1/*-
2 * Copyright (c) 2008 Isilon Inc http://www.isilon.com/
3 * Authors: Doug Rabson <dfr@rabson.org>
4 * Developed with Red Inc: Alfred Perlstein <alfred@freebsd.org>
5 *
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
9 * 1. Redistributions of source code must retain the above copyright
10 *    notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 *    notice, this list of conditions and the following disclaimer in the
13 *    documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25 * SUCH DAMAGE.
26 */
27/* $FreeBSD$ */
28
29#include <errno.h>
30#include <pwd.h>
31
32#include "krb5/gsskrb5_locl.h"
33
34OM_uint32
35_gsskrb5_pname_to_uid(OM_uint32 *minor_status, const gss_name_t pname,
36    const gss_OID mech, uid_t *uidp)
37{
38	krb5_context context;
39	krb5_const_principal name = (krb5_const_principal) pname;
40	krb5_error_code kret;
41	char lname[MAXLOGNAME + 1], buf[1024], *bufp;
42	struct passwd pwd, *pw;
43	size_t buflen;
44	int error;
45	OM_uint32 ret;
46	static size_t buflen_hint = 1024;
47
48	GSSAPI_KRB5_INIT (&context);
49
50	kret = krb5_aname_to_localname(context, name, sizeof(lname), lname);
51	if (kret) {
52		*minor_status = kret;
53		return (GSS_S_FAILURE);
54	}
55
56	*minor_status = 0;
57	buflen = buflen_hint;
58	for (;;) {
59		pw = NULL;
60		bufp = buf;
61		if (buflen > sizeof(buf))
62			bufp = malloc(buflen);
63		if (bufp == NULL)
64			break;
65		error = getpwnam_r(lname, &pwd, bufp, buflen, &pw);
66		if (error != ERANGE)
67			break;
68		if (buflen > sizeof(buf))
69			free(bufp);
70		buflen += 1024;
71		if (buflen > buflen_hint)
72			buflen_hint = buflen;
73	}
74	if (pw) {
75		*uidp = pw->pw_uid;
76		ret = GSS_S_COMPLETE;
77	} else {
78		ret = GSS_S_FAILURE;
79	}
80	if (bufp != NULL && buflen > sizeof(buf))
81		free(bufp);
82	return (ret);
83}
84