155682Smarkm/* 2233294Sstas * Copyright (c) 1997-2004 Kungliga Tekniska H��gskolan 3233294Sstas * (Royal Institute of Technology, Stockholm, Sweden). 4233294Sstas * All rights reserved. 555682Smarkm * 6233294Sstas * Redistribution and use in source and binary forms, with or without 7233294Sstas * modification, are permitted provided that the following conditions 8233294Sstas * are met: 955682Smarkm * 10233294Sstas * 1. Redistributions of source code must retain the above copyright 11233294Sstas * notice, this list of conditions and the following disclaimer. 1255682Smarkm * 13233294Sstas * 2. Redistributions in binary form must reproduce the above copyright 14233294Sstas * notice, this list of conditions and the following disclaimer in the 15233294Sstas * documentation and/or other materials provided with the distribution. 1655682Smarkm * 17233294Sstas * 3. Neither the name of the Institute nor the names of its contributors 18233294Sstas * may be used to endorse or promote products derived from this software 19233294Sstas * without specific prior written permission. 2055682Smarkm * 21233294Sstas * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 22233294Sstas * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23233294Sstas * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24233294Sstas * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 25233294Sstas * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26233294Sstas * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27233294Sstas * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28233294Sstas * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29233294Sstas * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30233294Sstas * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31233294Sstas * SUCH DAMAGE. 3255682Smarkm */ 3355682Smarkm 3455682Smarkm#include "ktutil_locl.h" 3555682Smarkm 36233294SstasRCSID("$Id$"); 3755682Smarkm 3872445Sassar 3972445Sassarstatic krb5_boolean 4072445Sassarcompare_keyblock(const krb5_keyblock *a, const krb5_keyblock *b) 4172445Sassar{ 4272445Sassar if(a->keytype != b->keytype || 4372445Sassar a->keyvalue.length != b->keyvalue.length || 4472445Sassar memcmp(a->keyvalue.data, b->keyvalue.data, a->keyvalue.length) != 0) 4572445Sassar return FALSE; 4672445Sassar return TRUE; 4772445Sassar} 4872445Sassar 49233294Sstasint 50233294Sstaskt_copy (void *opt, int argc, char **argv) 5172445Sassar{ 5272445Sassar krb5_error_code ret; 5372445Sassar krb5_keytab src_keytab, dst_keytab; 5472445Sassar krb5_kt_cursor cursor; 5572445Sassar krb5_keytab_entry entry, dummy; 56233294Sstas const char *from = argv[0]; 57233294Sstas const char *to = argv[1]; 5872445Sassar 5972445Sassar ret = krb5_kt_resolve (context, from, &src_keytab); 6072445Sassar if (ret) { 6172445Sassar krb5_warn (context, ret, "resolving src keytab `%s'", from); 6278527Sassar return 1; 6372445Sassar } 6472445Sassar 6572445Sassar ret = krb5_kt_resolve (context, to, &dst_keytab); 6672445Sassar if (ret) { 6772445Sassar krb5_kt_close (context, src_keytab); 6872445Sassar krb5_warn (context, ret, "resolving dst keytab `%s'", to); 6978527Sassar return 1; 7072445Sassar } 7172445Sassar 7272445Sassar ret = krb5_kt_start_seq_get (context, src_keytab, &cursor); 7372445Sassar if (ret) { 7472445Sassar krb5_warn (context, ret, "krb5_kt_start_seq_get %s", keytab_string); 7578527Sassar goto out; 7672445Sassar } 7772445Sassar 7878527Sassar if (verbose_flag) 7978527Sassar fprintf(stderr, "copying %s to %s\n", from, to); 8078527Sassar 8172445Sassar while((ret = krb5_kt_next_entry(context, src_keytab, 8272445Sassar &entry, &cursor)) == 0) { 8372445Sassar char *name_str; 8472445Sassar char *etype_str; 85178825Sdfr ret = krb5_unparse_name (context, entry.principal, &name_str); 86178825Sdfr if(ret) { 87178825Sdfr krb5_warn(context, ret, "krb5_unparse_name"); 88178825Sdfr name_str = NULL; /* XXX */ 89178825Sdfr } 90178825Sdfr ret = krb5_enctype_to_string(context, entry.keyblock.keytype, &etype_str); 91178825Sdfr if(ret) { 92178825Sdfr krb5_warn(context, ret, "krb5_enctype_to_string"); 93178825Sdfr etype_str = NULL; /* XXX */ 94178825Sdfr } 95233294Sstas ret = krb5_kt_get_entry(context, dst_keytab, 96233294Sstas entry.principal, 97233294Sstas entry.vno, 9872445Sassar entry.keyblock.keytype, 9972445Sassar &dummy); 10072445Sassar if(ret == 0) { 10172445Sassar /* this entry is already in the new keytab, so no need to 10272445Sassar copy it; if the keyblocks are not the same, something 10372445Sassar is weird, so complain about that */ 10472445Sassar if(!compare_keyblock(&entry.keyblock, &dummy.keyblock)) { 10572445Sassar krb5_warnx(context, "entry with different keyvalue " 106233294Sstas "already exists for %s, keytype %s, kvno %d", 10772445Sassar name_str, etype_str, entry.vno); 10872445Sassar } 10972445Sassar krb5_kt_free_entry(context, &dummy); 11072445Sassar krb5_kt_free_entry (context, &entry); 11172445Sassar free(name_str); 11272445Sassar free(etype_str); 11372445Sassar continue; 11472445Sassar } else if(ret != KRB5_KT_NOTFOUND) { 115233294Sstas krb5_warn (context, ret, "%s: fetching %s/%s/%u", 116178825Sdfr to, name_str, etype_str, entry.vno); 11772445Sassar krb5_kt_free_entry (context, &entry); 11872445Sassar free(name_str); 11972445Sassar free(etype_str); 12072445Sassar break; 12172445Sassar } 12272445Sassar if (verbose_flag) 123233294Sstas fprintf (stderr, "copying %s, keytype %s, kvno %d\n", name_str, 12472445Sassar etype_str, entry.vno); 12572445Sassar ret = krb5_kt_add_entry (context, dst_keytab, &entry); 12672445Sassar krb5_kt_free_entry (context, &entry); 12772445Sassar if (ret) { 128233294Sstas krb5_warn (context, ret, "%s: adding %s/%s/%u", 129178825Sdfr to, name_str, etype_str, entry.vno); 13072445Sassar free(name_str); 13172445Sassar free(etype_str); 13272445Sassar break; 13372445Sassar } 13472445Sassar free(name_str); 13572445Sassar free(etype_str); 13672445Sassar } 13772445Sassar krb5_kt_end_seq_get (context, src_keytab, &cursor); 13872445Sassar 13978527Sassar out: 14072445Sassar krb5_kt_close (context, src_keytab); 14172445Sassar krb5_kt_close (context, dst_keytab); 142178825Sdfr return ret != 0; 14372445Sassar} 144