#include <afs/ktc.h>
#include <afs/token.h>
+#define KERBEROS_APPLE_DEPRECATED(x)
#include <krb5.h>
-#if defined(HAVE_ET_COM_ERR_H)
-#include <et/com_err.h>
+#ifdef HAVE_COM_ERR_H
+# include <com_err.h>
+#elif HAVE_ET_COM_ERR_H
+# include <et/com_err.h>
+#elif HAVE_KRB5_COM_ERR_H
+# include <krb5/com_err.h>
#else
-#include <com_err.h>
+# error No com_err.h? We need some kind of com_err.h
#endif
#ifndef HAVE_KERBEROSV_HEIM_ERR_H
#define DIRSTRING "/" /* String form of above */
#define VOLMARKER ':' /* Character separating cellname from mntpt */
#define VOLMARKERSTRING ":" /* String form of above */
+#define AKIMP_LIFETIME_MAX 720 /* Max token lifetime for akimpersonate in hours (30 days) */
typedef struct {
char cell[BUFSIZ];
#define TRYAGAIN(x) (x == AKLOG_TRYAGAIN || \
x == KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN || \
+ x == KRB5_KT_NOTFOUND || \
x == KRB5KRB_ERR_GENERIC)
#if defined(HAVE_KRB5_PRINC_SIZE) || defined(krb5_princ_size)
#error "Must have either krb5_princ_size or krb5_principal_get_comp_string"
#endif
+#if defined(HAVE_ENCODE_KRB5_TICKET)
+extern krb5_error_code encode_krb5_ticket (const krb5_ticket *rep,
+ krb5_data **code);
+#endif
+
#if !defined(HAVE_KRB5_ENCRYPT_TKT_PART) && defined(HAVE_ENCODE_KRB5_ENC_TKT_PART) && defined(HAVE_KRB5_C_ENCRYPT)
extern krb5_error_code encode_krb5_enc_tkt_part (const krb5_enc_tkt_part *rep,
krb5_data **code);
#error "Must have either keyblock or session member of krb5_creds"
#endif
-#ifdef AFS_DARWIN110_ENV
-#define HAVE_NO_KRB5_524 /* MITKerberosShim logs but returns success */
+/* MITKerberosShim logs but returns success */
+#if !defined(HAVE_KRB5_524_CONV_PRINCIPAL) || defined(AFS_DARWIN110_ENV) || (!defined(HAVE_KRB5_524_CONVERT_CREDS) && !defined(HAVE_KRB524_CONVERT_CREDS_KDC))
+#define HAVE_NO_KRB5_524
#elif !defined(HAVE_KRB5_524_CONVERT_CREDS) && defined(HAVE_KRB524_CONVERT_CREDS_KDC)
#define krb5_524_convert_creds krb524_convert_creds_kdc
-#elif !defined(HAVE_KRB5_524_CONVERT_CREDS) && !defined(HAVE_KRB524_CONVERT_CREDS_KDC)
-#define HAVE_NO_KRB5_524
#endif
#if USING_HEIMDAL
static linked_list zsublist; /* List of zephyr subscriptions */
static linked_list hostlist; /* List of host addresses */
static linked_list authedcells; /* List of cells already logged to */
+static int akimp_lifetime = 36000; /* Lifetime for akimpersonate tokens. Default 10 hrs */
+static int akimplifetime_present = 0; /* Whether a lifetime was specified for akimpersonate */
/* A com_error bodge. The idea here is that this routine lets us lookup
* things in the system com_err, if the AFS one just tells us the error
if (strncmp(str, "unknown", strlen("unknown")) == 0) {
#ifdef HAVE_KRB5_SVC_GET_MSG
krb5_svc_get_msg(code,&str);
-#elif defined(HAVE_ERROR_MESSAGE)
- str = error_message(code);
+#elif defined(HAVE_KRB5_GET_ERROR_MESSAGE)
+ krb5_context context;
+ if (krb5_init_context(&context) == 0) {
+ str = krb5_get_error_message(context, code);
+ krb5_free_context(context);
+ }
#else
; /* IRIX apparently has neither: use the string we have */
#endif
exit(AKLOG_AFS);
}
- if (afsconf_GetLocalCell(configdir, *local_cell, MAXCELLCHARS)) {
- fprintf(stderr, "%s: can't determine local cell.\n", progname);
- exit(AKLOG_AFS);
+ if (cell != NULL && cell[0] == '\0') {
+ /* Use the local cell */
