diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index c78f6a3..40603ef 100644 --- a/.gitignore +++ b/.gitignore @@ -1,49 +1,50 @@ -krb5-1.3.4.tar.gz -krb5-1.3.5.tar.gz -krb5-1.3.5.tar.gz.asc -krb5-1.3.6.tar.gz -krb5-1.3.6.tar.gz.asc -krb5-1.4.tar.gz -krb5-1.4.tar.gz.asc -krb5-1.4.1.tar.gz -krb5-1.4.1.tar.gz.asc -krb5-1.4.2.tar.gz -krb5-1.4.2.tar.gz.asc -krb5-1.4.3.tar.gz -krb5-1.4.3.tar.gz.asc -krb5-1.5.tar.gz -krb5-1.5.tar.gz.asc -krb5-1.6.tar.gz -krb5-1.6.tar.gz.asc -krb5-1.6-pdf.tar.gz -krb5-1.6.1.tar.gz -krb5-1.6.1.tar.gz.asc -krb5-1.6.1-pdf.tar.gz -krb5-1.6.2.tar.gz -krb5-1.6.2.tar.gz.asc -krb5-1.6.2-pdf.tar.gz -krb5-1.6.3.tar.gz -krb5-1.6.3.tar.gz.asc -krb5-1.6.3-pdf.tar.gz -krb5-1.7.tar.gz -krb5-1.7.tar.gz.asc -krb5-1.7-pdf.tar.gz -krb5-1.7.1.tar.gz -krb5-1.7.1.tar.gz.asc -krb5-1.7.1-pdf.tar.gz -krb5-1.8.tar.gz -krb5-1.8.tar.gz.asc -krb5-appl-1.0.tar.gz -krb5-appl-1.0.tar.gz.asc -krb5-1.8-pdf.tar.gz -krb5-1.8.1.tar.gz -krb5-1.8.1.tar.gz.asc -krb5-1.8.1-pdf.tar.gz -krb5-1.8.2.tar.gz.asc -krb5-1.8.2-pdf.tar.gz -krb5-1.8.3.tar.gz -krb5-1.8.3.tar.gz.asc -krb5-1.8.3-pdf.tar.gz +/results_krb5 +/krb5-1.3.4.tar.gz +/krb5-1.3.5.tar.gz +/krb5-1.3.5.tar.gz.asc +/krb5-1.3.6.tar.gz +/krb5-1.3.6.tar.gz.asc +/krb5-1.4.tar.gz +/krb5-1.4.tar.gz.asc +/krb5-1.4.1.tar.gz +/krb5-1.4.1.tar.gz.asc +/krb5-1.4.2.tar.gz +/krb5-1.4.2.tar.gz.asc +/krb5-1.4.3.tar.gz +/krb5-1.4.3.tar.gz.asc +/krb5-1.5.tar.gz +/krb5-1.5.tar.gz.asc +/krb5-1.6.tar.gz +/krb5-1.6.tar.gz.asc +/krb5-1.6-pdf.tar.gz +/krb5-1.6.1.tar.gz +/krb5-1.6.1.tar.gz.asc +/krb5-1.6.1-pdf.tar.gz +/krb5-1.6.2.tar.gz +/krb5-1.6.2.tar.gz.asc +/krb5-1.6.2-pdf.tar.gz +/krb5-1.6.3.tar.gz +/krb5-1.6.3.tar.gz.asc +/krb5-1.6.3-pdf.tar.gz +/krb5-1.7.tar.gz +/krb5-1.7.tar.gz.asc +/krb5-1.7-pdf.tar.gz +/krb5-1.7.1.tar.gz +/krb5-1.7.1.tar.gz.asc +/krb5-1.7.1-pdf.tar.gz +/krb5-1.8.tar.gz +/krb5-1.8.tar.gz.asc +/krb5-appl-1.0.tar.gz +/krb5-appl-1.0.tar.gz.asc +/krb5-1.8-pdf.tar.gz +/krb5-1.8.1.tar.gz +/krb5-1.8.1.tar.gz.asc +/krb5-1.8.1-pdf.tar.gz +/krb5-1.8.2.tar.gz.asc +/krb5-1.8.2-pdf.tar.gz +/krb5-1.8.3.tar.gz +/krb5-1.8.3.tar.gz.asc +/krb5-1.8.3-pdf.tar.gz /krb5-1.9-beta2.tar.gz /krb5-1.9-beta2.tar.gz.asc /krb5-1.9-beta2-pdf.tar.bz2 @@ -154,3 +155,56 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.15.2-pdfs.tar /krb5-1.15.2.tar.gz /krb5-1.15.2.tar.gz.asc +/krb5-1.16-beta1-pdfs.tar +/krb5-1.16-beta1.tar.gz +/krb5-1.16-beta1.tar.gz.asc +/krb5-1.16-beta2.tar.gz +/krb5-1.16-beta2.tar.gz.asc +/krb5-1.16-beta2-pdfs.tar +/krb5-1.16-pdfs.tar +/krb5-1.16.tar.gz +/krb5-1.16.tar.gz.asc +/krb5-1.16.1-pdfs.tar +/krb5-1.16.1.tar.gz +/krb5-1.16.1.tar.gz.asc +/krb5-1.17-beta1.tar.gz +/krb5-1.17-beta1.tar.gz.asc +/krb5-1.17-beta1-pdfs.tar +/krb5-1.17-beta2.tar.gz +/krb5-1.17-beta2.tar.gz.asc +/krb5-1.17-beta2-pdfs.tar +/krb5-1.17-pdfs.tar +/krb5-1.17.tar.gz +/krb5-1.17.tar.gz.asc +/krb5-1.17.1.tar.gz +/krb5-1.17.1.tar.gz.asc +/krb5-1.18-beta1.tar.gz +/krb5-1.18-beta1.tar.gz.asc +/krb5-1.18-beta2.tar.gz +/krb5-1.18-beta2.tar.gz.asc +/krb5-1.18.tar.gz +/krb5-1.18.tar.gz.asc +/krb5-1.18.1.tar.gz +/krb5-1.18.1.tar.gz.asc +/krb5-1.18.2.tar.gz +/krb5-1.18.2.tar.gz.asc +/krb5-1.18.3.tar.gz +/krb5-1.18.3.tar.gz.asc +/krb5-1.19-beta1.tar.gz +/krb5-1.19-beta1.tar.gz.asc +/krb5-1.19-beta2.tar.gz +/krb5-1.19-beta2.tar.gz.asc +/krb5-1.19.tar.gz +/krb5-1.19.tar.gz.asc +/krb5-1.19.1.tar.gz +/krb5-1.19.1.tar.gz.asc +/krb5-1.19.2.tar.gz +/krb5-1.19.2.tar.gz.asc +/krb5-1.20.1.tar.gz +/krb5-1.20.1.tar.gz.asc +/krb5-1.21.tar.gz +/krb5-1.21.tar.gz.asc +/krb5-1.21.2.tar.gz +/krb5-1.21.2.tar.gz.asc +/krb5-1.21.3.tar.gz +/krb5-1.21.3.tar.gz.asc diff --git a/0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch b/0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch new file mode 100644 index 0000000..84d04bf --- /dev/null +++ b/0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch @@ -0,0 +1,310 @@ +From 6f7fd964539dfe4a885068f43a91db9738661870 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Tue, 9 Jul 2024 11:15:33 +0200 +Subject: [PATCH] [downstream] Revert "Don't issue session keys with + deprecated enctypes" + +This reverts commit 1b57a4d134bbd0e7c52d5885a92eccc815726463. +--- + doc/admin/conf_files/krb5_conf.rst | 12 ------------ + doc/admin/enctypes.rst | 23 +++------------------- + src/include/k5-int.h | 4 ---- + src/kdc/kdc_util.c | 10 ---------- + src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++------------------- + src/lib/krb5/krb/init_ctx.c | 10 ---------- + src/tests/gssapi/t_enctypes.py | 3 +-- + src/tests/t_etype_info.py | 2 +- + src/tests/t_sesskeynego.py | 28 ++------------------------- + src/util/k5test.py | 4 ++-- + 10 files changed, 20 insertions(+), 107 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index ecdf917501..f22d5db11b 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,18 +95,6 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + +-**allow_des3** +- Permit the KDC to issue tickets with des3-cbc-sha1 session keys. +- In future releases, this flag will allow des3-cbc-sha1 to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- +-**allow_rc4** +- Permit the KDC to issue tickets with arcfour-hmac session keys. +- In future releases, this flag will allow arcfour-hmac to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- + **allow_weak_crypto** + If this flag is set to false, then weak encryption types (as noted + in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index dce19ad43e..694922c0d9 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -48,15 +48,12 @@ Session key selection + The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of +-enctypes. Starting in krb5-1.21, all services are assumed to support +-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session +-keys will not be issued by default. ++enctypes. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +-issue for service tickets for that principal, overriding the service's +-long-term keys and the assumption of aes256-cts-hmac-sha1-96 support. +-See :ref:`set_string` in :ref:`kadmin(1)` for details. ++issue for service tickets for that principal. See :ref:`set_string` ++in :ref:`kadmin(1)` for details. + + + Choosing enctypes for a service +@@ -90,20 +87,6 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + +-**allow_des3** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- des3-cbc-sha1 session keys. In a future release, this flag will +- control whether des3-cbc-sha1 is permitted in similar fashion to +- weak enctypes. +- +-**allow_rc4** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- arcfour-hmac session keys. In a future release, this flag will +- control whether arcfour-hmac is permitted in similar fashion to +- weak enctypes. +- + **permitted_enctypes** + controls the set of enctypes that a service will permit for + session keys and for ticket and authenticator encryption. The KDC +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 2f7791b775..1d1c8293f4 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -180,8 +180,6 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" +-#define KRB5_CONF_ALLOW_DES3 "allow_des3" +-#define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" + #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" +@@ -1240,8 +1238,6 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; +- krb5_boolean allow_des3; +- krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; + enum dns_canonhost dns_canonicalize_hostname; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index e54cc751f9..75e04b73db 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1088,16 +1088,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + if (!krb5_is_permitted_enctype(context, ktype[i])) + continue; + +- /* +- * Prevent these deprecated enctypes from being used as session keys +- * unless they are explicitly allowed. In the future they will be more +- * comprehensively disabled and eventually removed. +- */ +- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) +- continue; +- if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) +- continue; +- + if (dbentry_supports_enctype(context, server, ktype[i])) + return ktype[i]; + } +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index ea089f0fcc..1b420a3ac2 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1582,31 +1582,22 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + (*prompter)(context, data, 0, banner, 0, 0); + } + +-/* Display a warning via the prompter if a deprecated enctype was used for +- * either the reply key or the session key. */ ++/* Display a warning via the prompter if des3-cbc-sha1 was used for either the ++ * reply key or the session key. */ + static void +-warn_deprecated(krb5_context context, krb5_init_creds_context ctx, +- krb5_enctype as_key_enctype) ++warn_des3(krb5_context context, krb5_init_creds_context ctx, ++ krb5_enctype as_key_enctype) + { +- krb5_enctype etype; +- char encbuf[128], banner[256]; ++ const char *banner; + +- if (ctx->prompter == NULL) +- return; +- +- if (krb5int_c_deprecated_enctype(as_key_enctype)) +- etype = as_key_enctype; +- else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype)) +- etype = ctx->cred.keyblock.enctype; +- else ++ if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 && ++ ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1) + return; +- +- if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0) ++ if (ctx->prompter == NULL) + return; +- snprintf(banner, sizeof(banner), +- _("Warning: encryption type %s used for authentication is " +- "deprecated and will be disabled"), encbuf); + ++ banner = _("Warning: encryption type des3-cbc-sha1 used for " ++ "authentication is weak and will be disabled"); + /* PROMPTER_INVOCATION */ + (*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL); + } +@@ -1857,7 +1848,7 @@ init_creds_step_reply(krb5_context context, + ctx->complete = TRUE; + warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, + ctx->in_tkt_service, ctx->reply); +- warn_deprecated(context, ctx, encrypting_key.enctype); ++ warn_des3(context, ctx, encrypting_key.enctype); + + cleanup: + krb5_free_pa_data(context, kdc_padata); +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index a6c2bbeb54..87b486c53f 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -221,16 +221,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_des3 = tmp; +- +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_rc4 = tmp; +- + retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index f5f11842e2..7494d7fcdb 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -18,8 +18,7 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. + supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', +- 'allow_des3': 'true', 'allow_rc4': 'true'}, ++conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 38cf96ca8f..c982508d8b 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,7 @@ + from k5test import * + + supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++conf = {'libdefaults': {'allow_weak_crypto': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 5a213617b5..9024aee838 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -25,8 +25,6 @@ conf3 = {'libdefaults': { + 'default_tkt_enctypes': 'aes128-cts', + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} +-conf5 = {'libdefaults': {'allow_rc4': 'true'}} +-conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -56,12 +54,10 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'aes128-cts,aes256-cts']) + test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + +-# 3b: Skip RC4 (as the KDC does not allow it for session keys by +-# default) and negotiate aes128-cts session key, with only an aes256 +-# long-term service key. ++# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) +-test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + realm.stop() + + # 4: Check that permitted_enctypes is a default for session key enctypes. +@@ -71,24 +67,4 @@ realm.run([kvno, 'user'], + expected_trace=('etypes requested in TGS request: aes256-cts',)) + realm.stop() + +-# 5: allow_rc4 permits negotiation of rc4-hmac session key. +-realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) +-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- +-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. +-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) +-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- +-# 7: default config negotiates aes256-sha1 session key for RC4-only service. +-realm = K5Realm(create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) +-test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac') +-realm.stop() +- + success('sesskeynego') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 8e5f5ba8e9..2a86c5cdfc 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1340,14 +1340,14 @@ _passes = [ + + # Exercise the DES3 enctype. + ('des3', None, +- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, ++ {'libdefaults': {'permitted_enctypes': 'des3'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'des3-cbc-sha1:normal', + 'master_key_type': 'des3-cbc-sha1'}}}), + + # Exercise the arcfour enctype. + ('arcfour', None, +- {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, ++ {'libdefaults': {'permitted_enctypes': 'rc4'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'arcfour-hmac:normal', + 'master_key_type': 'arcfour-hmac'}}}), +-- +2.45.1 + diff --git a/krb5-1.12.1-pam.patch b/0002-downstream-ksu-pam-integration.patch similarity index 95% rename from krb5-1.12.1-pam.patch rename to 0002-downstream-ksu-pam-integration.patch index 5372fb4..9afd094 100644 --- a/krb5-1.12.1-pam.patch +++ b/0002-downstream-ksu-pam-integration.patch @@ -1,7 +1,7 @@ -From e0924e10dd431a898c9c95faa04b51edbe59c5ef Mon Sep 17 00:00:00 2001 +From de4205c45e310ceaaa7cd7958af7293322fa43a6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 -Subject: [PATCH] krb5-1.12.1-pam.patch +Subject: [PATCH] [downstream] ksu pam integration Modify ksu so that it performs account and session management on behalf of the target user account, mimicking the action of regular su. The default @@ -16,25 +16,28 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. + +Last-updated: krb5-1.18-beta1 --- - src/aclocal.m4 | 67 ++++++++ + src/aclocal.m4 | 69 +++++++ src/clients/ksu/Makefile.in | 8 +- - src/clients/ksu/main.c | 88 +++++++++- - src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++++++++++ - src/clients/ksu/pam.h | 57 +++++++ - src/configure.in | 2 + - 6 files changed, 608 insertions(+), 3 deletions(-) + src/clients/ksu/main.c | 88 +++++++- + src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++ + src/clients/ksu/pam.h | 57 ++++++ + src/configure.ac | 2 + + 6 files changed, 610 insertions(+), 3 deletions(-) create mode 100644 src/clients/ksu/pam.c create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 9c46da4b5..508e5fe90 100644 +index 3d66a876b3..ce3c5a9bac 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1675,3 +1675,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ - ])) +@@ -1458,3 +1458,72 @@ if test "$with_ldap" = yes; then + OPENLDAP_PLUGIN=yes + fi ])dnl - dnl ++dnl +dnl +dnl Use PAM instead of local crypt() compare for checking local passwords, +dnl and perform PAM account, session management, and password-changing where @@ -102,12 +105,13 @@ index 9c46da4b5..508e5fe90 100644 +AC_SUBST(PAM_MAN) +AC_SUBST(NON_PAM_MAN) +])dnl ++ diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in -index b2fcbf240..5755bb58a 100644 +index 8b4edce4d8..9d58f29b5d 100644 --- a/src/clients/ksu/Makefile.in +++ b/src/clients/ksu/Makefile.in @@ -3,12 +3,14 @@ BUILDTOP=$(REL)..$(S).. - DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"' + DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"' KSU_LIBS=@KSU_LIBS@ +PAM_LIBS=@PAM_LIBS@ @@ -141,11 +145,11 @@ index b2fcbf240..5755bb58a 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 28342c2d7..cab0c1806 100644 +index af12861729..931f054041 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ - * KSU was writen by: Ari Medvinsky, ari@isi.edu + * KSU was written by: Ari Medvinsky, ari@isi.edu */ +#include "autoconf.h" @@ -171,7 +175,7 @@ index 28342c2d7..cab0c1806 100644 /***********/ #define KS_TEMPORARY_CACHE "MEMORY:_ksu" -@@ -515,6 +521,23 @@ main (argc, argv) +@@ -536,6 +542,23 @@ main (argc, argv) prog_name,target_user,client_name, source_user,ontty()); @@ -195,7 +199,7 @@ index 28342c2d7..cab0c1806 100644 /* Run authorization as target.*/ if (krb5_seteuid(target_uid)) { com_err(prog_name, errno, _("while switching to target for " -@@ -575,6 +598,24 @@ main (argc, argv) +@@ -596,6 +619,24 @@ main (argc, argv) exit(1); } @@ -220,7 +224,7 @@ index 28342c2d7..cab0c1806 100644 } if( some_rest_copy){ -@@ -632,6 +673,30 @@ main (argc, argv) +@@ -653,6 +694,30 @@ main (argc, argv) exit(1); } @@ -251,7 +255,7 @@ index 28342c2d7..cab0c1806 100644 /* set permissions */ if (setgid(target_pwd->pw_gid) < 0) { perror("ksu: setgid"); -@@ -729,7 +794,7 @@ main (argc, argv) +@@ -750,7 +815,7 @@ main (argc, argv) fprintf(stderr, "program to be execed %s\n",params[0]); } @@ -260,7 +264,7 @@ index 28342c2d7..cab0c1806 100644 execv(params[0], params); com_err(prog_name, errno, _("while trying to execv %s"), params[0]); sweep_up(ksu_context, cc_target); -@@ -759,16 +824,35 @@ main (argc, argv) +@@ -780,16 +845,35 @@ main (argc, argv) if (ret_pid == -1) { com_err(prog_name, errno, _("while calling waitpid")); } @@ -299,7 +303,7 @@ index 28342c2d7..cab0c1806 100644 } diff --git a/src/clients/ksu/pam.c b/src/clients/ksu/pam.c new file mode 100644 -index 000000000..cbfe48704 +index 0000000000..cbfe487047 --- /dev/null +++ b/src/clients/ksu/pam.c @@ -0,0 +1,389 @@ @@ -694,7 +698,7 @@ index 000000000..cbfe48704 +#endif diff --git a/src/clients/ksu/pam.h b/src/clients/ksu/pam.h new file mode 100644 -index 000000000..0ab76569c +index 0000000000..0ab76569cb --- /dev/null +++ b/src/clients/ksu/pam.h @@ -0,0 +1,57 @@ @@ -755,11 +759,11 @@ index 000000000..0ab76569c +int appl_pam_cred_init(void); +void appl_pam_cleanup(void); +#endif -diff --git a/src/configure.in b/src/configure.in -index 037c9f316..daabd12c8 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1336,6 +1336,8 @@ AC_SUBST([VERTO_VERSION]) +diff --git a/src/configure.ac b/src/configure.ac +index 77be7a2025..587221936e 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1399,6 +1399,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) @@ -768,3 +772,6 @@ index 037c9f316..daabd12c8 100644 # Make localedir work in autoconf 2.5x. if test "${localedir+set}" != set; then localedir='$(datadir)/locale' +-- +2.45.1 + diff --git a/krb5-1.15.1-selinux-label.patch b/0003-downstream-SELinux-integration.patch similarity index 82% rename from krb5-1.15.1-selinux-label.patch rename to 0003-downstream-SELinux-integration.patch index 2590f8e..a3b32c3 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/0003-downstream-SELinux-integration.patch @@ -1,7 +1,7 @@ -From aaf74b66a51cbda90ba40f73eb8def9b192ab262 Mon Sep 17 00:00:00 2001 +From 30ff501e4b519396f5aea25e24919be817863e7c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 -Subject: [PATCH] krb5-1.15.1-selinux-label.patch +Subject: [PATCH] [downstream] SELinux integration SELinux bases access to files on the domain of the requesting process, the operation being performed, and the context applied to the file. @@ -35,41 +35,44 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. + +Last-updated: krb5-1.20.1 +[jrische@redhat.com: Replace deprecated security_context_t by char *: + - src/util/support/selinux.c] --- - src/aclocal.m4 | 49 +++ - src/build-tools/krb5-config.in | 3 +- - src/config/pre.in | 3 +- - src/configure.in | 2 + - src/include/k5-int.h | 1 + - src/include/k5-label.h | 32 ++ - src/include/krb5/krb5.hin | 6 + - src/kadmin/dbutil/dump.c | 11 +- - src/kdc/main.c | 2 +- - src/lib/kadm5/logger.c | 4 +- - src/lib/kdb/kdb_log.c | 2 +- - src/lib/krb5/ccache/cc_dir.c | 26 +- - src/lib/krb5/keytab/kt_file.c | 4 +- - src/lib/krb5/os/trace.c | 2 +- - src/lib/krb5/rcache/rc_dfl.c | 13 + - src/plugins/kdb/db2/adb_openclose.c | 2 +- - src/plugins/kdb/db2/kdb_db2.c | 4 +- - src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +- - src/plugins/kdb/db2/libdb2/hash/hash.c | 3 +- - src/plugins/kdb/db2/libdb2/recno/rec_open.c | 4 +- - .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- - src/slave/kpropd.c | 9 + - src/util/profile/prof_file.c | 3 +- - src/util/support/Makefile.in | 3 +- - src/util/support/selinux.c | 406 +++++++++++++++++++++ - 25 files changed, 587 insertions(+), 21 deletions(-) + src/aclocal.m4 | 48 +++ + src/build-tools/krb5-config.in | 3 +- + src/config/pre.in | 3 +- + src/configure.ac | 2 + + src/include/k5-int.h | 1 + + src/include/k5-label.h | 32 ++ + src/include/krb5/krb5.hin | 6 + + src/kadmin/dbutil/dump.c | 11 +- + src/kdc/main.c | 2 +- + src/kprop/kpropd.c | 9 + + src/lib/kadm5/logger.c | 4 +- + src/lib/kdb/kdb_log.c | 2 +- + src/lib/krb5/ccache/cc_dir.c | 26 +- + src/lib/krb5/keytab/kt_file.c | 4 +- + src/lib/krb5/os/trace.c | 2 +- + src/plugins/kdb/db2/adb_openclose.c | 2 +- + src/plugins/kdb/db2/kdb_db2.c | 4 +- + src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +- + src/plugins/kdb/db2/libdb2/hash/hash.c | 3 +- + src/plugins/kdb/db2/libdb2/recno/rec_open.c | 4 +- + .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- + src/util/profile/prof_file.c | 3 +- + src/util/support/Makefile.in | 3 +- + src/util/support/selinux.c | 405 ++++++++++++++++++ + 24 files changed, 572 insertions(+), 21 deletions(-) create mode 100644 src/include/k5-label.h create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 508e5fe90..607859f17 100644 +index ce3c5a9bac..3331970930 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag) +@@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag) dnl KRB5_AC_PRAGMA_WEAK_REF WITH_LDAP @@ -77,7 +80,7 @@ index 508e5fe90..607859f17 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1742,3 +1743,51 @@ AC_SUBST(PAM_LIBS) +@@ -1526,4 +1527,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -100,7 +103,7 @@ index 508e5fe90..607859f17 100644 + AC_MSG_ERROR([Unable to locate selinux/selinux.h.]) + fi + fi -+ + + LIBS= + unset ac_cv_func_setfscreatecon + AC_CHECK_FUNCS(setfscreatecon selabel_open) @@ -130,10 +133,10 @@ index 508e5fe90..607859f17 100644 +AC_SUBST(SELINUX_LIBS) +])dnl diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index f6184da3f..c17cb5eb5 100755 +index 8e6eb86601..7677f37359 100755 --- a/src/build-tools/krb5-config.in +++ b/src/build-tools/krb5-config.in -@@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@' +@@ -40,6 +40,7 @@ DL_LIB='@DL_LIB@' DEFCCNAME='@DEFCCNAME@' DEFKTNAME='@DEFKTNAME@' DEFCKTNAME='@DEFCKTNAME@' @@ -141,7 +144,7 @@ index f6184da3f..c17cb5eb5 100755 LIBS='@LIBS@' GEN_LIB=@GEN_LIB@ -@@ -255,7 +256,7 @@ if test -n "$do_libs"; then +@@ -253,7 +254,7 @@ if test -n "$do_libs"; then fi # If we ever support a flag to generate output suitable for static @@ -151,7 +154,7 @@ index f6184da3f..c17cb5eb5 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index e0626320c..fcea229bd 100644 +index a0c60c70b3..7eaa2f351c 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -162,7 +165,7 @@ index e0626320c..fcea229bd 100644 INSTALL=@INSTALL@ INSTALL_STRIP= -@@ -399,7 +400,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) +@@ -379,7 +380,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) # HESIOD_LIBS is -lhesiod... HESIOD_LIBS = @HESIOD_LIBS@ @@ -170,12 +173,12 @@ index e0626320c..fcea229bd 100644 +KRB5_BASE_LIBS = $(KRB5_LIB) $(K5CRYPTO_LIB) $(COM_ERR_LIB) $(SUPPORT_LIB) $(GEN_LIB) $(LIBS) $(SELINUX_LIBS) $(DL_LIB) KDB5_LIBS = $(KDB5_LIB) $(GSSRPC_LIBS) GSS_LIBS = $(GSS_KRB5_LIB) - # needs fixing if ever used on Mac OS X! -diff --git a/src/configure.in b/src/configure.in -index daabd12c8..acf3a458b 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1338,6 +1338,8 @@ AC_PATH_PROG(GROFF, groff) + # needs fixing if ever used on macOS! +diff --git a/src/configure.ac b/src/configure.ac +index 587221936e..69be9030f8 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1401,6 +1401,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -185,7 +188,7 @@ index daabd12c8..acf3a458b 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 64991738a..173cb0264 100644 +index 1d1c8293f4..768110e5ef 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -198,7 +201,7 @@ index 64991738a..173cb0264 100644 #define KRB5_KDB_MAX_RLIFE (60*60*24*7) /* one week */ diff --git a/src/include/k5-label.h b/src/include/k5-label.h new file mode 100644 -index 000000000..dfaaa847c +index 0000000000..dfaaa847cb --- /dev/null +++ b/src/include/k5-label.h @@ -0,0 +1,32 @@ @@ -235,10 +238,10 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index ac22f4c55..cf60d6c41 100644 +index 4e09ed345d..09f800be52 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -87,6 +87,12 @@ +@@ -83,6 +83,12 @@ #define THREEPARAMOPEN(x,y,z) open(x,y,z) #endif @@ -252,7 +255,7 @@ index ac22f4c55..cf60d6c41 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index f7889bd23..cad53cfbf 100644 +index a89b5144f6..4d6cc0bdf9 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -277,20 +280,20 @@ index f7889bd23..cad53cfbf 100644 if (fd == -1) goto error; -@@ -194,7 +203,7 @@ prep_ok_file(krb5_context context, char *file_name, int *fd) - return 0; +@@ -197,7 +206,7 @@ prep_ok_file(krb5_context context, char *file_name, int *fd_out) + goto cleanup; } -- *fd = open(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); -+ *fd = THREEPARAMOPEN(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); - if (*fd == -1) { +- fd = open(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); ++ fd = THREEPARAMOPEN(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); + if (fd == -1) { com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); - exit_status++; + goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index ebc852bba..a4dffb29a 100644 +index bfdfef5c48..b43fe9a082 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -872,7 +872,7 @@ write_pid_file(const char *path) +@@ -844,7 +844,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -299,11 +302,41 @@ index ebc852bba..a4dffb29a 100644 if (file == NULL) return errno; pid = (unsigned long) getpid(); +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index aa3c81ea30..cb9785aaeb 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -488,6 +488,9 @@ doit(int fd) + krb5_enctype etype; + int database_fd; + char host[INET6_ADDRSTRLEN + 1]; ++#ifdef USE_SELINUX ++ void *selabel; ++#endif + + signal_wrapper(SIGALRM, alarm_handler); + alarm(params.iprop_resync_timeout); +@@ -543,9 +546,15 @@ doit(int fd) + free(name); + exit(1); + } ++#ifdef USE_SELINUX ++ selabel = krb5int_push_fscreatecon_for(file); ++#endif + omask = umask(077); + lock_fd = open(temp_file_name, O_RDWR | O_CREAT, 0600); + (void)umask(omask); ++#ifdef USE_SELINUX ++ krb5int_pop_fscreatecon(selabel); ++#endif + retval = krb5_lock_file(kpropd_context, lock_fd, + KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); + if (retval) { diff --git a/src/lib/kadm5/logger.c b/src/lib/kadm5/logger.c -index ce79fabf7..c53a5743f 100644 +index e14da53790..b879a4049b 100644 --- a/src/lib/kadm5/logger.c +++ b/src/lib/kadm5/logger.c -@@ -414,7 +414,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do +@@ -310,7 +310,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do */ append = (cp[4] == ':') ? O_APPEND : 0; if (append || cp[4] == '=') { @@ -312,7 +345,7 @@ index ce79fabf7..c53a5743f 100644 S_IRUSR | S_IWUSR | S_IRGRP); if (fd != -1) f = fdopen(fd, append ? "a" : "w"); -@@ -918,7 +918,7 @@ krb5_klog_reopen(krb5_context kcontext) +@@ -777,7 +777,7 @@ krb5_klog_reopen(krb5_context kcontext) * In case the old logfile did not get moved out of the * way, open for append to prevent squashing the old logs. */ @@ -322,20 +355,20 @@ index ce79fabf7..c53a5743f 100644 set_cloexec_file(f); log_control.log_entries[lindex].lfu_filep = f; diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c -index 766d3002a..6466417b7 100644 +index 2659a25018..e9b95fce59 100644 --- a/src/lib/kdb/kdb_log.c +++ b/src/lib/kdb/kdb_log.c -@@ -476,7 +476,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries) - int ulogfd = -1; +@@ -480,7 +480,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries) + return ENOMEM; if (stat(logname, &st) == -1) { -- ulogfd = open(logname, O_RDWR | O_CREAT, 0600); -+ ulogfd = THREEPARAMOPEN(logname, O_RDWR | O_CREAT, 0600); - if (ulogfd == -1) - return errno; - +- log_ctx->ulogfd = open(logname, O_RDWR | O_CREAT, 0600); ++ log_ctx->ulogfd = THREEPARAMOPEN(logname, O_RDWR | O_CREAT, 0600); + if (log_ctx->ulogfd == -1) { + retval = errno; + goto cleanup; diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c -index bba64e516..73f0fe62d 100644 +index 1da40b51d0..f3ab7340a6 100644 --- a/src/lib/krb5/ccache/cc_dir.c +++ b/src/lib/krb5/ccache/cc_dir.c @@ -183,10 +183,19 @@ write_primary_file(const char *primary_path, const char *contents) @@ -385,10 +418,10 @@ index bba64e516..73f0fe62d 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 6a42f267d..674d88bab 100644 +index e510211fc5..f3ea28c8ec 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c -@@ -1022,14 +1022,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) +@@ -735,14 +735,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) KTCHECKLOCK(id); errno = 0; @@ -406,10 +439,10 @@ index 6a42f267d..674d88bab 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 83c8d4db8..a19246128 100644 +index 4cbbbb270a..c4058ddc96 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c -@@ -397,7 +397,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) +@@ -460,7 +460,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) fd = malloc(sizeof(*fd)); if (fd == NULL) return ENOMEM; @@ -418,40 +451,8 @@ index 83c8d4db8..a19246128 100644 if (*fd == -1) { free(fd); return errno; -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index c4d2c744d..c0f12ed9d 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -794,6 +794,9 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - krb5_error_code retval = 0; - krb5_rcache tmp; - krb5_deltat lifespan = t->lifespan; /* save original lifespan */ -+#ifdef USE_SELINUX -+ void *selabel; -+#endif - - if (! t->recovering) { - name = t->name; -@@ -815,7 +818,17 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - retval = krb5_rc_resolve(context, tmp, 0); - if (retval) - goto cleanup; -+#ifdef USE_SELINUX -+ if (t->d.fn != NULL) -+ selabel = krb5int_push_fscreatecon_for(t->d.fn); -+ else -+ selabel = NULL; -+#endif - retval = krb5_rc_initialize(context, tmp, lifespan); -+#ifdef USE_SELINUX -+ if (selabel != NULL) -+ krb5int_pop_fscreatecon(selabel); -+#endif - if (retval) - goto cleanup; - for (q = t->a; q; q = q->na) { diff --git a/src/plugins/kdb/db2/adb_openclose.c b/src/plugins/kdb/db2/adb_openclose.c -index 7db30a33b..2b9d01921 100644 +index 9a506e9d44..f92ab47143 100644 --- a/src/plugins/kdb/db2/adb_openclose.c +++ b/src/plugins/kdb/db2/adb_openclose.c @@ -152,7 +152,7 @@ osa_adb_init_db(osa_adb_db_t *dbp, char *filename, char *lockfilename, @@ -464,7 +465,7 @@ index 7db30a33b..2b9d01921 100644 * maybe someone took away write permission so we could only * get shared locks? diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c -index 4c4036eb4..d90bdeaba 100644 +index 2c163d91cc..9a344a603e 100644 --- a/src/plugins/kdb/db2/kdb_db2.c +++ b/src/plugins/kdb/db2/kdb_db2.c @@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc) @@ -479,7 +480,7 @@ index 4c4036eb4..d90bdeaba 100644 retval = errno; goto cleanup; diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_open.c b/src/plugins/kdb/db2/libdb2/btree/bt_open.c -index 2977b17f3..d5809a5a9 100644 +index 2977b17f3a..d5809a5a93 100644 --- a/src/plugins/kdb/db2/libdb2/btree/bt_open.c +++ b/src/plugins/kdb/db2/libdb2/btree/bt_open.c @@ -60,6 +60,7 @@ static char sccsid[] = "@(#)bt_open.c 8.11 (Berkeley) 11/2/95"; @@ -500,7 +501,7 @@ index 2977b17f3..d5809a5a9 100644 } else { diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c -index 76f5d4709..1fa8b8389 100644 +index 862dbb1640..686a960c96 100644 --- a/src/plugins/kdb/db2/libdb2/hash/hash.c +++ b/src/plugins/kdb/db2/libdb2/hash/hash.c @@ -51,6 +51,7 @@ static char sccsid[] = "@(#)hash.c 8.12 (Berkeley) 11/7/95"; @@ -511,7 +512,7 @@ index 76f5d4709..1fa8b8389 100644 #include "db-int.h" #include "hash.h" #include "page.h" -@@ -140,7 +141,7 @@ __kdb2_hash_open(file, flags, mode, info, dflags) +@@ -129,7 +130,7 @@ __kdb2_hash_open(file, flags, mode, info, dflags) new_table = 1; } if (file) { @@ -521,7 +522,7 @@ index 76f5d4709..1fa8b8389 100644 (void)fcntl(hashp->fp, F_SETFD, 1); } diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_open.c b/src/plugins/kdb/db2/libdb2/recno/rec_open.c -index d8b26e701..b0daa7c02 100644 +index d8b26e7011..b0daa7c021 100644 --- a/src/plugins/kdb/db2/libdb2/recno/rec_open.c +++ b/src/plugins/kdb/db2/libdb2/recno/rec_open.c @@ -51,6 +51,7 @@ static char sccsid[] = "@(#)rec_open.c 8.12 (Berkeley) 11/18/94"; @@ -543,10 +544,10 @@ index d8b26e701..b0daa7c02 100644 if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) { diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index 022156a5e..3d6994c67 100644 +index e87688d666..30f7c00ab5 100644 --- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -@@ -203,7 +203,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -190,7 +190,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) /* set password in the file */ old_mode = umask(0177); @@ -555,7 +556,7 @@ index 022156a5e..3d6994c67 100644 if (pfile == NULL) { com_err(me, errno, _("Failed to open file %s: %s"), file_name, strerror (errno)); -@@ -244,6 +244,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -231,6 +231,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) * Delete the existing entry and add the new entry */ FILE *newfile; @@ -565,7 +566,7 @@ index 022156a5e..3d6994c67 100644 mode_t omask; -@@ -255,7 +258,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -242,7 +245,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) } omask = umask(077); @@ -579,38 +580,8 @@ index 022156a5e..3d6994c67 100644 umask (omask); if (newfile == NULL) { com_err(me, errno, _("Error creating file %s"), tmp_file); -diff --git a/src/slave/kpropd.c b/src/slave/kpropd.c -index 056c31a42..b78c3d9e5 100644 ---- a/src/slave/kpropd.c -+++ b/src/slave/kpropd.c -@@ -464,6 +464,9 @@ doit(int fd) - krb5_enctype etype; - int database_fd; - char host[INET6_ADDRSTRLEN + 1]; -+#ifdef USE_SELINUX -+ void *selabel; -+#endif - - signal_wrapper(SIGALRM, alarm_handler); - alarm(params.iprop_resync_timeout); -@@ -520,9 +523,15 @@ doit(int fd) - free(name); - exit(1); - } -+#ifdef USE_SELINUX -+ selabel = krb5int_push_fscreatecon_for(file); -+#endif - omask = umask(077); - lock_fd = open(temp_file_name, O_RDWR | O_CREAT, 0600); - (void)umask(omask); -+#ifdef USE_SELINUX -+ krb5int_pop_fscreatecon(selabel); -+#endif - retval = krb5_lock_file(kpropd_context, lock_fd, - KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); - if (retval) { diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index 907c119bb..0f5462aea 100644 +index aa951df05f..79f9500f69 100644 --- a/src/util/profile/prof_file.c +++ b/src/util/profile/prof_file.c @@ -33,6 +33,7 @@ @@ -621,7 +592,7 @@ index 907c119bb..0f5462aea 100644 struct global_shared_profile_data { /* This is the head of the global list of shared trees */ -@@ -423,7 +424,7 @@ static errcode_t write_data_to_file(prf_data_t data, const char *outfile, +@@ -391,7 +392,7 @@ static errcode_t write_data_to_file(prf_data_t data, const char *outfile, errno = 0; @@ -631,10 +602,10 @@ index 907c119bb..0f5462aea 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index 6239e4176..17bcd2a67 100644 +index 86d5a950a6..1052d53a1e 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in -@@ -69,6 +69,7 @@ IPC_SYMS= \ +@@ -74,6 +74,7 @@ IPC_SYMS= \ STLIBOBJS= \ threads.o \ @@ -642,7 +613,7 @@ index 6239e4176..17bcd2a67 100644 init-addrinfo.o \ plugins.o \ errors.o \ -@@ -148,7 +149,7 @@ SRCS=\ +@@ -168,7 +169,7 @@ SRCS=\ SHLIB_EXPDEPS = # Add -lm if dumping thread stats, for sqrt. @@ -653,10 +624,10 @@ index 6239e4176..17bcd2a67 100644 diff --git a/src/util/support/selinux.c b/src/util/support/selinux.c new file mode 100644 -index 000000000..6d41f3244 +index 0000000000..807d039da3 --- /dev/null +++ b/src/util/support/selinux.c -@@ -0,0 +1,406 @@ +@@ -0,0 +1,405 @@ +/* + * Copyright 2007,2008,2009,2011,2012,2013,2016 Red Hat, Inc. All Rights Reserved. + * @@ -755,17 +726,16 @@ index 000000000..6d41f3244 + } +} + -+static security_context_t ++static char * +push_fscreatecon(const char *pathname, mode_t mode) +{ -+ security_context_t previous, configuredsc, currentsc, derivedsc; ++ char *previous, *configuredsc, *currentsc, *genpath; ++ const char *derivedsc, *fullpath, *currentuser; + context_t current, derived; -+ const char *fullpath, *currentuser; -+ char *genpath; + -+ previous = configuredsc = currentsc = derivedsc = NULL; ++ previous = configuredsc = currentsc = genpath = NULL; ++ derivedsc = NULL; + current = derived = NULL; -+ genpath = NULL; + + fullpath = pathname; + @@ -893,7 +863,7 @@ index 000000000..6d41f3244 +} + +static void -+pop_fscreatecon(security_context_t previous) ++pop_fscreatecon(char *previous) +{ + if (!is_selinux_enabled()) { + return; @@ -947,7 +917,7 @@ index 000000000..6d41f3244 +{ + FILE *fp; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + if ((strcmp(mode, "r") == 0) || + (strcmp(mode, "rb") == 0)) { @@ -973,7 +943,7 @@ index 000000000..6d41f3244 +{ + int fd; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -994,7 +964,7 @@ index 000000000..6d41f3244 +{ + int ret; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -1015,7 +985,7 @@ index 000000000..6d41f3244 +{ + int ret; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -1036,7 +1006,7 @@ index 000000000..6d41f3244 +{ + int fd; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + mode_t mode; + va_list ap; + @@ -1063,3 +1033,6 @@ index 000000000..6d41f3244 +} + +#endif /* USE_SELINUX */ +-- +2.45.1 + diff --git a/krb5-1.9-debuginfo.patch b/0004-downstream-fix-debuginfo-with-y.tab.c.patch similarity index 85% rename from krb5-1.9-debuginfo.patch rename to 0004-downstream-fix-debuginfo-with-y.tab.c.patch index d3d0080..c21b269 100644 --- a/krb5-1.9-debuginfo.patch +++ b/0004-downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,18 +1,20 @@ -From e1d7fcf9713fe322ad5740045650dac86427e6ae Mon Sep 17 00:00:00 2001 +From 393830d96000ed692aa9a99ef87187d6f2863931 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 -Subject: [PATCH] krb5-1.9-debuginfo.patch +Subject: [PATCH] [downstream] fix debuginfo with y.tab.c We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. + +Last-updated: krb5-1.9 --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/src/kadmin/cli/Makefile.in b/src/kadmin/cli/Makefile.in -index adfea6e2b..d1327e400 100644 +index adfea6e2b5..d1327e400b 100644 --- a/src/kadmin/cli/Makefile.in +++ b/src/kadmin/cli/Makefile.in @@ -37,3 +37,8 @@ clean-unix:: @@ -25,7 +27,7 @@ index adfea6e2b..d1327e400 100644 + $(YACC.y) $< + $(CP) y.tab.c $@ diff --git a/src/plugins/kdb/ldap/ldap_util/Makefile.in b/src/plugins/kdb/ldap/ldap_util/Makefile.in -index 8669c2436..a22f23c02 100644 +index 8669c2436c..a22f23c02c 100644 --- a/src/plugins/kdb/ldap/ldap_util/Makefile.in +++ b/src/plugins/kdb/ldap/ldap_util/Makefile.in @@ -20,7 +20,7 @@ $(PROG): $(OBJS) $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIB) $(GETDATE) @@ -37,3 +39,6 @@ index 8669c2436..a22f23c02 100644 install: $(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG) +-- +2.45.1 + diff --git a/0005-downstream-Remove-3des-support.patch b/0005-downstream-Remove-3des-support.patch new file mode 100644 index 0000000..fcdb136 --- /dev/null +++ b/0005-downstream-Remove-3des-support.patch @@ -0,0 +1,6205 @@ +From 7d697742abb370cfc7241c1faa78ba08d7650f6a Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 26 Mar 2019 18:51:10 -0400 +Subject: [PATCH] [downstream] Remove 3des support + +Completely remove support for all DES3 enctypes (des3-cbc-raw, +des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation +to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain +their constants. + +Last-updated: 1.21.1-final +[antorres@redhat.com: remove diffs for: + - src/kdamin/testing/proto/kdc.conf.proto + - src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp + - src/lib/kadm5/unit-test/api.current/get-principal-v2.exp + - src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp + since they were removed by Remove-TCL-based-libkadm5-API-tests.patch] +[jrische@redhat.com: restore supportedCMSTypes (not using 3DES any more): + - src/plugins/preauth/pkinit/pkinit_crypto.h + - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c + - src/plugins/preauth/pkinit/pkinit_clnt.c] +--- + doc/admin/advanced/retiring-des.rst | 11 + + doc/admin/conf_files/kdc_conf.rst | 7 +- + doc/admin/enctypes.rst | 10 +- + doc/admin/troubleshoot.rst | 9 +- + doc/appdev/refs/macros/index.rst | 1 - + doc/conf.py | 2 +- + doc/mitK5features.rst | 2 +- + src/Makefile.in | 4 +- + src/configure.ac | 4 +- + src/include/krb5/krb5.hin | 10 +- + src/kdc/kdc_util.c | 4 - + src/lib/crypto/Makefile.in | 8 +- + src/lib/crypto/builtin/Makefile.in | 4 +- + src/lib/crypto/builtin/des/ISSUES | 13 - + src/lib/crypto/builtin/des/Makefile.in | 82 ---- + src/lib/crypto/builtin/des/d3_aead.c | 137 ------ + src/lib/crypto/builtin/des/d3_kysched.c | 55 --- + src/lib/crypto/builtin/des/deps | 146 ------- + src/lib/crypto/builtin/des/des_int.h | 285 ------------- + src/lib/crypto/builtin/des/des_keys.c | 38 -- + src/lib/crypto/builtin/des/destest.c | 240 ----------- + src/lib/crypto/builtin/des/doc/libdes.doc | 208 --------- + src/lib/crypto/builtin/des/f_aead.c | 177 -------- + src/lib/crypto/builtin/des/f_cbc.c | 256 ------------ + src/lib/crypto/builtin/des/f_cksum.c | 141 ------- + src/lib/crypto/builtin/des/f_parity.c | 64 --- + src/lib/crypto/builtin/des/f_sched.c | 363 ---------------- + src/lib/crypto/builtin/des/f_tables.c | 375 ----------------- + src/lib/crypto/builtin/des/f_tables.h | 285 ------------- + src/lib/crypto/builtin/des/key_sched.c | 66 --- + src/lib/crypto/builtin/des/keytest.data | 171 -------- + src/lib/crypto/builtin/des/t_verify.c | 395 ------------------ + src/lib/crypto/builtin/des/weak_key.c | 90 ---- + .../crypto/builtin/enc_provider/Makefile.in | 5 +- + src/lib/crypto/builtin/enc_provider/deps | 11 - + src/lib/crypto/builtin/enc_provider/des3.c | 109 ----- + src/lib/crypto/crypto_tests/t_cf2.expected | 1 - + src/lib/crypto/crypto_tests/t_cf2.in | 5 - + src/lib/crypto/crypto_tests/t_cksums.c | 10 - + src/lib/crypto/crypto_tests/t_decrypt.c | 57 --- + src/lib/crypto/crypto_tests/t_derive.c | 36 -- + src/lib/crypto/crypto_tests/t_encrypt.c | 1 - + src/lib/crypto/crypto_tests/t_short.c | 1 - + src/lib/crypto/crypto_tests/t_str2key.c | 52 --- + src/lib/crypto/crypto_tests/vectors.c | 4 - + src/lib/crypto/krb/Makefile.in | 3 - + src/lib/crypto/krb/cksumtypes.c | 6 - + src/lib/crypto/krb/crypto_int.h | 11 - + src/lib/crypto/krb/default_state.c | 10 - + src/lib/crypto/krb/enctype_util.c | 3 + + src/lib/crypto/krb/etypes.c | 21 - + src/lib/crypto/krb/prf_des.c | 47 --- + src/lib/crypto/krb/random_to_key.c | 28 -- + src/lib/crypto/libk5crypto.exports | 1 - + src/lib/crypto/openssl/Makefile.in | 4 +- + src/lib/crypto/openssl/des/Makefile.in | 20 - + src/lib/crypto/openssl/des/deps | 14 - + src/lib/crypto/openssl/des/des_keys.c | 39 -- + .../crypto/openssl/enc_provider/Makefile.in | 3 - + src/lib/crypto/openssl/enc_provider/deps | 11 - + src/lib/crypto/openssl/enc_provider/des3.c | 188 --------- + src/lib/crypto/openssl/kdf.c | 2 - + src/lib/gssapi/krb5/accept_sec_context.c | 1 - + src/lib/gssapi/krb5/gssapiP_krb5.h | 6 +- + src/lib/gssapi/krb5/k5seal.c | 35 +- + src/lib/gssapi/krb5/k5sealiov.c | 27 +- + src/lib/gssapi/krb5/k5unseal.c | 88 ++-- + src/lib/gssapi/krb5/k5unsealiov.c | 38 +- + src/lib/gssapi/krb5/util_crypt.c | 11 - + src/lib/krb5/krb/init_ctx.c | 3 - + src/lib/krb5/krb/s4u_creds.c | 2 - + src/lib/krb5/krb/t_etypes.c | 48 +-- + src/lib/krb5/os/t_trace.c | 4 +- + src/lib/krb5/os/t_trace.ref | 2 +- + src/plugins/preauth/pkinit/pkcs11.h | 6 +- + src/plugins/preauth/pkinit/pkinit_crypto.h | 10 +- + src/plugins/preauth/pkinit/pkinit_kdf_test.c | 30 -- + src/plugins/preauth/spake/t_vectors.c | 25 -- + src/tests/gssapi/t_enctypes.py | 33 +- + src/tests/gssapi/t_invalid.c | 12 - + src/tests/gssapi/t_pcontok.c | 16 +- + src/tests/gssapi/t_prf.c | 7 - + src/tests/t_authdata.py | 2 +- + src/tests/t_etype_info.py | 21 +- + src/tests/t_keyrollover.py | 8 +- + src/tests/t_mkey.py | 35 -- + src/tests/t_salt.py | 5 +- + src/util/k5test.py | 7 - + .../leash/htmlhelp/html/Encryption_Types.htm | 13 - + 89 files changed, 149 insertions(+), 4712 deletions(-) + delete mode 100644 src/lib/crypto/builtin/des/ISSUES + delete mode 100644 src/lib/crypto/builtin/des/Makefile.in + delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c + delete mode 100644 src/lib/crypto/builtin/des/d3_kysched.c + delete mode 100644 src/lib/crypto/builtin/des/deps + delete mode 100644 src/lib/crypto/builtin/des/des_int.h + delete mode 100644 src/lib/crypto/builtin/des/des_keys.c + delete mode 100644 src/lib/crypto/builtin/des/destest.c + delete mode 100644 src/lib/crypto/builtin/des/doc/libdes.doc + delete mode 100644 src/lib/crypto/builtin/des/f_aead.c + delete mode 100644 src/lib/crypto/builtin/des/f_cbc.c + delete mode 100644 src/lib/crypto/builtin/des/f_cksum.c + delete mode 100644 src/lib/crypto/builtin/des/f_parity.c + delete mode 100644 src/lib/crypto/builtin/des/f_sched.c + delete mode 100644 src/lib/crypto/builtin/des/f_tables.c + delete mode 100644 src/lib/crypto/builtin/des/f_tables.h + delete mode 100644 src/lib/crypto/builtin/des/key_sched.c + delete mode 100644 src/lib/crypto/builtin/des/keytest.data + delete mode 100644 src/lib/crypto/builtin/des/t_verify.c + delete mode 100644 src/lib/crypto/builtin/des/weak_key.c + delete mode 100644 src/lib/crypto/builtin/enc_provider/des3.c + delete mode 100644 src/lib/crypto/krb/prf_des.c + delete mode 100644 src/lib/crypto/openssl/des/Makefile.in + delete mode 100644 src/lib/crypto/openssl/des/deps + delete mode 100644 src/lib/crypto/openssl/des/des_keys.c + delete mode 100644 src/lib/crypto/openssl/enc_provider/des3.c + +diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst +index 38f76d3f45..d5e3c30c04 100644 +--- a/doc/admin/advanced/retiring-des.rst ++++ b/doc/admin/advanced/retiring-des.rst +@@ -10,6 +10,13 @@ ability have rendered DES vulnerable to brute force attacks on its 56-bit + keyspace. As such, it is now considered insecure and should not be + used (:rfc:`6649`). + ++In 1999, MIT krb5 added support for Triple-DES (3DES) encryption types. ++However, due to weakenings of DES and other security concerns, it is now also ++considered insecure and should not be used (:rfc:`8429`). AES encryption ++types were added to MIT in 2003, meaning that the number of deployments with ++3DES as the strongest encryption type is hopefully small. The rotation ++procedure described herein works for both DES and 3DES. ++ + History + ------- + +@@ -27,6 +34,10 @@ and removed DES (single-DES) support in release 1.18. As a + consequence, a release prior to 1.18 is required to perform these + migrations. + ++3DES (a flagged deprecated encryption type) was also removed downstream by ++rharwood@redhat.com starting in 1.18; likewise, a pre-1.18 release is required ++to perform these migrations. ++ + Types of keys + ------------- + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 74a0a2acef..846c58ed82 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -854,8 +854,6 @@ Encryption types marked as "weak" and "deprecated" are available for + compatibility but not recommended for use. + + ==================================================== ========================================================= +-des3-cbc-raw Triple DES cbc mode raw (weak) +-des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 (deprecated) + aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC + aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC + aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC +@@ -864,7 +862,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 (deprecat + arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) + camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC + camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC +-des3 The triple DES family: des3-cbc-sha1 + aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 + rc4 The RC4 family: arcfour-hmac + camellia The Camellia family: camellia256-cts-cmac and camellia128-cts-cmac +@@ -876,8 +873,8 @@ from the current list by prefixing them with a minus sign ("-"). + Types or families can be prefixed with a plus sign ("+") for symmetry; + it has the same meaning as just listing the type or family. For + example, "``DEFAULT -rc4``" would be the default set of encryption +-types with RC4 types removed, and "``des3 DEFAULT``" would be the +-default set of encryption types with triple DES types moved to the ++types with RC4 types removed, and "``aes128-sha2 DEFAULT``" would be ++the default set of encryption types with aes128-sha2 moved to the + front. + + While **aes128-cts** and **aes256-cts** are supported for all Kerberos +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index 694922c0d9..c4d5499d3b 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -129,7 +129,7 @@ enctype weak? krb5 Windows + des-cbc-crc weak <1.18 >=2000 + des-cbc-md4 weak <1.18 ? + des-cbc-md5 weak <1.18 >=2000 +-des3-cbc-sha1 deprecated >=1.1 none ++des3-cbc-sha1 deprecated <1.18 none + arcfour-hmac deprecated >=1.3 >=2000 + arcfour-hmac-exp weak >=1.3 >=2000 + aes128-cts-hmac-sha1-96 >=1.3 >=Vista +@@ -148,9 +148,11 @@ default. + krb5 releases 1.17 and later flag deprecated encryption types + (including ``des3-cbc-sha1`` and ``arcfour-hmac``) in KDC logs and + kadmin output. krb5 release 1.19 issues a warning during initial +-authentication if ``des3-cbc-sha1`` is used. Future releases will +-disable ``des3-cbc-sha1`` by default and eventually remove support for +-it. ++authentication if ``des3-cbc-sha1`` is used. ++ ++krb5 releases 1.18 and later remove single-DES and 3DES ++(downstream-only patch) enctype support. Microsoft Windows never ++supported 3DES. + + + Migrating away from older encryption types +diff --git a/doc/admin/troubleshoot.rst b/doc/admin/troubleshoot.rst +index ade5e1f87a..e4dc54f7e5 100644 +--- a/doc/admin/troubleshoot.rst ++++ b/doc/admin/troubleshoot.rst +@@ -73,11 +73,10 @@ credential verification failed: KDC has no support for encryption type + ...................................................................... + + This most commonly happens when trying to use a principal with only +-DES keys, in a release (MIT krb5 1.7 or later) which disables DES by +-default. DES encryption is considered weak due to its inadequate key +-size. If you cannot migrate away from its use, you can re-enable DES +-by adding ``allow_weak_crypto = true`` to the :ref:`libdefaults` +-section of :ref:`krb5.conf(5)`. ++DES/3DES keys, in a release (MIT krb5 1.7 or later) which disables DES ++by default. DES encryption is considered weak due to its inadequate ++key size and has been removed upstream; 3DES is not recommended, and ++has been removed downstream by rharwood@redhat.com. + + + .. _err_cert_chain_cert_expired: +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index 45fe160d7f..b4b1f3bd93 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -36,7 +36,6 @@ Public + CKSUMTYPE_HMAC_SHA1_96_AES256.rst + CKSUMTYPE_HMAC_SHA256_128_AES128.rst + CKSUMTYPE_HMAC_SHA384_192_AES256.rst +- CKSUMTYPE_HMAC_SHA1_DES3.rst + CKSUMTYPE_MD5_HMAC_ARCFOUR.rst + CKSUMTYPE_NIST_SHA.rst + CKSUMTYPE_RSA_MD4.rst +diff --git a/doc/conf.py b/doc/conf.py +index ecf9020a72..db7fa377ef 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -281,7 +281,7 @@ else: + rst_epilog += ''' + .. |krb5conf| replace:: ``/etc/krb5.conf`` + .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` +-.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` ++.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` + .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` + .. |copy| unicode:: U+000A9 + ''' +diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst +index 10effcf175..cad0855724 100644 +--- a/doc/mitK5features.rst ++++ b/doc/mitK5features.rst +@@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB + + krb4 support: Kerberos 5 release < 1.8 + +-DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) ++DES/3DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) + + Interoperability + ---------------- +diff --git a/src/Makefile.in b/src/Makefile.in +index 8f14e9bf2c..ba3bb18eec 100644 +--- a/src/Makefile.in ++++ b/src/Makefile.in +@@ -130,7 +130,7 @@ WINMAKEFILES=Makefile \ + lib\Makefile lib\crypto\Makefile lib\crypto\krb\Makefile \ + lib\crypto\builtin\Makefile lib\crypto\builtin\aes\Makefile \ + lib\crypto\builtin\enc_provider\Makefile \ +- lib\crypto\builtin\des\Makefile lib\crypto\builtin\md5\Makefile \ ++ lib\crypto\builtin\md5\Makefile \ + lib\crypto\builtin\camellia\Makefile lib\crypto\builtin\md4\Makefile \ + lib\crypto\builtin\hash_provider\Makefile \ + lib\crypto\builtin\sha2\Makefile lib\crypto\builtin\sha1\Makefile \ +@@ -202,8 +202,6 @@ WINMAKEFILES=Makefile \ + ##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\enc_provider\Makefile: lib\crypto\builtin\enc_provider\Makefile.in $(MKFDEP) + ##DOS## $(WCONFIG) config < $@.in > $@ +-##DOS##lib\crypto\builtin\des\Makefile: lib\crypto\builtin\des\Makefile.in $(MKFDEP) +-##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\md5\Makefile: lib\crypto\builtin\md5\Makefile.in $(MKFDEP) + ##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) +diff --git a/src/configure.ac b/src/configure.ac +index 69be9030f8..2561e917a2 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1513,12 +1513,12 @@ V5_AC_OUTPUT_MAKEFILE(. + lib lib/kdb + + lib/crypto lib/crypto/krb lib/crypto/crypto_tests +- lib/crypto/builtin lib/crypto/builtin/des ++ lib/crypto/builtin + lib/crypto/builtin/aes lib/crypto/builtin/camellia + lib/crypto/builtin/md4 lib/crypto/builtin/md5 + lib/crypto/builtin/sha1 lib/crypto/builtin/sha2 + lib/crypto/builtin/enc_provider lib/crypto/builtin/hash_provider +- lib/crypto/openssl lib/crypto/openssl/des ++ lib/crypto/openssl + lib/crypto/openssl/enc_provider lib/crypto/openssl/hash_provider + + lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 09f800be52..c5a625db8f 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -422,8 +422,8 @@ typedef struct _krb5_crypto_iov { + #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated no longer supported */ +-#define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated DES-3 cbc with SHA1 */ +-#define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated DES-3 cbc mode raw */ ++#define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated no longer supported */ ++#define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated no longer supported */ + /* PKINIT */ + #define ENCTYPE_DSA_SHA1_CMS 0x0009 /**< DSA with SHA1, CMS signature */ +@@ -432,9 +432,9 @@ typedef struct _krb5_crypto_iov { + #define ENCTYPE_RC2_CBC_ENV 0x000c /**< RC2 cbc mode, CMS enveloped data */ + #define ENCTYPE_RSA_ENV 0x000d /**< RSA encryption, CMS enveloped data */ + #define ENCTYPE_RSA_ES_OAEP_ENV 0x000e /**< RSA w/OEAP encryption, CMS enveloped data */ +-#define ENCTYPE_DES3_CBC_ENV 0x000f /**< DES-3 cbc mode, CMS enveloped data */ ++#define ENCTYPE_DES3_CBC_ENV 0x000f /**< @deprecated no longer supported */ + +-#define ENCTYPE_DES3_CBC_SHA1 0x0010 ++#define ENCTYPE_DES3_CBC_SHA1 0x0010 /**< @deprecated removed */ + #define ENCTYPE_AES128_CTS_HMAC_SHA1_96 0x0011 /**< RFC 3962 */ + #define ENCTYPE_AES256_CTS_HMAC_SHA1_96 0x0012 /**< RFC 3962 */ + #define ENCTYPE_AES128_CTS_HMAC_SHA256_128 0x0013 /**< RFC 8009 */ +@@ -459,7 +459,7 @@ typedef struct _krb5_crypto_iov { + #define CKSUMTYPE_RSA_MD5 0x0007 + #define CKSUMTYPE_RSA_MD5_DES 0x0008 + #define CKSUMTYPE_NIST_SHA 0x0009 +-#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c ++#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c /* @deprecated removed */ + #define CKSUMTYPE_SHA1 0x000e /**< RFC 3961 */ + #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with + ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 75e04b73db..fe4e48209a 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1154,8 +1154,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + name = "rsaEncryption-EnvOID"; + else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) + name = "id-RSAES-OAEP-EnvOID"; +- else if (ktype == ENCTYPE_DES3_CBC_ENV) +- name = "des-ede3-cbc-EnvOID"; + else + return krb5_enctype_to_name(ktype, FALSE, buf, buflen); + +@@ -1647,8 +1645,6 @@ krb5_boolean + enctype_requires_etype_info_2(krb5_enctype enctype) + { + switch(enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP : + return 0; +diff --git a/src/lib/crypto/Makefile.in b/src/lib/crypto/Makefile.in +index 10e8c74cf8..25c4f40cc3 100644 +--- a/src/lib/crypto/Makefile.in ++++ b/src/lib/crypto/Makefile.in +@@ -10,12 +10,12 @@ LIBMINOR=1 + RELDIR=crypto + + STOBJLISTS=krb/OBJS.ST \ +- builtin/OBJS.ST builtin/des/OBJS.ST \ ++ builtin/OBJS.ST \ + builtin/aes/OBJS.ST builtin/camellia/OBJS.ST \ + builtin/md4/OBJS.ST builtin/md5/OBJS.ST \ + builtin/sha1/OBJS.ST builtin/sha2/OBJS.ST \ + builtin/enc_provider/OBJS.ST builtin/hash_provider/OBJS.ST \ +- openssl/OBJS.ST openssl/des/OBJS.ST \ ++ openssl/OBJS.ST \ + openssl/enc_provider/OBJS.ST openssl/hash_provider/OBJS.ST + + SUBDIROBJLISTS=$(STOBJLISTS) +@@ -28,8 +28,8 @@ SHLIB_EXPDEPLIBS= $(SUPPORT_DEPLIB) + SHLIB_LDFLAGS= $(LDFLAGS) @SHLIB_RPATH_DIRS@ + + ##DOS##LIBNAME=$(OUTPRE)crypto.lib +-##DOS##OBJFILEDEP=$(OUTPRE)krb.lst $(OUTPRE)aes.lst $(OUTPRE)enc_provider.lst $(OUTPRE)des.lst $(OUTPRE)md5.lst $(OUTPRE)camellia.lst $(OUTPRE)md4.lst $(OUTPRE)hash_provider.lst $(OUTPRE)sha2.lst $(OUTPRE)sha1.lst $(OUTPRE)builtin.lst +-##DOS##OBJFILELIST=@$(OUTPRE)krb.lst @$(OUTPRE)aes.lst @$(OUTPRE)enc_provider.lst @$(OUTPRE)des.lst @$(OUTPRE)md5.lst @$(OUTPRE)camellia.lst @$(OUTPRE)md4.lst @$(OUTPRE)hash_provider.lst @$(OUTPRE)sha2.lst @$(OUTPRE)sha1.lst @$(OUTPRE)builtin.lst ++##DOS##OBJFILEDEP=$(OUTPRE)krb.lst $(OUTPRE)aes.lst $(OUTPRE)enc_provider.lst $(OUTPRE)md5.lst $(OUTPRE)camellia.lst $(OUTPRE)md4.lst $(OUTPRE)hash_provider.lst $(OUTPRE)sha2.lst $(OUTPRE)sha1.lst $(OUTPRE)builtin.lst ++##DOS##OBJFILELIST=@$(OUTPRE)krb.lst @$(OUTPRE)aes.lst @$(OUTPRE)enc_provider.lst @$(OUTPRE)md5.lst @$(OUTPRE)camellia.lst @$(OUTPRE)md4.lst @$(OUTPRE)hash_provider.lst @$(OUTPRE)sha2.lst @$(OUTPRE)sha1.lst @$(OUTPRE)builtin.lst + + all-unix: all-liblinks + install-unix: install-libs +diff --git a/src/lib/crypto/builtin/Makefile.in b/src/lib/crypto/builtin/Makefile.in +index 243bb17ba3..30bfcd30c0 100644 +--- a/src/lib/crypto/builtin/Makefile.in ++++ b/src/lib/crypto/builtin/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)crypto$(S)builtin + BUILDTOP=$(REL)..