2 * Copyright 1987, 1988 by the Massachusetts Institute of Technology.
4 * For copying and distribution information, please see the file
7 * Include file for the Kerberos library.
10 /* Only one time, please */
16 /* Need some defs from des.h */
19 /* Text describing error codes */
20 #define MAX_KRB_ERRORS 256
21 extern char *krb_err_txt[MAX_KRB_ERRORS];
23 /* General definitions */
28 typedef unsigned short uid_t;
29 typedef unsigned short gid_t;
30 #endif /* NO_UIDGID_T */
33 * Kerberos specific definitions
35 * KRBLOG is the log file for the kerberos master server. KRB_CONF is
36 * the configuration file where different host machines running master
37 * and slave servers can be found. KRB_MASTER is the name of the
38 * machine with the master database. The admin_server runs on this
39 * machine, and all changes to the db (as opposed to read-only
40 * requests, which can go to slaves) must go to it. KRB_HOST is the
41 * default machine * when looking for a kerberos slave server. Other
42 * possibilities are * in the KRB_CONF file. KRB_REALM is the name of
47 /* this is server - only, does not belong here; */
48 #define KRBLOG "/kerberos/kerberos.log"
49 /* are these used anyplace? */
50 #define VX_KRB_HSTFILE "/etc/krbhst"
51 #define PC_KRB_HSTFILE "\\kerberos\\krbhst"
56 #define KRB_CONF "krb.con"
57 #define KRB_RLM_TRANS "krbrealm.con"
61 #define KRB_CONF "/etc/krb.conf"
62 #define KRB_RLM_TRANS "/etc/krb.realms"
67 #define KRB_MASTER "kerberos.mit.edu"
68 #define KRB_REALM "ATHENA.MIT.EDU"
69 #define KRB_HOST KRB_MASTER
71 /* The maximum sizes for aname, realm, sname, and instance +1 */
77 /* include space for '.' and '@' */
78 #define MAX_K_NAME_SZ (ANAME_SZ + INST_SZ + REALM_SZ + 2)
82 #define DATE_SZ 26 /* RTI date output */
86 #ifndef DEFAULT_TKT_LIFE /* allow compile-time override */
87 #define DEFAULT_TKT_LIFE 120 /* default lifetime for krb_mk_req
91 /* Definition of text structure used to pass text around */
92 #define MAX_KTXT_LEN 1250
95 int length; /* Length of the text */
96 unsigned char dat[MAX_KTXT_LEN]; /* The data itself */
97 unsigned long mbz; /* zero to catch runaway strings */
100 typedef struct ktext far *KTEXT;
101 typedef struct ktext far *KTEXT_FP;
102 typedef struct ktext KTEXT_ST;
105 /* Definitions for send_to_kdc */
106 #define CLIENT_KRB_TIMEOUT 10 /* time between retries */ /* changed from 4, 8-14-94 pbh */
107 #define CLIENT_KRB_RETRY 5 /* retry this many times */
108 #define CLIENT_KRB_BUFLEN 512 /* max unfragmented packet */
110 /* Definitions for ticket file utilities */
114 /* Definitions for cl_get_tgt */
116 #define CL_GTGT_INIT_FILE "\\kerberos\\k_in_tkts" /* WTF??!? */
118 #define CL_GTGT_INIT_FILE "/etc/k_in_tkts"
121 /* Parameters for rd_ap_req */
122 /* Maximum alloable clock skew in seconds */
123 #define CLOCK_SKEW 5*60
124 /* Filename for readservkey */
125 #define KEYFILE "/etc/srvtab"
127 /* Structure definition for rd_ap_req */
130 unsigned char k_flags; /* Flags from ticket */
131 char pname[ANAME_SZ]; /* Principal's name */
132 char pinst[INST_SZ]; /* His Instance */
133 char prealm[REALM_SZ]; /* His Realm */
134 unsigned long checksum; /* Data checksum (opt) */
135 C_Block session; /* Session Key */
136 int life; /* Life of ticket */
137 unsigned long time_sec; /* Time ticket issued */
138 unsigned long address; /* Address in ticket */
139 KTEXT_ST reply; /* Auth reply (opt) */
142 typedef struct auth_dat AUTH_DAT;
144 /* Structure definition for credentials returned by get_cred */
147 char service[ANAME_SZ]; /* Service name */
148 char instance[INST_SZ]; /* Instance */
149 char realm[REALM_SZ]; /* Auth domain */
