1/*-
2 * Copyright (c) 2005 Doug Rabson
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 *    notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 *    notice, this list of conditions and the following disclaimer in the
12 *    documentation and/or other materials provided with the distribution.
13 *
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24 * SUCH DAMAGE.
25 *
26 *	$FreeBSD: src/lib/libgssapi/gss_export_sec_context.c,v 1.1 2005/12/29 14:40:20 dfr Exp $
27 */
28
29#include "mech_locl.h"
30
31GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
32gss_export_sec_context(OM_uint32 *minor_status,
33    gss_ctx_id_t *context_handle,
34    gss_buffer_t interprocess_token)
35{
36	OM_uint32 major_status;
37	struct _gss_context *ctx;
38	gssapi_mech_interface m;
39	gss_buffer_desc buf;
40
41	*minor_status = 0;
42
43	if (interprocess_token)
44	    _mg_buffer_zero(interprocess_token);
45	else
46	    return GSS_S_CALL_INACCESSIBLE_READ;
47
48	if (context_handle == NULL)
49	    return GSS_S_NO_CONTEXT;
50
51	ctx = (struct _gss_context *) *context_handle;
52	if (ctx == NULL || ctx->gc_ctx == NULL) {
53	    *minor_status = 0;
54	    return GSS_S_NO_CONTEXT;
55	}
56
57	m = ctx->gc_mech;
58
59	major_status = m->gm_export_sec_context(minor_status,
60	    &ctx->gc_ctx, &buf);
61
62	if (major_status == GSS_S_COMPLETE) {
63		unsigned char *p;
64
65		free(ctx);
66		*context_handle = GSS_C_NO_CONTEXT;
67		interprocess_token->length = buf.length
68			+ 2 + m->gm_mech_oid.length;
69		interprocess_token->value = malloc(interprocess_token->length);
70		if (!interprocess_token->value) {
71			/*
72			 * We are in trouble here - the context is
73			 * already gone. This is allowed as long as we
74			 * set the caller's context_handle to
75			 * GSS_C_NO_CONTEXT, which we did above.
76			 * Return GSS_S_FAILURE.
77			 */
78			_mg_buffer_zero(interprocess_token);
79			*minor_status = ENOMEM;
80			return (GSS_S_FAILURE);
81		}
82		p = interprocess_token->value;
83		p[0] = m->gm_mech_oid.length >> 8;
84		p[1] = m->gm_mech_oid.length;
85		memcpy(p + 2, m->gm_mech_oid.elements, m->gm_mech_oid.length);
86		memcpy(p + 2 + m->gm_mech_oid.length, buf.value, buf.length);
87		gss_release_buffer(minor_status, &buf);
88	} else {
89		_gss_mg_error(m, *minor_status);
90	}
91
92	return (major_status);
93}
94