1/*-
2 * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3 *
4 * Copyright (c) 2005 Doug Rabson
5 * All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 *    notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 *    notice, this list of conditions and the following disclaimer in the
14 *    documentation and/or other materials provided with the distribution.
15 *
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 *
28 *	$FreeBSD$
29 */
30
31#include <unistd.h>
32#include <sys/queue.h>
33
34typedef OM_uint32 _gss_acquire_cred_t
35	      (OM_uint32 *,            /* minor_status */
36	       const gss_name_t,       /* desired_name */
37	       OM_uint32,              /* time_req */
38	       const gss_OID_set,      /* desired_mechs */
39	       gss_cred_usage_t,       /* cred_usage */
40	       gss_cred_id_t *,        /* output_cred_handle */
41	       gss_OID_set *,          /* actual_mechs */
42	       OM_uint32 *             /* time_rec */
43	      );
44
45typedef OM_uint32 _gss_release_cred_t
46	      (OM_uint32 *,            /* minor_status */
47	       gss_cred_id_t *         /* cred_handle */
48	      );
49
50typedef OM_uint32 _gss_init_sec_context_t
51	      (OM_uint32 *,            /* minor_status */
52	       const gss_cred_id_t,    /* initiator_cred_handle */
53	       gss_ctx_id_t *,         /* context_handle */
54	       const gss_name_t,       /* target_name */
55	       const gss_OID,          /* mech_type */
56	       OM_uint32,              /* req_flags */
57	       OM_uint32,              /* time_req */
58	       const gss_channel_bindings_t,
59				       /* input_chan_bindings */
60	       const gss_buffer_t,     /* input_token */
61	       gss_OID *,              /* actual_mech_type */
62	       gss_buffer_t,           /* output_token */
63	       OM_uint32 *,            /* ret_flags */
64	       OM_uint32 *             /* time_rec */
65	      );
66
67typedef OM_uint32 _gss_accept_sec_context_t
68	      (OM_uint32 *,            /* minor_status */
69	       gss_ctx_id_t *,         /* context_handle */
70	       const gss_cred_id_t,    /* acceptor_cred_handle */
71	       const gss_buffer_t,     /* input_token_buffer */
72	       const gss_channel_bindings_t,
73				       /* input_chan_bindings */
74	       gss_name_t *,           /* src_name */
75	       gss_OID *,              /* mech_type */
76	       gss_buffer_t,           /* output_token */
77	       OM_uint32 *,            /* ret_flags */
78	       OM_uint32 *,            /* time_rec */
79	       gss_cred_id_t *         /* delegated_cred_handle */
80	      );
81
82typedef OM_uint32 _gss_process_context_token_t
83	      (OM_uint32 *,            /* minor_status */
84	       const gss_ctx_id_t,     /* context_handle */
85	       const gss_buffer_t      /* token_buffer */
86	      );
87
88typedef OM_uint32 _gss_delete_sec_context_t
89	      (OM_uint32 *,            /* minor_status */
90	       gss_ctx_id_t *,         /* context_handle */
91	       gss_buffer_t            /* output_token */
92	      );
93
94typedef OM_uint32 _gss_context_time_t
95	      (OM_uint32 *,            /* minor_status */
96	       const gss_ctx_id_t,     /* context_handle */
97	       OM_uint32 *             /* time_rec */
98	      );
99
100typedef OM_uint32 _gss_get_mic_t
101	      (OM_uint32 *,            /* minor_status */
102	       const gss_ctx_id_t,     /* context_handle */
103	       gss_qop_t,              /* qop_req */
104	       const gss_buffer_t,     /* message_buffer */
105	       gss_buffer_t            /* message_token */
