gssapi_link.c revision ec5347e2c775f027573ce5648b910361aa926c01
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Copyright (C) 2004-2006 Internet Systems Consortium, Inc. ("ISC")
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Copyright (C) 2000-2002 Internet Software Consortium.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews *
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Permission to use, copy, modify, and/or distribute this software for any
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * purpose with or without fee is hereby granted, provided that the above
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * copyright notice and this permission notice appear in all copies.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews *
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * PERFORMANCE OF THIS SOFTWARE.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * $Id: gssapi_link.c,v 1.6 2007/06/18 23:47:40 tbox Exp $
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <config.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#ifdef GSSAPI
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <isc/buffer.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <isc/mem.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <isc/string.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <isc/util.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <dst/result.h>
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include "dst_internal.h"
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include "dst_parse.h"
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <dst/gssapi.h>
02d54949f0f1db4729e14c3322b207f58d2578a4Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#define INITIAL_BUFFER_SIZE 1024
02d54949f0f1db4729e14c3322b207f58d2578a4Mark Andrews#define BUFFER_EXTRA 1024
02d54949f0f1db4729e14c3322b207f58d2578a4Mark Andrews
02d54949f0f1db4729e14c3322b207f58d2578a4Mark Andrews#define REGION_TO_GBUFFER(r, gb) \
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews do { \
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews (gb).length = (r).length; \
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews (gb).value = (r).base; \
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews } while (0)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstruct dst_gssapi_signverifyctx {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_t *buffer;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews};
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*%
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Allocate a temporary "context" for use in gathering data for signing
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * or verifying.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_create_signverify_ctx(dst_key_t *key, dst_context_t *dctx) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_signverifyctx_t *ctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_result_t result;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews UNUSED(key);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews ctx = isc_mem_get(dctx->mctx, sizeof(dst_gssapi_signverifyctx_t));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (ctx == NULL)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_NOMEMORY);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews ctx->buffer = NULL;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews result = isc_buffer_allocate(dctx->mctx, &ctx->buffer,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews INITIAL_BUFFER_SIZE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (result != ISC_R_SUCCESS) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_mem_put(dctx->mctx, ctx, sizeof(dst_gssapi_signverifyctx_t));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (result);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews }
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dctx->ctxdata.gssctx = ctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*%
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Destroy the temporary sign/verify context.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic void
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_destroy_signverify_ctx(dst_context_t *dctx) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_signverifyctx_t *ctx = dctx->ctxdata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (ctx != NULL) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (ctx->buffer != NULL)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_free(&ctx->buffer);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_mem_put(dctx->mctx, ctx, sizeof(dst_gssapi_signverifyctx_t));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dctx->ctxdata.gssctx = NULL;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews }
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*%
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Add data to our running buffer of data we will be signing or verifying.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * This code will see if the new data will fit in our existing buffer, and
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * copy it in if it will. If not, it will attempt to allocate a larger
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * buffer and copy old+new into it, and free the old buffer.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_adddata(dst_context_t *dctx, const isc_region_t *data) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_signverifyctx_t *ctx = dctx->ctxdata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_t *newbuffer = NULL;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_region_t r;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews unsigned int length;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_result_t result;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews result = isc_buffer_copyregion(ctx->buffer, data);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (result == ISC_R_SUCCESS)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews length = isc_buffer_length(ctx->buffer) + data->length + BUFFER_EXTRA;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews result = isc_buffer_allocate(dctx->mctx, &newbuffer, length);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (result != ISC_R_SUCCESS)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (result);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_usedregion(ctx->buffer, &r);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews (void)isc_buffer_copyregion(newbuffer, &r);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews (void)isc_buffer_copyregion(newbuffer, data);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_free(&ctx->buffer);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews ctx->buffer = newbuffer;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*%
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Sign.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_sign(dst_context_t *dctx, isc_buffer_t *sig) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_signverifyctx_t *ctx = dctx->ctxdata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_region_t message;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_buffer_desc gmessage, gsig;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews OM_uint32 minor, gret;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_ctx_id_t gssctx = dctx->key->keydata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews char buf[1024];
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Convert the data we wish to sign into a structure gssapi can
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * understand.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_usedregion(ctx->buffer, &message);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews REGION_TO_GBUFFER(message, gmessage);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Generate the signature.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret = gss_get_mic(&minor, gssctx, GSS_C_QOP_DEFAULT, &gmessage,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews &gsig);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * If it did not complete, we log the result and return a generic
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * failure code.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (gret != GSS_S_COMPLETE) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_log(3, "GSS sign error: %s",