150 C_Block session; /* Session key */
151 int lifetime; /* Lifetime */
152 int kvno; /* Key version number */
153 KTEXT_ST ticket_st; /* The ticket itself */
154 long issue_date; /* The issue time */
155 char pname[ANAME_SZ]; /* Principal's name */
156 char pinst[INST_SZ]; /* Principal's instance */
157 char address[ADDR_SZ]; /* IP Address in ticket */
160 typedef struct credentials CREDENTIALS;
162 /* Structure definition for rd_private_msg and rd_safe_msg */
165 unsigned char far *app_data; /* pointer to appl data */
166 unsigned long app_length; /* length of appl data */
167 unsigned long hash; /* hash to lookup replay */
168 int swap; /* swap bytes? */
169 long time_sec; /* msg timestamp seconds */
170 unsigned char time_5ms; /* msg timestamp 5ms units */
173 typedef struct msg_dat MSG_DAT;
176 /* Location of ticket file for save_cred and get_cred */
177 #define TKT_FILE tkt_string()
179 #define TKT_ENV "KERBEROS_TICKETS"
184 int sema; /* semaphore 0 - OK, -1 - lock write, +ve lock read */
187 tkt_header far *tkt_ptr(void);
192 #define TKT_ROOT "/tmp/tkt"
194 /* Error codes returned from the KDC */
195 #define KDC_OK 0 /* Request OK */
196 #define KDC_NAME_EXP 1 /* Principal expired */
197 #define KDC_SERVICE_EXP 2 /* Service expired */
198 #define KDC_AUTH_EXP 3 /* Auth expired */
199 #define KDC_PKT_VER 4 /* Protocol version unknown */
200 #define KDC_P_MKEY_VER 5 /* Wrong master key version */
201 #define KDC_S_MKEY_VER 6 /* Wrong master key version */
202 #define KDC_BYTE_ORDER 7 /* Byte order unknown */
203 #define KDC_PR_UNKNOWN 8 /* Principal unknown */
204 #define KDC_PR_N_UNIQUE 9 /* Principal not unique */
205 #define KDC_NULL_KEY 10 /* Principal has null key */
206 #define KDC_GEN_ERR 20 /* Generic error from KDC */
208 /* Values returned by get_credentials */
209 #define GC_OK 0 /* Retrieve OK */
210 #define RET_OK 0 /* Retrieve OK */
211 #define GC_TKFIL 21 /* Can't read ticket file */
212 #define RET_TKFIL 21 /* Can't read ticket file */
213 #define GC_NOTKT 22 /* Can't find ticket or TGT */
214 #define RET_NOTKT 22 /* Can't find ticket or TGT */
216 /* Values returned by mk_ap_req */
217 #define MK_AP_OK 0 /* Success */
218 #define MK_AP_TGTEXP 26 /* TGT Expired */
220 /* Values returned by rd_ap_req */
221 #define RD_AP_OK 0 /* Request authentic */
222 #define RD_AP_UNDEC 31 /* Can't decode authenticator */
223 #define RD_AP_EXP 32 /* Ticket expired */
224 #define RD_AP_NYV 33 /* Ticket not yet valid */
225 #define RD_AP_REPEAT 34 /* Repeated request */
226 #define RD_AP_NOT_US 35 /* The ticket isn't for us */
227 #define RD_AP_INCON 36 /* Request is inconsistent */
228 #define RD_AP_TIME 37 /* delta_t too big */
229 #define RD_AP_BADD 38 /* Incorrect net address */
230 #define RD_AP_VERSION 39 /* protocol version mismatch */
231 #define RD_AP_MSG_TYPE 40 /* invalid msg type */
232 #define RD_AP_MODIFIED 41 /* message stream modified */
233 #define RD_AP_ORDER 42 /* message out of order */
234 #define RD_AP_UNAUTHOR 43 /* unauthorized request */
236 /* Values returned by get_pw_tkt */
237 #define GT_PW_OK 0 /* Got password changing tkt */
238 #define GT_PW_NULL 51 /* Current PW is null */
239 #define GT_PW_BADPW 52 /* Incorrect current password */
240 #define GT_PW_PROT 53 /* Protocol Error */
241 #define GT_PW_KDCERR 54 /* Error returned by KDC */
242 #define GT_PW_NULLTKT 55 /* Null tkt returned by KDC */
244 /* Values returned by send_to_kdc */
245 #define SKDC_OK 0 /* Response received */
246 #define SKDC_RETRY 56 /* Retry count exceeded */
247 #define SKDC_CANT 57 /* Can't send request */
250 * Values returned by get_intkt
251 * (can also return SKDC_* and KDC errors)