+ cell = NULL;
}
- if ((cell == NULL) || (cell[0] == 0))
- cell = *local_cell;
-
/* XXX - This function modifies 'cell' by passing it through lcstring */
if (afsconf_GetCellInfo(configdir, cell, NULL, cellconfig)) {
- fprintf(stderr, "%s: Can't get information about cell %s.\n",
- progname, cell);
+ if (cell != NULL) {
+ fprintf(stderr, "%s: Can't get information about cell %s.\n",
+ progname, cell);
+ } else {
+ fprintf(stderr, "%s: Can't get information about the local cell.\n",
+ progname);
+ }
status = AKLOG_AFS;
+ } else if (afsconf_GetLocalCell(configdir, *local_cell, MAXCELLCHARS)) {
+ fprintf(stderr, "%s: can't determine local cell.\n", progname);
+ exit(AKLOG_AFS);
}
afsconf_Close(configdir);
}
afs_dprintf("We've deduced that we need to authenticate"
" to realm %s.\n", realm_of_cell);
+ status = get_credv5(context, AFSKEY, cell->name,
+ realm_of_cell, v5cred);
}
- status = get_credv5(context, AFSKEY, cell->name,
- realm_of_cell, v5cred);
}
/* If the realm and cell name match, then try without an
afs_com_err(progname, status, "while getting AFS tickets");
#ifdef KRB5_CC_NOT_KTYPE
if (status == KRB5_CC_NOT_KTYPE) {
- fprintf(stderr, "allow_weak_enctypes may be required in the Kerberos configuration\n");
+ fprintf(stderr, "allow_weak_crypto may be required in the Kerberos configuration\n");
}
#endif
status = AKLOG_KERBEROS;
* structure which should be freed by the caller.
* @param[out[ userPtr
* A string containing the principal of the user to whom the token was
- * issued. This is a malloc'd block which should be freed by the caller.
+ * issued. This is a malloc'd block which should be freed by the caller,
+ * if set.
*
* @returns
* 0 on success, an error value upon failure
static int
rxkad_build_native_token(krb5_context context, krb5_creds *v5cred,
struct ktc_tokenUnion **tokenPtr, char **userPtr) {
- char username[BUFSIZ];
+ char username[BUFSIZ]="";
struct ktc_token token;
int status;
#ifdef HAVE_NO_KRB5_524
char k4inst[INST_SZ];
char k4realm[REALM_SZ];
#endif
+ void *inkey = get_cred_keydata(v5cred);
+ size_t inkey_sz = get_cred_keylen(v5cred);
afs_dprintf("Using Kerberos V5 ticket natively\n");
(char *) &k4inst,
(char *) &k4realm);
if (status) {
- afs_com_err(progname, status, "while converting principal "
- "to Kerberos V4 format");
- return AKLOG_KERBEROS;
- }
- strcpy (username, k4name);
- if (k4inst[0]) {
- strcat (username, ".");
- strcat (username, k4inst);
+ if (!noprdb)
+ afs_com_err(progname, status,
+ "while converting principal to Kerberos V4 format");
+ } else {
+ strcpy (username, k4name);
+ if (k4inst[0]) {
+ strcat (username, ".");
+ strcat (username, k4inst);
+ }
}
#else
len = min(get_princ_len(context, v5cred->client, 0),
token.kvno = RXKAD_TKT_TYPE_KERBEROS_V5;
token.startTime = v5cred->times.starttime;;
token.endTime = v5cred->times.endtime;
- memcpy(&token.sessionKey, get_cred_keydata(v5cred),
- get_cred_keylen(v5cred));
+ if (tkt_DeriveDesKey(get_creds_enctype(v5cred), inkey, inkey_sz,
+ &token.sessionKey) != 0) {
+ return RXKADBADKEY;
+ }
token.ticketLen = v5cred->ticket.length;
memcpy(token.ticket, v5cred->ticket.data, token.ticketLen);
return status;
}
- *userPtr = strdup(username);
+ if (username[0] != '\0')
+ *userPtr = strdup(username);
return 0;
}
* structure which should be freed by the caller.