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_error_tostring(gret, minor, buf, sizeof(buf)));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_FAILURE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews }
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * If it will not fit in our allocated buffer, return that we need
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * more space.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (gsig.length > isc_buffer_availablelength(sig)) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_release_buffer(&minor, &gsig);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_NOSPACE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews }
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Copy the output into our buffer space, and release the gssapi
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * allocated space.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_putmem(sig, gsig.value, gsig.length);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_release_buffer(&minor, &gsig);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*%
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Verify.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_verify(dst_context_t *dctx, const isc_region_t *sig) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_signverifyctx_t *ctx = dctx->ctxdata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_region_t message, r;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_buffer_desc gmessage, gsig;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews OM_uint32 minor, gret;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_ctx_id_t gssctx = dctx->key->keydata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews unsigned char *buf;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews char err[1024];
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Convert the data we wish to sign into a structure gssapi can
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * understand.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_buffer_usedregion(ctx->buffer, &message);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews REGION_TO_GBUFFER(message, gmessage);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * XXXMLG
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * It seem that gss_verify_mic() modifies the signature buffer,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * at least on Heimdal's implementation. Copy it here to an allocated
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * buffer.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews buf = isc_mem_allocate(dst__memory_pool, sig->length);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (buf == NULL)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_FAILURE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews memcpy(buf, sig->base, sig->length);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews r.base = buf;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews r.length = sig->length;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews REGION_TO_GBUFFER(r, gsig);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Verify the data.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret = gss_verify_mic(&minor, gssctx, &gmessage, &gsig, NULL);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_mem_free(dst__memory_pool, buf);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /*
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews * Convert return codes into something useful to us.
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (gret != GSS_S_COMPLETE) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_log(3, "GSS verify error: %s",
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_error_tostring(gret, minor, err, sizeof(err)));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (gret == GSS_S_DEFECTIVE_TOKEN ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_BAD_SIG ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_DUPLICATE_TOKEN ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_OLD_TOKEN ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_UNSEQ_TOKEN ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_GAP_TOKEN ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_CONTEXT_EXPIRED ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_NO_CONTEXT ||
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gret == GSS_S_FAILURE)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return(DST_R_VERIFYFAILURE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews else
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_FAILURE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews }
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_boolean_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_compare(const dst_key_t *key1, const dst_key_t *key2) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_ctx_id_t gsskey1 = key1->keydata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gss_ctx_id_t gsskey2 = key2->keydata.gssctx;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /* No idea */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_TF(gsskey1 == gsskey2));
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_generate(dst_key_t *key, int unused) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews UNUSED(key);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews UNUSED(unused);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews /* No idea */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_FAILURE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic isc_boolean_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_isprivate(const dst_key_t *key) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews UNUSED(key);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_TRUE);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic void
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsgssapi_destroy(dst_key_t *key) {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews REQUIRE(key != NULL);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews dst_gssapi_deletectx(key->mctx, &key->keydata.gssctx);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews key->keydata.gssctx = NULL;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstatic dst_func_t gssapi_functions = {
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_create_signverify_ctx,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_destroy_signverify_ctx,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_adddata,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_sign,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_verify,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews NULL, /*%< computesecret */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_compare,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews NULL, /*%< paramcompare */
373b9944b66f218b3ef1a8bf8eed4731b4f7618aMark Andrews gssapi_generate,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_isprivate,
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews gssapi_destroy,
373b9944b66f218b3ef1a8bf8eed4731b4f7618aMark Andrews NULL, /*%< todns */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews NULL, /*%< fromdns */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews NULL, /*%< tofile */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews NULL, /*%< parse */
45b2fd65df3013ab2c6e3e13dd8d56a6f329b98cMichael Graff NULL, /*%< cleanup */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews};
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsisc_result_t
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsdst__gssapi_init(dst_func_t **funcp) {
45b2fd65df3013ab2c6e3e13dd8d56a6f329b98cMichael Graff REQUIRE(funcp != NULL);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews if (*funcp == NULL)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews *funcp = &gssapi_functions;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews return (ISC_R_SUCCESS);
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews}
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#else
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsint gssapi_link_unneeded = 1;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#endif
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews/*! \file */
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews