2023-02-03 20:52:04 +03:00
/*
2005-09-29 04:02:38 +04:00
Unix SMB / CIFS implementation .
Handle user credentials ( as regards krb5 )
Copyright ( C ) Jelmer Vernooij 2005
Copyright ( C ) Tim Potter 2001
Copyright ( C ) Andrew Bartlett < abartlet @ samba . org > 2005
2023-02-03 20:52:04 +03:00
2005-09-29 04:02:38 +04:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-10 06:07:03 +04:00
the Free Software Foundation ; either version 3 of the License , or
2005-09-29 04:02:38 +04:00
( at your option ) any later version .
2023-02-03 20:52:04 +03:00
2005-09-29 04:02:38 +04:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2023-02-03 20:52:04 +03:00
2005-09-29 04:02:38 +04:00
You should have received a copy of the GNU General Public License
2007-07-10 06:07:03 +04:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2005-09-29 04:02:38 +04:00
*/
# include "includes.h"
# include "system/kerberos.h"
2012-04-24 20:37:13 +04:00
# include "system/gssapi.h"
2005-09-29 04:02:38 +04:00
# include "auth/kerberos/kerberos.h"
2006-11-07 03:48:36 +03:00
# include "auth/credentials/credentials.h"
2013-07-31 14:41:40 +04:00
# include "auth/credentials/credentials_internal.h"
2006-11-07 03:48:36 +03:00
# include "auth/credentials/credentials_krb5.h"
2010-05-01 04:33:08 +04:00
# include "auth/kerberos/kerberos_credentials.h"
2012-03-31 03:33:53 +04:00
# include "auth/kerberos/kerberos_srv_keytab.h"
2010-10-11 03:28:45 +04:00
# include "auth/kerberos/kerberos_util.h"
2012-04-22 01:26:18 +04:00
# include "auth/kerberos/pac_utils.h"
2007-12-02 22:56:26 +03:00
# include "param/param.h"
2018-02-16 19:15:28 +03:00
# include "../libds/common/flags.h"
2005-09-29 04:02:38 +04:00
2017-12-19 12:49:10 +03:00
# undef DBGC_CLASS
# define DBGC_CLASS DBGC_AUTH
2020-08-07 23:27:39 +03:00
# undef strncasecmp
2012-03-31 01:11:02 +04:00
static void cli_credentials_invalidate_client_gss_creds (
struct cli_credentials * cred ,
enum credentials_obtained obtained ) ;
2016-10-06 10:22:29 +03:00
/* Free a memory ccache */
static int free_mccache ( struct ccache_container * ccc )
{
2016-10-01 12:25:44 +03:00
if ( ccc - > ccache ! = NULL ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ) ;
ccc - > ccache = NULL ;
}
2016-10-06 10:22:29 +03:00
return 0 ;
}
/* Free a disk-based ccache */
2016-10-01 12:27:54 +03:00
static int free_dccache ( struct ccache_container * ccc )
{
if ( ccc - > ccache ! = NULL ) {
krb5_cc_close ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ) ;
ccc - > ccache = NULL ;
}
2016-10-06 10:22:29 +03:00
return 0 ;
}
2016-12-22 15:50:05 +03:00
static uint32_t smb_gss_krb5_copy_ccache ( uint32_t * min_stat ,
gss_cred_id_t cred ,
struct ccache_container * ccc )
{
# ifndef SAMBA4_USES_HEIMDAL /* MIT 1.10 */
krb5_context context = ccc - > smb_krb5_context - > krb5_context ;
krb5_ccache dummy_ccache = NULL ;
krb5_creds creds = { 0 } ;
krb5_cc_cursor cursor = NULL ;
krb5_principal princ = NULL ;
krb5_error_code code ;
uint32_t maj_stat = GSS_S_FAILURE ;
/*
* Create a dummy ccache , so we can iterate over the credentials
* and find the default principal for the ccache we want to
* copy . The new ccache needs to be initialized with this
* principal .
*/
2024-02-27 18:19:58 +03:00
code = smb_krb5_cc_new_unique_memory ( context , NULL , NULL , & dummy_ccache ) ;
2016-12-22 15:50:05 +03:00
if ( code ! = 0 ) {
* min_stat = code ;
return GSS_S_FAILURE ;
}
/*
* We do not need set a default principal on the temporary dummy
* ccache , as we do consume it at all in this function .
*/
maj_stat = gss_krb5_copy_ccache ( min_stat , cred , dummy_ccache ) ;
if ( maj_stat ! = 0 ) {
2024-02-27 18:07:22 +03:00
krb5_cc_destroy ( context , dummy_ccache ) ;
2016-12-22 15:50:05 +03:00
return maj_stat ;
}
code = krb5_cc_start_seq_get ( context , dummy_ccache , & cursor ) ;
if ( code ! = 0 ) {
2024-02-27 18:07:22 +03:00
krb5_cc_destroy ( context , dummy_ccache ) ;
2016-12-22 15:50:05 +03:00
* min_stat = EINVAL ;
return GSS_S_FAILURE ;
}
code = krb5_cc_next_cred ( context ,
dummy_ccache ,
& cursor ,
& creds ) ;
if ( code ! = 0 ) {
2024-02-27 18:07:22 +03:00
krb5_cc_destroy ( context , dummy_ccache ) ;
2016-12-22 15:50:05 +03:00
* min_stat = EINVAL ;
return GSS_S_FAILURE ;
}
do {
if ( creds . ticket_flags & TKT_FLG_PRE_AUTH ) {
krb5_data * tgs ;
tgs = krb5_princ_component ( context ,
creds . server ,
0 ) ;
if ( tgs ! = NULL & & tgs - > length > = 1 ) {
int cmp ;
cmp = memcmp ( tgs - > data ,
KRB5_TGS_NAME ,
tgs - > length ) ;
if ( cmp = = 0 & & creds . client ! = NULL ) {
princ = creds . client ;
code = KRB5_CC_END ;
break ;
}
}
}
krb5_free_cred_contents ( context , & creds ) ;
code = krb5_cc_next_cred ( context ,
dummy_ccache ,
& cursor ,
& creds ) ;
} while ( code = = 0 ) ;
if ( code = = KRB5_CC_END ) {
krb5_cc_end_seq_get ( context , dummy_ccache , & cursor ) ;
code = 0 ;
}
2024-02-27 18:07:22 +03:00
krb5_cc_destroy ( context , dummy_ccache ) ;
2016-12-22 15:50:05 +03:00
if ( code ! = 0 | | princ = = NULL ) {
krb5_free_cred_contents ( context , & creds ) ;
* min_stat = EINVAL ;
return GSS_S_FAILURE ;
}
/*
* Set the default principal for the cache we copy
* into . This is needed to be able that other calls
* can read it with e . g . gss_acquire_cred ( ) or
* krb5_cc_get_principal ( ) .