* @param[out[ userPtr
* A string containing the principal of the user to whom the token was
- * issued. This is a malloc'd block which should be freed by the caller.
+ * issued. This is a malloc'd block which should be freed by the caller,
+ * if set.
*
* @returns
* 0 on success, an error value upon failure
* be freed by the caller.
* @parma[out] authuser
* A string containing the principal of the user to whom the token was
- * issued. This is a malloc'd block which should be freed by the caller.
+ * issued. This is a malloc'd block which should be freed by the caller,
+ * if set.
* @param[out] foreign
* Whether the user is considered as 'foreign' to the realm of the cell.
*
static int
rxkad_get_token(krb5_context context, struct afsconf_cell *cell, char *realm,
struct ktc_tokenUnion **token, char **authuser, int *foreign) {
- krb5_creds *v5cred;
+ krb5_creds *v5cred = NULL;
char *realmUsed = NULL;
char *username = NULL;
int status;
status = rxkad_get_ticket(context, realm, cell, &v5cred, &realmUsed);
if (status)
- return status;
+ goto out;
if (do524)
status = rxkad_get_converted_token(context, v5cred, token, &username);
/* We now have the username, plus the realm name, so stitch them together
* to give us the name that the ptserver will know the user by */
- if (realmUsed == NULL) {
+ if (realmUsed == NULL || username == NULL) {
*authuser = username;
username = NULL;
*foreign = 0;
} else {
- asprintf(authuser, "%s@%s", username, realmUsed);
+ if (asprintf(authuser, "%s@%s", username, realmUsed) < 0) {
+ fprintf(stderr, "%s: Out of memory building PTS name\n", progname);
+ *authuser = NULL;
+ status = AKLOG_MISC;
+ goto out;
+ }
*foreign = 1;
}
free(realmUsed);
if (username)
free(username);
+ if (v5cred)
+ krb5_free_creds(context, v5cred);
return status;
}
noprdb = 1;
#endif
- if (noprdb) {
+ if (username == NULL) {
+ afs_dprintf("Not resolving name to id\n");
+ }
+ else if (noprdb) {
afs_dprintf("Not resolving name %s to id (-noprdb set)\n", username);
}
else {
}
}
- afs_dprintf("Setting tokens. %s @ %s \n", username, cellconf.name);
+ if (username) {
+ afs_dprintf("Setting tokens. %s @ %s\n",
+ username, cellconf.name);
+ } else {
+ afs_dprintf("Setting tokens for cell %s\n", cellconf.name);
+ }
#ifndef AFS_AIX51_ENV
/* on AIX 4.1.4 with AFS 3.4a+ if a write is not done before
* this routine, it will not add the token. It is not clear what
* is going on here! So we will do the following operation.
* On AIX 5, it causes the parent program to die, so we won't.
+ * We don't care about the return value, but need to collect it
+ * to avoid compiler warnings.