$(S)..$(S).. +-SUBDIRS=camellia des aes md4 md5 sha1 sha2 enc_provider hash_provider ++SUBDIRS=camellia aes md4 md5 sha1 sha2 enc_provider hash_provider + LOCALINCLUDES=-I$(srcdir)/../krb $(CRYPTO_IMPL_CFLAGS) + + ##DOS##BUILDTOP = ..\..\.. +@@ -25,7 +25,7 @@ SRCS=\ + $(srcdir)/kdf.c \ + $(srcdir)/pbkdf2.c + +-SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ +diff --git a/src/lib/crypto/builtin/des/ISSUES b/src/lib/crypto/builtin/des/ISSUES +deleted file mode 100644 +index 1578911033..0000000000 +--- a/src/lib/crypto/builtin/des/ISSUES ++++ /dev/null +@@ -1,13 +0,0 @@ +-Issues to be addressed for src/lib/crypto/des: -*- text -*- +- +- +-"const" could be used in more places +- +- +-Array types are used in calling interfaces. Under ANSI C, a value of +-type "arraytype *" cannot be assigned to a variable of type "const +-arraytype *", so we get compilation warnings. +- +-Possible fix: Rewrite internal interfaces to not use arrays this way. +-Provide external routines compatible with old API, but not using +-const? +diff --git a/src/lib/crypto/builtin/des/Makefile.in b/src/lib/crypto/builtin/des/Makefile.in +deleted file mode 100644 +index 397ac87ed4..0000000000 +--- a/src/lib/crypto/builtin/des/Makefile.in ++++ /dev/null +@@ -1,82 +0,0 @@ +-mydir=lib$(S)crypto$(S)builtin$(S)des +-BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES=-I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) +- +-##DOS##BUILDTOP = ..\..\..\.. +-##DOS##PREFIXDIR = builtin\des +-##DOS##OBJFILE = ..\..\$(OUTPRE)des.lst +- +-STLIBOBJS=\ +- d3_aead.o \ +- d3_kysched.o \ +- des_keys.o \ +- f_aead.o \ +- f_cksum.o \ +- f_parity.o \ +- f_sched.o \ +- f_tables.o \ +- key_sched.o \ +- weak_key.o +- +-OBJS= $(OUTPRE)d3_aead.$(OBJEXT) \ +- $(OUTPRE)d3_kysched.$(OBJEXT) \ +- $(OUTPRE)des_keys.$(OBJEXT) \ +- $(OUTPRE)f_aead.$(OBJEXT) \ +- $(OUTPRE)f_cksum.$(OBJEXT) \ +- $(OUTPRE)f_parity.$(OBJEXT) \ +- $(OUTPRE)f_sched.$(OBJEXT) \ +- $(OUTPRE)f_tables.$(OBJEXT) \ +- $(OUTPRE)key_sched.$(OBJEXT) \ +- $(OUTPRE)weak_key.$(OBJEXT) +- +-SRCS= $(srcdir)/d3_aead.c \ +- $(srcdir)/d3_kysched.c \ +- $(srcdir)/des_keys.c \ +- $(srcdir)/f_aead.c \ +- $(srcdir)/f_cksum.c \ +- $(srcdir)/f_parity.c \ +- $(srcdir)/f_sched.c \ +- $(srcdir)/f_tables.c \ +- $(srcdir)/key_sched.c \ +- $(srcdir)/weak_key.c +- +-EXTRADEPSRCS = $(srcdir)/destest.c $(srcdir)/f_cbc.c $(srcdir)/t_verify.c +- +-##DOS##LIBOBJS = $(OBJS) +- +-TOBJS = $(OUTPRE)key_sched.$(OBJEXT) $(OUTPRE)f_sched.$(OBJEXT) \ +- $(OUTPRE)f_cbc.$(OBJEXT) $(OUTPRE)f_tables.$(OBJEXT) \ +- $(OUTPRE)f_cksum.$(OBJEXT) +- +-verify$(EXEEXT): t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ +- $(COM_ERR_DEPLIB) $(SUPPORT_DEPLIB) +- $(CC_LINK) -o $@ t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ +- $(COM_ERR_LIB) $(SUPPORT_LIB) +- +-destest$(EXEEXT): destest.$(OBJEXT) $(TOBJS) $(SUPPORT_DEPLIB) +- $(CC_LINK) -o $@ destest.$(OBJEXT) $(TOBJS) $(SUPPORT_LIB) +- +-all-unix: all-libobjs +- +-check-unix: check-unix-@CRYPTO_BUILTIN_TESTS@ +-check-unix-no: +-check-unix-yes: verify destest +- $(RUN_TEST) ./verify -z +- $(RUN_TEST) ./verify -m +- $(RUN_TEST) ./verify +- $(RUN_TEST) ./destest < $(srcdir)/keytest.data +- +-includes: depend +- +-depend: $(SRCS) +- +-check-windows: +- +-clean: +- $(RM) destest.$(OBJEXT) destest$(EXEEXT) verify$(EXEEXT) \ +- t_verify.$(OBJEXT) $(TOBJS) +- +-clean-unix:: clean-libobjs +- +-@libobj_frag@ +- +diff --git a/src/lib/crypto/builtin/des/d3_aead.c b/src/lib/crypto/builtin/des/d3_aead.c +deleted file mode 100644 +index fb83f73b43..0000000000 +--- a/src/lib/crypto/builtin/des/d3_aead.c ++++ /dev/null +@@ -1,137 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 2008 by the Massachusetts Institute of Technology. +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-#ifdef K5_BUILTIN_DES +- +-void +-krb5int_des3_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp1, *kp2, *kp3; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointers here. These won't need to be reinitialized. */ +- kp1 = (const unsigned DES_INT32 *)ks1; +- kp2 = (const unsigned DES_INT32 *)ks2; +- kp3 = (const unsigned DES_INT32 *)ks3; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* xor this block with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have and store it back into block. */ +- DES_DO_ENCRYPT(left, right, kp1); +- DES_DO_DECRYPT(left, right, kp2); +- DES_DO_ENCRYPT(left, right, kp3); +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(left, ivec); +- store_32_be(right, ivec + 4); +- } +-} +- +-void +-krb5int_des3_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp1, *kp2, *kp3; +- const unsigned char *ip; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointers here. These won't need to be reinitialized. */ +- kp1 = (const unsigned DES_INT32 *)ks1; +- kp2 = (const unsigned DES_INT32 *)ks2; +- kp3 = (const unsigned DES_INT32 *)ks3; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- /* Prime the old cipher with ivec.*/ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- ocipherl = load_32_be(ip); +- ocipherr = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Split this block into left and right. */ +- cipherl = left = load_32_be(block); +- cipherr = right = load_32_be(block + 4); +- +- /* Decrypt and xor with the old cipher to get plain text. */ +- DES_DO_DECRYPT(left, right, kp3); +- DES_DO_ENCRYPT(left, right, kp2); +- DES_DO_DECRYPT(left, right, kp1); +- left ^= ocipherl; +- right ^= ocipherr; +- +- /* Store the encrypted halves back into block. */ +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- /* Save current cipher block halves. */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(ocipherl, ivec); +- store_32_be(ocipherr, ivec + 4); +- } +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/d3_kysched.c b/src/lib/crypto/builtin/des/d3_kysched.c +deleted file mode 100644 +index 55fb9449b5..0000000000 +--- a/src/lib/crypto/builtin/des/d3_kysched.c ++++ /dev/null +@@ -1,55 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES +- +-int +-mit_des3_key_sched(mit_des3_cblock k, mit_des3_key_schedule schedule) +-{ +- mit_des_make_key_sched(k[0],schedule[0]); +- mit_des_make_key_sched(k[1],schedule[1]); +- mit_des_make_key_sched(k[2],schedule[2]); +- +- if (!mit_des_check_key_parity(k[0])) /* bad parity --> return -1 */ +- return(-1); +- if (mit_des_is_weak_key(k[0])) +- return(-2); +- +- if (!mit_des_check_key_parity(k[1])) +- return(-1); +- if (mit_des_is_weak_key(k[1])) +- return(-2); +- +- if (!mit_des_check_key_parity(k[2])) +- return(-1); +- if (mit_des_is_weak_key(k[2])) +- return(-2); +- +- /* if key was good, return 0 */ +- return 0; +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/deps b/src/lib/crypto/builtin/des/deps +deleted file mode 100644 +index 1c1239d696..0000000000 +--- a/src/lib/crypto/builtin/des/deps ++++ /dev/null +@@ -1,146 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-d3_aead.so d3_aead.po $(OUTPRE)d3_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- d3_aead.c des_int.h f_tables.h +-d3_kysched.so d3_kysched.po $(OUTPRE)d3_kysched.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h d3_kysched.c des_int.h +-des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h des_keys.c +-f_aead.so f_aead.po $(OUTPRE)f_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_aead.c f_tables.h +-f_cksum.so f_cksum.po $(OUTPRE)f_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_cksum.c f_tables.h +-f_parity.so f_parity.po $(OUTPRE)f_parity.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_parity.c +-f_sched.so f_sched.po $(OUTPRE)f_sched.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_sched.c +-f_tables.so f_tables.po $(OUTPRE)f_tables.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_tables.c \ +- f_tables.h +-key_sched.so key_sched.po $(OUTPRE)key_sched.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h key_sched.c +-weak_key.so weak_key.po $(OUTPRE)weak_key.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h weak_key.c +-destest.so destest.po $(OUTPRE)destest.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h destest.c +-f_cbc.so f_cbc.po $(OUTPRE)f_cbc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_cbc.c \ +- f_tables.h +-t_verify.so t_verify.po $(OUTPRE)t_verify.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h t_verify.c +diff --git a/src/lib/crypto/builtin/des/des_int.h b/src/lib/crypto/builtin/des/des_int.h +deleted file mode 100644 +index f8dc6b296a..0000000000 +--- a/src/lib/crypto/builtin/des/des_int.h ++++ /dev/null +@@ -1,285 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/des_int.h */ +-/* +- * Copyright 1987, 1988, 1990, 2002 by the Massachusetts Institute of +- * Technology. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* Private include file for the Data Encryption Standard library. */ +- +-/* only do the whole thing once */ +-#ifndef DES_INTERNAL_DEFS +-#define DES_INTERNAL_DEFS +- +-#include "k5-int.h" +-/* +- * Begin "mit-des.h" +- */ +-#ifndef KRB5_MIT_DES__ +-#define KRB5_MIT_DES__ +- +-#if defined(__MACH__) && defined(__APPLE__) +-#include +-#include +-#if TARGET_RT_MAC_CFM +-#error "Use KfM 4.0 SDK headers for CFM compilation." +-#endif +-#if defined(DEPRECATED_IN_MAC_OS_X_VERSION_10_5) && !defined(KRB5_SUPRESS_DEPRECATED_WARNINGS) +-#define KRB5INT_DES_DEPRECATED DEPRECATED_IN_MAC_OS_X_VERSION_10_5 +-#endif +-#endif /* defined(__MACH__) && defined(__APPLE__) */ +- +-/* Macro to add deprecated attribute to DES types and functions */ +-/* Currently only defined on macOS 10.5 and later. */ +-#ifndef KRB5INT_DES_DEPRECATED +-#define KRB5INT_DES_DEPRECATED +-#endif +- +-#include +- +-#if UINT_MAX >= 0xFFFFFFFFUL +-#define DES_INT32 int +-#define DES_UINT32 unsigned int +-#else +-#define DES_INT32 long +-#define DES_UINT32 unsigned long +-#endif +- +-typedef unsigned char des_cblock[8] /* crypto-block size */ +-KRB5INT_DES_DEPRECATED; +- +-/* +- * Key schedule. +- * +- * This used to be +- * +- * typedef struct des_ks_struct { +- * union { DES_INT32 pad; des_cblock _;} __; +- * } des_key_schedule[16]; +- * +- * but it would cause trouble if DES_INT32 were ever more than 4 +- * bytes. The reason is that all the encryption functions cast it to +- * (DES_INT32 *), and treat it as if it were DES_INT32[32]. If +- * 2*sizeof(DES_INT32) is ever more than sizeof(des_cblock), the +- * caller-allocated des_key_schedule will be overflowed by the key +- * scheduling functions. We can't assume that every platform will +- * have an exact 32-bit int, and nothing should be looking inside a +- * des_key_schedule anyway. +- */ +-typedef struct des_ks_struct { DES_INT32 _[2]; } des_key_schedule[16] +-KRB5INT_DES_DEPRECATED; +- +-typedef des_cblock mit_des_cblock; +-typedef des_key_schedule mit_des_key_schedule; +- +-/* Triple-DES structures */ +-typedef mit_des_cblock mit_des3_cblock[3]; +-typedef mit_des_key_schedule mit_des3_key_schedule[3]; +- +-#define MIT_DES_ENCRYPT 1 +-#define MIT_DES_DECRYPT 0 +- +-typedef struct mit_des_ran_key_seed { +- krb5_encrypt_block eblock; +- krb5_data sequence; +-} mit_des_random_state; +- +-/* the first byte of the key is already in the keyblock */ +- +-#define MIT_DES_BLOCK_LENGTH (8*sizeof(krb5_octet)) +-/* This used to be 8*sizeof(krb5_octet) */ +-#define MIT_DES_KEYSIZE 8 +- +-#define MIT_DES_CBC_CKSUM_LENGTH (4*sizeof(krb5_octet)) +- +-#endif /* KRB5_MIT_DES__ */ +-/* +- * End "mit-des.h" +- */ +- +-/* afsstring2key.c */ +-krb5_error_code mit_afs_string_to_key(krb5_keyblock *keyblock, +- const krb5_data *data, +- const krb5_data *salt); +-char *mit_afs_crypt(const char *pw, const char *salt, char *iobuf); +- +-/* f_cksum.c */ +-unsigned long mit_des_cbc_cksum(const krb5_octet *, krb5_octet *, +- unsigned long, const mit_des_key_schedule, +- const krb5_octet *); +- +-/* f_cbc.c (used by test programs) */ +-int +-mit_des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec, int enc); +- +-#define mit_des_zeroblock krb5int_c_mit_des_zeroblock +-extern const mit_des_cblock mit_des_zeroblock; +- +-/* fin_rndkey.c */ +-krb5_error_code mit_des_finish_random_key(const krb5_encrypt_block *, +- krb5_pointer *); +- +-/* finish_key.c */ +-krb5_error_code mit_des_finish_key(krb5_encrypt_block *); +- +-/* init_rkey.c */ +-krb5_error_code mit_des_init_random_key(const krb5_encrypt_block *, +- const krb5_keyblock *, +- krb5_pointer *); +- +-/* key_parity.c */ +-void mit_des_fixup_key_parity(mit_des_cblock); +-int mit_des_check_key_parity(mit_des_cblock); +- +-/* key_sched.c */ +-int mit_des_key_sched(mit_des_cblock, mit_des_key_schedule); +- +-/* process_ky.c */ +-krb5_error_code mit_des_process_key(krb5_encrypt_block *, +- const krb5_keyblock *); +- +-/* random_key.c */ +-krb5_error_code mit_des_random_key(const krb5_encrypt_block *, +- krb5_pointer, krb5_keyblock **); +- +-/* string2key.c */ +-krb5_error_code mit_des_string_to_key(const krb5_encrypt_block *, +- krb5_keyblock *, const krb5_data *, +- const krb5_data *); +-krb5_error_code mit_des_string_to_key_int(krb5_keyblock *, const krb5_data *, +- const krb5_data *); +- +-/* weak_key.c */ +-int mit_des_is_weak_key(mit_des_cblock); +- +-/* cmb_keys.c */ +-krb5_error_code mit_des_combine_subkeys(const krb5_keyblock *, +- const krb5_keyblock *, +- krb5_keyblock **); +- +-/* f_pcbc.c */ +-int mit_des_pcbc_encrypt(); +- +-/* f_sched.c */ +-int mit_des_make_key_sched(mit_des_cblock, mit_des_key_schedule); +- +- +-/* misc.c */ +-extern void swap_bits(char *); +-extern unsigned long long_swap_bits(unsigned long); +-extern unsigned long swap_six_bits_to_ansi(unsigned long); +-extern unsigned long swap_four_bits_to_ansi(unsigned long); +-extern unsigned long swap_bit_pos_1(unsigned long); +-extern unsigned long swap_bit_pos_0(unsigned long); +-extern unsigned long swap_bit_pos_0_to_ansi(unsigned long); +-extern unsigned long rev_swap_bit_pos_0(unsigned long); +-extern unsigned long swap_byte_bits(unsigned long); +-extern unsigned long swap_long_bytes_bit_number(unsigned long); +-#ifdef FILE +-/* XXX depends on FILE being a #define! */ +-extern void test_set(FILE *, const char *, int, const char *, int); +-#endif +- +-void +-krb5int_des3_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec); +- +-void +-krb5int_des3_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_mac(const krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, mit_des_cblock ivec, +- mit_des_cblock out); +- +-/* d3_procky.c */ +-krb5_error_code mit_des3_process_key(krb5_encrypt_block *eblock, +- const krb5_keyblock *keyblock); +- +-/* d3_kysched.c */ +-int mit_des3_key_sched(mit_des3_cblock key, mit_des3_key_schedule schedule); +- +-/* d3_str2ky.c */ +-krb5_error_code mit_des3_string_to_key(const krb5_encrypt_block *eblock, +- krb5_keyblock *keyblock, +- const krb5_data *data, +- const krb5_data *salt); +- +-/* u_nfold.c */ +-krb5_error_code mit_des_n_fold(const krb5_octet *input, const size_t in_len, +- krb5_octet *output, const size_t out_len); +- +-/* u_rn_key.c */ +-int mit_des_is_weak_keyblock(krb5_keyblock *keyblock); +- +-void mit_des_fixup_keyblock_parity(krb5_keyblock *keyblock); +- +-krb5_error_code mit_des_set_random_generator_seed(const krb5_data *seed, +- krb5_pointer random_state); +- +-krb5_error_code mit_des_set_random_sequence_number(const krb5_data *sequence, +- krb5_pointer random_state); +-#endif /*DES_INTERNAL_DEFS*/ +diff --git a/src/lib/crypto/builtin/des/des_keys.c b/src/lib/crypto/builtin/des/des_keys.c +deleted file mode 100644 +index 027b09d728..0000000000 +--- a/src/lib/crypto/builtin/des/des_keys.c ++++ /dev/null +@@ -1,38 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/des_keys.c - Key functions used by Kerberos code */ +-/* +- * Copyright (C) 2011 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES_KEY_PARITY +- +-void +-k5_des_fixup_key_parity(unsigned char *keybits) +-{ +- mit_des_fixup_key_parity(keybits); +-} +- +-#endif /* K5_BUILTIN_DES_KEY_PARITY */ +diff --git a/src/lib/crypto/builtin/des/destest.c b/src/lib/crypto/builtin/des/destest.c +deleted file mode 100644 +index 52114304e3..0000000000 +--- a/src/lib/crypto/builtin/des/destest.c ++++ /dev/null +@@ -1,240 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/destest.c */ +-/* +- * Copyright 1990,1991 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* Test a DES implementation against known inputs & outputs. */ +- +-#include "des_int.h" +-#include +-#include +- +-void convert (char *, unsigned char []); +- +-void des_cblock_print_file (mit_des_cblock, FILE *); +- +-krb5_octet zeroblock[8] = {0,0,0,0,0,0,0,0}; +- +-int +-main(argc, argv) +- int argc; +- char *argv[]; +-{ +- char block1[17], block2[17], block3[17]; +- /* Force tests of unaligned accesses. */ +- union { unsigned char c[8*4+3]; long l; } u; +- unsigned char *ioblocks = u.c; +- unsigned char *input = ioblocks+1; +- unsigned char *output = ioblocks+10; +- unsigned char *output2 = ioblocks+19; +- unsigned char *key = ioblocks+27; +- mit_des_key_schedule sched; +- int num = 0; +- int retval; +- +- int error = 0; +- +- while (scanf("%16s %16s %16s", block1, block2, block3) == 3) { +- convert(block1, key); +- convert(block2, input); +- convert(block3, output); +- +- retval = mit_des_key_sched(key, sched); +- if (retval) { +- fprintf(stderr, "des test: can't process key: %d\n", retval); +- fprintf(stderr, "des test: %s %s %s\n", block1, block2, block3); +- exit(1); +- } +- mit_des_cbc_encrypt((const mit_des_cblock *) input, +- (mit_des_cblock *) output2, 8, +- sched, zeroblock, 1); +- +- if (memcmp((char *)output2, (char *)output, 8)) { +- fprintf(stderr, +- "DES ENCRYPT ERROR, key %s, text %s, real cipher %s, computed cyphertext %02X%02X%02X%02X%02X%02X%02X%02X\n", +- block1, block2, block3, +- output2[0],output2[1],output2[2],output2[3], +- output2[4],output2[5],output2[6],output2[7]); +- error++; +- } +- +- /* +- * Now try decrypting.... +- */ +- mit_des_cbc_encrypt((const mit_des_cblock *) output, +- (mit_des_cblock *) output2, 8, +- sched, zeroblock, 0); +- +- if (memcmp((char *)output2, (char *)input, 8)) { +- fprintf(stderr, +- "DES DECRYPT ERROR, key %s, text %s, real cipher %s, computed cleartext %02X%02X%02X%02X%02X%02X%02X%02X\n", +- block1, block2, block3, +- output2[0],output2[1],output2[2],output2[3], +- output2[4],output2[5],output2[6],output2[7]); +- error++; +- } +- +- num++; +- } +- +- if (error) +- printf("destest: failed to pass the test\n"); +- else +- printf("destest: %d tests passed successfully\n", num); +- +- exit( (error > 256 && error % 256) ? 1 : error); +-} +- +-int value[128] = { +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- 0, 1, 2, 3, 4, 5, 6, 7, +- 8, 9, -1, -1, -1, -1, -1, -1, +- -1, 10, 11, 12, 13, 14, 15, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +-}; +- +-void +-convert(text, cblock) +- char *text; +- unsigned char cblock[]; +-{ +- int i; +- for (i = 0; i < 8; i++) { +- if (!isascii((unsigned char)text[i * 2])) +- abort (); +- if (value[(int) text[i*2]] == -1 || value[(int) text[i*2+1]] == -1) { +- printf("Bad value byte %d in %s\n", i, text); +- exit(1); +- } +- cblock[i] = 16*value[(int) text[i*2]] + value[(int) text[i*2+1]]; +- } +- return; +-} +- +-/* +- * Fake out the DES library, for the purposes of testing. +- */ +- +-int +-mit_des_is_weak_key(key) +- mit_des_cblock key; +-{ +- return 0; /* fake it out for testing */ +-} +- +-void +-des_cblock_print_file(x, fp) +- mit_des_cblock x; +- FILE *fp; +-{ +- unsigned char *y = (unsigned char *) x; +- int i = 0; +- fprintf(fp," 0x { "); +- +- while (i++ < 8) { +- fprintf(fp,"%x",*y++); +- if (i < 8) +- fprintf(fp,", "); +- } +- fprintf(fp," }"); +-} +- +- +-#define smask(step) ((1<>step)&smask(step))) +-#define parity_char(x) pstep(pstep(pstep((x),4),2),1) +- +-/* +- * des_check_key_parity: returns true iff key has the correct des parity. +- * See des_fix_key_parity for the definition of +- * correct des parity. +- */ +-int +-mit_des_check_key_parity(key) +- mit_des_cblock key; +-{ +- unsigned int i; +- +- for (i=0; i decrypt, else encrypt */ +- Key_schedule schedule; /* addr of key schedule */ +- +-This is the low level routine that encrypts or decrypts a single 8-byte +-block in electronic code book mode. Always transforms the input +-data into the output data. +- +-If encrypt is non-zero, the input (cleartext) is encrypted into the +-output (ciphertext) using the specified key_schedule, pre-set via "des_set_key". +- +-If encrypt is zero, the input (now ciphertext) is decrypted into +-the output (now cleartext). +- +-Input and output may be the same space. +- +-Does not return any meaningful value. Void is not used for compatibility +-with other compilers. +- +-/* -------------------------------------------------------------- */ +- +-int +- cbc_encrypt(input,output,length,schedule,ivec,encrypt) +- +- C_Block *input; /* ptr to input data */ +- C_Block *output; /* ptr to output data */ +- int length; /* desired length, in bytes */ +- Key_schedule schedule; /* addr of precomputed schedule */ +- C_Block *ivec; /* pointer to 8 byte initialization +- * vector +- */ +- int encrypt /* 0 ==> decrypt; else encrypt*/ +- +- +- If encrypt is non-zero, the routine cipher-block-chain encrypts +- the INPUT (cleartext) into the OUTPUT (ciphertext) using the provided +- key schedule and initialization vector. If the length is not an integral +- multiple of eight bytes, the last block is copied to a temp and zero +- filled (highest addresses). The output is ALWAYS an integral multiple +- of eight bytes. +- +- If encrypt is zero, the routine cipher-block chain decrypts the INPUT +- (ciphertext) into the OUTPUT (cleartext) using the provided key schedule +- and initialization vector. Decryption ALWAYS operates on integral +- multiples of 8 bytes, so will round the length provided up to the +- appropriate multiple. Consequently, it will always produce the rounded-up +- number of bytes of output cleartext. The application must determine if +- the output cleartext was zero-padded due to cleartext lengths not integral +- multiples of 8. +- +- No errors or meaningful value are returned. Void is not used for +- compatibility with other compilers. +- +- +-/* cbc checksum (MAC) only routine ---------------------------------------- */ +-int +- cbc_cksum(input,output,length,schedule,ivec) +- +- C_Block *input; /* >= length bytes of inputtext */ +- C_Block *output; /* >= length bytes of outputtext */ +- int length; /* in bytes */ +- Key_schedule schedule; /* precomputed key schedule */ +- C_Block *ivec; /* 8 bytes of ivec */ +- +- +- Produces a cryptographic checksum, 8 bytes, by cipher-block-chain +- encrypting the input, discarding the ciphertext output, and only retaining +- the last ciphertext 8-byte block. Uses the provided key schedule and ivec. +- The input is effectively zero-padded to an integral multiple of +- eight bytes, though the original input is not modified. +- +- No meaningful value is returned. Void is not used for compatibility +- with other compilers. +- +- +-/* random_key ----------------------------------------*/ +-int +- random_key(key) +- +- C_Block *key; +- +- The start for the random number generated is set from the current time +- in microseconds, then the random number generator is invoked +- to create an eight byte output key (not a schedule). The key +- generated is set to odd parity per FIPS spec. +- +- The caller must supply space for the output key, pointed to +- by "*key", then after getting a new key, call the des_set_key() +- routine when needed. +- +- No meaningful value is returned. Void is not used for compatibility +- with other compilers. +- +- +-/* string_to_key --------------------------------------------*/ +- +-int +- string_to_key(str,key) +- char *str; +- C_Block *key; +- +- This routines converts an arbitrary length, null terminated string +- to an 8 byte DES key, with each byte parity set to odd, per FIPS spec. +- +- The algorithm is as follows: +- +-| Take the first 8 bytes and remove the parity (leaving 56 bits). +-| Do the same for the second 8 bytes, and the third, etc. Do this for +-| as many sets of 8 bytes as necessary, filling in the remainder of the +-| last set with nulls. Fold the second set back on the first (i.e. bit +-| 0 over bit 55, and bit 55 over bit 0). Fold the third over the second +-| (bit 0 of the third set is now over bit 0 of the first set). Repeat +-| until you have done this to all sets. Xor the folded sets. Break the +-| result into 8 7 bit bytes, and generate odd parity for each byte. You +-| now have 64 bits. Note that DES takes a 64 bit key, and uses only the +-| non parity bits. +- +- +-/* read_password -------------------------------------------*/ +- +-read_password(k,prompt,verify) +- C_Block *k; +- char *prompt; +- int verify; +- +-This routine issues the supplied prompt, turns off echo, if possible, and +-reads an input string. If verify is non-zero, it does it again, for use +-in applications such as changing a password. If verify is non-zero, both +-versions are compared, and the input is requested repeatedly until they +-match. Then, the input string is mapped into a valid DES key, internally +-using the string_to_key routine. The newly created key is copied to the +-area pointed to by parameter "k". +- +-No meaningful value is returned. If an error occurs trying to manipulate +-the terminal echo, the routine forces the process to exit. +- +-/* get_line ------------------------*/ +-long get_line(p,max) +- char *p; +- long max; +- +-Reads input characters from standard input until either a newline appears or +-else the max length is reached. The characters read are stuffed into +-the string pointed to, which will always be null terminated. The newline +-is not inserted in the string. The max parameter includes the byte needed +-for the null terminator, so allocate and pass one more than the maximum +-string length desired. +diff --git a/src/lib/crypto/builtin/des/f_aead.c b/src/lib/crypto/builtin/des/f_aead.c +deleted file mode 100644 +index f887735820..0000000000 +--- a/src/lib/crypto/builtin/des/f_aead.c ++++ /dev/null +@@ -1,177 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 2008 by the Massachusetts Institute of Technology. +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-#ifdef K5_BUILTIN_DES +- +-const mit_des_cblock mit_des_zeroblock /* = all zero */; +- +-void +-krb5int_des_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Decompose this block and xor it with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have and put back into block. */ +- DES_DO_ENCRYPT(left, right, kp); +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(left, ivec); +- store_32_be(right, ivec + 4); +- } +-} +- +-void +-krb5int_des_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- /* Prime the old cipher with ivec. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- ocipherl = load_32_be(ip); +- ocipherr = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Split this block into left and right. */ +- cipherl = left = load_32_be(block); +- cipherr = right = load_32_be(block + 4); +- +- /* Decrypt and xor with the old cipher to get plain text. */ +- DES_DO_DECRYPT(left, right, kp); +- left ^= ocipherl; +- right ^= ocipherr; +- +- /* Store the encrypted halves back into block. */ +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- /* Save current cipher block halves. */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(ocipherl, ivec); +- store_32_be(ocipherr, ivec + 4); +- } +-} +- +-void +-krb5int_des_cbc_mac(const krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, mit_des_cblock ivec, +- mit_des_cblock out) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, TRUE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Decompose this block and xor it with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have. */ +- DES_DO_ENCRYPT(left, right, kp); +- } +- +- /* Output the final ciphertext block. */ +- store_32_be(left, out); +- store_32_be(right, out + 4); +-} +- +-#if defined(CONFIG_SMALL) && !defined(CONFIG_SMALL_NO_CRYPTO) +-void krb5int_des_do_encrypt_2 (unsigned DES_INT32 *left, +- unsigned DES_INT32 *right, +- const unsigned DES_INT32 *kp) +-{ +- DES_DO_ENCRYPT_1 (*left, *right, kp); +-} +- +-void krb5int_des_do_decrypt_2 (unsigned DES_INT32 *left, +- unsigned DES_INT32 *right, +- const unsigned DES_INT32 *kp) +-{ +- DES_DO_DECRYPT_1 (*left, *right, kp); +-} +-#endif +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/f_cbc.c b/src/lib/crypto/builtin/des/f_cbc.c +deleted file mode 100644 +index 84d5382f22..0000000000 +--- a/src/lib/crypto/builtin/des/f_cbc.c ++++ /dev/null +@@ -1,256 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_cbc.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * CBC functions; used only by the test programs at this time. (krb5 uses the +- * functions in f_aead.c instead.) +- */ +- +-/* +- * des_cbc_encrypt.c - an implementation of the DES cipher function in cbc mode +- */ +-#include "des_int.h" +-#include "f_tables.h" +- +-/* +- * des_cbc_encrypt - {en,de}crypt a stream in CBC mode +- */ +- +-/* +- * This routine performs DES cipher-block-chaining operation, either +- * encrypting from cleartext to ciphertext, if encrypt != 0 or +- * decrypting from ciphertext to cleartext, if encrypt == 0. +- * +- * The key schedule is passed as an arg, as well as the cleartext or +- * ciphertext. The cleartext and ciphertext should be in host order. +- * +- * NOTE-- the output is ALWAYS an multiple of 8 bytes long. If not +- * enough space was provided, your program will get trashed. +- * +- * For encryption, the cleartext string is null padded, at the end, to +- * an integral multiple of eight bytes. +- * +- * For decryption, the ciphertext will be used in integral multiples +- * of 8 bytes, but only the first "length" bytes returned into the +- * cleartext. +- */ +- +-const mit_des_cblock mit_des_zeroblock /* = all zero */; +- +-static void +-des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- +- /* +- * Get key pointer here. This won't need to be reinitialized +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Initialize left and right with the contents of the initial +- * vector. +- */ +- ip = ivec; +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- +- /* +- * Suitably initialized, now work the length down 8 bytes +- * at a time. +- */ +- ip = *in; +- op = *out; +- while (length > 0) { +- /* +- * Get more input, xor it in. If the length is +- * greater than or equal to 8 this is straight +- * forward. Otherwise we have to fart around. +- */ +- if (length >= 8) { +- unsigned DES_INT32 temp; +- GET_HALF_BLOCK(temp, ip); +- left ^= temp; +- GET_HALF_BLOCK(temp, ip); +- right ^= temp; +- length -= 8; +- } else { +- /* +- * Oh, shoot. We need to pad the +- * end with zeroes. Work backwards +- * to do this. +- */ +- ip += (int) length; +- switch(length) { +- case 7: +- right ^= (*(--ip) & FF_UINT32) << 8; +- case 6: +- right ^= (*(--ip) & FF_UINT32) << 16; +- case 5: +- right ^= (*(--ip) & FF_UINT32) << 24; +- case 4: +- left ^= *(--ip) & FF_UINT32; +- case 3: +- left ^= (*(--ip) & FF_UINT32) << 8; +- case 2: +- left ^= (*(--ip) & FF_UINT32) << 16; +- case 1: +- left ^= (*(--ip) & FF_UINT32) << 24; +- break; +- } +- length = 0; +- } +- +- /* +- * Encrypt what we have +- */ +- DES_DO_ENCRYPT(left, right, kp); +- +- /* +- * Copy the results out +- */ +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- } +-} +- +-static void +-des_cbc_decrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- +- /* +- * Get key pointer here. This won't need to be reinitialized +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- if (length <= 0) +- return; +- +- /* +- * Prime the old cipher with ivec. +- */ +- ip = ivec; +- GET_HALF_BLOCK(ocipherl, ip); +- GET_HALF_BLOCK(ocipherr, ip); +- +- /* +- * Now do this in earnest until we run out of length. +- */ +- ip = *in; +- op = *out; +- for (;;) { /* check done inside loop */ +- /* +- * Read a block from the input into left and +- * right. Save this cipher block for later. +- */ +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- cipherl = left; +- cipherr = right; +- +- /* +- * Decrypt this. +- */ +- DES_DO_DECRYPT(left, right, kp); +- +- /* +- * Xor with the old cipher to get plain +- * text. Output 8 or less bytes of this. +- */ +- left ^= ocipherl; +- right ^= ocipherr; +- if (length > 8) { +- length -= 8; +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- /* +- * Save current cipher block here +- */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- } else { +- /* +- * Trouble here. Start at end of output, +- * work backwards. +- */ +- op += (int) length; +- switch(length) { +- case 8: +- *(--op) = (unsigned char) (right & 0xff); +- case 7: +- *(--op) = (unsigned char) ((right >> 8) & 0xff); +- case 6: +- *(--op) = (unsigned char) ((right >> 16) & 0xff); +- case 5: +- *(--op) = (unsigned char) ((right >> 24) & 0xff); +- case 4: +- *(--op) = (unsigned char) (left & 0xff); +- case 3: +- *(--op) = (unsigned char) ((left >> 8) & 0xff); +- case 2: +- *(--op) = (unsigned char) ((left >> 16) & 0xff); +- case 1: +- *(--op) = (unsigned char) ((left >> 24) & 0xff); +- break; +- } +- break; /* we're done */ +- } +- } +-} +- +-int +-mit_des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec, int enc) +-{ +- /* +- * Deal with encryption and decryption separately. +- */ +- if (enc) +- des_cbc_encrypt(in, out, length, schedule, ivec); +- else +- des_cbc_decrypt(in, out, length, schedule, ivec); +- return 0; +-} +diff --git a/src/lib/crypto/builtin/des/f_cksum.c b/src/lib/crypto/builtin/des/f_cksum.c +deleted file mode 100644 +index 615a947f4a..0000000000 +--- a/src/lib/crypto/builtin/des/f_cksum.c ++++ /dev/null +@@ -1,141 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_cksum.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* DES implementation donated by Dennis Ferguson */ +- +-/* +- * des_cbc_cksum.c - compute an 8 byte checksum using DES in CBC mode +- */ +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-#ifdef K5_BUILTIN_DES +- +-/* +- * This routine performs DES cipher-block-chaining checksum operation, +- * a.k.a. Message Authentication Code. It ALWAYS encrypts from input +- * to a single 64 bit output MAC checksum. +- * +- * The key schedule is passed as an arg, as well as the cleartext or +- * ciphertext. The cleartext and ciphertext should be in host order. +- * +- * NOTE-- the output is ALWAYS 8 bytes long. If not enough space was +- * provided, your program will get trashed. +- * +- * The input is null padded, at the end (highest addr), to an integral +- * multiple of eight bytes. +- */ +- +-unsigned long +-mit_des_cbc_cksum(const krb5_octet *in, krb5_octet *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const krb5_octet *ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- DES_INT32 len; +- +- /* +- * Initialize left and right with the contents of the initial +- * vector. +- */ +- ip = ivec; +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- +- /* +- * Suitably initialized, now work the length down 8 bytes +- * at a time. +- */ +- ip = in; +- len = length; +- while (len > 0) { +- /* +- * Get more input, xor it in. If the length is +- * greater than or equal to 8 this is straight +- * forward. Otherwise we have to fart around. +- */ +- if (len >= 8) { +- unsigned DES_INT32 temp; +- GET_HALF_BLOCK(temp, ip); +- left ^= temp; +- GET_HALF_BLOCK(temp, ip); +- right ^= temp; +- len -= 8; +- } else { +- /* +- * Oh, shoot. We need to pad the +- * end with zeroes. Work backwards +- * to do this. +- */ +- ip += (int) len; +- switch(len) { +- case 7: +- right ^= (*(--ip) & FF_UINT32) << 8; +- case 6: +- right ^= (*(--ip) & FF_UINT32) << 16; +- case 5: +- right ^= (*(--ip) & FF_UINT32) << 24; +- case 4: +- left ^= *(--ip) & FF_UINT32; +- case 3: +- left ^= (*(--ip) & FF_UINT32) << 8; +- case 2: +- left ^= (*(--ip) & FF_UINT32) << 16; +- case 1: +- left ^= (*(--ip) & FF_UINT32) << 24; +- break; +- } +- len = 0; +- } +- +- /* +- * Encrypt what we have +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- DES_DO_ENCRYPT(left, right, kp); +- } +- +- /* +- * Done. Left and right have the checksum. Put it into +- * the output. +- */ +- op = out; +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- +- /* +- * Return right. I'll bet the MIT code returns this +- * inconsistantly (with the low order byte of the checksum +- * not always in the low order byte of the DES_INT32). We won't. +- */ +- return right & 0xFFFFFFFFUL; +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/f_parity.c b/src/lib/crypto/builtin/des/f_parity.c +deleted file mode 100644 +index a658878f6f..0000000000 +--- a/src/lib/crypto/builtin/des/f_parity.c ++++ /dev/null +@@ -1,64 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * These routines check and fix parity of encryption keys for the DES +- * algorithm. +- * +- * They are a replacement for routines in key_parity.c, that don't require +- * the table building that they do. +- * +- * Mark Eichin -- Cygnus Support +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES_KEY_PARITY +- +-/* +- * des_fixup_key_parity: Forces odd parity per byte; parity is bits +- * 8,16,...64 in des order, implies 0, 8, 16, ... +- * vax order. +- */ +-#define smask(step) ((1<>step)&smask(step))) +-#define parity_char(x) pstep(pstep(pstep((x),4),2),1) +- +-void +-mit_des_fixup_key_parity(mit_des_cblock key) +-{ +- unsigned int i; +- for (i=0; i> 29) & 0x7] +- | (PC1_CL[(tmp >> 21) & 0x7] << 1) +- | (PC1_CL[(tmp >> 13) & 0x7] << 2) +- | (PC1_CL[(tmp >> 5) & 0x7] << 3); +- d = PC1_DL[(tmp >> 25) & 0xf] +- | (PC1_DL[(tmp >> 17) & 0xf] << 1) +- | (PC1_DL[(tmp >> 9) & 0xf] << 2) +- | (PC1_DL[(tmp >> 1) & 0xf] << 3); +- +- tmp = load_32_be(k), k += 4; +- +- c |= PC1_CR[(tmp >> 28) & 0xf] +- | (PC1_CR[(tmp >> 20) & 0xf] << 1) +- | (PC1_CR[(tmp >> 12) & 0xf] << 2) +- | (PC1_CR[(tmp >> 4) & 0xf] << 3); +- d |= PC1_DR[(tmp >> 25) & 0x7] +- | (PC1_DR[(tmp >> 17) & 0x7] << 1) +- | (PC1_DR[(tmp >> 9) & 0x7] << 2) +- | (PC1_DR[(tmp >> 1) & 0x7] << 3); +- } +- +- { +- /* +- * Need several temporaries in here +- */ +- unsigned DES_INT32 ltmp, rtmp; +- unsigned DES_INT32 *k; +- int two_bit_shifts; +- int i; +- /* +- * Now iterate to compute the key schedule. Note that we +- * record the entire set of subkeys in 6 bit chunks since +- * they are used that way. At 6 bits/char, we need +- * 48/6 char's/subkey * 16 subkeys/encryption == 128 bytes. +- * The schedule must be this big. +- */ +- k = (unsigned DES_INT32 *)schedule; +- two_bit_shifts = TWO_BIT_SHIFTS; +- for (i = 16; i > 0; i--) { +- /* +- * Do the rotation. One bit and two bit rotations +- * are done separately. Note C and D are 28 bits. +- */ +- if (two_bit_shifts & 0x1) { +- c = ((c << 2) & 0xffffffc) | (c >> 26); +- d = ((d << 2) & 0xffffffc) | (d >> 26); +- } else { +- c = ((c << 1) & 0xffffffe) | (c >> 27); +- d = ((d << 1) & 0xffffffe) | (d >> 27); +- } +- two_bit_shifts >>= 1; +- +- /* +- * Apply permutted choice 2 to C to get the first +- * 24 bits worth of keys. Note that bits 9, 18, 22 +- * and 25 (using DES numbering) in C are unused. The +- * shift-mask stuff is done to delete these bits from +- * the indices, since this cuts the table size in half. +- * +- * The table is torqued, by the way. If the standard +- * byte order for this (high to low order) is 1234, +- * the table actually gives us 4132. +- */ +- ltmp = PC2_C[0][((c >> 22) & 0x3f)] +- | PC2_C[1][((c >> 15) & 0xf) | ((c >> 16) & 0x30)] +- | PC2_C[2][((c >> 4) & 0x3) | ((c >> 9) & 0x3c)] +- | PC2_C[3][((c ) & 0x7) | ((c >> 4) & 0x38)]; +- /* +- * Apply permutted choice 2 to D to get the other half. +- * Here, bits 7, 10, 15 and 26 go unused. The sqeezing +- * actually turns out to be cheaper here. +- * +- * This table is similarly torqued. If the standard +- * byte order is 5678, the table has the bytes permuted +- * to give us 7685. +- */ +- rtmp = PC2_D[0][((d >> 22) & 0x3f)] +- | PC2_D[1][((d >> 14) & 0xf) | ((d >> 15) & 0x30)] +- | PC2_D[2][((d >> 7) & 0x3f)] +- | PC2_D[3][((d ) & 0x3) | ((d >> 1) & 0x3c)]; +- +- /* +- * Make up two words of the key schedule, with a +- * byte order which is convenient for the DES +- * inner loop. The high order (first) word will +- * hold bytes 7135 (high to low order) while the +- * second holds bytes 4682. +- */ +- *k++ = (ltmp & 0x00ffff00) | (rtmp & 0xff0000ff); +- *k++ = (ltmp & 0xff0000ff) | (rtmp & 0x00ffff00); +- } +- } +- return (0); +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/f_tables.c b/src/lib/crypto/builtin/des/f_tables.c +deleted file mode 100644 +index e50ab1fc60..0000000000 +--- a/src/lib/crypto/builtin/des/f_tables.c ++++ /dev/null +@@ -1,375 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_tables.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* DES implementation donated by Dennis Ferguson */ +- +-/* +- * des_tables.c - precomputed tables used for the DES cipher function +- */ +- +-/* +- * Include the header file so something will complain if the +- * declarations get out of sync +- */ +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-#ifdef K5_BUILTIN_DES +- +-/* +- * These tables may be declared const if you want. Many compilers +- * don't support this, though. +- */ +- +-/* +- * The DES algorithm which uses these is intended to be fairly speedy +- * at the expense of some memory. All the standard hacks are used. +- * The S boxes and the P permutation are precomputed into one table. +- * The E box never actually appears explicitly since it is easy to apply +- * this algorithmically as needed. The initial permutation and final +- * (inverse initial) permutation are computed from tables designed to +- * permute one byte at a time. This should run pretty fast on machines +- * with 32 bit words and bit field/multiple bit shift instructions which +- * are fast. +- */ +- +-/* +- * The initial permutation array. This is used to compute both the +- * left and the right halves of the initial permutation using bytes +- * from words made from the following operations: +- * +- * ((left & 0x55555555) << 1) | (right & 0x55555555) for left half +- * (left & 0xaaaaaaaa) | ((right & 0xaaaaaaaa) >> 1) for right half +- * +- * The scheme is that we index into the table using each byte. The +- * result from the high order byte is or'd with the result from the +- * next byte shifted left once is or'd with the result from the next +- * byte shifted left twice if or'd with the result from the low order +- * byte shifted left by three. Clear? +- */ +- +-const unsigned DES_INT32 des_IP_table[256] = { +- 0x00000000, 0x00000010, 0x00000001, 0x00000011, +- 0x00001000, 0x00001010, 0x00001001, 0x00001011, +- 0x00000100, 0x00000110, 0x00000101, 0x00000111, +- 0x00001100, 0x00001110, 0x00001101, 0x00001111, +- 0x00100000, 0x00100010, 0x00100001, 0x00100011, +- 0x00101000, 0x00101010, 0x00101001, 0x00101011, +- 0x00100100, 0x00100110, 0x00100101, 0x00100111, +- 0x00101100, 0x00101110, 0x00101101, 0x00101111, +- 0x00010000, 0x00010010, 0x00010001, 0x00010011, +- 0x00011000, 0x00011010, 0x00011001, 0x00011011, +- 0x00010100, 0x00010110, 0x00010101, 0x00010111, +- 0x00011100, 0x00011110, 0x00011101, 0x00011111, +- 0x00110000, 0x00110010, 0x00110001, 0x00110011, +- 0x00111000, 0x00111010, 0x00111001, 0x00111011, +- 0x00110100, 0x00110110, 0x00110101, 0x00110111, +- 0x00111100, 0x00111110, 0x00111101, 0x00111111, +- 0x10000000, 0x10000010, 0x10000001, 0x10000011, +- 0x10001000, 0x10001010, 0x10001001, 0x10001011, +- 0x10000100, 0x10000110, 0x10000101, 0x10000111, +- 0x10001100, 0x10001110, 0x10001101, 0x10001111, +- 0x10100000, 0x10100010, 0x10100001, 0x10100011, +- 0x10101000, 0x10101010, 0x10101001, 0x10101011, +- 0x10100100, 0x10100110, 0x10100101, 0x10100111, +- 0x10101100, 0x10101110, 0x10101101, 0x10101111, +- 0x10010000, 0x10010010, 0x10010001, 0x10010011, +- 0x10011000, 0x10011010, 0x10011001, 0x10011011, +- 0x10010100, 0x10010110, 0x10010101, 0x10010111, +- 0x10011100, 0x10011110, 0x10011101, 0x10011111, +- 0x10110000, 0x10110010, 0x10110001, 0x10110011, +- 0x10111000, 0x10111010, 0x10111001, 0x10111011, +- 0x10110100, 0x10110110, 0x10110101, 0x10110111, +- 0x10111100, 0x10111110, 0x10111101, 0x10111111, +- 0x01000000, 0x01000010, 0x01000001, 0x01000011, +- 0x01001000, 0x01001010, 0x01001001, 0x01001011, +- 0x01000100, 0x01000110, 0x01000101, 0x01000111, +- 0x01001100, 0x01001110, 0x01001101, 0x01001111, +- 0x01100000, 0x01100010, 0x01100001, 0x01100011, +- 0x01101000, 0x01101010, 0x01101001, 0x01101011, +- 0x01100100, 0x01100110, 0x01100101, 0x01100111, +- 0x01101100, 0x01101110, 0x01101101, 0x01101111, +- 0x01010000, 0x01010010, 0x01010001, 0x01010011, +- 0x01011000, 0x01011010, 0x01011001, 0x01011011, +- 0x01010100, 0x01010110, 0x01010101, 0x01010111, +- 0x01011100, 0x01011110, 0x01011101, 0x01011111, +- 0x01110000, 0x01110010, 0x01110001, 0x01110011, +- 0x01111000, 0x01111010, 0x01111001, 0x01111011, +- 0x01110100, 0x01110110, 0x01110101, 0x01110111, +- 0x01111100, 0x01111110, 0x01111101, 0x01111111, +- 0x11000000, 0x11000010, 0x11000001, 0x11000011, +- 0x11001000, 0x11001010, 0x11001001, 0x11001011, +- 0x11000100, 0x11000110, 0x11000101, 0x11000111, +- 0x11001100, 0x11001110, 0x11001101, 0x11001111, +- 0x11100000, 0x11100010, 0x11100001, 0x11100011, +- 0x11101000, 0x11101010, 0x11101001, 0x11101011, +- 0x11100100, 0x11100110, 0x11100101, 0x11100111, +- 0x11101100, 0x11101110, 0x11101101, 0x11101111, +- 0x11010000, 0x11010010, 0x11010001, 0x11010011, +- 0x11011000, 0x11011010, 0x11011001, 0x11011011, +- 0x11010100, 0x11010110, 0x11010101, 0x11010111, +- 0x11011100, 0x11011110, 0x11011101, 0x11011111, +- 0x11110000, 0x11110010, 0x11110001, 0x11110011, +- 0x11111000, 0x11111010, 0x11111001, 0x11111011, +- 0x11110100, 0x11110110, 0x11110101, 0x11110111, +- 0x11111100, 0x11111110, 0x11111101, 0x11111111 +-}; +- +-/* +- * The final permutation array. Like the IP array, used +- * to compute both the left and right results from the bytes +- * of words computed from: +- * +- * ((left & 0x0f0f0f0f) << 4) | (right & 0x0f0f0f0f) for left result +- * (left & 0xf0f0f0f0) | ((right & 0xf0f0f0f0) >> 4) for right result +- * +- * The result from the high order byte is shifted left 6 bits and +- * or'd with the result from the next byte shifted left 4 bits, which +- * is or'd with the result from the next byte shifted left 2 bits, +- * which is or'd with the result from the low byte. +- */ +-const unsigned DES_INT32 des_FP_table[256] = { +- 0x00000000, 0x02000000, 0x00020000, 0x02020000, +- 0x00000200, 0x02000200, 0x00020200, 0x02020200, +- 0x00000002, 0x02000002, 0x00020002, 0x02020002, +- 0x00000202, 0x02000202, 0x00020202, 0x02020202, +- 0x01000000, 0x03000000, 0x01020000, 0x03020000, +- 0x01000200, 0x03000200, 0x01020200, 0x03020200, +- 0x01000002, 0x03000002, 0x01020002, 0x03020002, +- 0x01000202, 0x03000202, 0x01020202, 0x03020202, +- 0x00010000, 0x02010000, 0x00030000, 0x02030000, +- 0x00010200, 0x02010200, 0x00030200, 0x02030200, +- 0x00010002, 0x02010002, 0x00030002, 0x02030002, +- 0x00010202, 0x02010202, 0x00030202, 0x02030202, +- 0x01010000, 0x03010000, 0x01030000, 0x03030000, +- 0x01010200, 0x03010200, 0x01030200, 0x03030200, +- 0x01010002, 0x03010002, 0x01030002, 0x03030002, +- 0x01010202, 0x03010202, 0x01030202, 0x03030202, +- 0x00000100, 0x02000100, 0x00020100, 0x02020100, +- 0x00000300, 0x02000300, 0x00020300, 0x02020300, +- 0x00000102, 0x02000102, 0x00020102, 0x02020102, +- 0x00000302, 0x02000302, 0x00020302, 0x02020302, +- 0x01000100, 0x03000100, 0x01020100, 0x03020100, +- 0x01000300, 0x03000300, 0x01020300, 0x03020300, +- 0x01000102, 0x03000102, 0x01020102, 0x03020102, +- 0x01000302, 0x03000302, 0x01020302, 0x03020302, +- 0x00010100, 0x02010100, 0x00030100, 0x02030100, +- 0x00010300, 0x02010300, 0x00030300, 0x02030300, +- 0x00010102, 0x02010102, 0x00030102, 0x02030102, +- 0x00010302, 0x02010302, 0x00030302, 0x02030302, +- 0x01010100, 0x03010100, 0x01030100, 0x03030100, +- 0x01010300, 0x03010300, 0x01030300, 0x03030300, +- 0x01010102, 0x03010102, 0x01030102, 0x03030102, +- 0x01010302, 0x03010302, 0x01030302, 0x03030302, +- 0x00000001, 0x02000001, 0x00020001, 0x02020001, +- 0x00000201, 0x02000201, 0x00020201, 0x02020201, +- 0x00000003, 0x02000003, 0x00020003, 0x02020003, +- 0x00000203, 0x02000203, 0x00020203, 0x02020203, +- 0x01000001, 0x03000001, 0x01020001, 0x03020001, +- 0x01000201, 0x03000201, 0x01020201, 0x03020201, +- 0x01000003, 0x03000003, 0x01020003, 0x03020003, +- 0x01000203, 0x03000203, 0x01020203, 0x03020203, +- 0x00010001, 0x02010001, 0x00030001, 0x02030001, +- 0x00010201, 0x02010201, 0x00030201, 0x02030201, +- 0x00010003, 0x02010003, 0x00030003, 0x02030003, +- 0x00010203, 0x02010203, 0x00030203, 0x02030203, +- 0x01010001, 0x03010001, 0x01030001, 0x03030001, +- 0x01010201, 0x03010201, 0x01030201, 0x03030201, +- 0x01010003, 0x03010003, 0x01030003, 0x03030003, +- 0x01010203, 0x03010203, 0x01030203, 0x03030203, +- 0x00000101, 0x02000101, 0x00020101, 0x02020101, +- 0x00000301, 0x02000301, 0x00020301, 0x02020301, +- 0x00000103, 0x02000103, 0x00020103, 0x02020103, +- 0x00000303, 0x02000303, 0x00020303, 0x02020303, +- 0x01000101, 0x03000101, 0x01020101, 0x03020101, +- 0x01000301, 0x03000301, 0x01020301, 0x03020301, +- 0x01000103, 0x03000103, 0x01020103, 0x03020103, +- 0x01000303, 0x03000303, 0x01020303, 0x03020303, +- 0x00010101, 0x02010101, 0x00030101, 0x02030101, +- 0x00010301, 0x02010301, 0x00030301, 0x02030301, +- 0x00010103, 0x02010103, 0x00030103, 0x02030103, +- 0x00010303, 0x02010303, 0x00030303, 0x02030303, +- 0x01010101, 0x03010101, 0x01030101, 0x03030101, +- 0x01010301, 0x03010301, 0x01030301, 0x03030301, +- 0x01010103, 0x03010103, 0x01030103, 0x03030103, +- 0x01010303, 0x03010303, 0x01030303, 0x03030303 +-}; +- +- +-/* +- * The SP table is actually the S boxes and the P permutation +- * table combined. This table is actually reordered from the +- * spec, to match the order of key application we follow. +- */ +-const unsigned DES_INT32 des_SP_table[8][64] = { +- { +- 0x00100000, 0x02100001, 0x02000401, 0x00000000, /* 7 */ +- 0x00000400, 0x02000401, 0x00100401, 0x02100400, +- 0x02100401, 0x00100000, 0x00000000, 0x02000001, +- 0x00000001, 0x02000000, 0x02100001, 0x00000401, +- 0x02000400, 0x00100401, 0x00100001, 0x02000400, +- 0x02000001, 0x02100000, 0x02100400, 0x00100001, +- 0x02100000, 0x00000400, 0x00000401, 0x02100401, +- 0x00100400, 0x00000001, 0x02000000, 0x00100400, +- 0x02000000, 0x00100400, 0x00100000, 0x02000401, +- 0x02000401, 0x02100001, 0x02100001, 0x00000001, +- 0x00100001, 0x02000000, 0x02000400, 0x00100000, +- 0x02100400, 0x00000401, 0x00100401, 0x02100400, +- 0x00000401, 0x02000001, 0x02100401, 0x02100000, +- 0x00100400, 0x00000000, 0x00000001, 0x02100401, +- 0x00000000, 0x00100401, 0x02100000, 0x00000400, +- 0x02000001, 0x02000400, 0x00000400, 0x00100001, +- }, +- { +- 0x00808200, 0x00000000, 0x00008000, 0x00808202, /* 1 */ +- 0x00808002, 0x00008202, 0x00000002, 0x00008000, +- 0x00000200, 0x00808200, 0x00808202, 0x00000200, +- 0x00800202, 0x00808002, 0x00800000, 0x00000002, +- 0x00000202, 0x00800200, 0x00800200, 0x00008200, +- 0x00008200, 0x00808000, 0x00808000, 0x00800202, +- 0x00008002, 0x00800002, 0x00800002, 0x00008002, +- 0x00000000, 0x00000202, 0x00008202, 0x00800000, +- 0x00008000, 0x00808202, 0x00000002, 0x00808000, +- 0x00808200, 0x00800000, 0x00800000, 0x00000200, +- 0x00808002, 0x00008000, 0x00008200, 0x00800002, +- 0x00000200, 0x00000002, 0x00800202, 0x00008202, +- 0x00808202, 0x00008002, 0x00808000, 0x00800202, +- 0x00800002, 0x00000202, 0x00008202, 0x00808200, +- 0x00000202, 0x00800200, 0x00800200, 0x00000000, +- 0x00008002, 0x00008200, 0x00000000, 0x00808002, +- }, +- { +- 0x00000104, 0x04010100, 0x00000000, 0x04010004, /* 3 */ +- 0x04000100, 0x00000000, 0x00010104, 0x04000100, +- 0x00010004, 0x04000004, 0x04000004, 0x00010000, +- 0x04010104, 0x00010004, 0x04010000, 0x00000104, +- 0x04000000, 0x00000004, 0x04010100, 0x00000100, +- 0x00010100, 0x04010000, 0x04010004, 0x00010104, +- 0x04000104, 0x00010100, 0x00010000, 0x04000104, +- 0x00000004, 0x04010104, 0x00000100, 0x04000000, +- 0x04010100, 0x04000000, 0x00010004, 0x00000104, +- 0x00010000, 0x04010100, 0x04000100, 0x00000000, +- 0x00000100, 0x00010004, 0x04010104, 0x04000100, +- 0x04000004, 0x00000100, 0x00000000, 0x04010004, +- 0x04000104, 0x00010000, 0x04000000, 0x04010104, +- 0x00000004, 0x00010104, 0x00010100, 0x04000004, +- 0x04010000, 0x04000104, 0x00000104, 0x04010000, +- 0x00010104, 0x00000004, 0x04010004, 0x00010100, +- }, +- { +- 0x00000080, 0x01040080, 0x01040000, 0x21000080, /* 5 */ +- 0x00040000, 0x00000080, 0x20000000, 0x01040000, +- 0x20040080, 0x00040000, 0x01000080, 0x20040080, +- 0x21000080, 0x21040000, 0x00040080, 0x20000000, +- 0x01000000, 0x20040000, 0x20040000, 0x00000000, +- 0x20000080, 0x21040080, 0x21040080, 0x01000080, +- 0x21040000, 0x20000080, 0x00000000, 0x21000000, +- 0x01040080, 0x01000000, 0x21000000, 0x00040080, +- 0x00040000, 0x21000080, 0x00000080, 0x01000000, +- 0x20000000, 0x01040000, 0x21000080, 0x20040080, +- 0x01000080, 0x20000000, 0x21040000, 0x01040080, +- 0x20040080, 0x00000080, 0x01000000, 0x21040000, +- 0x21040080, 0x00040080, 0x21000000, 0x21040080, +- 0x01040000, 0x00000000, 0x20040000, 0x21000000, +- 0x00040080, 0x01000080, 0x20000080, 0x00040000, +- 0x00000000, 0x20040000, 0x01040080, 0x20000080, +- }, +- { +- 0x80401000, 0x80001040, 0x80001040, 0x00000040, /* 4 */ +- 0x00401040, 0x80400040, 0x80400000, 0x80001000, +- 0x00000000, 0x00401000, 0x00401000, 0x80401040, +- 0x80000040, 0x00000000, 0x00400040, 0x80400000, +- 0x80000000, 0x00001000, 0x00400000, 0x80401000, +- 0x00000040, 0x00400000, 0x80001000, 0x00001040, +- 0x80400040, 0x80000000, 0x00001040, 0x00400040, +- 0x00001000, 0x00401040, 0x80401040, 0x80000040, +- 0x00400040, 0x80400000, 0x00401000, 0x80401040, +- 0x80000040, 0x00000000, 0x00000000, 0x00401000, +- 0x00001040, 0x00400040, 0x80400040, 0x80000000, +- 0x80401000, 0x80001040, 0x80001040, 0x00000040, +- 0x80401040, 0x80000040, 0x80000000, 0x00001000, +- 0x80400000, 0x80001000, 0x00401040, 0x80400040, +- 0x80001000, 0x00001040, 0x00400000, 0x80401000, +- 0x00000040, 0x00400000, 0x00001000, 0x00401040, +- }, +- { +- 0x10000008, 0x10200000, 0x00002000, 0x10202008, /* 6 */ +- 0x10200000, 0x00000008, 0x10202008, 0x00200000, +- 0x10002000, 0x00202008, 0x00200000, 0x10000008, +- 0x00200008, 0x10002000, 0x10000000, 0x00002008, +- 0x00000000, 0x00200008, 0x10002008, 0x00002000, +- 0x00202000, 0x10002008, 0x00000008, 0x10200008, +- 0x10200008, 0x00000000, 0x00202008, 0x10202000, +- 0x00002008, 0x00202000, 0x10202000, 0x10000000, +- 0x10002000, 0x00000008, 0x10200008, 0x00202000, +- 0x10202008, 0x00200000, 0x00002008, 0x10000008, +- 0x00200000, 0x10002000, 0x10000000, 0x00002008, +- 0x10000008, 0x10202008, 0x00202000, 0x10200000, +- 0x00202008, 0x10202000, 0x00000000, 0x10200008, +- 0x00000008, 0x00002000, 0x10200000, 0x00202008, +- 