254 #define INTK_OK 0 /* Ticket obtained */
255 #define INTK_PW_NULL 51 /* Current PW is null */
256 #define INTK_W_NOTALL 61 /* Not ALL tickets returned */
257 #define INTK_BADPW 62 /* Incorrect password */
258 #define INTK_PROT 63 /* Protocol Error */
259 #define INTK_ERR 70 /* Other error */
261 /* Values returned by get_adtkt */
262 #define AD_OK 0 /* Ticket Obtained */
263 #define AD_NOTGT 71 /* Don't have tgt */
265 /* Error codes returned by ticket file utilities */
266 #define NO_TKT_FIL 76 /* No ticket file found */
267 #define TKT_FIL_ACC 77 /* Couldn't access tkt file */
268 #define TKT_FIL_LCK 78 /* Couldn't lock ticket file */
269 #define TKT_FIL_FMT 79 /* Bad ticket file format */
270 #define TKT_FIL_INI 80 /* tf_init not called first */
272 /* Error code returned by kparse_name */
273 #define KNAME_FMT 81 /* Bad Kerberos name format */
275 /* Error code returned by krb_mk_safe */
276 #define SAFE_PRIV_ERROR -1 /* syscall error */
279 * macros for byte swapping; also scratch space
280 * u_quad 0-->7, 1-->6, 2-->5, 3-->4, 4-->3, 5-->2, 6-->1, 7-->0
281 * u_long 0-->3, 1-->2, 2-->1, 3-->0
282 * u_short 0-->1, 1-->0
285 #define swap_u_16(x) {\
286 unsigned long _krb_swap_tmp[4];\
287 _swab(((char *) x) +0, ((char *) _krb_swap_tmp) +14 ,2); \
288 _swab(((char *) x) +2, ((char *) _krb_swap_tmp) +12 ,2); \
289 _swab(((char *) x) +4, ((char *) _krb_swap_tmp) +10 ,2); \
290 _swab(((char *) x) +6, ((char *) _krb_swap_tmp) +8 ,2); \
291 _swab(((char *) x) +8, ((char *) _krb_swap_tmp) +6 ,2); \
292 _swab(((char *) x) +10,((char *) _krb_swap_tmp) +4 ,2); \
293 _swab(((char *) x) +12,((char *) _krb_swap_tmp) +2 ,2); \
294 _swab(((char *) x) +14,((char *) _krb_swap_tmp) +0 ,2); \
295 bcopy((char *)_krb_swap_tmp,(char *)x,16);\
298 #define swap_u_12(x) {\
299 unsigned long _krb_swap_tmp[4];\
300 _swab(( char *) x, ((char *) _krb_swap_tmp) +10 ,2); \
301 _swab(((char *) x) +2, ((char *) _krb_swap_tmp) +8 ,2); \
302 _swab(((char *) x) +4, ((char *) _krb_swap_tmp) +6 ,2); \
303 _swab(((char *) x) +6, ((char *) _krb_swap_tmp) +4 ,2); \
304 _swab(((char *) x) +8, ((char *) _krb_swap_tmp) +2 ,2); \
305 _swab(((char *) x) +10,((char *) _krb_swap_tmp) +0 ,2); \
306 bcopy((char *)_krb_swap_tmp,(char *)x,12);\
309 #define swap_C_Block(x) {\
310 unsigned long _krb_swap_tmp[4];\
311 _swab(( char *) x, ((char *) _krb_swap_tmp) +6 ,2); \
312 _swab(((char *) x) +2,((char *) _krb_swap_tmp) +4 ,2); \
313 _swab(((char *) x) +4,((char *) _krb_swap_tmp) +2 ,2); \
314 _swab(((char *) x) +6,((char *) _krb_swap_tmp) ,2); \
315 bcopy((char *)_krb_swap_tmp,(char *)x,8);\
317 #define swap_u_quad(x) {\
318 unsigned long _krb_swap_tmp[4];\
319 _swab(( char *) &x, ((char *) _krb_swap_tmp) +6 ,2); \
320 _swab(((char *) &x) +2,((char *) _krb_swap_tmp) +4 ,2); \
321 _swab(((char *) &x) +4,((char *) _krb_swap_tmp) +2 ,2); \
322 _swab(((char *) &x) +6,((char *) _krb_swap_tmp) ,2); \
323 bcopy((char *)_krb_swap_tmp,(char *)&x,8);\
326 #define swap_u_long(x) {\
327 unsigned long _krb_swap_tmp[4];\
328 _swab((char *) &x, ((char *) _krb_swap_tmp) +2 ,2); \
329 _swab(((char *) &x) +2,((char *) _krb_swap_tmp),2); \
330 x = _krb_swap_tmp[0]; \
333 #define swap_u_short(x) {\
334 unsigned short _krb_swap_sh_tmp; \
335 _swab((char *) &x, ( &_krb_swap_sh_tmp) ,2); \
336 x = (unsigned short) _krb_swap_sh_tmp; \
339 /* Kerberos ticket flag field bit definitions */
340 #define K_FLAG_ORDER 0 /* bit 0 --> lsb */
341 #define K_FLAG_1 /* reserved */
342 #define K_FLAG_2 /* reserved */
343 #define K_FLAG_3 /* reserved */
344 #define K_FLAG_4 /* reserved */
345 #define K_FLAG_5 /* reserved */
346 #define K_FLAG_6 /* reserved */
