freebsd-src/sys/kgssapi/gssapi_impl.h
Rick Macklem e3ac01e18e kgssapi: Fix the kgssapi so that it can use MIT Kerberos
Without this patch, the kgssapi uses detailed knowledge
of the internal context structure for Heimdal (up to vers 1.5).
It also does four upcalls to the gssd daemon to establish
a server side RPCSEC_GSS context.

This patch adds support for three new upcalls:
gss_init_sec_context_lucid_v1()
gss_accept_sec_context_lucid_v1()
gss_supports_lucid()

These are used to determine if the gssd can do the upcalls
and uses them to avoid needing detailed Heimdal knowledge
if they are supported.

gss_init_sec_context_lucid_v1() and
gss_accept_sec_context_lucid_v1() return the information
needed to complete the RPCSEC_GSS context.
They use gss_krb5_export_lucid_sec_context() to acquire
the information from the libraries. (MIT Kerberos supports
this and I believe newer versions of Heimdal does, as well).

This avoids the need for detailed knowledge about MIT's
internals and replaces the 2 or 4 (initiator or acceptor) upcalls
with a single upcall to create the RPCSEC_GSS context.

The old Heimdal (up to 1.5) support is left intact, but should
be removed whenever Heimdal 1.5 is removed from /usr/src.

It also modifies the Makefile so that the gssd is only built
when MK_KERBEROS_SUPPORT != "no", since it is useless without
Kerberos.

Reviewed by:	cy
Differeential Revision:	https://reviews.freebsd.org/D51731
Differeential Revision:	https://reviews.freebsd.org/D51733
2025-08-07 14:02:32 -07:00

82 lines
3.1 KiB
C

/*-
* SPDX-License-Identifier: BSD-2-Clause
*
* Copyright (c) 2008 Isilon Inc http://www.isilon.com/
* Authors: Doug Rabson <dfr@rabson.org>
* Developed with Red Inc: Alfred Perlstein <alfred@freebsd.org>
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*/
#include "gssd.h"
MALLOC_DECLARE(M_GSSAPI);
struct _gss_ctx_id_t {
KOBJ_FIELDS;
gssd_ctx_id_t handle;
};
struct _gss_cred_id_t {
gssd_cred_id_t handle;
};
struct _gss_name_t {
gssd_name_t handle;
};
struct kgss_mech {
LIST_ENTRY(kgss_mech) km_link;
gss_OID km_mech_type;
const char *km_mech_name;
struct kobj_class *km_class;
};
LIST_HEAD(kgss_mech_list, kgss_mech);
/* Macros for VIMAGE. */
/* Just define the KGSS_VNETxxx() macros as VNETxxx() macros. */
#define KGSS_VNET_DEFINE(t, n) VNET_DEFINE(t, n)
#define KGSS_VNET_DEFINE_STATIC(t, n) VNET_DEFINE_STATIC(t, n)
#define KGSS_VNET_DECLARE(t, n) VNET_DECLARE(t, n)
#define KGSS_VNET(n) VNET(n)
#define KGSS_CURVNET_SET(n) CURVNET_SET(n)
#define KGSS_CURVNET_SET_QUIET(n) CURVNET_SET_QUIET(n)
#define KGSS_CURVNET_RESTORE() CURVNET_RESTORE()
#define KGSS_TD_TO_VNET(n) TD_TO_VNET(n)
extern struct mtx kgss_gssd_lock;
extern struct kgss_mech_list kgss_mechs;
KGSS_VNET_DECLARE(CLIENT *, kgss_gssd_handle);
CLIENT *kgss_gssd_client(void);
int kgss_oid_equal(const gss_OID oid1, const gss_OID oid2);
extern void kgss_install_mech(gss_OID mech_type, const char *name,
struct kobj_class *cls);
extern void kgss_uninstall_mech(gss_OID mech_type);
extern gss_OID kgss_find_mech_by_name(const char *name);
extern const char *kgss_find_mech_by_oid(const gss_OID oid);
extern gss_ctx_id_t kgss_create_context(gss_OID mech_type);
extern void kgss_delete_context(gss_ctx_id_t ctx, gss_buffer_t output_token);
extern OM_uint32 kgss_transfer_context(gss_ctx_id_t ctx, void *lctx);
extern void kgss_copy_buffer(const gss_buffer_t from, gss_buffer_t to);