0x00002000, 0x00200008, 0x10002008, 0x00000000, +- 0x10202000, 0x10000000, 0x00200008, 0x10002008, +- }, +- { +- 0x08000820, 0x00000800, 0x00020000, 0x08020820, /* 8 */ +- 0x08000000, 0x08000820, 0x00000020, 0x08000000, +- 0x00020020, 0x08020000, 0x08020820, 0x00020800, +- 0x08020800, 0x00020820, 0x00000800, 0x00000020, +- 0x08020000, 0x08000020, 0x08000800, 0x00000820, +- 0x00020800, 0x00020020, 0x08020020, 0x08020800, +- 0x00000820, 0x00000000, 0x00000000, 0x08020020, +- 0x08000020, 0x08000800, 0x00020820, 0x00020000, +- 0x00020820, 0x00020000, 0x08020800, 0x00000800, +- 0x00000020, 0x08020020, 0x00000800, 0x00020820, +- 0x08000800, 0x00000020, 0x08000020, 0x08020000, +- 0x08020020, 0x08000000, 0x00020000, 0x08000820, +- 0x00000000, 0x08020820, 0x00020020, 0x08000020, +- 0x08020000, 0x08000800, 0x08000820, 0x00000000, +- 0x08020820, 0x00020800, 0x00020800, 0x00000820, +- 0x00000820, 0x00020020, 0x08000000, 0x08020800, +- }, +- { +- 0x40084010, 0x40004000, 0x00004000, 0x00084010, /* 2 */ +- 0x00080000, 0x00000010, 0x40080010, 0x40004010, +- 0x40000010, 0x40084010, 0x40084000, 0x40000000, +- 0x40004000, 0x00080000, 0x00000010, 0x40080010, +- 0x00084000, 0x00080010, 0x40004010, 0x00000000, +- 0x40000000, 0x00004000, 0x00084010, 0x40080000, +- 0x00080010, 0x40000010, 0x00000000, 0x00084000, +- 0x00004010, 0x40084000, 0x40080000, 0x00004010, +- 0x00000000, 0x00084010, 0x40080010, 0x00080000, +- 0x40004010, 0x40080000, 0x40084000, 0x00004000, +- 0x40080000, 0x40004000, 0x00000010, 0x40084010, +- 0x00084010, 0x00000010, 0x00004000, 0x40000000, +- 0x00004010, 0x40084000, 0x00080000, 0x40000010, +- 0x00080010, 0x40004010, 0x40000010, 0x00080010, +- 0x00084000, 0x00000000, 0x40004000, 0x00004010, +- 0x40000000, 0x40080010, 0x40084010, 0x00084000 +- }, +-}; +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/f_tables.h b/src/lib/crypto/builtin/des/f_tables.h +deleted file mode 100644 +index fc91b566cf..0000000000 +--- a/src/lib/crypto/builtin/des/f_tables.h ++++ /dev/null +@@ -1,285 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_tables.h */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * DES implementation donated by Dennis Ferguson +- */ +- +-/* +- * des_tables.h - declarations to import the DES tables, used internally +- * by some of the library routines. +- */ +-#ifndef __DES_TABLES_H__ +-#define __DES_TABLES_H__ /* nothing */ +- +-#include "k5-platform.h" +-/* +- * These may be declared const if you wish. Be sure to change the +- * declarations in des_tables.c as well. +- */ +-extern const unsigned DES_INT32 des_IP_table[256]; +-extern const unsigned DES_INT32 des_FP_table[256]; +-extern const unsigned DES_INT32 des_SP_table[8][64]; +- +-/* +- * Use standard shortforms to reference these to save typing +- */ +-#define IP des_IP_table +-#define FP des_FP_table +-#define SP des_SP_table +- +-#ifdef DEBUG +-#define DEB(foofraw) printf foofraw +-#else +-#define DEB(foofraw) /* nothing */ +-#endif +- +-/* +- * Code to do a DES round using the tables. Note that the E expansion +- * is easy to compute algorithmically, especially if done out-of-order. +- * Take a look at its form and compare it to everything involving temp +- * below. Since SP[0-7] don't have any bits in common set it is okay +- * to do the successive xor's. +- * +- * Note too that the SP table has been reordered to match the order of +- * the keys (if the original order of SP was 12345678, the reordered +- * table is 71354682). This is unnecessary, but was done since some +- * compilers seem to like you going through the matrix from beginning +- * to end. +- * +- * There is a difference in the best way to do this depending on whether +- * one is encrypting or decrypting. If encrypting we move forward through +- * the keys and hence should move forward through the table. If decrypting +- * we go back. Part of the need for this comes from trying to emulate +- * existing software which generates a single key schedule and uses it +- * both for encrypting and decrypting. Generating separate encryption +- * and decryption key schedules would allow one to use the same code +- * for both. +- * +- * left, right and temp should be unsigned DES_INT32 values. left and right +- * should be the high and low order parts of the cipher block at the +- * current stage of processing (this makes sense if you read the spec). +- * kp should be an unsigned DES_INT32 pointer which points at the current +- * set of subkeys in the key schedule. It is advanced to the next set +- * (i.e. by 8 bytes) when this is done. +- * +- * This occurs in the innermost loop of the DES function. The four +- * variables should really be in registers. +- * +- * When using this, the inner loop of the DES function might look like: +- * +- * for (i = 0; i < 8; i++) { +- * DES_SP_{EN,DE}CRYPT_ROUND(left, right, temp, kp); +- * DES_SP_{EN,DE}CRYPT_ROUND(right, left, temp, kp); +- * } +- * +- * Note the trick above. You are supposed to do 16 rounds, swapping +- * left and right at the end of each round. By doing two rounds at +- * a time and swapping left and right in the code we can avoid the +- * swaps altogether. +- */ +-#define DES_SP_ENCRYPT_ROUND(left, right, temp, kp) do { \ +- (temp) = (((right) >> 11) | ((right) << 21)) ^ *(kp)++; \ +- (left) ^= SP[0][((temp) >> 24) & 0x3f] \ +- | SP[1][((temp) >> 16) & 0x3f] \ +- | SP[2][((temp) >> 8) & 0x3f] \ +- | SP[3][((temp) ) & 0x3f]; \ +- (temp) = (((right) >> 23) | ((right) << 9)) ^ *(kp)++; \ +- (left) ^= SP[4][((temp) >> 24) & 0x3f] \ +- | SP[5][((temp) >> 16) & 0x3f] \ +- | SP[6][((temp) >> 8) & 0x3f] \ +- | SP[7][((temp) ) & 0x3f]; \ +- } while(0); +- +-#define DES_SP_DECRYPT_ROUND(left, right, temp, kp) do { \ +- (temp) = (((right) >> 23) | ((right) << 9)) ^ *(--(kp)); \ +- (left) ^= SP[7][((temp) ) & 0x3f] \ +- | SP[6][((temp) >> 8) & 0x3f] \ +- | SP[5][((temp) >> 16) & 0x3f] \ +- | SP[4][((temp) >> 24) & 0x3f]; \ +- (temp) = (((right) >> 11) | ((right) << 21)) ^ *(--(kp)); \ +- (left) ^= SP[3][((temp) ) & 0x3f] \ +- | SP[2][((temp) >> 8) & 0x3f] \ +- | SP[1][((temp) >> 16) & 0x3f] \ +- | SP[0][((temp) >> 24) & 0x3f]; \ +- } while (0); +- +-/* +- * Macros to help deal with the initial permutation table. Note +- * the IP table only deals with 32 bits at a time, allowing us to +- * collect the bits we need to deal with each half into an unsigned +- * DES_INT32. By carefully selecting how the bits are ordered we also +- * take advantages of symmetries in the table so that we can use a +- * single table to compute the permutation of all bytes. This sounds +- * complicated, but if you go through the process of designing the +- * table you'll find the symmetries fall right out. +- * +- * The follow macros compute the set of bits used to index the +- * table for produce the left and right permuted result. +- * +- * The inserted cast to unsigned DES_INT32 circumvents a bug in +- * the Macintosh MPW 3.2 C compiler which loses the unsignedness and +- * propagates the high-order bit in the shift. +- */ +-#define DES_IP_LEFT_BITS(left, right) \ +- ((((left) & 0x55555555) << 1) | ((right) & 0x55555555)) +-#define DES_IP_RIGHT_BITS(left, right) \ +- (((left) & 0xaaaaaaaa) | \ +- ( ( (unsigned DES_INT32) ((right) & 0xaaaaaaaa) ) >> 1)) +- +-/* +- * The following macro does an in-place initial permutation given +- * the current left and right parts of the block and a single +- * temporary. Use this more as a guide for rolling your own, though. +- * The best way to do the IP depends on the form of the data you +- * are dealing with. If you use this, though, try to make left, +- * right and temp unsigned DES_INT32s. +- */ +-#define DES_INITIAL_PERM(left, right, temp) do { \ +- (temp) = DES_IP_RIGHT_BITS((left), (right)); \ +- (right) = DES_IP_LEFT_BITS((left), (right)); \ +- (left) = IP[((right) >> 24) & 0xff] \ +- | (IP[((right) >> 16) & 0xff] << 1) \ +- | (IP[((right) >> 8) & 0xff] << 2) \ +- | (IP[(right) & 0xff] << 3); \ +- (right) = IP[((temp) >> 24) & 0xff] \ +- | (IP[((temp) >> 16) & 0xff] << 1) \ +- | (IP[((temp) >> 8) & 0xff] << 2) \ +- | (IP[(temp) & 0xff] << 3); \ +- } while(0); +- +-/* +- * Now the final permutation stuff. The same comments apply to +- * this as to the initial permutation, except that we use different +- * bits and shifts. +- * +- * The inserted cast to unsigned DES_INT32 circumvents a bug in +- * the Macintosh MPW 3.2 C compiler which loses the unsignedness and +- * propagates the high-order bit in the shift. +- */ +-#define DES_FP_LEFT_BITS(left, right) \ +- ((((left) & 0x0f0f0f0f) << 4) | ((right) & 0x0f0f0f0f)) +-#define DES_FP_RIGHT_BITS(left, right) \ +- (((left) & 0xf0f0f0f0) | \ +- ( ( (unsigned DES_INT32) ((right) & 0xf0f0f0f0) ) >> 4)) +- +- +-/* +- * Here is a sample final permutation. Note that there is a trick +- * here. DES requires swapping the left and right parts after the +- * last cipher round but before the final permutation. We do this +- * swapping internally, which is why left and right are confused +- * at the beginning. +- */ +-#define DES_FINAL_PERM(left, right, temp) do { \ +- (temp) = DES_FP_RIGHT_BITS((right), (left)); \ +- (right) = DES_FP_LEFT_BITS((right), (left)); \ +- (left) = (FP[((right) >> 24) & 0xff] << 6) \ +- | (FP[((right) >> 16) & 0xff] << 4) \ +- | (FP[((right) >> 8) & 0xff] << 2) \ +- | FP[(right) & 0xff]; \ +- (right) = (FP[((temp) >> 24) & 0xff] << 6) \ +- | (FP[((temp) >> 16) & 0xff] << 4) \ +- | (FP[((temp) >> 8) & 0xff] << 2) \ +- | FP[temp & 0xff]; \ +- } while(0); +- +- +-/* +- * Finally, as a sample of how all this might be held together, the +- * following two macros do in-place encryptions and decryptions. left +- * and right are two unsigned DES_INT32 variables which at the beginning +- * are expected to hold the clear (encrypted) block in host byte order +- * (left the high order four bytes, right the low order). At the end +- * they will contain the encrypted (clear) block. temp is an unsigned DES_INT32 +- * used as a temporary. kp is an unsigned DES_INT32 pointer pointing at +- * the start of the key schedule. All these should be in registers. +- * +- * You can probably do better than these by rewriting for particular +- * situations. These aren't bad, though. +- * +- * The DEB macros enable debugging when this code breaks (typically +- * when a buggy compiler breaks it), by printing the intermediate values +- * at each stage of the encryption, so that by comparing the output to +- * a known good machine, the location of the first error can be found. +- */ +-#define DES_DO_ENCRYPT_1(left, right, kp) \ +- do { \ +- int i; \ +- unsigned DES_INT32 temp1; \ +- DEB (("do_encrypt %8lX %8lX \n", left, right)); \ +- DES_INITIAL_PERM((left), (right), (temp1)); \ +- DEB ((" after IP %8lX %8lX\n", left, right)); \ +- for (i = 0; i < 8; i++) { \ +- DES_SP_ENCRYPT_ROUND((left), (right), (temp1), (kp)); \ +- DEB ((" round %2d %8lX %8lX \n", i*2, left, right)); \ +- DES_SP_ENCRYPT_ROUND((right), (left), (temp1), (kp)); \ +- DEB ((" round %2d %8lX %8lX \n", 1+i*2, left, right)); \ +- } \ +- DES_FINAL_PERM((left), (right), (temp1)); \ +- (kp) -= (2 * 16); \ +- DEB ((" after FP %8lX %8lX \n", left, right)); \ +- } while (0) +- +-#define DES_DO_DECRYPT_1(left, right, kp) \ +- do { \ +- int i; \ +- unsigned DES_INT32 temp2; \ +- DES_INITIAL_PERM((left), (right), (temp2)); \ +- (kp) += (2 * 16); \ +- for (i = 0; i < 8; i++) { \ +- DES_SP_DECRYPT_ROUND((left), (right), (temp2), (kp)); \ +- DES_SP_DECRYPT_ROUND((right), (left), (temp2), (kp)); \ +- } \ +- DES_FINAL_PERM((left), (right), (temp2)); \ +- } while (0) +- +-#if defined(CONFIG_SMALL) && !defined(CONFIG_SMALL_NO_CRYPTO) +-extern void krb5int_des_do_encrypt_2(unsigned DES_INT32 *l, +- unsigned DES_INT32 *r, +- const unsigned DES_INT32 *k); +-extern void krb5int_des_do_decrypt_2(unsigned DES_INT32 *l, +- unsigned DES_INT32 *r, +- const unsigned DES_INT32 *k); +-#define DES_DO_ENCRYPT(L,R,K) krb5int_des_do_encrypt_2(&(L), &(R), (K)) +-#define DES_DO_DECRYPT(L,R,K) krb5int_des_do_decrypt_2(&(L), &(R), (K)) +-#else +-#define DES_DO_ENCRYPT DES_DO_ENCRYPT_1 +-#define DES_DO_DECRYPT DES_DO_DECRYPT_1 +-#endif +- +-/* +- * These are handy dandy utility thingies for straightening out bytes. +- * Included here because they're used a couple of places. +- */ +-#define GET_HALF_BLOCK(lr, ip) ((lr) = load_32_be(ip), (ip) += 4) +-#define PUT_HALF_BLOCK(lr, op) (store_32_be(lr, op), (op) += 4) +- +-/* Shorthand that we'll need in several places, for creating values that +- really can hold 32 bits regardless of the prevailing int size. */ +-#define FF_UINT32 ((unsigned DES_INT32) 0xFF) +- +-#endif /* __DES_TABLES_H__ */ +diff --git a/src/lib/crypto/builtin/des/key_sched.c b/src/lib/crypto/builtin/des/key_sched.c +deleted file mode 100644 +index d6dedd93c6..0000000000 +--- a/src/lib/crypto/builtin/des/key_sched.c ++++ /dev/null +@@ -1,66 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/key_sched.c */ +-/* +- * Copyright 1985, 1986, 1987, 1988, 1990 by the Massachusetts Institute +- * of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * This routine computes the DES key schedule given a key. The +- * permutations and shifts have been done at compile time, resulting +- * in a direct one-step mapping from the input key to the key +- * schedule. +- * +- * Also checks parity and weak keys. +- * +- * Watch out for the subscripts -- most effectively start at 1 instead +- * of at zero. Maybe some bugs in that area. +- * +- * In case the user wants to cache the computed key schedule, it is +- * passed as an arg. Also implies that caller has explicit control +- * over zeroing both the key schedule and the key. +- * +- * Originally written 6/85 by Steve Miller, MIT Project Athena. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES +- +-int +-mit_des_key_sched(mit_des_cblock k, mit_des_key_schedule schedule) +-{ +- mit_des_make_key_sched(k,schedule); +- +- if (!mit_des_check_key_parity(k)) /* bad parity --> return -1 */ +- return(-1); +- +- if (mit_des_is_weak_key(k)) +- return(-2); +- +- /* if key was good, return 0 */ +- return 0; +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/des/keytest.data b/src/lib/crypto/builtin/des/keytest.data +deleted file mode 100644 +index 7ff34eedcf..0000000000 +--- a/src/lib/crypto/builtin/des/keytest.data ++++ /dev/null +@@ -1,171 +0,0 @@ +-0101010101010101 95F8A5E5DD31D900 8000000000000000 +-0101010101010101 DD7F121CA5015619 4000000000000000 +-0101010101010101 2E8653104F3834EA 2000000000000000 +-0101010101010101 4BD388FF6CD81D4F 1000000000000000 +-0101010101010101 20B9E767B2FB1456 0800000000000000 +-0101010101010101 55579380D77138EF 0400000000000000 +-0101010101010101 6CC5DEFAAF04512F 0200000000000000 +-0101010101010101 0D9F279BA5D87260 0100000000000000 +-0101010101010101 D9031B0271BD5A0A 0080000000000000 +-0101010101010101 424250B37C3DD951 0040000000000000 +-0101010101010101 B8061B7ECD9A21E5 0020000000000000 +-0101010101010101 F15D0F286B65BD28 0010000000000000 +-0101010101010101 ADD0CC8D6E5DEBA1 0008000000000000 +-0101010101010101 E6D5F82752AD63D1 0004000000000000 +-0101010101010101 ECBFE3BD3F591A5E 0002000000000000 +-0101010101010101 F356834379D165CD 0001000000000000 +-0101010101010101 2B9F982F20037FA9 0000800000000000 +-0101010101010101 889DE068A16F0BE6 0000400000000000 +-0101010101010101 E19E275D846A1298 0000200000000000 +-0101010101010101 329A8ED523D71AEC 0000100000000000 +-0101010101010101 E7FCE22557D23C97 0000080000000000 +-0101010101010101 12A9F5817FF2D65D 0000040000000000 +-0101010101010101 A484C3AD38DC9C19 0000020000000000 +-0101010101010101 FBE00A8A1EF8AD72 0000010000000000 +-0101010101010101 750D079407521363 0000008000000000 +-0101010101010101 64FEED9C724C2FAF 0000004000000000 +-0101010101010101 F02B263B328E2B60 0000002000000000 +-0101010101010101 9D64555A9A10B852 0000001000000000 +-0101010101010101 D106FF0BED5255D7 0000000800000000 +-0101010101010101 E1652C6B138C64A5 0000000400000000 +-0101010101010101 E428581186EC8F46 0000000200000000 +-0101010101010101 AEB5F5EDE22D1A36 0000000100000000 +-0101010101010101 E943D7568AEC0C5C 0000000080000000 +-0101010101010101 DF98C8276F54B04B 0000000040000000 +-0101010101010101 B160E4680F6C696F 0000000020000000 +-0101010101010101 FA0752B07D9C4AB8 0000000010000000 +-0101010101010101 CA3A2B036DBC8502 0000000008000000 +-0101010101010101 5E0905517BB59BCF 0000000004000000 +-0101010101010101 814EEB3B91D90726 0000000002000000 +-0101010101010101 4D49DB1532919C9F 0000000001000000 +-0101010101010101 25EB5FC3F8CF0621 0000000000800000 +-0101010101010101 AB6A20C0620D1C6F 0000000000400000 +-0101010101010101 79E90DBC98F92CCA 0000000000200000 +-0101010101010101 866ECEDD8072BB0E 0000000000100000 +-0101010101010101 8B54536F2F3E64A8 0000000000080000 +-0101010101010101 EA51D3975595B86B 0000000000040000 +-0101010101010101 CAFFC6AC4542DE31 0000000000020000 +-0101010101010101 8DD45A2DDF90796C 0000000000010000 +-0101010101010101 1029D55E880EC2D0 0000000000008000 +-0101010101010101 5D86CB23639DBEA9 0000000000004000 +-0101010101010101 1D1CA853AE7C0C5F 0000000000002000 +-0101010101010101 CE332329248F3228 0000000000001000 +-0101010101010101 8405D1ABE24FB942 0000000000000800 +-0101010101010101 E643D78090CA4207 0000000000000400 +-0101010101010101 48221B9937748A23 0000000000000200 +-0101010101010101 DD7C0BBD61FAFD54 0000000000000100 +-0101010101010101 2FBC291A570DB5C4 0000000000000080 +-0101010101010101 E07C30D7E4E26E12 0000000000000040 +-0101010101010101 0953E2258E8E90A1 0000000000000020 +-0101010101010101 5B711BC4CEEBF2EE 0000000000000010 +-0101010101010101 CC083F1E6D9E85F6 0000000000000008 +-0101010101010101 D2FD8867D50D2DFE 0000000000000004 +-0101010101010101 06E7EA22CE92708F 0000000000000002 +-0101010101010101 166B40B44ABA4BD6 0000000000000001 +-8001010101010101 0000000000000000 95A8D72813DAA94D +-4001010101010101 0000000000000000 0EEC1487DD8C26D5 +-2001010101010101 0000000000000000 7AD16FFB79C45926 +-1001010101010101 0000000000000000 D3746294CA6A6CF3 +-0801010101010101 0000000000000000 809F5F873C1FD761 +-0401010101010101 0000000000000000 C02FAFFEC989D1FC +-0201010101010101 0000000000000000 4615AA1D33E72F10 +-0180010101010101 0000000000000000 2055123350C00858 +-0140010101010101 0000000000000000 DF3B99D6577397C8 +-0120010101010101 0000000000000000 31FE17369B5288C9 +-0110010101010101 0000000000000000 DFDD3CC64DAE1642 +-0108010101010101 0000000000000000 178C83CE2B399D94 +-0104010101010101 0000000000000000 50F636324A9B7F80 +-0102010101010101 0000000000000000 A8468EE3BC18F06D +-0101800101010101 0000000000000000 A2DC9E92FD3CDE92 +-0101400101010101 0000000000000000 CAC09F797D031287 +-0101200101010101 0000000000000000 90BA680B22AEB525 +-0101100101010101 0000000000000000 CE7A24F350E280B6 +-0101080101010101 0000000000000000 882BFF0AA01A0B87 +-0101040101010101 0000000000000000 25610288924511C2 +-0101020101010101 0000000000000000 C71516C29C75D170 +-0101018001010101 0000000000000000 5199C29A52C9F059 +-0101014001010101 0000000000000000 C22F0A294A71F29F +-0101012001010101 0000000000000000 EE371483714C02EA +-0101011001010101 0000000000000000 A81FBD448F9E522F +-0101010801010101 0000000000000000 4F644C92E192DFED +-0101010401010101 0000000000000000 1AFA9A66A6DF92AE +-0101010201010101 0000000000000000 B3C1CC715CB879D8 +-0101010180010101 0000000000000000 19D032E64AB0BD8B +-0101010140010101 0000000000000000 3CFAA7A7DC8720DC +-0101010120010101 0000000000000000 B7265F7F447AC6F3 +-0101010110010101 0000000000000000 9DB73B3C0D163F54 +-0101010108010101 0000000000000000 8181B65BABF4A975 +-0101010104010101 0000000000000000 93C9B64042EAA240 +-0101010102010101 0000000000000000 5570530829705592 +-0101010101800101 0000000000000000 8638809E878787A0 +-0101010101400101 0000000000000000 41B9A79AF79AC208 +-0101010101200101 0000000000000000 7A9BE42F2009A892 +-0101010101100101 0000000000000000 29038D56BA6D2745 +-0101010101080101 0000000000000000 5495C6ABF1E5DF51 +-0101010101040101 0000000000000000 AE13DBD561488933 +-0101010101020101 0000000000000000 024D1FFA8904E389 +-0101010101018001 0000000000000000 D1399712F99BF02E +-0101010101014001 0000000000000000 14C1D7C1CFFEC79E +-0101010101012001 0000000000000000 1DE5279DAE3BED6F +-0101010101011001 0000000000000000 E941A33F85501303 +-0101010101010801 0000000000000000 DA99DBBC9A03F379 +-0101010101010401 0000000000000000 B7FC92F91D8E92E9 +-0101010101010201 0000000000000000 AE8E5CAA3CA04E85 +-0101010101010180 0000000000000000 9CC62DF43B6EED74 +-0101010101010140 0000000000000000 D863DBB5C59A91A0 +-0101010101010120 0000000000000000 A1AB2190545B91D7 +-0101010101010110 0000000000000000 0875041E64C570F7 +-0101010101010108 0000000000000000 5A594528BEBEF1CC +-0101010101010104 0000000000000000 FCDB3291DE21F0C0 +-0101010101010102 0000000000000000 869EFD7F9F265A09 +-1046913489980131 0000000000000000 88D55E54F54C97B4 +-1007103489988020 0000000000000000 0C0CC00C83EA48FD +-10071034C8980120 0000000000000000 83BC8EF3A6570183 +-1046103489988020 0000000000000000 DF725DCAD94EA2E9 +-1086911519190101 0000000000000000 E652B53B550BE8B0 +-1086911519580101 0000000000000000 AF527120C485CBB0 +-5107B01519580101 0000000000000000 0F04CE393DB926D5 +-1007B01519190101 0000000000000000 C9F00FFC74079067 +-3107915498080101 0000000000000000 7CFD82A593252B4E +-3107919498080101 0000000000000000 CB49A2F9E91363E3 +-10079115B9080140 0000000000000000 00B588BE70D23F56 +-3107911598080140 0000000000000000 406A9A6AB43399AE +-1007D01589980101 0000000000000000 6CB773611DCA9ADA +-9107911589980101 0000000000000000 67FD21C17DBB5D70 +-9107D01589190101 0000000000000000 9592CB4110430787 +-1007D01598980120 0000000000000000 A6B7FF68A318DDD3 +-1007940498190101 0000000000000000 4D102196C914CA16 +-0107910491190401 0000000000000000 2DFA9F4573594965 +-0107910491190101 0000000000000000 B46604816C0E0774 +-0107940491190401 0000000000000000 6E7E6221A4F34E87 +-19079210981A0101 0000000000000000 AA85E74643233199 +-1007911998190801 0000000000000000 2E5A19DB4D1962D6 +-10079119981A0801 0000000000000000 23A866A809D30894 +-1007921098190101 0000000000000000 D812D961F017D320 +-100791159819010B 0000000000000000 055605816E58608F +-1004801598190101 0000000000000000 ABD88E8B1B7716F1 +-1004801598190102 0000000000000000 537AC95BE69DA1E1 +-1004801598190108 0000000000000000 AED0F6AE3C25CDD8 +-1002911598100104 0000000000000000 B3E35A5EE53E7B8D +-1002911598190104 0000000000000000 61C79C71921A2EF8 +-1002911598100201 0000000000000000 E2F5728F0995013C +-1002911698100101 0000000000000000 1AEAC39A61F0A464 +-7CA110454A1A6E57 01A1D6D039776742 690F5B0D9A26939B +-0131D9619DC1376E 5CD54CA83DEF57DA 7A389D10354BD271 +-07A1133E4A0B2686 0248D43806F67172 868EBB51CAB4599A +-3849674C2602319E 51454B582DDF440A 7178876E01F19B2A +-04B915BA43FEB5B6 42FD443059577FA2 AF37FB421F8C4095 +-0113B970FD34F2CE 059B5E0851CF143A 86A560F10EC6D85B +-0170F175468FB5E6 0756D8E0774761D2 0CD3DA020021DC09 +-43297FAD38E373FE 762514B829BF486A EA676B2CB7DB2B7A +-07A7137045DA2A16 3BDD119049372802 DFD64A815CAF1A0F +-04689104C2FD3B2F 26955F6835AF609A 5C513C9C4886C088 +-37D06BB516CB7546 164D5E404F275232 0A2AEEAE3FF4AB77 +-1F08260D1AC2465E 6B056E18759F5CCA EF1BF03E5DFA575A +-584023641ABA6176 004BD6EF09176062 88BF0DB6D70DEE56 +-025816164629B007 480D39006EE762F2 A1F9915541020B56 +-49793EBC79B3258F 437540C8698F3CFA 6FBF1CAFCFFD0556 +-4FB05E1515AB73A7 072D43A077075292 2F22E49BAB7CA1AC +-49E95D6D4CA229BF 02FE55778117F12A 5A6B612CC26CCE4A +-018310DC409B26D6 1D9D5C5018F728C2 5F4C038ED12B2E41 +-1C587F1C13924FEF 305532286D6F295A 63FAC0D034D9F793 +diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c +deleted file mode 100644 +index 4a19933cad..0000000000 +--- a/src/lib/crypto/builtin/des/t_verify.c ++++ /dev/null +@@ -1,395 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/t_verify.c */ +-/* +- * Copyright 1988, 1990 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* +- * +- * Program to test the correctness of the DES library +- * implementation. +- * +- * exit returns 0 ==> success +- * -1 ==> error +- */ +- +-#include "k5-int.h" +-#include "des_int.h" +-#include +-#include "com_err.h" +- +-static void do_encrypt(unsigned char *, unsigned char *); +-static void do_decrypt(unsigned char *, unsigned char *); +- +-char *progname; +-int nflag = 2; +-int vflag; +-int mflag; +-int zflag; +-int pid; +-int mit_des_debug; +- +-unsigned char cipher_text[64]; +-unsigned char clear_text[64] = "Now is the time for all " ; +-unsigned char clear_text2[64] = "7654321 Now is the time for "; +-unsigned char clear_text3[64] = {2,0,0,0, 1,0,0,0}; +-unsigned char output[64]; +-unsigned char zero_text[8] = {0x0,0,0,0,0,0,0,0}; +-unsigned char msb_text[8] = {0x0,0,0,0, 0,0,0,0x40}; /* to ANSI MSB */ +-unsigned char *input; +- +-/* 0x0123456789abcdef */ +-unsigned char default_key[8] = { +- 0x01,0x23,0x45,0x67,0x89,0xab,0xcd,0xef +-}; +-unsigned char key2[8] = { 0x08,0x19,0x2a,0x3b,0x4c,0x5d,0x6e,0x7f }; +-unsigned char key3[8] = { 0x80,1,1,1,1,1,1,1 }; +-mit_des_cblock s_key; +-unsigned char default_ivec[8] = { +- 0x12,0x34,0x56,0x78,0x90,0xab,0xcd,0xef +-}; +-unsigned char *ivec; +-unsigned char zero_key[8] = {1,1,1,1,1,1,1,1}; /* just parity bits */ +- +-unsigned char cipher1[8] = { +- 0x25,0xdd,0xac,0x3e,0x96,0x17,0x64,0x67 +-}; +-unsigned char cipher2[8] = { +- 0x3f,0xa4,0x0e,0x8a,0x98,0x4d,0x48,0x15 +-}; +-unsigned char cipher3[64] = { +- 0xe5,0xc7,0xcd,0xde,0x87,0x2b,0xf2,0x7c, +- 0x43,0xe9,0x34,0x00,0x8c,0x38,0x9c,0x0f, +- 0x68,0x37,0x88,0x49,0x9a,0x7c,0x05,0xf6 +-}; +-unsigned char checksum[8] = { +- 0x58,0xd2,0xe7,0x7e,0x86,0x06,0x27,0x33 +-}; +- +-unsigned char zresult[8] = { +- 0x8c, 0xa6, 0x4d, 0xe9, 0xc1, 0xb1, 0x23, 0xa7 +-}; +- +-unsigned char mresult[8] = { +- 0xa3, 0x80, 0xe0, 0x2a, 0x6b, 0xe5, 0x46, 0x96 +-}; +- +- +-/* +- * Can also add : +- * plaintext = 0, key = 0, cipher = 0x8ca64de9c1b123a7 (or is it a 1?) +- */ +- +-mit_des_key_schedule sched; +- +-int +-main(argc,argv) +- int argc; +- char *argv[]; +-{ +- /* Local Declarations */ +- size_t in_length; +- int retval; +- int i, j; +- +-#ifdef WINDOWS +- /* Set screen window buffer to infinite size -- MS default is tiny. */ +- _wsetscreenbuf (fileno (stdout), _WINBUFINF); +-#endif +- progname=argv[0]; /* salt away invoking program */ +- +- while (--argc > 0 && (*++argv)[0] == '-') +- for (i=1; argv[0][i] != '\0'; i++) { +- switch (argv[0][i]) { +- +- /* debug flag */ +- case 'd': +- mit_des_debug=3; +- continue; +- +- case 'z': +- zflag = 1; +- continue; +- +- case 'm': +- mflag = 1; +- continue; +- +- default: +- printf("%s: illegal flag \"%c\" ", +- progname,argv[0][i]); +- exit(1); +- } +- }; +- +- if (argc) { +- fprintf(stderr, "Usage: %s [-dmz]\n", progname); +- exit(1); +- } +- +- /* do some initialisation */ +- +- /* use known input and key */ +- +- /* ECB zero text zero key */ +- if (zflag) { +- input = zero_text; +- mit_des_key_sched(zero_key, sched); +- printf("plaintext = key = 0, cipher = 0x8ca64de9c1b123a7\n"); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)zresult, 8) ) { +- printf("verify: error in zero key test\n"); +- exit(-1); +- } +- +- exit(0); +- } +- +- if (mflag) { +- input = msb_text; +- mit_des_key_sched(key3, sched); +- printf("plaintext = 0x00 00 00 00 00 00 00 40, "); +- printf("key = 0x80 01 01 01 01 01 01 01\n"); +- printf(" cipher = 0xa380e02a6be54696\n"); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) { +- printf("%02x ",cipher_text[j]); +- } +- printf("\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)mresult, 8) ) { +- printf("verify: error in msb test\n"); +- exit(-1); +- } +- exit(0); +- } +- +- /* ECB mode Davies and Price */ +- { +- input = zero_text; +- mit_des_key_sched(key2, sched); +- printf("Examples per FIPS publication 81, keys ivs and cipher\n"); +- printf("in hex. These are the correct answers, see below for\n"); +- printf("the actual answers.\n\n"); +- printf("Examples per Davies and Price.\n\n"); +- printf("EXAMPLE ECB\tkey = 08192a3b4c5d6e7f\n"); +- printf("\tclear = 0\n"); +- printf("\tcipher = 25 dd ac 3e 96 17 64 67\n"); +- printf("ACTUAL ECB\n"); +- printf("\tclear \"%s\"\n", input); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)cipher1, 8) ) { +- printf("verify: error in ECB encryption\n"); +- exit(-1); +- } +- else +- printf("verify: ECB encryption is correct\n\n"); +- } +- +- /* ECB mode */ +- { +- mit_des_key_sched(default_key, sched); +- input = clear_text; +- ivec = default_ivec; +- printf("EXAMPLE ECB\tkey = 0123456789abcdef\n"); +- printf("\tclear = \"Now is the time for all \"\n"); +- printf("\tcipher = 3f a4 0e 8a 98 4d 48 15 ...\n"); +- printf("ACTUAL ECB\n\tclear \"%s\"",input); +- do_encrypt(input,cipher_text); +- printf("\n\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) { +- printf("%02x ",cipher_text[j]); +- } +- printf("\n\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)cipher2, 8) ) { +- printf("verify: error in ECB encryption\n"); +- exit(-1); +- } +- else +- printf("verify: ECB encryption is correct\n\n"); +- } +- +- /* CBC mode */ +- printf("EXAMPLE CBC\tkey = 0123456789abcdef"); +- printf("\tiv = 1234567890abcdef\n"); +- printf("\tclear = \"Now is the time for all \"\n"); +- printf("\tcipher =\te5 c7 cd de 87 2b f2 7c\n"); +- printf("\t\t\t43 e9 34 00 8c 38 9c 0f\n"); +- printf("\t\t\t68 37 88 49 9a 7c 05 f6\n"); +- +- printf("ACTUAL CBC\n\tclear \"%s\"\n",input); +- in_length = strlen((char *)input); +- if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) input, +- (mit_des_cblock *) cipher_text, +- (size_t) in_length, +- sched, +- ivec, +- MIT_DES_ENCRYPT))) { +- com_err("des verify", retval, "can't encrypt"); +- exit(-1); +- } +- printf("\tciphertext = (low to high bytes)\n"); +- for (i = 0; i <= 2; i++) { +- printf("\t\t"); +- for (j = 0; j <= 7; j++) { +- printf("%02x ",cipher_text[i*8+j]); +- } +- printf("\n"); +- } +- if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) cipher_text, +- (mit_des_cblock *) clear_text, +- (size_t) in_length, +- sched, +- ivec, +- MIT_DES_DECRYPT))) { +- com_err("des verify", retval, "can't decrypt"); +- exit(-1); +- } +- printf("\tdecrypted clear_text = \"%s\"\n",clear_text); +- +- if ( memcmp((char *)cipher_text, (char *)cipher3, in_length) ) { +- printf("verify: error in CBC encryption\n"); +- exit(-1); +- } +- else +- printf("verify: CBC encryption is correct\n\n"); +- +- printf("EXAMPLE CBC checksum"); +- printf("\tkey = 0123456789abcdef\tiv = 1234567890abcdef\n"); +- printf("\tclear =\t\t\"7654321 Now is the time for \"\n"); +- printf("\tchecksum\t58 d2 e7 7e 86 06 27 33, "); +- printf("or some part thereof\n"); +- input = clear_text2; +- mit_des_cbc_cksum(input,cipher_text, strlen((char *)input), +- sched,ivec); +- printf("ACTUAL CBC checksum\n"); +- printf("\t\tencrypted cksum = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n\n"); +- if ( memcmp((char *)cipher_text, (char *)checksum, 8) ) { +- printf("verify: error in CBC checksum\n"); +- exit(-1); +- } +- else +- printf("verify: CBC checksum is correct\n\n"); +- +- exit(0); +-} +- +-static void +-do_encrypt(in,out) +- unsigned char *in; +- unsigned char *out; +-{ +- int i, j; +- for (i =1; i<=nflag; i++) { +- mit_des_cbc_encrypt((const mit_des_cblock *)in, +- (mit_des_cblock *)out, +- 8, +- sched, +- zero_text, +- MIT_DES_ENCRYPT); +- if (mit_des_debug) { +- printf("\nclear %s\n",in); +- for (j = 0; j<=7; j++) +- printf("%02X ",in[j] & 0xff); +- printf("\tcipher "); +- for (j = 0; j<=7; j++) +- printf("%02X ",out[j] & 0xff); +- } +- } +-} +- +-static void +-do_decrypt(in,out) +- unsigned char *out; +- unsigned char *in; +- /* try to invert it */ +-{ +- int i, j; +- for (i =1; i<=nflag; i++) { +- mit_des_cbc_encrypt((const mit_des_cblock *)out, +- (mit_des_cblock *)in, +- 8, +- sched, +- zero_text, +- MIT_DES_DECRYPT); +- if (mit_des_debug) { +- printf("clear %s\n",in); +- for (j = 0; j<=7; j++) +- printf("%02X ",in[j] & 0xff); +- printf("\tcipher "); +- for (j = 0; j<=7; j++) +- printf("%02X ",out[j] & 0xff); +- } +- } +-} +- +-/* +- * Fake out the DES library, for the purposes of testing. +- */ +- +-int +-mit_des_is_weak_key(key) +- mit_des_cblock key; +-{ +- return 0; /* fake it out for testing */ +-} +diff --git a/src/lib/crypto/builtin/des/weak_key.c b/src/lib/crypto/builtin/des/weak_key.c +deleted file mode 100644 +index f8304a3638..0000000000 +--- a/src/lib/crypto/builtin/des/weak_key.c ++++ /dev/null +@@ -1,90 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/weak_key.c */ +-/* +- * Copyright 1989,1990 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * Under U.S. law, this software may not be exported outside the US +- * without license from the U.S. Commerce department. +- * +- * These routines form the library interface to the DES facilities. +- * +- * Originally written 8/85 by Steve Miller, MIT Project Athena. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES +- +-/* +- * The following are the weak DES keys: +- */ +-static const mit_des_cblock weak[16] = { +- /* weak keys */ +- {0x01,0x01,0x01,0x01,0x01,0x01,0x01,0x01}, +- {0xfe,0xfe,0xfe,0xfe,0xfe,0xfe,0xfe,0xfe}, +- {0x1f,0x1f,0x1f,0x1f,0x0e,0x0e,0x0e,0x0e}, +- {0xe0,0xe0,0xe0,0xe0,0xf1,0xf1,0xf1,0xf1}, +- +- /* semi-weak */ +- {0x01,0xfe,0x01,0xfe,0x01,0xfe,0x01,0xfe}, +- {0xfe,0x01,0xfe,0x01,0xfe,0x01,0xfe,0x01}, +- +- {0x1f,0xe0,0x1f,0xe0,0x0e,0xf1,0x0e,0xf1}, +- {0xe0,0x1f,0xe0,0x1f,0xf1,0x0e,0xf1,0x0e}, +- +- {0x01,0xe0,0x01,0xe0,0x01,0xf1,0x01,0xf1}, +- {0xe0,0x01,0xe0,0x01,0xf1,0x01,0xf1,0x01}, +- +- {0x1f,0xfe,0x1f,0xfe,0x0e,0xfe,0x0e,0xfe}, +- {0xfe,0x1f,0xfe,0x1f,0xfe,0x0e,0xfe,0x0e}, +- +- {0x01,0x1f,0x01,0x1f,0x01,0x0e,0x01,0x0e}, +- {0x1f,0x01,0x1f,0x01,0x0e,0x01,0x0e,0x01}, +- +- {0xe0,0xfe,0xe0,0xfe,0xf1,0xfe,0xf1,0xfe}, +- {0xfe,0xe0,0xfe,0xe0,0xfe,0xf1,0xfe,0xf1} +-}; +- +-/* +- * mit_des_is_weak_key: returns true iff key is a [semi-]weak des key. +- * +- * Requires: key has correct odd parity. +- */ +-int +-mit_des_is_weak_key(mit_des_cblock key) +-{ +- unsigned int i; +- const mit_des_cblock *weak_p = weak; +- +- for (i = 0; i < (sizeof(weak)/sizeof(mit_des_cblock)); i++) { +- if (!memcmp(weak_p++,key,sizeof(mit_des_cblock))) +- return 1; +- } +- +- return 0; +-} +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/builtin/enc_provider/Makefile.in b/src/lib/crypto/builtin/enc_provider/Makefile.in +index 6ad7cbd4e0..655966b255 100644 +--- a/src/lib/crypto/builtin/enc_provider/Makefile.in ++++ b/src/lib/crypto/builtin/enc_provider/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)crypto$(S)builtin$(S)enc_provider + BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES = -I$(srcdir)/../des -I$(srcdir)/../aes -I$(srcdir)/../camellia \ ++LOCALINCLUDES = -I$(srcdir)/../aes -I$(srcdir)/../camellia \ + -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) + + ##DOS##BUILDTOP = ..\..\..\.. +@@ -8,19 +8,16 @@ LOCALINCLUDES = -I$(srcdir)/../des -I$(srcdir)/../aes -I$(srcdir)/../camellia \ + ##DOS##OBJFILE = ..\..\$(OUTPRE)enc_provider.lst + + STLIBOBJS= \ +- des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ + $(srcdir)/rc4.c +diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps +index a3414a38ec..dc29d9fce8 100644 +--- a/src/lib/crypto/builtin/enc_provider/deps ++++ b/src/lib/crypto/builtin/enc_provider/deps +@@ -1,17 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../des/des_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des3.c + aes.so aes.po $(OUTPRE)aes.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/builtin/enc_provider/des3.c b/src/lib/crypto/builtin/enc_provider/des3.c +deleted file mode 100644 +index c2634d5e10..0000000000 +--- a/src/lib/crypto/builtin/enc_provider/des3.c ++++ /dev/null +@@ -1,109 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-#ifdef K5_BUILTIN_DES +- +-static krb5_error_code +-validate_and_schedule(krb5_key key, const krb5_data *ivec, +- const krb5_crypto_iov *data, size_t num_data, +- mit_des3_key_schedule *schedule) +-{ +- if (key->keyblock.length != 24) +- return(KRB5_BAD_KEYSIZE); +- if (iov_total_length(data, num_data, FALSE) % 8 != 0) +- return(KRB5_BAD_MSIZE); +- if (ivec && (ivec->length != 8)) +- return(KRB5_BAD_MSIZE); +- +- switch (mit_des3_key_sched(*(mit_des3_cblock *)key->keyblock.contents, +- *schedule)) { +- case -1: +- return(KRB5DES_BAD_KEYPAR); +- case -2: +- return(KRB5DES_WEAK_KEY); +- } +- return 0; +-} +- +-static krb5_error_code +-k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des3_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, &schedule); +- if (err) +- return err; +- +- /* this has a return value, but the code always returns zero */ +- krb5int_des3_cbc_encrypt(data, num_data, +- schedule[0], schedule[1], schedule[2], +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- +- return(0); +-} +- +-static krb5_error_code +-k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des3_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, &schedule); +- if (err) +- return err; +- +- /* this has a return value, but the code always returns zero */ +- krb5int_des3_cbc_decrypt(data, num_data, +- schedule[0], schedule[1], schedule[2], +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des3 = { +- 8, +- 21, 24, +- k5_des3_encrypt, +- k5_des3_decrypt, +- NULL, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +- +-#endif /* K5_BUILTIN_DES */ +diff --git a/src/lib/crypto/crypto_tests/t_cf2.expected b/src/lib/crypto/crypto_tests/t_cf2.expected +index f8251a16cb..bc6aa50c84 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.expected ++++ b/src/lib/crypto/crypto_tests/t_cf2.expected +@@ -1,6 +1,5 @@ + 97df97e4b798b29eb31ed7280287a92a + 4d6ca4e629785c1f01baf55e2e548566b9617ae3a96868c337cb93b5e72b1c7b +-e58f9eb643862c13ad38e529313462a7f73e62834fe54a01 + 24d7f6b6bae4e5c00d2082c5ebab3672 + edd02a39d2dbde31611c16e610be062c + 67f6ea530aea85a37dcbb23349ea52dcc61ca8493ff557252327fd8304341584 +diff --git a/src/lib/crypto/crypto_tests/t_cf2.in b/src/lib/crypto/crypto_tests/t_cf2.in +index 73e2f8fbc9..c4d23b506b 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.in ++++ b/src/lib/crypto/crypto_tests/t_cf2.in +@@ -8,11 +8,6 @@ key1 + key2 + a + b +-16 +-key1 +-key2 +-a +-b + 23 + key1 + key2 +diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c +index 557340ec5e..9f9a177ef0 100644 +--- a/src/lib/crypto/crypto_tests/t_cksums.c ++++ b/src/lib/crypto/crypto_tests/t_cksums.c +@@ -59,16 +59,6 @@ struct test { + "\xDA\x39\xA3\xEE\x5E\x6B\x4B\x0D\x32\x55\xBF\xEF\x95\x60\x18\x90" + "\xAF\xD8\x07\x09" } + }, +- { +- { KV5M_DATA, 9, "six seven" }, +- CKSUMTYPE_HMAC_SHA1_DES3, ENCTYPE_DES3_CBC_SHA1, 2, +- { KV5M_DATA, 24, +- "\x7A\x25\xDF\x89\x92\x29\x6D\xCE\xDA\x0E\x13\x5B\xC4\x04\x6E\x23" +- "\x75\xB3\xC1\x4C\x98\xFB\xC1\x62" }, +- { KV5M_DATA, 20, +- "\x0E\xEF\xC9\xC3\xE0\x49\xAA\xBC\x1B\xA5\xC4\x01\x67\x7D\x9A\xB6" +- "\x99\x08\x2B\xB4" } +- }, + { + { KV5M_DATA, 37, "eight nine ten eleven twelve thirteen" }, + CKSUMTYPE_HMAC_SHA1_96_AES128, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 3, +diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c +index a40a855007..716f2c337a 100644 +--- a/src/lib/crypto/crypto_tests/t_decrypt.c ++++ b/src/lib/crypto/crypto_tests/t_decrypt.c +@@ -39,62 +39,6 @@ struct test { + krb5_data keybits; + krb5_data ciphertext; + } test_cases[] = { +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 0, "", }, 0, +- { KV5M_DATA, 24, +- "\x7A\x25\xDF\x89\x92\x29\x6D\xCE\xDA\x0E\x13\x5B\xC4\x04\x6E\x23" +- "\x75\xB3\xC1\x4C\x98\xFB\xC1\x62" }, +- { KV5M_DATA, 28, +- "\x54\x8A\xF4\xD5\x04\xF7\xD7\x23\x30\x3F\x12\x17\x5F\xE8\x38\x6B" +- "\x7B\x53\x35\xA9\x67\xBA\xD6\x1F\x3B\xF0\xB1\x43" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 1, "1", }, 1, +- { KV5M_DATA, 24, +- "\xBC\x07\x83\x89\x15\x13\xD5\xCE\x57\xBC\x13\x8F\xD3\xC1\x1A\xE6" +- "\x40\x45\x23\x85\x32\x29\x62\xB6" }, +- { KV5M_DATA, 36, +- "\x9C\x3C\x1D\xBA\x47\x47\xD8\x5A\xF2\x91\x6E\x47\x45\xF2\xDC\xE3" +- "\x80\x46\x79\x6E\x51\x04\xBC\xCD\xFB\x66\x9A\x91\xD4\x4B\xC3\x56" +- "\x66\x09\x45\xC7" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 9, "9 bytesss", }, 2, +- { KV5M_DATA, 24, +- "\x2F\xD0\xF7\x25\xCE\x04\x10\x0D\x2F\xC8\xA1\x80\x98\x83\x1F\x85" +- "\x0B\x45\xD9\xEF\x85\x0B\xD9\x20" }, +- { KV5M_DATA, 44, +- "\xCF\x91\x44\xEB\xC8\x69\x79\x81\x07\x5A\x8B\xAD\x8D\x74\xE5\xD7" +- "\xD5\x91\xEB\x7D\x97\x70\xC7\xAD\xA2\x5E\xE8\xC5\xB3\xD6\x94\x44" +- "\xDF\xEC\x79\xA5\xB7\xA0\x14\x82\xD9\xAF\x74\xE6" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 13, "13 bytes byte", }, 3, +- { KV5M_DATA, 24, +- "\x0D\xD5\x20\x94\xE0\xF4\x1C\xEC\xCB\x5B\xE5\x10\xA7\x64\xB3\x51" +- "\x76\xE3\x98\x13\x32\xF1\xE5\x98" }, +- { KV5M_DATA, 44, +- "\x83\x9A\x17\x08\x1E\xCB\xAF\xBC\xDC\x91\xB8\x8C\x69\x55\xDD\x3C" +- "\x45\x14\x02\x3C\xF1\x77\xB7\x7B\xF0\xD0\x17\x7A\x16\xF7\x05\xE8" +- "\x49\xCB\x77\x81\xD7\x6A\x31\x6B\x19\x3F\x8D\x30" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, +- { KV5M_DATA, 24, +- "\xF1\x16\x86\xCB\xBC\x9E\x23\xEA\x54\xFE\xCD\x2A\x3D\xCD\xFB\x20" +- "\xB6\xFE\x98\xBF\x26\x45\xC4\xC4" }, +- { KV5M_DATA, 60, +- "\x89\x43\x3E\x83\xFD\x0E\xA3\x66\x6C\xFF\xCD\x18\xD8\xDE\xEB\xC5" +- "\x3B\x9A\x34\xED\xBE\xB1\x59\xD9\xF6\x67\xC6\xC2\xB9\xA9\x64\x40" +- "\x1D\x55\xE7\xE9\xC6\x8D\x64\x8D\x65\xC3\xAA\x84\xFF\xA3\x79\x0C" +- "\x14\xA8\x64\xDA\x80\x73\xA9\xA9\x5C\x4B\xA2\xBC" } +- }, +- + { + ENCTYPE_ARCFOUR_HMAC, + { KV5M_DATA, 0, "", }, 0, +@@ -524,7 +468,6 @@ printhex(const char *head, void *data, size_t len) + + static krb5_enctype + enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_derive.c b/src/lib/crypto/crypto_tests/t_derive.c +index afbf7477f6..93ce30da20 100644 +--- a/src/lib/crypto/crypto_tests/t_derive.c ++++ b/src/lib/crypto/crypto_tests/t_derive.c +@@ -38,41 +38,6 @@ struct test { + enum deriv_alg alg; + krb5_data expected_key; + } test_cases[] = { +- /* Kc, Ke, Kei for a DES3 key */ +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\x99" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\xF7\x8C\x49\x6D\x16\xE6\xC2\xDA\xE0\xE0\xB6\xC2\x40\x57\xA8\x4C" +- "\x04\x26\xAE\xEF\x26\xFD\x6D\xCE" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\xAA" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\x5B\x57\x23\xD0\xB6\x34\xCB\x68\x4C\x3E\xBA\x52\x64\xE9\xA7\x0D" +- "\x52\xE6\x83\x23\x1A\xD3\xC4\xCE" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\x55" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\xA7\x7C\x94\x98\x0E\x9B\x73\x45\xA8\x15\x25\xC4\x23\xA7\x37\xCE" +- "\x67\xF4\xCD\x91\xB6\xB3\xDA\x45" } +- }, +- + /* Kc, Ke, Ki for an AES-128 key */ + { + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +@@ -286,7 +251,6 @@ static const struct krb5_enc_provider * + get_enc_provider(krb5_enctype enctype) + { + switch (enctype) { +- case ENCTYPE_DES3_CBC_SHA1: return &krb5int_enc_des3; + case ENCTYPE_AES128_CTS_HMAC_SHA1_96: return &krb5int_enc_aes128; + case ENCTYPE_AES256_CTS_HMAC_SHA1_96: return &krb5int_enc_aes256; + case ENCTYPE_CAMELLIA128_CTS_CMAC: return &krb5int_enc_camellia128; +diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c +index bd9b94691c..290a72e1e0 100644 +--- a/src/lib/crypto/crypto_tests/t_encrypt.c ++++ b/src/lib/crypto/crypto_tests/t_encrypt.c +@@ -37,7 +37,6 @@ + + /* What enctypes should we test?*/ + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_short.c b/src/lib/crypto/crypto_tests/t_short.c +index d4c2b97dfd..4466b71158 100644 +--- a/src/lib/crypto/crypto_tests/t_short.c ++++ b/src/lib/crypto/crypto_tests/t_short.c +@@ -34,7 +34,6 @@ + #include "k5-int.h" + + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c +index cdb1acc6d0..ef4c4a7d3b 100644 +--- a/src/lib/crypto/crypto_tests/t_str2key.c ++++ b/src/lib/crypto/crypto_tests/t_str2key.c +@@ -35,58 +35,6 @@ struct test { + krb5_error_code expected_err; + krb5_boolean allow_weak; + } test_cases[] = { +- /* Test vectors from RFC 3961 appendix A.4. */ +- { +- ENCTYPE_DES3_CBC_SHA1, +- "password", +- { KV5M_DATA, 21, "ATHENA.MIT.EDUraeburn" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C" +- "\x31\x3E\x3B\xFE\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "potatoe", +- { KV5M_DATA, 19, "WHITEHOUSE.GOVdanny" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\xDF\xCD\x23\x3D\xD0\xA4\x32\x04\xEA\x6D\xC4\x37" +- "\xFB\x15\xE0\x61\xB0\x29\x79\xC1\xF7\x4F\x37\x7A" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "penny", +- { KV5M_DATA, 19, "EXAMPLE.COMbuckaroo" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x6D\x2F\xCD\xF2\xD6\xFB\xBC\x3D\xDC\xAD\xB5\xDA" +- "\x57\x10\xA2\x34\x89\xB0\xD3\xB6\x9D\x5D\x9D\x4A" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "\xC3\x9F", +- { KV5M_DATA, 23, "ATHENA.MIT.EDUJuri\xC5\xA1\x69\xC4\x87" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x16\xD5\xA4\x0E\x1C\xE3\xBA\xCB\x61\xB9\xDC\xE0" +- "\x04\x70\x32\x4C\x83\x19\x73\xA7\xB9\x52\xFE\xB0" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "\xF0\x9D\x84\x9E", +- { KV5M_DATA, 18, "EXAMPLE.COMpianist" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x85\x76\x37\x26\x58\x5D\xBC\x1C\xCE\x6E\xC4\x3E" +- "\x1F\x75\x1F\x07\xF1\xC4\xCB\xB0\x98\xF4\x0B\x19" }, +- 0, +- FALSE +- }, +- + /* Test vectors from RFC 3962 appendix B. */ + { + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c +index bcf5c9106f..eb107dbcd2 100644 +--- a/src/lib/crypto/crypto_tests/vectors.c ++++ b/src/lib/crypto/crypto_tests/vectors.c +@@ -190,8 +190,6 @@ test_s2k (krb5_enctype enctype) + } + } + +-static void test_des3_s2k () { test_s2k (ENCTYPE_DES3_CBC_SHA1); } +- + static void + keyToData (krb5_keyblock *k, krb5_data *d) + { +@@ -208,8 +206,6 @@ void check_error (int r, int line) { + } + #define CHECK check_error(r, __LINE__) + +-extern struct krb5_enc_provider krb5int_enc_des3; +-struct krb5_enc_provider *enc = &krb5int_enc_des3; + extern struct krb5_enc_provider krb5int_enc_aes128, krb5int_enc_aes256; + + void DK (krb5_keyblock *out, krb5_keyblock *in, const krb5_data *usage) { +diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in +index cb2e40a3a5..f66698bd53 100644 +--- a/src/lib/crypto/krb/Makefile.in ++++ b/src/lib/crypto/krb/Makefile.in +@@ -47,7 +47,6 @@ STLIBOBJS=\ + prf.o \ + prf_aes2.o \ + prf_cmac.o \ +- prf_des.o \ + prf_dk.o \ + prf_rc4.o \ + prng.o \ +@@ -103,7 +102,6 @@ OBJS=\ + $(OUTPRE)prf.$(OBJEXT) \ + $(OUTPRE)prf_aes2.$(OBJEXT) \ + $(OUTPRE)prf_cmac.$(OBJEXT) \ +- $(OUTPRE)prf_des.$(OBJEXT) \ + $(OUTPRE)prf_dk.$(OBJEXT) \ + $(OUTPRE)prf_rc4.$(OBJEXT) \ + $(OUTPRE)prng.$(OBJEXT) \ +@@ -159,7 +157,6 @@ SRCS=\ + $(srcdir)/prf.c \ + $(srcdir)/prf_aes2.c \ + $(srcdir)/prf_cmac.c \ +- $(srcdir)/prf_des.c \ + $(srcdir)/prf_dk.c \ + $(srcdir)/prf_rc4.c \ + $(srcdir)/prng.c \ +diff --git a/src/lib/crypto/krb/cksumtypes.c b/src/lib/crypto/krb/cksumtypes.c +index f7ba322f24..25a3ffd2d2 100644 +--- a/src/lib/crypto/krb/cksumtypes.c ++++ b/src/lib/crypto/krb/cksumtypes.c +@@ -52,12 +52,6 @@ const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { + krb5int_unkeyed_checksum, NULL, + 20, 20, CKSUM_UNKEYED }, + +- { CKSUMTYPE_HMAC_SHA1_DES3, +- "hmac-sha1-des3", { "hmac-sha1-des3-kd" }, "HMAC-SHA1 DES3 key", +- &krb5int_enc_des3, &krb5int_hash_sha1, +- krb5int_dk_checksum, NULL, +- 20, 20, 0 }, +- + { CKSUMTYPE_HMAC_MD5_ARCFOUR, + "hmac-md5-rc4", { "hmac-md5-enc", "hmac-md5-earcfour" }, + "Microsoft HMAC MD5", +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index 3629616d96..1ee4b30e02 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -332,8 +332,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, + /* Random to key */ + krb5_error_code k5_rand2key_direct(const krb5_data *randombits, + krb5_keyblock *keyblock); +-krb5_error_code k5_rand2key_des3(const krb5_data *randombits, +- krb5_keyblock *keyblock); + + /* Pseudo-random function */ + krb5_error_code krb5int_des_prf(const struct krb5_keytypes *ktp, +@@ -411,11 +409,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); + /* Ensure library initialization has occurred. */ + int krb5int_crypto_init(void); + +-/* DES default state initialization handler (used by module enc providers). */ +-krb5_error_code krb5int_des_init_state(const krb5_keyblock *key, +- krb5_keyusage keyusage, +- krb5_data *state_out); +- + /* Default state cleanup handler (used by module enc providers). */ + void krb5int_default_free_state(krb5_data *state); + +@@ -468,7 +461,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); + /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ + + /* Modules must implement the following enc_providers and hash_providers: */ +-extern const struct krb5_enc_provider krb5int_enc_des3; + extern const struct krb5_enc_provider krb5int_enc_arcfour; + extern const struct krb5_enc_provider krb5int_enc_aes128; + extern const struct krb5_enc_provider krb5int_enc_aes256; +@@ -485,9 +477,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; + + /* Modules must implement the following functions. */ + +-/* Set the parity bits to the correct values in keybits. */ +-void k5_des_fixup_key_parity(unsigned char *keybits); +- + /* Compute an HMAC using the provided hash function, key, and data, storing the + * result into output (caller-allocated). */ + krb5_error_code krb5int_hmac(const struct krb5_hash_provider *hash, +diff --git a/src/lib/crypto/krb/default_state.c b/src/lib/crypto/krb/default_state.c +index 0757c8b02c..f89dc79023 100644 +--- a/src/lib/crypto/krb/default_state.c ++++ b/src/lib/crypto/krb/default_state.c +@@ -32,16 +32,6 @@ + + #include "crypto_int.h" + +-krb5_error_code +-krb5int_des_init_state(const krb5_keyblock *key, krb5_keyusage usage, +- krb5_data *state_out) +-{ +- if (alloc_data(state_out, 8)) +- return ENOMEM; +- +- return 0; +-} +- + void + krb5int_default_free_state(krb5_data *state) + { +diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c +index 1542d40629..a0037912a7 100644 +--- a/src/lib/crypto/krb/enctype_util.c ++++ b/src/lib/crypto/krb/enctype_util.c +@@ -45,6 +45,9 @@ struct { + { ENCTYPE_DES_CBC_MD5, "des-cbc-md5" }, + { ENCTYPE_DES_CBC_RAW, "des-cbc-raw" }, + { ENCTYPE_DES_HMAC_SHA1, "des-hmac-sha1" }, ++ { ENCTYPE_DES3_CBC_SHA, "des3-cbc-sha1" }, ++ { ENCTYPE_DES3_CBC_RAW, "des3-cbc-raw" }, ++ { ENCTYPE_DES3_CBC_SHA1, "des3-hmac-sha1" }, + { ENCTYPE_NULL, NULL } + }; + +diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c +index fc278783b9..7635393a41 100644 +--- a/src/lib/crypto/krb/etypes.c ++++ b/src/lib/crypto/krb/etypes.c +@@ -35,27 +35,6 @@ + + /* Deprecations come from RFC 6649 and RFC 8249. */ + const struct krb5_keytypes krb5int_enctypes_list[] = { +- { ENCTYPE_DES3_CBC_RAW, +- "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", +- &krb5int_enc_des3, NULL, +- 16, +- krb5int_raw_crypto_length, krb5int_raw_encrypt, krb5int_raw_decrypt, +- krb5int_dk_string_to_key, k5_rand2key_des3, +- NULL, /*PRF*/ +- 0, +- ETYPE_WEAK | ETYPE_DEPRECATED, 112 }, +- +- { ENCTYPE_DES3_CBC_SHA1, +- "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, +- "Triple DES cbc mode with HMAC/sha1", +- &krb5int_enc_des3, &krb5int_hash_sha1, +- 16, +- krb5int_dk_crypto_length, krb5int_dk_encrypt, krb5int_dk_decrypt, +- krb5int_dk_string_to_key, k5_rand2key_des3, +- krb5int_dk_prf, +- CKSUMTYPE_HMAC_SHA1_DES3, +- ETYPE_DEPRECATED, 112 }, +- + /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we + * consider its strength degraded and assign it an SSF value of 64. */ + { ENCTYPE_ARCFOUR_HMAC, +diff --git a/src/lib/crypto/krb/prf_des.c b/src/lib/crypto/krb/prf_des.c +deleted file mode 100644 +index 7a2d719c5f..0000000000 +--- a/src/lib/crypto/krb/prf_des.c ++++ /dev/null +@@ -1,47 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/prf_des.c - RFC 3961 DES-based PRF */ +-/* +- * Copyright (C) 2004, 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +- +-krb5_error_code +-krb5int_des_prf(const struct krb5_keytypes *ktp, krb5_key key, +- const krb5_data *in, krb5_data *out) +-{ +- const struct krb5_hash_provider *hash = &krb5int_hash_md5; +- krb5_crypto_iov iov; +- krb5_error_code ret; +- +- /* Compute a hash of the input, storing into the output buffer. */ +- iov.flags = KRB5_CRYPTO_TYPE_DATA; +- iov.data = *in; +- ret = hash->hash(&iov, 1, out); +- if (ret != 0) +- return ret; +- +- /* Encrypt the hash in place. */ +- iov.data = *out; +- return ktp->enc->encrypt(key, NULL, &iov, 1); +-} +diff --git a/src/lib/crypto/krb/random_to_key.c b/src/lib/crypto/krb/random_to_key.c +index 9394385aa0..863090beb2 100644 +--- a/src/lib/crypto/krb/random_to_key.c ++++ b/src/lib/crypto/krb/random_to_key.c +@@ -71,31 +71,3 @@ k5_rand2key_direct(const krb5_data *randombits, krb5_keyblock *keyblock) + memcpy(keyblock->contents, randombits->data, randombits->length); + return 0; + } +- +-static inline void +-eighth_byte(unsigned char *b) +-{ +- b[7] = (((b[0] & 1) << 1) | ((b[1] & 1) << 2) | ((b[2] & 1) << 3) | +- ((b[3] & 1) << 4) | ((b[4] & 1) << 5) | ((b[5] & 1) << 6) | +- ((b[6] & 1) << 7)); +-} +- +-krb5_error_code +-k5_rand2key_des3(const krb5_data *randombits, krb5_keyblock *keyblock) +-{ +- int i; +- +- if (randombits->length != 21) +- return KRB5_CRYPTO_INTERNAL; +- +- keyblock->magic = KV5M_KEYBLOCK; +- +- /* Take the seven bytes, move them around into the top 7 bits of the +- * 8 key bytes, then compute the parity bits. Do this three times. */ +- for (i = 0; i < 3; i++) { +- memcpy(&keyblock->contents[i * 8], &randombits->data[i * 7], 7); +- eighth_byte(&keyblock->contents[i * 8]); +- k5_des_fixup_key_parity(&keyblock->contents[i * 8]); +- } +- return 0; +-} +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index 052f4d4b51..d8ffa63304 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -86,7 +86,6 @@ krb5_k_verify_checksum + krb5_k_verify_checksum_iov + krb5int_aes_encrypt + krb5int_aes_decrypt +-krb5int_enc_des3 + krb5int_arcfour_gsscrypt + krb5int_camellia_encrypt + krb5int_cmac_checksum +diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in +index cf11f6847b..8e4cdb8bbf 100644 +--- a/src/lib/crypto/openssl/Makefile.in ++++ b/src/lib/crypto/openssl/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)crypto$(S)openssl + BUILDTOP=$(REL)..$(S)..$(S).. +-SUBDIRS=des enc_provider hash_provider ++SUBDIRS=enc_provider hash_provider + LOCALINCLUDES=-I$(srcdir)/../krb $(CRYPTO_IMPL_CFLAGS) + + STLIBOBJS=\ +@@ -24,7 +24,7 @@ SRCS=\ + $(srcdir)/pbkdf2.c \ + $(srcdir)/sha256.c + +-SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ +diff --git a/src/lib/crypto/openssl/des/Makefile.in b/src/lib/crypto/openssl/des/Makefile.in +deleted file mode 100644 +index a6cece1dd1..0000000000 +--- a/src/lib/crypto/openssl/des/Makefile.in ++++ /dev/null +@@ -1,20 +0,0 @@ +-mydir=lib$(S)crypto$(S)openssl$(S)des +-BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES = -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) +- +-STLIBOBJS= des_keys.o +- +-OBJS= $(OUTPRE)des_keys.$(OBJEXT) +- +-SRCS= $(srcdir)/des_keys.c +- +-all-unix: all-libobjs +- +-includes: depend +- +-depend: $(SRCS) +- +-clean-unix:: clean-libobjs +- +-@libobj_frag@ +- +diff --git a/src/lib/crypto/openssl/des/deps b/src/lib/crypto/openssl/des/deps +deleted file mode 100644 +index 723c268082..0000000000 +--- a/src/lib/crypto/openssl/des/deps ++++ /dev/null +@@ -1,14 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_keys.c +diff --git a/src/lib/crypto/openssl/des/des_keys.c b/src/lib/crypto/openssl/des/des_keys.c +deleted file mode 100644 +index 83f1cbf22a..0000000000 +--- a/src/lib/crypto/openssl/des/des_keys.c ++++ /dev/null +@@ -1,39 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/openssl/des/des_keys.c - Key functions used by Kerberos code */ +-/* +- * Copyright (C) 2011 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +- +-#ifdef K5_OPENSSL_DES_KEY_PARITY +- +-#include +- +-void +-k5_des_fixup_key_parity(unsigned char *keybits) +-{ +- DES_set_odd_parity((DES_cblock *)keybits); +-} +- +-#endif +diff --git a/src/lib/crypto/openssl/enc_provider/Makefile.in b/src/lib/crypto/openssl/enc_provider/Makefile.in +index 26827cfed5..f0d37c1213 100644 +--- a/src/lib/crypto/openssl/enc_provider/Makefile.in ++++ b/src/lib/crypto/openssl/enc_provider/Makefile.in +@@ -3,19 +3,16 @@ BUILDTOP=$(REL)..$(S)..$(S)..$(S).. + LOCALINCLUDES = -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) + + STLIBOBJS= \ +- des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ + $(srcdir)/rc4.c +diff --git a/src/lib/crypto/openssl/enc_provider/deps b/src/lib/crypto/openssl/enc_provider/deps +index 1c87a526d0..a502990a0c 100644 +--- a/src/lib/crypto/openssl/enc_provider/deps ++++ b/src/lib/crypto/openssl/enc_provider/deps +@@ -1,17 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des3.c + aes.so aes.po $(OUTPRE)aes.