195 lines
5.2 KiB
C
195 lines
5.2 KiB
C
/*
|
|
* Copyright (c) 1997-2007 Kungliga Tekniska Högskolan
|
|
* (Royal Institute of Technology, Stockholm, Sweden).
|
|
* All rights reserved.
|
|
*
|
|
* Portions Copyright (c) 2010 Apple Inc. All rights reserved.
|
|
*
|
|
* Redistribution and use in source and binary forms, with or without
|
|
* modification, are permitted provided that the following conditions
|
|
* are met:
|
|
*
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
* notice, this list of conditions and the following disclaimer.
|
|
*
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
* documentation and/or other materials provided with the distribution.
|
|
*
|
|
* 3. Neither the name of the Institute nor the names of its contributors
|
|
* may be used to endorse or promote products derived from this software
|
|
* without specific prior written permission.
|
|
*
|
|
* THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
|
|
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
|
|
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
* SUCH DAMAGE.
|
|
*/
|
|
|
|
#include "kdc_locl.h"
|
|
|
|
krb5_error_code
|
|
_kdc_fast_mk_response(krb5_context context,
|
|
krb5_crypto armor_crypto,
|
|
METHOD_DATA *pa_data,
|
|
krb5_keyblock *strengthen_key,
|
|
KrbFastFinished *finished,
|
|
krb5uint32 nonce,
|
|
krb5_data *data)
|
|
{
|
|
PA_FX_FAST_REPLY fxfastrep;
|
|
KrbFastResponse fastrep;
|
|
krb5_error_code ret;
|
|
krb5_data buf;
|
|
size_t size;
|
|
|
|
memset(&fxfastrep, 0, sizeof(fxfastrep));
|
|
memset(&fastrep, 0, sizeof(fastrep));
|
|
krb5_data_zero(data);
|
|
|
|
if (pa_data) {
|
|
fastrep.padata.val = pa_data->val;
|
|
fastrep.padata.len = pa_data->len;
|
|
}
|
|
fastrep.strengthen_key = strengthen_key;
|
|
fastrep.finished = finished;
|
|
fastrep.nonce = nonce;
|
|
|
|
ASN1_MALLOC_ENCODE(KrbFastResponse, buf.data, buf.length,
|
|
&fastrep, &size, ret);
|
|
if (ret)
|
|
return ret;
|
|
if (buf.length != size)
|
|
krb5_abortx(context, "internal asn.1 error");
|
|
|
|
fxfastrep.element = choice_PA_FX_FAST_REPLY_armored_data;
|
|
|
|
ret = krb5_encrypt_EncryptedData(context,
|
|
armor_crypto,
|
|
KRB5_KU_FAST_REP,
|
|
buf.data,
|
|
buf.length,
|
|
0,
|
|
&fxfastrep.u.armored_data.enc_fast_rep);
|
|
krb5_data_free(&buf);
|
|
if (ret)
|
|
return ret;
|
|
|
|
ASN1_MALLOC_ENCODE(PA_FX_FAST_REPLY, data->data, data->length,
|
|
&fxfastrep, &size, ret);
|
|
free_PA_FX_FAST_REPLY(&fxfastrep);
|
|
if (ret)
|
|
return ret;
|
|
if (data->length != size)
|
|
krb5_abortx(context, "internal asn.1 error");
|
|
|
|
return 0;
|
|
}
|
|
|
|
|
|
krb5_error_code
|
|
_kdc_fast_mk_error(krb5_context context,
|
|
METHOD_DATA *error_method,
|
|
krb5_crypto armor_crypto,
|
|
const KDC_REQ_BODY *req_body,
|
|
krb5_error_code outer_error,
|
|
const char *e_text,
|
|
krb5_principal error_client,
|
|
krb5_principal error_server,
|
|
time_t *csec, int *cusec,
|
|
krb5_data *error_msg)
|
|
{
|
|
krb5_error_code ret;
|
|
krb5_data e_data;
|
|
size_t size;
|
|
|
|
krb5_data_zero(&e_data);
|
|
|
|
if (armor_crypto) {
|
|
PA_FX_FAST_REPLY fxfastrep;
|
|
KrbFastResponse fastrep;
|
|
|
|
memset(&fxfastrep, 0, sizeof(fxfastrep));
|
|
memset(&fastrep, 0, sizeof(fastrep));
|
|
|
|
/* first add the KRB-ERROR to the fast errors */
|
|
|
|
ret = krb5_mk_error(context,
|
|
outer_error,
|
|
e_text,
|
|
NULL,
|
|
error_client,
|
|
error_server,
|
|
NULL,
|
|
NULL,
|
|
&e_data);
|
|
if (ret)
|
|
return ret;
|
|
|
|
ret = krb5_padata_add(context, error_method,
|
|
KRB5_PADATA_FX_ERROR,
|
|
e_data.data, e_data.length);
|
|
if (ret) {
|
|
krb5_data_free(&e_data);
|
|
return ret;
|
|
}
|
|
|
|
if (/* hide_principal */ 0) {
|
|
error_client = NULL;
|
|
error_server = NULL;
|
|
e_text = NULL;
|
|
}
|
|
|
|
ret = krb5_padata_add(context, error_method,
|
|
KRB5_PADATA_FX_COOKIE,
|
|
NULL, 0);
|
|
if (ret)
|
|
return ret;
|
|
|
|
ret = _kdc_fast_mk_response(context, armor_crypto,
|
|
error_method, NULL, NULL,
|
|
req_body->nonce, &e_data);
|
|
free_METHOD_DATA(error_method);
|
|
if (ret)
|
|
return ret;
|
|
|
|
ret = krb5_padata_add(context, error_method,
|
|
KRB5_PADATA_FX_FAST,
|
|
e_data.data, e_data.length);
|
|
if (ret)
|
|
return ret;
|
|
|
|
if (ret)
|
|
return ret;
|
|
}
|
|
|
|
if (error_method && error_method->len) {
|
|
ASN1_MALLOC_ENCODE(METHOD_DATA, e_data.data, e_data.length,
|
|
error_method, &size, ret);
|
|
if (ret)
|
|
return ret;
|
|
if (e_data.length != size)
|
|
krb5_abortx(context, "internal asn.1 error");
|
|
}
|
|
|
|
ret = krb5_mk_error(context,
|
|
outer_error,
|
|
e_text,
|
|
(e_data.length ? &e_data : NULL),
|
|
error_client,
|
|
error_server,
|
|
csec,
|
|
cusec,
|
|
error_msg);
|
|
krb5_data_free(&e_data);
|
|
|
|
return ret;
|
|
}
|