pgssapi.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297
  1. #ifndef PUTTY_PGSSAPI_H
  2. #define PUTTY_PGSSAPI_H
  3. #include "putty.h"
  4. #ifndef NO_GSSAPI
  5. /*
  6. * On Unix, if we're statically linking against GSSAPI, we leave the
  7. * declaration of all this lot to the official header. If we're
  8. * dynamically linking, we declare it ourselves, because that avoids
  9. * us needing the official header at compile time.
  10. *
  11. * However, we still need the function pointer types, because even
  12. * with statically linked GSSAPI we use the ssh_gss_library wrapper.
  13. */
  14. #ifdef STATIC_GSSAPI
  15. #include <gssapi/gssapi.h>
  16. typedef gss_OID const_gss_OID; /* for our prototypes below */
  17. #else /* STATIC_GSSAPI */
  18. /*******************************************************************************
  19. * GSSAPI Definitions, taken from RFC 2744
  20. ******************************************************************************/
  21. /* GSSAPI Type Definitions */
  22. typedef uint32 OM_uint32;
  23. typedef struct gss_OID_desc_struct {
  24. OM_uint32 length;
  25. void *elements;
  26. } gss_OID_desc;
  27. typedef const gss_OID_desc *const_gss_OID;
  28. typedef gss_OID_desc *gss_OID;
  29. typedef struct gss_OID_set_desc_struct {
  30. size_t count;
  31. gss_OID elements;
  32. } gss_OID_set_desc;
  33. typedef const gss_OID_set_desc *const_gss_OID_set;
  34. typedef gss_OID_set_desc *gss_OID_set;
  35. typedef struct gss_buffer_desc_struct {
  36. size_t length;
  37. void *value;
  38. } gss_buffer_desc, *gss_buffer_t;
  39. typedef struct gss_channel_bindings_struct {
  40. OM_uint32 initiator_addrtype;
  41. gss_buffer_desc initiator_address;
  42. OM_uint32 acceptor_addrtype;
  43. gss_buffer_desc acceptor_address;
  44. gss_buffer_desc application_data;
  45. } *gss_channel_bindings_t;
  46. typedef void * gss_ctx_id_t;
  47. typedef void * gss_name_t;
  48. typedef void * gss_cred_id_t;
  49. typedef OM_uint32 gss_qop_t;
  50. /* Flag bits for context-level services. */
  51. #define GSS_C_DELEG_FLAG 1
  52. #define GSS_C_MUTUAL_FLAG 2
  53. #define GSS_C_REPLAY_FLAG 4
  54. #define GSS_C_SEQUENCE_FLAG 8
  55. #define GSS_C_CONF_FLAG 16
  56. #define GSS_C_INTEG_FLAG 32
  57. #define GSS_C_ANON_FLAG 64
  58. #define GSS_C_PROT_READY_FLAG 128
  59. #define GSS_C_TRANS_FLAG 256
  60. /* Credential usage options */
  61. #define GSS_C_BOTH 0
  62. #define GSS_C_INITIATE 1
  63. #define GSS_C_ACCEPT 2
  64. /* Status code types for gss_display_status */
  65. #define GSS_C_GSS_CODE 1
  66. #define GSS_C_MECH_CODE 2
  67. /* The constant definitions for channel-bindings address families */
  68. #define GSS_C_AF_UNSPEC 0
  69. #define GSS_C_AF_LOCAL 1
  70. #define GSS_C_AF_INET 2
  71. #define GSS_C_AF_IMPLINK 3
  72. #define GSS_C_AF_PUP 4
  73. #define GSS_C_AF_CHAOS 5
  74. #define GSS_C_AF_NS 6
  75. #define GSS_C_AF_NBS 7
  76. #define GSS_C_AF_ECMA 8
  77. #define GSS_C_AF_DATAKIT 9
  78. #define GSS_C_AF_CCITT 10
  79. #define GSS_C_AF_SNA 11
  80. #define GSS_C_AF_DECnet 12
  81. #define GSS_C_AF_DLI 13
  82. #define GSS_C_AF_LAT 14
  83. #define GSS_C_AF_HYLINK 15
  84. #define GSS_C_AF_APPLETALK 16
  85. #define GSS_C_AF_BSC 17
  86. #define GSS_C_AF_DSS 18
  87. #define GSS_C_AF_OSI 19
  88. #define GSS_C_AF_X25 21
  89. #define GSS_C_AF_NULLADDR 255
  90. /* Various Null values */
  91. #define GSS_C_NO_NAME ((gss_name_t) 0)
  92. #define GSS_C_NO_BUFFER ((gss_buffer_t) 0)
  93. #define GSS_C_NO_OID ((gss_OID) 0)
  94. #define GSS_C_NO_OID_SET ((gss_OID_set) 0)
  95. #define GSS_C_NO_CONTEXT ((gss_ctx_id_t) 0)
  96. #define GSS_C_NO_CREDENTIAL ((gss_cred_id_t) 0)
  97. #define GSS_C_NO_CHANNEL_BINDINGS ((gss_channel_bindings_t) 0)
  98. #define GSS_C_EMPTY_BUFFER {0, NULL}
  99. /* Major status codes */
  100. #define GSS_S_COMPLETE 0
  101. /* Some "helper" definitions to make the status code macros obvious. */
  102. #define GSS_C_CALLING_ERROR_OFFSET 24
  103. #define GSS_C_ROUTINE_ERROR_OFFSET 16
  104. #define GSS_C_SUPPLEMENTARY_OFFSET 0
  105. #define GSS_C_CALLING_ERROR_MASK 0377ul
  106. #define GSS_C_ROUTINE_ERROR_MASK 0377ul
  107. #define GSS_C_SUPPLEMENTARY_MASK 0177777ul
  108. /*
  109. * The macros that test status codes for error conditions.