*/
code = krb5_cc_initialize ( context , ccc - > ccache , princ ) ;
if ( code ! = 0 ) {
krb5_free_cred_contents ( context , & creds ) ;
* min_stat = EINVAL ;
return GSS_S_FAILURE ;
}
krb5_free_cred_contents ( context , & creds ) ;
# endif /* SAMBA4_USES_HEIMDAL */
return gss_krb5_copy_ccache ( min_stat ,
cred ,
ccc - > ccache ) ;
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_krb5_context ( struct cli_credentials * cred ,
2007-12-02 22:56:26 +03:00
struct loadparm_context * lp_ctx ,
2023-02-03 20:52:04 +03:00
struct smb_krb5_context * * smb_krb5_context )
2005-10-20 07:47:55 +04:00
{
int ret ;
if ( cred - > smb_krb5_context ) {
* smb_krb5_context = cred - > smb_krb5_context ;
return 0 ;
}
2014-04-17 14:35:33 +04:00
ret = smb_krb5_init_context ( cred , lp_ctx ,
2010-02-20 03:44:41 +03:00
& cred - > smb_krb5_context ) ;
2005-10-20 07:47:55 +04:00
if ( ret ) {
2007-12-06 23:39:56 +03:00
cred - > smb_krb5_context = NULL ;
2005-10-20 07:47:55 +04:00
return ret ;
}
* smb_krb5_context = cred - > smb_krb5_context ;
return 0 ;
}
2005-09-29 04:02:38 +04:00
2010-10-27 08:22:46 +04:00
/* For most predictable behaviour, this needs to be called directly after the cli_credentials_init(),
* otherwise we may still have references to the old smb_krb5_context in a credential cache etc
2006-01-24 08:31:08 +03:00
*/
2023-02-03 20:52:04 +03:00
_PUBLIC_ NTSTATUS cli_credentials_set_krb5_context ( struct cli_credentials * cred ,
2006-01-24 08:31:08 +03:00
struct smb_krb5_context * smb_krb5_context )
{
2010-10-27 08:22:46 +04:00
if ( smb_krb5_context = = NULL ) {
talloc_unlink ( cred , cred - > smb_krb5_context ) ;
cred - > smb_krb5_context = NULL ;
return NT_STATUS_OK ;
}
2006-01-24 08:31:08 +03:00
if ( ! talloc_reference ( cred , smb_krb5_context ) ) {
return NT_STATUS_NO_MEMORY ;
}
cred - > smb_krb5_context = smb_krb5_context ;
return NT_STATUS_OK ;
}
2023-02-03 20:52:04 +03:00
static int cli_credentials_set_from_ccache ( struct cli_credentials * cred ,
2010-02-25 08:16:33 +03:00
struct ccache_container * ccache ,
enum credentials_obtained obtained ,
const char * * error_string )
2005-09-29 04:02:38 +04:00
{
2016-12-22 00:17:22 +03:00
bool ok ;
char * realm ;
2005-09-29 04:02:38 +04:00
krb5_principal princ ;
krb5_error_code ret ;
char * name ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( cred - > ccache_obtained > obtained ) {
return 0 ;
}
2023-02-03 20:52:04 +03:00
ret = krb5_cc_get_principal ( ccache - > smb_krb5_context - > krb5_context ,
2007-05-25 09:19:02 +04:00
ccache - > ccache , & princ ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " failed to get principal from ccache: %s \n " ,
smb_get_krb5_error_message ( ccache - > smb_krb5_context - > krb5_context ,
ret , cred ) ) ;
2005-09-29 04:02:38 +04:00
return ret ;
}
2023-02-03 20:52:04 +03:00
2007-05-25 09:19:02 +04:00
ret = krb5_unparse_name ( ccache - > smb_krb5_context - > krb5_context , princ , & name ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " failed to unparse principal from ccache: %s \n " ,
smb_get_krb5_error_message ( ccache - > smb_krb5_context - > krb5_context ,
ret , cred ) ) ;
2023-07-26 17:28:36 +03:00
krb5_free_principal ( ccache - > smb_krb5_context - > krb5_context , princ ) ;
2005-09-29 04:02:38 +04:00
return ret ;
}
2016-12-22 00:17:22 +03:00
ok = cli_credentials_set_principal ( cred , name , obtained ) ;
2017-01-17 16:39:02 +03:00
krb5_free_unparsed_name ( ccache - > smb_krb5_context - > krb5_context , name ) ;
2016-12-22 00:17:22 +03:00
if ( ! ok ) {
krb5_free_principal ( ccache - > smb_krb5_context - > krb5_context , princ ) ;
return ENOMEM ;
}
2005-09-29 04:02:38 +04:00
2018-11-20 19:45:11 +03:00
realm = smb_krb5_principal_get_realm (
cred , ccache - > smb_krb5_context - > krb5_context , princ ) ;
2007-05-25 09:19:02 +04:00
krb5_free_principal ( ccache - > smb_krb5_context - > krb5_context , princ ) ;
2016-12-22 00:17:22 +03:00
if ( realm = = NULL ) {
return ENOMEM ;
}
ok = cli_credentials_set_realm ( cred , realm , obtained ) ;
2018-11-20 19:45:11 +03:00
TALLOC_FREE ( realm ) ;
2016-12-22 00:17:22 +03:00
if ( ! ok ) {
return ENOMEM ;
}
2005-09-29 04:02:38 +04:00
2007-05-22 09:21:59 +04:00
/* set the ccache_obtained here, as it just got set to UNINITIALISED by the calls above */
2005-09-29 04:02:38 +04:00
cred - > ccache_obtained = obtained ;
return 0 ;
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_set_ccache ( struct cli_credentials * cred ,
2010-02-25 08:16:33 +03:00
struct loadparm_context * lp_ctx ,
const char * name ,
enum credentials_obtained obtained ,
const char * * error_string )
2005-09-29 04:02:38 +04:00
{
krb5_error_code ret ;
krb5_principal princ ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
struct ccache_container * ccc ;
if ( cred - > ccache_obtained > obtained ) {
return 0 ;
}
ccc = talloc ( cred , struct ccache_container ) ;
2005-09-29 04:02:38 +04:00
if ( ! ccc ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = error_message ( ENOMEM ) ;
2005-09-29 04:02:38 +04:00
return ENOMEM ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_krb5_context ( cred , lp_ctx ,
2007-12-04 01:33:16 +03:00
& ccc - > smb_krb5_context ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = error_message ( ret ) ;
2005-09-29 04:02:38 +04:00
talloc_free ( ccc ) ;
return ret ;
}
2007-04-28 20:38:06 +04:00
if ( ! talloc_reference ( ccc , ccc - > smb_krb5_context ) ) {
talloc_free ( ccc ) ;
2010-02-25 08:16:33 +03:00
( * error_string ) = error_message ( ENOMEM ) ;
2007-04-28 20:38:06 +04:00
return ENOMEM ;
}
2005-10-20 07:47:55 +04:00
2005-09-29 04:02:38 +04:00
if ( name ) {
ret = krb5_cc_resolve ( ccc - > smb_krb5_context - > krb5_context , name , & ccc - > ccache ) ;
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " failed to read krb5 ccache: %s: %s \n " ,
name ,
smb_get_krb5_error_message ( ccc - > smb_krb5_context - > krb5_context ,
ret , ccc ) ) ;
2005-09-29 04:02:38 +04:00
talloc_free ( ccc ) ;
return ret ;
}
} else {
2024-05-11 03:38:21 +03:00
/*
* This is where the caller really wants to use
* the default krb5 ccache .
*/
ret = smb_force_krb5_cc_default ( ccc - > smb_krb5_context - > krb5_context , & ccc - > ccache ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " failed to read default krb5 ccache: %s \n " ,
smb_get_krb5_error_message ( ccc - > smb_krb5_context - > krb5_context ,
ret , ccc ) ) ;
2005-09-29 04:02:38 +04:00
talloc_free ( ccc ) ;
return ret ;
}
}
talloc_set_destructor ( ccc , free_dccache ) ;
ret = krb5_cc_get_principal ( ccc - > smb_krb5_context - > krb5_context , ccc - > ccache , & princ ) ;
2010-05-12 06:34:15 +04:00
if ( ret = = 0 ) {
krb5_free_principal ( ccc - > smb_krb5_context - > krb5_context , princ ) ;
ret = cli_credentials_set_from_ccache ( cred , ccc , obtained , error_string ) ;
2005-09-29 04:02:38 +04:00
2010-05-12 06:34:15 +04:00
if ( ret ) {
( * error_string ) = error_message ( ret ) ;
2018-11-21 17:24:24 +03:00
TALLOC_FREE ( ccc ) ;
2010-05-12 06:34:15 +04:00
return ret ;
}
2018-11-21 17:28:42 +03:00
}
2005-09-29 04:02:38 +04:00
2018-11-21 17:28:42 +03:00
cred - > ccache = ccc ;
cred - > ccache_obtained = obtained ;
cli_credentials_invalidate_client_gss_creds (
cred , cred - > ccache_obtained ) ;
2005-09-29 04:02:38 +04:00
return 0 ;
}
2019-03-27 19:12:09 +03:00
# ifndef SAMBA4_USES_HEIMDAL
/*
* This function is a workaround for old MIT Kerberos versions which did not
* implement the krb5_cc_remove_cred function . It creates a temporary
* credentials cache to copy the credentials in the current cache
* except the one we want to remove and then overwrites the contents of the
* current cache with the temporary copy .
*/
static krb5_error_code krb5_cc_remove_cred_wrap ( struct ccache_container * ccc ,
krb5_creds * creds )
{
krb5_ccache dummy_ccache = NULL ;
krb5_creds cached_creds = { 0 } ;
krb5_cc_cursor cursor = NULL ;
krb5_error_code code ;
2024-02-27 17:49:09 +03:00
code = smb_krb5_cc_new_unique_memory ( ccc - > smb_krb5_context - > krb5_context ,
NULL , NULL ,
& dummy_ccache ) ;
2019-03-27 19:12:09 +03:00
if ( code ! = 0 ) {
DBG_ERR ( " krb5_cc_resolve failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
code = krb5_cc_start_seq_get ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ,
& cursor ) ;
if ( code ! = 0 ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
DBG_ERR ( " krb5_cc_start_seq_get failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
while ( ( code = krb5_cc_next_cred ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ,
& cursor ,
& cached_creds ) ) = = 0 ) {
/* If the principal matches skip it and do not copy to the
* temporary cache as this is the one we want to remove */
if ( krb5_principal_compare_flags (
ccc - > smb_krb5_context - > krb5_context ,
creds - > server ,
cached_creds . server ,
0 ) ) {
continue ;
}
code = krb5_cc_store_cred (
ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ,
& cached_creds ) ;
if ( code ! = 0 ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
DBG_ERR ( " krb5_cc_store_cred failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
}
if ( code = = KRB5_CC_END ) {
krb5_cc_end_seq_get ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ,
& cursor ) ;
code = 0 ;
}
if ( code ! = 0 ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
DBG_ERR ( " krb5_cc_next_cred failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
code = krb5_cc_initialize ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ,
creds - > client ) ;
if ( code ! = 0 ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
DBG_ERR ( " krb5_cc_initialize failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
code = krb5_cc_copy_creds ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ,
ccc - > ccache ) ;
if ( code ! = 0 ) {
krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
DBG_ERR ( " krb5_cc_copy_creds failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
code = krb5_cc_destroy ( ccc - > smb_krb5_context - > krb5_context ,
dummy_ccache ) ;
if ( code ! = 0 ) {
DBG_ERR ( " krb5_cc_destroy failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
code , ccc ) ) ;
return code ;
}
return code ;
}
# endif
2012-10-31 10:58:20 +04:00
/*
2023-09-05 07:02:59 +03:00
* Indicate that we failed to log in to this service / host with these
2012-10-31 10:58:20 +04:00
* credentials . The caller passes an unsigned int which they
* initialise to the number of times they would like to retry .
*
* This method is used to support re - trying with freshly fetched
* credentials in case a server is rebuilt while clients have
* non - expired tickets . When the client code gets a logon failure they
* throw away the existing credentials for the server and retry .