*/
- write(2,"",0); /* dummy write */
+ if (write(2,"",0) < 0) {
+ /* dummy write, don't care */
+ }
#endif
token_setPag(token, afssetpag);
status = ktc_SetTokenEx(token);
struct ViceIoctl vio;
char cellname[BUFSIZ];
- memset(our_file, 0, sizeof(our_file));
- strcpy(our_file, file);
+ strlcpy(our_file, file, sizeof(our_file));
if ((last_component = strrchr(our_file, DIR))) {
*last_component++ = 0;
vio.out = cellname;
if (!pioctl(file, VIOC_FILE_CELL_NAME, &vio, 1)) {
- strcat(cellname, VOLMARKERSTRING);
- strcat(cellname, mountpoint + 1);
+ strlcat(cellname, VOLMARKERSTRING, sizeof(cellname));
+ strlcat(cellname, mountpoint + 1, sizeof(cellname));
memset(mountpoint + 1, 0, size - 1);
strcpy(mountpoint + 1, cellname);
}
static char path[MAXPATHLEN + 1];
static char pathtocheck[MAXPATHLEN + 1];
- int link = FALSE; /* Is this a symbolic link? */
+ ssize_t link; /* Return value from readlink */
char linkbuf[MAXPATHLEN + 1];
char tmpbuf[MAXPATHLEN + 1];
if (origpath) {
memset(path, 0, sizeof(path));
memset(pathtocheck, 0, sizeof(pathtocheck));
- strcpy(path, origpath);
+ strlcpy(path, origpath, sizeof(path));
last_comp = path;
symlinkcount = 0;
return(NULL);
? elast_comp - last_comp : strlen(last_comp);
strncat(pathtocheck, last_comp, len);
memset(linkbuf, 0, sizeof(linkbuf));
- if ((link = (readlink(pathtocheck, linkbuf,
- sizeof(linkbuf)) > 0))) {
+ link = readlink(pathtocheck, linkbuf, sizeof(linkbuf)-1);
+
+ if (link > 0) {
+ linkbuf[link] = '\0'; /* NUL terminate string */
+
if (++symlinkcount > MAXSYMLINKS) {
fprintf(stderr, "%s: %s\n", progname, strerror(ELOOP));
exit(AKLOG_BADPATH);
}
+
memset(tmpbuf, 0, sizeof(tmpbuf));
if (elast_comp)
- strcpy(tmpbuf, elast_comp);
+ strlcpy(tmpbuf, elast_comp, sizeof(tmpbuf));
if (linkbuf[0] == DIR) {
/*
* If this is a symbolic link to an absolute path,
else
last_comp = elast_comp;
}
- while(link);
+ while(link > 0);
return(pathtocheck);
}
/* Initialize */
if (path[0] == DIR)
- strcpy(pathtocheck, path);
+ strlcpy(pathtocheck, path, sizeof(pathtocheck));
else {
if (getcwd(pathtocheck, sizeof(pathtocheck)) == NULL) {
fprintf(stderr, "Unable to find current working directory:\n");
exit(AKLOG_BADPATH);
}
else {
- strcat(pathtocheck, DIRSTRING);
- strcat(pathtocheck, path);
+ strlcat(pathtocheck, DIRSTRING, sizeof(pathtocheck));
+ strlcat(pathtocheck, path, sizeof(pathtocheck));
}
}
next_path(pathtocheck);
/* Go on to the next level down the path */
while ((nextpath = next_path(NULL))) {
- strcpy(pathtocheck, nextpath);
+ strlcpy(pathtocheck, nextpath, sizeof(pathtocheck));
afs_dprintf("Checking directory %s\n", pathtocheck);
/*
* If this is an afs mountpoint, determine what cell from
"[-d] [[-cell | -c] cell [-k krb_realm]] ",
"[[-p | -path] pathname]\n",
" [-zsubs] [-hosts] [-noauth] [-noprdb] [-force] [-setpag] \n"
- " [-linked]"
+ " [-linked] [-insecure_des]"
#ifndef HAVE_NO_KRB5_524
" [-524]"
#endif
#ifndef HAVE_NO_KRB5_524
fprintf(stderr, " -524 means use the 524 converter instead of V5 directly\n");
#endif
+ fprintf(stderr, " -insecure_des enables insecure single-DES for krb5.\n");
fprintf(stderr, " No commandline arguments means ");
fprintf(stderr, "authenticate to the local cell.\n");
fprintf(stderr, "\n");
int status = AKLOG_SUCCESS;
int i;
int somethingswrong = FALSE;
+ int insecure_des = 0;
cellinfo_t cellinfo;