106	      );
107
108typedef OM_uint32 _gss_verify_mic_t
109	      (OM_uint32 *,            /* minor_status */
110	       const gss_ctx_id_t,     /* context_handle */
111	       const gss_buffer_t,     /* message_buffer */
112	       const gss_buffer_t,     /* token_buffer */
113	       gss_qop_t *             /* qop_state */
114	      );
115
116typedef OM_uint32 _gss_wrap_t
117	      (OM_uint32 *,            /* minor_status */
118	       const gss_ctx_id_t,     /* context_handle */
119	       int,                    /* conf_req_flag */
120	       gss_qop_t,              /* qop_req */
121	       const gss_buffer_t,     /* input_message_buffer */
122	       int *,                  /* conf_state */
123	       gss_buffer_t            /* output_message_buffer */
124	      );
125
126typedef OM_uint32 _gss_unwrap_t
127	      (OM_uint32 *,            /* minor_status */
128	       const gss_ctx_id_t,     /* context_handle */
129	       const gss_buffer_t,     /* input_message_buffer */
130	       gss_buffer_t,           /* output_message_buffer */
131	       int *,                  /* conf_state */
132	       gss_qop_t *             /* qop_state */
133	      );
134
135typedef OM_uint32 _gss_display_status_t
136	      (OM_uint32 *,            /* minor_status */
137	       OM_uint32,              /* status_value */
138	       int,                    /* status_type */
139	       const gss_OID,          /* mech_type */
140	       OM_uint32 *,            /* message_context */
141	       gss_buffer_t            /* status_string */
142	      );
143
144typedef OM_uint32 _gss_indicate_mechs_t
145	      (OM_uint32 *,            /* minor_status */
146	       gss_OID_set *           /* mech_set */
147	      );
148
149typedef OM_uint32 _gss_compare_name_t
150	      (OM_uint32 *,            /* minor_status */
151	       const gss_name_t,       /* name1 */
152	       const gss_name_t,       /* name2 */
153	       int *                   /* name_equal */
154	      );
155
156typedef OM_uint32 _gss_display_name_t
157	      (OM_uint32 *,            /* minor_status */
158	       const gss_name_t,       /* input_name */
159	       gss_buffer_t,           /* output_name_buffer */
160	       gss_OID *               /* output_name_type */
161	      );
162
163typedef OM_uint32 _gss_import_name_t
164	      (OM_uint32 *,            /* minor_status */
165	       const gss_buffer_t,     /* input_name_buffer */
166	       const gss_OID,          /* input_name_type */
167	       gss_name_t *            /* output_name */
168	      );
169
170typedef OM_uint32 _gss_export_name_t
171	      (OM_uint32 *,            /* minor_status */
172	       const gss_name_t,       /* input_name */
173	       gss_buffer_t            /* exported_name */
174	      );
175
176typedef OM_uint32 _gss_release_name_t
177	      (OM_uint32 *,            /* minor_status */
178	       gss_name_t *            /* input_name */
179	      );
180
181typedef OM_uint32 _gss_inquire_cred_t
182	      (OM_uint32 *,            /* minor_status */
183	       const gss_cred_id_t,    /* cred_handle */
184	       gss_name_t *,           /* name */
185	       OM_uint32 *,            /* lifetime */
186	       gss_cred_usage_t *,     /* cred_usage */
187	       gss_OID_set *           /* mechanisms */
188	      );
189
190typedef OM_uint32 _gss_inquire_context_t
191	      (OM_uint32 *,            /* minor_status */
192	       const gss_ctx_id_t,     /* context_handle */
193	       gss_name_t *,           /* src_name */
194	       gss_name_t *,           /* targ_name */
