taclib.h revision 103976
1/*- 2 * Copyright (c) 1998, 2001, Juniper Networks, Inc. 3 * All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 17 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 24 * SUCH DAMAGE. 25 * 26 * $FreeBSD: head/lib/libtacplus/taclib.h 103976 2002-09-25 23:18:51Z pst $ 27 */ 28 29#ifndef _TACLIB_H_ 30#define _TACLIB_H_ 31 32#include <sys/types.h> 33 34struct tac_handle; 35 36/* Flags for tac_add_server(). */ 37#define TAC_SRVR_SINGLE_CONNECT 0x04 /* Keep connection open for multiple 38 sessions. */ 39 40/* Disassembly of tac_send_authen() return value. */ 41#define TAC_AUTHEN_STATUS(s) ((s) & 0xff) 42#define TAC_AUTHEN_NOECHO(s) ((s) & (1<<8)) 43 44/* Disassembly of tac_send_author() return value. */ 45#define TAC_AUTHOR_STATUS(s) ((s) & 0xff) 46#define TAC_AUTHEN_AV_COUNT(s) (((s)>>8) & 0xff) 47 48/* Privilege levels */ 49#define TAC_PRIV_LVL_MIN 0x00 50#define TAC_PRIV_LVL_USER 0x01 51#define TAC_PRIV_LVL_ROOT 0x0f 52#define TAC_PRIV_LVL_MAX 0x0f 53 54/* Authentication actions */ 55#define TAC_AUTHEN_LOGIN 0x01 56#define TAC_AUTHEN_CHPASS 0x02 57#define TAC_AUTHEN_SENDPASS 0x03 58#define TAC_AUTHEN_SENDAUTH 0x04 59 60/* Authentication types */ 61#define TAC_AUTHEN_TYPE_ASCII 0x01 62#define TAC_AUTHEN_TYPE_PAP 0x02 63#define TAC_AUTHEN_TYPE_CHAP 0x03 64#define TAC_AUTHEN_TYPE_ARAP 0x04 65#define TAC_AUTHEN_TYPE_MSCHAP 0x05 66 67/* Authentication services */ 68#define TAC_AUTHEN_SVC_NONE 0x00 69#define TAC_AUTHEN_SVC_LOGIN 0x01 70#define TAC_AUTHEN_SVC_ENABLE 0x02 71#define TAC_AUTHEN_SVC_PPP 0x03 72#define TAC_AUTHEN_SVC_ARAP 0x04 73#define TAC_AUTHEN_SVC_PT 0x05 74#define TAC_AUTHEN_SVC_RCMD 0x06 75#define TAC_AUTHEN_SVC_X25 0x07 76#define TAC_AUTHEN_SVC_NASI 0x08 77#define TAC_AUTHEN_SVC_FWPROXY 0x09 78 79/* Authentication reply status codes */ 80#define TAC_AUTHEN_STATUS_PASS 0x01 81#define TAC_AUTHEN_STATUS_FAIL 0x02 82#define TAC_AUTHEN_STATUS_GETDATA 0x03 83#define TAC_AUTHEN_STATUS_GETUSER 0x04 84#define TAC_AUTHEN_STATUS_GETPASS 0x05 85#define TAC_AUTHEN_STATUS_RESTART 0x06 86#define TAC_AUTHEN_STATUS_ERROR 0x07 87#define TAC_AUTHEN_STATUS_FOLLOW 0x21 88 89/* Authorization authenticatication methods */ 90#define TAC_AUTHEN_METH_NOT_SET 0x00 91#define TAC_AUTHEN_METH_NONE 0x01 92#define TAC_AUTHEN_METH_KRB5 0x02 93#define TAC_AUTHEN_METH_LINE 0x03 94#define TAC_AUTHEN_METH_ENABLE 0x04 95#define TAC_AUTHEN_METH_LOCAL 0x05 96#define TAC_AUTHEN_METH_TACACSPLUS 0x06 97#define TAC_AUTHEN_METH_RCMD 0x20 98/* If adding more, see comments in protocol_version() in taclib.c */ 99 100/* Authorization status */ 101#define TAC_AUTHOR_STATUS_PASS_ADD 0x01 102#define TAC_AUTHOR_STATUS_PASS_REPL 0x02 103#define TAC_AUTHOR_STATUS_FAIL 0x10 104#define TAC_AUTHOR_STATUS_ERROR 0x11 105 106__BEGIN_DECLS 107int tac_add_server(struct tac_handle *, 108 const char *, int, const char *, int, int); 109void tac_close(struct tac_handle *); 110int tac_config(struct tac_handle *, const char *); 111int tac_create_authen(struct tac_handle *, int, int, int); 112void *tac_get_data(struct tac_handle *, size_t *); 113char *tac_get_msg(struct tac_handle *); 114struct tac_handle *tac_open(void); 115int tac_send_authen(struct tac_handle *); 116int tac_set_data(struct tac_handle *, 117 const void *, size_t); 118int tac_set_msg(struct tac_handle *, const char *); 119int tac_set_port(struct tac_handle *, const char *); 120int tac_set_priv(struct tac_handle *, int); 121int tac_set_rem_addr(struct tac_handle *, const char *); 122int tac_set_user(struct tac_handle *, const char *); 123const char *tac_strerror(struct tac_handle *); 124int tac_send_author(struct tac_handle *); 125int tac_create_author(struct tac_handle *, int, int, int); 126int tac_set_av(struct tac_handle *, u_int, const char *); 127char *tac_get_av(struct tac_handle *, u_int); 128char *tac_get_av_value(struct tac_handle *, const char *); 129void tac_clear_avs(struct tac_handle *); 130__END_DECLS 131 132#endif /* _TACLIB_H_ */ 133