  110. * Note that the GSS_ERROR() macro has changed slightly from
  111. * the V1 GSS-API so that it now evaluates its argument
  112. * only once.
  113. */
  114. #define GSS_CALLING_ERROR(x) \
  115. (x & (GSS_C_CALLING_ERROR_MASK << GSS_C_CALLING_ERROR_OFFSET))
  116. #define GSS_ROUTINE_ERROR(x) \
  117. (x & (GSS_C_ROUTINE_ERROR_MASK << GSS_C_ROUTINE_ERROR_OFFSET))
  118. #define GSS_SUPPLEMENTARY_INFO(x) \
  119. (x & (GSS_C_SUPPLEMENTARY_MASK << GSS_C_SUPPLEMENTARY_OFFSET))
  120. #define GSS_ERROR(x) \
  121. (x & ((GSS_C_CALLING_ERROR_MASK << GSS_C_CALLING_ERROR_OFFSET) | \
  122. (GSS_C_ROUTINE_ERROR_MASK << GSS_C_ROUTINE_ERROR_OFFSET)))
  123. /* Now the actual status code definitions */
  124. /* Calling errors: */
  125. #define GSS_S_CALL_INACCESSIBLE_READ \
  126. (1ul << GSS_C_CALLING_ERROR_OFFSET)
  127. #define GSS_S_CALL_INACCESSIBLE_WRITE \
  128. (2ul << GSS_C_CALLING_ERROR_OFFSET)
  129. #define GSS_S_CALL_BAD_STRUCTURE \
  130. (3ul << GSS_C_CALLING_ERROR_OFFSET)
  131. /* Routine errors: */
  132. #define GSS_S_BAD_MECH (1ul << \
  133. GSS_C_ROUTINE_ERROR_OFFSET)
  134. #define GSS_S_BAD_NAME (2ul << \
  135. GSS_C_ROUTINE_ERROR_OFFSET)
  136. #define GSS_S_BAD_NAMETYPE (3ul << \
  137. GSS_C_ROUTINE_ERROR_OFFSET)
  138. #define GSS_S_BAD_BINDINGS (4ul << \
  139. GSS_C_ROUTINE_ERROR_OFFSET)
  140. #define GSS_S_BAD_STATUS (5ul << \
  141. GSS_C_ROUTINE_ERROR_OFFSET)
  142. #define GSS_S_BAD_SIG (6ul << \
  143. GSS_C_ROUTINE_ERROR_OFFSET)
  144. #define GSS_S_BAD_MIC GSS_S_BAD_SIG
  145. #define GSS_S_NO_CRED (7ul << \
  146. GSS_C_ROUTINE_ERROR_OFFSET)
  147. #define GSS_S_NO_CONTEXT (8ul << \
  148. GSS_C_ROUTINE_ERROR_OFFSET)
  149. #define GSS_S_DEFECTIVE_TOKEN (9ul << \
  150. GSS_C_ROUTINE_ERROR_OFFSET)
  151. #define GSS_S_DEFECTIVE_CREDENTIAL (10ul << \
  152. GSS_C_ROUTINE_ERROR_OFFSET)
  153. #define GSS_S_CREDENTIALS_EXPIRED (11ul << \
  154. GSS_C_ROUTINE_ERROR_OFFSET)
  155. #define GSS_S_CONTEXT_EXPIRED (12ul << \
  156. GSS_C_ROUTINE_ERROR_OFFSET)
  157. #define GSS_S_FAILURE (13ul << \
  158. GSS_C_ROUTINE_ERROR_OFFSET)
  159. #define GSS_S_BAD_QOP (14ul << \
  160. GSS_C_ROUTINE_ERROR_OFFSET)
  161. #define GSS_S_UNAUTHORIZED (15ul << \
  162. GSS_C_ROUTINE_ERROR_OFFSET)
  163. #define GSS_S_UNAVAILABLE (16ul << \
  164. GSS_C_ROUTINE_ERROR_OFFSET)
  165. #define GSS_S_DUPLICATE_ELEMENT (17ul << \
  166. GSS_C_ROUTINE_ERROR_OFFSET)
  167. #define GSS_S_NAME_NOT_MN (18ul << \
  168. GSS_C_ROUTINE_ERROR_OFFSET)
  169. /* Supplementary info bits: */
  170. #define GSS_S_CONTINUE_NEEDED \
  171. (1ul << (GSS_C_SUPPLEMENTARY_OFFSET + 0))
  172. #define GSS_S_DUPLICATE_TOKEN \
  173. (1ul << (GSS_C_SUPPLEMENTARY_OFFSET + 1))
  174. #define GSS_S_OLD_TOKEN \
  175. (1ul << (GSS_C_SUPPLEMENTARY_OFFSET + 2))
  176. #define GSS_S_UNSEQ_TOKEN \
  177. (1ul << (GSS_C_SUPPLEMENTARY_OFFSET + 3))
  178. #define GSS_S_GAP_TOKEN \
  179. (1ul << (GSS_C_SUPPLEMENTARY_OFFSET + 4))