347 #define K_FLAG_7 /* reserved, bit 7 --> msb */
350 #define krb_mk_req mk_ap_req
351 #define krb_rd_req rd_ap_req
352 #define krb_kntoln an_to_ln
353 #define krb_set_key set_serv_key
354 #define krb_get_cred get_credentials
355 #define krb_mk_priv mk_private_msg
356 #define krb_rd_priv rd_private_msg
357 #define krb_mk_safe mk_safe_msg
358 #define krb_rd_safe rd_safe_msg
359 #define krb_mk_err mk_appl_err_msg
360 #define krb_rd_err rd_appl_err_msg
361 #define krb_ck_repl check_replay
362 #define krb_get_pw_in_tkt get_in_tkt
363 #define krb_get_svc_in_tkt get_svc_in_tkt
364 #define krb_get_pw_tkt get_pw_tkt
365 #define krb_realmofhost krb_getrealm
366 #define krb_get_phost get_phost
367 #define krb_get_krbhst get_krbhst
368 #define krb_get_lrealm get_krbrlm
369 #endif /* OLDNAMES */
371 #define decomp_ticket k_decomp_ticket
372 /* Defines for krb_sendauth and krb_recvauth */
374 #define KOPT_DONT_MK_REQ 0x00000001 /* don't call krb_mk_req */
375 #define KOPT_DO_MUTUAL 0x00000002 /* do mutual auth */
377 #define KOPT_DONT_CANON 0x00000004 /*
378 * don't canonicalize inst as
382 #define KRB_SENDAUTH_VLEN 8 /* length for version strings */
385 #define KOPT_DO_OLDSTYLE 0x00000008 /* use the old-style protocol */
386 #endif /* ATHENA_COMPAT */
390 int gettimeofday(struct timeval *tv, struct timezone *tz);
392 int PASCAL krb_sendauth(long, int, KTEXT, char *, char *, char *,
393 unsigned long, MSG_DAT *, CREDENTIALS *,
394 Key_schedule *, struct sockaddr_in *,
395 struct sockaddr_in FAR *, char *);
396 int PASCAL krb_mk_req(KTEXT, char *, char *, char *, long);
397 char * PASCAL krb_getrealm(char *host);
399 void tkt_free(tkt_header FAR* hdr);
400 int krb_get_tf_fullname(char FAR *, char FAR *, char FAR *, char FAR *);
401 int krb_get_tf_realm(char FAR *,char FAR *);
402 int tf_init(char FAR*,int);
404 long LocalHostAddr();
405 int tf_get_pname(char FAR*);
406 int tf_get_pinst(char FAR*);
407 int tf_get_cred(CREDENTIALS FAR*);
409 int tf_save_cred(char FAR*,char FAR*,char FAR*,C_Block,int,int,KTEXT,long);
410 BOOL k_isinst(char FAR *s);
411 BOOL k_isrealm(char FAR *s);
412 BOOL k_isname(char FAR *s);
414 char ** get_krb_err_txt(void); /* 2-22-93, pbh */
416 /* Warning, unique to Windows! */
417 int set_krb_debug(int);
418 int set_krb_ap_req_debug(int);
419 char * PASCAL get_krb_err_txt_entry(int i);
420 char * krb_err_func(int offset, long code);
421 int PASCAL k_decomp_ticket(KTEXT, unsigned char *, char *, char *, char *,
422 unsigned long *, C_Block, int *, unsigned long *,
423 char *, char *, C_Block, Key_schedule);
424 int PASCAL krb_mk_req(KTEXT,char *,char *,char *,long);
425 char * PASCAL krb_getrealm(char *host);
426 char * PASCAL krb_realmofhost(char *host);
427 char * krb_get_phost(char *host);
429 int kname_parse(char *, char *, char *, char *);
430 int krb_get_pw_in_tkt(char *, char *, char *, char *, char *, int, char *);
432 int krb_get_lrealm(char *, int);
434 int krb_use_kerbmem();
436 int krb_check_serv(char *);
438 int krb_get_cred(char *, char *, char *, CREDENTIALS *);
439 int send_to_kdc(KTEXT, KTEXT, char *);
441 int create_ciph(KTEXT, C_Block, char *, char *, char *, unsigned long, int,
442 KTEXT, unsigned long, C_Block *);
444 char *krb_get_krbconf2(char *, size_t *);
445 char *krb_get_krbrealm2(char *, size_t *);
447 int krb_save_credentials(char *service, char *instance, char *realm,
448 C_Block session, int lifetime, int kvno,
449 KTEXT ticket, long issue_date);
451 #define krb_get_err_text get_krb_err_txt_entry
453 int krb_in_tkt(char *pname, char *pinst, char *prealm);
456 int krb_life_to_time(int start, int life);
457 int krb_time_to_life(int start, int end);
458 #endif /* KRB_DEFS */