*/
_PUBLIC_ bool cli_credentials_failed_kerberos_login ( struct cli_credentials * cred ,
const char * principal ,
unsigned int * count )
{
struct ccache_container * ccc ;
krb5_creds creds , creds2 ;
int ret ;
if ( principal = = NULL ) {
/* no way to delete if we don't know the principal */
return false ;
}
ccc = cred - > ccache ;
if ( ccc = = NULL ) {
/* not a kerberos connection */
return false ;
}
if ( * count > 0 ) {
/* We have already tried discarding the credentials */
return false ;
}
( * count ) + + ;
ZERO_STRUCT ( creds ) ;
ret = krb5_parse_name ( ccc - > smb_krb5_context - > krb5_context , principal , & creds . server ) ;
if ( ret ! = 0 ) {
return false ;
}
2019-03-27 19:07:05 +03:00
/* MIT kerberos requires creds.client to match against cached
* credentials */
ret = krb5_cc_get_principal ( ccc - > smb_krb5_context - > krb5_context ,
ccc - > ccache ,
& creds . client ) ;
if ( ret ! = 0 ) {
krb5_free_cred_contents ( ccc - > smb_krb5_context - > krb5_context ,
& creds ) ;
DBG_ERR ( " krb5_cc_get_principal failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
ret , ccc ) ) ;
return false ;
}
2012-10-31 10:58:20 +04:00
ret = krb5_cc_retrieve_cred ( ccc - > smb_krb5_context - > krb5_context , ccc - > ccache , KRB5_TC_MATCH_SRV_NAMEONLY , & creds , & creds2 ) ;
if ( ret ! = 0 ) {
/* don't retry - we didn't find these credentials to remove */
2014-11-28 19:24:09 +03:00
krb5_free_cred_contents ( ccc - > smb_krb5_context - > krb5_context , & creds ) ;
2012-10-31 10:58:20 +04:00
return false ;
}
ret = krb5_cc_remove_cred ( ccc - > smb_krb5_context - > krb5_context , ccc - > ccache , KRB5_TC_MATCH_SRV_NAMEONLY , & creds ) ;
2019-03-27 19:12:09 +03:00
# ifndef SAMBA4_USES_HEIMDAL
if ( ret = = KRB5_CC_NOSUPP ) {
/* Old MIT kerberos versions did not implement
* krb5_cc_remove_cred */
ret = krb5_cc_remove_cred_wrap ( ccc , & creds ) ;
}
# endif
2014-11-28 19:24:09 +03:00
krb5_free_cred_contents ( ccc - > smb_krb5_context - > krb5_context , & creds ) ;
2012-10-31 10:58:20 +04:00
krb5_free_cred_contents ( ccc - > smb_krb5_context - > krb5_context , & creds2 ) ;
if ( ret ! = 0 ) {
/* don't retry - we didn't find these credentials to
* remove . Note that with the current backend this
* never happens , as it always returns 0 even if the
* creds don ' t exist , which is why we do a separate
* krb5_cc_retrieve_cred ( ) above .
*/
2019-03-27 19:12:09 +03:00
DBG_ERR ( " krb5_cc_remove_cred failed: %s \n " ,
smb_get_krb5_error_message (
ccc - > smb_krb5_context - > krb5_context ,
ret , ccc ) ) ;
2012-10-31 10:58:20 +04:00
return false ;
}
return true ;
}
2005-09-29 04:02:38 +04:00
2023-02-03 20:52:04 +03:00
static int cli_credentials_new_ccache ( struct cli_credentials * cred ,
2007-12-14 00:46:17 +03:00
struct loadparm_context * lp_ctx ,
2024-02-27 18:38:42 +03:00
char * given_ccache_name ,
2010-02-25 08:16:33 +03:00
struct ccache_container * * _ccc ,
const char * * error_string )
2005-09-29 04:02:38 +04:00
{
2024-02-27 18:38:42 +03:00
char * ccache_name = given_ccache_name ;
2010-02-20 03:44:41 +03:00
bool must_free_cc_name = false ;
2005-09-29 04:02:38 +04:00
krb5_error_code ret ;
struct ccache_container * ccc = talloc ( cred , struct ccache_container ) ;
if ( ! ccc ) {
return ENOMEM ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_krb5_context ( cred , lp_ctx ,
2007-12-04 01:33:16 +03:00
& ccc - > smb_krb5_context ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
talloc_free ( ccc ) ;
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " Failed to get krb5_context: %s " ,
error_message ( ret ) ) ;
2005-09-29 04:02:38 +04:00
return ret ;
}
2007-04-28 20:38:06 +04:00
if ( ! talloc_reference ( ccc , ccc - > smb_krb5_context ) ) {
talloc_free ( ccc ) ;
2010-02-25 08:16:33 +03:00
( * error_string ) = strerror ( ENOMEM ) ;
2007-04-28 20:38:06 +04:00
return ENOMEM ;
}
2005-09-29 04:02:38 +04:00
2010-02-20 03:44:41 +03:00
if ( ! ccache_name ) {
2011-06-08 02:51:56 +04:00
if ( lpcfg_parm_bool ( lp_ctx , NULL , " credentials " , " krb5_cc_file " , false ) ) {
2023-02-03 20:52:04 +03:00
ccache_name = talloc_asprintf ( ccc , " FILE:/tmp/krb5_cc_samba_%u_%p " ,
2011-06-08 02:51:56 +04:00
( unsigned int ) getpid ( ) , ccc ) ;
2024-02-27 18:38:42 +03:00
if ( ccache_name = = NULL ) {
talloc_free ( ccc ) ;
( * error_string ) = strerror ( ENOMEM ) ;
return ENOMEM ;
}
must_free_cc_name = true ;
2010-02-20 03:44:41 +03:00
}
}
2024-02-27 18:38:42 +03:00
if ( ccache_name ! = NULL ) {
ret = krb5_cc_resolve ( ccc - > smb_krb5_context - > krb5_context , ccache_name ,
& ccc - > ccache ) ;
} else {
ret = smb_krb5_cc_new_unique_memory ( ccc - > smb_krb5_context - > krb5_context ,
ccc , & ccache_name ,
& ccc - > ccache ) ;
must_free_cc_name = true ;
}
2005-09-29 04:02:38 +04:00
if ( ret ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = talloc_asprintf ( cred , " failed to resolve a krb5 ccache (%s): %s \n " ,
ccache_name ,
smb_get_krb5_error_message ( ccc - > smb_krb5_context - > krb5_context ,
ret , ccc ) ) ;
2005-09-29 04:02:38 +04:00
talloc_free ( ccc ) ;
return ret ;
}
2010-02-20 03:44:41 +03:00
if ( strncasecmp ( ccache_name , " MEMORY: " , 7 ) = = 0 ) {
talloc_set_destructor ( ccc , free_mccache ) ;
} else {
talloc_set_destructor ( ccc , free_dccache ) ;
}
2005-09-29 04:02:38 +04:00
2010-02-20 03:44:41 +03:00
if ( must_free_cc_name ) {
talloc_free ( ccache_name ) ;
}
2005-09-29 04:02:38 +04:00
2007-05-25 09:19:02 +04:00
* _ccc = ccc ;
2005-11-02 03:31:22 +03:00
2010-02-25 08:16:33 +03:00
return 0 ;
2005-09-29 04:02:38 +04:00
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_named_ccache ( struct cli_credentials * cred ,
2010-02-20 03:44:41 +03:00
struct tevent_context * event_ctx ,
struct loadparm_context * lp_ctx ,
char * ccache_name ,
2010-02-25 08:16:33 +03:00
struct ccache_container * * ccc ,
const char * * error_string )
2005-09-29 04:02:38 +04:00
{
krb5_error_code ret ;
2010-05-01 04:33:08 +04:00
enum credentials_obtained obtained ;
2023-02-03 20:52:04 +03:00
2007-04-12 14:25:01 +04:00
if ( cred - > machine_account_pending ) {
2007-12-14 00:46:17 +03:00
cli_credentials_set_machine_account ( cred , lp_ctx ) ;
2007-04-12 14:25:01 +04:00
}
2023-02-03 20:52:04 +03:00
if ( cred - > ccache_obtained > = cred - > ccache_threshold & &
2007-08-09 10:26:19 +04:00
cred - > ccache_obtained > CRED_UNINITIALISED ) {
2011-06-08 02:53:16 +04:00
time_t lifetime ;
bool expired = false ;
2012-04-27 22:29:47 +04:00
ret = smb_krb5_cc_get_lifetime ( cred - > ccache - > smb_krb5_context - > krb5_context ,
cred - > ccache - > ccache , & lifetime ) ;
2020-04-03 16:27:45 +03:00
if ( ret = = KRB5_CC_END | | ret = = ENOENT ) {
2011-06-08 02:53:16 +04:00
/* If we have a particular ccache set, without
* an initial ticket , then assume there is a
* good reason */
} else if ( ret = = 0 ) {
if ( lifetime = = 0 ) {
DEBUG ( 3 , ( " Ticket in credentials cache for %s expired, will refresh \n " ,
cli_credentials_get_principal ( cred , cred ) ) ) ;
expired = true ;
} else if ( lifetime < 300 ) {
2023-02-03 20:52:04 +03:00
DEBUG ( 3 , ( " Ticket in credentials cache for %s will shortly expire (%u secs), will refresh \n " ,
2011-06-08 02:53:16 +04:00
cli_credentials_get_principal ( cred , cred ) , ( unsigned int ) lifetime ) ) ;
expired = true ;
}
} else {
( * error_string ) = talloc_asprintf ( cred , " failed to get ccache lifetime: %s \n " ,
smb_get_krb5_error_message ( cred - > ccache - > smb_krb5_context - > krb5_context ,