  180. extern const_gss_OID GSS_C_NT_USER_NAME;
  181. extern const_gss_OID GSS_C_NT_MACHINE_UID_NAME;
  182. extern const_gss_OID GSS_C_NT_STRING_UID_NAME;
  183. extern const_gss_OID GSS_C_NT_HOSTBASED_SERVICE_X;
  184. extern const_gss_OID GSS_C_NT_HOSTBASED_SERVICE;
  185. extern const_gss_OID GSS_C_NT_ANONYMOUS;
  186. extern const_gss_OID GSS_C_NT_EXPORT_NAME;
  187. #endif /* STATIC_GSSAPI */
  188. extern const gss_OID GSS_MECH_KRB5;
  189. /* GSSAPI functions we use.
  190. * TODO: Replace with all GSSAPI functions from RFC?
  191. */
  192. /* Calling convention, just in case we need one. */
  193. #ifndef GSS_CC
  194. #define GSS_CC
  195. #endif /*GSS_CC*/
  196. typedef OM_uint32 (GSS_CC *t_gss_release_cred)
  197. (OM_uint32 * /*minor_status*/,
  198. gss_cred_id_t * /*cred_handle*/);
  199. typedef OM_uint32 (GSS_CC *t_gss_init_sec_context)
  200. (OM_uint32 * /*minor_status*/,
  201. const gss_cred_id_t /*initiator_cred_handle*/,
  202. gss_ctx_id_t * /*context_handle*/,
  203. const gss_name_t /*target_name*/,
  204. const gss_OID /*mech_type*/,
  205. OM_uint32 /*req_flags*/,
  206. OM_uint32 /*time_req*/,
  207. const gss_channel_bindings_t /*input_chan_bindings*/,
  208. const gss_buffer_t /*input_token*/,
  209. gss_OID * /*actual_mech_type*/,
  210. gss_buffer_t /*output_token*/,
  211. OM_uint32 * /*ret_flags*/,
  212. OM_uint32 * /*time_rec*/);
  213. typedef OM_uint32 (GSS_CC *t_gss_delete_sec_context)
  214. (OM_uint32 * /*minor_status*/,
  215. gss_ctx_id_t * /*context_handle*/,
  216. gss_buffer_t /*output_token*/);
  217. typedef OM_uint32 (GSS_CC *t_gss_get_mic)
  218. (OM_uint32 * /*minor_status*/,
  219. const gss_ctx_id_t /*context_handle*/,
  220. gss_qop_t /*qop_req*/,
  221. const gss_buffer_t /*message_buffer*/,
  222. gss_buffer_t /*msg_token*/);
  223. typedef OM_uint32 (GSS_CC *t_gss_display_status)
  224. (OM_uint32 * /*minor_status*/,
  225. OM_uint32 /*status_value*/,
  226. int /*status_type*/,
  227. const gss_OID /*mech_type*/,
  228. OM_uint32 * /*message_context*/,
  229. gss_buffer_t /*status_string*/);
  230. typedef OM_uint32 (GSS_CC *t_gss_import_name)
  231. (OM_uint32 * /*minor_status*/,
  232. const gss_buffer_t /*input_name_buffer*/,
  233. const_gss_OID /*input_name_type*/,
  234. gss_name_t * /*output_name*/);
  235. typedef OM_uint32 (GSS_CC *t_gss_release_name)
  236. (OM_uint32 * /*minor_status*/,
  237. gss_name_t * /*name*/);
  238. typedef OM_uint32 (GSS_CC *t_gss_release_buffer)
  239. (OM_uint32 * /*minor_status*/,
  240. gss_buffer_t /*buffer*/);
  241. struct gssapi_functions {
  242. t_gss_delete_sec_context delete_sec_context;
  243. t_gss_display_status display_status;
  244. t_gss_get_mic get_mic;
  245. t_gss_import_name import_name;
  246. t_gss_init_sec_context init_sec_context;
  247. t_gss_release_buffer release_buffer;
  248. t_gss_release_cred release_cred;
  249. t_gss_release_name release_name;
  250. };
  251. #endif /* NO_GSSAPI */
  252. #endif /* PUTTY_PGSSAPI_H */