1#!/bin/sh
2#
3# Copyright (c) 2006 - 2007 Kungliga Tekniska Högskolan
4# (Royal Institute of Technology, Stockholm, Sweden). 
5# All rights reserved. 
6#
7# Redistribution and use in source and binary forms, with or without 
8# modification, are permitted provided that the following conditions 
9# are met: 
10#
11# 1. Redistributions of source code must retain the above copyright 
12#    notice, this list of conditions and the following disclaimer. 
13#
14# 2. Redistributions in binary form must reproduce the above copyright 
15#    notice, this list of conditions and the following disclaimer in the 
16#    documentation and/or other materials provided with the distribution. 
17#
18# 3. Neither the name of the Institute nor the names of its contributors 
19#    may be used to endorse or promote products derived from this software 
20#    without specific prior written permission. 
21#
22# THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 
23# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 
24# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 
25# ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 
26# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 
27# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 
28# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 
29# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 
30# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 
31# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 
32# SUCH DAMAGE. 
33#
34# $Id$
35#
36
37srcdir="@srcdir@"
38objdir="@objdir@"
39EGREP="@EGREP@"
40
41testfailed="echo test failed; cat messages.log; exit 1"
42
43# If there is no useful db support compile in, disable test
44../db/have-db || exit 77
45
46R=TEST.H5L.SE
47
48port=@port@
49
50kadmin="${TESTS_ENVIRONMENT} ../../kadmin/kadmin -l -r ${R}"
51kdc="${TESTS_ENVIRONMENT} ../../kdc/kdc --addresses=localhost -P $port"
52
53server=host/datan.test.h5l.se
54cache="FILE:${objdir}/cache.krb5"
55keytabfile=${objdir}/server.keytab
56keytab="FILE:${keytabfile}"
57
58kinit="${TESTS_ENVIRONMENT} ../../kuser/kinit -c $cache ${afs_no_afslog}"
59klist="${TESTS_ENVIRONMENT} ../../kuser/klist -c $cache"
60kgetcred="${TESTS_ENVIRONMENT} ../../kuser/kgetcred -c $cache"
61kdestroy="${TESTS_ENVIRONMENT} ../../kuser/kdestroy -c $cache ${afs_no_unlog}"
62test_apreq="${TESTS_ENVIRONMENT} ../../lib/krb5/test_ap-req"
63
64KRB5_CONFIG="${objdir}/krb5.conf"
65export KRB5_CONFIG
66
67rm -f ${keytabfile}
68rm -f current-db*
69rm -f out-*
70rm -f mkey.file*
71
72> messages.log
73
74echo Creating database
75${kadmin} \
76    init \
77    --realm-max-ticket-life=1day \
78    --realm-max-renewable-life=1month \
79    ${R} || exit 1
80
81${kadmin} add -p foo --use-defaults foo@${R} || exit 1
82${kadmin} add -p bar --use-defaults ${server}@${R} || exit 1
83${kadmin} ext -k ${keytab} ${server}@${R} || exit 1
84
85echo "Doing database check"
86${kadmin} check ${R} || exit 1
87${kadmin} check ${R2} || exit 1
88
89echo foo > ${objdir}/foopassword
90
91echo "Empty log"
92> messages.log
93
94echo Starting kdc
95${kdc} &
96kdcpid=$!
97
98sh ${srcdir}/../kdc/wait-kdc.sh
99if [ "$?" != 0 ] ; then
100    kill ${kdcpid}
101    exit 1
102fi
103
104trap "kill ${kdcpid}; echo signal killing kdc; exit 1;" EXIT
105
106ec=0
107
108echo "Check that WINDC module was loaded "
109grep "windc init" messages.log >/dev/null || \
110	{ ec=1 ; eval "${testfailed}"; }
111
112echo "Getting client initial tickets"; > messages.log
113${kinit} --password-file=${objdir}/foopassword foo@${R} || \
114	{ ec=1 ; eval "${testfailed}"; }
115echo "Getting tickets" ; > messages.log
116${kgetcred} ${server}@${R} || { ec=1 ; eval "${testfailed}"; }
117echo "Verify PAC on server"; > messages.log
118${test_apreq} --verify-pac ${server}@${R} ${keytab} ${cache} || \
119	{ ec=1 ; eval "${testfailed}"; }
120${kdestroy}
121
122echo "Getting client initial tickets (pag)"; > messages.log
123${kinit} --request-pac --password-file=${objdir}/foopassword foo@${R} || \
124	{ ec=1 ; eval "${testfailed}"; }
125echo "Getting tickets" ; > messages.log
126${kgetcred} ${server}@${R} || { ec=1 ; eval "${testfailed}"; }
127echo "Verify PAC on server (pag)"; > messages.log
128${test_apreq} --verify-pac ${server}@${R} ${keytab} ${cache} || \
129	{ ec=1 ; eval "${testfailed}"; }
130${kdestroy}
131
132echo "Getting client initial tickets (no pag)"; > messages.log
133${kinit} --no-request-pac --password-file=${objdir}/foopassword foo@${R} || \
134	{ ec=1 ; eval "${testfailed}"; }
135echo "Getting tickets" ; > messages.log
136${kgetcred} ${server}@${R} || { ec=1 ; eval "${testfailed}"; }
137echo "Verify PAC on server (no pag)"; > messages.log
138${test_apreq} --verify-pac ${server}@${R} ${keytab} ${cache} 2> /dev/null && \
139	{ ec=1 ; eval "${testfailed}"; }
140${kdestroy}
141
142
143echo "killing kdc (${kdcpid})"
144kill $kdcpid || exit 1
145
146trap "" EXIT
147
148exit $ec
149