Sjmallett break; 150232812Sjmallett } 151232812Sjmallett memcpy(kd->key_data_contents[0], key->key.keyvalue.data, 152232812Sjmallett kd->key_data_length[0]); 153232812Sjmallett /* setup salt */ 154232812Sjmallett if(key->salt) 155232812Sjmallett sp = &key->salt->salt; 156232812Sjmallett else 157232812Sjmallett sp = &salt.saltvalue; 158232812Sjmallett kd->key_data_length[1] = sp->length; 159232812Sjmallett kd->key_data_contents[1] = malloc(kd->key_data_length[1]); 160232812Sjmallett if(kd->key_data_length[1] != 0 161232812Sjmallett && kd->key_data_contents[1] == NULL) { 162232812Sjmallett memset(kd->key_data_contents[0], 0, kd->key_data_length[0]); 163232812Sjmallett ret = ENOMEM; 164232812Sjmallett break; 165232812Sjmallett } 166232812Sjmallett memcpy(kd->key_data_contents[1], sp->data, kd->key_data_length[1]); 167232812Sjmallett out->n_key_data = i + 1; 168232812Sjmallett } 169232812Sjmallett krb5_free_salt(context->context, salt); 170232812Sjmallett } 171232812Sjmallett if(ret){ 172232812Sjmallett kadm5_free_principal_ent(context, out); 173232812Sjmallett goto out; 174232812Sjmallett } 175232812Sjmallett if(mask & KADM5_TL_DATA) 176232812Sjmallett /* XXX implement */; 177232812Sjmallettout: 178232812Sjmallett hdb_free_entry(context->context, &ent); 179232812Sjmallett 180232812Sjmallett return _kadm5_error_code(ret); 181232812Sjmallett} 182232812Sjmallett