ret , cred ) ) ;
return ret ;
}
2023-02-03 20:52:04 +03:00
DEBUG ( 5 , ( " Ticket in credentials cache for %s will expire in %u secs \n " ,
2011-06-08 02:53:16 +04:00
cli_credentials_get_principal ( cred , cred ) , ( unsigned int ) lifetime ) ) ;
2023-02-03 20:52:04 +03:00
2011-06-08 02:53:16 +04:00
if ( ! expired ) {
* ccc = cred - > ccache ;
return 0 ;
}
2005-09-29 04:02:38 +04:00
}
if ( cli_credentials_is_anonymous ( cred ) ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = " Cannot get anonymous kerberos credentials " ;
2005-09-29 04:02:38 +04:00
return EINVAL ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_new_ccache ( cred , lp_ctx , ccache_name , ccc , error_string ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
return ret ;
}
2007-05-25 09:19:02 +04:00
2023-11-20 04:12:19 +03:00
ret = kinit_to_ccache ( cred ,
cred ,
( * ccc ) - > smb_krb5_context ,
lp_ctx ,
event_ctx ,
( * ccc ) - > ccache ,
& obtained ,
error_string ) ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
return ret ;
}
2023-02-03 20:52:04 +03:00
ret = cli_credentials_set_from_ccache ( cred , * ccc ,
2010-05-01 04:33:08 +04:00
obtained , error_string ) ;
2023-02-03 20:52:04 +03:00
2007-05-25 09:19:02 +04:00
cred - > ccache = * ccc ;
cred - > ccache_obtained = cred - > principal_obtained ;
2005-09-29 04:02:38 +04:00
if ( ret ) {
return ret ;
}
2007-05-25 09:19:02 +04:00
cli_credentials_invalidate_client_gss_creds ( cred , cred - > ccache_obtained ) ;
2010-02-25 08:16:33 +03:00
return 0 ;
2005-09-29 04:02:38 +04:00
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_ccache ( struct cli_credentials * cred ,
2010-02-20 03:44:41 +03:00
struct tevent_context * event_ctx ,
struct loadparm_context * lp_ctx ,
2010-02-25 08:16:33 +03:00
struct ccache_container * * ccc ,
const char * * error_string )
2010-02-20 03:44:41 +03:00
{
2010-02-25 08:16:33 +03:00
return cli_credentials_get_named_ccache ( cred , event_ctx , lp_ctx , NULL , ccc , error_string ) ;
2010-02-20 03:44:41 +03:00
}
2022-04-14 14:29:47 +03:00
/**
* @ brief Check if a valid Kerberos credential cache is attached .
*
* This will not ask for a password nor do a kinit .
*
* @ param cred The credentials context .
*
* @ param mem_ctx A memory context to allocate the ccache_name .
*
* @ param ccache_name A pointer to a string to store the ccache name .
*
* @ param obtained A pointer to store the information how the ccache was
* obtained .
*
* @ return True if a credential cache is attached , false if not or an error
* occurred .
*/
_PUBLIC_ bool cli_credentials_get_ccache_name_obtained (
struct cli_credentials * cred ,
TALLOC_CTX * mem_ctx ,
char * * ccache_name ,
enum credentials_obtained * obtained )
{
if ( ccache_name ! = NULL ) {
* ccache_name = NULL ;
}
if ( obtained ! = NULL ) {
* obtained = CRED_UNINITIALISED ;
}
if ( cred - > machine_account_pending ) {
return false ;
}
if ( cred - > ccache_obtained = = CRED_UNINITIALISED ) {
return false ;
}
if ( cred - > ccache_obtained > = cred - > ccache_threshold ) {
krb5_context k5ctx = cred - > ccache - > smb_krb5_context - > krb5_context ;
krb5_ccache k5ccache = cred - > ccache - > ccache ;
krb5_error_code ret ;
time_t lifetime = 0 ;
ret = smb_krb5_cc_get_lifetime ( k5ctx , k5ccache , & lifetime ) ;
if ( ret = = KRB5_CC_END | | ret = = ENOENT ) {
return false ;
}
if ( ret ! = 0 ) {
return false ;
}
if ( lifetime = = 0 ) {
return false ;
} else if ( lifetime < 300 ) {
if ( cred - > password_obtained > = cred - > ccache_obtained ) {
/*
* we have a password to re - kinit
* so let the caller try that .
*/
return false ;
}
}
if ( ccache_name ! = NULL ) {
char * name = NULL ;
ret = krb5_cc_get_full_name ( k5ctx , k5ccache , & name ) ;
if ( ret ! = 0 ) {
return false ;
}
* ccache_name = talloc_strdup ( mem_ctx , name ) ;
SAFE_FREE ( name ) ;
if ( * ccache_name = = NULL ) {
return false ;
}
}
if ( obtained ! = NULL ) {
* obtained = cred - > ccache_obtained ;
}
return true ;
}
return false ;
}
2010-05-01 04:33:08 +04:00
/* We have good reason to think the ccache in these credentials is invalid - blow it away */
static void cli_credentials_unconditionally_invalidate_client_gss_creds ( struct cli_credentials * cred )
{
if ( cred - > client_gss_creds_obtained > CRED_UNINITIALISED ) {
talloc_unlink ( cred , cred - > client_gss_creds ) ;
cred - > client_gss_creds = NULL ;
}
cred - > client_gss_creds_obtained = CRED_UNINITIALISED ;
}
2023-02-03 20:52:04 +03:00
void cli_credentials_invalidate_client_gss_creds ( struct cli_credentials * cred ,
2007-05-22 09:21:59 +04:00
enum credentials_obtained obtained )
{
/* If the caller just changed the username/password etc, then
* any cached credentials are now invalid */
if ( obtained > = cred - > client_gss_creds_obtained ) {
if ( cred - > client_gss_creds_obtained > CRED_UNINITIALISED ) {
2007-08-09 10:26:19 +04:00
talloc_unlink ( cred , cred - > client_gss_creds ) ;
2007-05-25 09:19:02 +04:00
cred - > client_gss_creds = NULL ;
2007-05-22 09:21:59 +04:00
}
cred - > client_gss_creds_obtained = CRED_UNINITIALISED ;
}
/* Now that we know that the data is 'this specified', then
* don ' t allow something less ' known ' to be returned as a
2011-06-17 13:53:11 +04:00
* ccache . Ie , if the username is on the command line , we
2007-05-22 09:21:59 +04:00
* don ' t want to later guess to use a file - based ccache */
if ( obtained > cred - > client_gss_creds_threshold ) {
cred - > client_gss_creds_threshold = obtained ;
}
}
2010-05-01 04:33:08 +04:00
/* We have good reason to think this CCACHE is invalid. Blow it away */
static void cli_credentials_unconditionally_invalidate_ccache ( struct cli_credentials * cred )
{
if ( cred - > ccache_obtained > CRED_UNINITIALISED ) {
talloc_unlink ( cred , cred - > ccache ) ;
cred - > ccache = NULL ;
}
cred - > ccache_obtained = CRED_UNINITIALISED ;
cli_credentials_unconditionally_invalidate_client_gss_creds ( cred ) ;
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ void cli_credentials_invalidate_ccache ( struct cli_credentials * cred ,
2007-05-22 09:21:59 +04:00
enum credentials_obtained obtained )
{
/* If the caller just changed the username/password etc, then
* any cached credentials are now invalid */
if ( obtained > = cred - > ccache_obtained ) {
if ( cred - > ccache_obtained > CRED_UNINITIALISED ) {
2007-08-09 10:26:19 +04:00
talloc_unlink ( cred , cred - > ccache ) ;
2007-05-25 09:19:02 +04:00
cred - > ccache = NULL ;
2007-05-22 09:21:59 +04:00
}
cred - > ccache_obtained = CRED_UNINITIALISED ;
}
/* Now that we know that the data is 'this specified', then
* don ' t allow something less ' known ' to be returned as a
2011-06-17 13:53:11 +04:00
* ccache . i . e , if the username is on the command line , we
2007-05-22 09:21:59 +04:00
* don ' t want to later guess to use a file - based ccache */
if ( obtained > cred - > ccache_threshold ) {
cred - > ccache_threshold = obtained ;
}
2023-02-03 20:52:04 +03:00
cli_credentials_invalidate_client_gss_creds ( cred ,
2007-05-22 09:21:59 +04:00
obtained ) ;
}
2006-05-24 11:32:17 +04:00
static int free_gssapi_creds ( struct gssapi_creds_container * gcc )
{
2011-11-22 01:06:00 +04:00
OM_uint32 min_stat ;
( void ) gss_release_cred ( & min_stat , & gcc - > creds ) ;
2005-11-02 03:31:22 +03:00
return 0 ;
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_client_gss_creds ( struct cli_credentials * cred ,
2010-02-25 08:16:33 +03:00
struct tevent_context * event_ctx ,