195	       OM_uint32 *,            /* lifetime_rec */
196	       gss_OID *,              /* mech_type */
197	       OM_uint32 *,            /* ctx_flags */
198	       int *,                  /* locally_initiated */
199	       int *                   /* open */
200	      );
201
202typedef OM_uint32 _gss_wrap_size_limit_t
203	      (OM_uint32 *,            /* minor_status */
204	       const gss_ctx_id_t,     /* context_handle */
205	       int,                    /* conf_req_flag */
206	       gss_qop_t,              /* qop_req */
207	       OM_uint32,              /* req_output_size */
208	       OM_uint32 *             /* max_input_size */
209	      );
210
211typedef OM_uint32 _gss_add_cred_t (
212	       OM_uint32 *,            /* minor_status */
213	       const gss_cred_id_t,    /* input_cred_handle */
214	       const gss_name_t,       /* desired_name */
215	       const gss_OID,          /* desired_mech */
216	       gss_cred_usage_t,       /* cred_usage */
217	       OM_uint32,              /* initiator_time_req */
218	       OM_uint32,              /* acceptor_time_req */
219	       gss_cred_id_t *,        /* output_cred_handle */
220	       gss_OID_set *,          /* actual_mechs */
221	       OM_uint32 *,            /* initiator_time_rec */
222	       OM_uint32 *             /* acceptor_time_rec */
223	      );
224
225typedef OM_uint32 _gss_inquire_cred_by_mech_t (
226	       OM_uint32 *,            /* minor_status */
227	       const gss_cred_id_t,    /* cred_handle */
228	       const gss_OID,          /* mech_type */
229	       gss_name_t *,           /* name */
230	       OM_uint32 *,            /* initiator_lifetime */
231	       OM_uint32 *,            /* acceptor_lifetime */
232	       gss_cred_usage_t *      /* cred_usage */
233	      );
234
235typedef OM_uint32 _gss_export_sec_context_t (
236	       OM_uint32 *,            /* minor_status */
237	       gss_ctx_id_t *,         /* context_handle */
238	       gss_buffer_t            /* interprocess_token */
239	      );
240
241typedef OM_uint32 _gss_import_sec_context_t (
242	       OM_uint32 *,            /* minor_status */
243	       const gss_buffer_t,     /* interprocess_token */
244	       gss_ctx_id_t *          /* context_handle */
245	      );
246
247typedef OM_uint32 _gss_inquire_names_for_mech_t (
248	       OM_uint32 *,            /* minor_status */
249	       const gss_OID,          /* mechanism */
250	       gss_OID_set *           /* name_types */
251	      );
252
253typedef OM_uint32 _gss_inquire_mechs_for_name_t (
254	       OM_uint32 *,            /* minor_status */
255	       const gss_name_t,       /* input_name */
256	       gss_OID_set *           /* mech_types */
257	      );
258
259typedef OM_uint32 _gss_canonicalize_name_t (
260	       OM_uint32 *,            /* minor_status */
261	       const gss_name_t,       /* input_name */
262	       const gss_OID,          /* mech_type */
263	       gss_name_t *            /* output_name */
264	      );
265
266typedef OM_uint32 _gss_duplicate_name_t (
267	       OM_uint32 *,            /* minor_status */
268	       const gss_name_t,       /* src_name */
269	       gss_name_t *            /* dest_name */
270	      );
271
272typedef OM_uint32 _gss_inquire_sec_context_by_oid
273	      (OM_uint32 *,		/* minor_status */
274	       const gss_ctx_id_t,	/* context_handle */
275	       const gss_OID,		/* desired_object */
276	       gss_buffer_set_t *	/* result */
277	      );
278
279typedef OM_uint32 _gss_inquire_cred_by_oid
280	      (OM_uint32 *,	       /* bminor_status */