{
char *filepath = NULL, *newpath = NULL;
#ifndef AFS_DARWIN_ENV
- char *defaultpath = "/etc/krb5.conf";
+ char *defaultpath = "/etc/krb5.conf:/etc/krb5/krb5.conf";
#else
char *defaultpath = "~/Library/Preferences/edu.mit.Kerberos:/Library/Preferences/edu.mit.Kerberos";
#endif
filepath = getenv("KRB5_CONFIG");
- asprintf(&newpath, "%s:%s/krb5-weak.conf",
- filepath ? filepath : defaultpath,
- AFSDIR_CLIENT_ETC_DIRPATH);
- setenv("KRB5_CONFIG", newpath, 1);
+
+ /* only fiddle with KRB5_CONFIG if krb5-weak.conf actually exists */
+ if (asprintf(&newpath, "%s/krb5-weak.conf",
+ AFSDIR_CLIENT_ETC_DIRPATH) < 0)
+ newpath = NULL;
+ if (newpath != NULL && access(newpath, R_OK) == 0) {
+ free(newpath);
+ newpath = NULL;
+ if (asprintf(&newpath, "%s:%s/krb5-weak.conf",
+ filepath ? filepath : defaultpath,
+ AFSDIR_CLIENT_ETC_DIRPATH) < 0)
+ newpath = NULL;
+ else
+ setenv("KRB5_CONFIG", newpath, 1);
+ }
#endif
krb5_init_context(&context);
#if defined(KRB5_PROG_ETYPE_NOSUPP) && !(defined(HAVE_KRB5_ENCTYPE_ENABLE) || defined(HAVE_KRB5_ALLOW_WEAK_CRYPTO))
- free(newpath);
+ if (newpath)
+ free(newpath);
if (filepath)
setenv("KRB5_CONFIG", filepath, 1);
else
initialize_PT_error_table();
afs_set_com_err_hook(redirect_errors);
- /*
- * Enable DES enctypes, which are currently still required for AFS.
- * krb5_allow_weak_crypto is MIT Kerberos 1.8. krb5_enctype_enable is
- * Heimdal.
- */
-#if defined(HAVE_KRB5_ENCTYPE_ENABLE)
- i = krb5_enctype_valid(context, ETYPE_DES_CBC_CRC);
- if (i)
- krb5_enctype_enable(context, ETYPE_DES_CBC_CRC);
-#elif defined(HAVE_KRB5_ALLOW_WEAK_CRYPTO)
- krb5_allow_weak_crypto(context, 1);
-#endif
-
/* Initialize list of cells to which we have authenticated */
ll_init(&authedcells);
(strcmp(argv[i], "-c") == 0)) && !pmode)
if (++i < argc) {
cmode++;
- strcpy(cell, argv[i]);
+ strlcpy(cell, argv[i], sizeof(cell));
}
else
usage();
}
else
usage();
+ else if ((strcmp(argv[i], "-token-lifetime") == 0))
+ if (++i < argc) {
+ status = util_GetInt32(argv[i], &akimp_lifetime);
+ if (status) {
+ fprintf(stderr,
+ "%s: invalid value specified for token-lifetime.\n",
+ progname);
+ exit(AKLOG_MISC);
+ }
+
+ if (akimp_lifetime < 0 || akimp_lifetime > AKIMP_LIFETIME_MAX) {
+ fprintf(stderr,
+ "%s: token-lifetime must be within 0 and %d hrs.\n",
+ progname, AKIMP_LIFETIME_MAX);
+ exit(AKLOG_MISC);
+ }
+
+ akimp_lifetime = akimp_lifetime * 60 * 60;
+ akimplifetime_present = TRUE;
+ }
+ else
+ usage();
else if ((strcmp(argv[i], "-principal") == 0))
if (++i < argc) {
client = argv[i];
(strcmp(argv[i], "-p") == 0)) && !cmode)
if (++i < argc) {
pmode++;
- strcpy(path, argv[i]);
+ strlcpy(path, argv[i], sizeof(path));
}
else
usage();
}
else
usage();
+ else if (strcmp(argv[i], "-insecure_des") == 0)
+ insecure_des = 1;
else if (argv[i][0] == '-')
usage();
else if (!pmode && !cmode) {
if (strchr(argv[i], DIR) || (strcmp(argv[i], ".") == 0) ||
(strcmp(argv[i], "..") == 0)) {
pmode++;
- strcpy(path, argv[i]);
+ strlcpy(path, argv[i], sizeof(path));
}
else {
cmode++;
- strcpy(cell, argv[i]);
+ strlcpy(cell, argv[i], sizeof(cell));
}
}
else
usage();
+ /*
+ * Enable DES enctypes if requested. This is not required when rxkad-k5
+ * is used, but some sites may not have updated.
+ * krb5_allow_weak_crypto is MIT Kerberos 1.8. krb5_enctype_enable is
+ * Heimdal.