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c +deleted file mode 100644 +index 90fcf9acb5..0000000000 +--- a/src/lib/crypto/openssl/enc_provider/des3.c ++++ /dev/null +@@ -1,188 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/openssl/enc_provider/des3.c */ +-/* +- * Copyright (C) 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +- +-#ifdef K5_OPENSSL_DES +- +-#include +- +-#define DES3_BLOCK_SIZE 8 +-#define DES3_KEY_SIZE 24 +-#define DES3_KEY_BYTES 21 +- +-static krb5_error_code +-validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data, +- size_t num_data, krb5_boolean *empty) +-{ +- size_t input_length = iov_total_length(data, num_data, FALSE); +- +- if (key->keyblock.length != DES3_KEY_SIZE) +- return(KRB5_BAD_KEYSIZE); +- if ((input_length%DES3_BLOCK_SIZE) != 0) +- return(KRB5_BAD_MSIZE); +- if (ivec && (ivec->length != 8)) +- return(KRB5_BAD_MSIZE); +- +- *empty = (input_length == 0); +- return 0; +-} +- +-static krb5_error_code +-k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES3_BLOCK_SIZE; +- unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_EncryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL, +- key->keyblock.contents, +- (ivec) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx,0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES3_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, oblock, DES3_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-static krb5_error_code +-k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES3_BLOCK_SIZE; +- unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_DecryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL, +- key->keyblock.contents, +- (ivec) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx,0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_DecryptUpdate(ctx, oblock, &olen, +- (unsigned char *)iblock, DES3_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, iblock, DES3_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des3 = { +- DES3_BLOCK_SIZE, +- DES3_KEY_BYTES, DES3_KEY_SIZE, +- k5_des3_encrypt, +- k5_des3_decrypt, +- NULL, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +- +-#endif /* K5_OPENSSL_DES */ +diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c +index 41e845eae0..5a43c3d9eb 100644 +--- a/src/lib/crypto/openssl/kdf.c ++++ b/src/lib/crypto/openssl/kdf.c +@@ -60,8 +60,6 @@ enc_name(const struct krb5_enc_provider *enc) + return "AES-128-CBC"; + if (enc == &krb5int_enc_aes256) + return "AES-256-CBC"; +- if (enc == &krb5int_enc_des3) +- return "DES-EDE3-CBC"; + return NULL; + } + +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index b35e11bfb6..d7c2ad321e 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -1026,7 +1026,6 @@ kg_accept_krb5(minor_status, context_handle, + } + + switch (negotiated_etype) { +- case ENCTYPE_DES3_CBC_SHA1: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP: + /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" +diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h +index 7364607198..5aeb69aebc 100644 +--- a/src/lib/gssapi/krb5/gssapiP_krb5.h ++++ b/src/lib/gssapi/krb5/gssapiP_krb5.h +@@ -125,14 +125,14 @@ enum sgn_alg { + /* SGN_ALG_DES_MAC = 0x0002, */ + /* SGN_ALG_3 = 0x0003, /\* not published *\/ */ + SGN_ALG_HMAC_MD5 = 0x0011, /* microsoft w2k; */ +- SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 ++ /* SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 */ + }; + enum seal_alg { + SEAL_ALG_NONE = 0xffff, + /* SEAL_ALG_DES = 0x0000, */ + /* SEAL_ALG_1 = 0x0001, /\* not published *\/ */ + SEAL_ALG_MICROSOFT_RC4 = 0x0010, /* microsoft w2k; */ +- SEAL_ALG_DES3KD = 0x0002 ++ /* SEAL_ALG_DES3KD = 0x0002 */ + }; + + /* for 3DES */ +@@ -153,7 +153,7 @@ enum qop { + GSS_KRB5_INTEG_C_QOP_HMAC_SHA1 = 0x0004, + GSS_KRB5_INTEG_C_QOP_MASK = 0x00ff, + /* GSS_KRB5_CONF_C_QOP_DES = 0x0100, */ +- GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, ++ /* GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, */ + GSS_KRB5_CONF_C_QOP_MASK = 0xff00 + }; + +diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c +index 99275be53a..0e5d10b115 100644 +--- a/src/lib/gssapi/krb5/k5seal.c ++++ b/src/lib/gssapi/krb5/k5seal.c +@@ -142,19 +142,12 @@ make_seal_token_v1 (krb5_context context, + + /* pad the plaintext, encrypt if needed, and stick it in the token */ + +- /* initialize the the checksum */ +- switch (signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- if (toktype != KG_TOK_SEAL_MSG) +- sign_usage = 15; +- break; +- default: +- abort (); +- } ++ if (signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ if (toktype != KG_TOK_SEAL_MSG) ++ sign_usage = 15; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code) { +@@ -203,20 +196,8 @@ make_seal_token_v1 (krb5_context context, + gssalloc_free(t); + return(code); + } +- switch(signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- /* +- * Using key derivation, the call to krb5_c_make_checksum +- * already dealt with encrypting. +- */ +- if (md5cksum.length != cksum_size) +- abort (); +- memcpy(checksum, md5cksum.contents, md5cksum.length); +- break; +- case SGN_ALG_HMAC_MD5: +- memcpy(checksum, md5cksum.contents, cksum_size); +- break; +- } ++ ++ memcpy(checksum, md5cksum.contents, cksum_size); + + krb5_free_checksum_contents(context, &md5cksum); + +diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c +index 7bf7609a48..d5e12cb436 100644 +--- a/src/lib/gssapi/krb5/k5sealiov.c ++++ b/src/lib/gssapi/krb5/k5sealiov.c +@@ -147,18 +147,11 @@ make_seal_token_v1_iov(krb5_context context, + /* pad the plaintext, encrypt if needed, and stick it in the token */ + + /* initialize the checksum */ +- switch (ctx->signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- if (toktype != KG_TOK_WRAP_MSG) +- sign_usage = 15; +- break; +- default: +- abort (); +- } ++ if (ctx->signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ if (toktype != KG_TOK_WRAP_MSG) ++ sign_usage = 15; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &k5_trailerlen); + if (code != 0) +@@ -182,15 +175,7 @@ make_seal_token_v1_iov(krb5_context context, + if (code != 0) + goto cleanup; + +- switch (ctx->signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- assert(md5cksum.length == ctx->cksum_size); +- memcpy(checksum, md5cksum.contents, md5cksum.length); +- break; +- case SGN_ALG_HMAC_MD5: +- memcpy(checksum, md5cksum.contents, ctx->cksum_size); +- break; +- } ++ memcpy(checksum, md5cksum.contents, ctx->cksum_size); + + /* create the seq_num */ + code = kg_make_seq_num(context, ctx->seq, ctx->initiate ? 0 : 0xFF, +diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c +index 9b183bc337..f0cc4a6809 100644 +--- a/src/lib/gssapi/krb5/k5unseal.c ++++ b/src/lib/gssapi/krb5/k5unseal.c +@@ -131,28 +131,21 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + but few enough that we can try them all. */ + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_DES3KD && +- signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && + signalg != SGN_ALG_HMAC_MD5)) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- cksum_len = 8; +- if (toktype != KG_TOK_SEAL_MSG) +- sign_usage = 15; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- cksum_len = 20; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + ++ cksum_len = 8; ++ if (toktype != KG_TOK_SEAL_MSG) ++ sign_usage = 15; ++ + if ((size_t)bodysize < 14 + cksum_len) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; +@@ -252,64 +245,53 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + /* compute the checksum of the message */ + + /* initialize the the cksum */ +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- default: +- abort (); +- } ++ if (signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code) + return(code); + md5cksum.length = sumlen; + +- switch (signalg) { +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return(GSS_S_DEFECTIVE_TOKEN); ++ } + +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- case SGN_ALG_HMAC_MD5: +- /* compute the checksum of the message */ +- +- /* 8 = bytes of token body to be checksummed according to spec */ ++ /* compute the checksum of the message */ + +- if (! (data_ptr = xmalloc(8 + plainlen))) { +- if (sealalg != 0xffff) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = ENOMEM; +- return(GSS_S_FAILURE); +- } ++ /* 8 = bytes of token body to be checksummed according to spec */ + +- (void) memcpy(data_ptr, ptr-2, 8); ++ if (! (data_ptr = xmalloc(8 + plainlen))) { ++ if (sealalg != 0xffff) ++ xfree(plain); ++ if (toktype == KG_TOK_SEAL_MSG) ++ gssalloc_free(token.value); ++ *minor_status = ENOMEM; ++ return(GSS_S_FAILURE); ++ } + +- (void) memcpy(data_ptr+8, plain, plainlen); ++ (void) memcpy(data_ptr, ptr-2, 8); + +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); ++ (void) memcpy(data_ptr+8, plain, plainlen); + +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } ++ plaind.length = 8 + plainlen; ++ plaind.data = data_ptr; ++ code = krb5_k_make_checksum(context, md5cksum.checksum_type, ++ ctx->seq, sign_usage, ++ &plaind, &md5cksum); ++ xfree(data_ptr); + +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; ++ if (code) { ++ if (toktype == KG_TOK_SEAL_MSG) ++ gssalloc_free(token.value); ++ *minor_status = code; ++ return(GSS_S_FAILURE); + } + ++ code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); ++ + krb5_free_checksum_contents(context, &md5cksum); + if (sealalg != 0xffff) + xfree(plain); +diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c +index 21b501731e..6a6585d9af 100644 +--- a/src/lib/gssapi/krb5/k5unsealiov.c ++++ b/src/lib/gssapi/krb5/k5unsealiov.c +@@ -103,28 +103,21 @@ kg_unseal_v1_iov(krb5_context context, + } + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_DES3KD && +- signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && + signalg != SGN_ALG_HMAC_MD5)) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- cksum_len = 8; +- if (toktype != KG_TOK_WRAP_MSG) +- sign_usage = 15; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- cksum_len = 20; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + ++ cksum_len = 8; ++ if (toktype != KG_TOK_WRAP_MSG) ++ sign_usage = 15; ++ + /* get the token parameters */ + code = kg_get_seq_num(context, ctx->seq, ptr + 14, ptr + 6, &direction, + &seqnum); +@@ -182,16 +175,10 @@ kg_unseal_v1_iov(krb5_context context, + + /* initialize the checksum */ + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) + abort(); +- } ++ ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code != 0) { +@@ -210,18 +197,13 @@ kg_unseal_v1_iov(krb5_context context, + goto cleanup; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- case SGN_ALG_HMAC_MD5: +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + code = 0; + retval = GSS_S_DEFECTIVE_TOKEN; + goto cleanup; +- break; + } + ++ code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); + if (code != 0) { + code = 0; + retval = GSS_S_BAD_SIG; +diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c +index 84f1949887..32150f5e34 100644 +--- a/src/lib/gssapi/krb5/util_crypt.c ++++ b/src/lib/gssapi/krb5/util_crypt.c +@@ -97,17 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, + return code; + + switch (subkey->keyblock.enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- code = kg_copy_keys(context, ctx, subkey); +- if (code != 0) +- return code; +- +- ctx->enc->keyblock.enctype = ENCTYPE_DES3_CBC_RAW; +- ctx->seq->keyblock.enctype = ENCTYPE_DES3_CBC_RAW; +- ctx->signalg = SGN_ALG_HMAC_SHA1_DES3_KD; +- ctx->cksum_size = 20; +- ctx->sealalg = SEAL_ALG_DES3KD; +- break; + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP: + /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 87b486c53f..2b5abcd817 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -59,7 +59,6 @@ + static krb5_enctype default_enctype_list[] = { + ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, + 0 +@@ -450,8 +449,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, + /* Set all enctypes in the default list. */ + for (i = 0; default_list[i]; i++) + mod_list(default_list[i], sel, weak, &list); +- } else if (strcasecmp(token, "des3") == 0) { +- mod_list(ENCTYPE_DES3_CBC_SHA1, sel, weak, &list); + } else if (strcasecmp(token, "aes") == 0) { + mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); + mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index 44d113e7c5..9662785783 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -288,8 +288,6 @@ verify_s4u2self_reply(krb5_context context, + assert(req_s4u_user != NULL); + + switch (subkey->enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP : + not_newer = TRUE; +diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c +index 90c9f626c6..935aca12f5 100644 +--- a/src/lib/krb5/krb/t_etypes.c ++++ b/src/lib/krb5/krb/t_etypes.c +@@ -50,17 +50,6 @@ static struct { + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, + 0, 0 + }, +- /* Family followed by enctype */ +- { "aes des3-cbc-sha1-kd", +- { 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- 0, 0 +- }, + /* Family with enctype removed */ + { "camellia -camellia256-cts-cmac", + { 0 }, +@@ -69,46 +58,15 @@ static struct { + }, + /* Default set with family added and enctype removed */ + { "DEFAULT +aes -arcfour-hmac-md5", +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, ++ { ENCTYPE_ARCFOUR_HMAC, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, + ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, + ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, +- ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, + 0 }, + 0, 0 + }, +- /* Default set with families removed and enctypes added (one redundant) */ +- { "DEFAULT -des3 rc4-hmac rc4-hmac-exp", +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, +- 0, 0 +- }, +- /* Default set with family moved to front */ +- { "des3 +DEFAULT", +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, +- ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, +- ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, +- 0, 0 +- }, +- /* Two families with default set removed (exotic case), enctype added */ +- { "aes +rc4 -DEFaulT des3-hmac-sha1", +- { ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_DES3_CBC_SHA1, +- ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, +- ENCTYPE_AES128_CTS_HMAC_SHA256_128, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, +- ENCTYPE_AES128_CTS_HMAC_SHA256_128, ENCTYPE_DES3_CBC_SHA1, 0 }, +- 0, 0 +- }, + /* Test krb5_set_default_in_tkt_ktypes */ + { NULL, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, +diff --git a/src/lib/krb5/os/t_trace.c b/src/lib/krb5/os/t_trace.c +index 10ba8d0ac7..24064ffcfd 100644 +--- a/src/lib/krb5/os/t_trace.c ++++ b/src/lib/krb5/os/t_trace.c +@@ -65,8 +65,8 @@ main (int argc, char *argv[]) + krb5_principal princ = &principal_data; + krb5_pa_data padata, padata2, **padatap; + krb5_enctype enctypes[4] = { +- ENCTYPE_DES3_CBC_SHA, ENCTYPE_ARCFOUR_HMAC_EXP, ENCTYPE_UNKNOWN, +- ENCTYPE_NULL}; ++ ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_ARCFOUR_HMAC_EXP, ++ ENCTYPE_UNKNOWN, ENCTYPE_NULL}; + krb5_ccache ccache; + krb5_keytab keytab; + krb5_creds creds; +diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref +index 044a66999e..98fb14f3f7 100644 +--- a/src/lib/krb5/os/t_trace.ref ++++ b/src/lib/krb5/os/t_trace.ref +@@ -41,7 +41,7 @@ int, krb5_principal type: ? + krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 + krb5_pa_data **, display list of padata type numbers: (empty) + krb5_enctype, display shortest name of enctype: aes128-cts +-krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 ++krb5_enctype *, display list of enctypes: aes128-cts, rc4-hmac-exp, 511 + krb5_enctype *, display list of enctypes: (empty) + krb5_ccache, display type:name: FILE:/path/to/ccache + krb5_keytab, display name: FILE:/etc/krb5.keytab +diff --git a/src/plugins/preauth/pkinit/pkcs11.h b/src/plugins/preauth/pkinit/pkcs11.h +index e3d2846315..586661bb7e 100644 +--- a/src/plugins/preauth/pkinit/pkcs11.h ++++ b/src/plugins/preauth/pkinit/pkcs11.h +@@ -339,9 +339,9 @@ typedef unsigned long ck_key_type_t; + #define CKK_GENERIC_SECRET (0x10) + #define CKK_RC2 (0x11) + #define CKK_RC4 (0x12) +-#define CKK_DES (0x13) +-#define CKK_DES2 (0x14) +-#define CKK_DES3 (0x15) ++/* #define CKK_DES (0x13) */ ++/* #define CKK_DES2 (0x14) */ ++/* #define CKK_DES3 (0x15) */ + #define CKK_CAST (0x16) + #define CKK_CAST3 (0x17) + #define CKK_CAST128 (0x18) +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index e22798f668..9fa315d7a0 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -370,11 +370,11 @@ krb5_error_code server_process_dh + * krb5_algorithm_identifier + */ + krb5_error_code create_krb5_supportedCMSTypes +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_algorithm_identifier ***supportedCMSTypes); /* OUT */ ++ (krb5_context context, /* IN */ ++ pkinit_plg_crypto_context plg_cryptoctx, /* IN */ ++ pkinit_req_crypto_context req_cryptoctx, /* IN */ ++ pkinit_identity_crypto_context id_cryptoctx, /* IN */ ++ krb5_algorithm_identifier ***supportedCMSTypes); /* OUT */ + + /* + * this functions takes in crypto specific representation of +diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +index 7f38e84910..99c93ac128 100644 +--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c ++++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +@@ -49,7 +49,6 @@ char eighteen_bs[9]; + char party_u_name[] = "lha@SU.SE"; + char party_v_name[] = "krbtgt/SU.SE@SU.SE"; + int enctype_aes = ENCTYPE_AES256_CTS_HMAC_SHA1_96; +-int enctype_des3 = ENCTYPE_DES3_CBC_SHA1; + const krb5_data lha_data = DATA_FROM_STRING("lha"); + + krb5_octet key1_hex[] = +@@ -187,35 +186,6 @@ main(int argc, char **argv) + goto cleanup; + } + +- /* TEST 3: SHA-512/DES3 */ +- /* set up algorithm id */ +- alg_id.algorithm = sha512_id; +- +- enctype = enctype_des3; +- +- /* call pkinit_alg_agility_kdf() with test vector values*/ +- if (0 != (retval = pkinit_alg_agility_kdf(context, &secret, +- &alg_id.algorithm, +- u_principal, v_principal, +- enctype, &as_req, &pk_as_rep, +- &key_block))) { +- printf("ERROR in pkinit_kdf_test: kdf call failed, retval = %d\n", +- retval); +- goto cleanup; +- } +- +- /* compare key to expected key value */ +- +- if ((key_block.length == sizeof(key3_hex)) && +- (0 == memcmp(key_block.contents, key3_hex, key_block.length))) { +- printf("SUCCESS: TEST 3 (SHA-512/DES3), Correct key value generated.\n"); +- retval = 0; +- } else { +- printf("FAILURE: TEST 2 (SHA-512/DES3), Incorrect key value generated!\n"); +- retval = 1; +- goto cleanup; +- } +- + cleanup: + /* release all allocated resources, whether good or bad return */ + free(secret.data); +diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c +index 2279202d3a..96b0307d78 100644 +--- a/src/plugins/preauth/spake/t_vectors.c ++++ b/src/plugins/preauth/spake/t_vectors.c +@@ -56,31 +56,6 @@ struct test { + const char *K2; + const char *K3; + } tests[] = { +- { ENCTYPE_DES3_CBC_SHA1, SPAKE_GROUP_EDWARDS25519, +- /* initial key, w, x, y, T, S, K */ +- "850BB51358548CD05E86768C313E3BFEF7511937DCF72C3E", +- "686D84730CB8679AE95416C6567C6A63F2C9CEF124F7A3371AE81E11CAD42A37", +- "201012D07BFD48DDFA33C4AAC4FB1E229FB0D043CFE65EBFB14399091C71A723", +- "500B294797B8B042ACA1BEDC0F5931A4F52C537B3608B2D05CC8A2372F439F25", +- "18F511E750C97B592ACD30DB7D9E5FCA660389102E6BF610C1BFBED4616C8362", +- "5D10705E0D1E43D5DBF30240CCFBDE4A0230C70D4C79147AB0B317EDAD2F8AE7", +- "25BDE0D875F0FEB5755F45BA5E857889D916ECF7476F116AA31DC3E037EC4292", +- /* support, challenge, thash, body */ +- "A0093007A0053003020101", +- "A1363034A003020101A122042018F511E750C97B592ACD30DB7D9E5FCA660389" +- "102E6BF610C1BFBED4616C8362A20930073005A003020101", +- "EAAA08807D0616026FF51C849EFBF35BA0CE3C5300E7D486DA46351B13D4605B", +- "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" +- "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" +- "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" +- "303130313030303030305AA703020100A8053003020110", +- /* K'[0], K'[1], K'[2], K'[3] */ +- "BAF12FAE7CD958CBF1A29BFBC71F89CE49E03E295D89DAFD", +- "64F73DD9C41908206BCEC1F719026B574F9D13463D7A2520", +- "0454520B086B152C455829E6BAEFF78A61DFE9E3D04A895D", +- "4A92260B25E3EF94C125D5C24C3E5BCED5B37976E67F25C4", +- }, +- + { ENCTYPE_ARCFOUR_HMAC, SPAKE_GROUP_EDWARDS25519, + /* initial key, w, x, y, T, S, K */ + "8846F7EAEE8FB117AD06BDD830B7586C", +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index 7494d7fcdb..2f95d89967 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -1,24 +1,17 @@ + from k5test import * + +-# Define some convenience abbreviations for enctypes we will see in +-# test program output. For background, aes256 and aes128 are "CFX +-# enctypes", meaning that they imply support for RFC 4121, while des3 +-# and rc4 are not. DES3 keys will appear as 'des3-cbc-raw' in +-# t_enctypes output because that's how GSSAPI does raw triple-DES +-# encryption without the RFC3961 framing. ++# Define some convenience abbreviations for enctypes we will see in test ++# program output. For background, aes256 and aes128 are "CFX enctypes", ++# meaning that they imply support for RFC 4121, while rc4 does not. + aes256 = 'aes256-cts-hmac-sha1-96' + aes128 = 'aes128-cts-hmac-sha1-96' +-des3 = 'des3-cbc-sha1' +-d_des3 = 'DEPRECATED:des3-cbc-sha1' +-des3raw = 'des3-cbc-raw' +-d_des3raw = 'DEPRECATED:des3-cbc-raw' + rc4 = 'arcfour-hmac' + d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, ++supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +@@ -87,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', + test_err('acc aes128', None, 'aes128-cts', + 'Encryption type aes256-cts-hmac-sha1-96 not permitted') + +-# If the initiator constrains the permitted session enctypes to des3, +-# no acceptor subkey will be generated because we can't upgrade to a +-# CFX enctype. +-test('init des3', 'des3', None, +- tktenc=aes256, tktsession=d_des3, +- proto='rfc1964', isubkey=des3raw, asubkey=None) +- + # Force the ticket session key to be rc4, so we can test some subkey + # upgrade cases. The ticket encryption key remains aes256. + realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4']) + + # With no arguments, the initiator should send an upgrade list of +-# [aes256 aes128 des3] and the acceptor should upgrade to an aes256 ++# [aes256 aes128] and the acceptor should upgrade to an aes256 + # subkey. + test('upgrade noargs', None, None, + tktenc=aes256, tktsession=d_rc4, +@@ -115,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, + tktenc=aes256, tktsession=d_rc4, + proto='cfx', isubkey=rc4, asubkey=aes128) + +-# If the initiator permits rc4 but prefers des3, it will send an +-# upgrade list of [des3], but the acceptor won't generate a subkey +-# because des3 isn't a CFX enctype. +-test('upgrade init des3+rc4', 'des3 rc4', None, +- tktenc=aes256, tktsession=d_rc4, +- proto='rfc1964', isubkey=rc4, asubkey=None) +- + # If the acceptor permits only aes128, subkey negotiation will fail + # because the ticket session key and initiator subkey are + # non-permitted. (This is unfortunate if the acceptor's restriction +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index 882e163634..8192935099 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -94,18 +94,6 @@ struct test { + size_t toklen; + const char *token; + } tests[] = { +- { +- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES3_CBC_RAW, +- SEAL_ALG_DES3KD, SGN_ALG_HMAC_SHA1_DES3_KD, 20, +- 24, +- "\x4F\xEA\x19\x19\x5E\x0E\x10\xDF\x3D\x29\xB5\x13\x8F\x01\xC7\xA7" +- "\x92\x3D\x38\xF7\x26\x73\x0D\x6D", +- 65, +- "\x60\x3F\x06\x09\x2A\x86\x48\x86\xF7\x12\x01\x02\x02\x02\x01\x04" +- "\x00\x02\x00\xFF\xFF\xEB\xF3\x9A\x89\x24\x57\xB8\x63\x95\x25\xE8" +- "\x6E\x8E\x79\xE6\x2E\xCA\xD3\xFF\x57\x9F\x8C\xAB\xEF\xDD\x28\x10" +- "\x2F\x93\x21\x2E\xF2\x52\xB6\x6F\xA8\xBB\x8A\x6D\xAA\x6F\xB7\xF4\xD4" +- }, + { + ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC, + SEAL_ALG_MICROSOFT_RC4, SGN_ALG_HMAC_MD5, 8, +diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c +index 7368f752f0..bf22bd3da1 100644 +--- a/src/tests/gssapi/t_pcontok.c ++++ b/src/tests/gssapi/t_pcontok.c +@@ -43,7 +43,6 @@ + #include "k5-int.h" + #include "common.h" + +-#define SGN_ALG_HMAC_SHA1_DES3_KD 0x04 + #define SGN_ALG_HMAC_MD5 0x11 + + /* +@@ -77,17 +76,12 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) + ret = krb5_k_create_key(context, &seqkb, &seq); + check_k5err(context, "krb5_k_create_key", ret); + +- if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { +- cktype = CKSUMTYPE_HMAC_SHA1_DES3; +- cksize = 20; +- ckusage = 23; +- } else if (signalg == SGN_ALG_HMAC_MD5) { +- cktype = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- cksize = 8; +- ckusage = 15; +- } else { ++ if (signalg != SGN_ALG_HMAC_MD5) + abort(); +- } ++ ++ cktype = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ cksize = 8; ++ ckusage = 15; + + tlen = 20 + mech_krb5.length + cksize; + token = malloc(tlen); +diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c +index f71774cdc9..d1857c433f 100644 +--- a/src/tests/gssapi/t_prf.c ++++ b/src/tests/gssapi/t_prf.c +@@ -41,13 +41,6 @@ static struct { + const char *key2; + const char *out2; + } tests[] = { +- { ENCTYPE_DES3_CBC_SHA1, +- "70378A19CD64134580C27C0115D6B34A1CF2FEECEF9886A2", +- "9F8D127C520BB826BFF3E0FE5EF352389C17E0C073D9" +- "AC4A333D644D21BA3EF24F4A886D143F85AC9F6377FB", +- "3452A167DF1094BA1089E0A20E9E51ABEF1525922558B69E", +- "6BF24FABC858F8DD9752E4FCD331BB831F238B5BE190" +- "4EEA42E38F7A60C588F075C5C96A67E7F8B7BD0AECF4" }, + { ENCTYPE_ARCFOUR_HMAC, + "3BB3AE288C12B3B9D06B208A4151B3B6", + "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" +diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py +index bde1c36844..8fcd30db51 100644 +--- a/src/tests/t_authdata.py ++++ b/src/tests/t_authdata.py +@@ -179,7 +179,7 @@ realm.run([kvno, 'restricted']) + # preferred krbtgt enctype changes. + mark('#8139 regression test') + realm.kinit(realm.user_princ, password('user'), ['-f']) +-realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'des3-cbc-sha1', ++realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-sha2', + realm.krbtgt_princ]) + realm.run(['./forward']) + realm.run([kvno, realm.host_princ]) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index c982508d8b..a6f538b66d 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,8 +1,7 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_weak_crypto': 'true'}, +- 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} ++supported_enctypes = 'aes128-cts rc4-hmac' ++conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + + realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth', +@@ -26,9 +25,9 @@ def test_etinfo(princ, enctypes, expected_lines): + # With no newer enctypes in the request, PA-ETYPE-INFO2, + # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one + # key for the most preferred matching enctype. +-test_etinfo('user', 'rc4-hmac-exp des3 rc4', +- ['asrep etype_info2 des3-cbc-sha1 KRBTEST.COMuser', +- 'asrep etype_info des3-cbc-sha1 KRBTEST.COMuser', ++test_etinfo('user', 'rc4-hmac-exp rc4', ++ ['asrep etype_info2 rc4-hmac KRBTEST.COMuser', ++ 'asrep etype_info rc4-hmac KRBTEST.COMuser', + 'asrep pw_salt KRBTEST.COMuser']) + + # With a newer enctype in the request (even if it is not the most +@@ -39,9 +38,9 @@ test_etinfo('user', 'rc4 aes256-cts', + + # In preauth-required errors, PA-PW-SALT does not appear, but the same + # etype-info2 values are expected. +-test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4', +- ['error etype_info2 des3-cbc-sha1 KRBTEST.COMpreauthuser', +- 'error etype_info des3-cbc-sha1 KRBTEST.COMpreauthuser']) ++test_etinfo('preauthuser', 'rc4-hmac-exp rc4', ++ ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser', ++ 'error etype_info rc4-hmac KRBTEST.COMpreauthuser']) + test_etinfo('preauthuser', 'rc4 aes256-cts', + ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) + +@@ -50,8 +49,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', + # (to allow for preauth mechs which don't depend on long-term keys). + # An AS-REP cannot be generated without preauth as there is no reply + # key. +-test_etinfo('rc4user', 'des3', []) +-test_etinfo('nokeyuser', 'des3', []) ++test_etinfo('rc4user', 'aes128-cts', []) ++test_etinfo('nokeyuser', 'aes128-cts', []) + + # Verify that etype-info2 is included in a MORE_PREAUTH_DATA_REQUIRED + # error if the client does optimistic preauth. +diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py +index e9840dfae8..583c2fa27e 100755 +--- a/src/tests/t_keyrollover.py ++++ b/src/tests/t_keyrollover.py +@@ -37,9 +37,9 @@ realm.run([klist, '-e'], expected_msg=msg) + + # Test that the KDC only accepts the first enctype for a kvno, for a + # local-realm TGS request. To set this up, we abuse an edge-case +-# behavior of modprinc -kvno. First, set up a DES3 krbtgt entry at ++# behavior of modprinc -kvno. First, set up an aes128-sha2 krbtgt entry at + # kvno 1 and cache a krbtgt ticket. +-realm.run([kadminl, 'cpw', '-randkey', '-e', 'des3-cbc-sha1', ++realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes128-cts-hmac-sha256-128', + realm.krbtgt_princ]) + realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) + realm.kinit(realm.user_princ, password('user')) +@@ -50,9 +50,9 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts', + realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) + out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ]) + if 'vno 1, aes256-cts' not in out or \ +- 'vno 1, DEPRECATED:des3-cbc-sha1' not in out: ++ 'vno 1, aes128-cts-hmac-sha256-128' not in out: + fail('keyrollover: setup for TGS enctype test failed') +-# Now present the DES3 ticket to the KDC and make sure it's rejected. ++# Now present the aes128-sha2 ticket to the KDC and make sure it's rejected. + realm.run([kvno, realm.host_princ], expected_code=1) + + realm.stop() +diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py +index 32f4070bcb..da0ed1831e 100755 +--- a/src/tests/t_mkey.py ++++ b/src/tests/t_mkey.py +@@ -7,7 +7,6 @@ import struct + # default enctype for master keys. + aes256 = 'aes256-cts-hmac-sha1-96' + aes128 = 'aes128-cts-hmac-sha1-96' +-des3 = 'des3-cbc-sha1' + defetype = aes256 + + realm = K5Realm(create_host=False, start_kadmind=True) +@@ -300,40 +299,6 @@ if 'Decrypt integrity check failed' in out or 'added to keytab' not in out: + + realm.stop() + +-# Load a dump file created with krb5 1.6, before the master key +-# rollover changes were introduced. Write out an old-format stash +-# file consistent with the dump's master password ("footes"). The K/M +-# entry in this database will not have actkvno tl-data because it was +-# created prior to master key rollover support. Verify that: +-# 1. We can access the database using the old-format stash file. +-# 2. list_mkeys displays the same list as for a post-1.7 KDB. +-mark('pre-1.7 stash file') +-dumpfile = os.path.join(srctop, 'tests', 'dumpfiles', 'dump.16') +-os.remove(stash_file) +-f = open(stash_file, 'wb') +-f.write(struct.pack('=HL24s', 16, 24, +- b'\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' +- b'\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) +-f.close() +-realm.run([kdb5_util, 'load', dumpfile]) +-nprincs = len(realm.run([kadminl, 'listprincs']).splitlines()) +-check_mkvno('K/M', 1) +-check_mkey_list((1, des3, True, True)) +- +-# Create a new master key and verify that, without actkvkno tl-data: +-# 1. list_mkeys displays the same as for a post-1.7 KDB. +-# 2. update_princ_encryption still targets mkvno 1. +-# 3. libkadm5 still uses mkvno 1 for key changes. +-# 4. use_mkey creates the same list as for a post-1.7 KDB. +-mark('rollover from pre-1.7 KDB') +-add_mkey([]) +-check_mkey_list((2, defetype, False, False), (1, des3, True, True)) +-update_princ_encryption(False, 1, 0, nprincs - 1) +-realm.run([kadminl, 'addprinc', '-randkey', realm.user_princ]) +-check_mkvno(realm.user_princ, 1) +-realm.run([kdb5_util, 'use_mkey', '2', 'now-1day']) +-check_mkey_list((2, defetype, True, True), (1, des3, True, False)) +- + # Regression test for #8395. Purge the master key and verify that a + # master key fetch does not segfault. + mark('#8395 regression test') +diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py +index 65084bbf35..55ca897459 100755 +--- a/src/tests/t_salt.py ++++ b/src/tests/t_salt.py +@@ -16,13 +16,12 @@ def test_salt(realm, e1, salt, e2): + + # Enctype/salt pairs chosen with non-default salt types. + # The enctypes are mostly arbitrary. +-salts = [('des3-cbc-sha1', 'norealm'), ++salts = [('aes128-cts-hmac-sha1-96', 'norealm'), + ('arcfour-hmac', 'onlyrealm'), + ('aes128-cts-hmac-sha1-96', 'special')] + # These enctypes are chosen to cover the different string-to-key routines. + # Omit ":normal" from aes256 to check that salttype defaulting works. +-second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal', +- 'des3-cbc-sha1:normal'] ++second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal'] + + # Test using different salt types in a principal's key list. + # Parameters from one key in the list must not leak over to later ones. +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 2a86c5cdfc..d823653aa0 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1338,13 +1338,6 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + +- # Exercise the DES3 enctype. +- ('des3', None, +- {'libdefaults': {'permitted_enctypes': 'des3'}}, +- {'realms': {'$realm': { +- 'supported_enctypes': 'des3-cbc-sha1:normal', +- 'master_key_type': 'des3-cbc-sha1'}}}), +- + # Exercise the arcfour enctype. + ('arcfour', None, + {'libdefaults': {'permitted_enctypes': 'rc4'}}, +diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +index 1aebdd0b4a..c38eefd2bd 100644 +--- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm ++++ b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +@@ -79,19 +79,6 @@ will have an entry in the Encryption type column.
+ Description + + +- des3- +- The triple DES family improves on +-the original DES (Data Encryption Standard) by using 3 separate 56-bit +-keys. Some modes of 3DES are considered weak while others are strong +-(if slow).
    +-
  • des3-cbc-sha1
  • +-
  • des3-cbc-raw (weak)
  • +-
  • des3-hmac-sha1
  • +-
  • des3-cbc-sha1-kd
  • +-
+- +- +- + aes + The AES Advanced Encryption Standard + family, like 3DES, is a symmetric block cipher and was designed +-- +2.45.1 + diff --git a/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch new file mode 100644 index 0000000..989b501 --- /dev/null +++ b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -0,0 +1,612 @@ +From 7b6453903c248a761d3ceb538dfacebbf3d3a9ff Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 9 Nov 2018 15:12:21 -0500 +Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 + +NB: Use openssl's PRNG in FIPS mode and taint within krad. + +A lot of the FIPS error conditions from OpenSSL are incredibly +mysterious (at best, things return NULL unexpectedly; at worst, +internal assertions are tripped; most of the time, you just get +ENOMEM). In order to cope with this, we need to have some level of +awareness of what we can and can't safely call. + +This will slow down some calls slightly (FIPS_mode() takes multiple +locks), but not for any ciphers we care about - which is to say that +AES is fine. Shame about SPAKE though. + +post6 restores MD4 (and therefore keygen-only RC4). + +post7 restores MD5 and adds radius_md5_fips_override. + +post8 silences a static analyzer warning. + +Last-updated: krb5-1.20 +--- + doc/admin/conf_files/krb5_conf.rst | 6 +++ + src/lib/crypto/krb/prng.c | 15 +++++- + .../crypto/openssl/enc_provider/camellia.c | 6 +++ + src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- + .../crypto/openssl/hash_provider/hash_evp.c | 12 +++++ + src/lib/crypto/openssl/hmac.c | 6 ++- + src/lib/krad/attr.c | 46 ++++++++++++++----- + src/lib/krad/attrset.c | 5 +- + src/lib/krad/internal.h | 28 ++++++++++- + src/lib/krad/packet.c | 22 +++++---- + src/lib/krad/remote.c | 10 +++- + src/lib/krad/t_attr.c | 3 +- + src/lib/krad/t_attrset.c | 4 +- + src/plugins/preauth/spake/spake_client.c | 6 +++ + src/plugins/preauth/spake/spake_kdc.c | 6 +++ + 15 files changed, 155 insertions(+), 33 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index f22d5db11b..a33711d918 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: + qualification of shortnames, set this relation to the empty string + with ``qualify_shortname = ""``. (New in release 1.18.) + ++**radius_md5_fips_override** ++ Downstream-only option to enable use of MD5 in RADIUS ++ communication (libkrad). This allows for local (or protected ++ tunnel) communication with a RADIUS server that doesn't use krad ++ (e.g., freeradius) while in FIPS mode. ++ + **rdns** + If this flag is true, reverse name lookup will be used in addition + to forward name lookup to canonicalizing hostnames for use in +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index d6b79e2dea..9e80a03d21 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -26,6 +26,12 @@ + + #include "crypto_int.h" + ++#include ++ ++#if OPENSSL_VERSION_NUMBER < 0x30000000L ++#include ++#endif ++ + krb5_error_code KRB5_CALLCONV + krb5_c_random_seed(krb5_context context, krb5_data *data) + { +@@ -96,9 +102,16 @@ cleanup: + static krb5_boolean + get_os_entropy(unsigned char *buf, size_t len) + { +-#if defined(__linux__) && defined(SYS_getrandom) + int r; + ++ /* A wild FIPS mode appeared! */ ++ if (FIPS_mode()) { ++ /* The return codes on this API are not good */ ++ r = RAND_bytes(buf, len); ++ return r == 1; ++ } ++ ++#if defined(__linux__) && defined(SYS_getrandom) + while (len > 0) { + /* + * Pull from the /dev/urandom pool, but require it to have been seeded. +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index 01920e6ce1..d9f327add6 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -387,6 +387,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, + unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE]; + struct iov_cursor cursor; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + if (output->length < CAMELLIA_BLOCK_SIZE) + return KRB5_BAD_MSIZE; + +@@ -418,6 +421,9 @@ static krb5_error_code + krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage, + krb5_data *state) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + state->length = 16; + state->data = (void *) malloc(16); + if (state->data == NULL) +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index 448d563348..ce63cb5f1b 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -69,6 +69,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx = NULL; + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + arcstate = (state != NULL) ? (void *)state->data : NULL; + if (arcstate != NULL) { + ctx = arcstate->ctx; +@@ -116,7 +119,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + static void + k5_arcfour_free_state(krb5_data *state) + { +- struct arcfour_state *arcstate = (void *)state->data; ++ struct arcfour_state *arcstate; ++ ++ if (FIPS_mode()) ++ return; ++ ++ arcstate = (void *) state->data; + + EVP_CIPHER_CTX_free(arcstate->ctx); + free(arcstate); +@@ -128,6 +136,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, + { + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + /* + * The cipher state here is a saved pointer to a struct arcfour_state + * object, rather than a flat byte array as in most enc providers. The +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index f2fbffdb29..11659908bb 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -60,6 +60,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + if (ctx == NULL) + return ENOMEM; + ++ if (type == EVP_md4() || type == EVP_md5()) { ++ /* See comments below in hash_md4() and hash_md5(). */ ++ EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); ++ } ++ + ok = EVP_DigestInit_ex(ctx, type, NULL); + for (i = 0; i < num_data; i++) { + if (!SIGN_IOV(&data[i])) +@@ -78,6 +83,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + static krb5_error_code + hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ /* ++ * MD4 is needed in FIPS mode to perform key generation for RC4 keys used ++ * by IPA. These keys are only used along a (separately) secured channel ++ * for legacy reasons when performing trusts to Active Directory. ++ */ + return hash_evp(EVP_md4(), data, num_data, output); + } + +@@ -90,6 +100,8 @@ const struct krb5_hash_provider krb5int_hash_md4 = { + static krb5_error_code + hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ /* MD5 is needed in FIPS mode for communication with RADIUS servers. This ++ * is gated in libkrad by libdefaults->radius_md5_fips_override. */ + return hash_evp(EVP_md5(), data, num_data, output); + } + +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index bf12b8d6a0..f21e268f7f 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -111,7 +111,11 @@ map_digest(const struct krb5_hash_provider *hash) + return EVP_sha256(); + else if (hash == &krb5int_hash_sha384) + return EVP_sha384(); +- else if (hash == &krb5int_hash_md5) ++ ++ if (FIPS_mode()) ++ return NULL; ++ ++ if (hash == &krb5int_hash_md5) + return EVP_md5(); + else if (hash == &krb5int_hash_md4) + return EVP_md4(); +diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c +index 9c13d9d755..42d354a3b5 100644 +--- a/src/lib/krad/attr.c ++++ b/src/lib/krad/attr.c +@@ -38,7 +38,8 @@ + typedef krb5_error_code + (*attribute_transform_fn)(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + typedef struct { + const char *name; +@@ -51,12 +52,14 @@ typedef struct { + static krb5_error_code + user_password_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + static krb5_error_code + user_password_decode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *ignored); + + static const attribute_record attributes[UCHAR_MAX] = { + {"User-Name", 1, MAX_ATTRSIZE, NULL, NULL}, +@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = { + static krb5_error_code + user_password_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + const unsigned char *indx; + krb5_error_code retval; +@@ -154,8 +158,15 @@ user_password_encode(krb5_context ctx, const char *secret, + for (blck = 0, indx = auth; blck * BLOCKSIZE < len; blck++) { + memcpy(tmp.data + seclen, indx, BLOCKSIZE); + +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, +- &sum); ++ if (kr_use_fips(ctx)) { ++ /* Skip encryption here. Taint so that we won't pass it out of ++ * the machine by accident. */ ++ *is_fips = TRUE; ++ sum.contents = calloc(1, BLOCKSIZE); ++ } else { ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, ++ &sum); ++ } + if (retval != 0) { + zap(tmp.data, tmp.length); + zap(outbuf, len); +@@ -180,7 +191,8 @@ user_password_encode(krb5_context ctx, const char *secret, + static krb5_error_code + user_password_decode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + const unsigned char *indx; + krb5_error_code retval; +@@ -204,8 +216,15 @@ user_password_decode(krb5_context ctx, const char *secret, + for (blck = 0, indx = auth; blck * BLOCKSIZE < in->length; blck++) { + memcpy(tmp.data + seclen, indx, BLOCKSIZE); + +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, +- &tmp, &sum); ++ if (kr_use_fips(ctx)) { ++ /* Skip encryption here. Taint so that we won't pass it out of ++ * the machine by accident. */ ++ *is_fips = TRUE; ++ sum.contents = calloc(1, BLOCKSIZE); ++ } else { ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, ++ &tmp, &sum); ++ } + if (retval != 0) { + zap(tmp.data, tmp.length); + zap(outbuf, in->length); +@@ -248,7 +267,7 @@ krb5_error_code + kr_attr_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, krad_attr type, + const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE], +- size_t *outlen) ++ size_t *outlen, krb5_boolean *is_fips) + { + krb5_error_code retval; + +@@ -265,7 +284,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, + return 0; + } + +- return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen); ++ return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen, ++ is_fips); + } + + krb5_error_code +@@ -274,6 +294,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) + { + krb5_error_code retval; ++ krb5_boolean ignored; + + retval = kr_attr_valid(type, in); + if (retval != 0) +@@ -288,7 +309,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + return 0; + } + +- return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen); ++ return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen, ++ &ignored); + } + + krad_attr +diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c +index f309f1581c..6ec031e320 100644 +--- a/src/lib/krad/attrset.c ++++ b/src/lib/krad/attrset.c +@@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy) + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, + const unsigned char *auth, +- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + unsigned char buffer[MAX_ATTRSIZE]; + krb5_error_code retval; +@@ -181,7 +182,7 @@ kr_attrset_encode(const krad_attrset *set, const char *secret, + + K5_TAILQ_FOREACH(a, &set->list, list) { + retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr, +- buffer, &attrlen); ++ buffer, &attrlen, is_fips); + if (retval != 0) + return retval; + +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index 7619563fc5..e123763954 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -39,6 +39,8 @@ + #include + #include + ++#include ++ + #ifndef UCHAR_MAX + #define UCHAR_MAX 255 + #endif +@@ -49,6 +51,13 @@ + + typedef struct krad_remote_st krad_remote; + ++struct krad_packet_st { ++ char buffer[KRAD_PACKET_SIZE_MAX]; ++ krad_attrset *attrset; ++ krb5_data pkt; ++ krb5_boolean is_fips; ++}; ++ + /* Validate constraints of an attribute. */ + krb5_error_code + kr_attr_valid(krad_attr type, const krb5_data *data); +@@ -57,7 +66,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data); + krb5_error_code + kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth, + krad_attr type, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + /* Decode an attribute. */ + krb5_error_code +@@ -69,7 +79,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, + const unsigned char *auth, +- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + /* Decode attributes from a buffer. */ + krb5_error_code +@@ -156,4 +167,17 @@ gai_error_code(int err) + } + } + ++static inline krb5_boolean ++kr_use_fips(krb5_context ctx) ++{ ++ int val = 0; ++ ++ if (!FIPS_mode()) ++ return 0; ++ ++ (void)profile_get_boolean(ctx->profile, "libdefaults", ++ "radius_md5_fips_override", NULL, 0, &val); ++ return !val; ++} ++ + #endif /* INTERNAL_H_ */ +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index c597174b65..fc2d248001 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -53,12 +53,6 @@ typedef unsigned char uchar; + #define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH)) + #define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR)) + +-struct krad_packet_st { +- char buffer[KRAD_PACKET_SIZE_MAX]; +- krad_attrset *attrset; +- krb5_data pkt; +-}; +- + typedef struct { + uchar x[(UCHAR_MAX + 1) / 8]; + } idmap; +@@ -187,8 +181,14 @@ auth_generate_response(krb5_context ctx, const char *secret, + memcpy(data.data + response->pkt.length, secret, strlen(secret)); + + /* Hash it. */ +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, +- &hash); ++ if (kr_use_fips(ctx)) { ++ /* This checksum does very little security-wise anyway, so don't ++ * taint. */ ++ hash.contents = calloc(1, AUTH_FIELD_SIZE); ++ } else { ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, ++ &hash); ++ } + free(data.data); + if (retval != 0) + return retval; +@@ -276,7 +276,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + + /* Encode the attributes. */ + retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt), +- &attrset_len); ++ &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -314,7 +314,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + + /* Encode the attributes. */ + retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt), +- &attrset_len); ++ &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -451,6 +451,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + const krb5_data * + krad_packet_encode(const krad_packet *pkt) + { ++ if (pkt->is_fips) ++ return NULL; + return &pkt->pkt; + } + +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index 06ae751bc8..929f1cef67 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -263,7 +263,7 @@ on_io_write(krad_remote *rr) + request *r; + + K5_TAILQ_FOREACH(r, &rr->list, list) { +- tmp = krad_packet_encode(r->request); ++ tmp = &r->request->pkt; + + /* If the packet has already been sent, do nothing. */ + if (r->sent == tmp->length) +@@ -359,7 +359,7 @@ on_io_read(krad_remote *rr) + if (req != NULL) { + K5_TAILQ_FOREACH(r, &rr->list, list) { + if (r->request == req && +- r->sent == krad_packet_encode(req)->length) { ++ r->sent == req->pkt.length) { + request_finish(r, 0, rsp); + break; + } +@@ -460,6 +460,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, + (krad_packet_iter_cb)iterator, &r, &tmp); + if (retval != 0) + goto error; ++ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL && ++ rr->info->ai_family != AF_UNIX) { ++ /* This would expose cleartext passwords, so abort. */ ++ retval = ESOCKTNOSUPPORT; ++ goto error; ++ } + + K5_TAILQ_FOREACH(r, &rr->list, list) { + if (r->request == tmp) { +diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c +index eb2a780c89..4d285ad9de 100644 +--- a/src/lib/krad/t_attr.c ++++ b/src/lib/krad/t_attr.c +@@ -50,6 +50,7 @@ main() + const char *tmp; + krb5_data in; + size_t len; ++ krb5_boolean is_fips = FALSE; + + noerror(krb5_init_context(&ctx)); + +@@ -73,7 +74,7 @@ main() + in = string2data((char *)decoded); + retval = kr_attr_encode(ctx, secret, auth, + krad_attr_name2num("User-Password"), +- &in, outbuf, &len); ++ &in, outbuf, &len, &is_fips); + insist(retval == 0); + insist(len == sizeof(encoded)); + insist(memcmp(outbuf, encoded, len) == 0); +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 7928335ca4..0f95762534 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -49,6 +49,7 @@ main() + krb5_context ctx; + size_t len = 0, encode_len; + krb5_data tmp; ++ krb5_boolean is_fips = FALSE; + + noerror(krb5_init_context(&ctx)); + noerror(krad_attrset_new(ctx, &set)); +@@ -62,7 +63,8 @@ main() + noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp)); + + /* Encode attrset. */ +- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len)); ++ noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len, ++ &is_fips)); + krad_attrset_free(set); + + /* Manually encode User-Name. */ +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index 00734a13b5..a3ce22b70f 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -38,6 +38,8 @@ + #include "groups.h" + #include + ++#include ++ + typedef struct reqstate_st { + krb5_pa_spake *msg; /* set in prep_questions, used in process */ + krb5_keyblock *initial_key; +@@ -375,6 +377,10 @@ clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, + + if (maj_ver != 1) + return KRB5_PLUGIN_VER_NOTSUPP; ++ ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + vt = (krb5_clpreauth_vtable)vtable; + vt->name = "spake"; + vt->pa_type_list = pa_types; +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +index 1a772d450f..232e78bc05 100644 +--- a/src/plugins/preauth/spake/spake_kdc.c ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -41,6 +41,8 @@ + + #include + ++#include ++ + /* + * The SPAKE kdcpreauth module uses a secure cookie containing the following + * concatenated fields (all integer fields are big-endian): +@@ -551,6 +553,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, + + if (maj_ver != 1) + return KRB5_PLUGIN_VER_NOTSUPP; ++ ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + vt = (krb5_kdcpreauth_vtable)vtable; + vt->name = "spake"; + vt->pa_type_list = pa_types; +-- +2.45.1 + diff --git a/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch new file mode 100644 index 0000000..b339700 --- /dev/null +++ b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch @@ -0,0 +1,82 @@ +From 707fa7bd2be6327343dc8fc5c20dc77645524518 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 5 May 2022 17:15:12 +0200 +Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection + with FIPS + +libkrad allows to establish connections only to UNIX socket in FIPS +mode, because MD5 digest is not considered safe enough to be used for +network communication. However, FreeRadius requires connection on TCP or +UDP ports. + +This commit allows TCP or UDP connections in FIPS mode if destination is +localhost. + +Resolves: rhbz#2082189 +--- + src/lib/krad/remote.c | 35 +++++++++++++++++++++++++++++++++-- + 1 file changed, 33 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index 929f1cef67..063f17a613 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -33,6 +33,7 @@ + + #include + #include ++#include + + #include + +@@ -74,6 +75,35 @@ on_io(verto_ctx *ctx, verto_ev *ev); + static void + on_timeout(verto_ctx *ctx, verto_ev *ev); + ++static in_addr_t get_in_addr(struct addrinfo *info) ++{ return ((struct sockaddr_in *)(info->ai_addr))->sin_addr.s_addr; } ++ ++static struct in6_addr *get_in6_addr(struct addrinfo *info) ++{ return &(((struct sockaddr_in6 *)(info->ai_addr))->sin6_addr); } ++ ++static bool is_inet_localhost(struct addrinfo *info) ++{ ++ struct addrinfo *p; ++ ++ for (p = info; p; p = p->ai_next) { ++ switch (p->ai_family) { ++ case AF_INET: ++ if (IN_LOOPBACKNET != (get_in_addr(p) & IN_CLASSA_NET ++ >> IN_CLASSA_NSHIFT)) ++ return false; ++ break; ++ case AF_INET6: ++ if (!IN6_IS_ADDR_LOOPBACK(get_in6_addr(p))) ++ return false; ++ break; ++ default: ++ return false; ++ } ++ } ++ ++ return true; ++} ++ + /* Iterate over the set of outstanding packets. */ + static const krad_packet * + iterator(request **out) +@@ -460,8 +490,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, + (krad_packet_iter_cb)iterator, &r, &tmp); + if (retval != 0) + goto error; +- else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL && +- rr->info->ai_family != AF_UNIX) { ++ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL ++ && rr->info->ai_family != AF_UNIX ++ && !is_inet_localhost(rr->info)) { + /* This would expose cleartext passwords, so abort. */ + retval = ESOCKTNOSUPPORT; + goto error; +-- +2.45.1 + diff --git a/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch new file mode 100644 index 0000000..ceb9595 --- /dev/null +++ b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch @@ -0,0 +1,41 @@ +From 1da88bea558348be2974470774aa688f8be634c0 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 7 Dec 2022 13:22:42 +0100 +Subject: [PATCH] [downstream] Make tests compatible with + sssd_krb5_locator_plugin.so + +The sssd_krb5_locator_plugin.so plugin provided by sssd-client conflicts +with the upstream test t_discover_uri.py. The test has to be modified in +order to avoid false positive. +--- + src/lib/krb5/os/t_discover_uri.py | 9 ++++++++- + 1 file changed, 8 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py +index 87bac17929..26bc95a8dc 100644 +--- a/src/lib/krb5/os/t_discover_uri.py ++++ b/src/lib/krb5/os/t_discover_uri.py +@@ -1,3 +1,4 @@ ++from os.path import exists + from k5test import * + + entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n', +@@ -37,8 +38,14 @@ realm.env['RESOLV_WRAPPER_HOSTS'] = hosts_filename + out = realm.run(['./t_locate_kdc', 'TEST'], env=realm.env) + l = out.splitlines() + ++if (exists('/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so') ++ or exists('/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')): ++ line_range = range(6, 14) ++else: ++ line_range = range(4, 12) ++ + j = 0 +-for i in range(4, 12): ++for i in line_range: + if l[i].strip() != expected[j]: + fail('URI answers do not match') + j += 1 +-- +2.45.1 + diff --git a/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch new file mode 100644 index 0000000..ef6f825 --- /dev/null +++ b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch @@ -0,0 +1,120 @@ +From 775ed8588cc21385fb16a4cec4a861f0d578ce04 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 5 Jan 2023 20:06:47 +0100 +Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header + +The inclusion of openssl/fips.h, which provides the declaration of +FIPS_mode(), was removed from openssl/crypto.h. As a consequence, this +header file has to be included explicitly in krb5 code. +--- + src/lib/crypto/krb/prng.c | 4 +++- + src/lib/crypto/openssl/enc_provider/camellia.c | 1 + + src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++++ + src/lib/crypto/openssl/hmac.c | 1 + + src/lib/krad/internal.h | 4 ++++ + src/plugins/preauth/spake/spake_client.c | 4 ++++ + src/plugins/preauth/spake/spake_kdc.c | 4 ++++ + 7 files changed, 21 insertions(+), 1 deletion(-) + +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index 9e80a03d21..ae37c77518 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -28,7 +28,9 @@ + + #include + +-#if OPENSSL_VERSION_NUMBER < 0x30000000L ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#else + #include + #endif + +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index d9f327add6..3dd3b0624f 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -32,6 +32,7 @@ + #include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include ++#include + #else + #include + #endif +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index ce63cb5f1b..6a83f10d27 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -38,6 +38,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + /* + * The loopback field is a pointer to the structure. If the application copies + * the state (not a valid operation, but one which happens to works with some +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index f21e268f7f..25a419d73a 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -59,6 +59,7 @@ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include ++#include + #else + #include + #endif +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index e123763954..a17b6f39b1 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -41,6 +41,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + #ifndef UCHAR_MAX + #define UCHAR_MAX 255 + #endif +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index a3ce22b70f..13c699071f 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -40,6 +40,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + typedef struct reqstate_st { + krb5_pa_spake *msg; /* set in prep_questions, used in process */ + krb5_keyblock *initial_key; +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +index 232e78bc05..3394f8a58e 100644 +--- a/src/plugins/preauth/spake/spake_kdc.c ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -43,6 +43,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + /* + * The SPAKE kdcpreauth module uses a secure cookie containing the following + * concatenated fields (all integer fields are big-endian): +-- +2.45.1 + diff --git a/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch new file mode 100644 index 0000000..bd4ab77 --- /dev/null +++ b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch @@ -0,0 +1,31 @@ +From 4fd20741afcf76085ea62eb015cd589bb9392a7b Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Mon, 9 Jan 2023 22:39:52 +0100 +Subject: [PATCH] [downstream] Do not set root as ksu file owner + +Upstream Makefile uses the install command to set root as owner of the +ksu executable file. However, this is no longer supported on latest +versions of the Mock build environment. + +In case of ksu, the owner, group, and mode are already set using %attr() +in the specfile. +--- + src/config/pre.in | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/config/pre.in b/src/config/pre.in +index 7eaa2f351c..e9ae71471e 100644 +--- a/src/config/pre.in ++++ b/src/config/pre.in +@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) + INSTALL_SCRIPT=@INSTALL_PROGRAM@ + INSTALL_DATA=@INSTALL_DATA@ + INSTALL_SHLIB=@INSTALL_SHLIB@ +-INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root ++INSTALL_SETUID=$(INSTALL) + ## This is needed because autoconf will sometimes define @exec_prefix@ to be + ## ${prefix}. + prefix=@prefix@ +-- +2.45.1 + diff --git a/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch new file mode 100644 index 0000000..5e45141 --- /dev/null +++ b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch @@ -0,0 +1,165 @@ +From 16f90c007036789d8d9343e8a0cbabfd21853b5a Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 19 Jan 2023 19:22:27 +0100 +Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode + +OpenSSL's restrictions to use KRB5KDF, MD5, and MD4 in FIPS mode are +bypassed in case AES SHA-1 HMAC or RC4 encryption types are allowed by +the crypto policy. +--- + .../crypto/openssl/hash_provider/hash_evp.c | 97 +++++++++++++++++-- + src/lib/crypto/openssl/kdf.c | 2 +- + 2 files changed, 89 insertions(+), 10 deletions(-) + +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 11659908bb..eb2e693e9f 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -44,6 +44,49 @@ + #define EVP_MD_CTX_free EVP_MD_CTX_destroy + #endif + ++#include ++#include ++#include ++ ++typedef struct ossl_lib_md_context { ++ OSSL_LIB_CTX *libctx; ++ OSSL_PROVIDER *default_provider; ++ OSSL_PROVIDER *legacy_provider; ++} ossl_md_context_t; ++ ++static thread_local ossl_md_context_t *ossl_md_ctx = NULL; ++ ++static krb5_error_code ++init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo) ++{ ++ ctx->libctx = OSSL_LIB_CTX_new(); ++ if (!ctx->libctx) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Load both legacy and default provider as both may be needed. */ ++ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); ++ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); ++ ++ if (!