281	       const gss_cred_id_t,    /* cred_handle, */
282	       const gss_OID,	       /* desired_object */
283	       gss_buffer_set_t *      /* data_set */
284	      );
285
286typedef OM_uint32 _gss_set_sec_context_option
287	      (OM_uint32 *,		/* minor status */
288	       gss_ctx_id_t *,		/* context */
289	       const gss_OID,		/* option to set */
290	       const gss_buffer_t	/* option value */
291	      );
292
293typedef OM_uint32 _gss_set_cred_option
294	      (OM_uint32 *,		/* minor status */
295	       gss_cred_id_t *,		/* cred */
296	       const gss_OID,		/* option to set */
297	       const gss_buffer_t	/* option value */
298	      );
299
300typedef OM_uint32 _gss_pseudo_random
301	      (OM_uint32 *,	       /* minor status */
302	       gss_ctx_id_t,	       /* context */
303	       int,		       /* PRF key */
304	       const gss_buffer_t,     /* PRF input */
305	       ssize_t,		       /* desired output length */
306	       gss_buffer_t	       /* PRF output */
307	      );
308
309typedef OM_uint32 _gss_pname_to_uid
310	      (OM_uint32 *,		/* minor status */
311	       gss_name_t pname,	/* principal name */
312	       gss_OID mech,		/* mechanism to query */
313	       uid_t *uidp		/* pointer to UID for result */
314	      );
315
316struct _gss_mech_switch {
317	SLIST_ENTRY(_gss_mech_switch)	gm_link;
318	const char			*gm_name_prefix;
319	gss_OID_desc			gm_mech_oid;
320	void				*gm_so;
321	_gss_acquire_cred_t		*gm_acquire_cred;
322	_gss_release_cred_t		*gm_release_cred;
323	_gss_init_sec_context_t		*gm_init_sec_context;
324	_gss_accept_sec_context_t	*gm_accept_sec_context;
325	_gss_process_context_token_t	*gm_process_context_token;
326	_gss_delete_sec_context_t	*gm_delete_sec_context;
327	_gss_context_time_t		*gm_context_time;
328	_gss_get_mic_t			*gm_get_mic;
329	_gss_verify_mic_t		*gm_verify_mic;
330	_gss_wrap_t			*gm_wrap;
331	_gss_unwrap_t			*gm_unwrap;
332	_gss_display_status_t		*gm_display_status;
333	_gss_indicate_mechs_t		*gm_indicate_mechs;
334	_gss_compare_name_t		*gm_compare_name;
335	_gss_display_name_t		*gm_display_name;
336	_gss_import_name_t		*gm_import_name;
337	_gss_export_name_t		*gm_export_name;
338	_gss_release_name_t		*gm_release_name;
339	_gss_inquire_cred_t		*gm_inquire_cred;
340	_gss_inquire_context_t		*gm_inquire_context;
341	_gss_wrap_size_limit_t		*gm_wrap_size_limit;
342	_gss_add_cred_t			*gm_add_cred;
343	_gss_inquire_cred_by_mech_t	*gm_inquire_cred_by_mech;
344	_gss_export_sec_context_t	*gm_export_sec_context;
345	_gss_import_sec_context_t	*gm_import_sec_context;
346	_gss_inquire_names_for_mech_t	*gm_inquire_names_for_mech;
347	_gss_inquire_mechs_for_name_t	*gm_inquire_mechs_for_name;
348	_gss_canonicalize_name_t	*gm_canonicalize_name;
349	_gss_duplicate_name_t		*gm_duplicate_name;
350	_gss_inquire_sec_context_by_oid	*gm_inquire_sec_context_by_oid;
351	_gss_inquire_cred_by_oid	*gm_inquire_cred_by_oid;
352	_gss_set_sec_context_option	*gm_set_sec_context_option;
353	_gss_set_cred_option		*gm_set_cred_option;
354	_gss_pseudo_random		*gm_pseudo_random;
355	_gss_pname_to_uid		*gm_pname_to_uid;
356};
357SLIST_HEAD(_gss_mech_switch_list, _gss_mech_switch);
358extern struct _gss_mech_switch_list _gss_mechs;
359extern gss_OID_set _gss_mech_oids;
360
361extern void _gss_load_mech(void);
362extern struct _gss_mech_switch *_gss_find_mech_switch(gss_OID);
363extern void _gss_mg_error(struct _gss_mech_switch *m, OM_uint32 maj,
364    OM_uint32 min);
365extern void _gss_mg_collect_error(gss_OID mech, OM_uint32 maj, OM_uint32 min);
366