struct loadparm_context * lp_ctx ,
struct gssapi_creds_container * * _gcc ,
const char * * error_string )
2005-11-02 03:31:22 +03:00
{
int ret = 0 ;
OM_uint32 maj_stat , min_stat ;
struct gssapi_creds_container * gcc ;
struct ccache_container * ccache ;
2015-06-22 16:17:33 +03:00
# ifdef HAVE_GSS_KRB5_CRED_NO_CI_FLAGS_X
2008-06-27 13:31:49 +04:00
gss_buffer_desc empty_buffer = GSS_C_EMPTY_BUFFER ;
2016-09-28 20:19:06 +03:00
gss_OID oid = discard_const ( GSS_KRB5_CRED_NO_CI_FLAGS_X ) ;
2014-05-08 12:12:01 +04:00
# endif
2008-07-25 18:00:50 +04:00
krb5_enctype * etypes = NULL ;
2008-06-27 13:31:49 +04:00
2023-02-03 20:52:04 +03:00
if ( cred - > client_gss_creds_obtained > = cred - > client_gss_creds_threshold & &
2007-08-09 10:26:19 +04:00
cred - > client_gss_creds_obtained > CRED_UNINITIALISED ) {
2011-06-08 02:53:16 +04:00
bool expired = false ;
OM_uint32 lifetime = 0 ;
gss_cred_usage_t usage = 0 ;
2023-02-03 20:52:04 +03:00
maj_stat = gss_inquire_cred ( & min_stat , cred - > client_gss_creds - > creds ,
2011-06-08 02:53:16 +04:00
NULL , & lifetime , & usage , NULL ) ;
if ( maj_stat = = GSS_S_CREDENTIALS_EXPIRED ) {
DEBUG ( 3 , ( " Credentials for %s expired, must refresh credentials cache \n " , cli_credentials_get_principal ( cred , cred ) ) ) ;
expired = true ;
} else if ( maj_stat = = GSS_S_COMPLETE & & lifetime < 300 ) {
DEBUG ( 3 , ( " Credentials for %s will expire shortly (%u sec), must refresh credentials cache \n " , cli_credentials_get_principal ( cred , cred ) , lifetime ) ) ;
expired = true ;
} else if ( maj_stat ! = GSS_S_COMPLETE ) {
2023-09-05 07:02:59 +03:00
* error_string = talloc_asprintf ( cred , " inquiry of credential lifetime via GSSAPI gss_inquire_cred failed: %s \n " ,
2011-06-08 02:53:16 +04:00
gssapi_error_string ( cred , maj_stat , min_stat , NULL ) ) ;
return EINVAL ;
}
if ( expired ) {
cli_credentials_unconditionally_invalidate_client_gss_creds ( cred ) ;
} else {
2023-02-03 20:52:04 +03:00
DEBUG ( 5 , ( " GSSAPI credentials for %s will expire in %u secs \n " ,
2011-06-08 02:53:16 +04:00
cli_credentials_get_principal ( cred , cred ) , ( unsigned int ) lifetime ) ) ;
2023-02-03 20:52:04 +03:00
2011-06-08 02:53:16 +04:00
* _gcc = cred - > client_gss_creds ;
return 0 ;
}
2005-11-02 03:31:22 +03:00
}
2008-06-27 13:31:49 +04:00
2012-05-24 16:17:40 +04:00
ret = cli_credentials_get_ccache ( cred , event_ctx , lp_ctx ,
& ccache , error_string ) ;
2005-11-02 03:31:22 +03:00
if ( ret ) {
2020-08-20 10:40:41 +03:00
if ( cli_credentials_get_kerberos_state ( cred ) = = CRED_USE_KERBEROS_REQUIRED ) {
2012-02-10 01:14:59 +04:00
DEBUG ( 1 , ( " Failed to get kerberos credentials (kerberos required): %s \n " , * error_string ) ) ;
2011-06-17 07:47:14 +04:00
} else {
2012-02-10 01:14:59 +04:00
DEBUG ( 4 , ( " Failed to get kerberos credentials: %s \n " , * error_string ) ) ;
2011-06-17 07:47:14 +04:00
}
2005-11-02 03:31:22 +03:00
return ret ;
}
gcc = talloc ( cred , struct gssapi_creds_container ) ;
if ( ! gcc ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = error_message ( ENOMEM ) ;
2005-11-02 03:31:22 +03:00
return ENOMEM ;
}
2017-03-03 17:57:13 +03:00
maj_stat = smb_gss_krb5_import_cred ( & min_stat , ccache - > smb_krb5_context - > krb5_context ,
ccache - > ccache , NULL , NULL ,
& gcc - > creds ) ;
2016-12-22 19:01:35 +03:00
if ( ( maj_stat = = GSS_S_FAILURE ) & &
( min_stat = = ( OM_uint32 ) KRB5_CC_END | |
min_stat = = ( OM_uint32 ) KRB5_CC_NOTFOUND | |
min_stat = = ( OM_uint32 ) KRB5_FCC_NOFILE ) )
{
2010-05-01 04:33:08 +04:00
/* This CCACHE is no good. Ensure we don't use it again */
cli_credentials_unconditionally_invalidate_ccache ( cred ) ;
/* Now try again to get a ccache */
ret = cli_credentials_get_ccache ( cred , event_ctx , lp_ctx ,
& ccache , error_string ) ;
if ( ret ) {
DEBUG ( 1 , ( " Failed to re-get CCACHE for GSSAPI client: %s \n " , error_message ( ret ) ) ) ;
return ret ;
}
2017-03-03 17:57:13 +03:00
maj_stat = smb_gss_krb5_import_cred ( & min_stat , ccache - > smb_krb5_context - > krb5_context ,
ccache - > ccache , NULL , NULL ,
& gcc - > creds ) ;
2010-05-01 04:33:08 +04:00
}
2005-11-02 03:31:22 +03:00
if ( maj_stat ) {
2008-06-11 09:59:20 +04:00
talloc_free ( gcc ) ;
2005-11-02 03:31:22 +03:00
if ( min_stat ) {
ret = min_stat ;
} else {
ret = EINVAL ;
}
2017-03-03 17:57:13 +03:00
( * error_string ) = talloc_asprintf ( cred , " smb_gss_krb5_import_cred failed: %s " , error_message ( ret ) ) ;
2008-06-11 09:59:20 +04:00
return ret ;
2005-11-02 03:31:22 +03:00
}
2008-06-11 09:59:20 +04:00
2014-04-29 20:22:55 +04:00
2008-07-28 11:29:42 +04:00
/*
* transfer the enctypes from the smb_krb5_context to the gssapi layer
*
* We use ' our ' smb_krb5_context to do the AS - REQ and it is possible
* to configure the enctypes via the krb5 . conf .
*
* And the gss_init_sec_context ( ) creates it ' s own krb5_context and
* the TGS - REQ had all enctypes in it and only the ones configured
* and used for the AS - REQ , so it wasn ' t possible to disable the usage
* of AES keys .
*/
2016-08-25 18:02:59 +03:00
min_stat = smb_krb5_get_allowed_etypes ( ccache - > smb_krb5_context - > krb5_context ,
2014-04-29 20:22:55 +04:00
& etypes ) ;
2008-07-25 18:00:50 +04:00
if ( min_stat = = 0 ) {
OM_uint32 num_ktypes ;
for ( num_ktypes = 0 ; etypes [ num_ktypes ] ; num_ktypes + + ) ;
maj_stat = gss_krb5_set_allowable_enctypes ( & min_stat , gcc - > creds ,
2010-08-27 00:30:04 +04:00
num_ktypes ,
( int32_t * ) etypes ) ;
2023-07-27 17:26:57 +03:00
krb5_free_enctypes ( ccache - > smb_krb5_context - > krb5_context ,
etypes ) ;
2008-07-25 18:00:50 +04:00
if ( maj_stat ) {
talloc_free ( gcc ) ;
if ( min_stat ) {
ret = min_stat ;
} else {
ret = EINVAL ;
}
2010-04-27 07:57:39 +04:00
( * error_string ) = talloc_asprintf ( cred , " gss_krb5_set_allowable_enctypes failed: %s " , error_message ( ret ) ) ;
2008-07-25 18:00:50 +04:00
return ret ;
}
}
2014-04-29 20:22:55 +04:00
2015-06-22 16:17:33 +03:00
# ifdef HAVE_GSS_KRB5_CRED_NO_CI_FLAGS_X
2015-06-23 18:39:27 +03:00
/*
* Don ' t force GSS_C_CONF_FLAG and GSS_C_INTEG_FLAG .
*
* This allows us to disable SIGN and SEAL on a TLS connection with
* GSS - SPNENO . For example ldaps : // connections.
*
* https : //groups.yahoo.com/neo/groups/cat-ietf/conversations/topics/575
* http : //krbdev.mit.edu/rt/Ticket/Display.html?id=6938
*/
2008-06-27 01:32:37 +04:00
maj_stat = gss_set_cred_option ( & min_stat , & gcc - > creds ,
2016-09-28 20:19:06 +03:00
oid ,
2008-06-27 13:31:49 +04:00
& empty_buffer ) ;
2008-06-11 09:59:20 +04:00
if ( maj_stat ) {
talloc_free ( gcc ) ;
if ( min_stat ) {
ret = min_stat ;
} else {
ret = EINVAL ;
}
2010-04-27 07:57:39 +04:00
( * error_string ) = talloc_asprintf ( cred , " gss_set_cred_option failed: %s " , error_message ( ret ) ) ;
2008-06-11 09:59:20 +04:00
return ret ;
2005-11-02 03:31:22 +03:00
}
2012-05-02 20:53:34 +04:00
# endif
2008-06-11 09:59:20 +04:00
cred - > client_gss_creds_obtained = cred - > ccache_obtained ;
talloc_set_destructor ( gcc , free_gssapi_creds ) ;
cred - > client_gss_creds = gcc ;
* _gcc = gcc ;
return 0 ;
2005-11-02 03:31:22 +03:00
}
/**
2007-12-02 21:31:14 +03:00
Set a gssapi cred_id_t into the credentials system . ( Client case )
2005-11-02 03:31:22 +03:00
This grabs the credentials both ' intact ' and getting the krb5
ccache out of it . This routine can be generalised in future for
2023-02-03 20:52:04 +03:00
the case where we deal with GSSAPI mechs other than krb5 .