+ */
+ if (insecure_des) {
+#if defined(HAVE_KRB5_ENCTYPE_ENABLE)
+ i = krb5_enctype_valid(context, ETYPE_DES_CBC_CRC);
+ if (i)
+ krb5_enctype_enable(context, ETYPE_DES_CBC_CRC);
+#elif defined(HAVE_KRB5_ALLOW_WEAK_CRYPTO)
+ krb5_allow_weak_crypto(context, 1);
+#else
+ fprintf(stderr,
+ "%s: -insecure_des is not supported by this libkrb5\n", progname);
+ exit(AKLOG_MISC);
+#endif
+ }
+
if (cmode) {
if (((i + 1) < argc) && (strcmp(argv[i + 1], "-k") == 0)) {
i+=2;
if (i < argc)
- strcpy(realm, argv[i]);
+ strlcpy(realm, argv[i], sizeof(realm));
else
usage();
}
}
}
+ if (akimplifetime_present && !keytab) {
+ fprintf(stderr,
+ "%s: -token-lifetime is valid only if -keytab is specified.\n",
+ progname);
+ exit(AKLOG_MISC);
+ }
+
/* If nothing was given, log to the local cell. */
if ((cells.nelements + paths.nelements) == 0) {
struct passwd *pwd;
FILE *f;
char fcell[100], xlog_path[512];
- strcpy(xlog_path, pwd->pw_dir);
- strcat(xlog_path, "/.xlog");
+ strlcpy(xlog_path, pwd->pw_dir, sizeof(xlog_path));
+ strlcat(xlog_path, "/.xlog", sizeof(xlog_path));
if ((stat(xlog_path, &sbuf) == 0) &&
((f = fopen(xlog_path, "r")) != NULL)) {
krb5_principal client_principal,
time_t starttime,
time_t endtime,
- int *allowed_enctypes,
int *paddress,
krb5_creds** out_creds /* out */ )
{
-#if defined(USING_HEIMDAL) || (defined(HAVE_ENCODE_KRB5_ENC_TKT) && defined(HAVE_ENCODE_KRB5_TICKET) && defined(HAVE_KRB5_C_ENCRYPT))
+#if defined(USING_HEIMDAL) || (defined(HAVE_ENCODE_KRB5_ENC_TKT_PART) && defined(HAVE_ENCODE_KRB5_TICKET) && defined(HAVE_KRB5_C_ENCRYPT))
krb5_error_code code;
krb5_keytab kt = 0;
- krb5_kt_cursor cursor[1];
krb5_keytab_entry entry[1];
krb5_ccache cc = 0;
krb5_creds *creds = 0;
krb5_data * temp;
#endif
int i;
- static int any_enctype[] = {0};
*out_creds = 0;
if (!(creds = malloc(sizeof *creds))) {
code = ENOMEM;
goto cleanup;
}
- if (!allowed_enctypes)
- allowed_enctypes = any_enctype;
cc = 0;
enctype = 0; /* AKIMPERSONATE_IGNORE_ENCTYPE */
goto cleanup;
}
- if (service_principal) {
- for (i = 0; (enctype = allowed_enctypes[i]) || !i; ++i) {
- code = krb5_kt_get_entry(context,
- kt,
- service_principal,
- kvno,
- enctype,
- entry);
- if (!code) {
- if (allowed_enctypes[i])
- deref_keyblock_enctype(session_key) = allowed_enctypes[i];
- break;
- }
- }
- if (code) {
- afs_com_err(progname, code,"while scanning keytab entries");
- goto cleanup;
- }
- } else {
- krb5_keytab_entry new[1];
- int best = -1;
- memset(new, 0, sizeof *new);
- if ((code == krb5_kt_start_seq_get(context, kt, cursor))) {
- afs_com_err(progname, code, "while starting keytab scan");
- goto cleanup;
- }
- while (!(code = krb5_kt_next_entry(context, kt, new, cursor))) {
- for (i = 0;
- allowed_enctypes[i] && allowed_enctypes[i]
- != deref_entry_enctype(new); ++i)
- ;
- if ((!i || allowed_enctypes[i]) &&
- (best < 0 || best > i)) {
- krb5_free_keytab_entry_contents(context, entry);
- *entry = *new;
- memset(new, 0, sizeof *new);
- } else krb5_free_keytab_entry_contents(context, new);
- }
- if ((i = krb5_kt_end_seq_get(context, kt, cursor))) {
