505d05c73a6e56769f263d4803b22eddd168ee24gtb/*
505d05c73a6e56769f263d4803b22eddd168ee24gtb * lib/krb5/ccache/ccfns.c
505d05c73a6e56769f263d4803b22eddd168ee24gtb *
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan * Copyright 2000, 2007 by the Massachusetts Institute of Technology.
505d05c73a6e56769f263d4803b22eddd168ee24gtb * All Rights Reserved.
505d05c73a6e56769f263d4803b22eddd168ee24gtb *
505d05c73a6e56769f263d4803b22eddd168ee24gtb * Export of this software from the United States of America may
505d05c73a6e56769f263d4803b22eddd168ee24gtb * require a specific license from the United States Government.
505d05c73a6e56769f263d4803b22eddd168ee24gtb * It is the responsibility of any person or organization contemplating
505d05c73a6e56769f263d4803b22eddd168ee24gtb * export to obtain such a license before exporting.
505d05c73a6e56769f263d4803b22eddd168ee24gtb *
505d05c73a6e56769f263d4803b22eddd168ee24gtb * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
505d05c73a6e56769f263d4803b22eddd168ee24gtb * distribute this software and its documentation for any purpose and
505d05c73a6e56769f263d4803b22eddd168ee24gtb * without fee is hereby granted, provided that the above copyright
505d05c73a6e56769f263d4803b22eddd168ee24gtb * notice appear in all copies and that both that copyright notice and
505d05c73a6e56769f263d4803b22eddd168ee24gtb * this permission notice appear in supporting documentation, and that
505d05c73a6e56769f263d4803b22eddd168ee24gtb * the name of M.I.T. not be used in advertising or publicity pertaining
505d05c73a6e56769f263d4803b22eddd168ee24gtb * to distribution of the software without specific, written prior
505d05c73a6e56769f263d4803b22eddd168ee24gtb * permission. Furthermore if you modify this software you must label
505d05c73a6e56769f263d4803b22eddd168ee24gtb * your software as modified software and not distribute it in such a
505d05c73a6e56769f263d4803b22eddd168ee24gtb * fashion that it might be confused with the original M.I.T. software.
505d05c73a6e56769f263d4803b22eddd168ee24gtb * M.I.T. makes no representations about the suitability of
505d05c73a6e56769f263d4803b22eddd168ee24gtb * this software for any purpose. It is provided "as is" without express
505d05c73a6e56769f263d4803b22eddd168ee24gtb * or implied warranty.
505d05c73a6e56769f263d4803b22eddd168ee24gtb */
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtb/*
505d05c73a6e56769f263d4803b22eddd168ee24gtb * Dispatch methods for credentials cache code.
505d05c73a6e56769f263d4803b22eddd168ee24gtb */
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtb#include "k5-int.h"
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbconst char * KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_get_name (krb5_context context, krb5_ccache cache)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->get_name(context, cache);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_gen_new (krb5_context context, krb5_ccache *cache)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return (*cache)->ops->gen_new(context, cache);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_initialize(krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_principal principal)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->init(context, cache, principal);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_destroy (krb5_context context, krb5_ccache cache)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->destroy(context, cache);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_close (krb5_context context, krb5_ccache cache)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->close(context, cache);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_store_cred (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_creds *creds)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_error_code ret;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_ticket *tkt;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_principal s1, s2;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan ret = cache->ops->store(context, cache, creds);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan if (ret) return ret;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan /*
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan * If creds->server and the server in the decoded ticket differ,
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan * store both principals.
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan */
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan s1 = creds->server;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan ret = decode_krb5_ticket(&creds->ticket, &tkt);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan /* Bail out on errors in case someone is storing a non-ticket. */
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan if (ret) return 0;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan s2 = tkt->server;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan if (!krb5_principal_compare(context, s1, s2)) {
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan creds->server = s2;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan ret = cache->ops->store(context, cache, creds);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan creds->server = s1;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan }
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_free_ticket(context, tkt);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan return ret;
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_retrieve_cred (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_flags flags, krb5_creds *mcreds,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_creds *creds)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_error_code ret;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan krb5_data tmprealm;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan ret = cache->ops->retrieve(context, cache, flags, mcreds, creds);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan if (ret != KRB5_CC_NOTFOUND)
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan return ret;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan if (!krb5_is_referral_realm(&mcreds->server->realm))
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan return ret;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan /*
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan * Retry using client's realm if service has referral realm.
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan */
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan tmprealm = mcreds->server->realm;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan mcreds->server->realm = mcreds->client->realm;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan ret = cache->ops->retrieve(context, cache, flags, mcreds, creds);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan mcreds->server->realm = tmprealm;
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan return ret;
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_get_principal (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_principal *principal)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->get_princ(context, cache, principal);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_start_seq_get (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_cc_cursor *cursor)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->get_first(context, cache, cursor);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_next_cred (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_cc_cursor *cursor, krb5_creds *creds)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->get_next(context, cache, cursor, creds);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_end_seq_get (krb5_context context, krb5_ccache cache,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_cc_cursor *cursor)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->end_get(context, cache, cursor);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_remove_cred (krb5_context context, krb5_ccache cache, krb5_flags flags,
505d05c73a6e56769f263d4803b22eddd168ee24gtb krb5_creds *creds)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->remove_cred(context, cache, flags, creds);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_error_code KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_set_flags (krb5_context context, krb5_ccache cache, krb5_flags flags)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->set_flags(context, cache, flags);
505d05c73a6e56769f263d4803b22eddd168ee24gtb}
505d05c73a6e56769f263d4803b22eddd168ee24gtb
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalankrb5_error_code KRB5_CALLCONV
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalankrb5_cc_get_flags (krb5_context context, krb5_ccache cache, krb5_flags *flags)
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan{
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan return cache->ops->get_flags(context, cache, flags);
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan}
159d09a20817016f09b3ea28d1bdada4a336bb91Mark Phalan
505d05c73a6e56769f263d4803b22eddd168ee24gtbconst char * KRB5_CALLCONV
505d05c73a6e56769f263d4803b22eddd168ee24gtbkrb5_cc_get_type (krb5_context context, krb5_ccache cache)
505d05c73a6e56769f263d4803b22eddd168ee24gtb{
505d05c73a6e56769f263d4803b22eddd168ee24gtb return cache->ops->prefix;
505d05c73a6e56769f263d4803b22eddd168ee24gtb}