2005-11-02 03:31:22 +03:00
2023-03-14 10:50:34 +03:00
On success , the caller must not free gssapi_cred , as it now belongs
2005-11-02 03:31:22 +03:00
to the credentials system .
*/
2023-02-03 20:52:04 +03:00
int cli_credentials_set_client_gss_creds ( struct cli_credentials * cred ,
2008-03-17 07:22:52 +03:00
struct loadparm_context * lp_ctx ,
gss_cred_id_t gssapi_cred ,
2010-02-25 08:16:33 +03:00
enum credentials_obtained obtained ,
const char * * error_string )
2005-11-02 03:31:22 +03:00
{
int ret ;
OM_uint32 maj_stat , min_stat ;
2016-12-22 15:50:05 +03:00
struct ccache_container * ccc = NULL ;
struct gssapi_creds_container * gcc = NULL ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( cred - > client_gss_creds_obtained > obtained ) {
return 0 ;
}
gcc = talloc ( cred , struct gssapi_creds_container ) ;
2005-11-02 03:31:22 +03:00
if ( ! gcc ) {
2010-02-25 08:16:33 +03:00
( * error_string ) = error_message ( ENOMEM ) ;
2005-11-02 03:31:22 +03:00
return ENOMEM ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_new_ccache ( cred , lp_ctx , NULL , & ccc , error_string ) ;
2005-11-02 03:31:22 +03:00
if ( ret ! = 0 ) {
return ret ;
}
2016-12-22 15:50:05 +03:00
maj_stat = smb_gss_krb5_copy_ccache ( & min_stat ,
gssapi_cred ,
ccc ) ;
2005-11-02 03:31:22 +03:00
if ( maj_stat ) {
if ( min_stat ) {
ret = min_stat ;
} else {
ret = EINVAL ;
}
2010-02-25 08:16:33 +03:00
if ( ret ) {
( * error_string ) = error_message ( ENOMEM ) ;
}
2005-11-02 03:31:22 +03:00
}
if ( ret = = 0 ) {
2010-02-25 08:16:33 +03:00
ret = cli_credentials_set_from_ccache ( cred , ccc , obtained , error_string ) ;
2005-11-02 03:31:22 +03:00
}
2007-05-25 09:19:02 +04:00
cred - > ccache = ccc ;
cred - > ccache_obtained = obtained ;
2005-11-02 03:31:22 +03:00
if ( ret = = 0 ) {
gcc - > creds = gssapi_cred ;
talloc_set_destructor ( gcc , free_gssapi_creds ) ;
2023-02-03 20:52:04 +03:00
2023-09-05 07:02:59 +03:00
/* set the client_gss_creds_obtained here, as it just
2007-05-22 09:21:59 +04:00
got set to UNINITIALISED by the calls above */
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
cred - > client_gss_creds_obtained = obtained ;
cred - > client_gss_creds = gcc ;
2005-11-02 03:31:22 +03:00
}
return ret ;
}
2016-07-21 16:08:32 +03:00
static int cli_credentials_shallow_ccache ( struct cli_credentials * cred )
{
krb5_error_code ret ;
const struct ccache_container * old_ccc = NULL ;
2020-04-03 16:29:32 +03:00
enum credentials_obtained old_obtained ;
2016-07-21 16:08:32 +03:00
struct ccache_container * ccc = NULL ;
2018-11-21 19:36:35 +03:00
krb5_principal princ ;
2016-07-21 16:08:32 +03:00
2020-04-03 16:29:32 +03:00
old_obtained = cred - > ccache_obtained ;
2016-07-21 16:08:32 +03:00
old_ccc = cred - > ccache ;
if ( old_ccc = = NULL ) {
return 0 ;
}
2020-04-03 16:29:32 +03:00
cred - > ccache = NULL ;
cred - > ccache_obtained = CRED_UNINITIALISED ;
cred - > client_gss_creds = NULL ;
cred - > client_gss_creds_obtained = CRED_UNINITIALISED ;
2018-11-21 19:36:35 +03:00
ret = krb5_cc_get_principal (
old_ccc - > smb_krb5_context - > krb5_context ,
old_ccc - > ccache ,
& princ ) ;
if ( ret ! = 0 ) {
/*
* This is an empty ccache . No point in copying anything .
*/
return 0 ;
}
krb5_free_principal ( old_ccc - > smb_krb5_context - > krb5_context , princ ) ;
2016-07-21 16:08:32 +03:00
ccc = talloc ( cred , struct ccache_container ) ;
if ( ccc = = NULL ) {
return ENOMEM ;
}
* ccc = * old_ccc ;
ccc - > ccache = NULL ;
2024-02-27 18:21:02 +03:00
ret = smb_krb5_cc_new_unique_memory ( ccc - > smb_krb5_context - > krb5_context ,
NULL ,
NULL ,
& ccc - > ccache ) ;
2016-07-21 16:08:32 +03:00
if ( ret ! = 0 ) {
TALLOC_FREE ( ccc ) ;
return ret ;
}
talloc_set_destructor ( ccc , free_mccache ) ;
2016-07-24 15:47:33 +03:00
ret = smb_krb5_cc_copy_creds ( ccc - > smb_krb5_context - > krb5_context ,
old_ccc - > ccache , ccc - > ccache ) ;
2016-07-21 16:08:32 +03:00
if ( ret ! = 0 ) {
TALLOC_FREE ( ccc ) ;
return ret ;
}
cred - > ccache = ccc ;
2020-04-03 16:29:32 +03:00
cred - > ccache_obtained = old_obtained ;
2016-07-21 16:08:32 +03:00
return ret ;
}
_PUBLIC_ struct cli_credentials * cli_credentials_shallow_copy ( TALLOC_CTX * mem_ctx ,
struct cli_credentials * src )
{
2023-11-17 07:41:53 +03:00
struct cli_credentials * dst , * armor_credentials ;
2016-07-21 16:08:32 +03:00
int ret ;
dst = talloc ( mem_ctx , struct cli_credentials ) ;
if ( dst = = NULL ) {
return NULL ;
}
* dst = * src ;
2023-11-17 07:41:53 +03:00
if ( dst - > krb5_fast_armor_credentials ! = NULL ) {
armor_credentials = talloc_reference ( dst , dst - > krb5_fast_armor_credentials ) ;
if ( armor_credentials = = NULL ) {
TALLOC_FREE ( dst ) ;
return NULL ;
}
}
2016-07-21 16:08:32 +03:00
ret = cli_credentials_shallow_ccache ( dst ) ;
if ( ret ! = 0 ) {
TALLOC_FREE ( dst ) ;
return NULL ;
}
return dst ;
}
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
/* Get the keytab (actually, a container containing the krb5_keytab)
* attached to this context . If this hasn ' t been done or set before ,
* it will be generated from the password .