(ctx->default_provider && ctx->legacy_provider)) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ return 0; ++} ++ ++static void ++deinit_ossl_ctx(ossl_md_context_t *ctx) ++{ ++ if (ctx->legacy_provider) ++ OSSL_PROVIDER_unload(ctx->legacy_provider); ++ ++ if (ctx->default_provider) ++ OSSL_PROVIDER_unload(ctx->default_provider); ++ ++ if (ctx->libctx) ++ OSSL_LIB_CTX_free(ctx->libctx); ++} ++ ++ + static krb5_error_code + hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + krb5_data *output) +@@ -60,11 +103,6 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + if (ctx == NULL) + return ENOMEM; + +- if (type == EVP_md4() || type == EVP_md5()) { +- /* See comments below in hash_md4() and hash_md5(). */ +- EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); +- } +- + ok = EVP_DigestInit_ex(ctx, type, NULL); + for (i = 0; i < num_data; i++) { + if (!SIGN_IOV(&data[i])) +@@ -77,6 +115,43 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } + ++static krb5_error_code ++hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output) ++{ ++ krb5_error_code err; ++ EVP_MD *md = NULL; ++ ++ if (!ossl_md_ctx) { ++ ossl_md_ctx = malloc(sizeof(ossl_md_context_t)); ++ if (!ossl_md_ctx) { ++ err = ENOMEM; ++ goto end; ++ } ++ ++ err = init_ossl_md_ctx(ossl_md_ctx, algo); ++ if (err) { ++ deinit_ossl_ctx(ossl_md_ctx); ++ free(ossl_md_ctx); ++ ossl_md_ctx = NULL; ++ goto end; ++ } ++ } ++ ++ md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL); ++ if (!md) { ++ err = KRB5_CRYPTO_INTERNAL; ++ goto end; ++ } ++ ++ err = hash_evp(md, data, num_data, output); ++ ++end: ++ if (md) ++ EVP_MD_free(md); ++ ++ return err; ++} + #endif + + #ifdef K5_OPENSSL_MD4 +@@ -88,7 +163,8 @@ hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + * by IPA. These keys are only used along a (separately) secured channel + * for legacy reasons when performing trusts to Active Directory. + */ +- return hash_evp(EVP_md4(), data, num_data, output); ++ return FIPS_mode() ? hash_legacy_evp("MD4", data, num_data, output) ++ : hash_evp(EVP_md4(), data, num_data, output); + } + + const struct krb5_hash_provider krb5int_hash_md4 = { +@@ -100,9 +176,12 @@ const struct krb5_hash_provider krb5int_hash_md4 = { + static krb5_error_code + hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { +- /* MD5 is needed in FIPS mode for communication with RADIUS servers. This +- * is gated in libkrad by libdefaults->radius_md5_fips_override. */ +- return hash_evp(EVP_md5(), data, num_data, output); ++ /* ++ * MD5 is needed in FIPS mode for communication with RADIUS servers. This ++ * is gated in libkrad by libdefaults->radius_md5_fips_override. ++ */ ++ return FIPS_mode() ? hash_legacy_evp("MD5", data, num_data, output) ++ : hash_evp(EVP_md5(), data, num_data, output); + } + + const struct krb5_hash_provider krb5int_hash_md5 = { +diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c +index 5a43c3d9eb..8528ddc4a9 100644 +--- a/src/lib/crypto/openssl/kdf.c ++++ b/src/lib/crypto/openssl/kdf.c +@@ -198,7 +198,7 @@ k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, krb5_key key, + goto done; + } + +- kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); ++ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", "-fips"); + if (kdf == NULL) { + ret = KRB5_CRYPTO_INTERNAL; + goto done; +-- +2.45.1 + diff --git a/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch new file mode 100644 index 0000000..57b4a76 --- /dev/null +++ b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch @@ -0,0 +1,280 @@ +From 23b58199db429603802e338db530677b61561335 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 15 Mar 2023 15:56:34 +0100 +Subject: [PATCH] [downstream] Allow to set PAC ticket signature as + optional + +MS-PAC states that "The ticket signature SHOULD be included in tickets +that are not encrypted to the krbtgt account". However, the +implementation of krb5_kdc_verify_ticket() will require the ticket +signature to be present in case the target of the request is a service +principal. + +In gradual upgrade environments, it results in S4U2Proxy requests +against a 1.20 KDC using a service ticket generated by an older version +KDC to fail. + +This commit adds a krb5_kdc_verify_ticket_ext() function with an extra +switch parameter to tolerate the absence of ticket signature in this +scenario. If the ticket signature is present, it has to be valid, +regardless of this parameter. + +This parameter is set based on the "optional_pac_tkt_chksum" string +attribute of the TGT KDB entry. +--- + doc/admin/admin_commands/kadmin_local.rst | 6 ++++ + doc/appdev/refs/api/index.rst | 1 + + src/include/kdb.h | 1 + + src/include/krb5/krb5.hin | 40 +++++++++++++++++++++++ + src/kdc/kdc_util.c | 32 ++++++++++++++---- + src/lib/krb5/krb/pac.c | 31 +++++++++++++++--- + src/lib/krb5/libkrb5.exports | 1 + + src/man/kadmin.man | 6 ++++ + 8 files changed, 108 insertions(+), 10 deletions(-) + +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index 2435b3c361..58ac79549f 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -658,6 +658,12 @@ KDC: + Directory realm when using aes-sha2 keys on the local krbtgt + entry. + ++**optional_pac_tkt_chksum** ++ Boolean value defining the behavior of the KDC in case an expected ++ ticket checksum signed with one of this principal keys is not ++ present in the PAC. This is typically the case for TGS or ++ cross-realm TGS principals when processing S4U2Proxy requests. ++ + This command requires the **modify** privilege. + + Alias: **setstr** +diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst +index d12be47c3c..9b95ebd0f9 100644 +--- a/doc/appdev/refs/api/index.rst ++++ b/doc/appdev/refs/api/index.rst +@@ -225,6 +225,7 @@ Rarely used public interfaces + krb5_is_referral_realm.rst + krb5_kdc_sign_ticket.rst + krb5_kdc_verify_ticket.rst ++ krb5_kdc_verify_ticket_ext.rst + krb5_kt_add_entry.rst + krb5_kt_end_seq_get.rst + krb5_kt_get_entry.rst +diff --git a/src/include/kdb.h b/src/include/kdb.h +index 745b24f351..6075349e5e 100644 +--- a/src/include/kdb.h ++++ b/src/include/kdb.h +@@ -136,6 +136,7 @@ + #define KRB5_KDB_SK_PAC_PRIVSVR_ENCTYPE "pac_privsvr_enctype" + #define KRB5_KDB_SK_SESSION_ENCTYPES "session_enctypes" + #define KRB5_KDB_SK_REQUIRE_AUTH "require_auth" ++#define KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM "optional_pac_tkt_chksum" + + #if !defined(_WIN32) + +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index c5a625db8f..2d9b64dc85 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -8329,6 +8329,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + const krb5_keyblock *server, + const krb5_keyblock *privsvr, krb5_pac *pac_out); + ++/** ++ * Verify a PAC, possibly including ticket signature ++ * ++ * @param [in] context Library context ++ * @param [in] enc_tkt Ticket enc-part, possibly containing a PAC ++ * @param [in] server_princ Canonicalized name of ticket server ++ * @param [in] server Key to validate server checksum (or NULL) ++ * @param [in] privsvr Key to validate KDC checksum (or NULL) ++ * @paran [in] optional_tkt_chksum Whether to require a ticket checksum ++ * @param [out] pac_out Verified PAC (NULL if no PAC included) ++ * ++ * This function is an extension of krb5_kdc_verify_ticket(), adding the @a ++ * optional_tkt_chksum parameter allowing to tolerate the absence of the PAC ++ * ticket signature. ++ * ++ * If a PAC is present in @a enc_tkt, verify its signatures. If @a privsvr is ++ * not NULL and @a server_princ is not a krbtgt or kadmin/changepw service and ++ * @a optional_tkt_chksum is FALSE, require a ticket signature over @a enc_tkt ++ * in addition to the KDC signature. Place the verified PAC in @a pac_out. If ++ * an invalid PAC signature is found, return an error matching the Windows KDC ++ * protocol code for that condition as closely as possible. ++ * ++ * If no PAC is present in @a enc_tkt, set @a pac_out to NULL and return ++ * successfully. ++ * ++ * @note This function does not validate the PAC_CLIENT_INFO buffer. If a ++ * specific value is expected, the caller can make a separate call to ++ * krb5_pac_verify_ext() with a principal but no keys. ++ * ++ * @retval 0 Success; otherwise - Kerberos error codes ++ */ ++krb5_error_code KRB5_CALLCONV ++krb5_kdc_verify_ticket_ext(krb5_context context, ++ const krb5_enc_tkt_part *enc_tkt, ++ krb5_const_principal server_princ, ++ const krb5_keyblock *server, ++ const krb5_keyblock *privsvr, ++ krb5_boolean optional_tkt_chksum, ++ krb5_pac *pac_out); ++ + /** @deprecated Use krb5_kdc_sign_ticket() instead. */ + krb5_error_code KRB5_CALLCONV + krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index fe4e48209a..93415ba862 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -560,16 +560,36 @@ cleanup: + static krb5_error_code + try_verify_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_db_entry *server, krb5_keyblock *server_key, +- const krb5_keyblock *tgt_key, krb5_pac *pac_out) ++ krb5_db_entry *tgt, const krb5_keyblock *tgt_key, ++ krb5_pac *pac_out) + { + krb5_error_code ret; ++ krb5_boolean optional_tkt_chksum; ++ char *str = NULL; + krb5_keyblock *privsvr_key; + + ret = pac_privsvr_key(context, server, tgt_key, &privsvr_key); + if (ret) + return ret; +- ret = krb5_kdc_verify_ticket(context, enc_tkt, server->princ, server_key, +- privsvr_key, pac_out); ++ ++ /* Check if the absence of ticket signature is tolerated for this realm */ ++ ret = krb5_dbe_get_string(context, tgt, ++ KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM, &str); ++ /* TODO: should be using _krb5_conf_boolean(), but os-proto.h is not ++ * available here. ++ */ ++ optional_tkt_chksum = !ret && str && (strncasecmp(str, "true", 4) == 0 ++ || strncasecmp(str, "t", 1) == 0 ++ || strncasecmp(str, "yes", 3) == 0 ++ || strncasecmp(str, "y", 1) == 0 ++ || strncasecmp(str, "1", 1) == 0 ++ || strncasecmp(str, "on", 2) == 0); ++ ++ krb5_dbe_free_string(context, str); ++ ++ ret = krb5_kdc_verify_ticket_ext(context, enc_tkt, server->princ, ++ server_key, privsvr_key, ++ optional_tkt_chksum, pac_out); + krb5_free_keyblock(context, privsvr_key); + return ret; + } +@@ -599,7 +619,7 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + server_key, NULL, pac_out); + } + +- ret = try_verify_pac(context, enc_tkt, server, server_key, tgt_key, ++ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, tgt_key, + pac_out); + if (ret != KRB5KRB_AP_ERR_MODIFIED && ret != KRB5_BAD_ENCTYPE) + return ret; +@@ -613,8 +633,8 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &old_key, NULL); + if (ret) + return ret; +- ret = try_verify_pac(context, enc_tkt, server, server_key, &old_key, +- pac_out); ++ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, ++ &old_key, pac_out); + krb5_free_keyblock_contents(context, &old_key); + if (!ret) + return 0; +diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c +index 5d1fdf1ba0..0c0e2ada68 100644 +--- a/src/lib/krb5/krb/pac.c ++++ b/src/lib/krb5/krb/pac.c +@@ -594,6 +594,19 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_const_principal server_princ, + const krb5_keyblock *server, + const krb5_keyblock *privsvr, krb5_pac *pac_out) ++{ ++ return krb5_kdc_verify_ticket_ext(context, enc_tkt, server_princ, server, ++ privsvr, FALSE, pac_out); ++} ++ ++krb5_error_code KRB5_CALLCONV ++krb5_kdc_verify_ticket_ext(krb5_context context, ++ const krb5_enc_tkt_part *enc_tkt, ++ krb5_const_principal server_princ, ++ const krb5_keyblock *server, ++ const krb5_keyblock *privsvr, ++ krb5_boolean optional_tkt_chksum, ++ krb5_pac *pac_out) + { + krb5_error_code ret; + krb5_pac pac = NULL; +@@ -602,7 +615,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_authdata *orig, **ifrel = NULL, **recoded_ifrel = NULL; + uint8_t z = 0; + krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z }; +- krb5_boolean is_service_tkt; ++ krb5_boolean is_service_tkt, has_tkt_chksum = FALSE; + size_t i, j; + + *pac_out = NULL; +@@ -667,11 +680,21 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + + ret = verify_checksum(context, pac, KRB5_PAC_TICKET_CHECKSUM, privsvr, + KRB5_KEYUSAGE_APP_DATA_CKSUM, recoded_tkt); +- if (ret) +- goto cleanup; ++ if (ret) { ++ if (!optional_tkt_chksum) ++ goto cleanup; ++ else if (ret != ENOENT) ++ goto cleanup; ++ /* Otherwise ticket signature is absent but optional. Proceed... */ ++ } else { ++ has_tkt_chksum = TRUE; ++ } + } ++ /* Else, we make the assumption the ticket signature is absent in case this ++ * is not a service ticket. ++ */ + +- ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr); ++ ret = verify_pac_checksums(context, pac, has_tkt_chksum, server, privsvr); + if (ret) + goto cleanup; + +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index 4c50e935a2..d4b0455c8c 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -463,6 +463,7 @@ krb5_is_thread_safe + krb5_kdc_rep_decrypt_proc + krb5_kdc_sign_ticket + krb5_kdc_verify_ticket ++krb5_kdc_verify_ticket_ext + krb5_kt_add_entry + krb5_kt_client_default + krb5_kt_close +diff --git a/src/man/kadmin.man b/src/man/kadmin.man +index 8413e70ccd..f68eb0569d 100644 +--- a/src/man/kadmin.man ++++ b/src/man/kadmin.man +@@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to + "aes256\-sha1" on the cross\-realm krbtgt entry for an Active + Directory realm when using aes\-sha2 keys on the local krbtgt + entry. ++.TP ++\fBoptional_pac_tkt_chksum\fP ++Boolean value defining the behavior of the KDC in case an expected ticket ++checksum signed with one of this principal keys is not present in the PAC. This ++is typically the case for TGS or cross-realm TGS principals when processing ++S4U2Proxy requests. + .UNINDENT + .sp + This command requires the \fBmodify\fP privilege. +-- +2.45.1 + diff --git a/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch new file mode 100644 index 0000000..68a2a6d --- /dev/null +++ b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch @@ -0,0 +1,47 @@ +From 31b9debcf2cbd558f8f315fefb69fc8206b115b4 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Tue, 23 May 2023 12:19:54 +0200 +Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature + verification available in FIPS mode + +We recommend using the SHA1 crypto-module in order to allow the +verification of SHA-1 signature for CMS messages. However, this module +does not work in FIPS mode, because the SHA-1 algorithm is absent from +the OpenSSL FIPS provider. + +This commit enables the signature verification process to fetch the +algorithm from a non-FIPS OpenSSL provider. + +Support for SHA-1 CMS signature is still required, especially in order +to interoperate with Active Directory. At least it is until elliptic +curve cryptography is implemented for PKINIT in MIT krb5. +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index cb9c79626c..17dd18e37d 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -1844,8 +1844,17 @@ cms_signeddata_verify(krb5_context context, + if (oid == NULL) + goto cleanup; + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ /* Do not use FIPS provider (even in FIPS mode) because it keeps from ++ * allowing SHA-1 signature verification using the SHA1 crypto-module ++ */ ++ cms = CMS_ContentInfo_new_ex(NULL, "-fips"); ++ if (!cms) ++ goto cleanup; ++#endif ++ + /* decode received CMS message */ +- if ((cms = d2i_CMS_ContentInfo(NULL, &p, (int)signed_data_len)) == NULL) { ++ if (!d2i_CMS_ContentInfo(&cms, &p, (int)signed_data_len)) { + retval = oerr(context, 0, _("Failed to decode CMS message")); + goto cleanup; + } +-- +2.45.1 + diff --git a/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch new file mode 100644 index 0000000..30646aa --- /dev/null +++ b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch @@ -0,0 +1,218 @@ +From c24c9faf859ddc04910a6bc591d8ddb2ada93e80 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 30 May 2023 01:21:48 -0400 +Subject: [PATCH] Enable PKINIT if at least one group is available + +OpenSSL may no longer allow decoding of non-well-known Diffie-Hellman +group parameters as EVP_PKEY objects in FIPS mode. However, OpenSSL +does not know about MODP group 2 (1024-bit), which is considered as a +custom group. As a consequence, the PKINIT kdcpreauth module fails to +load in FIPS mode. + +Allow initialization of PKINIT plugin if at least one of the MODP +well-known group parameters successfully decodes. + +[ghudson@mit.edu: minor commit message and code edits] + +ticket: 9096 (new) +(cherry picked from commit 509d8db922e9ad6f108883838473b6178f89874a) +--- + src/plugins/preauth/pkinit/pkinit_clnt.c | 2 +- + src/plugins/preauth/pkinit/pkinit_crypto.h | 3 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 76 +++++++++++-------- + src/plugins/preauth/pkinit/pkinit_srv.c | 2 +- + src/plugins/preauth/pkinit/pkinit_trace.h | 3 + + 5 files changed, 51 insertions(+), 35 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 725d5bc438..ea9ba454df 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -1378,7 +1378,7 @@ pkinit_client_plugin_init(krb5_context context, + if (retval) + goto errout; + +- retval = pkinit_init_plg_crypto(&ctx->cryptoctx); ++ retval = pkinit_init_plg_crypto(context, &ctx->cryptoctx); + if (retval) + goto errout; + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 9fa315d7a0..8bdbea8e95 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -103,7 +103,8 @@ typedef struct _pkinit_cert_matching_data { + /* + * Functions to initialize and cleanup crypto contexts + */ +-krb5_error_code pkinit_init_plg_crypto(pkinit_plg_crypto_context *); ++krb5_error_code pkinit_init_plg_crypto(krb5_context, ++ pkinit_plg_crypto_context *); + void pkinit_fini_plg_crypto(pkinit_plg_crypto_context); + + krb5_error_code pkinit_init_req_crypto(pkinit_req_crypto_context *); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 17dd18e37d..8cdc40bfb4 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -47,7 +47,8 @@ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +-static krb5_error_code pkinit_init_dh_params(pkinit_plg_crypto_context ); ++static krb5_error_code pkinit_init_dh_params(krb5_context, ++ pkinit_plg_crypto_context); + static void pkinit_fini_dh_params(pkinit_plg_crypto_context ); + + static krb5_error_code pkinit_init_certs(pkinit_identity_crypto_context ctx); +@@ -951,7 +952,8 @@ oerr_cert(krb5_context context, krb5_error_code code, X509_STORE_CTX *certctx, + } + + krb5_error_code +-pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx) ++pkinit_init_plg_crypto(krb5_context context, ++ pkinit_plg_crypto_context *cryptoctx) + { + krb5_error_code retval = ENOMEM; + pkinit_plg_crypto_context ctx = NULL; +@@ -969,7 +971,7 @@ pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx) + if (retval) + goto out; + +- retval = pkinit_init_dh_params(ctx); ++ retval = pkinit_init_dh_params(context, ctx); + if (retval) + goto out; + +@@ -1278,30 +1280,36 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx) + ASN1_OBJECT_free(ctx->id_kp_serverAuth); + } + +-static krb5_error_code +-pkinit_init_dh_params(pkinit_plg_crypto_context plgctx) ++static int ++try_import_group(krb5_context context, const krb5_data *params, ++ const char *name, EVP_PKEY **pkey_out) + { +- krb5_error_code retval = ENOMEM; +- +- plgctx->dh_1024 = decode_dh_params(&oakley_1024); +- if (plgctx->dh_1024 == NULL) +- goto cleanup; +- +- plgctx->dh_2048 = decode_dh_params(&oakley_2048); +- if (plgctx->dh_2048 == NULL) +- goto cleanup; ++ *pkey_out = decode_dh_params(params); ++ if (*pkey_out == NULL) ++ TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name); ++ return (*pkey_out != NULL) ? 1 : 0; ++} + +- plgctx->dh_4096 = decode_dh_params(&oakley_4096); +- if (plgctx->dh_4096 == NULL) +- goto cleanup; ++static krb5_error_code ++pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx) ++{ ++ int n = 0; + +- retval = 0; ++ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", ++ &plgctx->dh_1024); ++ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", ++ &plgctx->dh_2048); ++ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", ++ &plgctx->dh_4096); + +-cleanup: +- if (retval) ++ if (n == 0) { + pkinit_fini_dh_params(plgctx); ++ k5_setmsg(context, ENOMEM, ++ _("PKINIT cannot initialize any key exchange groups")); ++ return ENOMEM; ++ } + +- return retval; ++ return 0; + } + + static void +@@ -2912,11 +2920,11 @@ client_create_dh(krb5_context context, + + if (cryptoctx->received_params != NULL) + params = cryptoctx->received_params; +- else if (dh_size == 1024) ++ else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024) + params = plg_cryptoctx->dh_1024; +- else if (dh_size == 2048) ++ else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048) + params = plg_cryptoctx->dh_2048; +- else if (dh_size == 4096) ++ else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096) + params = plg_cryptoctx->dh_4096; + else + goto cleanup; +@@ -3212,19 +3220,23 @@ pkinit_create_td_dh_parameters(krb5_context context, + krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 }; + krb5_algorithm_identifier *alglist[4]; + +- if (opts->dh_min_bits > 4096) { +- ret = KRB5KRB_ERR_GENERIC; +- goto cleanup; +- } +- + i = 0; +- if (opts->dh_min_bits <= 2048) ++ if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048) + alglist[i++] = &alg_2048; +- alglist[i++] = &alg_4096; +- if (opts->dh_min_bits <= 1024) ++ if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096) ++ alglist[i++] = &alg_4096; ++ if (plg_cryptoctx->dh_1024 != NULL && opts->dh_min_bits <= 1024) + alglist[i++] = &alg_1024; + alglist[i] = NULL; + ++ if (i == 0) { ++ ret = KRB5KRB_ERR_GENERIC; ++ k5_setmsg(context, ret, ++ _("OpenSSL has no supported key exchange groups for " ++ "pkinit_dh_min_bits=%d"), opts->dh_min_bits); ++ goto cleanup; ++ } ++ + ret = k5int_encode_krb5_td_dh_parameters(alglist, &der_alglist); + if (ret) + goto cleanup; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 1b3bf6d4d0..768a4e559f 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -1222,7 +1222,7 @@ pkinit_server_plugin_init_realm(krb5_context context, const char *realmname, + goto errout; + plgctx->realmname_len = strlen(plgctx->realmname); + +- retval = pkinit_init_plg_crypto(&plgctx->cryptoctx); ++ retval = pkinit_init_plg_crypto(context, &plgctx->cryptoctx); + if (retval) + goto errout; + +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 259e95c6c2..5ee39c085c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -90,6 +90,9 @@ + #define TRACE_PKINIT_CLIENT_TRYAGAIN(c) \ + TRACE(c, "PKINIT client trying again with KDC-provided parameters") + ++#define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \ ++ TRACE(c, "PKINIT key exchange group {str} unsupported", name) ++ + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) + +-- +2.45.1 + diff --git a/0015-Replace-ssl.wrap_socket-for-tests.patch b/0015-Replace-ssl.wrap_socket-for-tests.patch new file mode 100644 index 0000000..34cef96 --- /dev/null +++ b/0015-Replace-ssl.wrap_socket-for-tests.patch @@ -0,0 +1,64 @@ +From e92365b510a2407eaceaec90836f5c713403d75f Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 19 Jul 2023 13:43:17 +0200 +Subject: [PATCH] Replace ssl.wrap_socket() for tests + +The ssl.wrap_socket() function was deprecated in Python 3.7 and is +removed in Python 3.12. The ssl.SSLContext.wrap_socket() method +replaces it. + +Bump the required Python version for tests to 3.4 for +ssl.create_default_context(). + +[ghudson@mit.edu: changed minimum Python version] + +(cherry picked from commit 0ceab6c363e65fb21d3312a663f2b9b569ecc415) +--- + src/configure.ac | 9 ++++----- + src/util/wsgiref-kdcproxy.py | 4 +++- + 2 files changed, 7 insertions(+), 6 deletions(-) + +diff --git a/src/configure.ac b/src/configure.ac +index 2561e917a2..487f393146 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1157,10 +1157,9 @@ AC_SUBST(PKINIT) + # for lib/apputils + AC_REPLACE_FUNCS(daemon) + +-# For Python tests. Python version 3.2.4 is required as prior +-# versions do not accept string input to subprocess.Popen.communicate +-# when universal_newlines is set. +-PYTHON_MINVERSION=3.2.4 ++# For Python tests. Python version 3.4 is required for ++# ssl.create_default_context(). ++PYTHON_MINVERSION=3.4 + AC_SUBST(PYTHON_MINVERSION) + AC_CHECK_PROG(PYTHON,python3,python3) + if test x"$PYTHON" = x; then +@@ -1168,7 +1167,7 @@ if test x"$PYTHON" = x; then + fi + HAVE_PYTHON=no + if test x"$PYTHON" != x; then +- wantver="(sys.hexversion >= 0x30204F0)" ++ wantver="(sys.hexversion >= 0x30400F0)" + if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then + HAVE_PYTHON=yes + fi +diff --git a/src/util/wsgiref-kdcproxy.py b/src/util/wsgiref-kdcproxy.py +index 58759696b6..d1d10d733c 100755 +--- a/src/util/wsgiref-kdcproxy.py ++++ b/src/util/wsgiref-kdcproxy.py +@@ -14,6 +14,8 @@ else: + pem = '*' + + server = make_server('localhost', port, kdcproxy.Application()) +-server.socket = ssl.wrap_socket(server.socket, certfile=pem, server_side=True) ++sslctx = ssl.create_default_context(purpose=ssl.Purpose.CLIENT_AUTH) ++sslctx.load_cert_chain(certfile=pem) ++server.socket = sslctx.wrap_socket(server.socket, server_side=True) + os.write(sys.stdout.fileno(), b'proxy server ready\n') + server.serve_forever() +-- +2.45.1 + diff --git a/0016-Eliminate-old-style-function-declarations.patch b/0016-Eliminate-old-style-function-declarations.patch new file mode 100644 index 0000000..2b07a72 --- /dev/null +++ b/0016-Eliminate-old-style-function-declarations.patch @@ -0,0 +1,10685 @@ +From 1ad0abf12b212d19ac7b3903deeaf7fff4e2c3cf Mon Sep 17 00:00:00 2001 +From: Ken Hornstein +Date: Fri, 9 Jun 2023 23:53:53 -0400 +Subject: [PATCH] Eliminate old-style function declarations + +The C2x standard removes support for non-prototype function +declarations, and clang 15 issues warnings for them +(https://reviews.llvm.org/D122895). Add -Werror=strict-prototypes to +the build and fix all of the non-prototype declarations and +definitions. + +For RPC code, try to be consistent with libtirpc and recent *BSD +versions of rpcgen. This includes casting each time a concrete +function is used as an xdrproc_t value, since each XDR per-type +function accepts a different object pointer type. A few invocations +of xdrproc_t values pass a third argument with value LASTUNSIGNED, +even though XDR per-type functions accept only two parameters. +libtirpc has removed these third arguments; do so here as well. + +[ghudson@mit.edu: added -Werror=strict-prototypes and fixed +declarations it breaks under gcc and clang; added xdrproc_t changes; +rewrote commit message; style changes] + +(cherry picked from commit 4b9d7f7c107f01a61600fddcd8cde3812d0366a2) +--- + src/aclocal.m4 | 2 +- + src/appl/gss-sample/gss-client.c | 29 +--- + src/appl/gss-sample/gss-misc.c | 26 +-- + src/appl/gss-sample/gss-server.c | 2 +- + src/appl/user_user/server.c | 5 +- + src/clients/kdestroy/kdestroy.c | 2 +- + src/clients/kinit/kinit.c | 4 +- + src/clients/klist/klist.c | 2 +- + src/clients/ksu/authorization.c | 95 ++++------ + src/clients/ksu/ccache.c | 108 ++++-------- + src/clients/ksu/heuristic.c | 94 ++++------ + src/clients/ksu/krb_auth_su.c | 49 ++---- + src/clients/ksu/main.c | 40 ++--- + src/clients/kvno/kvno.c | 2 +- + src/include/gssrpc/auth_gssapi.h | 10 +- + src/include/gssrpc/xdr.h | 3 +- + src/include/k5-int.h | 2 +- + src/include/k5-plugin.h | 2 +- + src/include/net-server.h | 6 +- + src/kadmin/cli/getdate.y | 3 - + src/kadmin/cli/kadmin.c | 6 +- + src/kadmin/cli/keytab.c | 4 +- + src/kadmin/dbutil/kdb5_create.c | 16 +- + src/kadmin/dbutil/kdb5_destroy.c | 4 +- + src/kadmin/dbutil/kdb5_stash.c | 4 +- + src/kadmin/dbutil/kdb5_util.c | 24 +-- + src/kadmin/dbutil/ovload.c | 14 +- + src/kadmin/dbutil/strtok.c | 4 +- + src/kadmin/ktutil/ktutil.c | 45 ++--- + src/kadmin/ktutil/ktutil_funcs.c | 37 ++-- + src/kadmin/server/ipropd_svc.c | 24 +-- + src/kadmin/server/kadm_rpc_svc.c | 162 +++++++++--------- + src/kadmin/server/ovsec_kadmd.c | 4 +- + src/kdc/t_ndr.c | 2 +- + src/kdc/t_replay.c | 6 +- + src/kprop/kpropd.c | 2 +- + src/kprop/kproplog.c | 4 +- + src/lib/apputils/net-server.c | 7 +- + src/lib/crypto/builtin/aes/aes-gen.c | 18 +- + .../crypto/builtin/camellia/camellia-gen.c | 18 +- + src/lib/crypto/builtin/sha1/t_shs.c | 7 +- + src/lib/crypto/builtin/sha1/t_shs3.c | 7 +- + src/lib/crypto/crypto_tests/aes-test.c | 8 +- + src/lib/crypto/crypto_tests/camellia-test.c | 8 +- + src/lib/crypto/crypto_tests/t_cf2.c | 4 +- + src/lib/crypto/crypto_tests/t_cts.c | 2 +- + src/lib/crypto/crypto_tests/t_encrypt.c | 2 +- + src/lib/crypto/crypto_tests/t_fork.c | 2 +- + src/lib/crypto/crypto_tests/t_hmac.c | 3 +- + src/lib/crypto/crypto_tests/t_mddriver.c | 25 ++- + src/lib/crypto/crypto_tests/t_nfold.c | 16 +- + src/lib/crypto/crypto_tests/t_prf.c | 2 +- + src/lib/crypto/crypto_tests/t_sha2.c | 2 +- + src/lib/gssapi/generic/t_seqstate.c | 2 +- + src/lib/gssapi/krb5/accept_sec_context.c | 76 +++----- + src/lib/gssapi/krb5/compare_name.c | 7 +- + src/lib/gssapi/krb5/context_time.c | 6 +- + src/lib/gssapi/krb5/delete_sec_context.c | 7 +- + src/lib/gssapi/krb5/disp_name.c | 9 +- + src/lib/gssapi/krb5/disp_status.c | 11 +- + src/lib/gssapi/krb5/export_sec_context.c | 7 +- + src/lib/gssapi/krb5/gssapi_krb5.c | 4 +- + src/lib/gssapi/krb5/import_name.c | 8 +- + src/lib/gssapi/krb5/import_sec_context.c | 10 +- + src/lib/gssapi/krb5/indicate_mechs.c | 4 +- + src/lib/gssapi/krb5/init_sec_context.c | 55 ++---- + src/lib/gssapi/krb5/inq_context.c | 17 +- + src/lib/gssapi/krb5/inq_cred.c | 26 +-- + src/lib/gssapi/krb5/inq_names.c | 6 +- + src/lib/gssapi/krb5/k5seal.c | 38 ++-- + src/lib/gssapi/krb5/k5unseal.c | 51 ++---- + src/lib/gssapi/krb5/process_context_token.c | 8 +- + src/lib/gssapi/krb5/rel_cred.c | 4 +- + src/lib/gssapi/krb5/rel_name.c | 4 +- + src/lib/gssapi/krb5/rel_oid.c | 8 +- + src/lib/gssapi/krb5/ser_sctx.c | 16 +- + src/lib/gssapi/krb5/util_cksum.c | 6 +- + src/lib/gssapi/krb5/util_seed.c | 5 +- + src/lib/gssapi/krb5/util_seqnum.c | 19 +- + src/lib/gssapi/krb5/val_cred.c | 4 +- + src/lib/gssapi/krb5/wrap_size_limit.c | 11 +- + .../gssapi/mechglue/g_accept_sec_context.c | 31 +--- + src/lib/gssapi/mechglue/g_acquire_cred.c | 95 +++------- + .../gssapi/mechglue/g_acquire_cred_with_pw.c | 56 ++---- + src/lib/gssapi/mechglue/g_canon_name.c | 10 +- + src/lib/gssapi/mechglue/g_compare_name.c | 12 +- + src/lib/gssapi/mechglue/g_context_time.c | 10 +- + .../gssapi/mechglue/g_delete_sec_context.c | 10 +- + src/lib/gssapi/mechglue/g_dsp_name.c | 12 +- + src/lib/gssapi/mechglue/g_dsp_status.c | 22 +-- + src/lib/gssapi/mechglue/g_dup_name.c | 8 +- + src/lib/gssapi/mechglue/g_exp_sec_context.c | 10 +- + src/lib/gssapi/mechglue/g_export_name.c | 8 +- + src/lib/gssapi/mechglue/g_glue.c | 75 +++----- + src/lib/gssapi/mechglue/g_imp_name.c | 18 +- + src/lib/gssapi/mechglue/g_imp_sec_context.c | 11 +- + src/lib/gssapi/mechglue/g_init_sec_context.c | 37 +--- + src/lib/gssapi/mechglue/g_initialize.c | 22 +-- + src/lib/gssapi/mechglue/g_inq_cred.c | 31 +--- + src/lib/gssapi/mechglue/g_inq_names.c | 8 +- + src/lib/gssapi/mechglue/g_mechname.c | 14 +- + src/lib/gssapi/mechglue/g_oid_ops.c | 27 +-- + src/lib/gssapi/mechglue/g_process_context.c | 10 +- + src/lib/gssapi/mechglue/g_rel_buffer.c | 6 +- + src/lib/gssapi/mechglue/g_rel_cred.c | 7 +- + src/lib/gssapi/mechglue/g_rel_name.c | 7 +- + src/lib/gssapi/mechglue/g_rel_oid_set.c | 6 +- + src/lib/gssapi/mechglue/g_sign.c | 29 +--- + src/lib/gssapi/mechglue/g_store_cred.c | 48 ++---- + src/lib/gssapi/mechglue/g_unseal.c | 35 +--- + src/lib/gssapi/mechglue/g_unwrap_aead.c | 19 +- + src/lib/gssapi/mechglue/g_unwrap_iov.c | 15 +- + src/lib/gssapi/mechglue/g_verify.c | 30 +--- + src/lib/gssapi/mechglue/g_wrap_aead.c | 39 ++--- + src/lib/gssapi/mechglue/g_wrap_iov.c | 43 +---- + src/lib/kadm5/clnt/client_rpc.c | 1 + + src/lib/kadm5/kadm_rpc.h | 45 ----- + src/lib/kadm5/kadm_rpc_xdr.c | 37 ++-- + src/lib/kadm5/misc_free.c | 5 +- + src/lib/kadm5/srv/adb_xdr.c | 6 +- + src/lib/kadm5/srv/svr_principal.c | 12 +- + src/lib/kadm5/str_conv.c | 18 +- + src/lib/kadm5/t_kadm5.c | 22 +-- + src/lib/kdb/kdb5.c | 8 +- + src/lib/kdb/kdb_cpw.c | 32 +--- + src/lib/kdb/keytab.c | 19 +- + src/lib/kdb/t_stringattr.c | 2 +- + src/lib/krad/packet.c | 2 +- + src/lib/krad/t_attr.c | 2 +- + src/lib/krad/t_attrset.c | 2 +- + src/lib/krad/t_code.c | 2 +- + src/lib/krb5/ccache/cc_keyring.c | 2 +- + src/lib/krb5/krb/plugin.c | 2 +- + src/lib/krb5/krb/t_authdata.c | 2 +- + src/lib/krb5/krb/t_response_items.c | 2 +- + src/lib/krb5/krb/t_ser.c | 8 +- + src/lib/krb5/krb/t_sname_match.c | 2 +- + src/lib/krb5/krb/t_valid_times.c | 2 +- + src/lib/krb5/rcache/t_memrcache.c | 2 +- + src/lib/rpc/auth_gss.c | 4 +- + src/lib/rpc/auth_gssapi.c | 14 +- + src/lib/rpc/auth_gssapi_misc.c | 4 +- + src/lib/rpc/authunix_prot.c | 3 +- + src/lib/rpc/clnt_perror.c | 1 - + src/lib/rpc/clnt_raw.c | 2 +- + src/lib/rpc/dyn.c | 85 ++++----- + src/lib/rpc/pmap_clnt.c | 9 +- + src/lib/rpc/pmap_getmaps.c | 5 +- + src/lib/rpc/pmap_getport.c | 6 +- + src/lib/rpc/pmap_prot2.c | 3 +- + src/lib/rpc/pmap_rmt.c | 10 +- + src/lib/rpc/rpc_prot.c | 4 +- + src/lib/rpc/svc.c | 4 +- + src/lib/rpc/svc_auth_gss.c | 10 +- + src/lib/rpc/svc_auth_gssapi.c | 28 +-- + src/lib/rpc/svc_simple.c | 4 +- + src/lib/rpc/unit-test/client.c | 18 +- + src/lib/rpc/unit-test/rpc_test_clnt.c | 4 +- + src/lib/rpc/unit-test/rpc_test_svc.c | 16 +- + src/lib/rpc/unit-test/server.c | 2 +- + src/lib/rpc/xdr.c | 4 +- + src/lib/rpc/xdr_array.c | 4 +- + src/lib/rpc/xdr_rec.c | 13 +- + src/lib/rpc/xdr_reference.c | 4 +- + src/lib/rpc/xdr_sizeof.c | 29 +--- + src/plugins/kdb/db2/db2_exp.c | 4 +- + src/plugins/kdb/db2/libdb2/btree/bt_close.c | 10 +- + src/plugins/kdb/db2/libdb2/btree/bt_conv.c | 13 +- + src/plugins/kdb/db2/libdb2/btree/bt_delete.c | 34 +--- + src/plugins/kdb/db2/libdb2/btree/bt_get.c | 6 +- + src/plugins/kdb/db2/libdb2/btree/bt_open.c | 12 +- + .../kdb/db2/libdb2/btree/bt_overflow.c | 16 +- + src/plugins/kdb/db2/libdb2/btree/bt_page.c | 8 +- + src/plugins/kdb/db2/libdb2/btree/bt_put.c | 11 +- + src/plugins/kdb/db2/libdb2/btree/bt_search.c | 17 +- + src/plugins/kdb/db2/libdb2/btree/bt_seq.c | 27 +-- + src/plugins/kdb/db2/libdb2/btree/bt_split.c | 42 +---- + src/plugins/kdb/db2/libdb2/btree/bt_utils.c | 18 +- + src/plugins/kdb/db2/libdb2/db/db.c | 26 ++- + src/plugins/kdb/db2/libdb2/hash/dbm.c | 50 ++---- + src/plugins/kdb/db2/libdb2/hash/hash.c | 94 +++------- + src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c | 35 +--- + src/plugins/kdb/db2/libdb2/hash/hash_func.c | 16 +- + src/plugins/kdb/db2/libdb2/hash/hash_log2.c | 3 +- + src/plugins/kdb/db2/libdb2/hash/hash_page.c | 121 ++++--------- + src/plugins/kdb/db2/libdb2/hash/hsearch.c | 9 +- + src/plugins/kdb/db2/libdb2/mpool/mpool.c | 54 ++---- + src/plugins/kdb/db2/libdb2/recno/rec_close.c | 7 +- + src/plugins/kdb/db2/libdb2/recno/rec_delete.c | 14 +- + src/plugins/kdb/db2/libdb2/recno/rec_get.c | 22 +-- + src/plugins/kdb/db2/libdb2/recno/rec_open.c | 9 +- + src/plugins/kdb/db2/libdb2/recno/rec_put.c | 12 +- + src/plugins/kdb/db2/libdb2/recno/rec_search.c | 5 +- + src/plugins/kdb/db2/libdb2/recno/rec_seq.c | 5 +- + src/plugins/kdb/db2/libdb2/recno/rec_utils.c | 6 +- + src/plugins/kdb/db2/libdb2/test/dbtest.c | 59 ++----- + src/plugins/kdb/db2/pol_xdr.c | 2 +- + .../kdb/ldap/ldap_util/kdb5_ldap_util.c | 4 +- + src/plugins/kdb/lmdb/kdb_lmdb.c | 4 +- + src/plugins/kdb/test/kdb_test.c | 4 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 4 +- + src/plugins/preauth/spake/t_vectors.c | 2 +- + src/tests/asn.1/krb5_decode_test.c | 5 +- + src/tests/asn.1/krb5_encode_test.c | 13 +- + src/tests/asn.1/t_trval.c | 14 +- + src/tests/asn.1/trval.c | 73 +++----- + src/tests/conccache.c | 4 +- + src/tests/create/kdb5_mkdums.c | 16 +- + src/tests/forward.c | 2 +- + src/tests/gss-threads/gss-client.c | 4 +- + src/tests/gss-threads/gss-server.c | 2 +- + src/tests/gssapi/reload.c | 2 +- + src/tests/gssapi/t_add_cred.c | 2 +- + src/tests/gssapi/t_enctypes.c | 2 +- + src/tests/gssapi/t_invalid.c | 2 +- + src/tests/gssapi/t_oid.c | 2 +- + src/tests/gssapi/t_spnego.c | 2 +- + src/tests/hammer/kdc5_hammer.c | 36 ++-- + src/tests/kdbtest.c | 2 +- + src/tests/misc/test_getpw.c | 2 +- + src/tests/plugorder.c | 2 +- + src/tests/shlib/t_loader.c | 2 +- + src/tests/softpkcs11/main.c | 2 +- + src/tests/t_inetd.c | 7 +- + src/tests/test1.c | 4 +- + src/tests/verify/kdb5_verify.c | 17 +- + src/util/et/error_message.c | 2 +- + src/util/et/test_et.c | 3 +- + src/util/profile/prof_init.c | 2 +- + src/util/profile/t_profile.c | 22 +-- + src/util/profile/test_load.c | 2 +- + src/util/profile/test_parse.c | 5 +- + src/util/profile/test_profile.c | 10 +- + src/util/profile/test_vtable.c | 3 +- + src/util/ss/error.c | 13 +- + src/util/ss/execute_cmd.c | 23 +-- + src/util/ss/help.c | 115 ++++++------- + src/util/ss/invocation.c | 13 +- + src/util/ss/list_rqs.c | 11 +- + src/util/ss/listen.c | 32 ++-- + src/util/ss/pager.c | 10 +- + src/util/ss/parse.c | 6 +- + src/util/ss/prompt.c | 7 +- + src/util/ss/request_tbl.c | 11 +- + src/util/ss/requests.c | 2 +- + src/util/ss/ss.h | 1 - + src/util/ss/ss_internal.h | 3 +- + src/util/support/plugins.c | 10 +- + src/util/support/t_hashtab.c | 6 +- + src/util/support/t_hex.c | 3 +- + src/util/support/t_json.c | 2 +- + src/util/support/t_k5buf.c | 16 +- + src/util/support/t_unal.c | 3 +- + 253 files changed, 1379 insertions(+), 2717 deletions(-) + +diff --git a/src/aclocal.m4 b/src/aclocal.m4 +index 3331970930..040d5bdd0c 100644 +--- a/src/aclocal.m4 ++++ b/src/aclocal.m4 +@@ -546,7 +546,7 @@ if test "$GCC" = yes ; then + TRY_WARN_CC_FLAG(-Wno-format-zero-length) + # Other flags here may not be supported on some versions of + # gcc that people want to use. +- for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized no-maybe-uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int ; do ++ for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized no-maybe-uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int error=strict-prototypes; do + TRY_WARN_CC_FLAG(-W$flag) + done + # old-style-definition? generates many, many warnings +diff --git a/src/appl/gss-sample/gss-client.c b/src/appl/gss-sample/gss-client.c +index 6e2aa33690..0722ae196f 100644 +--- a/src/appl/gss-sample/gss-client.c ++++ b/src/appl/gss-sample/gss-client.c +@@ -75,7 +75,7 @@ static gss_OID_desc gss_spnego_mechanism_oid_desc = + {6, (void *)"\x2b\x06\x01\x05\x05\x02"}; + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-client [-port port] [-mech mechanism] " + "[-spnego] [-d]\n"); +@@ -359,9 +359,7 @@ client_establish_context(int s, char *service_name, OM_uint32 gss_flags, + } + + static void +-read_file(file_name, in_buf) +- char *file_name; +- gss_buffer_t in_buf; ++read_file(char *file_name, gss_buffer_t in_buf) + { + int fd, count; + struct stat stat_buf; +@@ -431,21 +429,10 @@ read_file(file_name, in_buf) + * verifies it with gss_verify. -1 is returned if any step fails, + * otherwise 0 is returned. */ + static int +-call_server(host, port, oid, service_name, gss_flags, auth_flag, +- wrap_flag, encrypt_flag, mic_flag, v1_format, msg, use_file, +- mcount, username, password) +- char *host; +- u_short port; +- gss_OID oid; +- char *service_name; +- OM_uint32 gss_flags; +- int auth_flag, wrap_flag, encrypt_flag, mic_flag; +- int v1_format; +- char *msg; +- int use_file; +- int mcount; +- char *username; +- char *password; ++call_server(char *host, u_short port, gss_OID oid, char *service_name, ++ OM_uint32 gss_flags, int auth_flag, int wrap_flag, ++ int encrypt_flag, int mic_flag, int v1_format, char *msg, ++ int use_file, int mcount, char *username, char *password) + { + gss_ctx_id_t context = GSS_C_NO_CONTEXT; + gss_buffer_desc in_buf, out_buf; +@@ -774,9 +761,7 @@ worker_bee(void *unused) + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + int i; + +diff --git a/src/appl/gss-sample/gss-misc.c b/src/appl/gss-sample/gss-misc.c +index 1d051edf1e..7eb4c7971d 100644 +--- a/src/appl/gss-sample/gss-misc.c ++++ b/src/appl/gss-sample/gss-misc.c +@@ -157,10 +157,7 @@ read_all(int fildes, void *data, unsigned int nbyte) + * if an error occurs or if it could not write all the data. + */ + int +-send_token(s, flags, tok) +- int s; +- int flags; +- gss_buffer_t tok; ++send_token(int s, int flags, gss_buffer_t tok) + { + int ret; + unsigned char char_flags = (unsigned char) flags; +@@ -230,10 +227,7 @@ send_token(s, flags, tok) + * and -1 if an error occurs or if it could not read all the data. + */ + int +-recv_token(s, flags, tok) +- int s; +- int *flags; +- gss_buffer_t tok; ++recv_token(int s, int *flags, gss_buffer_t tok) + { + int ret; + unsigned char char_flags; +@@ -303,10 +297,7 @@ recv_token(s, flags, tok) + } + + static void +-display_status_1(m, code, type) +- char *m; +- OM_uint32 code; +- int type; ++display_status_1(char *m, OM_uint32 code, int type) + { + OM_uint32 min_stat; + gss_buffer_desc msg; +@@ -344,10 +335,7 @@ display_status_1(m, code, type) + * followed by a newline. + */ + void +-display_status(msg, maj_stat, min_stat) +- char *msg; +- OM_uint32 maj_stat; +- OM_uint32 min_stat; ++display_status(char *msg, OM_uint32 maj_stat, OM_uint32 min_stat) + { + display_status_1(msg, maj_stat, GSS_C_GSS_CODE); + display_status_1(msg, min_stat, GSS_C_MECH_CODE); +@@ -370,8 +358,7 @@ display_status(msg, maj_stat, min_stat) + */ + + void +-display_ctx_flags(flags) +- OM_uint32 flags; ++display_ctx_flags(OM_uint32 flags) + { + if (flags & GSS_C_DELEG_FLAG) + fprintf(display_file, "context flag: GSS_C_DELEG_FLAG\n"); +@@ -388,8 +375,7 @@ display_ctx_flags(flags) + } + + void +-print_token(tok) +- gss_buffer_t tok; ++print_token(gss_buffer_t tok) + { + unsigned int i; + unsigned char *p = tok->value; +diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c +index 9b6ce9ffb3..0e9c857e56 100644 +--- a/src/appl/gss-sample/gss-server.c ++++ b/src/appl/gss-sample/gss-server.c +@@ -73,7 +73,7 @@ static OM_uint32 + showLocalIdentity(OM_uint32 *minor, gss_name_t name); + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-server [-port port] [-verbose] [-once]"); + #ifdef _WIN32 +diff --git a/src/appl/user_user/server.c b/src/appl/user_user/server.c +index f2b5b614e3..afb3d2bcba 100644 +--- a/src/appl/user_user/server.c ++++ b/src/appl/user_user/server.c +@@ -39,9 +39,8 @@ + + /* fd 0 is a tcp socket used to talk to the client */ + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + krb5_data pname_data, tkt_data; + int sock = 0; +diff --git a/src/clients/kdestroy/kdestroy.c b/src/clients/kdestroy/kdestroy.c +index 774b729fdb..48f672a1e8 100644 +--- a/src/clients/kdestroy/kdestroy.c ++++ b/src/clients/kdestroy/kdestroy.c +@@ -47,7 +47,7 @@ char *progname; + + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: %s [-A] [-q] [-c cache_name] [-p princ_name]\n"), + progname); +diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c +index f4c7b2b842..7a33ffae59 100644 +--- a/src/clients/kinit/kinit.c ++++ b/src/clients/kinit/kinit.c +@@ -45,7 +45,7 @@ + #ifdef HAVE_PWD_H + #include + static char * +-get_name_from_os() ++get_name_from_os(void) + { + struct passwd *pw; + +@@ -137,7 +137,7 @@ const char *shopts = "r:fpFPn54aAVl:s:c:kit:T:RS:vX:CEI:"; + #define USAGE_BREAK "\n\t" + + static void +-usage() ++usage(void) + { + fprintf(stderr, + _("Usage: %s [-V] [-l lifetime] [-s start_time] " +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index dcdc5a2d59..c797b1698f 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -80,7 +80,7 @@ static void fillit(FILE *, unsigned int, int); + #define KEYTAB 2 + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] " + "[-a [-n]]] [-k [-i] [-t] [-K]] [-C] [name]\n"), +diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c +index fb9d5d0942..17a8a8f2f0 100644 +--- a/src/clients/ksu/authorization.c ++++ b/src/clients/ksu/authorization.c +@@ -30,9 +30,8 @@ + + static void auth_cleanup (FILE *, FILE *, char *); + +-krb5_boolean fowner(fp, uid) +- FILE *fp; +- uid_t uid; ++krb5_boolean ++fowner(FILE *fp, uid_t uid) + { + struct stat sbuf; + +@@ -59,16 +58,10 @@ krb5_boolean fowner(fp, uid) + * + */ + +-krb5_error_code krb5_authorization(context, principal, luser, +- cmd, ok, out_fcmd) +-/* IN */ +- krb5_context context; +- krb5_principal principal; +- const char *luser; +- char *cmd; +- /* OUT */ +- krb5_boolean *ok; +- char **out_fcmd; ++krb5_error_code ++krb5_authorization(krb5_context context, krb5_principal principal, ++ const char *luser, char *cmd, krb5_boolean *ok, ++ char **out_fcmd) + { + struct passwd *pwd; + char *princname; +@@ -178,10 +171,8 @@ any tokens after the principal name FALSE is returned. + + ***********************************************************/ + +-krb5_error_code k5login_lookup (fp, princname, found) +- FILE *fp; +- char *princname; +- krb5_boolean *found; ++krb5_error_code ++k5login_lookup(FILE *fp, char *princname, krb5_boolean *found) + { + + krb5_error_code retval; +@@ -240,12 +231,9 @@ if princname is found{ + + + ***********************************************************/ +-krb5_error_code k5users_lookup (fp, princname, cmd, found, out_fcmd) +- FILE *fp; +- char *princname; +- char *cmd; +- krb5_boolean *found; +- char **out_fcmd; ++krb5_error_code ++k5users_lookup(FILE *fp, char *princname, char *cmd, ++ krb5_boolean *found, char **out_fcmd) + { + krb5_error_code retval; + char * line; +@@ -328,10 +316,8 @@ resolves it into a full path name. + + ************************************************/ + +-krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +- char *fcmd; +- char ***out_fcmd; +- char **out_err; ++krb5_boolean ++fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + { + char * err; + char ** tmp_fcmd; +@@ -407,8 +393,8 @@ cmd_single - checks if cmd consists of a path + + ********************************************/ + +-krb5_boolean cmd_single(cmd) +- char * cmd; ++krb5_boolean ++cmd_single(char *cmd) + { + + if ( ( strrchr( cmd, '/')) == NULL){ +@@ -423,9 +409,8 @@ cmd_arr_cmp_postfix - compares a command with the postfix + of fcmd + ********************************************/ + +-int cmd_arr_cmp_postfix(fcmd_arr, cmd) +- char **fcmd_arr; +- char *cmd; ++int ++cmd_arr_cmp_postfix(char **fcmd_arr, char *cmd) + { + char * temp_fcmd; + char *ptr; +@@ -457,9 +442,8 @@ cmd_arr_cmp - checks if cmd matches any + + **********************************************/ + +-int cmd_arr_cmp (fcmd_arr, cmd) +- char **fcmd_arr; +- char *cmd; ++int ++cmd_arr_cmp(char **fcmd_arr, char *cmd) + { + int result =1; + int i = 0; +@@ -475,10 +459,8 @@ int cmd_arr_cmp (fcmd_arr, cmd) + } + + +-krb5_boolean find_first_cmd_that_exists(fcmd_arr, cmd_out, err_out) +- char **fcmd_arr; +- char **cmd_out; +- char **err_out; ++krb5_boolean ++find_first_cmd_that_exists(char **fcmd_arr, char **cmd_out, char **err_out) + { + struct stat st_temp; + int i = 0; +@@ -517,12 +499,9 @@ returns 1 if there is an error, 0 if no error. + + ***************************************************************/ + +-int match_commands (fcmd, cmd, match, cmd_out, err_out) +- char *fcmd; +- char *cmd; +- krb5_boolean *match; +- char **cmd_out; +- char **err_out; ++int ++match_commands(char *fcmd, char *cmd, krb5_boolean *match, ++ char **cmd_out, char **err_out) + { + char ** fcmd_arr; + char * err; +@@ -566,11 +545,8 @@ int match_commands (fcmd, cmd, match, cmd_out, err_out) + is set to null if eof. + *********************************************************/ + +-krb5_error_code get_line (fp, out_line) +-/* IN */ +- FILE *fp; +- /* OUT */ +- char **out_line; ++krb5_error_code ++get_line(FILE *fp, char **out_line) + { + char * line, *r, *newline , *line_ptr; + int chunk_count = 1; +@@ -615,9 +591,8 @@ will be returned as part of the first token. + Note: this routine reuses the space pointed to by line + ******************************************************/ + +-char * get_first_token (line, lnext) +- char *line; +- char **lnext; ++char * ++get_first_token(char *line, char **lnext) + { + + char * lptr, * out_ptr; +@@ -651,8 +626,8 @@ Note: that this function modifies the stream + lnext to the next tocken. + **********************************************************/ + +-char * get_next_token (lnext) +- char **lnext; ++char * ++get_next_token (char **lnext) + { + char * lptr, * out_ptr; + +@@ -677,10 +652,8 @@ char * get_next_token (lnext) + return out_ptr; + } + +-static void auth_cleanup(users_fp, login_fp, princname) +- FILE *users_fp; +- FILE *login_fp; +- char *princname; ++static void ++auth_cleanup(FILE *users_fp, FILE *login_fp, char *princname) + { + + free (princname); +@@ -690,8 +663,8 @@ static void auth_cleanup(users_fp, login_fp, princname) + fclose(login_fp); + } + +-void init_auth_names(pw_dir) +- char *pw_dir; ++void ++init_auth_names(char *pw_dir) + { + const char *sep; + int r1, r2; +diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c +index cbb9aa2b85..cca9ce2dfc 100644 +--- a/src/clients/ksu/ccache.c ++++ b/src/clients/ksu/ccache.c +@@ -40,24 +40,18 @@ copies the default cache into the secondary cache, + + ************************************************************************/ + +-void show_credential(); ++void show_credential(krb5_context, krb5_creds *, krb5_ccache); + + /* modifies only the cc_other, the algorithm may look a bit funny, + but I had to do it this way, since remove function did not come + with k5 beta 3 release. + */ + +-krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, +- restrict_creds, primary_principal, stored) +-/* IN */ +- krb5_context context; +- krb5_ccache cc_def; +- krb5_principal target_principal; +- krb5_ccache cc_target; +- krb5_boolean restrict_creds; +- krb5_principal primary_principal; +- /* OUT */ +- krb5_boolean *stored; ++krb5_error_code ++krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, ++ krb5_principal target_principal, krb5_ccache cc_target, ++ krb5_boolean restrict_creds, krb5_principal primary_principal, ++ krb5_boolean *stored) + { + int i=0; + krb5_error_code retval=0; +@@ -105,11 +99,9 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, + } + + +-krb5_error_code krb5_store_all_creds(context, cc, creds_def, creds_other) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds **creds_def; +- krb5_creds **creds_other; ++krb5_error_code ++krb5_store_all_creds(krb5_context context, krb5_ccache cc, ++ krb5_creds **creds_def, krb5_creds **creds_other) + { + + int i = 0; +@@ -173,10 +165,8 @@ krb5_error_code krb5_store_all_creds(context, cc, creds_def, creds_other) + return 0; + } + +-krb5_boolean compare_creds(context, cred1, cred2) +- krb5_context context; +- krb5_creds *cred1; +- krb5_creds *cred2; ++krb5_boolean ++compare_creds(krb5_context context, krb5_creds *cred1, krb5_creds *cred2) + { + krb5_boolean retval; + +@@ -188,13 +178,9 @@ krb5_boolean compare_creds(context, cred1, cred2) + return retval; + } + +- +- +- +-krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds ***creds_array; ++krb5_error_code ++krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, ++ krb5_creds ***creds_array) + { + + krb5_creds creds, temp_tktq, temp_tkt; +@@ -262,10 +248,8 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) + + } + +- +-krb5_error_code krb5_check_exp(context, tkt_time) +- krb5_context context; +- krb5_ticket_times tkt_time; ++krb5_error_code ++krb5_check_exp(krb5_context context, krb5_ticket_times tkt_time) + { + krb5_error_code retval =0; + krb5_timestamp currenttime; +@@ -290,9 +274,8 @@ krb5_error_code krb5_check_exp(context, tkt_time) + return 0; + } + +- +-char *flags_string(cred) +- krb5_creds *cred; ++char * ++flags_string(krb5_creds *cred) + { + static char buf[32]; + int i = 0; +@@ -323,7 +306,8 @@ char *flags_string(cred) + return(buf); + } + +-void printtime(krb5_timestamp ts) ++void ++printtime(krb5_timestamp ts) + { + char fmtbuf[18], fill = ' '; + +@@ -333,9 +317,7 @@ void printtime(krb5_timestamp ts) + + + krb5_error_code +-krb5_get_login_princ(luser, princ_list) +- const char *luser; +- char ***princ_list; ++krb5_get_login_princ(const char *luser, char ***princ_list) + { + struct stat sbuf; + struct passwd *pwd; +@@ -420,13 +402,8 @@ krb5_get_login_princ(luser, princ_list) + return 0; + } + +- +- + void +-show_credential(context, cred, cc) +- krb5_context context; +- krb5_creds *cred; +- krb5_ccache cc; ++show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) + { + krb5_error_code retval; + char *name, *sname, *flags; +@@ -519,11 +496,9 @@ gen_sym(krb5_context context, char **sym_out) + return 0; + } + +-krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) +- krb5_context context; +- krb5_ccache ccs; +- krb5_ccache cct; +- krb5_principal primary_principal; ++krb5_error_code ++krb5_ccache_overwrite(krb5_context context, krb5_ccache ccs, krb5_ccache cct, ++ krb5_principal primary_principal) + { + krb5_error_code retval=0; + krb5_principal temp_principal; +@@ -560,14 +535,10 @@ krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) + return retval; + } + +-krb5_error_code krb5_store_some_creds(context, cc, creds_def, creds_other, prst, +- stored) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds **creds_def; +- krb5_creds **creds_other; +- krb5_principal prst; +- krb5_boolean *stored; ++krb5_error_code ++krb5_store_some_creds(krb5_context context, krb5_ccache cc, ++ krb5_creds **creds_def, krb5_creds **creds_other, ++ krb5_principal prst, krb5_boolean *stored) + { + + int i = 0; +@@ -610,10 +581,8 @@ krb5_error_code krb5_store_some_creds(context, cc, creds_def, creds_other, prst, + return 0; + } + +-krb5_error_code krb5_ccache_filter (context, cc, prst) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal prst; ++krb5_error_code ++krb5_ccache_filter(krb5_context context, krb5_ccache cc, krb5_principal prst) + { + + int i=0; +@@ -657,10 +626,9 @@ krb5_error_code krb5_ccache_filter (context, cc, prst) + return 0; + } + +-krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) +- krb5_context context; +- krb5_creds **creds_list; +- krb5_principal princ; ++krb5_boolean ++krb5_find_princ_in_cred_list(krb5_context context, krb5_creds **creds_list, ++ krb5_principal princ) + { + + int i = 0; +@@ -682,11 +650,9 @@ krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) + return temp_stored; + } + +-krb5_error_code krb5_find_princ_in_cache (context, cc, princ, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal princ; +- krb5_boolean *found; ++krb5_error_code ++krb5_find_princ_in_cache(krb5_context context, krb5_ccache cc, ++ krb5_principal princ, krb5_boolean *found) + { + krb5_error_code retval; + krb5_creds ** creds_list = NULL; +diff --git a/src/clients/ksu/heuristic.c b/src/clients/ksu/heuristic.c +index 4f7280f4cb..e906de8ef0 100644 +--- a/src/clients/ksu/heuristic.c ++++ b/src/clients/ksu/heuristic.c +@@ -41,9 +41,8 @@ get_all_princ_from_file - retrieves all principal names + static void close_time (int, FILE *, int, FILE *); + static krb5_boolean find_str_in_list (char **, char *); + +-krb5_error_code get_all_princ_from_file (fp, plist) +- FILE *fp; +- char ***plist; ++krb5_error_code ++get_all_princ_from_file(FILE *fp, char ***plist) + { + + krb5_error_code retval; +@@ -92,10 +91,8 @@ list_union - combines list1 and list2 into combined_list. + or used by combined_list. + **************************************************************/ + +-krb5_error_code list_union(list1, list2, combined_list) +- char **list1; +- char **list2; +- char ***combined_list; ++krb5_error_code ++list_union(char **list1, char **list2, char ***combined_list) + { + + unsigned int c1 =0, c2 = 0, i=0, j=0; +@@ -141,11 +138,7 @@ krb5_error_code list_union(list1, list2, combined_list) + } + + krb5_error_code +-filter(fp, cmd, k5users_list, k5users_filt_list) +- FILE *fp; +- char *cmd; +- char **k5users_list; +- char ***k5users_filt_list; ++filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) + { + + krb5_error_code retval =0; +@@ -195,10 +188,7 @@ filter(fp, cmd, k5users_list, k5users_filt_list) + } + + krb5_error_code +-get_authorized_princ_names(luser, cmd, princ_list) +- const char *luser; +- char *cmd; +- char ***princ_list; ++get_authorized_princ_names(const char *luser, char *cmd, char ***princ_list) + { + + struct passwd *pwd; +@@ -272,11 +262,8 @@ get_authorized_princ_names(luser, cmd, princ_list) + return 0; + } + +-static void close_time(k5users_flag, users_fp, k5login_flag, login_fp) +- int k5users_flag; +- FILE *users_fp; +- int k5login_flag; +- FILE *login_fp; ++static void ++close_time(int k5users_flag, FILE *users_fp, int k5login_flag, FILE *login_fp) + { + + if (!k5users_flag) fclose(users_fp); +@@ -284,9 +271,8 @@ static void close_time(k5users_flag, users_fp, k5login_flag, login_fp) + + } + +-static krb5_boolean find_str_in_list(list , elm) +- char **list; +- char *elm; ++static krb5_boolean ++find_str_in_list(char **list, char *elm) + { + + int i=0; +@@ -313,12 +299,9 @@ A principal is picked that has the best chance of getting in. + + **********************************************************************/ + +- +-krb5_error_code get_closest_principal(context, plist, client, found) +- krb5_context context; +- char **plist; +- krb5_principal *client; +- krb5_boolean *found; ++krb5_error_code ++get_closest_principal(krb5_context context, char **plist, ++ krb5_principal *client, krb5_boolean *found) + { + krb5_error_code retval =0; + krb5_principal temp_client, best_client = NULL; +@@ -385,12 +368,9 @@ find_either_ticket checks to see whether there is a ticket for the + end server or tgt, if neither is there the return FALSE, + *****************************************************************/ + +-krb5_error_code find_either_ticket (context, cc, client, end_server, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal client; +- krb5_principal end_server; +- krb5_boolean *found; ++krb5_error_code ++find_either_ticket(krb5_context context, krb5_ccache cc, krb5_principal client, ++ krb5_principal end_server, krb5_boolean *found) + { + + krb5_principal kdc_server; +@@ -424,13 +404,9 @@ krb5_error_code find_either_ticket (context, cc, client, end_server, found) + return 0; + } + +- +-krb5_error_code find_ticket (context, cc, client, server, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal client; +- krb5_principal server; +- krb5_boolean *found; ++krb5_error_code ++find_ticket(krb5_context context, krb5_ccache cc, krb5_principal client, ++ krb5_principal server, krb5_boolean *found) + { + + krb5_creds tgt, tgtq; +@@ -470,13 +446,9 @@ krb5_error_code find_ticket (context, cc, client, server, found) + return 0; + } + +- +- +-krb5_error_code find_princ_in_list (context, princ, plist, found) +- krb5_context context; +- krb5_principal princ; +- char **plist; +- krb5_boolean *found; ++krb5_error_code ++find_princ_in_list(krb5_context context, krb5_principal princ, char **plist, ++ krb5_boolean *found) + { + + int i=0; +@@ -516,21 +488,13 @@ path_out gets set to ... + + ***********************************************************************/ + +-krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +- source_user, target_user, +- cc_source, options, cmd, +- hostname, client, path_out) +- krb5_context context; +- uid_t source_uid; +- uid_t target_uid; +- char *source_user; +- char *target_user; +- krb5_ccache cc_source; +- krb5_get_init_creds_opt *options; +- char *cmd; +- char *hostname; +- krb5_principal *client; +- int *path_out; ++krb5_error_code ++get_best_princ_for_target(krb5_context context, uid_t source_uid, ++ uid_t target_uid, char *source_user, ++ char *target_user, krb5_ccache cc_source, ++ krb5_get_init_creds_opt *options, char *cmd, ++ char *hostname, krb5_principal *client, ++ int *path_out) + { + + princ_info princ_trials[10]; +diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c +index fb848dcab1..db10251f95 100644 +--- a/src/clients/ksu/krb_auth_su.c ++++ b/src/clients/ksu/krb_auth_su.c +@@ -29,18 +29,13 @@ + #include "ksu.h" + + +-void plain_dump_principal (); +- +-krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +- target_user, cc, path_passwd, target_uid) +- krb5_context context; +- krb5_principal client_pname; +- char *hostname; +- krb5_get_init_creds_opt *options; +- char *target_user; +- uid_t target_uid; +- krb5_ccache cc; +- int *path_passwd; ++void plain_dump_principal(krb5_context, krb5_principal); ++ ++krb5_boolean ++krb5_auth_check(krb5_context context, krb5_principal client_pname, ++ char *hostname, krb5_get_init_creds_opt *options, ++ char *target_user, krb5_ccache cc, int *path_passwd, ++ uid_t target_uid) + { + krb5_principal client; + krb5_verify_init_creds_opt vfy_opts; +@@ -137,13 +132,10 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + return (TRUE); + } + +-krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +- creds_out) +- krb5_context context; +- krb5_principal client; +- krb5_get_init_creds_opt *options; +- krb5_boolean *zero_password; +- krb5_creds *creds_out; ++krb5_boolean ++ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, ++ krb5_get_init_creds_opt *options, ++ krb5_boolean *zero_password, krb5_creds *creds_out) + { + krb5_error_code code; + krb5_creds creds; +@@ -212,11 +204,8 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + return (TRUE); + } + +- +-void dump_principal (context, str, p) +- krb5_context context; +- char *str; +- krb5_principal p; ++void ++dump_principal(krb5_context context, char *str, krb5_principal p) + { + char * stname; + krb5_error_code retval; +@@ -228,9 +217,8 @@ void dump_principal (context, str, p) + fprintf(stderr, " %s: %s\n", str, stname); + } + +-void plain_dump_principal (context, p) +- krb5_context context; +- krb5_principal p; ++void ++plain_dump_principal (krb5_context context, krb5_principal p) + { + char * stname; + krb5_error_code retval; +@@ -251,11 +239,8 @@ A principal is picked that has the best chance of getting in. + + **********************************************************************/ + +- +-krb5_error_code get_best_principal(context, plist, client) +- krb5_context context; +- char **plist; +- krb5_principal *client; ++krb5_error_code ++get_best_principal(krb5_context context, char **plist, krb5_principal *client) + { + krb5_error_code retval =0; + krb5_principal temp_client, best_client = NULL; +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 931f054041..2a351662c8 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -70,7 +70,9 @@ static krb5_error_code resolve_target_cache(krb5_context ksu_context, + /* insure the proper specification of target user as well as catching + ill specified arguments to commands */ + +-void usage (){ ++void ++usage(void) ++{ + fprintf(stderr, + _("Usage: %s [target user] [-n principal] [-c source cachename] " + "[-k] [-r time] [-p|-P] [-f|-F] [-l lifetime] [-zZ] [-q] " +@@ -86,9 +88,7 @@ void usage (){ + static uid_t source_uid, target_uid; + + int +-main (argc, argv) +- int argc; +- char ** argv; ++main(int argc, char ** argv) + { + int hp =0; + int some_rest_copy = 0; +@@ -120,7 +120,6 @@ main (argc, argv) + char ** params; + int keep_target_cache = 0; + int child_pid, child_pgrp, ret_pid; +- extern char * getpass(), *crypt(); + int pargc; + char ** pargv; + krb5_boolean stored = FALSE, cc_reused = FALSE, given_princ = FALSE; +@@ -1049,11 +1048,10 @@ cleanup: + + #ifdef HAVE_GETUSERSHELL + +-int standard_shell(sh) +- char *sh; ++int ++standard_shell(char *sh) + { + char *cp; +- char *getusershell(); + + while ((cp = getusershell()) != NULL) + if (!strcmp(cp, sh)) +@@ -1063,7 +1061,8 @@ int standard_shell(sh) + + #endif /* HAVE_GETUSERSHELL */ + +-static char * ontty() ++static char * ++ontty(void) + { + char *p; + static char buf[MAXPATHLEN + 5]; +@@ -1080,10 +1079,8 @@ static char * ontty() + return (buf); + } + +- +-static int set_env_var(name, value) +- char *name; +- char *value; ++static int ++set_env_var(char *name, char *value) + { + char * env_var_buf; + +@@ -1092,9 +1089,8 @@ static int set_env_var(name, value) + + } + +-static void sweep_up(context, cc) +- krb5_context context; +- krb5_ccache cc; ++static void ++sweep_up(krb5_context context, krb5_ccache cc) + { + krb5_error_code retval; + +@@ -1122,11 +1118,7 @@ get_params is to be called for the -a option or -e option to + *****************************************************************/ + + krb5_error_code +-get_params(optindex, pargc, pargv, params) +- int *optindex; +- int pargc; +- char **pargv; +- char ***params; ++get_params(int *optindex, int pargc, char **pargv, char ***params) + { + + int i,j; +@@ -1159,10 +1151,8 @@ void print_status(const char *fmt, ...) + } + + krb5_error_code +-ksu_tgtname(context, server, client, tgtprinc) +- krb5_context context; +- const krb5_data *server, *client; +- krb5_principal *tgtprinc; ++ksu_tgtname(krb5_context context, const krb5_data *server, ++ const krb5_data *client, krb5_principal *tgtprinc) + { + return krb5_build_principal_ext(context, tgtprinc, client->length, client->data, + KRB5_TGS_NAME_SIZE, KRB5_TGS_NAME, +diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c +index 03f72f596d..ac77a7d524 100644 +--- a/src/clients/kvno/kvno.c ++++ b/src/clients/kvno/kvno.c +@@ -39,7 +39,7 @@ static char *prog; + static int quiet = 0; + + static void +-xusage() ++xusage(void) + { + fprintf(stderr, _("usage: %s [-c ccache] [-e etype] [-k keytab] [-q] " + "[-u | -S sname]\n" +diff --git a/src/include/gssrpc/auth_gssapi.h b/src/include/gssrpc/auth_gssapi.h +index 9d94853228..63436a698a 100644 +--- a/src/include/gssrpc/auth_gssapi.h ++++ b/src/include/gssrpc/auth_gssapi.h +@@ -82,14 +82,12 @@ bool_t xdr_authgssapi_init_res(XDR *, auth_gssapi_init_res *); + + bool_t auth_gssapi_wrap_data + (OM_uint32 *major, OM_uint32 *minor, +- gss_ctx_id_t context, uint32_t seq_num, XDR +- *out_xdrs, bool_t (*xdr_func)(), caddr_t +- xdr_ptr); ++ gss_ctx_id_t context, uint32_t seq_num, ++ XDR *out_xdrs, xdrproc_t xdr_func, caddr_t xdr_ptr); + bool_t auth_gssapi_unwrap_data + (OM_uint32 *major, OM_uint32 *minor, +- gss_ctx_id_t context, uint32_t seq_num, XDR +- *in_xdrs, bool_t (*xdr_func)(), caddr_t +- xdr_ptr); ++ gss_ctx_id_t context, uint32_t seq_num, ++ XDR *in_xdrs, xdrproc_t xdr_func, caddr_t xdr_ptr); + + AUTH *auth_gssapi_create + (CLIENT *clnt, +diff --git a/src/include/gssrpc/xdr.h b/src/include/gssrpc/xdr.h +index da9e173782..4e5c29bdc2 100644 +--- a/src/include/gssrpc/xdr.h ++++ b/src/include/gssrpc/xdr.h +@@ -102,7 +102,6 @@ enum xdr_op { + * + * XXX can't actually prototype it, because some take three args!!! + */ +-typedef bool_t (*xdrproc_t)(); + + /* + * The XDR handle. +@@ -143,6 +142,8 @@ typedef struct XDR { + int x_handy; /* extra private word */ + } XDR; + ++typedef bool_t (*xdrproc_t)(XDR *, void *); ++ + /* + * Operations defined on a XDR handle + * +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 768110e5ef..b3e07945c1 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2236,7 +2236,7 @@ make_data(void *data, unsigned int len) + } + + static inline krb5_data +-empty_data() ++empty_data(void) + { + return make_data(NULL, 0); + } +diff --git a/src/include/k5-plugin.h b/src/include/k5-plugin.h +index 90809e168e..5c5af586c5 100644 +--- a/src/include/k5-plugin.h ++++ b/src/include/k5-plugin.h +@@ -97,7 +97,7 @@ krb5int_get_plugin_data (struct plugin_file_handle *, const char *, void **, + + long KRB5_CALLCONV + krb5int_get_plugin_func (struct plugin_file_handle *, const char *, +- void (**)(), struct errinfo *); ++ void (**)(void), struct errinfo *); + + + long KRB5_CALLCONV +diff --git a/src/include/net-server.h b/src/include/net-server.h +index a30749d851..29b235eeb8 100644 +--- a/src/include/net-server.h ++++ b/src/include/net-server.h +@@ -30,6 +30,7 @@ + #define NET_SERVER_H + + #include ++#include + + /* The delimiter characters supported by the addresses string. */ + #define ADDRESSES_DELIM ",; " +@@ -64,13 +65,14 @@ krb5_error_code loop_add_udp_address(int default_port, const char *addresses); + krb5_error_code loop_add_tcp_address(int default_port, const char *addresses); + krb5_error_code loop_add_rpc_service(int default_port, const char *addresses, + u_long prognum, u_long versnum, +- void (*dispatchfn)()); ++ void (*dispatchfn)(struct svc_req *, ++ SVCXPRT *)); + + krb5_error_code loop_setup_network(verto_ctx *ctx, void *handle, + const char *progname, + int tcp_listen_backlog); + krb5_error_code loop_setup_signals(verto_ctx *ctx, void *handle, +- void (*reset)()); ++ void (*reset)(void *)); + void loop_free(verto_ctx *ctx); + + /* to be supplied by the server application */ +diff --git a/src/kadmin/cli/getdate.y b/src/kadmin/cli/getdate.y +index d14cf963c5..3d69f0b8a4 100644 +--- a/src/kadmin/cli/getdate.y ++++ b/src/kadmin/cli/getdate.y +@@ -100,9 +100,6 @@ struct my_timeb { + #define bcopy(from, to, len) memcpy ((to), (from), (len)) + #endif + +-extern struct tm *gmtime(); +-extern struct tm *localtime(); +- + #define yyparse getdate_yyparse + #define yylex getdate_yylex + #define yyerror getdate_yyerror +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index f3ea6fae17..23b64b0f58 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -98,7 +98,7 @@ error(const char *fmt, ...) + } + + static void +-usage() ++usage(void) + { + error(_("Usage: %s [-r realm] [-p principal] [-q query] " + "[clnt|local args]\n" +@@ -1130,7 +1130,7 @@ kadmin_parse_princ_args(int argc, char *argv[], kadm5_principal_ent_t oprinc, + } + + static void +-kadmin_addprinc_usage() ++kadmin_addprinc_usage(void) + { + error(_("usage: add_principal [options] principal\n")); + error(_("\toptions are:\n")); +@@ -1154,7 +1154,7 @@ kadmin_addprinc_usage() + } + + static void +-kadmin_modprinc_usage() ++kadmin_modprinc_usage(void) + { + error(_("usage: modify_principal [options] principal\n")); + error(_("\toptions are:\n")); +diff --git a/src/kadmin/cli/keytab.c b/src/kadmin/cli/keytab.c +index b0c8378b40..26f340af31 100644 +--- a/src/kadmin/cli/keytab.c ++++ b/src/kadmin/cli/keytab.c +@@ -50,14 +50,14 @@ static int quiet; + static int norandkey; + + static void +-add_usage() ++add_usage(void) + { + fprintf(stderr, _("Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] " + "[-norandkey] [principal | -glob princ-exp] [...]\n")); + } + + static void +-rem_usage() ++rem_usage(void) + { + fprintf(stderr, _("Usage: ktremove [-k[eytab] keytab] [-q] principal " + "[kvno|\"all\"|\"old\"]\n")); +diff --git a/src/kadmin/dbutil/kdb5_create.c b/src/kadmin/dbutil/kdb5_create.c +index 038a0b2190..9178fca6da 100644 +--- a/src/kadmin/dbutil/kdb5_create.c ++++ b/src/kadmin/dbutil/kdb5_create.c +@@ -139,9 +139,8 @@ extern int exit_status; + extern kadm5_config_params global_params; + extern krb5_context util_context; + +-void kdb5_create(argc, argv) +- int argc; +- char *argv[]; ++void ++kdb5_create(int argc, char *argv[]) + { + int optchar; + +@@ -337,9 +336,7 @@ void kdb5_create(argc, argv) + } + + static krb5_error_code +-tgt_keysalt_iterate(ksent, ptr) +- krb5_key_salt_tuple *ksent; +- krb5_pointer ptr; ++tgt_keysalt_iterate(krb5_key_salt_tuple *ksent, krb5_pointer ptr) + { + krb5_context context; + krb5_error_code kret; +@@ -378,11 +375,8 @@ tgt_keysalt_iterate(ksent, ptr) + } + + static krb5_error_code +-add_principal(context, princ, op, pblock) +- krb5_context context; +- krb5_principal princ; +- enum ap_op op; +- struct realm_info *pblock; ++add_principal(krb5_context context, krb5_principal princ, enum ap_op op, ++ struct realm_info *pblock) + { + krb5_error_code retval; + krb5_db_entry *entry = NULL; +diff --git a/src/kadmin/dbutil/kdb5_destroy.c b/src/kadmin/dbutil/kdb5_destroy.c +index fffce74296..556cf0b6bb 100644 +--- a/src/kadmin/dbutil/kdb5_destroy.c ++++ b/src/kadmin/dbutil/kdb5_destroy.c +@@ -39,9 +39,7 @@ char *yes = "yes\n"; /* \n to compare against result of + fgets */ + + void +-kdb5_destroy(argc, argv) +- int argc; +- char *argv[]; ++kdb5_destroy(int argc, char *argv[]) + { + extern int optind; + int optchar; +diff --git a/src/kadmin/dbutil/kdb5_stash.c b/src/kadmin/dbutil/kdb5_stash.c +index e05944f290..eaba6cd353 100644 +--- a/src/kadmin/dbutil/kdb5_stash.c ++++ b/src/kadmin/dbutil/kdb5_stash.c +@@ -63,9 +63,7 @@ extern int exit_status; + extern int close_policy_db; + + void +-kdb5_stash(argc, argv) +- int argc; +- char *argv[]; ++kdb5_stash(int argc, char *argv[]) + { + extern char *optarg; + extern int optind; +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index 19a59250ee..55d529fa4c 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -143,8 +143,8 @@ struct _cmd_table { + {NULL, NULL, 0}, + }; + +-static struct _cmd_table *cmd_lookup(name) +- char *name; ++static struct _cmd_table * ++cmd_lookup(char *name) + { + struct _cmd_table *cmd = cmd_table; + while (cmd->name) { +@@ -162,8 +162,9 @@ static struct _cmd_table *cmd_lookup(name) + char **db5util_db_args = NULL; + int db5util_db_args_size = 0; + +-static void extended_com_err_fn (const char *myprog, errcode_t code, +- const char *fmt, va_list args) ++static void ++extended_com_err_fn(const char *myprog, errcode_t code, const char *fmt, ++ va_list args) + { + const char *emsg; + if (code) { +@@ -177,7 +178,8 @@ static void extended_com_err_fn (const char *myprog, errcode_t code, + fprintf (stderr, "\n"); + } + +-int add_db_arg(char *arg) ++int ++add_db_arg(char *arg) + { + char **temp; + db5util_db_args_size++; +@@ -191,9 +193,8 @@ int add_db_arg(char *arg) + return 1; + } + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + struct _cmd_table *cmd = NULL; + char *koptarg, **cmd_argv; +@@ -365,7 +366,8 @@ int main(argc, argv) + * cannot be fetched (the master key stash file may not exist when the + * program is run). + */ +-static int open_db_and_mkey() ++static int ++open_db_and_mkey() + { + krb5_error_code retval; + krb5_data scratch, pwd, seed; +@@ -508,9 +510,7 @@ quit() + } + + static void +-add_random_key(argc, argv) +- int argc; +- char **argv; ++add_random_key(int argc, char **argv) + { + krb5_error_code ret; + krb5_principal princ; +diff --git a/src/kadmin/dbutil/ovload.c b/src/kadmin/dbutil/ovload.c +index 15a5ab3005..b2e6c00eac 100644 +--- a/src/kadmin/dbutil/ovload.c ++++ b/src/kadmin/dbutil/ovload.c +@@ -11,9 +11,8 @@ + + #define LINESIZE 32768 /* XXX */ + +-static int parse_pw_hist_ent(current, hist) +- char *current; +- osa_pw_hist_ent *hist; ++static int ++parse_pw_hist_ent(char *current, osa_pw_hist_ent *hist) + { + int tmp, i, j, ret; + char *cp; +@@ -90,12 +89,9 @@ done: + * [modifies] + * + */ +-int process_ov_principal(kcontext, fname, filep, verbose, linenop) +- krb5_context kcontext; +- const char *fname; +- FILE *filep; +- krb5_boolean verbose; +- int *linenop; ++int ++process_ov_principal(krb5_context kcontext, const char *fname, FILE *filep, ++ krb5_boolean verbose, int *linenop) + { + XDR xdrs; + osa_princ_ent_t rec; +diff --git a/src/kadmin/dbutil/strtok.c b/src/kadmin/dbutil/strtok.c +index dee466aea1..93f3e85a51 100644 +--- a/src/kadmin/dbutil/strtok.c ++++ b/src/kadmin/dbutil/strtok.c +@@ -50,9 +50,7 @@ + */ + + char * +-nstrtok(s, delim) +- char *s; +- const char *delim; ++nstrtok(char *s, const char *delim) + { + const char *spanp; + int c, sc; +diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c +index 92d7023a4f..87a69ca145 100644 +--- a/src/kadmin/ktutil/ktutil.c ++++ b/src/kadmin/ktutil/ktutil.c +@@ -39,9 +39,8 @@ extern ss_request_table ktutil_cmds; + krb5_context kcontext; + krb5_kt_list ktlist = NULL; + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + krb5_error_code retval; + int sci_idx; +@@ -63,9 +62,8 @@ int main(argc, argv) + exit(0); + } + +-void ktutil_clear_list(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_clear_list(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -79,9 +77,8 @@ void ktutil_clear_list(argc, argv) + ktlist = NULL; + } + +-void ktutil_read_v5(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_read_v5(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -94,17 +91,15 @@ void ktutil_read_v5(argc, argv) + com_err(argv[0], retval, _("while reading keytab \"%s\""), argv[1]); + } + +-void ktutil_read_v4(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_read_v4(int argc, char *argv[]) + { + fprintf(stderr, _("%s: reading srvtabs is no longer supported\n"), + argv[0]); + } + +-void ktutil_write_v5(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_write_v5(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -117,17 +112,15 @@ void ktutil_write_v5(argc, argv) + com_err(argv[0], retval, _("while writing keytab \"%s\""), argv[1]); + } + +-void ktutil_write_v4(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_write_v4(int argc, char *argv[]) + { + fprintf(stderr, _("%s: writing srvtabs is no longer supported\n"), + argv[0]); + } + +-void ktutil_add_entry(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_add_entry(int argc, char *argv[]) + { + krb5_error_code retval; + char *princ = NULL; +@@ -183,9 +176,8 @@ void ktutil_add_entry(argc, argv) + com_err(argv[0], retval, _("while adding new entry")); + } + +-void ktutil_delete_entry(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_delete_entry(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -198,9 +190,8 @@ void ktutil_delete_entry(argc, argv) + com_err(argv[0], retval, _("while deleting entry %d"), atoi(argv[1])); + } + +-void ktutil_list(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_list(int argc, char *argv[]) + { + krb5_error_code retval; + krb5_kt_list lp; +diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c +index 56bed1bbcc..e489b5b57a 100644 +--- a/src/kadmin/ktutil/ktutil_funcs.c ++++ b/src/kadmin/ktutil/ktutil_funcs.c +@@ -37,9 +37,8 @@ + /* + * Free a kt_list + */ +-krb5_error_code ktutil_free_kt_list(context, list) +- krb5_context context; +- krb5_kt_list list; ++krb5_error_code ++ktutil_free_kt_list(krb5_context context, krb5_kt_list list) + { + krb5_kt_list lp, prev; + krb5_error_code retval = 0; +@@ -60,10 +59,8 @@ krb5_error_code ktutil_free_kt_list(context, list) + * Delete a numbered entry in a kt_list. Takes a pointer to a kt_list + * in case head gets deleted. + */ +-krb5_error_code ktutil_delete(context, list, idx) +- krb5_context context; +- krb5_kt_list *list; +- int idx; ++krb5_error_code ++ktutil_delete(krb5_context context, krb5_kt_list *list, int idx) + { + krb5_kt_list lp, prev; + int i; +@@ -138,16 +135,10 @@ get_etype_info(krb5_context context, krb5_principal princ, int fetch, + * password or key. If the keytab list is NULL, allocate a new + * one first. + */ +-krb5_error_code ktutil_add(context, list, princ_str, fetch, kvno, +- enctype_str, use_pass, salt_str) +- krb5_context context; +- krb5_kt_list *list; +- char *princ_str; +- int fetch; +- krb5_kvno kvno; +- char *enctype_str; +- int use_pass; +- char *salt_str; ++krb5_error_code ++ktutil_add(krb5_context context, krb5_kt_list *list, char *princ_str, ++ int fetch, krb5_kvno kvno, char *enctype_str, int use_pass, ++ char *salt_str) + { + krb5_keytab_entry *entry = NULL; + krb5_kt_list lp, *last; +@@ -269,10 +260,8 @@ cleanup: + * Read in a keytab and append it to list. If list starts as NULL, + * allocate a new one if necessary. + */ +-krb5_error_code ktutil_read_keytab(context, name, list) +- krb5_context context; +- char *name; +- krb5_kt_list *list; ++krb5_error_code ++ktutil_read_keytab(krb5_context context, char *name, krb5_kt_list *list) + { + krb5_kt_list lp = NULL, tail = NULL, back = NULL; + krb5_keytab kt; +@@ -344,10 +333,8 @@ close_kt: + /* + * Takes a kt_list and writes it to the named keytab. + */ +-krb5_error_code ktutil_write_keytab(context, list, name) +- krb5_context context; +- krb5_kt_list list; +- char *name; ++krb5_error_code ++ktutil_write_keytab(krb5_context context, krb5_kt_list list, char *name) + { + krb5_kt_list lp; + krb5_keytab kt; +diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c +index 56e9b90b20..e5dd233e81 100644 +--- a/src/kadmin/server/ipropd_svc.c ++++ b/src/kadmin/server/ipropd_svc.c +@@ -535,8 +535,8 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + kdb_last_t iprop_get_updates_1_arg; + } argument; + void *result; +- bool_t (*_xdr_argument)(), (*_xdr_result)(); +- void *(*local)(/* union XXX *, struct svc_req * */); ++ xdrproc_t _xdr_argument, _xdr_result; ++ void *(*local)(char *, struct svc_req *); + char *whoami = "krb5_iprop_prog_1"; + + if (!check_iprop_rpcsec_auth(rqstp)) { +@@ -555,21 +555,21 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + return; + + case IPROP_GET_UPDATES: +- _xdr_argument = xdr_kdb_last_t; +- _xdr_result = xdr_kdb_incr_result_t; +- local = (void *(*)()) iprop_get_updates_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_kdb_last_t; ++ _xdr_result = (xdrproc_t)xdr_kdb_incr_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_get_updates_1_svc; + break; + + case IPROP_FULL_RESYNC: +- _xdr_argument = xdr_void; +- _xdr_result = xdr_kdb_fullresync_result_t; +- local = (void *(*)()) iprop_full_resync_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_void; ++ _xdr_result = (xdrproc_t)xdr_kdb_fullresync_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_full_resync_1_svc; + break; + + case IPROP_FULL_RESYNC_EXT: +- _xdr_argument = xdr_u_int32; +- _xdr_result = xdr_kdb_fullresync_result_t; +- local = (void *(*)()) iprop_full_resync_ext_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_u_int32; ++ _xdr_result = (xdrproc_t)xdr_kdb_fullresync_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_full_resync_ext_1_svc; + break; + + default: +@@ -587,7 +587,7 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + svcerr_decode(transp); + return; + } +- result = (*local)(&argument, rqstp); ++ result = (*local)((char *)&argument, rqstp); + + if (_xdr_result && result != NULL && + !svc_sendreply(transp, _xdr_result, result)) { +diff --git a/src/kadmin/server/kadm_rpc_svc.c b/src/kadmin/server/kadm_rpc_svc.c +index 8371fa76ca..f0e43d9aea 100644 +--- a/src/kadmin/server/kadm_rpc_svc.c ++++ b/src/kadmin/server/kadm_rpc_svc.c +@@ -9,6 +9,7 @@ + #include /* for gss_nt_krb5_name */ + #include + #include ++#include + #include + #include + #include +@@ -36,9 +37,8 @@ static int check_rpcsec_auth(struct svc_req *); + * Modifies: + */ + +-void kadm_1(rqstp, transp) +- struct svc_req *rqstp; +- SVCXPRT *transp; ++void ++kadm_1(struct svc_req *rqstp, SVCXPRT *transp) + { + union { + cprinc_arg create_principal_2_arg; +@@ -73,8 +73,8 @@ void kadm_1(rqstp, transp) + getpkeys_ret get_principal_keys_ret; + } result; + bool_t retval; +- bool_t (*xdr_argument)(), (*xdr_result)(); +- bool_t (*local)(); ++ xdrproc_t xdr_argument, xdr_result; ++ bool_t (*local)(char *, void *, struct svc_req *); + + if (rqstp->rq_cred.oa_flavor != AUTH_GSSAPI && + !check_rpcsec_auth(rqstp)) { +@@ -92,153 +92,153 @@ void kadm_1(rqstp, transp) + return; + + case CREATE_PRINCIPAL: +- xdr_argument = xdr_cprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_principal_2_svc; + break; + + case DELETE_PRINCIPAL: +- xdr_argument = xdr_dprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) delete_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_dprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))delete_principal_2_svc; + break; + + case MODIFY_PRINCIPAL: +- xdr_argument = xdr_mprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) modify_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_mprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))modify_principal_2_svc; + break; + + case RENAME_PRINCIPAL: +- xdr_argument = xdr_rprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) rename_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_rprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))rename_principal_2_svc; + break; + + case GET_PRINCIPAL: +- xdr_argument = xdr_gprinc_arg; +- xdr_result = xdr_gprinc_ret; +- local = (bool_t (*)()) get_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gprinc_arg; ++ xdr_result = (xdrproc_t)xdr_gprinc_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_principal_2_svc; + break; + + case GET_PRINCS: +- xdr_argument = xdr_gprincs_arg; +- xdr_result = xdr_gprincs_ret; +- local = (bool_t (*)()) get_princs_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gprincs_arg; ++ xdr_result = (xdrproc_t)xdr_gprincs_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_princs_2_svc; + break; + + case CHPASS_PRINCIPAL: +- xdr_argument = xdr_chpass_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) chpass_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chpass_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chpass_principal_2_svc; + break; + + case SETKEY_PRINCIPAL: +- xdr_argument = xdr_setkey_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal_2_svc; + break; + + case CHRAND_PRINCIPAL: +- xdr_argument = xdr_chrand_arg; +- xdr_result = xdr_chrand_ret; +- local = (bool_t (*)()) chrand_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chrand_arg; ++ xdr_result = (xdrproc_t)xdr_chrand_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chrand_principal_2_svc; + break; + + case CREATE_POLICY: +- xdr_argument = xdr_cpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_policy_2_svc; + break; + + case DELETE_POLICY: +- xdr_argument = xdr_dpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) delete_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_dpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))delete_policy_2_svc; + break; + + case MODIFY_POLICY: +- xdr_argument = xdr_mpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) modify_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_mpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))modify_policy_2_svc; + break; + + case GET_POLICY: +- xdr_argument = xdr_gpol_arg; +- xdr_result = xdr_gpol_ret; +- local = (bool_t (*)()) get_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gpol_arg; ++ xdr_result = (xdrproc_t)xdr_gpol_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_policy_2_svc; + break; + + case GET_POLS: +- xdr_argument = xdr_gpols_arg; +- xdr_result = xdr_gpols_ret; +- local = (bool_t (*)()) get_pols_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gpols_arg; ++ xdr_result = (xdrproc_t)xdr_gpols_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_pols_2_svc; + break; + + case GET_PRIVS: +- xdr_argument = xdr_u_int32; +- xdr_result = xdr_getprivs_ret; +- local = (bool_t (*)()) get_privs_2_svc; ++ xdr_argument = (xdrproc_t)xdr_u_int32; ++ xdr_result = (xdrproc_t)xdr_getprivs_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_privs_2_svc; + break; + + case INIT: +- xdr_argument = xdr_u_int32; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) init_2_svc; ++ xdr_argument = (xdrproc_t)xdr_u_int32; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))init_2_svc; + break; + + case CREATE_PRINCIPAL3: +- xdr_argument = xdr_cprinc3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cprinc3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_principal3_2_svc; + break; + + case CHPASS_PRINCIPAL3: +- xdr_argument = xdr_chpass3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) chpass_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chpass3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chpass_principal3_2_svc; + break; + + case CHRAND_PRINCIPAL3: +- xdr_argument = xdr_chrand3_arg; +- xdr_result = xdr_chrand_ret; +- local = (bool_t (*)()) chrand_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chrand3_arg; ++ xdr_result = (xdrproc_t)xdr_chrand_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chrand_principal3_2_svc; + break; + + case SETKEY_PRINCIPAL3: +- xdr_argument = xdr_setkey3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal3_2_svc; + break; + + case PURGEKEYS: +- xdr_argument = xdr_purgekeys_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) purgekeys_2_svc; ++ xdr_argument = (xdrproc_t)xdr_purgekeys_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))purgekeys_2_svc; + break; + + case GET_STRINGS: +- xdr_argument = xdr_gstrings_arg; +- xdr_result = xdr_gstrings_ret; +- local = (bool_t (*)()) get_strings_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gstrings_arg; ++ xdr_result = (xdrproc_t)xdr_gstrings_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_strings_2_svc; + break; + + case SET_STRING: +- xdr_argument = xdr_sstring_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) set_string_2_svc; ++ xdr_argument = (xdrproc_t)xdr_sstring_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))set_string_2_svc; + break; + + case SETKEY_PRINCIPAL4: +- xdr_argument = xdr_setkey4_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal4_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey4_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal4_2_svc; + break; + + case EXTRACT_KEYS: +- xdr_argument = xdr_getpkeys_arg; +- xdr_result = xdr_getpkeys_ret; +- local = (bool_t (*)()) get_principal_keys_2_svc; ++ xdr_argument = (xdrproc_t)xdr_getpkeys_arg; ++ xdr_result = (xdrproc_t)xdr_getpkeys_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_principal_keys_2_svc; + break; + + default: +@@ -253,7 +253,7 @@ void kadm_1(rqstp, transp) + return; + } + memset(&result, 0, sizeof(result)); +- retval = (*local)(&argument, &result, rqstp); ++ retval = (*local)((char *)&argument, &result, rqstp); + if (retval && !svc_sendreply(transp, xdr_result, (void *)&result)) { + krb5_klog_syslog(LOG_ERR, "WARNING! Unable to send function results, " + "continuing."); +diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c +index b29a0f5b63..a9508af120 100644 +--- a/src/kadmin/server/ovsec_kadmd.c ++++ b/src/kadmin/server/ovsec_kadmd.c +@@ -77,7 +77,7 @@ static krb5_context context; + static char *progname; + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: kadmind [-x db_args]* [-r realm] [-m] [-nofork] " + "[-port port-number]\n" +@@ -173,7 +173,7 @@ setup_loop(kadm5_config_params *params, int proponly, verto_ctx **ctx_out) + + /* Point GSSAPI at the KDB keytab so we don't need an actual file keytab. */ + static krb5_error_code +-setup_kdb_keytab() ++setup_kdb_keytab(void) + { + krb5_error_code ret; + +diff --git a/src/kdc/t_ndr.c b/src/kdc/t_ndr.c +index a3ac661bd0..c2a2414313 100644 +--- a/src/kdc/t_ndr.c ++++ b/src/kdc/t_ndr.c +@@ -173,7 +173,7 @@ test_dec_enc(uint8_t *blob, size_t len, char *name, int fail) + #define RUN_TEST_FAIL(blob) test_dec_enc(blob, sizeof(blob), #blob, 1) + + int +-main() ++main(void) + { + printf("Running NDR tests...\n"); + +diff --git a/src/kdc/t_replay.c b/src/kdc/t_replay.c +index 57aad886cd..c9c9d65946 100644 +--- a/src/kdc/t_replay.c ++++ b/src/kdc/t_replay.c +@@ -570,7 +570,8 @@ test_kdc_insert_lookaside_cache_expire(void **state) + assert_int_equal(total_size, e2_size); + } + +-int main() ++int ++main(void) + { + int ret; + +@@ -611,7 +612,8 @@ int main() + + #else /* NOCACHE */ + +-int main() ++int ++main(void) + { + return 0; + } +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index cb9785aaeb..f883ae2df8 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -165,7 +165,7 @@ static kadm5_ret_t kadm5_get_kiprop_host_srv_name(krb5_context context, + char **host_service_name); + + static void +-usage() ++usage(void) + { + fprintf(stderr, + _("\nUsage: %s [-r realm] [-s keytab] [-d] [-D] [-S]\n" +diff --git a/src/kprop/kproplog.c b/src/kprop/kproplog.c +index 06af2a1d60..1f10aa6dc7 100644 +--- a/src/kprop/kproplog.c ++++ b/src/kprop/kproplog.c +@@ -24,7 +24,7 @@ + static char *progname; + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("\nUsage: %s [-h] [-v] [-v] [-e num]\n\t%s -R\n\n"), + progname, progname); +@@ -393,7 +393,7 @@ print_update(kdb_hlog_t *ulog, uint32_t entry, uint32_t ulogentries, + print_attr(&upd.kdb_update.kdbe_t_val[j], verbose > 1 ? 1 : 0); + } + +- xdr_free(xdr_kdb_incr_update_t, (char *)&upd); ++ xdr_free((xdrproc_t)xdr_kdb_incr_update_t, (char *)&upd); + free(dbprinc); + } + } +diff --git a/src/lib/apputils/net-server.c b/src/lib/apputils/net-server.c +index 1bdc7932b6..75372d8940 100644 +--- a/src/lib/apputils/net-server.c ++++ b/src/lib/apputils/net-server.c +@@ -203,7 +203,7 @@ struct connection { + struct rpc_svc_data { + u_long prognum; + u_long versnum; +- void (*dispatch)(); ++ void (*dispatch)(struct svc_req *, SVCXPRT *); + }; + + struct bind_address { +@@ -255,7 +255,7 @@ free_sighup_context(verto_ctx *ctx, verto_ev *ev) + } + + krb5_error_code +-loop_setup_signals(verto_ctx *ctx, void *handle, void (*reset)()) ++loop_setup_signals(verto_ctx *ctx, void *handle, void (*reset)(void *)) + { + struct sighup_context *sc; + verto_ev *ev; +@@ -434,7 +434,8 @@ loop_add_tcp_address(int default_port, const char *addresses) + + krb5_error_code + loop_add_rpc_service(int default_port, const char *addresses, u_long prognum, +- u_long versnum, void (*dispatchfn)()) ++ u_long versnum, ++ void (*dispatchfn)(struct svc_req *, SVCXPRT *)) + { + struct rpc_svc_data svc; + +diff --git a/src/lib/crypto/builtin/aes/aes-gen.c b/src/lib/crypto/builtin/aes/aes-gen.c +index b528d3796d..4d7a16ee9a 100644 +--- a/src/lib/crypto/builtin/aes/aes-gen.c ++++ b/src/lib/crypto/builtin/aes/aes-gen.c +@@ -54,7 +54,8 @@ uint8_t test_case[NTESTS][4 * B] = { + aes_encrypt_ctx ctx; + aes_decrypt_ctx dctx; + +-static void init () ++static void ++init (void) + { + AES_RETURN r; + +@@ -71,7 +72,8 @@ static void hexdump(const unsigned char *ptr, size_t len) + printf ("%s%02X", (i % 16 == 0) ? "\n " : " ", ptr[i]); + } + +-static void fips_test () ++static void ++fips_test (void) + { + static const unsigned char fipskey[16] = { + 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, +@@ -254,7 +256,8 @@ cts_dec (unsigned char *out, unsigned char *in, unsigned char *iv, + memcpy(out+B, pn, len-B); + } + +-static void ecb_test () ++static void ++ecb_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -285,7 +288,8 @@ static void ecb_test () + + unsigned char ivec[16] = { 0 }; + +-static void cbc_test () ++static void ++cbc_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -314,7 +318,8 @@ static void cbc_test () + printf ("\n"); + } + +-static void cts_test () ++static void ++cts_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -339,7 +344,8 @@ static void cts_test () + printf ("\n"); + } + +-int main () ++int ++main (void) + { + init (); + fips_test (); +diff --git a/src/lib/crypto/builtin/camellia/camellia-gen.c b/src/lib/crypto/builtin/camellia/camellia-gen.c +index 23b69c1741..6eca0e0525 100644 +--- a/src/lib/crypto/builtin/camellia/camellia-gen.c ++++ b/src/lib/crypto/builtin/camellia/camellia-gen.c +@@ -19,7 +19,8 @@ struct { + } test_case[NTESTS]; + camellia_ctx ctx, dctx; + +-static void init () ++static void ++init (void) + { + size_t i, j; + cam_rval r; +@@ -46,7 +47,8 @@ static void hexdump(const unsigned char *ptr, size_t len) + printf ("%s%02X", (i % 16 == 0) ? "\n " : " ", ptr[i]); + } + +-static void fips_test () ++static void ++fips_test (void) + { + static const unsigned char fipskey[16] = { + 0x01, 0x23, 0x45, 0x67, 0x89, 0xab, 0xcd, 0xef, +@@ -234,7 +236,8 @@ cts_dec (unsigned char *out, unsigned char *in, unsigned char *iv, + memcpy(out+B, pn, len-B); + } + +-static void ecb_test () ++static void ++ecb_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -265,7 +268,8 @@ static void ecb_test () + + unsigned char ivec[16] = { 0 }; + +-static void cbc_test () ++static void ++cbc_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -294,7 +298,8 @@ static void cbc_test () + printf ("\n"); + } + +-static void cts_test () ++static void ++cts_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -319,7 +324,8 @@ static void cts_test () + printf ("\n"); + } + +-int main () ++int ++main (void) + { + init (); + fips_test (); +diff --git a/src/lib/crypto/builtin/sha1/t_shs.c b/src/lib/crypto/builtin/sha1/t_shs.c +index c1d18f5571..a668cb0c06 100644 +--- a/src/lib/crypto/builtin/sha1/t_shs.c ++++ b/src/lib/crypto/builtin/sha1/t_shs.c +@@ -29,9 +29,8 @@ static SHS_LONG shsTestResults[][ 5 ] = { + }; + #endif /* NEW_SHS */ + +-static int compareSHSresults(shsInfo, shsTestLevel) +- SHS_INFO *shsInfo; +- int shsTestLevel; ++static int ++compareSHSresults(SHS_INFO *shsInfo, int shsTestLevel) + { + int i, fail = 0; + +@@ -55,7 +54,7 @@ static int compareSHSresults(shsInfo, shsTestLevel) + } + + int +-main() ++main(int argc, char *argv[]) + { + SHS_INFO shsInfo; + unsigned int i; +diff --git a/src/lib/crypto/builtin/sha1/t_shs3.c b/src/lib/crypto/builtin/sha1/t_shs3.c +index 7aa0bbdee3..87caf7fa37 100644 +--- a/src/lib/crypto/builtin/sha1/t_shs3.c ++++ b/src/lib/crypto/builtin/sha1/t_shs3.c +@@ -55,9 +55,7 @@ int mode; + int Dflag; + + int +-main(argc,argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + char *argp; + +@@ -131,8 +129,7 @@ static void process(void) + + #ifndef shsDigest + static unsigned char * +-shsDigest(si) +- SHS_INFO *si; ++shsDigest(SHS_INFO *si) + { + longReverse(si->digest, SHS_DIGESTSIZE); + return (unsigned char*) si->digest; +diff --git a/src/lib/crypto/crypto_tests/aes-test.c b/src/lib/crypto/crypto_tests/aes-test.c +index a7382a48ad..d26f711b8d 100644 +--- a/src/lib/crypto/crypto_tests/aes-test.c ++++ b/src/lib/crypto/crypto_tests/aes-test.c +@@ -37,14 +37,14 @@ static char plain[16], cipher[16], zero[16]; + + static krb5_keyblock enc_key; + static krb5_data ivec; +-static void init() ++static void init(void) + { + enc_key.contents = (krb5_octet *)key; + enc_key.length = 16; + ivec.data = zero; + ivec.length = 16; + } +-static void enc() ++static void enc(void) + { + krb5_key k; + krb5_crypto_iov iov; +@@ -93,7 +93,7 @@ static void vk_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vk_test() ++static void vk_test(void) + { + vk_test_1(16, ENCTYPE_AES128_CTS_HMAC_SHA1_96); + vk_test_1(32, ENCTYPE_AES256_CTS_HMAC_SHA1_96); +@@ -119,7 +119,7 @@ static void vt_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vt_test() ++static void vt_test(void) + { + vt_test_1(16, ENCTYPE_AES128_CTS_HMAC_SHA1_96); + vt_test_1(32, ENCTYPE_AES256_CTS_HMAC_SHA1_96); +diff --git a/src/lib/crypto/crypto_tests/camellia-test.c b/src/lib/crypto/crypto_tests/camellia-test.c +index 23d14667e1..ca6579f7d1 100644 +--- a/src/lib/crypto/crypto_tests/camellia-test.c ++++ b/src/lib/crypto/crypto_tests/camellia-test.c +@@ -35,14 +35,14 @@ static char plain[16], cipher[16], zero[16]; + + static krb5_keyblock enc_key; + static krb5_data ivec; +-static void init() ++static void init(void) + { + enc_key.contents = (unsigned char *)key; + enc_key.length = 16; + ivec.data = zero; + ivec.length = 16; + } +-static void enc() ++static void enc(void) + { + krb5_key k; + krb5_crypto_iov iov; +@@ -91,7 +91,7 @@ static void vk_test_1(int len) + } + printf("\n==========\n"); + } +-static void vk_test() ++static void vk_test(void) + { + vk_test_1(16); + vk_test_1(32); +@@ -117,7 +117,7 @@ static void vt_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vt_test() ++static void vt_test(void) + { + vt_test_1(16, ENCTYPE_CAMELLIA128_CTS_CMAC); + vt_test_1(32, ENCTYPE_CAMELLIA256_CTS_CMAC); +diff --git a/src/lib/crypto/crypto_tests/t_cf2.c b/src/lib/crypto/crypto_tests/t_cf2.c +index 67c9dcdee2..4c894ad09c 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.c ++++ b/src/lib/crypto/crypto_tests/t_cf2.c +@@ -46,7 +46,9 @@ + #include + #include + +-int main () { ++int ++main(void) ++{ + krb5_error_code ret; + char pepper1[1025], pepper2[1025]; + krb5_keyblock *k1 = NULL, *k2 = NULL, *out = NULL; +diff --git a/src/lib/crypto/crypto_tests/t_cts.c b/src/lib/crypto/crypto_tests/t_cts.c +index fe505169f3..f8a5a534b2 100644 +--- a/src/lib/crypto/crypto_tests/t_cts.c ++++ b/src/lib/crypto/crypto_tests/t_cts.c +@@ -77,7 +77,7 @@ static void printk(const char *descr, krb5_keyblock *k) { + printd(descr, &d); + } + +-static void test_cts() ++static void test_cts(void) + { + static const char input[4*16] = + "I would like the General Gau's Chicken, please, and wonton soup."; +diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c +index 290a72e1e0..83bc98a2f1 100644 +--- a/src/lib/crypto/crypto_tests/t_encrypt.c ++++ b/src/lib/crypto/crypto_tests/t_encrypt.c +@@ -87,7 +87,7 @@ display(const char *msg, const krb5_data *d) + } + + int +-main () ++main(void) + { + krb5_context context = 0; + krb5_data in, in2, out, out2, check, check2, state, signdata; +diff --git a/src/lib/crypto/crypto_tests/t_fork.c b/src/lib/crypto/crypto_tests/t_fork.c +index 428fc8a6a1..8be7474227 100644 +--- a/src/lib/crypto/crypto_tests/t_fork.c ++++ b/src/lib/crypto/crypto_tests/t_fork.c +@@ -55,7 +55,7 @@ prepare_enc_data(krb5_key key, size_t in_len, krb5_enc_data *enc_data) + } + + int +-main() ++main(void) + { + krb5_keyblock kb_aes, kb_rc4; + krb5_key key_aes, key_rc4; +diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c +index da359cb494..e40136bff0 100644 +--- a/src/lib/crypto/crypto_tests/t_hmac.c ++++ b/src/lib/crypto/crypto_tests/t_hmac.c +@@ -122,7 +122,8 @@ static krb5_error_code hmac1(const struct krb5_hash_provider *h, + return err; + } + +-static void test_hmac() ++static void ++test_hmac(void) + { + krb5_keyblock key; + krb5_data in, out; +diff --git a/src/lib/crypto/crypto_tests/t_mddriver.c b/src/lib/crypto/crypto_tests/t_mddriver.c +index ad65d03156..035f825bbc 100644 +--- a/src/lib/crypto/crypto_tests/t_mddriver.c ++++ b/src/lib/crypto/crypto_tests/t_mddriver.c +@@ -111,9 +111,8 @@ struct md_test_entry md_test_suite[] = { + -t - runs time trial + -x - runs test script + */ +-int main (argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + int i; + +@@ -128,10 +127,8 @@ int main (argc, argv) + return (0); + } + +-static void MDHash (bytes, len, count, out) +- char *bytes; +- size_t len, count; +- unsigned char *out; ++static void ++MDHash(char *bytes, size_t len, size_t count, unsigned char *out) + { + krb5_crypto_iov *iov; + krb5_data outdata = make_data (out, MDProvider.hashsize); +@@ -150,8 +147,8 @@ static void MDHash (bytes, len, count, out) + + /* Digests a string and prints the result. + */ +-static void MDString (string) +- char *string; ++static void ++MDString(char *string) + { + unsigned char digest[16]; + +@@ -164,7 +161,8 @@ static void MDString (string) + /* Measures the time to digest TEST_BLOCK_COUNT TEST_BLOCK_LEN-byte + blocks. + */ +-static void MDTimeTrial () ++static void ++MDTimeTrial(void) + { + time_t endTime, startTime; + unsigned char block[TEST_BLOCK_LEN], digest[16]; +@@ -197,7 +195,8 @@ static void MDTimeTrial () + + /* Digests a reference suite of strings and prints the results. + */ +-static void MDTestSuite () ++static void ++MDTestSuite(void) + { + #ifdef HAVE_TEST_SUITE + struct md_test_entry *entry; +@@ -246,8 +245,8 @@ static void MDTestSuite () + + /* Prints a message digest in hexadecimal. + */ +-static void MDPrint (digest) +- unsigned char digest[16]; ++static void ++MDPrint(unsigned char digest[16]) + { + unsigned int i; + +diff --git a/src/lib/crypto/crypto_tests/t_nfold.c b/src/lib/crypto/crypto_tests/t_nfold.c +index b94353c221..a741b61e0c 100644 +--- a/src/lib/crypto/crypto_tests/t_nfold.c ++++ b/src/lib/crypto/crypto_tests/t_nfold.c +@@ -33,17 +33,20 @@ + + #define ASIZE(ARRAY) (sizeof(ARRAY)/sizeof(ARRAY[0])) + +-static void printhex (size_t len, const unsigned char *p) ++static void ++printhex(size_t len, const unsigned char *p) + { + while (len--) + printf ("%02x", 0xff & *p++); + } + +-static void printstringhex (const unsigned char *p) { ++static void ++printstringhex(const unsigned char *p) { + printhex (strlen ((const char *) p), p); + } + +-static void rfc_tests () ++static void ++rfc_tests(void) + { + unsigned i; + struct { +@@ -92,7 +95,8 @@ static void rfc_tests () + } + } + +-static void fold_kerberos(unsigned int nbytes) ++static void ++fold_kerberos(unsigned int nbytes) + { + unsigned char cipher_text[300]; + unsigned int j; +@@ -125,9 +129,7 @@ unsigned char nfold_192[4][24] = { + }; + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + unsigned char cipher_text[64]; + unsigned int i, j; +diff --git a/src/lib/crypto/crypto_tests/t_prf.c b/src/lib/crypto/crypto_tests/t_prf.c +index d9877bd1f7..6fa0afb183 100644 +--- a/src/lib/crypto/crypto_tests/t_prf.c ++++ b/src/lib/crypto/crypto_tests/t_prf.c +@@ -116,7 +116,7 @@ struct test { + }; + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_data output; +diff --git a/src/lib/crypto/crypto_tests/t_sha2.c b/src/lib/crypto/crypto_tests/t_sha2.c +index e6fa584982..776c4e964f 100644 +--- a/src/lib/crypto/crypto_tests/t_sha2.c ++++ b/src/lib/crypto/crypto_tests/t_sha2.c +@@ -137,7 +137,7 @@ hash_test(const struct krb5_hash_provider *hash, struct test *tests) + } + + int +-main() ++main(void) + { + hash_test(&krb5int_hash_sha256, sha256_tests); + hash_test(&krb5int_hash_sha384, sha384_tests); +diff --git a/src/lib/gssapi/generic/t_seqstate.c b/src/lib/gssapi/generic/t_seqstate.c +index 8f44fcf3ed..4df1ed6b9c 100644 +--- a/src/lib/gssapi/generic/t_seqstate.c ++++ b/src/lib/gssapi/generic/t_seqstate.c +@@ -164,7 +164,7 @@ struct test { + }; + + int +-main() ++main(void) + { + size_t i, j; + enum width w; +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index d7c2ad321e..90a9ad2d9d 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -160,11 +160,8 @@ create_constrained_deleg_creds(OM_uint32 *minor_status, + + /* Decode, decrypt and store the forwarded creds in the local ccache. */ + static krb5_error_code +-rd_and_store_for_creds(context, auth_context, inbuf, out_cred) +- krb5_context context; +- krb5_auth_context auth_context; +- krb5_data *inbuf; +- krb5_gss_cred_id_t *out_cred; ++rd_and_store_for_creds(krb5_context context, krb5_auth_context auth_context, ++ krb5_data *inbuf, krb5_gss_cred_id_t *out_cred) + { + krb5_creds ** creds = NULL; + krb5_error_code retval; +@@ -286,20 +283,12 @@ cleanup: + * Performs third leg of DCE authentication + */ + static OM_uint32 +-kg_accept_dce(minor_status, context_handle, verifier_cred_handle, +- input_token, input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, delegated_cred_handle) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; ++kg_accept_dce(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, gss_name_t *src_name, ++ gss_OID *mech_type, gss_buffer_t output_token, ++ OM_uint32 *ret_flags, OM_uint32 *time_rec, ++ gss_cred_id_t *delegated_cred_handle) + { + krb5_error_code code; + krb5_gss_ctx_id_rec *ctx = 0; +@@ -637,23 +626,13 @@ fail: + } + + static OM_uint32 +-kg_accept_krb5(minor_status, context_handle, +- verifier_cred_handle, input_token, +- input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, +- delegated_cred_handle, exts) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; +- krb5_gss_ctx_ext_t exts; ++kg_accept_krb5(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, gss_cred_id_t *delegated_cred_handle, ++ krb5_gss_ctx_ext_t exts) + { + krb5_context context; + unsigned char *ptr; +@@ -1309,22 +1288,15 @@ krb5_gss_accept_sec_context_ext( + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_accept_sec_context(minor_status, context_handle, +- verifier_cred_handle, input_token, +- input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, +- delegated_cred_handle) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; ++krb5_gss_accept_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, ++ gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, ++ gss_cred_id_t *delegated_cred_handle) + { + krb5_gss_ctx_ext_rec exts; + +diff --git a/src/lib/gssapi/krb5/compare_name.c b/src/lib/gssapi/krb5/compare_name.c +index 3f3788d2bf..3aa5a0d79f 100644 +--- a/src/lib/gssapi/krb5/compare_name.c ++++ b/src/lib/gssapi/krb5/compare_name.c +@@ -28,11 +28,8 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_compare_name(minor_status, name1, name2, name_equal) +- OM_uint32 *minor_status; +- gss_name_t name1; +- gss_name_t name2; +- int *name_equal; ++krb5_gss_compare_name(OM_uint32 *minor_status, gss_name_t name1, ++ gss_name_t name2, int *name_equal) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c +index 226de05f51..0ab885deca 100644 +--- a/src/lib/gssapi/krb5/context_time.c ++++ b/src/lib/gssapi/krb5/context_time.c +@@ -28,10 +28,8 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_context_time(minor_status, context_handle, time_rec) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- OM_uint32 *time_rec; ++krb5_gss_context_time(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ OM_uint32 *time_rec) + { + krb5_error_code code; + krb5_gss_ctx_id_rec *ctx; +diff --git a/src/lib/gssapi/krb5/delete_sec_context.c b/src/lib/gssapi/krb5/delete_sec_context.c +index 4b9dfae0d5..92e84b79c5 100644 +--- a/src/lib/gssapi/krb5/delete_sec_context.c ++++ b/src/lib/gssapi/krb5/delete_sec_context.c +@@ -28,10 +28,9 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_delete_sec_context(minor_status, context_handle, output_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_buffer_t output_token; ++krb5_gss_delete_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_buffer_t output_token) + { + krb5_context context; + krb5_gss_ctx_id_rec *ctx; +diff --git a/src/lib/gssapi/krb5/disp_name.c b/src/lib/gssapi/krb5/disp_name.c +index b097bf0e21..75fef01238 100644 +--- a/src/lib/gssapi/krb5/disp_name.c ++++ b/src/lib/gssapi/krb5/disp_name.c +@@ -24,12 +24,9 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_display_name(minor_status, input_name, output_name_buffer, +- output_name_type) +- OM_uint32 *minor_status; +- gss_name_t input_name; +- gss_buffer_t output_name_buffer; +- gss_OID *output_name_type; ++krb5_gss_display_name(OM_uint32 *minor_status, gss_name_t input_name, ++ gss_buffer_t output_name_buffer, ++ gss_OID *output_name_type) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/disp_status.c b/src/lib/gssapi/krb5/disp_status.c +index 6ff62a9d84..71000b7a45 100644 +--- a/src/lib/gssapi/krb5/disp_status.c ++++ b/src/lib/gssapi/krb5/disp_status.c +@@ -154,14 +154,9 @@ void krb5_gss_delete_error_info(void *p) + /**/ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_display_status(minor_status, status_value, status_type, +- mech_type, message_context, status_string) +- OM_uint32 *minor_status; +- OM_uint32 status_value; +- int status_type; +- gss_OID mech_type; +- OM_uint32 *message_context; +- gss_buffer_t status_string; ++krb5_gss_display_status(OM_uint32 *minor_status, OM_uint32 status_value, ++ int status_type, gss_OID mech_type, ++ OM_uint32 *message_context, gss_buffer_t status_string) + { + status_string->length = 