1/*
2 * Copyright (c) 2003-2004 Kungliga Tekniska H�gskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
4 * All rights reserved.
5 *
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
9 *
10 * 1. Redistributions of source code must retain the above copyright
11 *    notice, this list of conditions and the following disclaimer.
12 *
13 * 2. Redistributions in binary form must reproduce the above copyright
14 *    notice, this list of conditions and the following disclaimer in the
15 *    documentation and/or other materials provided with the distribution.
16 *
17 * 3. Neither the name of KTH nor the names of its contributors may be
18 *    used to endorse or promote products derived from this software without
19 *    specific prior written permission.
20 *
21 * THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS ``AS IS'' AND ANY
22 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
24 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS CONTRIBUTORS BE
25 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28 * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29 * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
30 * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
31 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32 */
33
34#ifdef HAVE_CONFIG_H
35#include <config.h>
36#endif
37
38#include <stdio.h>
39#include <stdlib.h>
40#include <string.h>
41#include <stdarg.h>
42#include <gssapi.h>
43#include <err.h>
44#include <roken.h>
45#include <getarg.h>
46
47RCSID("$Id: test_cred.c 17750 2006-06-30 11:55:28Z lha $");
48
49static void
50gss_print_errors (int min_stat)
51{
52    OM_uint32 new_stat;
53    OM_uint32 msg_ctx = 0;
54    gss_buffer_desc status_string;
55    OM_uint32 ret;
56
57    do {
58	ret = gss_display_status (&new_stat,
59				  min_stat,
60				  GSS_C_MECH_CODE,
61				  GSS_C_NO_OID,
62				  &msg_ctx,
63				  &status_string);
64	if (!GSS_ERROR(ret)) {
65	    fprintf (stderr, "%s\n", (char *)status_string.value);
66	    gss_release_buffer (&new_stat, &status_string);
67	}
68    } while (!GSS_ERROR(ret) && msg_ctx != 0);
69}
70
71static void
72gss_err(int exitval, int status, const char *fmt, ...)
73{
74    va_list args;
75
76    va_start(args, fmt);
77    vwarnx (fmt, args);
78    gss_print_errors (status);
79    va_end(args);
80    exit (exitval);
81}
82
83static void
84acquire_release_loop(gss_name_t name, int counter, gss_cred_usage_t usage)
85{
86    OM_uint32 maj_stat, min_stat;
87    gss_cred_id_t cred;
88    int i;
89
90    for (i = 0; i < counter; i++) {
91	maj_stat = gss_acquire_cred(&min_stat, name,
92				    GSS_C_INDEFINITE,
93				    GSS_C_NO_OID_SET,
94				    usage,
95				    &cred,
96				    NULL,
97				    NULL);
98	if (maj_stat != GSS_S_COMPLETE)
99	    gss_err(1, min_stat, "aquire %d %d != GSS_S_COMPLETE",
100		    i, (int)maj_stat);
101
102	maj_stat = gss_release_cred(&min_stat, &cred);
103	if (maj_stat != GSS_S_COMPLETE)
104	    gss_err(1, min_stat, "release %d %d != GSS_S_COMPLETE",
105		    i, (int)maj_stat);
106    }
107}
108
109
110static void
111acquire_add_release_add(gss_name_t name, gss_cred_usage_t usage)
112{
113    OM_uint32 maj_stat, min_stat;
114    gss_cred_id_t cred, cred2, cred3;
115
116    maj_stat = gss_acquire_cred(&min_stat, name,
117				GSS_C_INDEFINITE,
118				GSS_C_NO_OID_SET,
119				usage,
120				&cred,
121				NULL,
122				NULL);
123    if (maj_stat != GSS_S_COMPLETE)
124	gss_err(1, min_stat, "aquire %d != GSS_S_COMPLETE", (int)maj_stat);
125
126    maj_stat = gss_add_cred(&min_stat,
127			    cred,
128			    GSS_C_NO_NAME,
129			    GSS_KRB5_MECHANISM,
130			    usage,
131			    GSS_C_INDEFINITE,
132			    GSS_C_INDEFINITE,
133			    &cred2,
134			    NULL,
135			    NULL,
136			    NULL);
137
138    if (maj_stat != GSS_S_COMPLETE)
139	gss_err(1, min_stat, "add_cred %d != GSS_S_COMPLETE", (int)maj_stat);
140
141    maj_stat = gss_release_cred(&min_stat, &cred);
142    if (maj_stat != GSS_S_COMPLETE)
143	gss_err(1, min_stat, "release %d != GSS_S_COMPLETE", (int)maj_stat);
144
145    maj_stat = gss_add_cred(&min_stat,
146			    cred2,
147			    GSS_C_NO_NAME,
148			    GSS_KRB5_MECHANISM,
149			    GSS_C_BOTH,
150			    GSS_C_INDEFINITE,
151			    GSS_C_INDEFINITE,
152			    &cred3,
153			    NULL,
154			    NULL,
155			    NULL);
156
157    maj_stat = gss_release_cred(&min_stat, &cred2);
158    if (maj_stat != GSS_S_COMPLETE)
159	gss_err(1, min_stat, "release 2 %d != GSS_S_COMPLETE", (int)maj_stat);
160
161    maj_stat = gss_release_cred(&min_stat, &cred3);
162    if (maj_stat != GSS_S_COMPLETE)
163	gss_err(1, min_stat, "release 2 %d != GSS_S_COMPLETE", (int)maj_stat);
164}
165
166static int version_flag = 0;
167static int help_flag	= 0;
168
169static struct getargs args[] = {
170    {"version",	0,	arg_flag,	&version_flag, "print version", NULL },
171    {"help",	0,	arg_flag,	&help_flag,  NULL, NULL }
172};
173
174static void
175usage (int ret)
176{
177    arg_printusage (args, sizeof(args)/sizeof(*args),
178		    NULL, "service@host");
179    exit (ret);
180}
181
182
183int
184main(int argc, char **argv)
185{
186    struct gss_buffer_desc_struct name_buffer;
187    OM_uint32 maj_stat, min_stat;
188    gss_name_t name;
189    int optidx = 0;
190
191    setprogname(argv[0]);
192    if(getarg(args, sizeof(args) / sizeof(args[0]), argc, argv, &optidx))
193	usage(1);
194
195    if (help_flag)
196	usage (0);
197
198    if(version_flag){
199	print_version(NULL);
200	exit(0);
201    }
202
203    argc -= optidx;
204    argv += optidx;
205
206    if (argc < 1)
207	errx(1, "argc < 1");
208
209    name_buffer.value = argv[0];
210    name_buffer.length = strlen(argv[0]);
211
212    maj_stat = gss_import_name(&min_stat, &name_buffer,
213			       GSS_C_NT_HOSTBASED_SERVICE,
214			       &name);
215    if (maj_stat != GSS_S_COMPLETE)
216	errx(1, "import name error");
217
218    acquire_release_loop(name, 100, GSS_C_ACCEPT);
219    acquire_release_loop(name, 100, GSS_C_INITIATE);
220    acquire_release_loop(name, 100, GSS_C_BOTH);
221
222    acquire_add_release_add(name, GSS_C_ACCEPT);
223    acquire_add_release_add(name, GSS_C_INITIATE);
224    acquire_add_release_add(name, GSS_C_BOTH);
225
226    gss_release_name(&min_stat, &name);
227
228    return 0;
229}
230