*/
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_keytab ( struct cli_credentials * cred ,
2010-10-11 09:53:08 +04:00
struct loadparm_context * lp_ctx ,
struct keytab_container * * _ktc )
2005-10-20 07:47:55 +04:00
{
krb5_error_code ret ;
struct keytab_container * ktc ;
struct smb_krb5_context * smb_krb5_context ;
2012-03-31 11:23:19 +04:00
const char * keytab_name ;
krb5_keytab keytab ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
TALLOC_CTX * mem_ctx ;
2015-04-23 20:18:32 +03:00
const char * username = cli_credentials_get_username ( cred ) ;
const char * realm = cli_credentials_get_realm ( cred ) ;
2017-05-18 11:50:34 +03:00
char * salt_principal = NULL ;
2005-10-20 07:47:55 +04:00
2023-02-03 20:52:04 +03:00
if ( cred - > keytab_obtained > = ( MAX ( cred - > principal_obtained ,
2005-10-20 07:47:55 +04:00
cred - > username_obtained ) ) ) {
* _ktc = cred - > keytab ;
return 0 ;
}
if ( cli_credentials_is_anonymous ( cred ) ) {
return EINVAL ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_krb5_context ( cred , lp_ctx ,
2007-12-04 02:12:03 +03:00
& smb_krb5_context ) ;
2005-10-20 07:47:55 +04:00
if ( ret ) {
return ret ;
}
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
mem_ctx = talloc_new ( cred ) ;
if ( ! mem_ctx ) {
return ENOMEM ;
}
2023-12-21 02:00:46 +03:00
salt_principal = cli_credentials_get_salt_principal ( cred , mem_ctx ) ;
if ( salt_principal = = NULL ) {
2015-04-23 20:18:32 +03:00
talloc_free ( mem_ctx ) ;
2023-12-21 02:00:46 +03:00
return ENOMEM ;
2015-04-23 20:18:32 +03:00
}
2012-04-02 03:08:15 +04:00
ret = smb_krb5_create_memory_keytab ( mem_ctx ,
2015-04-23 20:18:32 +03:00
smb_krb5_context - > krb5_context ,
cli_credentials_get_password ( cred ) ,
username ,
realm ,
salt_principal ,
cli_credentials_get_kvno ( cred ) ,
& keytab ,
& keytab_name ) ;
2012-03-31 11:23:19 +04:00
if ( ret ) {
talloc_free ( mem_ctx ) ;
return ret ;
}
ret = smb_krb5_get_keytab_container ( mem_ctx , smb_krb5_context ,
keytab , keytab_name , & ktc ) ;
2005-10-20 07:47:55 +04:00
if ( ret ) {
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
talloc_free ( mem_ctx ) ;
2005-10-20 07:47:55 +04:00
return ret ;
}
2023-02-03 20:52:04 +03:00
cred - > keytab_obtained = ( MAX ( cred - > principal_obtained ,
2005-10-20 07:47:55 +04:00
cred - > username_obtained ) ) ;
2012-08-30 01:49:21 +04:00
/* We make this keytab up based on a password. Therefore
* match - by - key is acceptable , we can ' t match on the wrong
* principal */
ktc - > password_based = true ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
talloc_steal ( cred , ktc ) ;
2005-10-20 07:47:55 +04:00
cred - > keytab = ktc ;
* _ktc = cred - > keytab ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
talloc_free ( mem_ctx ) ;
return ret ;
}
/* Given the name of a keytab (presumably in the format
* FILE : / etc / krb5 . keytab ) , open it and attach it */
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_set_keytab_name ( struct cli_credentials * cred ,
2010-10-11 09:53:08 +04:00
struct loadparm_context * lp_ctx ,
const char * keytab_name ,
enum credentials_obtained obtained )
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
{
krb5_error_code ret ;
struct keytab_container * ktc ;
struct smb_krb5_context * smb_krb5_context ;
TALLOC_CTX * mem_ctx ;
if ( cred - > keytab_obtained > = obtained ) {
return 0 ;
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_krb5_context ( cred , lp_ctx , & smb_krb5_context ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( ret ) {
return ret ;
}
mem_ctx = talloc_new ( cred ) ;
if ( ! mem_ctx ) {
return ENOMEM ;
}
2011-04-14 09:42:42 +04:00
ret = smb_krb5_get_keytab_container ( mem_ctx , smb_krb5_context ,
2012-03-31 11:23:19 +04:00
NULL , keytab_name , & ktc ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( ret ) {
return ret ;
}
cred - > keytab_obtained = obtained ;
talloc_steal ( cred , ktc ) ;
cred - > keytab = ktc ;
talloc_free ( mem_ctx ) ;
return ret ;
}
/* Get server gss credentials (in gsskrb5, this means the keytab) */
2023-02-03 20:52:04 +03:00
_PUBLIC_ int cli_credentials_get_server_gss_creds ( struct cli_credentials * cred ,
2010-10-11 09:53:08 +04:00
struct loadparm_context * lp_ctx ,
struct gssapi_creds_container * * _gcc )
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
{
int ret = 0 ;
OM_uint32 maj_stat , min_stat ;
struct gssapi_creds_container * gcc ;
struct keytab_container * ktc ;
struct smb_krb5_context * smb_krb5_context ;
TALLOC_CTX * mem_ctx ;
krb5_principal princ ;
2010-02-25 08:16:33 +03:00
const char * error_string ;
2010-05-01 04:33:08 +04:00
enum credentials_obtained obtained ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
2010-05-01 04:33:08 +04:00
mem_ctx = talloc_new ( cred ) ;
if ( ! mem_ctx ) {
return ENOMEM ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_krb5_context ( cred , lp_ctx , & smb_krb5_context ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( ret ) {
return ret ;
}
2010-05-01 04:33:08 +04:00
ret = principal_from_credentials ( mem_ctx , cred , smb_krb5_context , & princ , & obtained , & error_string ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( ret ) {
2011-03-01 00:04:29 +03:00
DEBUG ( 1 , ( " cli_credentials_get_server_gss_creds: making krb5 principal failed (%s) \n " ,
2010-05-01 04:33:08 +04:00
error_string ) ) ;
talloc_free ( mem_ctx ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
return ret ;
}
2010-05-01 04:33:08 +04:00
if ( cred - > server_gss_creds_obtained > = ( MAX ( cred - > keytab_obtained , obtained ) ) ) {
talloc_free ( mem_ctx ) ;
* _gcc = cred - > server_gss_creds ;
return 0 ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
}
2010-10-11 09:53:08 +04:00
ret = cli_credentials_get_keytab ( cred , lp_ctx , & ktc ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( ret ) {
2010-05-01 04:33:08 +04:00
DEBUG ( 1 , ( " Failed to get keytab for GSSAPI server: %s \n " , error_message ( ret ) ) ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
return ret ;
}
gcc = talloc ( cred , struct gssapi_creds_container ) ;
if ( ! gcc ) {
talloc_free ( mem_ctx ) ;
return ENOMEM ;
}
2012-08-30 01:49:21 +04:00
if ( ktc - > password_based | | obtained < CRED_SPECIFIED ) {
2016-12-13 13:38:13 +03:00
/*
* This creates a GSSAPI cred_id_t for match - by - key with only
* the keytab set
*/
princ = NULL ;
2011-12-06 07:18:41 +04:00
}
2016-12-13 13:38:13 +03:00
maj_stat = smb_gss_krb5_import_cred ( & min_stat ,
smb_krb5_context - > krb5_context ,
NULL , princ ,
ktc - > keytab ,
& gcc - > creds ) ;
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
if ( maj_stat ) {
if ( min_stat ) {
ret = min_stat ;
} else {
ret = EINVAL ;
}
}
if ( ret = = 0 ) {
cred - > server_gss_creds_obtained = cred - > keytab_obtained ;
talloc_set_destructor ( gcc , free_gssapi_creds ) ;
cred - > server_gss_creds = gcc ;
* _gcc = gcc ;
}
talloc_free ( mem_ctx ) ;
2005-10-20 07:47:55 +04:00
return ret ;
}
2023-02-03 20:52:04 +03:00
/**
2005-09-29 04:02:38 +04:00
* Set Kerberos KVNO
*/
2008-04-02 06:53:27 +04:00
_PUBLIC_ void cli_credentials_set_kvno ( struct cli_credentials * cred ,
2005-09-29 04:02:38 +04:00
int kvno )
{
cred - > kvno = kvno ;
}
/**
* Return Kerberos KVNO
*/
2008-04-02 06:53:27 +04:00
_PUBLIC_ int cli_credentials_get_kvno ( struct cli_credentials * cred )
2005-09-29 04:02:38 +04:00
{
return cred - > kvno ;
}
2007-04-28 20:38:06 +04:00
2023-12-21 02:00:46 +03:00
char * cli_credentials_get_salt_principal ( struct cli_credentials * cred , TALLOC_CTX * mem_ctx )
2005-10-20 14:28:16 +04:00
{
2023-12-21 02:00:46 +03:00
TALLOC_CTX * frame = NULL ;
const char * realm = NULL ;
const char * username = NULL ;
uint32_t uac_flags = 0 ;
char * salt_principal = NULL ;
const char * upn = NULL ;
int ret ;
/* If specified, use the specified value */
if ( cred - > salt_principal ! = NULL ) {
return talloc_strdup ( mem_ctx , cred - > salt_principal ) ;
}
frame = talloc_stackframe ( ) ;
switch ( cred - > secure_channel_type ) {
case SEC_CHAN_WKSTA :
case SEC_CHAN_RODC :
uac_flags = UF_WORKSTATION_TRUST_ACCOUNT ;
break ;
case SEC_CHAN_BDC :
uac_flags = UF_SERVER_TRUST_ACCOUNT ;
break ;
case SEC_CHAN_DOMAIN :
case SEC_CHAN_DNS_DOMAIN :
uac_flags = UF_INTERDOMAIN_TRUST_ACCOUNT ;
break ;
default :
upn = cli_credentials_get_principal ( cred , frame ) ;
if ( upn = = NULL ) {
TALLOC_FREE ( frame ) ;
return NULL ;
}
uac_flags = UF_NORMAL_ACCOUNT ;
break ;
}
realm = cli_credentials_get_realm ( cred ) ;
username = cli_credentials_get_username ( cred ) ;
ret = smb_krb5_salt_principal_str ( realm ,
username , /* sAMAccountName */
upn , /* userPrincipalName */
uac_flags ,
mem_ctx ,
& salt_principal ) ;
if ( ret ) {
TALLOC_FREE ( frame ) ;
return NULL ;
}
TALLOC_FREE ( frame ) ;
return salt_principal ;
2005-10-20 14:28:16 +04:00
}
2023-02-03 20:52:04 +03:00
_PUBLIC_ void cli_credentials_set_salt_principal ( struct cli_credentials * cred , const char * principal )
2005-10-20 14:28:16 +04:00
{
2010-03-03 03:34:04 +03:00
talloc_free ( cred - > salt_principal ) ;
2005-10-20 14:28:16 +04:00
cred - > salt_principal = talloc_strdup ( cred , principal ) ;
}
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
2011-06-17 13:53:11 +04:00
/* The 'impersonate_principal' is used to allow one Kerberos principal
2010-03-03 05:24:52 +03:00
* ( and it ' s associated keytab etc ) to impersonate another . The
* ability to do this is controlled by the KDC , but it is generally
* permitted to impersonate anyone to yourself . This allows any
* member of the domain to get the groups of a user . This is also
* known as S4U2Self */
2011-04-22 13:22:50 +04:00
_PUBLIC_ const char * cli_credentials_get_impersonate_principal ( struct cli_credentials * cred )
2010-03-03 05:24:52 +03:00
{
return cred - > impersonate_principal ;
}
2011-04-22 13:22:50 +04:00
/*
* The ' self_service ' is the service principal that
* represents the same object ( by its objectSid )
* as the client principal ( typically our machine account ) .