- afs_com_err(progname, i, "while ending keytab scan");
- code = i;
- goto cleanup;
- }
- if (best < 0) {
- afs_com_err(progname, code, "while scanning keytab");
- goto cleanup;
- }
+ code = krb5_kt_get_entry(context,
+ kt,
+ service_principal,
+ kvno,
+ enctype,
+ entry);
+ if (!code)
deref_keyblock_enctype(session_key) = deref_entry_enctype(entry);
+ else {
+ afs_com_err(progname, code, "while scanning keytab entries");
+ goto cleanup;
}
/* Make Ticket */
enc_tkt_reply->authtime = starttime;
enc_tkt_reply->starttime = temp_time;
*enc_tkt_reply->starttime = starttime;
-#if 0
- enc_tkt_reply->renew_till = temp_time + 1;
- *enc_tkt_reply->renew_till = endtime;
-#endif
enc_tkt_reply->endtime = endtime;
#else
if ((code = krb5_c_make_random_key(context,
if (deref_enc_data(&ticket_reply->enc_part))
free(deref_enc_data(&ticket_reply->enc_part));
krb5_free_keytab_entry_contents(context, entry);
- if (client_principal)
- krb5_free_principal(context, client_principal);
- if (service_principal)
- krb5_free_principal(context, service_principal);
if (cc)
krb5_cc_close(context, cc);
if (kt)
{
krb5_creds increds;
krb5_error_code r;
- static krb5_principal client_principal = 0;
afs_dprintf("Getting tickets: %s%s%s@%s\n", name,
(inst && inst[0]) ? "/" : "", inst ? inst : "", realm);
if ((r = krb5_build_principal(context, &increds.server,
strlen(realm), realm,
name,
- (inst && strlen(inst)) ? inst : (void *) NULL,
- (void *) NULL))) {
- return r;
+ (inst && strlen(inst)) ? inst : NULL,
+ NULL))) {
+ goto out;
}
if (!_krb425_ccache) {
r = krb5_cc_default(context, &_krb425_ccache);
if (r)
- return r;
+ goto out;
}
- if (!client_principal) {
- if (client) {
- r = krb5_parse_name(context, client, &client_principal);
- } else {
- r = krb5_cc_get_principal(context, _krb425_ccache, &client_principal);
- }
- if (r)
- return r;
+
+ if (client) {
+ r = krb5_parse_name(context, client, &increds.client);
+ } else {
+ r = krb5_cc_get_principal(context, _krb425_ccache, &increds.client);
}
- increds.client = client_principal;
+ if (r)
+ goto out;
+
increds.times.endtime = 0;
- /* Ask for DES since that is what V4 understands */
- get_creds_enctype((&increds)) = ENCTYPE_DES_CBC_CRC;
+ if (do524)
+ /* Ask for DES since that is what V4 understands */
+ get_creds_enctype((&increds)) = ENCTYPE_DES_CBC_CRC;
if (keytab) {
- int allowed_enctypes[] = {
- ENCTYPE_DES_CBC_CRC, 0
- };
+ afs_int32 start, end;
+ start = time(NULL);
+
+ if (akimp_lifetime == 0) {
+ end = MAX_AFS_INT32;
+ } else {
+ end = start + akimp_lifetime;
+ }
r = get_credv5_akimpersonate(context,
keytab,
increds.server,
increds.client,
- 300, ((~0U)>>1),
- allowed_enctypes,
+ start, end,
0 /* paddress */,
creds /* out */);
} else {
r = krb5_get_credentials(context, 0, _krb425_ccache, &increds, creds);
}
- return r;
-}
+ out:
+
+ if (increds.server) {
+ krb5_free_principal(context, increds.server);
+ }
+
+ if (increds.client) {
+ krb5_free_principal(context, increds.client);
+ }
+
+ return r;
+}
static int
get_user_realm(krb5_context context, char **realm)