* When trying to impersonate ' impersonate_principal ' with
* S4U2Self .
*/
_PUBLIC_ const char * cli_credentials_get_self_service ( struct cli_credentials * cred )
{
return cred - > self_service ;
}
_PUBLIC_ void cli_credentials_set_impersonate_principal ( struct cli_credentials * cred ,
const char * principal ,
const char * self_service )
2010-03-03 05:24:52 +03:00
{
talloc_free ( cred - > impersonate_principal ) ;
cred - > impersonate_principal = talloc_strdup ( cred , principal ) ;
2011-04-22 13:22:50 +04:00
talloc_free ( cred - > self_service ) ;
cred - > self_service = talloc_strdup ( cred , self_service ) ;
2020-08-19 16:46:11 +03:00
cli_credentials_set_kerberos_state ( cred ,
CRED_USE_KERBEROS_REQUIRED ,
CRED_SPECIFIED ) ;
2010-03-03 05:24:52 +03:00
}
2011-04-22 13:22:50 +04:00
/*
* when impersonating for S4U2proxy we need to set the target principal .
2010-03-03 05:24:52 +03:00
* Similarly , we may only be authorized to do general impersonation to
* some particular services .
*
* Likewise , password changes typically require a ticket to kpasswd / realm directly , not via a TGT
*
* NULL means that tickets will be obtained for the krbtgt service .
*/
const char * cli_credentials_get_target_service ( struct cli_credentials * cred )
{
return cred - > target_service ;
}
_PUBLIC_ void cli_credentials_set_target_service ( struct cli_credentials * cred , const char * target_service )
{
talloc_free ( cred - > target_service ) ;
cred - > target_service = talloc_strdup ( cred , target_service ) ;
}
r11995: A big kerberos-related update.
This merges Samba4 up to current lorikeet-heimdal, which includes a
replacement for some Samba-specific hacks.
In particular, the credentials system now supplies GSS client and
server credentials. These are imported into GSS with
gss_krb5_import_creds(). Unfortunetly this can't take an MEMORY
keytab, so we now create a FILE based keytab as provision and join
time.
Because the keytab is now created in advance, we don't spend .4s at
negprot doing sha1 s2k calls. Also, because the keytab is read in
real time, any change in the server key will be correctly picked up by
the the krb5 code.
To mark entries in the secrets which should be exported to a keytab,
there is a new kerberosSecret objectClass. The new routine
cli_credentials_update_all_keytabs() searches for these, and updates
the keytabs.
This is called in the provision.js via the ejs wrapper
credentials_update_all_keytabs().
We can now (in theory) use a system-provided /etc/krb5.keytab, if
krb5Keytab: FILE:/etc/krb5.keytab
is added to the secrets.ldb record. By default the attribute
privateKeytab: secrets.keytab
is set, pointing to allow the whole private directory to be moved
without breaking the internal links.
(This used to be commit 6b75573df49c6210e1b9d71e108a9490976bd41d)
2005-12-01 08:20:39 +03:00
2023-12-21 12:25:25 +03:00
_PUBLIC_ int cli_credentials_get_kerberos_key ( struct cli_credentials * cred ,
TALLOC_CTX * mem_ctx ,
struct loadparm_context * lp_ctx ,
krb5_enctype enctype ,
2023-12-21 04:04:23 +03:00
bool previous ,
2023-12-21 12:25:25 +03:00
DATA_BLOB * key_blob )
2022-05-09 05:35:05 +03:00
{
struct smb_krb5_context * smb_krb5_context = NULL ;
krb5_error_code krb5_ret ;
int ret ;
const char * password = NULL ;
2023-12-20 12:55:07 +03:00
const char * salt = NULL ;
2022-05-09 05:35:05 +03:00
krb5_data cleartext_data ;
2023-02-03 20:52:55 +03:00
krb5_data salt_data = {
. length = 0 ,
} ;
2022-05-09 05:35:05 +03:00
krb5_keyblock key ;
2023-12-21 02:00:46 +03:00
TALLOC_CTX * frame = talloc_stackframe ( ) ;
2023-12-21 12:25:25 +03:00
if ( ( int ) enctype = = ( int ) ENCTYPE_ARCFOUR_HMAC ) {
2023-12-21 04:04:23 +03:00
struct samr_Password * nt_hash ;
if ( previous ) {
nt_hash = cli_credentials_get_old_nt_hash ( cred , frame ) ;
} else {
nt_hash = cli_credentials_get_nt_hash ( cred , frame ) ;
}
2023-12-21 12:25:25 +03:00
if ( nt_hash = = NULL ) {
TALLOC_FREE ( frame ) ;
return EINVAL ;
}
* key_blob = data_blob_talloc ( mem_ctx ,
nt_hash - > hash ,
sizeof ( nt_hash - > hash ) ) ;
if ( key_blob - > data = = NULL ) {
TALLOC_FREE ( frame ) ;
return ENOMEM ;
}
TALLOC_FREE ( frame ) ;
return 0 ;
}
2022-05-09 05:35:05 +03:00
if ( cred - > password_will_be_nt_hash ) {
2023-12-21 12:25:25 +03:00
DEBUG ( 1 , ( " cli_credentials_get_kerberos_key: cannot generate Kerberos key using NT hash \n " ) ) ;
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return EINVAL ;
}
2023-12-21 02:00:46 +03:00
salt = cli_credentials_get_salt_principal ( cred , frame ) ;
2023-12-20 12:55:07 +03:00
if ( salt = = NULL ) {
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2023-12-20 12:55:07 +03:00
return EINVAL ;
}
2023-12-21 04:04:23 +03:00
if ( previous ) {
password = cli_credentials_get_old_password ( cred ) ;
} else {
password = cli_credentials_get_password ( cred ) ;
}
2022-05-09 05:35:05 +03:00
if ( password = = NULL ) {
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return EINVAL ;
}
cleartext_data . data = discard_const_p ( char , password ) ;
cleartext_data . length = strlen ( password ) ;
ret = cli_credentials_get_krb5_context ( cred , lp_ctx ,
& smb_krb5_context ) ;
if ( ret ! = 0 ) {
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return ret ;
}
salt_data . data = discard_const_p ( char , salt ) ;
salt_data . length = strlen ( salt ) ;
/*
2023-12-21 12:25:25 +03:00
* create Kerberos key out of
2022-05-09 05:35:05 +03:00
* the salt and the cleartext password
*/
krb5_ret = smb_krb5_create_key_from_string ( smb_krb5_context - > krb5_context ,
NULL ,
& salt_data ,
& cleartext_data ,
2023-12-21 12:25:25 +03:00
enctype ,
2022-05-09 05:35:05 +03:00
& key ) ;
if ( krb5_ret ! = 0 ) {
DEBUG ( 1 , ( " cli_credentials_get_aes256_key: "
2023-08-07 07:31:51 +03:00
" generation of a aes256-cts-hmac-sha1-96 key failed: %s \n " ,
2022-05-09 05:35:05 +03:00
smb_get_krb5_error_message ( smb_krb5_context - > krb5_context ,
krb5_ret , mem_ctx ) ) ) ;
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return EINVAL ;
}
2023-12-21 12:25:25 +03:00
* key_blob = data_blob_talloc ( mem_ctx ,
2022-05-09 05:35:05 +03:00
KRB5_KEY_DATA ( & key ) ,
KRB5_KEY_LENGTH ( & key ) ) ;
krb5_free_keyblock_contents ( smb_krb5_context - > krb5_context , & key ) ;
2023-12-21 12:25:25 +03:00
if ( key_blob - > data = = NULL ) {
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return ENOMEM ;
}
2023-12-21 12:25:25 +03:00
talloc_keep_secret ( key_blob - > data ) ;
2022-05-09 05:35:05 +03:00
2023-12-21 02:00:46 +03:00
TALLOC_FREE ( frame ) ;
2022-05-09 05:35:05 +03:00
return 0 ;
}
2023-11-17 07:41:53 +03:00
/* This take a reference to the armor credentials to ensure the lifetime is appropriate */
NTSTATUS cli_credentials_set_krb5_fast_armor_credentials ( struct cli_credentials * creds ,
struct cli_credentials * armor_creds ,
bool require_fast_armor )
{
talloc_unlink ( creds , creds - > krb5_fast_armor_credentials ) ;
if ( armor_creds = = NULL ) {
creds - > krb5_fast_armor_credentials = NULL ;
return NT_STATUS_OK ;
}
creds - > krb5_fast_armor_credentials = talloc_reference ( creds , armor_creds ) ;
if ( creds - > krb5_fast_armor_credentials = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
creds - > krb5_require_fast_armor = require_fast_armor ;
return NT_STATUS_OK ;
}
struct cli_credentials * cli_credentials_get_krb5_fast_armor_credentials ( struct cli_credentials * creds )
{
return creds - > krb5_fast_armor_credentials ;
}
bool cli_credentials_get_krb5_require_fast_armor ( struct cli_credentials * creds )
{
return creds - > krb5_require_fast_armor ;
}