0; + status_string->value = NULL; +diff --git a/src/lib/gssapi/krb5/export_sec_context.c b/src/lib/gssapi/krb5/export_sec_context.c +index 44e50080ab..9730e0597f 100644 +--- a/src/lib/gssapi/krb5/export_sec_context.c ++++ b/src/lib/gssapi/krb5/export_sec_context.c +@@ -27,10 +27,9 @@ + #include "gssapiP_krb5.h" + #ifndef LEAN_CLIENT + OM_uint32 KRB5_CALLCONV +-krb5_gss_export_sec_context(minor_status, context_handle, interprocess_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_buffer_t interprocess_token; ++krb5_gss_export_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_buffer_t interprocess_token) + { + krb5_context context = NULL; + krb5_error_code kret; +diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c +index 1e62b07cde..370b7d152a 100644 +--- a/src/lib/gssapi/krb5/gssapi_krb5.c ++++ b/src/lib/gssapi/krb5/gssapi_krb5.c +@@ -197,9 +197,7 @@ g_set kg_vdb = G_SET_INIT; + * so handling the expiration/invalidation condition here isn't needed. + */ + OM_uint32 +-kg_get_defcred(minor_status, cred) +- OM_uint32 *minor_status; +- gss_cred_id_t *cred; ++kg_get_defcred(OM_uint32 *minor_status, gss_cred_id_t *cred) + { + OM_uint32 major; + +diff --git a/src/lib/gssapi/krb5/import_name.c b/src/lib/gssapi/krb5/import_name.c +index f64635a202..cc6883b5fe 100644 +--- a/src/lib/gssapi/krb5/import_name.c ++++ b/src/lib/gssapi/krb5/import_name.c +@@ -120,12 +120,8 @@ parse_hostbased(const char *str, size_t len, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_import_name(minor_status, input_name_buffer, +- input_name_type, output_name) +- OM_uint32 *minor_status; +- gss_buffer_t input_name_buffer; +- gss_OID input_name_type; +- gss_name_t *output_name; ++krb5_gss_import_name(OM_uint32 *minor_status, gss_buffer_t input_name_buffer, ++ gss_OID input_name_type, gss_name_t *output_name) + { + krb5_context context; + krb5_principal princ = NULL; +diff --git a/src/lib/gssapi/krb5/import_sec_context.c b/src/lib/gssapi/krb5/import_sec_context.c +index 7d26f4df87..e39c036b80 100644 +--- a/src/lib/gssapi/krb5/import_sec_context.c ++++ b/src/lib/gssapi/krb5/import_sec_context.c +@@ -32,8 +32,7 @@ + * Fix up the OID of the mechanism so that uses the static version of + * the OID if possible. + */ +-gss_OID krb5_gss_convert_static_mech_oid(oid) +- gss_OID oid; ++gss_OID krb5_gss_convert_static_mech_oid(gss_OID oid) + { + const gss_OID_desc *p; + OM_uint32 minor_status; +@@ -49,10 +48,9 @@ gss_OID krb5_gss_convert_static_mech_oid(oid) + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_import_sec_context(minor_status, interprocess_token, context_handle) +- OM_uint32 *minor_status; +- gss_buffer_t interprocess_token; +- gss_ctx_id_t *context_handle; ++krb5_gss_import_sec_context(OM_uint32 *minor_status, ++ gss_buffer_t interprocess_token, ++ gss_ctx_id_t *context_handle) + { + krb5_context context; + krb5_error_code kret = 0; +diff --git a/src/lib/gssapi/krb5/indicate_mechs.c b/src/lib/gssapi/krb5/indicate_mechs.c +index 45538cb779..49d55e6217 100644 +--- a/src/lib/gssapi/krb5/indicate_mechs.c ++++ b/src/lib/gssapi/krb5/indicate_mechs.c +@@ -29,9 +29,7 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_indicate_mechs(minor_status, mech_set) +- OM_uint32 *minor_status; +- gss_OID_set *mech_set; ++krb5_gss_indicate_mechs(OM_uint32 *minor_status, gss_OID_set *mech_set) + { + return generic_gss_copy_oid_set(minor_status, kg_all_mechs, mech_set); + } +diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c +index 5748b8434c..0397fe1dfd 100644 +--- a/src/lib/gssapi/krb5/init_sec_context.c ++++ b/src/lib/gssapi/krb5/init_sec_context.c +@@ -117,14 +117,10 @@ int krb5_gss_dbg_client_expcreds = 0; + * Common code which fetches the correct krb5 credentials from the + * ccache. + */ +-static krb5_error_code get_credentials(context, cred, server, now, +- endtime, out_creds) +- krb5_context context; +- krb5_gss_cred_id_t cred; +- krb5_gss_name_t server; +- krb5_timestamp now; +- krb5_timestamp endtime; +- krb5_creds **out_creds; ++static krb5_error_code ++get_credentials(krb5_context context, krb5_gss_cred_id_t cred, ++ krb5_gss_name_t server, krb5_timestamp now, ++ krb5_timestamp endtime, krb5_creds **out_creds) + { + krb5_error_code code; + krb5_creds in_creds, evidence_creds, mcreds, *result_creds = NULL; +@@ -365,17 +361,11 @@ cleanup: + } + + static krb5_error_code +-make_ap_req_v1(context, ctx, cred, k_cred, ad_context, +- chan_bindings, mech_type, token, exts) +- krb5_context context; +- krb5_gss_ctx_id_rec *ctx; +- krb5_gss_cred_id_t cred; +- krb5_creds *k_cred; +- krb5_authdata_context ad_context; +- gss_channel_bindings_t chan_bindings; +- gss_OID mech_type; +- gss_buffer_t token; +- krb5_gss_ctx_ext_t exts; ++make_ap_req_v1(krb5_context context, krb5_gss_ctx_id_rec *ctx, ++ krb5_gss_cred_id_t cred, krb5_creds *k_cred, ++ krb5_authdata_context ad_context, ++ gss_channel_bindings_t chan_bindings, gss_OID mech_type, ++ gss_buffer_t token, krb5_gss_ctx_ext_t exts) + { + krb5_flags mk_req_flags = 0; + krb5_error_code code; +@@ -1048,24 +1038,15 @@ krb5int_gss_use_kdc_context(OM_uint32 *minor_status, + #endif + + OM_uint32 KRB5_CALLCONV +-krb5_gss_init_sec_context(minor_status, claimant_cred_handle, +- context_handle, target_name, mech_type, +- req_flags, time_req, input_chan_bindings, +- input_token, actual_mech_type, output_token, +- ret_flags, time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t claimant_cred_handle; +- gss_ctx_id_t *context_handle; +- gss_name_t target_name; +- gss_OID mech_type; +- OM_uint32 req_flags; +- OM_uint32 time_req; +- gss_channel_bindings_t input_chan_bindings; +- gss_buffer_t input_token; +- gss_OID *actual_mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; ++krb5_gss_init_sec_context(OM_uint32 *minor_status, ++ gss_cred_id_t claimant_cred_handle, ++ gss_ctx_id_t *context_handle, ++ gss_name_t target_name, gss_OID mech_type, ++ OM_uint32 req_flags, OM_uint32 time_req, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_buffer_t input_token, gss_OID *actual_mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec) + { + krb5_gss_ctx_ext_rec exts; + +diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c +index 97678e3ec5..f8229f9750 100644 +--- a/src/lib/gssapi/krb5/inq_context.c ++++ b/src/lib/gssapi/krb5/inq_context.c +@@ -78,18 +78,11 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_context(minor_status, context_handle, initiator_name, +- acceptor_name, lifetime_rec, mech_type, ret_flags, +- locally_initiated, opened) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_name_t *initiator_name; +- gss_name_t *acceptor_name; +- OM_uint32 *lifetime_rec; +- gss_OID *mech_type; +- OM_uint32 *ret_flags; +- int *locally_initiated; +- int *opened; ++krb5_gss_inquire_context(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_name_t *initiator_name, gss_name_t *acceptor_name, ++ OM_uint32 *lifetime_rec, gss_OID *mech_type, ++ OM_uint32 *ret_flags, int *locally_initiated, ++ int *opened) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c +index 0e675959a3..e968f8ad32 100644 +--- a/src/lib/gssapi/krb5/inq_cred.c ++++ b/src/lib/gssapi/krb5/inq_cred.c +@@ -73,14 +73,9 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, +- cred_usage, mechanisms) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_name_t *name; +- OM_uint32 *lifetime_ret; +- gss_cred_usage_t *cred_usage; +- gss_OID_set *mechanisms; ++krb5_gss_inquire_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_name_t *name, OM_uint32 *lifetime_ret, ++ gss_cred_usage_t *cred_usage, gss_OID_set *mechanisms) + { + krb5_context context; + gss_cred_id_t defcred = GSS_C_NO_CREDENTIAL; +@@ -209,16 +204,11 @@ cleanup: + + /* V2 interface */ + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_cred_by_mech(minor_status, cred_handle, +- mech_type, name, initiator_lifetime, +- acceptor_lifetime, cred_usage) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_OID mech_type; +- gss_name_t *name; +- OM_uint32 *initiator_lifetime; +- OM_uint32 *acceptor_lifetime; +- gss_cred_usage_t *cred_usage; ++krb5_gss_inquire_cred_by_mech(OM_uint32 *minor_status, ++ gss_cred_id_t cred_handle, gss_OID mech_type, ++ gss_name_t *name, OM_uint32 *initiator_lifetime, ++ OM_uint32 *acceptor_lifetime, ++ gss_cred_usage_t *cred_usage) + { + krb5_gss_cred_id_t cred; + OM_uint32 lifetime; +diff --git a/src/lib/gssapi/krb5/inq_names.c b/src/lib/gssapi/krb5/inq_names.c +index b326adbb5f..4a3709be4b 100644 +--- a/src/lib/gssapi/krb5/inq_names.c ++++ b/src/lib/gssapi/krb5/inq_names.c +@@ -27,10 +27,8 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_names_for_mech(minor_status, mechanism, name_types) +- OM_uint32 *minor_status; +- gss_OID mechanism; +- gss_OID_set *name_types; ++krb5_gss_inquire_names_for_mech(OM_uint32 *minor_status, gss_OID mechanism, ++ gss_OID_set *name_types) + { + OM_uint32 major, minor; + +diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c +index 0e5d10b115..1148f6929b 100644 +--- a/src/lib/gssapi/krb5/k5seal.c ++++ b/src/lib/gssapi/krb5/k5seal.c +@@ -271,16 +271,10 @@ make_seal_token_v1 (krb5_context context, + and do not encode the ENC_TYPE, MSG_LENGTH, or MSG_TEXT fields */ + + OM_uint32 +-kg_seal(minor_status, context_handle, conf_req_flag, qop_req, +- input_message_buffer, conf_state, output_message_buffer, toktype) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- gss_buffer_t input_message_buffer; +- int *conf_state; +- gss_buffer_t output_message_buffer; +- int toktype; ++kg_seal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_message_buffer, int *conf_state, ++ gss_buffer_t output_message_buffer, int toktype) + { + krb5_gss_ctx_id_rec *ctx; + krb5_error_code code; +@@ -342,16 +336,10 @@ kg_seal(minor_status, context_handle, conf_req_flag, qop_req, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_wrap(minor_status, context_handle, conf_req_flag, +- qop_req, input_message_buffer, conf_state, +- output_message_buffer) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- gss_buffer_t input_message_buffer; +- int *conf_state; +- gss_buffer_t output_message_buffer; ++krb5_gss_wrap(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_message_buffer, int *conf_state, ++ gss_buffer_t output_message_buffer) + { + return(kg_seal(minor_status, context_handle, conf_req_flag, + qop_req, input_message_buffer, conf_state, +@@ -359,13 +347,9 @@ krb5_gss_wrap(minor_status, context_handle, conf_req_flag, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_get_mic(minor_status, context_handle, qop_req, +- message_buffer, message_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_qop_t qop_req; +- gss_buffer_t message_buffer; +- gss_buffer_t message_token; ++krb5_gss_get_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_qop_t qop_req, gss_buffer_t message_buffer, ++ gss_buffer_t message_token) + { + return(kg_seal(minor_status, context_handle, 0, + qop_req, message_buffer, NULL, +diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c +index f0cc4a6809..e246365804 100644 +--- a/src/lib/gssapi/krb5/k5unseal.c ++++ b/src/lib/gssapi/krb5/k5unseal.c +@@ -58,17 +58,10 @@ + conf_state is only valid if SEAL. */ + + static OM_uint32 +-kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, +- conf_state, qop_state, toktype) +- krb5_context context; +- OM_uint32 *minor_status; +- krb5_gss_ctx_id_rec *ctx; +- unsigned char *ptr; +- int bodysize; +- gss_buffer_t message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; +- int toktype; ++kg_unseal_v1(krb5_context context, OM_uint32 *minor_status, ++ krb5_gss_ctx_id_rec *ctx, unsigned char *ptr, int bodysize, ++ gss_buffer_t message_buffer, int *conf_state, ++ gss_qop_t *qop_state, int toktype) + { + krb5_error_code code; + int conflen = 0; +@@ -342,15 +335,9 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + conf_state is only valid if SEAL. */ + + OM_uint32 +-kg_unseal(minor_status, context_handle, input_token_buffer, +- message_buffer, conf_state, qop_state, toktype) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t input_token_buffer; +- gss_buffer_t message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; +- int toktype; ++kg_unseal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_token_buffer, gss_buffer_t message_buffer, ++ int *conf_state, gss_qop_t *qop_state, int toktype) + { + krb5_gss_ctx_id_rec *ctx; + unsigned char *ptr; +@@ -421,15 +408,10 @@ kg_unseal(minor_status, context_handle, input_token_buffer, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_unwrap(minor_status, context_handle, +- input_message_buffer, output_message_buffer, +- conf_state, qop_state) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t input_message_buffer; +- gss_buffer_t output_message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; ++krb5_gss_unwrap(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, int *conf_state, ++ gss_qop_t *qop_state) + { + OM_uint32 rstat; + +@@ -440,14 +422,9 @@ krb5_gss_unwrap(minor_status, context_handle, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_verify_mic(minor_status, context_handle, +- message_buffer, token_buffer, +- qop_state) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t message_buffer; +- gss_buffer_t token_buffer; +- gss_qop_t *qop_state; ++krb5_gss_verify_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ gss_qop_t *qop_state) + { + OM_uint32 rstat; + +diff --git a/src/lib/gssapi/krb5/process_context_token.c b/src/lib/gssapi/krb5/process_context_token.c +index a672f48c85..67805fba78 100644 +--- a/src/lib/gssapi/krb5/process_context_token.c ++++ b/src/lib/gssapi/krb5/process_context_token.c +@@ -28,11 +28,9 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_process_context_token(minor_status, context_handle, +- token_buffer) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t token_buffer; ++krb5_gss_process_context_token(OM_uint32 *minor_status, ++ gss_ctx_id_t context_handle, ++ gss_buffer_t token_buffer) + { + krb5_gss_ctx_id_rec *ctx; + OM_uint32 majerr; +diff --git a/src/lib/gssapi/krb5/rel_cred.c b/src/lib/gssapi/krb5/rel_cred.c +index 0da6c1b950..9e04e2fa81 100644 +--- a/src/lib/gssapi/krb5/rel_cred.c ++++ b/src/lib/gssapi/krb5/rel_cred.c +@@ -24,9 +24,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_release_cred(minor_status, cred_handle) +- OM_uint32 *minor_status; +- gss_cred_id_t *cred_handle; ++krb5_gss_release_cred(OM_uint32 *minor_status, gss_cred_id_t *cred_handle) + { + krb5_context context; + krb5_gss_cred_id_t cred; +diff --git a/src/lib/gssapi/krb5/rel_name.c b/src/lib/gssapi/krb5/rel_name.c +index 3dabe32f33..558bb6dbc5 100644 +--- a/src/lib/gssapi/krb5/rel_name.c ++++ b/src/lib/gssapi/krb5/rel_name.c +@@ -24,9 +24,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_release_name(minor_status, input_name) +- OM_uint32 *minor_status; +- gss_name_t *input_name; ++krb5_gss_release_name(OM_uint32 *minor_status, gss_name_t *input_name) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/rel_oid.c b/src/lib/gssapi/krb5/rel_oid.c +index 739efe4680..900c4105f9 100644 +--- a/src/lib/gssapi/krb5/rel_oid.c ++++ b/src/lib/gssapi/krb5/rel_oid.c +@@ -27,9 +27,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 +-krb5_gss_release_oid(minor_status, oid) +- OM_uint32 *minor_status; +- gss_OID *oid; ++krb5_gss_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + /* + * The V2 API says the following! +@@ -52,9 +50,7 @@ krb5_gss_release_oid(minor_status, oid) + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_internal_release_oid(minor_status, oid) +- OM_uint32 *minor_status; +- gss_OID *oid; ++krb5_gss_internal_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + /* + * This function only knows how to release internal OIDs. It will +diff --git a/src/lib/gssapi/krb5/ser_sctx.c b/src/lib/gssapi/krb5/ser_sctx.c +index 9e2d32e98d..1129b6a1aa 100644 +--- a/src/lib/gssapi/krb5/ser_sctx.c ++++ b/src/lib/gssapi/krb5/ser_sctx.c +@@ -137,10 +137,8 @@ kg_oid_size(gss_OID oid, size_t *sizep) + } + + static krb5_error_code +-kg_seqstate_externalize(arg, buffer, lenremain) +- g_seqnum_state arg; +- krb5_octet **buffer; +- size_t *lenremain; ++kg_seqstate_externalize(g_seqnum_state arg, krb5_octet **buffer, ++ size_t *lenremain) + { + krb5_error_code err; + err = krb5_ser_pack_int32(KV5M_GSS_QUEUE, buffer, lenremain); +@@ -152,10 +150,8 @@ kg_seqstate_externalize(arg, buffer, lenremain) + } + + static krb5_error_code +-kg_seqstate_internalize(argp, buffer, lenremain) +- g_seqnum_state *argp; +- krb5_octet **buffer; +- size_t *lenremain; ++kg_seqstate_internalize(g_seqnum_state *argp, krb5_octet **buffer, ++ size_t *lenremain) + { + krb5_int32 ibuf; + krb5_octet *bp; +@@ -193,9 +189,7 @@ kg_seqstate_internalize(argp, buffer, lenremain) + } + + static krb5_error_code +-kg_seqstate_size(arg, sizep) +- g_seqnum_state arg; +- size_t *sizep; ++kg_seqstate_size(g_seqnum_state arg, size_t *sizep) + { + krb5_error_code kret; + size_t required; +diff --git a/src/lib/gssapi/krb5/util_cksum.c b/src/lib/gssapi/krb5/util_cksum.c +index 5b87956393..5f7694f5e6 100644 +--- a/src/lib/gssapi/krb5/util_cksum.c ++++ b/src/lib/gssapi/krb5/util_cksum.c +@@ -28,10 +28,8 @@ + + /* Checksumming the channel bindings always uses plain MD5. */ + krb5_error_code +-kg_checksum_channel_bindings(context, cb, cksum) +- krb5_context context; +- gss_channel_bindings_t cb; +- krb5_checksum *cksum; ++kg_checksum_channel_bindings(krb5_context context, gss_channel_bindings_t cb, ++ krb5_checksum *cksum) + { + struct k5buf buf; + size_t sumlen; +diff --git a/src/lib/gssapi/krb5/util_seed.c b/src/lib/gssapi/krb5/util_seed.c +index 6e1c9ac8ae..685736314c 100644 +--- a/src/lib/gssapi/krb5/util_seed.c ++++ b/src/lib/gssapi/krb5/util_seed.c +@@ -29,10 +29,7 @@ + static const unsigned char zeros[16] = {0,0,0,0, 0,0,0,0, 0,0,0,0, 0,0,0,0}; + + krb5_error_code +-kg_make_seed(context, key, seed) +- krb5_context context; +- krb5_key key; +- unsigned char *seed; ++kg_make_seed(krb5_context context, krb5_key key, unsigned char *seed) + { + krb5_error_code code; + krb5_key rkey = NULL; +diff --git a/src/lib/gssapi/krb5/util_seqnum.c b/src/lib/gssapi/krb5/util_seqnum.c +index bef631da9d..a5a4d5cf80 100644 +--- a/src/lib/gssapi/krb5/util_seqnum.c ++++ b/src/lib/gssapi/krb5/util_seqnum.c +@@ -30,13 +30,8 @@ + */ + + krb5_error_code +-kg_make_seq_num(context, key, direction, seqnum, cksum, buf) +- krb5_context context; +- krb5_key key; +- int direction; +- krb5_ui_4 seqnum; +- unsigned char *cksum; +- unsigned char *buf; ++kg_make_seq_num(krb5_context context, krb5_key key, int direction, ++ krb5_ui_4 seqnum, unsigned char *cksum, unsigned char *buf) + { + unsigned char plain[8]; + +@@ -59,13 +54,9 @@ kg_make_seq_num(context, key, direction, seqnum, cksum, buf) + return(kg_encrypt(context, key, KG_USAGE_SEQ, cksum, plain, buf, 8)); + } + +-krb5_error_code kg_get_seq_num(context, key, cksum, buf, direction, seqnum) +- krb5_context context; +- krb5_key key; +- unsigned char *cksum; +- unsigned char *buf; +- int *direction; +- krb5_ui_4 *seqnum; ++krb5_error_code ++kg_get_seq_num(krb5_context context, krb5_key key, unsigned char *cksum, ++ unsigned char *buf, int *direction, krb5_ui_4 *seqnum) + { + krb5_error_code code; + unsigned char plain[8]; +diff --git a/src/lib/gssapi/krb5/val_cred.c b/src/lib/gssapi/krb5/val_cred.c +index cb1cb9393a..83e7634106 100644 +--- a/src/lib/gssapi/krb5/val_cred.c ++++ b/src/lib/gssapi/krb5/val_cred.c +@@ -57,9 +57,7 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + } + + OM_uint32 +-krb5_gss_validate_cred(minor_status, cred_handle) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; ++krb5_gss_validate_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/wrap_size_limit.c b/src/lib/gssapi/krb5/wrap_size_limit.c +index 7959f424ec..8ea6ce1ad3 100644 +--- a/src/lib/gssapi/krb5/wrap_size_limit.c ++++ b/src/lib/gssapi/krb5/wrap_size_limit.c +@@ -74,14 +74,9 @@ + + /* V2 interface */ + OM_uint32 KRB5_CALLCONV +-krb5_gss_wrap_size_limit(minor_status, context_handle, conf_req_flag, +- qop_req, req_output_size, max_input_size) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- OM_uint32 req_output_size; +- OM_uint32 *max_input_size; ++krb5_gss_wrap_size_limit(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ OM_uint32 req_output_size, OM_uint32 *max_input_size) + { + krb5_gss_ctx_id_rec *ctx; + OM_uint32 data_size, conflen; +diff --git a/src/lib/gssapi/mechglue/g_accept_sec_context.c b/src/lib/gssapi/mechglue/g_accept_sec_context.c +index 4f2a66e26a..e4eff1f52c 100644 +--- a/src/lib/gssapi/mechglue/g_accept_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_accept_sec_context.c +@@ -128,30 +128,13 @@ allow_mech_by_default(gss_OID mech) + } + + OM_uint32 KRB5_CALLCONV +-gss_accept_sec_context (minor_status, +- context_handle, +- verifier_cred_handle, +- input_token_buffer, +- input_chan_bindings, +- src_name, +- mech_type, +- output_token, +- ret_flags, +- time_rec, +- d_cred) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_cred_id_t verifier_cred_handle; +-gss_buffer_t input_token_buffer; +-gss_channel_bindings_t input_chan_bindings; +-gss_name_t * src_name; +-gss_OID * mech_type; +-gss_buffer_t output_token; +-OM_uint32 * ret_flags; +-OM_uint32 * time_rec; +-gss_cred_id_t * d_cred; +- ++gss_accept_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, ++ gss_buffer_t input_token_buffer, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, gss_cred_id_t *d_cred) + { + OM_uint32 status, temp_status, temp_minor_status; + OM_uint32 temp_ret_flags = 0; +diff --git a/src/lib/gssapi/mechglue/g_acquire_cred.c b/src/lib/gssapi/mechglue/g_acquire_cred.c +index c885f56279..2fc9c5c786 100644 +--- a/src/lib/gssapi/mechglue/g_acquire_cred.c ++++ b/src/lib/gssapi/mechglue/g_acquire_cred.c +@@ -85,24 +85,10 @@ val_acq_cred_args( + + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred(minor_status, +- desired_name, +- time_req, +- desired_mechs, +- cred_usage, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_name_t desired_name; +-OM_uint32 time_req; +-gss_OID_set desired_mechs; +-int cred_usage; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; +- ++gss_acquire_cred(OM_uint32 *minor_status, gss_name_t desired_name, ++ OM_uint32 time_req, gss_OID_set desired_mechs, ++ int cred_usage, gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + return gss_acquire_cred_from(minor_status, desired_name, time_req, + desired_mechs, cred_usage, NULL, +@@ -110,26 +96,11 @@ OM_uint32 * time_rec; + } + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred_from(minor_status, +- desired_name, +- time_req, +- desired_mechs, +- cred_usage, +- cred_store, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_name_t desired_name; +-OM_uint32 time_req; +-gss_OID_set desired_mechs; +-int cred_usage; +-gss_const_key_value_set_t cred_store; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; +- ++gss_acquire_cred_from(OM_uint32 * minor_status, gss_name_t desired_name, ++ OM_uint32 time_req, gss_OID_set desired_mechs, ++ int cred_usage, gss_const_key_value_set_t cred_store, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + OM_uint32 major = GSS_S_FAILURE, tmpMinor; + OM_uint32 first_major = GSS_S_COMPLETE, first_minor = 0; +@@ -397,22 +368,12 @@ error: + + /* V2 KRB5_CALLCONV */ + OM_uint32 KRB5_CALLCONV +-gss_add_cred(minor_status, input_cred_handle, +- desired_name, desired_mech, cred_usage, +- initiator_time_req, acceptor_time_req, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t input_cred_handle; +- gss_name_t desired_name; +- gss_OID desired_mech; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_name_t desired_name, gss_OID desired_mech, ++ gss_cred_usage_t cred_usage, OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *initiator_time_rec, ++ OM_uint32 *acceptor_time_rec) + { + return gss_add_cred_from(minor_status, input_cred_handle, desired_name, + desired_mech, cred_usage, initiator_time_req, +@@ -422,25 +383,13 @@ gss_add_cred(minor_status, input_cred_handle, + } + + OM_uint32 KRB5_CALLCONV +-gss_add_cred_from(minor_status, input_cred_handle, +- desired_name, desired_mech, +- cred_usage, +- initiator_time_req, acceptor_time_req, +- cred_store, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t input_cred_handle; +- gss_name_t desired_name; +- gss_OID desired_mech; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_const_key_value_set_t cred_store; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred_from(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_name_t desired_name, gss_OID desired_mech, ++ gss_cred_usage_t cred_usage, OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, ++ gss_const_key_value_set_t cred_store, ++ gss_cred_id_t *output_cred_handle, gss_OID_set *actual_mechs, ++ OM_uint32 *initiator_time_rec, OM_uint32 *acceptor_time_rec) + { + OM_uint32 status, temp_minor_status; + OM_uint32 time_req, time_rec = 0, *time_recp = NULL; +diff --git a/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c b/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c +index cc34acc2bf..86abf984dc 100644 +--- a/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c ++++ b/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c +@@ -98,26 +98,12 @@ val_acq_cred_pw_args( + + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred_with_password( +- minor_status, +- desired_name, +- password, +- time_req, +- desired_mechs, +- cred_usage, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-const gss_name_t desired_name; +-const gss_buffer_t password; +-OM_uint32 time_req; +-const gss_OID_set desired_mechs; +-int cred_usage; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; ++gss_acquire_cred_with_password(OM_uint32 *minor_status, ++ const gss_name_t desired_name, ++ const gss_buffer_t password, OM_uint32 time_req, ++ const gss_OID_set desired_mechs, int cred_usage, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + OM_uint32 major = GSS_S_FAILURE; + OM_uint32 initTimeOut, acceptTimeOut, outTime = GSS_C_INDEFINITE; +@@ -306,23 +292,19 @@ val_add_cred_pw_args( + + /* V2 KRB5_CALLCONV */ + OM_uint32 KRB5_CALLCONV +-gss_add_cred_with_password(minor_status, input_cred_handle, +- desired_name, desired_mech, password, cred_usage, +- initiator_time_req, acceptor_time_req, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- const gss_cred_id_t input_cred_handle; +- const gss_name_t desired_name; +- const gss_OID desired_mech; +- const gss_buffer_t password; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred_with_password( ++ OM_uint32 *minor_status, ++ const gss_cred_id_t input_cred_handle, ++ const gss_name_t desired_name, ++ const gss_OID desired_mech, ++ const gss_buffer_t password, ++ gss_cred_usage_t cred_usage, ++ OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, ++ OM_uint32 *initiator_time_rec, ++ OM_uint32 *acceptor_time_rec) + { + OM_uint32 status, temp_minor_status; + OM_uint32 time_req, time_rec; +diff --git a/src/lib/gssapi/mechglue/g_canon_name.c b/src/lib/gssapi/mechglue/g_canon_name.c +index 61f657f91f..c5214db80a 100644 +--- a/src/lib/gssapi/mechglue/g_canon_name.c ++++ b/src/lib/gssapi/mechglue/g_canon_name.c +@@ -54,14 +54,8 @@ val_canon_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_canonicalize_name(minor_status, +- input_name, +- mech_type, +- output_name) +-OM_uint32 *minor_status; +-const gss_name_t input_name; +-const gss_OID mech_type; +-gss_name_t *output_name; ++gss_canonicalize_name(OM_uint32 *minor_status, const gss_name_t input_name, ++ const gss_OID mech_type, gss_name_t *output_name) + { + gss_union_name_t in_union, out_union = NULL, dest_union = NULL; + OM_uint32 major_status = GSS_S_FAILURE, tmpmin; +diff --git a/src/lib/gssapi/mechglue/g_compare_name.c b/src/lib/gssapi/mechglue/g_compare_name.c +index af2e76bbda..74a9529a35 100644 +--- a/src/lib/gssapi/mechglue/g_compare_name.c ++++ b/src/lib/gssapi/mechglue/g_compare_name.c +@@ -59,16 +59,8 @@ val_comp_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_compare_name (minor_status, +- name1, +- name2, +- name_equal) +- +-OM_uint32 * minor_status; +-gss_name_t name1; +-gss_name_t name2; +-int * name_equal; +- ++gss_compare_name(OM_uint32 * minor_status, gss_name_t name1, gss_name_t name2, ++ int * name_equal) + { + OM_uint32 major_status, temp_minor; + gss_union_name_t union_name1, union_name2; +diff --git a/src/lib/gssapi/mechglue/g_context_time.c b/src/lib/gssapi/mechglue/g_context_time.c +index c947e7646c..b11b32d6bb 100644 +--- a/src/lib/gssapi/mechglue/g_context_time.c ++++ b/src/lib/gssapi/mechglue/g_context_time.c +@@ -29,14 +29,8 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_context_time (minor_status, +- context_handle, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-OM_uint32 * time_rec; +- ++gss_context_time(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ OM_uint32 * time_rec) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_delete_sec_context.c b/src/lib/gssapi/mechglue/g_delete_sec_context.c +index 574ff02944..dc86cce3d3 100644 +--- a/src/lib/gssapi/mechglue/g_delete_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_delete_sec_context.c +@@ -62,14 +62,8 @@ val_del_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_delete_sec_context (minor_status, +- context_handle, +- output_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_buffer_t output_token; +- ++gss_delete_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_buffer_t output_token) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_dsp_name.c b/src/lib/gssapi/mechglue/g_dsp_name.c +index 21867c814e..fae64f712e 100644 +--- a/src/lib/gssapi/mechglue/g_dsp_name.c ++++ b/src/lib/gssapi/mechglue/g_dsp_name.c +@@ -70,16 +70,8 @@ val_dsp_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_display_name (minor_status, +- input_name, +- output_name_buffer, +- output_name_type) +- +-OM_uint32 * minor_status; +-gss_name_t input_name; +-gss_buffer_t output_name_buffer; +-gss_OID * output_name_type; +- ++gss_display_name(OM_uint32 *minor_status, gss_name_t input_name, ++ gss_buffer_t output_name_buffer, gss_OID *output_name_type) + { + OM_uint32 major_status; + gss_union_name_t union_name; +diff --git a/src/lib/gssapi/mechglue/g_dsp_status.c b/src/lib/gssapi/mechglue/g_dsp_status.c +index 70e8492636..14a7a8200c 100644 +--- a/src/lib/gssapi/mechglue/g_dsp_status.c ++++ b/src/lib/gssapi/mechglue/g_dsp_status.c +@@ -36,20 +36,9 @@ + static OM_uint32 displayMajor(OM_uint32, OM_uint32 *, gss_buffer_t); + + OM_uint32 KRB5_CALLCONV +-gss_display_status (minor_status, +- status_value, +- status_type, +- req_mech_type, +- message_context, +- status_string) +- +-OM_uint32 * minor_status; +-OM_uint32 status_value; +-int status_type; +-gss_OID req_mech_type; +-OM_uint32 * message_context; +-gss_buffer_t status_string; +- ++gss_display_status(OM_uint32 *minor_status, OM_uint32 status_value, ++ int status_type, gss_OID req_mech_type, ++ OM_uint32 *message_context, gss_buffer_t status_string) + { + gss_OID mech_type = (gss_OID) req_mech_type; + gss_mechanism mech; +@@ -147,10 +136,7 @@ gss_buffer_t status_string; + * >= 2 - the supplementary error code bit shifted by 1 + */ + static OM_uint32 +-displayMajor(status, msgCtxt, outStr) +-OM_uint32 status; +-OM_uint32 *msgCtxt; +-gss_buffer_t outStr; ++displayMajor(OM_uint32 status, OM_uint32 *msgCtxt, gss_buffer_t outStr) + { + OM_uint32 oneVal, mask = 0x1, currErr; + char *errStr = NULL; +diff --git a/src/lib/gssapi/mechglue/g_dup_name.c b/src/lib/gssapi/mechglue/g_dup_name.c +index ff01db27dc..bf6eb602ea 100644 +--- a/src/lib/gssapi/mechglue/g_dup_name.c ++++ b/src/lib/gssapi/mechglue/g_dup_name.c +@@ -51,12 +51,8 @@ val_dup_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_duplicate_name(minor_status, +- src_name, +- dest_name) +-OM_uint32 *minor_status; +-const gss_name_t src_name; +-gss_name_t *dest_name; ++gss_duplicate_name(OM_uint32 *minor_status, const gss_name_t src_name, ++ gss_name_t *dest_name) + { + gss_union_name_t src_union, dest_union; + OM_uint32 major_status = GSS_S_FAILURE; +diff --git a/src/lib/gssapi/mechglue/g_exp_sec_context.c b/src/lib/gssapi/mechglue/g_exp_sec_context.c +index a04afe3d1e..68a3267cf0 100644 +--- a/src/lib/gssapi/mechglue/g_exp_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_exp_sec_context.c +@@ -68,14 +68,8 @@ val_exp_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_export_sec_context(minor_status, +- context_handle, +- interprocess_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_buffer_t interprocess_token; +- ++gss_export_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_buffer_t interprocess_token) + { + OM_uint32 status; + OM_uint32 length; +diff --git a/src/lib/gssapi/mechglue/g_export_name.c b/src/lib/gssapi/mechglue/g_export_name.c +index c845f8caf7..2e0611d2d5 100644 +--- a/src/lib/gssapi/mechglue/g_export_name.c ++++ b/src/lib/gssapi/mechglue/g_export_name.c +@@ -20,12 +20,8 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_export_name(minor_status, +- input_name, +- exported_name) +-OM_uint32 * minor_status; +-const gss_name_t input_name; +-gss_buffer_t exported_name; ++gss_export_name(OM_uint32 *minor_status, const gss_name_t input_name, ++ gss_buffer_t exported_name) + { + gss_union_name_t union_name; + +diff --git a/src/lib/gssapi/mechglue/g_glue.c b/src/lib/gssapi/mechglue/g_glue.c +index 176fbe63eb..47f499307a 100644 +--- a/src/lib/gssapi/mechglue/g_glue.c ++++ b/src/lib/gssapi/mechglue/g_glue.c +@@ -75,9 +75,8 @@ static gss_OID_desc gss_krb5_mechanism_oid_desc = + + #define NTLMSSP_SIGNATURE "NTLMSSP" + +-OM_uint32 gssint_get_mech_type(OID, token) +- gss_OID OID; +- gss_buffer_t token; ++OM_uint32 ++gssint_get_mech_type(gss_OID OID, gss_buffer_t token) + { + /* Check for interoperability exceptions */ + if (token->length >= sizeof(NTLMSSP_SIGNATURE) && +@@ -163,12 +162,10 @@ import_internal_attributes(OM_uint32 *minor, + * Internal routines to get and release an internal mechanism name + */ + +-OM_uint32 gssint_import_internal_name (minor_status, mech_type, union_name, +- internal_name) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_union_name_t union_name; +-gss_name_t *internal_name; ++OM_uint32 ++gssint_import_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_union_name_t union_name, ++ gss_name_t *internal_name) + { + OM_uint32 status, tmpMinor; + gss_mechanism mech; +@@ -220,12 +217,10 @@ gss_name_t *internal_name; + return (status); + } + +-OM_uint32 gssint_export_internal_name(minor_status, mech_type, +- internal_name, name_buf) +- OM_uint32 *minor_status; +- const gss_OID mech_type; +- const gss_name_t internal_name; +- gss_buffer_t name_buf; ++OM_uint32 ++gssint_export_internal_name(OM_uint32 *minor_status, const gss_OID mech_type, ++ const gss_name_t internal_name, ++ gss_buffer_t name_buf) + { + OM_uint32 status; + gss_mechanism mech; +@@ -307,13 +302,10 @@ OM_uint32 gssint_export_internal_name(minor_status, mech_type, + return (GSS_S_COMPLETE); + } /* gssint_export_internal_name */ + +-OM_uint32 gssint_display_internal_name (minor_status, mech_type, internal_name, +- external_name, name_type) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_name_t internal_name; +-gss_buffer_t external_name; +-gss_OID *name_type; ++OM_uint32 ++gssint_display_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_name_t internal_name, ++ gss_buffer_t external_name, gss_OID *name_type) + { + OM_uint32 status; + gss_mechanism mech; +@@ -337,10 +329,9 @@ gss_OID *name_type; + return (GSS_S_BAD_MECH); + } + +-OM_uint32 gssint_release_internal_name (minor_status, mech_type, internal_name) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_name_t *internal_name; ++OM_uint32 ++gssint_release_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_name_t *internal_name) + { + OM_uint32 status; + gss_mechanism mech; +@@ -362,14 +353,10 @@ gss_name_t *internal_name; + return (GSS_S_BAD_MECH); + } + +-OM_uint32 gssint_delete_internal_sec_context (minor_status, +- mech_type, +- internal_ctx, +- output_token) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_ctx_id_t *internal_ctx; +-gss_buffer_t output_token; ++OM_uint32 ++gssint_delete_internal_sec_context(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_ctx_id_t *internal_ctx, ++ gss_buffer_t output_token) + { + OM_uint32 status; + gss_mechanism mech; +@@ -394,12 +381,10 @@ gss_buffer_t output_token; + * name. Note that internal_name should be considered "consumed" by + * this call, whether or not we return an error. + */ +-OM_uint32 gssint_convert_name_to_union_name(minor_status, mech, +- internal_name, external_name) +- OM_uint32 *minor_status; +- gss_mechanism mech; +- gss_name_t internal_name; +- gss_name_t *external_name; ++OM_uint32 ++gssint_convert_name_to_union_name(OM_uint32 *minor_status, gss_mechanism mech, ++ gss_name_t internal_name, ++ gss_name_t *external_name) + { + OM_uint32 major_status,tmp; + gss_union_name_t union_name; +@@ -473,9 +458,7 @@ allocation_failure: + * external union credential. + */ + gss_cred_id_t +-gssint_get_mechanism_cred(union_cred, mech_type) +- gss_union_cred_t union_cred; +- gss_OID mech_type; ++gssint_get_mechanism_cred(gss_union_cred_t union_cred, gss_OID mech_type) + { + int i; + +@@ -494,10 +477,8 @@ gssint_get_mechanism_cred(union_cred, mech_type) + * Both space for the structure and the data is allocated. + */ + OM_uint32 +-gssint_create_copy_buffer(srcBuf, destBuf, addNullChar) +- const gss_buffer_t srcBuf; +- gss_buffer_t *destBuf; +- int addNullChar; ++gssint_create_copy_buffer(const gss_buffer_t srcBuf, gss_buffer_t *destBuf, ++ int addNullChar) + { + gss_buffer_t aBuf; + unsigned int len; +diff --git a/src/lib/gssapi/mechglue/g_imp_name.c b/src/lib/gssapi/mechglue/g_imp_name.c +index a805078a81..65fa6c0fb3 100644 +--- a/src/lib/gssapi/mechglue/g_imp_name.c ++++ b/src/lib/gssapi/mechglue/g_imp_name.c +@@ -81,16 +81,8 @@ val_imp_name_args( + static gss_buffer_desc emptyNameBuffer; + + OM_uint32 KRB5_CALLCONV +-gss_import_name(minor_status, +- input_name_buffer, +- input_name_type, +- output_name) +- +-OM_uint32 * minor_status; +-gss_buffer_t input_name_buffer; +-gss_OID input_name_type; +-gss_name_t * output_name; +- ++gss_import_name(OM_uint32 * minor_status, gss_buffer_t input_name_buffer, ++ gss_OID input_name_type, gss_name_t * output_name) + { + gss_union_name_t union_name; + OM_uint32 tmp, major_status = GSS_S_FAILURE; +@@ -183,10 +175,8 @@ allocation_failure: + } + + static OM_uint32 +-importExportName(minor, unionName, inputNameType) +- OM_uint32 *minor; +- gss_union_name_t unionName; +- gss_OID inputNameType; ++importExportName(OM_uint32 *minor, gss_union_name_t unionName, ++ gss_OID inputNameType) + { + gss_OID_desc mechOid; + gss_buffer_desc expName; +diff --git a/src/lib/gssapi/mechglue/g_imp_sec_context.c b/src/lib/gssapi/mechglue/g_imp_sec_context.c +index 6315201a5f..55a3136df1 100644 +--- a/src/lib/gssapi/mechglue/g_imp_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_imp_sec_context.c +@@ -69,14 +69,9 @@ val_imp_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_import_sec_context(minor_status, +- interprocess_token, +- context_handle) +- +-OM_uint32 * minor_status; +-gss_buffer_t interprocess_token; +-gss_ctx_id_t * context_handle; +- ++gss_import_sec_context(OM_uint32 *minor_status, ++ gss_buffer_t interprocess_token, ++ gss_ctx_id_t *context_handle) + { + OM_uint32 length = 0; + OM_uint32 status; +diff --git a/src/lib/gssapi/mechglue/g_init_sec_context.c b/src/lib/gssapi/mechglue/g_init_sec_context.c +index a58074c007..d639a8de3b 100644 +--- a/src/lib/gssapi/mechglue/g_init_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_init_sec_context.c +@@ -88,34 +88,15 @@ val_init_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_init_sec_context (minor_status, +- claimant_cred_handle, +- context_handle, +- target_name, +- req_mech_type, +- req_flags, +- time_req, +- input_chan_bindings, +- input_token, +- actual_mech_type, +- output_token, +- ret_flags, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_cred_id_t claimant_cred_handle; +-gss_ctx_id_t * context_handle; +-gss_name_t target_name; +-gss_OID req_mech_type; +-OM_uint32 req_flags; +-OM_uint32 time_req; +-gss_channel_bindings_t input_chan_bindings; +-gss_buffer_t input_token; +-gss_OID * actual_mech_type; +-gss_buffer_t output_token; +-OM_uint32 * ret_flags; +-OM_uint32 * time_rec; +- ++gss_init_sec_context(OM_uint32 *minor_status, ++ gss_cred_id_t claimant_cred_handle, ++ gss_ctx_id_t *context_handle, gss_name_t target_name, ++ gss_OID req_mech_type, OM_uint32 req_flags, ++ OM_uint32 time_req, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_buffer_t input_token, gss_OID *actual_mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec) + { + OM_uint32 status, temp_minor_status; + gss_union_name_t union_name; +diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c +index 22f6c615c1..7e36c4a0d0 100644 +--- a/src/lib/gssapi/mechglue/g_initialize.c ++++ b/src/lib/gssapi/mechglue/g_initialize.c +@@ -169,9 +169,7 @@ gssint_mechglue_initialize_library(void) + * This routine requires direct access to the mechList. + */ + OM_uint32 KRB5_CALLCONV +-gss_release_oid(minor_status, oid) +-OM_uint32 *minor_status; +-gss_OID *oid; ++gss_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + OM_uint32 major; + gss_mech_info aMech; +@@ -267,9 +265,7 @@ prune_deprecated(gss_OID_set mech_set) + * a mech oid set, and only update it once the file has changed. + */ + OM_uint32 KRB5_CALLCONV +-gss_indicate_mechs(minorStatus, mechSet_out) +-OM_uint32 *minorStatus; +-gss_OID_set *mechSet_out; ++gss_indicate_mechs(OM_uint32 *minorStatus, gss_OID_set *mechSet_out) + { + OM_uint32 status; + +@@ -417,8 +413,7 @@ build_mechSet(void) + * caller is responsible for freeing the memory + */ + char * +-gssint_get_modOptions(oid) +-const gss_OID oid; ++gssint_get_modOptions(const gss_OID oid) + { + gss_mech_info aMech; + char *modOptions = NULL; +@@ -479,7 +474,7 @@ load_if_changed(const char *pathname, time_t last, time_t *highest) + /* Try to load any config files which have changed since the last call. Config + * files are MECH_CONF and any files matching MECH_CONF_PATTERN. */ + static void +-loadConfigFiles() ++loadConfigFiles(void) + { + glob_t globbuf; + time_t highest = (time_t)-1, now; +@@ -679,7 +674,8 @@ gssint_register_mechinfo(gss_mech_info template) + memset(&errinfo, 0, sizeof(errinfo)); \ + if (krb5int_get_plugin_func(_dl, \ + #_symbol, \ +- (void (**)())&(_mech)->_symbol, \ ++ (void (**)(void)) \ ++ &(_mech)->_symbol, \ + &errinfo) || errinfo.code) { \ + (_mech)->_symbol = NULL; \ + k5_clear_error(&errinfo); \ +@@ -801,7 +797,7 @@ build_dynamicMech(void *dl, const gss_OID mech_type) + memset(&errinfo, 0, sizeof(errinfo)); \ + if (krb5int_get_plugin_func(_dl, \ + "gssi" #_nsym, \ +- (void (**)())&(_mech)->_psym \ ++ (void (**)(void))&(_mech)->_psym \ + ## _nsym, \ + &errinfo) || errinfo.code) { \ + (_mech)->_psym ## _nsym = NULL; \ +@@ -948,7 +944,7 @@ loadInterMech(gss_mech_info minfo) + } + + if (krb5int_get_plugin_func(dl, MECH_INTERPOSER_SYM, +- (void (**)())&isym, &errinfo) != 0) ++ (void (**)(void))&isym, &errinfo) != 0) + goto cleanup; + + /* Get a list of mechs to interpose. */ +@@ -1184,7 +1180,7 @@ gssint_get_mechanism(gss_const_OID oid) + return ((gss_mechanism)NULL); + } + +- if (krb5int_get_plugin_func(dl, MECH_SYM, (void (**)())&sym, ++ if (krb5int_get_plugin_func(dl, MECH_SYM, (void (**)(void))&sym, + &errinfo) == 0) { + /* Call the symbol to get the mechanism table */ + aMech->mech = (*sym)(aMech->mech_type); +diff --git a/src/lib/gssapi/mechglue/g_inq_cred.c b/src/lib/gssapi/mechglue/g_inq_cred.c +index 4ed7774f1a..0aa9acc889 100644 +--- a/src/lib/gssapi/mechglue/g_inq_cred.c ++++ b/src/lib/gssapi/mechglue/g_inq_cred.c +@@ -35,20 +35,9 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_inquire_cred(minor_status, +- cred_handle, +- name, +- lifetime, +- cred_usage, +- mechanisms) +- +-OM_uint32 * minor_status; +-gss_cred_id_t cred_handle; +-gss_name_t * name; +-OM_uint32 * lifetime; +-int * cred_usage; +-gss_OID_set * mechanisms; +- ++gss_inquire_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_name_t *name, OM_uint32 *lifetime, int *cred_usage, ++ gss_OID_set *mechanisms) + { + OM_uint32 status, temp_minor_status; + gss_union_cred_t union_cred; +@@ -159,15 +148,11 @@ error: + } + + OM_uint32 KRB5_CALLCONV +-gss_inquire_cred_by_mech(minor_status, cred_handle, mech_type, name, +- initiator_lifetime, acceptor_lifetime, cred_usage) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_OID mech_type; +- gss_name_t *name; +- OM_uint32 *initiator_lifetime; +- OM_uint32 *acceptor_lifetime; +- gss_cred_usage_t *cred_usage; ++gss_inquire_cred_by_mech(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_OID mech_type, gss_name_t *name, ++ OM_uint32 *initiator_lifetime, ++ OM_uint32 *acceptor_lifetime, ++ gss_cred_usage_t *cred_usage) + { + gss_union_cred_t union_cred; + gss_cred_id_t mech_cred; +diff --git a/src/lib/gssapi/mechglue/g_inq_names.c b/src/lib/gssapi/mechglue/g_inq_names.c +index d22af8bcf9..066c00c042 100644 +--- a/src/lib/gssapi/mechglue/g_inq_names.c ++++ b/src/lib/gssapi/mechglue/g_inq_names.c +@@ -32,12 +32,8 @@ + + /* Last argument new for V2 */ + OM_uint32 KRB5_CALLCONV +-gss_inquire_names_for_mech(minor_status, mechanism, name_types) +- +-OM_uint32 * minor_status; +-gss_OID mechanism; +-gss_OID_set * name_types; +- ++gss_inquire_names_for_mech(OM_uint32 *minor_status, gss_OID mechanism, ++ gss_OID_set *name_types) + { + OM_uint32 status; + gss_OID selected_mech = GSS_C_NO_OID, public_mech; +diff --git a/src/lib/gssapi/mechglue/g_mechname.c b/src/lib/gssapi/mechglue/g_mechname.c +index cfb0a0d2af..5664fa157e 100644 +--- a/src/lib/gssapi/mechglue/g_mechname.c ++++ b/src/lib/gssapi/mechglue/g_mechname.c +@@ -20,8 +20,8 @@ static gss_mech_spec_name name_list = NULL; + /* + * generic searching helper function. + */ +-static gss_mech_spec_name search_mech_spec(name_type) +- gss_OID name_type; ++static gss_mech_spec_name ++search_mech_spec(gss_OID name_type) + { + gss_mech_spec_name p; + +@@ -36,8 +36,8 @@ static gss_mech_spec_name search_mech_spec(name_type) + * Given a name_type, if it is specific to a mechanism, return the + * mechanism OID. Otherwise, return NULL. + */ +-gss_OID gss_find_mechanism_from_name_type(name_type) +- gss_OID name_type; ++gss_OID ++gss_find_mechanism_from_name_type(gss_OID name_type) + { + gss_mech_spec_name p; + +@@ -54,10 +54,8 @@ gss_OID gss_find_mechanism_from_name_type(name_type) + * Otherwise, enter the pair into the registry. + */ + OM_uint32 +-gss_add_mech_name_type(minor_status, name_type, mech) +- OM_uint32 *minor_status; +- gss_OID name_type; +- gss_OID mech; ++gss_add_mech_name_type(OM_uint32 *minor_status, gss_OID name_type, ++ gss_OID mech) + { + OM_uint32 major_status, tmp; + gss_mech_spec_name p; +diff --git a/src/lib/gssapi/mechglue/g_oid_ops.c b/src/lib/gssapi/mechglue/g_oid_ops.c +index 1d7970c5dd..f29fb3b33e 100644 +--- a/src/lib/gssapi/mechglue/g_oid_ops.c ++++ b/src/lib/gssapi/mechglue/g_oid_ops.c +@@ -33,9 +33,7 @@ + */ + + OM_uint32 KRB5_CALLCONV +-gss_create_empty_oid_set(minor_status, oid_set) +- OM_uint32 *minor_status; +- gss_OID_set *oid_set; ++gss_create_empty_oid_set(OM_uint32 *minor_status, gss_OID_set *oid_set) + { + OM_uint32 status; + status = generic_gss_create_empty_oid_set(minor_status, oid_set); +@@ -45,10 +43,8 @@ gss_create_empty_oid_set(minor_status, oid_set) + } + + OM_uint32 KRB5_CALLCONV +-gss_add_oid_set_member(minor_status, member_oid, oid_set) +- OM_uint32 *minor_status; +- gss_OID member_oid; +- gss_OID_set *oid_set; ++gss_add_oid_set_member(OM_uint32 *minor_status, gss_OID member_oid, ++ gss_OID_set *oid_set) + { + OM_uint32 status; + status = generic_gss_add_oid_set_member(minor_status, member_oid, oid_set); +@@ -58,20 +54,14 @@ gss_add_oid_set_member(minor_status, member_oid, oid_set) + } + + OM_uint32 KRB5_CALLCONV +-gss_test_oid_set_member(minor_status, member, set, present) +- OM_uint32 *minor_status; +- gss_OID member; +- gss_OID_set set; +- int *present; ++gss_test_oid_set_member(OM_uint32 *minor_status, gss_OID member, ++ gss_OID_set set, int *present) + { + return generic_gss_test_oid_set_member(minor_status, member, set, present); + } + + OM_uint32 KRB5_CALLCONV +-gss_oid_to_str(minor_status, oid, oid_str) +- OM_uint32 *minor_status; +- gss_OID oid; +- gss_buffer_t oid_str; ++gss_oid_to_str(OM_uint32 *minor_status, gss_OID oid, gss_buffer_t oid_str) + { + OM_uint32 status = generic_gss_oid_to_str(minor_status, oid, oid_str); + if (status != GSS_S_COMPLETE) +@@ -80,10 +70,7 @@ gss_oid_to_str(minor_status, oid, oid_str) + } + + OM_uint32 KRB5_CALLCONV +-gss_str_to_oid(minor_status, oid_str, oid) +- OM_uint32 *minor_status; +- gss_buffer_t oid_str; +- gss_OID *oid; ++gss_str_to_oid(OM_uint32 *minor_status, gss_buffer_t oid_str, gss_OID *oid) + { + OM_uint32 status = generic_gss_str_to_oid(minor_status, oid_str, oid); + if (status != GSS_S_COMPLETE) +diff --git a/src/lib/gssapi/mechglue/g_process_context.c b/src/lib/gssapi/mechglue/g_process_context.c +index 3968b5d9c6..2b3f6c704d 100644 +--- a/src/lib/gssapi/mechglue/g_process_context.c ++++ b/src/lib/gssapi/mechglue/g_process_context.c +@@ -29,14 +29,8 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_process_context_token (minor_status, +- context_handle, +- token_buffer) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t token_buffer; +- ++gss_process_context_token(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t token_buffer) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_rel_buffer.c b/src/lib/gssapi/mechglue/g_rel_buffer.c +index 8c3328acc5..60117bdb56 100644 +--- a/src/lib/gssapi/mechglue/g_rel_buffer.c ++++ b/src/lib/gssapi/mechglue/g_rel_buffer.c +@@ -33,11 +33,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_buffer (minor_status, +- buffer) +- +-OM_uint32 * minor_status; +-gss_buffer_t buffer; ++gss_release_buffer(OM_uint32 *minor_status, gss_buffer_t buffer) + { + if (minor_status) + *minor_status = 0; +diff --git a/src/lib/gssapi/mechglue/g_rel_cred.c b/src/lib/gssapi/mechglue/g_rel_cred.c +index ccdee05a56..ee3d1d71e3 100644 +--- a/src/lib/gssapi/mechglue/g_rel_cred.c ++++ b/src/lib/gssapi/mechglue/g_rel_cred.c +@@ -31,12 +31,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_cred(minor_status, +- cred_handle) +- +-OM_uint32 * minor_status; +-gss_cred_id_t * cred_handle; +- ++gss_release_cred(OM_uint32 *minor_status, gss_cred_id_t *cred_handle) + { + OM_uint32 status, temp_status; + int j; +diff --git a/src/lib/gssapi/mechglue/g_rel_name.c b/src/lib/gssapi/mechglue/g_rel_name.c +index e008692383..d490f9f290 100644 +--- a/src/lib/gssapi/mechglue/g_rel_name.c ++++ b/src/lib/gssapi/mechglue/g_rel_name.c +@@ -34,12 +34,7 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_release_name (minor_status, +- input_name) +- +-OM_uint32 * minor_status; +-gss_name_t * input_name; +- ++gss_release_name(OM_uint32 *minor_status, gss_name_t *input_name) + { + gss_union_name_t union_name; + +diff --git a/src/lib/gssapi/mechglue/g_rel_oid_set.c b/src/lib/gssapi/mechglue/g_rel_oid_set.c +index fa008d6bb9..9151dd2e71 100644 +--- a/src/lib/gssapi/mechglue/g_rel_oid_set.c ++++ b/src/lib/gssapi/mechglue/g_rel_oid_set.c +@@ -33,11 +33,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_oid_set (minor_status, +- set) +- +-OM_uint32 * minor_status; +-gss_OID_set * set; ++gss_release_oid_set(OM_uint32 *minor_status, gss_OID_set *set) + { + return generic_gss_release_oid_set(minor_status, set); + } +diff --git a/src/lib/gssapi/mechglue/g_sign.c b/src/lib/gssapi/mechglue/g_sign.c +index 03fbd8c01f..c9af1da570 100644 +--- a/src/lib/gssapi/mechglue/g_sign.c ++++ b/src/lib/gssapi/mechglue/g_sign.c +@@ -66,18 +66,9 @@ val_get_mic_args( + + + OM_uint32 KRB5_CALLCONV +-gss_get_mic (minor_status, +- context_handle, +- qop_req, +- message_buffer, +- msg_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_qop_t qop_req; +-gss_buffer_t message_buffer; +-gss_buffer_t msg_token; +- ++gss_get_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_qop_t qop_req, gss_buffer_t message_buffer, ++ gss_buffer_t msg_token) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +@@ -118,18 +109,8 @@ gss_buffer_t msg_token; + } + + OM_uint32 KRB5_CALLCONV +-gss_sign (minor_status, +- context_handle, +- qop_req, +- message_buffer, +- msg_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int qop_req; +-gss_buffer_t message_buffer; +-gss_buffer_t msg_token; +- ++gss_sign(OM_uint32 *minor_status, gss_ctx_id_t context_handle, int qop_req, ++ gss_buffer_t message_buffer, gss_buffer_t msg_token) + { + return (gss_get_mic(minor_status, context_handle, (gss_qop_t) qop_req, + message_buffer, msg_token)); +diff --git a/src/lib/gssapi/mechglue/g_store_cred.c b/src/lib/gssapi/mechglue/g_store_cred.c +index c2b6ddf3c0..231b3e81a0 100644 +--- a/src/lib/gssapi/mechglue/g_store_cred.c ++++ b/src/lib/gssapi/mechglue/g_store_cred.c +@@ -93,24 +93,10 @@ val_store_cred_args( + + + OM_uint32 KRB5_CALLCONV +-gss_store_cred(minor_status, +- input_cred_handle, +- cred_usage, +- desired_mech, +- overwrite_cred, +- default_cred, +- elements_stored, +- cred_usage_stored) +- +-OM_uint32 *minor_status; +-gss_cred_id_t input_cred_handle; +-gss_cred_usage_t cred_usage; +-const gss_OID desired_mech; +-OM_uint32 overwrite_cred; +-OM_uint32 default_cred; +-gss_OID_set *elements_stored; +-gss_cred_usage_t *cred_usage_stored; +- ++gss_store_cred(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_cred_usage_t cred_usage, const gss_OID desired_mech, ++ OM_uint32 overwrite_cred, OM_uint32 default_cred, ++ gss_OID_set *elements_stored, gss_cred_usage_t *cred_usage_stored) + { + return gss_store_cred_into(minor_status, input_cred_handle, cred_usage, + desired_mech, overwrite_cred, default_cred, +@@ -119,26 +105,12 @@ gss_cred_usage_t *cred_usage_stored; + } + + OM_uint32 KRB5_CALLCONV +-gss_store_cred_into(minor_status, +- input_cred_handle, +- cred_usage, +- desired_mech, +- overwrite_cred, +- default_cred, +- cred_store, +- elements_stored, +- cred_usage_stored) +- +-OM_uint32 *minor_status; +-gss_cred_id_t input_cred_handle; +-gss_cred_usage_t cred_usage; +-gss_OID desired_mech; +-OM_uint32 overwrite_cred; +-OM_uint32 default_cred; +-gss_const_key_value_set_t cred_store; +-gss_OID_set *elements_stored; +-gss_cred_usage_t *cred_usage_stored; +- ++gss_store_cred_into(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_cred_usage_t cred_usage, gss_OID desired_mech, ++ OM_uint32 overwrite_cred, OM_uint32 default_cred, ++ gss_const_key_value_set_t cred_store, ++ gss_OID_set *elements_stored, ++ gss_cred_usage_t *cred_usage_stored) + { + OM_uint32 major_status = GSS_S_FAILURE; + gss_union_cred_t union_cred; +diff --git a/src/lib/gssapi/mechglue/g_unseal.c b/src/lib/gssapi/mechglue/g_unseal.c +index c208635b67..2be3745d1f 100644 +--- a/src/lib/gssapi/mechglue/g_unseal.c ++++ b/src/lib/gssapi/mechglue/g_unseal.c +@@ -29,20 +29,10 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_unwrap (minor_status, +- context_handle, +- input_message_buffer, +- output_message_buffer, +- conf_state, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t output_message_buffer; +-int * conf_state; +-gss_qop_t * qop_state; +- ++gss_unwrap(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, ++ int *conf_state, gss_qop_t *qop_state) + { + /* EXPORT DELETE START */ + OM_uint32 status; +@@ -111,20 +101,9 @@ gss_qop_t * qop_state; + } + + OM_uint32 KRB5_CALLCONV +-gss_unseal (minor_status, +- context_handle, +- input_message_buffer, +- output_message_buffer, +- conf_state, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t output_message_buffer; +-int * conf_state; +-int * qop_state; +- ++gss_unseal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, int *conf_state, int *qop_state) + { + return (gss_unwrap(minor_status, context_handle, + input_message_buffer, +diff --git a/src/lib/gssapi/mechglue/g_unwrap_aead.c b/src/lib/gssapi/mechglue/g_unwrap_aead.c +index 0682bd8998..5c9ff30031 100644 +--- a/src/lib/gssapi/mechglue/g_unwrap_aead.c ++++ b/src/lib/gssapi/mechglue/g_unwrap_aead.c +@@ -154,20 +154,11 @@ gssint_unwrap_aead (gss_mechanism mech, + } + + OM_uint32 KRB5_CALLCONV +-gss_unwrap_aead (minor_status, +- context_handle, +- input_message_buffer, +- input_assoc_buffer, +- output_payload_buffer, +- conf_state, +- qop_state) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t input_assoc_buffer; +-gss_buffer_t output_payload_buffer; +-int *conf_state; +-gss_qop_t *qop_state; ++gss_unwrap_aead(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t output_payload_buffer, ++ int *conf_state, gss_qop_t *qop_state) + { + + OM_uint32 status; +diff --git a/src/lib/gssapi/mechglue/g_unwrap_iov.c b/src/lib/gssapi/mechglue/g_unwrap_iov.c +index 599be2c7b2..bf9c3bcc33 100644 +--- a/src/lib/gssapi/mechglue/g_unwrap_iov.c ++++ b/src/lib/gssapi/mechglue/g_unwrap_iov.c +@@ -59,18 +59,9 @@ val_unwrap_iov_args( + + + OM_uint32 KRB5_CALLCONV +-gss_unwrap_iov (minor_status, +- context_handle, +- conf_state, +- qop_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int * conf_state; +-gss_qop_t *qop_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_unwrap_iov(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ int *conf_state, gss_qop_t *qop_state, ++ gss_iov_buffer_desc *iov, int iov_count) + { + /* EXPORT DELETE START */ + +diff --git a/src/lib/gssapi/mechglue/g_verify.c b/src/lib/gssapi/mechglue/g_verify.c +index 8996fce8d5..86ade66877 100644 +--- a/src/lib/gssapi/mechglue/g_verify.c ++++ b/src/lib/gssapi/mechglue/g_verify.c +@@ -29,18 +29,9 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_verify_mic (minor_status, +- context_handle, +- message_buffer, +- token_buffer, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t message_buffer; +-gss_buffer_t token_buffer; +-gss_qop_t * qop_state; +- ++gss_verify_mic(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ gss_qop_t *qop_state) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +@@ -89,18 +80,9 @@ gss_qop_t * qop_state; + } + + OM_uint32 KRB5_CALLCONV +-gss_verify (minor_status, +- context_handle, +- message_buffer, +- token_buffer, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t message_buffer; +-gss_buffer_t token_buffer; +-int * qop_state; +- ++gss_verify(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ int *qop_state) + { + return (gss_verify_mic(minor_status, context_handle, + message_buffer, token_buffer, +diff --git a/src/lib/gssapi/mechglue/g_wrap_aead.c b/src/lib/gssapi/mechglue/g_wrap_aead.c +index 7fe3b7b35b..5a6570f7f9 100644 +--- a/src/lib/gssapi/mechglue/g_wrap_aead.c ++++ b/src/lib/gssapi/mechglue/g_wrap_aead.c +@@ -177,15 +177,11 @@ gssint_wrap_aead_iov_shim(gss_mechanism mech, + } + + OM_uint32 +-gssint_wrap_aead (gss_mechanism mech, +- OM_uint32 *minor_status, +- gss_union_ctx_id_t ctx, +- int conf_req_flag, +- gss_qop_t qop_req, +- gss_buffer_t input_assoc_buffer, +- gss_buffer_t input_payload_buffer, +- int *conf_state, +- gss_buffer_t output_message_buffer) ++gssint_wrap_aead(gss_mechanism mech, OM_uint32 *minor_status, ++ gss_union_ctx_id_t ctx, int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t input_payload_buffer, ++ int *conf_state, gss_buffer_t output_message_buffer) + { + /* EXPORT DELETE START */ + OM_uint32 status; +@@ -223,22 +219,15 @@ gssint_wrap_aead (gss_mechanism mech, + } + + OM_uint32 KRB5_CALLCONV +-gss_wrap_aead (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- input_assoc_buffer, +- input_payload_buffer, +- conf_state, +- output_message_buffer) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-gss_buffer_t input_assoc_buffer; +-gss_buffer_t input_payload_buffer; +-int * conf_state; +-gss_buffer_t output_message_buffer; ++gss_wrap_aead ( ++ OM_uint32 * minor_status, ++ gss_ctx_id_t context_handle, ++ int conf_req_flag, ++ gss_qop_t qop_req, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t input_payload_buffer, ++ int * conf_state, ++ gss_buffer_t output_message_buffer) + { + OM_uint32 status; + gss_mechanism mech; +diff --git a/src/lib/gssapi/mechglue/g_wrap_iov.c b/src/lib/gssapi/mechglue/g_wrap_iov.c +index 14447c4ee1..aaf3a9308e 100644 +--- a/src/lib/gssapi/mechglue/g_wrap_iov.c ++++ b/src/lib/gssapi/mechglue/g_wrap_iov.c +@@ -60,20 +60,9 @@ val_wrap_iov_args( + + + OM_uint32 KRB5_CALLCONV +-gss_wrap_iov (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- conf_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-int * conf_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_wrap_iov(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, int *conf_state, ++ gss_iov_buffer_desc *iov, int iov_count) + { + /* EXPORT DELETE START */ + +@@ -120,20 +109,10 @@ int iov_count; + } + + OM_uint32 KRB5_CALLCONV +-gss_wrap_iov_length (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- conf_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-int * conf_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_wrap_iov_length(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ int *conf_state, gss_iov_buffer_desc *iov, ++ int iov_count) + { + /* EXPORT DELETE START */ + +@@ -239,12 +218,8 @@ gss_get_mic_iov_length(OM_uint32 *minor_status, gss_ctx_id_t context_handle, + } + + OM_uint32 KRB5_CALLCONV +-gss_release_iov_buffer (minor_status, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_release_iov_buffer(OM_uint32 * minor_status, gss_iov_buffer_desc *iov, ++ int iov_count) + { + OM_uint32 status = GSS_S_COMPLETE; + int i; +diff --git a/src/lib/kadm5/clnt/client_rpc.c b/src/lib/kadm5/clnt/client_rpc.c +index d84d158b46..c8d844e4c7 100644 +--- a/src/lib/kadm5/clnt/client_rpc.c ++++ b/src/lib/kadm5/clnt/client_rpc.c +@@ -1,6 +1,7 @@ + /* -*- mode: c; c-file-style: "bsd"; indent-tabs-mode: t -*- */ + #include + #include ++#include + #include + #include + #include /* for memset prototype */ +diff --git a/src/lib/kadm5/kadm_rpc.h b/src/lib/kadm5/kadm_rpc.h +index 5099c6c145..9efe49a373 100644 +--- a/src/lib/kadm5/kadm_rpc.h ++++ b/src/lib/kadm5/kadm_rpc.h +@@ -360,49 +360,4 @@ extern enum clnt_stat get_principal_keys_2(getpkeys_arg *, getpkeys_ret *, + CLIENT *); + extern bool_t get_principal_keys_2_svc(getpkeys_arg *, getpkeys_ret *, + struct svc_req *); +- +-extern bool_t xdr_cprinc_arg (); +-extern bool_t xdr_cprinc3_arg (); +-extern bool_t xdr_generic_ret (); +-extern bool_t xdr_dprinc_arg (); +-extern bool_t xdr_mprinc_arg (); +-extern bool_t xdr_rprinc_arg (); +-extern bool_t xdr_gprincs_arg (); +-extern bool_t xdr_gprincs_ret (); +-extern bool_t xdr_chpass_arg (); +-extern bool_t xdr_chpass3_arg (); +-extern bool_t xdr_setkey_arg (); +-extern bool_t xdr_setkey3_arg (); +-extern bool_t xdr_setkey4_arg (); +-extern bool_t xdr_chrand_arg (); +-extern bool_t xdr_chrand3_arg (); +-extern bool_t xdr_chrand_ret (); +-extern bool_t xdr_gprinc_arg (); +-extern bool_t xdr_gprinc_ret (); +-extern bool_t xdr_kadm5_ret_t (); +-extern bool_t xdr_kadm5_principal_ent_rec (); +-extern bool_t xdr_kadm5_policy_ent_rec (); +-extern bool_t xdr_krb5_keyblock (); +-extern bool_t xdr_krb5_principal (); +-extern bool_t xdr_krb5_enctype (); +-extern bool_t xdr_krb5_octet (); +-extern bool_t xdr_krb5_int32 (); +-extern bool_t xdr_u_int32 (); +-extern bool_t xdr_cpol_arg (); +-extern bool_t xdr_dpol_arg (); +-extern bool_t xdr_mpol_arg (); +-extern bool_t xdr_gpol_arg (); +-extern bool_t xdr_gpol_ret (); +-extern bool_t xdr_gpols_arg (); +-extern bool_t xdr_gpols_ret (); +-extern bool_t xdr_getprivs_ret (); +-extern bool_t xdr_purgekeys_arg (); +-extern bool_t xdr_gstrings_arg (); +-extern bool_t xdr_gstrings_ret (); +-extern bool_t xdr_sstring_arg (); +-extern bool_t xdr_krb5_string_attr (); +-extern bool_t xdr_kadm5_key_data (); +-extern bool_t xdr_getpkeys_arg (); +-extern bool_t xdr_getpkeys_ret (); +- + #endif /* __KADM_RPC_H__ */ +diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c +index 287cae750f..5e052dd90c 100644 +--- a/src/lib/kadm5/kadm_rpc_xdr.c ++++ b/src/lib/kadm5/kadm_rpc_xdr.c +@@ -408,7 +408,7 @@ _xdr_kadm5_principal_ent_rec(XDR *xdrs, kadm5_principal_ent_rec *objp, + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->mod_name, +- xdr_krb5_principal)) { ++ (xdrproc_t)xdr_krb5_principal)) { + return (FALSE); + } + if (!xdr_krb5_timestamp(xdrs, &objp->mod_date)) { +@@ -451,12 +451,13 @@ _xdr_kadm5_principal_ent_rec(XDR *xdrs, kadm5_principal_ent_rec *objp, + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) { ++ (xdrproc_t)xdr_krb5_tl_data)) { + return FALSE; + } + n = objp->n_key_data; + r = xdr_array(xdrs, (caddr_t *) &objp->key_data, &n, objp->n_key_data, +- sizeof(krb5_key_data), xdr_krb5_key_data_nocontents); ++ sizeof(krb5_key_data), ++ (xdrproc_t)xdr_krb5_key_data_nocontents); + objp->n_key_data = n; + if (!r) { + return (FALSE); +@@ -528,7 +529,7 @@ _xdr_kadm5_policy_ent_rec(XDR *xdrs, kadm5_policy_ent_rec *objp, int vers) + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) { ++ (xdrproc_t)xdr_krb5_tl_data)) { + return FALSE; + } + } +@@ -576,7 +577,7 @@ xdr_cprinc3_arg(XDR *xdrs, cprinc3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int *)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_nullstring(xdrs, &objp->passwd)) { +@@ -668,7 +669,7 @@ xdr_gprincs_ret(XDR *xdrs, gprincs_ret *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->princs, + (unsigned int *) &objp->count, ~0, +- sizeof(char *), xdr_nullstring)) { ++ sizeof(char *), (xdrproc_t)xdr_nullstring)) { + return (FALSE); + } + } +@@ -706,7 +707,7 @@ xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int*)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_nullstring(xdrs, &objp->pass)) { +@@ -726,7 +727,7 @@ xdr_setkey_arg(XDR *xdrs, setkey_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->keyblocks, + (unsigned int *) &objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { ++ sizeof(krb5_keyblock), (xdrproc_t)xdr_krb5_keyblock)) { + return (FALSE); + } + return (TRUE); +@@ -746,12 +747,13 @@ xdr_setkey3_arg(XDR *xdrs, setkey3_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->ks_tuple, + (unsigned int *) &objp->n_ks_tuple, ~0, +- sizeof(krb5_key_salt_tuple), xdr_krb5_key_salt_tuple)) { ++ sizeof(krb5_key_salt_tuple), ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_array(xdrs, (caddr_t *) &objp->keyblocks, + (unsigned int *) &objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { ++ sizeof(krb5_keyblock), (xdrproc_t)xdr_krb5_keyblock)) { + return (FALSE); + } + return (TRUE); +@@ -771,7 +773,8 @@ xdr_setkey4_arg(XDR *xdrs, setkey4_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (unsigned int *) &objp->n_key_data, ~0, +- sizeof(kadm5_key_data), xdr_kadm5_key_data)) { ++ sizeof(kadm5_key_data), ++ (xdrproc_t)xdr_kadm5_key_data)) { + return FALSE; + } + return TRUE; +@@ -804,7 +807,7 @@ xdr_chrand3_arg(XDR *xdrs, chrand3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int*)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + return (TRUE); +@@ -822,7 +825,8 @@ xdr_chrand_ret(XDR *xdrs, chrand_ret *objp) + if (objp->code == KADM5_OK) { + if (!xdr_array(xdrs, (char **)&objp->keys, + (unsigned int *)&objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) ++ sizeof(krb5_keyblock), ++ (xdrproc_t)xdr_krb5_keyblock)) + return FALSE; + } + +@@ -965,7 +969,7 @@ xdr_gpols_ret(XDR *xdrs, gpols_ret *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->pols, + (unsigned int *) &objp->count, ~0, +- sizeof(char *), xdr_nullstring)) { ++ sizeof(char *), (xdrproc_t)xdr_nullstring)) { + return (FALSE); + } + } +@@ -1030,7 +1034,7 @@ xdr_gstrings_ret(XDR *xdrs, gstrings_ret *objp) + if (!xdr_array(xdrs, (caddr_t *) &objp->strings, + (unsigned int *) &objp->count, ~0, + sizeof(krb5_string_attr), +- xdr_krb5_string_attr)) { ++ (xdrproc_t)xdr_krb5_string_attr)) { + return (FALSE); + } + } +@@ -1198,7 +1202,8 @@ xdr_getpkeys_ret(XDR *xdrs, getpkeys_ret *objp) + if (objp->code == KADM5_OK) { + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (unsigned int *) &objp->n_key_data, ~0, +- sizeof(kadm5_key_data), xdr_kadm5_key_data)) { ++ sizeof(kadm5_key_data), ++ (xdrproc_t)xdr_kadm5_key_data)) { + return FALSE; + } + } +diff --git a/src/lib/kadm5/misc_free.c b/src/lib/kadm5/misc_free.c +index 74d23760fb..9ac47bb87f 100644 +--- a/src/lib/kadm5/misc_free.c ++++ b/src/lib/kadm5/misc_free.c +@@ -41,9 +41,8 @@ kadm5_free_name_list(void *server_handle, char **names, int count) + } + + /* XXX this ought to be in libkrb5.a, but isn't */ +-kadm5_ret_t krb5_free_key_data_contents(context, key) +- krb5_context context; +- krb5_key_data *key; ++kadm5_ret_t ++krb5_free_key_data_contents(krb5_context context, krb5_key_data *key) + { + int i, idx; + +diff --git a/src/lib/kadm5/srv/adb_xdr.c b/src/lib/kadm5/srv/adb_xdr.c +index fc732971d2..b6ffdb8c7a 100644 +--- a/src/lib/kadm5/srv/adb_xdr.c ++++ b/src/lib/kadm5/srv/adb_xdr.c +@@ -53,8 +53,7 @@ xdr_osa_pw_hist_ent(XDR *xdrs, osa_pw_hist_ent *objp) + { + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (u_int *) &objp->n_key_data, ~0, +- sizeof(krb5_key_data), +- xdr_krb5_key_data)) ++ sizeof(krb5_key_data), (xdrproc_t)xdr_krb5_key_data)) + return (FALSE); + return (TRUE); + } +@@ -88,8 +87,7 @@ xdr_osa_princ_ent_rec(XDR *xdrs, osa_princ_ent_t objp) + return (FALSE); + if (!xdr_array(xdrs, (caddr_t *) &objp->old_keys, + (unsigned int *) &objp->old_key_len, ~0, +- sizeof(osa_pw_hist_ent), +- xdr_osa_pw_hist_ent)) ++ sizeof(osa_pw_hist_ent), (xdrproc_t)xdr_osa_pw_hist_ent)) + return (FALSE); + return (TRUE); + } +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 8c3ad3a691..d5bb0b167d 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -30,9 +30,9 @@ static int decrypt_key_data(krb5_context context, + /* + * XXX Functions that ought to be in libkrb5.a, but aren't. + */ +-kadm5_ret_t krb5_copy_key_data_contents(context, from, to) +- krb5_context context; +- krb5_key_data *from, *to; ++kadm5_ret_t ++krb5_copy_key_data_contents(krb5_context context, krb5_key_data *from, ++ krb5_key_data *to) + { + int i, idx; + +@@ -75,10 +75,8 @@ static krb5_tl_data *dup_tl_data(krb5_tl_data *tl) + } + + /* This is in lib/kdb/kdb_cpw.c, but is static */ +-static void cleanup_key_data(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++static void ++cleanup_key_data(krb5_context context, int count, krb5_key_data *data) + { + int i; + +diff --git a/src/lib/kadm5/str_conv.c b/src/lib/kadm5/str_conv.c +index 7982956062..f2fae832eb 100644 +--- a/src/lib/kadm5/str_conv.c ++++ b/src/lib/kadm5/str_conv.c +@@ -267,11 +267,8 @@ cleanup: + * Salttype may be negative to indicate a search for only a enctype. + */ + krb5_boolean +-krb5_keysalt_is_present(ksaltlist, nksalts, enctype, salttype) +- krb5_key_salt_tuple *ksaltlist; +- krb5_int32 nksalts; +- krb5_enctype enctype; +- krb5_int32 salttype; ++krb5_keysalt_is_present(krb5_key_salt_tuple *ksaltlist, krb5_int32 nksalts, ++ krb5_enctype enctype, krb5_int32 salttype) + { + krb5_boolean foundit; + int i; +@@ -375,12 +372,11 @@ cleanup: + * If ignoresalt set, then salttype is ignored. + */ + krb5_error_code +-krb5_keysalt_iterate(ksaltlist, nksalt, ignoresalt, iterator, arg) +- krb5_key_salt_tuple *ksaltlist; +- krb5_int32 nksalt; +- krb5_boolean ignoresalt; +- krb5_error_code (*iterator) (krb5_key_salt_tuple *, krb5_pointer); +- krb5_pointer arg; ++krb5_keysalt_iterate(krb5_key_salt_tuple *ksaltlist, krb5_int32 nksalt, ++ krb5_boolean ignoresalt, ++ krb5_error_code (*iterator)(krb5_key_salt_tuple *, ++ void *), ++ void *arg) + { + int i; + krb5_error_code kret; +diff --git a/src/lib/kadm5/t_kadm5.c b/src/lib/kadm5/t_kadm5.c +index 153147ffbf..b3ab1004f3 100644 +--- a/src/lib/kadm5/t_kadm5.c ++++ b/src/lib/kadm5/t_kadm5.c +@@ -276,7 +276,7 @@ cpw_test_succeed(char *user, krb5_principal princ, char *pass) + } + + static void +-test_chpass() ++test_chpass(void) + { + krb5_principal princ = parse_princ("chpass-test"); + krb5_principal hist_princ = parse_princ("kadmin/history"); +@@ -334,7 +334,7 @@ cpol_test_compare(char *user, kadm5_policy_ent_t ent, uint32_t mask) + } + + static void +-test_create_policy() ++test_create_policy(void) + { + void *handle; + kadm5_policy_ent_rec ent; +@@ -440,7 +440,7 @@ cprinc_test_compare(char *user, kadm5_principal_ent_t ent, uint32_t mask, + } + + static void +-test_create_principal() ++test_create_principal(void) + { + void *handle; + kadm5_principal_ent_rec ent; +@@ -535,7 +535,7 @@ dpol_test_succeed(char *user, char *name) + } + + static void +-test_delete_policy() ++test_delete_policy(void) + { + krb5_principal princ = parse_princ("delete-policy-test-princ"); + +@@ -587,7 +587,7 @@ dprinc_test_succeed(char *user, krb5_principal princ) + } + + static void +-test_delete_principal() ++test_delete_principal(void) + { + krb5_principal princ = parse_princ("delete-principal-test"); + +@@ -638,7 +638,7 @@ gpol_test_fail(char *user, char *name, krb5_error_code code) + } + + static void +-test_get_policy() ++test_get_policy(void) + { + /* Fails with unknown policy. */ + dpol_test_fail("admin", "unknown-policy", KADM5_UNK_POLICY); +@@ -684,7 +684,7 @@ gprinc_test_fail(char *user, krb5_principal princ, krb5_error_code code) + } + + static void +-test_get_principal() ++test_get_principal(void) + { + void *handle; + kadm5_principal_ent_rec ent; +@@ -743,7 +743,7 @@ test_get_principal() + } + + static void +-test_init_destroy() ++test_init_destroy(void) + { + krb5_context ctx; + kadm5_ret_t ret; +@@ -1019,7 +1019,7 @@ mpol_test_compare(void *handle, kadm5_policy_ent_t ent, uint32_t mask) + } + + static void +-test_modify_policy() ++test_modify_policy(void) + { + kadm5_policy_ent_rec ent; + +@@ -1109,7 +1109,7 @@ mprinc_test_compare(char *user, kadm5_principal_ent_t ent, uint32_t mask) + } + + static void +-test_modify_principal() ++test_modify_principal(void) + { + void *handle; + krb5_principal princ = parse_princ("modify-principal-test"); +@@ -1233,7 +1233,7 @@ rnd_test_succeed(char *user, krb5_principal princ) + } + + static void +-test_randkey() ++test_randkey(void) + { + void *handle; + krb5_principal princ = parse_princ("randkey-principal-test"); +diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c +index 415ae64e22..0837f567cc 100644 +--- a/src/lib/kdb/kdb5.c ++++ b/src/lib/kdb/kdb5.c +@@ -75,13 +75,13 @@ free_mkey_list(krb5_context context, krb5_keylist_node *mkey_list) + } + + int +-kdb_init_lock_list() ++kdb_init_lock_list(void) + { + return k5_mutex_finish_init(&db_lock); + } + + static int +-kdb_lock_list() ++kdb_lock_list(void) + { + int err; + err = CALL_INIT_FUNCTION (kdb_init_lock_list); +@@ -92,14 +92,14 @@ kdb_lock_list() + } + + void +-kdb_fini_lock_list() ++kdb_fini_lock_list(void) + { + if (INITIALIZER_RAN(kdb_init_lock_list)) + k5_mutex_destroy(&db_lock); + } + + static void +-kdb_unlock_list() ++kdb_unlock_list(void) + { + k5_mutex_unlock(&db_lock); + } +diff --git a/src/lib/kdb/kdb_cpw.c b/src/lib/kdb/kdb_cpw.c +index 450860f470..c33c7cf8d0 100644 +--- a/src/lib/kdb/kdb_cpw.c ++++ b/src/lib/kdb/kdb_cpw.c +@@ -57,10 +57,7 @@ + enum save { DISCARD_ALL, KEEP_LAST_KVNO, KEEP_ALL }; + + int +-krb5_db_get_key_data_kvno(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++krb5_db_get_key_data_kvno(krb5_context context, int count, krb5_key_data *data) + { + int i, kvno; + /* Find last key version number */ +@@ -73,10 +70,7 @@ krb5_db_get_key_data_kvno(context, count, data) + } + + static void +-cleanup_key_data(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++cleanup_key_data(krb5_context context, int count, krb5_key_data *data) + { + int i; + +@@ -149,13 +143,9 @@ preserve_old_keys(krb5_context context, krb5_keyblock *mkey, + } + + static krb5_error_code +-add_key_rnd(context, master_key, ks_tuple, ks_tuple_count, db_entry, kvno) +- krb5_context context; +- krb5_keyblock * master_key; +- krb5_key_salt_tuple * ks_tuple; +- int ks_tuple_count; +- krb5_db_entry * db_entry; +- int kvno; ++add_key_rnd(krb5_context context, krb5_keyblock *master_key, ++ krb5_key_salt_tuple *ks_tuple, int ks_tuple_count, ++ krb5_db_entry *db_entry, int kvno) + { + krb5_keyblock key; + int i, j; +@@ -246,15 +236,9 @@ make_random_salt(krb5_context context, krb5_keysalt *salt_out) + * If passwd is NULL the assumes that the caller wants a random password. + */ + static krb5_error_code +-add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, +- db_entry, kvno) +- krb5_context context; +- krb5_keyblock * master_key; +- krb5_key_salt_tuple * ks_tuple; +- int ks_tuple_count; +- const char * passwd; +- krb5_db_entry * db_entry; +- int kvno; ++add_key_pwd(krb5_context context, krb5_keyblock *master_key, ++ krb5_key_salt_tuple *ks_tuple, int ks_tuple_count, ++ const char *passwd, krb5_db_entry *db_entry, int kvno) + { + krb5_error_code retval; + krb5_keysalt key_salt; +diff --git a/src/lib/kdb/keytab.c b/src/lib/kdb/keytab.c +index a623e001ec..346cf962e8 100644 +--- a/src/lib/kdb/keytab.c ++++ b/src/lib/kdb/keytab.c +@@ -71,10 +71,7 @@ krb5_db_register_keytab(krb5_context context) + } + + krb5_error_code +-krb5_ktkdb_resolve(context, name, id) +- krb5_context context; +- const char * name; +- krb5_keytab * id; ++krb5_ktkdb_resolve(krb5_context context, const char *name, krb5_keytab *id) + { + if ((*id = (krb5_keytab) malloc(sizeof(**id))) == NULL) + return(ENOMEM); +@@ -84,9 +81,7 @@ krb5_ktkdb_resolve(context, name, id) + } + + krb5_error_code +-krb5_ktkdb_close(context, kt) +- krb5_context context; +- krb5_keytab kt; ++krb5_ktkdb_close(krb5_context context, krb5_keytab kt) + { + /* + * This routine is responsible for freeing all memory allocated +@@ -119,13 +114,9 @@ krb5_ktkdb_set_context(krb5_context ctx) + } + + krb5_error_code +-krb5_ktkdb_get_entry(in_context, id, principal, kvno, enctype, entry) +- krb5_context in_context; +- krb5_keytab id; +- krb5_const_principal principal; +- krb5_kvno kvno; +- krb5_enctype enctype; +- krb5_keytab_entry * entry; ++krb5_ktkdb_get_entry(krb5_context in_context, krb5_keytab id, ++ krb5_const_principal principal, krb5_kvno kvno, ++ krb5_enctype enctype, krb5_keytab_entry *entry) + { + krb5_context context; + krb5_error_code kerror = 0; +diff --git a/src/lib/kdb/t_stringattr.c b/src/lib/kdb/t_stringattr.c +index 11740368ea..2c643018b5 100644 +--- a/src/lib/kdb/t_stringattr.c ++++ b/src/lib/kdb/t_stringattr.c +@@ -38,7 +38,7 @@ + */ + + int +-main() ++main(void) + { + krb5_db_entry *ent; + krb5_context context; +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index fc2d248001..c5446b890c 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -200,7 +200,7 @@ auth_generate_response(krb5_context ctx, const char *secret, + + /* Create a new packet. */ + static krad_packet * +-packet_new() ++packet_new(void) + { + krad_packet *pkt; + +diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c +index 4d285ad9de..d5dd99a174 100644 +--- a/src/lib/krad/t_attr.c ++++ b/src/lib/krad/t_attr.c +@@ -40,7 +40,7 @@ const static unsigned char auth[] = { + }; + + int +-main() ++main(void) + { + unsigned char outbuf[MAX_ATTRSETSIZE]; + const char *decoded = "accept"; +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 0f95762534..4cdb8b7d8e 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -40,7 +40,7 @@ const static unsigned char encpass[] = { + }; + + int +-main() ++main(void) + { + unsigned char buffer[KRAD_PACKET_SIZE_MAX], encoded[MAX_ATTRSETSIZE]; + const char *username = "testUser", *password = "accept"; +diff --git a/src/lib/krad/t_code.c b/src/lib/krad/t_code.c +index b245a7efc0..6cd522af55 100644 +--- a/src/lib/krad/t_code.c ++++ b/src/lib/krad/t_code.c +@@ -30,7 +30,7 @@ + #include "t_test.h" + + int +-main() ++main(void) + { + const char *tmp; + +diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c +index 1dadeef64f..ab3cda6fef 100644 +--- a/src/lib/krb5/ccache/cc_keyring.c ++++ b/src/lib/krb5/ccache/cc_keyring.c +@@ -314,7 +314,7 @@ get_persistent_real(uid_t uid) + * for the session anchor. + */ + static key_serial_t +-session_write_anchor() ++session_write_anchor(void) + { + key_serial_t s, u; + +diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c +index 3bb7a38d44..1286e9e383 100644 +--- a/src/lib/krb5/krb/plugin.c ++++ b/src/lib/krb5/krb/plugin.c +@@ -355,7 +355,7 @@ load_if_needed(krb5_context context, struct plugin_mapping *map, + krb5_error_code ret; + char *symname = NULL; + struct plugin_file_handle *handle = NULL; +- void (*initvt_fn)(); ++ void (*initvt_fn)(void); + + if (map->module != NULL || map->dyn_path == NULL) + return; +diff --git a/src/lib/krb5/krb/t_authdata.c b/src/lib/krb5/krb/t_authdata.c +index dd834b9b0c..44f4a1cbd6 100644 +--- a/src/lib/krb5/krb/t_authdata.c ++++ b/src/lib/krb5/krb/t_authdata.c +@@ -74,7 +74,7 @@ static void compare_authdata(const krb5_authdata *adc1, krb5_authdata *adc2) { + } + + int +-main() ++main(void) + { + krb5_context context; + krb5_authdata **results; +diff --git a/src/lib/krb5/krb/t_response_items.c b/src/lib/krb5/krb/t_response_items.c +index 0deb9292a1..a6b02ca055 100644 +--- a/src/lib/krb5/krb/t_response_items.c ++++ b/src/lib/krb5/krb/t_response_items.c +@@ -61,7 +61,7 @@ nstrcmp(const char *a, const char *b) + } + + int +-main() ++main(void) + { + k5_response_items *ri; + +diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c +index d6746b74bd..9780c2e564 100644 +--- a/src/lib/krb5/krb/t_ser.c ++++ b/src/lib/krb5/krb/t_ser.c +@@ -195,7 +195,7 @@ ser_checksum(krb5_checksum *cksum) + } + + static void +-ser_context_test() ++ser_context_test(void) + { + krb5_context context; + profile_t sprofile; +@@ -216,7 +216,7 @@ ser_context_test() + } + + static void +-ser_acontext_test() ++ser_acontext_test(void) + { + krb5_auth_context actx; + krb5_address local_address; +@@ -306,7 +306,7 @@ ser_acontext_test() + } + + static void +-ser_princ_test() ++ser_princ_test(void) + { + krb5_principal princ; + char pname[1024]; +@@ -320,7 +320,7 @@ ser_princ_test() + } + + static void +-ser_cksum_test() ++ser_cksum_test(void) + { + krb5_checksum checksum; + krb5_octet ckdata[24]; +diff --git a/src/lib/krb5/krb/t_sname_match.c b/src/lib/krb5/krb/t_sname_match.c +index 021b720d65..ee5623c158 100644 +--- a/src/lib/krb5/krb/t_sname_match.c ++++ b/src/lib/krb5/krb/t_sname_match.c +@@ -80,7 +80,7 @@ struct test { + }; + + int +-main() ++main(void) + { + size_t i; + struct test *t; +diff --git a/src/lib/krb5/krb/t_valid_times.c b/src/lib/krb5/krb/t_valid_times.c +index e4b5f1bce4..1a8036e811 100644 +--- a/src/lib/krb5/krb/t_valid_times.c ++++ b/src/lib/krb5/krb/t_valid_times.c +@@ -36,7 +36,7 @@ + #define BOUNDARY (uint32_t)INT32_MIN + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_context context; +diff --git a/src/lib/krb5/rcache/t_memrcache.c b/src/lib/krb5/rcache/t_memrcache.c +index 6f212b0ecd..665da75ea5 100644 +--- a/src/lib/krb5/rcache/t_memrcache.c ++++ b/src/lib/krb5/rcache/t_memrcache.c +@@ -33,7 +33,7 @@ + #include "memrcache.c" + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_context context; +diff --git a/src/lib/rpc/auth_gss.c b/src/lib/rpc/auth_gss.c +index 319bc759b1..f61322d82b 100644 +--- a/src/lib/rpc/auth_gss.c ++++ b/src/lib/rpc/auth_gss.c +@@ -445,9 +445,9 @@ authgss_refresh(AUTH *auth, struct rpc_msg *msg) + memset(&gr, 0, sizeof(gr)); + + call_stat = clnt_call(gd->clnt, NULLPROC, +- xdr_rpc_gss_init_args, ++ (xdrproc_t)xdr_rpc_gss_init_args, + &send_token, +- xdr_rpc_gss_init_res, ++ (xdrproc_t)xdr_rpc_gss_init_res, + (caddr_t)&gr, AUTH_TIMEOUT); + + gss_release_buffer(&min_stat, &send_token); +diff --git a/src/lib/rpc/auth_gssapi.c b/src/lib/rpc/auth_gssapi.c +index 8ab7ab5ba7..b5e03b9641 100644 +--- a/src/lib/rpc/auth_gssapi.c ++++ b/src/lib/rpc/auth_gssapi.c +@@ -283,11 +283,11 @@ next_token: + + PRINTF(("gssapi_create: calling GSSAPI_INIT (%d)\n", init_func)); + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + memset(&call_res, 0, sizeof(call_res)); + callstat = clnt_call(clnt, init_func, +- xdr_authgssapi_init_arg, &call_arg, +- xdr_authgssapi_init_res, &call_res, ++ (xdrproc_t)xdr_authgssapi_init_arg, &call_arg, ++ (xdrproc_t)xdr_authgssapi_init_res, &call_res, + timeout); + gss_release_buffer(minor_stat, &call_arg.token); + +@@ -436,7 +436,7 @@ next_token: + /* don't assume the caller will want to change clnt->cl_auth */ + clnt->cl_auth = save_auth; + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + return auth; + + /******************************************************************/ +@@ -458,7 +458,7 @@ cleanup: + if (rpc_createerr.cf_stat == 0) + rpc_createerr.cf_stat = RPC_AUTHERROR; + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + return auth; + } + +@@ -760,7 +760,7 @@ skip_call: + static bool_t auth_gssapi_wrap( + AUTH *auth, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +@@ -791,7 +791,7 @@ static bool_t auth_gssapi_wrap( + static bool_t auth_gssapi_unwrap( + AUTH *auth, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +diff --git a/src/lib/rpc/auth_gssapi_misc.c b/src/lib/rpc/auth_gssapi_misc.c +index a60eb7f7cb..57fc1fb39f 100644 +--- a/src/lib/rpc/auth_gssapi_misc.c ++++ b/src/lib/rpc/auth_gssapi_misc.c +@@ -199,7 +199,7 @@ bool_t auth_gssapi_wrap_data( + gss_ctx_id_t context, + uint32_t seq_num, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + gss_buffer_desc in_buf, out_buf; +@@ -267,7 +267,7 @@ bool_t auth_gssapi_unwrap_data( + gss_ctx_id_t context, + uint32_t seq_num, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + gss_buffer_desc in_buf, out_buf; +diff --git a/src/lib/rpc/authunix_prot.c b/src/lib/rpc/authunix_prot.c +index 512d5a51b7..92276c3ad4 100644 +--- a/src/lib/rpc/authunix_prot.c ++++ b/src/lib/rpc/authunix_prot.c +@@ -58,7 +58,8 @@ xdr_authunix_parms(XDR *xdrs, struct authunix_parms *p) + && xdr_int(xdrs, &(p->aup_uid)) + && xdr_int(xdrs, &(p->aup_gid)) + && xdr_array(xdrs, (caddr_t *)&(p->aup_gids), +- &(p->aup_len), NGRPS, sizeof(int), xdr_int) ) { ++ &(p->aup_len), NGRPS, sizeof(int), ++ (xdrproc_t)xdr_int)) { + return (TRUE); + } + return (FALSE); +diff --git a/src/lib/rpc/clnt_perror.c b/src/lib/rpc/clnt_perror.c +index fcc3657464..912b267867 100644 +--- a/src/lib/rpc/clnt_perror.c ++++ b/src/lib/rpc/clnt_perror.c +@@ -76,7 +76,6 @@ char * + clnt_sperror(CLIENT *rpch, char *s) + { + struct rpc_err e; +- void clnt_perrno(); + char *err; + char *bufstart = get_buf(); + char *str = bufstart; +diff --git a/src/lib/rpc/clnt_raw.c b/src/lib/rpc/clnt_raw.c +index dcbb5cf23d..7e62a5c776 100644 +--- a/src/lib/rpc/clnt_raw.c ++++ b/src/lib/rpc/clnt_raw.c +@@ -80,7 +80,7 @@ static struct clnt_ops client_ops = { + clntraw_control + }; + +-void svc_getreq(); ++void svc_getreq(int); + + /* + * Create a client handle for memory based rpc. +diff --git a/src/lib/rpc/dyn.c b/src/lib/rpc/dyn.c +index bce1fd2a7d..a505f34817 100644 +--- a/src/lib/rpc/dyn.c ++++ b/src/lib/rpc/dyn.c +@@ -30,10 +30,8 @@ + /* + * Made obsolete by DynInsert, now just a convenience function. + */ +-int DynAppend(obj, els, num) +- DynObjectP obj; +- DynPtr els; +- int num; ++int ++DynAppend(DynObjectP obj, DynPtr els, int num) + { + return DynInsert(obj, DynSize(obj), els, num); + } +@@ -52,8 +50,8 @@ int DynAppend(obj, els, num) + + static int default_increment = DEFAULT_INC; + +-DynObjectP DynCreate(el_size, inc) +- int el_size, inc; ++DynObjectP ++DynCreate(int el_size, int inc) + { + DynObjectP obj; + +@@ -77,8 +75,8 @@ DynObjectP DynCreate(el_size, inc) + return obj; + } + +-DynObjectP DynCopy(obj) +- DynObjectP obj; ++DynObjectP ++DynCopy(DynObjectP obj) + { + DynObjectP obj1; + +@@ -104,8 +102,8 @@ DynObjectP DynCopy(obj) + return obj1; + } + +-int DynDestroy(obj) +- /*@only@*/DynObjectP obj; ++int ++DynDestroy(/*@only@*/DynObjectP obj) + { + if (obj->paranoid) { + if (obj->debug) +@@ -118,8 +116,8 @@ int DynDestroy(obj) + return DYN_OK; + } + +-int DynRelease(obj) +- DynObjectP obj; ++int ++DynRelease(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: release: freeing object structure.\n"); +@@ -134,9 +132,8 @@ int DynRelease(obj) + * contains the source code for the function DynDebug(). + */ + +-int DynDebug(obj, state) +- DynObjectP obj; +- int state; ++int ++DynDebug(DynObjectP obj, int state) + { + obj->debug = state; + +@@ -155,9 +152,8 @@ int DynDebug(obj, state) + * Checkers! Get away from that "hard disk erase" button! + * (Stupid dog. He almost did it to me again ...) + */ +-int DynDelete(obj, idx) +- DynObjectP obj; +- int idx; ++int ++DynDelete(DynObjectP obj, int idx) + { + if (idx < 0) { + if (obj->debug) +@@ -219,9 +215,8 @@ int DynDelete(obj, idx) + * contains the source code for the function DynInitZero(). + */ + +-int DynInitzero(obj, state) +- DynObjectP obj; +- int state; ++int ++DynInitzero(DynObjectP obj, int state) + { + obj->initzero = state; + +@@ -237,10 +232,8 @@ int DynInitzero(obj, state) + * contains the source code for the function DynInsert(). + */ + +-int DynInsert(obj, idx, els_in, num) +- DynObjectP obj; +- void *els_in; +- int idx, num; ++int ++DynInsert(DynObjectP obj, int idx, void *els_in, int num) + { + DynPtr els = (DynPtr) els_in; + int ret; +@@ -290,9 +283,8 @@ int DynInsert(obj, idx, els_in, num) + * contains the source code for the function DynDebug(). + */ + +-int DynParanoid(obj, state) +- DynObjectP obj; +- int state; ++int ++DynParanoid(DynObjectP obj, int state) + { + obj->paranoid = state; + +@@ -308,8 +300,8 @@ int DynParanoid(obj, state) + * contains the source code for the functions DynGet() and DynAdd(). + */ + +-DynPtr DynArray(obj) +- DynObjectP obj; ++DynPtr ++DynArray(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: array: returning array pointer %p.\n", +@@ -318,9 +310,8 @@ DynPtr DynArray(obj) + return obj->array; + } + +-DynPtr DynGet(obj, num) +- DynObjectP obj; +- int num; ++DynPtr ++DynGet(DynObjectP obj, int num) + { + if (num < 0) { + if (obj->debug) +@@ -342,9 +333,7 @@ DynPtr DynGet(obj, num) + return (DynPtr) obj->array + obj->el_size*num; + } + +-int DynAdd(obj, el) +- DynObjectP obj; +- void *el; ++int DynAdd(DynObjectP obj, void *el) + { + int ret; + +@@ -364,10 +353,8 @@ int DynAdd(obj, el) + * obj->num_el) will not be updated properly and many other functions + * in the library will lose. Have a nice day. + */ +-int DynPut(obj, el_in, idx) +- DynObjectP obj; +- void *el_in; +- int idx; ++int ++DynPut(DynObjectP obj, void *el_in, int idx) + { + DynPtr el = (DynPtr) el_in; + int ret; +@@ -397,9 +384,8 @@ int DynPut(obj, el_in, idx) + /* + * Resize the array so that element req exists. + */ +-int _DynResize(obj, req) +- DynObjectP obj; +- int req; ++int ++_DynResize(DynObjectP obj, int req) + { + int size; + +@@ -430,9 +416,8 @@ int _DynResize(obj, req) + * Ideally, this function should not be called from outside the + * library. However, nothing will break if it is. + */ +-int _DynRealloc(obj, num_incs) +- DynObjectP obj; +- int num_incs; ++int ++_DynRealloc(DynObjectP obj, int num_incs) + { + DynPtr temp; + int new_size_in_bytes; +@@ -475,8 +460,8 @@ int _DynRealloc(obj, num_incs) + * contains the source code for the function DynSize(). + */ + +-int DynSize(obj) +- DynObjectP obj; ++int ++DynSize(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: size: returning size %d.\n", obj->num_el); +@@ -484,8 +469,8 @@ int DynSize(obj) + return obj->num_el; + } + +-int DynCapacity(obj) +- DynObjectP obj; ++int ++DynCapacity(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: capacity: returning cap of %d.\n", obj->size); +diff --git a/src/lib/rpc/pmap_clnt.c b/src/lib/rpc/pmap_clnt.c +index 952a251453..5c3bba3528 100644 +--- a/src/lib/rpc/pmap_clnt.c ++++ b/src/lib/rpc/pmap_clnt.c +@@ -54,8 +54,6 @@ static char sccsid[] = "@(#)pmap_clnt.c 1.37 87/08/11 Copyr 1984 Sun Micro"; + static struct timeval timeout = { 5, 0 }; + static struct timeval tottimeout = { 60, 0 }; + +-void clnt_perror(); +- + /* + * Set a mapping between program,version and port. + * Calls the pmap service remotely to do the mapping. +@@ -128,7 +126,8 @@ pmap_set( + } + } + #endif +- if (CLNT_CALL(client, PMAPPROC_SET, xdr_pmap, &parms, xdr_bool, &rslt, ++ if (CLNT_CALL(client, PMAPPROC_SET, (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_bool, &rslt, + tottimeout) != RPC_SUCCESS) { + clnt_perror(client, "Cannot register service"); + return (FALSE); +@@ -161,8 +160,8 @@ pmap_unset( + parms.pm_prog = program; + parms.pm_vers = version; + parms.pm_port = parms.pm_prot = 0; +- CLNT_CALL(client, PMAPPROC_UNSET, xdr_pmap, &parms, xdr_bool, &rslt, +- tottimeout); ++ CLNT_CALL(client, PMAPPROC_UNSET, (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_bool, &rslt, tottimeout); + CLNT_DESTROY(client); + (void)close(sock); + return (rslt); +diff --git a/src/lib/rpc/pmap_getmaps.c b/src/lib/rpc/pmap_getmaps.c +index b8a9cecf7e..a9c4c52906 100644 +--- a/src/lib/rpc/pmap_getmaps.c ++++ b/src/lib/rpc/pmap_getmaps.c +@@ -77,8 +77,9 @@ pmap_getmaps(struct sockaddr_in *address) + client = clnttcp_create(address, PMAPPROG, + PMAPVERS, &sock, 50, 500); + if (client != (CLIENT *)NULL) { +- if (CLNT_CALL(client, PMAPPROC_DUMP, xdr_void, NULL, xdr_pmaplist, +- &head, minutetimeout) != RPC_SUCCESS) { ++ if (CLNT_CALL(client, PMAPPROC_DUMP, xdr_void, NULL, ++ (xdrproc_t)xdr_pmaplist, &head, ++ minutetimeout) != RPC_SUCCESS) { + clnt_perror(client, "pmap_getmaps rpc problem"); + } + CLNT_DESTROY(client); +diff --git a/src/lib/rpc/pmap_getport.c b/src/lib/rpc/pmap_getport.c +index 66635a1034..2d0792b698 100644 +--- a/src/lib/rpc/pmap_getport.c ++++ b/src/lib/rpc/pmap_getport.c +@@ -79,8 +79,10 @@ pmap_getport( + parms.pm_vers = version; + parms.pm_prot = protocol; + parms.pm_port = 0; /* not needed or used */ +- if (CLNT_CALL(client, PMAPPROC_GETPORT, xdr_pmap, &parms, +- xdr_u_short, &port, tottimeout) != RPC_SUCCESS){ ++ if (CLNT_CALL(client, PMAPPROC_GETPORT, ++ (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_u_short, &port, ++ tottimeout) != RPC_SUCCESS){ + rpc_createerr.cf_stat = RPC_PMAPFAILURE; + clnt_geterr(client, &rpc_createerr.cf_error); + } else if (port == 0) { +diff --git a/src/lib/rpc/pmap_prot2.c b/src/lib/rpc/pmap_prot2.c +index aeccac6637..3c0c612bec 100644 +--- a/src/lib/rpc/pmap_prot2.c ++++ b/src/lib/rpc/pmap_prot2.c +@@ -109,7 +109,8 @@ xdr_pmaplist(XDR *xdrs, struct pmaplist **rp) + if (freeing) + next = &((*rp)->pml_next); + if (! xdr_reference(xdrs, (caddr_t *)rp, +- (u_int)sizeof(struct pmaplist), xdr_pmap)) ++ (u_int)sizeof(struct pmaplist), ++ (xdrproc_t)xdr_pmap)) + return (FALSE); + rp = (freeing) ? next : &((*rp)->pml_next); + } +diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c +index 8c7e30c21a..434e4eea65 100644 +--- a/src/lib/rpc/pmap_rmt.c ++++ b/src/lib/rpc/pmap_rmt.c +@@ -105,8 +105,9 @@ pmap_rmtcall( + r.port_ptr = port_ptr; + r.results_ptr = resp; + r.xdr_results = xdrres; +- stat = CLNT_CALL(client, PMAPPROC_CALLIT, xdr_rmtcall_args, &a, +- xdr_rmtcallres, &r, tout); ++ stat = CLNT_CALL(client, PMAPPROC_CALLIT, ++ (xdrproc_t)xdr_rmtcall_args, &a, ++ (xdrproc_t)xdr_rmtcallres, &r, tout); + CLNT_DESTROY(client); + } else { + stat = RPC_FAILED; +@@ -161,7 +162,8 @@ xdr_rmtcallres( + + port_ptr = (caddr_t)(void *)crp->port_ptr; + if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), +- xdr_u_int32) && xdr_u_int32(xdrs, &crp->resultslen)) { ++ (xdrproc_t)xdr_u_int32) && ++ xdr_u_int32(xdrs, &crp->resultslen)) { + crp->port_ptr = (uint32_t *)(void *)port_ptr; + return ((*(crp->xdr_results))(xdrs, crp->results_ptr)); + } +@@ -343,7 +345,7 @@ clnt_broadcast( + recv_again: + msg.acpted_rply.ar_verf = gssrpc__null_auth; + msg.acpted_rply.ar_results.where = (caddr_t)&r; +- msg.acpted_rply.ar_results.proc = xdr_rmtcallres; ++ msg.acpted_rply.ar_results.proc = (xdrproc_t)xdr_rmtcallres; + readfds = mask; + t2 = t; + switch (select(gssrpc__rpc_dtablesize(), &readfds, (fd_set *)NULL, +diff --git a/src/lib/rpc/rpc_prot.c b/src/lib/rpc/rpc_prot.c +index 9b82e12c34..296968b946 100644 +--- a/src/lib/rpc/rpc_prot.c ++++ b/src/lib/rpc/rpc_prot.c +@@ -132,8 +132,8 @@ xdr_rejected_reply(XDR *xdrs, struct rejected_reply *rr) + } + + static struct xdr_discrim reply_dscrm[3] = { +- { (int)MSG_ACCEPTED, xdr_accepted_reply }, +- { (int)MSG_DENIED, xdr_rejected_reply }, ++ { (int)MSG_ACCEPTED, (xdrproc_t)xdr_accepted_reply }, ++ { (int)MSG_DENIED, (xdrproc_t)xdr_rejected_reply }, + { __dontcare__, NULL_xdrproc_t } }; + + /* +diff --git a/src/lib/rpc/svc.c b/src/lib/rpc/svc.c +index cfbc7aad4d..0bcf04e8d4 100644 +--- a/src/lib/rpc/svc.c ++++ b/src/lib/rpc/svc.c +@@ -80,7 +80,7 @@ static struct svc_callout { + struct svc_callout *sc_next; + rpcprog_t sc_prog; + rpcprog_t sc_vers; +- void (*sc_dispatch)(); ++ void (*sc_dispatch)(struct svc_req *, SVCXPRT *); + } *svc_head; + + static struct svc_callout *svc_find(rpcprog_t, rpcvers_t, +@@ -162,7 +162,7 @@ svc_register( + SVCXPRT *xprt, + rpcprog_t prog, + rpcvers_t vers, +- void (*dispatch)(), ++ void (*dispatch)(struct svc_req *, SVCXPRT *), + int protocol) + { + struct svc_callout *prev; +diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c +index aba7694807..98d601c8ab 100644 +--- a/src/lib/rpc/svc_auth_gss.c ++++ b/src/lib/rpc/svc_auth_gss.c +@@ -193,7 +193,7 @@ svcauth_gss_accept_sec_context(struct svc_req *rqst, + /* Deserialize arguments. */ + memset(&recv_tok, 0, sizeof(recv_tok)); + +- if (!svc_getargs(rqst->rq_xprt, xdr_rpc_gss_init_args, ++ if (!svc_getargs(rqst->rq_xprt, (xdrproc_t)xdr_rpc_gss_init_args, + (caddr_t)&recv_tok)) + return (FALSE); + +@@ -209,7 +209,8 @@ svcauth_gss_accept_sec_context(struct svc_req *rqst, + NULL, + NULL); + +- svc_freeargs(rqst->rq_xprt, xdr_rpc_gss_init_args, (caddr_t)&recv_tok); ++ svc_freeargs(rqst->rq_xprt, (xdrproc_t)xdr_rpc_gss_init_args, ++ (caddr_t)&recv_tok); + + log_status("accept_sec_context", gr->gr_major, gr->gr_minor); + if (gr->gr_major != GSS_S_COMPLETE && +@@ -495,7 +496,8 @@ gssrpc__svcauth_gss(struct svc_req *rqst, struct rpc_msg *msg, + } + *no_dispatch = TRUE; + +- call_stat = svc_sendreply(rqst->rq_xprt, xdr_rpc_gss_init_res, ++ call_stat = svc_sendreply(rqst->rq_xprt, ++ (xdrproc_t)xdr_rpc_gss_init_res, + (caddr_t)&gr); + + gss_release_buffer(&min_stat, &gr.gr_token); +@@ -544,7 +546,7 @@ gssrpc__svcauth_gss(struct svc_req *rqst, struct rpc_msg *msg, + } + retstat = AUTH_OK; + freegc: +- xdr_free(xdr_rpc_gss_cred, gc); ++ xdr_free((xdrproc_t)xdr_rpc_gss_cred, gc); + log_debug("returning %d from svcauth_gss()", retstat); + return (retstat); + } +diff --git a/src/lib/rpc/svc_auth_gssapi.c b/src/lib/rpc/svc_auth_gssapi.c +index b7ffee4515..267c1545bd 100644 +--- a/src/lib/rpc/svc_auth_gssapi.c ++++ b/src/lib/rpc/svc_auth_gssapi.c +@@ -201,7 +201,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (! xdr_authgssapi_creds(&xdrs, &creds)) { + PRINTF(("svcauth_gssapi: failed decoding creds\n")); + LOG_MISCERR("protocol error in client credentials"); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + XDR_DESTROY(&xdrs); + ret = AUTH_BADCRED; + goto error; +@@ -223,7 +223,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (creds.auth_msg && rqst->rq_proc == AUTH_GSSAPI_EXIT) { + PRINTF(("svcauth_gssapi: GSSAPI_EXIT, cleaning up\n")); + svc_sendreply(rqst->rq_xprt, xdr_void, NULL); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + cleanup(); + exit(0); + } +@@ -306,7 +306,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + + /* call is for us, deserialize arguments */ + memset(&call_arg, 0, sizeof(call_arg)); +- if (! svc_getargs(rqst->rq_xprt, xdr_authgssapi_init_arg, ++ if (! svc_getargs(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_arg, + &call_arg)) { + PRINTF(("svcauth_gssapi: cannot decode args\n")); + LOG_MISCERR("protocol error in procedure arguments"); +@@ -446,7 +446,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + minor_stat = call_res.gss_minor; + + /* done with call args */ +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, &call_arg); + + PRINTF(("svcauth_gssapi: accept_sec_context returned %#x %#x\n", + call_res.gss_major, call_res.gss_minor)); +@@ -459,7 +459,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + badauth(call_res.gss_major, call_res.gss_minor, rqst->rq_xprt); + + gss_release_buffer(&minor_stat, &output_token); +- svc_sendreply(rqst->rq_xprt, xdr_authgssapi_init_res, ++ svc_sendreply(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_res, + (caddr_t) &call_res); + *no_dispatch = TRUE; + ret = AUTH_OK; +@@ -492,7 +492,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + } + + PRINTF(("svcauth_gssapi: sending reply\n")); +- svc_sendreply(rqst->rq_xprt, xdr_authgssapi_init_res, ++ svc_sendreply(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_res, + (caddr_t) &call_res); + *no_dispatch = TRUE; + +@@ -583,11 +583,13 @@ enum auth_stat gssrpc__svcauth_gssapi( + case AUTH_GSSAPI_MSG: + PRINTF(("svcauth_gssapi: GSSAPI_MSG, getting args\n")); + memset(&call_arg, 0, sizeof(call_arg)); +- if (! svc_getargs(rqst->rq_xprt, xdr_authgssapi_init_arg, ++ if (! svc_getargs(rqst->rq_xprt, ++ (xdrproc_t)xdr_authgssapi_init_arg, + &call_arg)) { + PRINTF(("svcauth_gssapi: cannot decode args\n")); + LOG_MISCERR("protocol error in call arguments"); +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, ++ &call_arg); + ret = AUTH_BADCRED; + goto error; + } +@@ -598,7 +600,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + &call_arg.token); + + /* done with call args */ +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, &call_arg); + + if (gssstat != GSS_S_COMPLETE) { + AUTH_GSSAPI_DISPLAY_STATUS(("processing token", +@@ -641,7 +643,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (creds.client_handle.length != 0) { + PRINTF(("svcauth_gssapi: freeing client_handle len %d\n", + (int) creds.client_handle.length)); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + } + + PRINTF(("\n")); +@@ -651,7 +653,7 @@ error: + if (creds.client_handle.length != 0) { + PRINTF(("svcauth_gssapi: freeing client_handle len %d\n", + (int) creds.client_handle.length)); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + } + + PRINTF(("\n")); +@@ -1079,7 +1081,7 @@ void svcauth_gssapi_set_log_miscerr_func( + static bool_t svc_auth_gssapi_wrap( + SVCAUTH *auth, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +@@ -1102,7 +1104,7 @@ static bool_t svc_auth_gssapi_wrap( + static bool_t svc_auth_gssapi_unwrap( + SVCAUTH *auth, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + svc_auth_gssapi_data *client_data = SVCAUTH_PRIVATE(auth); +diff --git a/src/lib/rpc/svc_simple.c b/src/lib/rpc/svc_simple.c +index 315275f5fd..aa6c0a63d0 100644 +--- a/src/lib/rpc/svc_simple.c ++++ b/src/lib/rpc/svc_simple.c +@@ -48,7 +48,7 @@ static char sccsid[] = "@(#)svc_simple.c 1.18 87/08/11 Copyr 1984 Sun Micro"; + #include + + static struct proglst { +- char *(*p_progname)(); ++ char *(*p_progname)(void *); + int p_prognum; + int p_procnum; + xdrproc_t p_inproc, p_outproc; +@@ -62,7 +62,7 @@ registerrpc( + rpcprog_t prognum, + rpcvers_t versnum, + rpcproc_t procnum, +- char *(*progname)(), ++ char *(*progname)(void *), + xdrproc_t inproc, + xdrproc_t outproc) + { +diff --git a/src/lib/rpc/unit-test/client.c b/src/lib/rpc/unit-test/client.c +index c9a812bc5a..9b907bcdc6 100644 +--- a/src/lib/rpc/unit-test/client.c ++++ b/src/lib/rpc/unit-test/client.c +@@ -42,7 +42,7 @@ char *whoami; + #ifdef __GNUC__ + __attribute__((noreturn)) + #endif +-static void usage() ++static void usage(void) + { + fprintf(stderr, "usage: %s {-t|-u} [-a] [-s num] [-m num] host service [count]\n", + whoami); +@@ -50,9 +50,7 @@ static void usage() + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + char *host, *port, *target, *echo_arg, **echo_resp, buf[BIG_BUF]; + CLIENT *clnt; +@@ -172,7 +170,7 @@ main(argc, argv) + strcmp(echo_arg, (*echo_resp) + 6) != 0) + fprintf(stderr, "RPC_TEST_ECHO call %d response wrong: " + "arg = %s, resp = %s\n", i, echo_arg, *echo_resp); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + /* +@@ -194,7 +192,7 @@ main(argc, argv) + clnt_perror(clnt, whoami); + } else { + fprintf(stderr, "bad seq didn't cause failure\n"); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + AUTH_PRIVATE(clnt->cl_auth)->seq_num -= 3; +@@ -207,7 +205,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Sequence number improperly reset"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + /* + * Now simulate a lost server response, and see if +@@ -219,7 +217,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Auto-resynchronization failed"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + /* + * Now make sure auto-resyncrhonization actually worked +@@ -229,7 +227,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Auto-resynchronization did not work"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + if (! auth_once) { + tmp_auth = clnt->cl_auth; +@@ -259,7 +257,7 @@ main(argc, argv) + strcmp(echo_arg, (*echo_resp) + 6) != 0) + fprintf(stderr, + "RPC_TEST_LENGTHS call %d response wrong\n", i); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + /* cycle from 1 to 255 */ +diff --git a/src/lib/rpc/unit-test/rpc_test_clnt.c b/src/lib/rpc/unit-test/rpc_test_clnt.c +index 4e4a18a720..b9141672b1 100644 +--- a/src/lib/rpc/unit-test/rpc_test_clnt.c ++++ b/src/lib/rpc/unit-test/rpc_test_clnt.c +@@ -5,9 +5,7 @@ + static struct timeval TIMEOUT = { 25, 0 }; + + char ** +-rpc_test_echo_1(argp, clnt) +- char **argp; +- CLIENT *clnt; ++rpc_test_echo_1(char **argp, CLIENT *clnt) + { + static char *clnt_res; + +diff --git a/src/lib/rpc/unit-test/rpc_test_svc.c b/src/lib/rpc/unit-test/rpc_test_svc.c +index c54c0813db..3aa7674c51 100644 +--- a/src/lib/rpc/unit-test/rpc_test_svc.c ++++ b/src/lib/rpc/unit-test/rpc_test_svc.c +@@ -14,16 +14,14 @@ static int _rpcsvcstate = _IDLE; /* Set when a request is serviced */ + static int _rpcsvccount = 0; /* Number of requests being serviced */ + + void +-rpc_test_prog_1_svc(rqstp, transp) +- struct svc_req *rqstp; +- SVCXPRT *transp; ++rpc_test_prog_1_svc(struct svc_req *rqstp, SVCXPRT *transp) + { + union { + char *rpc_test_echo_1_arg; + } argument; + char *result; +- bool_t (*xdr_argument)(), (*xdr_result)(); +- char *(*local)(); ++ xdrproc_t xdr_argument, xdr_result; ++ char *(*local)(char *, struct svc_req *); + + _rpcsvccount++; + switch (rqstp->rq_proc) { +@@ -35,9 +33,9 @@ rpc_test_prog_1_svc(rqstp, transp) + return; + + case RPC_TEST_ECHO: +- xdr_argument = xdr_wrapstring; +- xdr_result = xdr_wrapstring; +- local = (char *(*)()) rpc_test_echo_1_svc; ++ xdr_argument = (xdrproc_t)xdr_wrapstring; ++ xdr_result = (xdrproc_t)xdr_wrapstring; ++ local = (char *(*)(char *, struct svc_req *)) rpc_test_echo_1_svc; + break; + + default: +@@ -53,7 +51,7 @@ rpc_test_prog_1_svc(rqstp, transp) + _rpcsvcstate = _SERVED; + return; + } +- result = (*local)(&argument, rqstp); ++ result = (*local)((char *)&argument, rqstp); + if (result != NULL && !svc_sendreply(transp, xdr_result, result)) { + svcerr_systemerr(transp); + } +diff --git a/src/lib/rpc/unit-test/server.c b/src/lib/rpc/unit-test/server.c +index c3bbcbf8cf..4400b969f6 100644 +--- a/src/lib/rpc/unit-test/server.c ++++ b/src/lib/rpc/unit-test/server.c +@@ -40,7 +40,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, + #define SERVICE_NAME "host" + #endif + +-static void usage() ++static void usage(void) + { + fprintf(stderr, "Usage: server {-t|-u} [svc-debug] [misc-debug]\n"); + exit(1); +diff --git a/src/lib/rpc/xdr.c b/src/lib/rpc/xdr.c +index 24c3de4bd9..49c31b3d1b 100644 +--- a/src/lib/rpc/xdr.c ++++ b/src/lib/rpc/xdr.c +@@ -579,14 +579,14 @@ xdr_union( + */ + for (; choices->proc != NULL_xdrproc_t; choices++) { + if (choices->value == dscm) +- return ((*(choices->proc))(xdrs, unp, LASTUNSIGNED)); ++ return choices->proc(xdrs, unp); + } + + /* + * no match - execute the default xdr routine if there is one + */ + return ((dfault == NULL_xdrproc_t) ? FALSE : +- (*dfault)(xdrs, unp, LASTUNSIGNED)); ++ (*dfault)(xdrs, unp)); + } + + +diff --git a/src/lib/rpc/xdr_array.c b/src/lib/rpc/xdr_array.c +index aeaa7f2bb0..3507d53aef 100644 +--- a/src/lib/rpc/xdr_array.c ++++ b/src/lib/rpc/xdr_array.c +@@ -113,7 +113,7 @@ xdr_array( + * now we xdr each element of array + */ + for (i = 0; (i < c) && stat; i++) { +- stat = (*elproc)(xdrs, target, LASTUNSIGNED); ++ stat = (*elproc)(xdrs, target); + target += elsize; + } + +@@ -150,7 +150,7 @@ xdr_vector( + + elptr = basep; + for (i = 0; i < nelem; i++) { +- if (! (*xdr_elem)(xdrs, elptr, LASTUNSIGNED)) { ++ if (! (*xdr_elem)(xdrs, elptr)) { + return(FALSE); + } + elptr += elemsize; +diff --git a/src/lib/rpc/xdr_rec.c b/src/lib/rpc/xdr_rec.c +index 1f6a7762fd..185254018a 100644 +--- a/src/lib/rpc/xdr_rec.c ++++ b/src/lib/rpc/xdr_rec.c +@@ -99,7 +99,7 @@ typedef struct rec_strm { + /* + * out-goung bits + */ +- int (*writeit)(); ++ int (*writeit)(caddr_t, caddr_t, int); + caddr_t out_base; /* output buffer (points to frag header) */ + caddr_t out_finger; /* next output position */ + caddr_t out_boundry; /* data cannot up to this address */ +@@ -108,7 +108,7 @@ typedef struct rec_strm { + /* + * in-coming bits + */ +- int (*readit)(); ++ int (*readit)(caddr_t, caddr_t, int); + uint32_t in_size; /* fixed size of the input buffer */ + caddr_t in_base; + caddr_t in_finger; /* location of next byte to be had */ +@@ -140,8 +140,10 @@ xdrrec_create( + u_int sendsize, + u_int recvsize, + caddr_t tcp_handle, +- int (*readit)(), /* like read, but pass it a tcp_handle, not sock */ +- int (*writeit)() /* like write, but pass it a tcp_handle, not sock */ ++ /* like read, but pass it a tcp_handle, not sock */ ++ int (*readit)(caddr_t, caddr_t, int), ++ /* like write, but pass it a tcp_handle, not sock */ ++ int (*writeit)(caddr_t, caddr_t, int) + ) + { + RECSTREAM *rstrm = mem_alloc(sizeof(RECSTREAM)); +@@ -528,8 +530,7 @@ get_input_bytes(RECSTREAM *rstrm, caddr_t addr, int len) + } + + static bool_t /* next four bytes of input stream are treated as a header */ +-set_input_fragment(rstrm) +- RECSTREAM *rstrm; ++set_input_fragment(RECSTREAM *rstrm) + { + uint32_t header; + +diff --git a/src/lib/rpc/xdr_reference.c b/src/lib/rpc/xdr_reference.c +index eff279dadf..f3d4b7dfb8 100644 +--- a/src/lib/rpc/xdr_reference.c ++++ b/src/lib/rpc/xdr_reference.c +@@ -47,8 +47,6 @@ static char sccsid[] = "@(#)xdr_reference.c 1.11 87/08/11 SMI"; + #include + #include + +-#define LASTUNSIGNED ((u_int)0-1) +- + /* + * XDR an indirect pointer + * xdr_reference is for recursively translating a structure that is +@@ -88,7 +86,7 @@ xdr_reference( + break; + } + +- stat = (*proc)(xdrs, loc, LASTUNSIGNED); ++ stat = (*proc)(xdrs, loc); + + if (xdrs->x_op == XDR_FREE) { + mem_free(loc, size); +diff --git a/src/lib/rpc/xdr_sizeof.c b/src/lib/rpc/xdr_sizeof.c +index 5b77fa6ac0..0c460e7cdb 100644 +--- a/src/lib/rpc/xdr_sizeof.c ++++ b/src/lib/rpc/xdr_sizeof.c +@@ -43,9 +43,7 @@ + + /* ARGSUSED */ + static bool_t +-x_putlong(xdrs, longp) +- XDR *xdrs; +- long *longp; ++x_putlong(XDR *xdrs, long *longp) + { + xdrs->x_handy += BYTES_PER_XDR_UNIT; + return (TRUE); +@@ -53,10 +51,7 @@ x_putlong(xdrs, longp) + + /* ARGSUSED */ + static bool_t +-x_putbytes(xdrs, bp, len) +- XDR *xdrs; +- char *bp; +- int len; ++x_putbytes(XDR *xdrs, char *bp, u_int len) + { + xdrs->x_handy += len; + +@@ -64,26 +59,21 @@ x_putbytes(xdrs, bp, len) + } + + static u_int +-x_getpostn(xdrs) +- XDR *xdrs; ++x_getpostn(XDR *xdrs) + { + return (xdrs->x_handy); + } + + /* ARGSUSED */ + static bool_t +-x_setpostn(xdrs, pos) +- XDR *xdrs; +- u_int pos; ++x_setpostn(XDR *xdrs, u_int pos) + { + /* This is not allowed */ + return (FALSE); + } + + static rpc_inline_t * +-x_inline(xdrs, len) +- XDR *xdrs; +- int len; ++x_inline(XDR *xdrs, int len) + { + if (len == 0) { + return (NULL); +@@ -110,15 +100,14 @@ x_inline(xdrs, len) + } + + static int +-harmless() ++harmless(void) + { + /* Always return FALSE/NULL, as the case may be */ + return (0); + } + + static void +-x_destroy(xdrs) +- XDR *xdrs; ++x_destroy(XDR *xdrs) + { + xdrs->x_handy = 0; + xdrs->x_private = NULL; +@@ -130,9 +119,7 @@ x_destroy(xdrs) + } + + unsigned long +-xdr_sizeof(func, data) +- xdrproc_t func; +- void *data; ++xdr_sizeof(xdrproc_t func, void *data) + { + XDR x; + struct xdr_ops ops; +diff --git a/src/plugins/kdb/db2/db2_exp.c b/src/plugins/kdb/db2/db2_exp.c +index 7cf8aa4d99..9b75f34a11 100644 +--- a/src/plugins/kdb/db2/db2_exp.c ++++ b/src/plugins/kdb/db2/db2_exp.c +@@ -68,7 +68,7 @@ k5_mutex_t *krb5_db2_mutex; + return result; \ + } \ + /* hack: decl to allow a following ";" */ \ +- static TYPE wrap_##NAME () ++ static TYPE wrap_##NAME ARGLIST + + /* Two special cases: void (can't assign result), and krb5_error_code + (return error from locking code). */ +@@ -81,7 +81,7 @@ k5_mutex_t *krb5_db2_mutex; + k5_mutex_unlock (krb5_db2_mutex); \ + } \ + /* hack: decl to allow a following ";" */ \ +- static void wrap_##NAME () ++ static void wrap_##NAME ARGLIST + + #define WRAP_K(NAME,ARGLIST,ARGNAMES) \ + WRAP(NAME,krb5_error_code,ARGLIST,ARGNAMES) +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_close.c b/src/plugins/kdb/db2/libdb2/btree/bt_close.c +index 11be134113..f12d74ba32 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_close.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_close.c +@@ -61,8 +61,7 @@ static int bt_meta __P((BTREE *)); + * RET_ERROR, RET_SUCCESS + */ + int +-__bt_close(dbp) +- DB *dbp; ++__bt_close(DB *dbp) + { + BTREE *t; + int fd; +@@ -116,9 +115,7 @@ __bt_close(dbp) + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_sync(dbp, flags) +- const DB *dbp; +- u_int flags; ++__bt_sync(const DB *dbp, u_int flags) + { + BTREE *t; + int status; +@@ -160,8 +157,7 @@ __bt_sync(dbp, flags) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_meta(t) +- BTREE *t; ++bt_meta(BTREE *t) + { + BTMETA m; + void *p; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_conv.c b/src/plugins/kdb/db2/libdb2/btree/bt_conv.c +index c0644ed713..99c4af56c0 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_conv.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_conv.c +@@ -59,10 +59,7 @@ static void mswap __P((PAGE *)); + * h: page to convert + */ + void +-__bt_pgin(t, pg, pp) +- void *t; +- db_pgno_t pg; +- void *pp; ++__bt_pgin(void *t, db_pgno_t pg, void *pp) + { + PAGE *h; + indx_t i, top; +@@ -128,10 +125,7 @@ __bt_pgin(t, pg, pp) + } + + void +-__bt_pgout(t, pg, pp) +- void *t; +- db_pgno_t pg; +- void *pp; ++__bt_pgout(void *t, db_pgno_t pg, void *pp) + { + PAGE *h; + indx_t i, top; +@@ -203,8 +197,7 @@ __bt_pgout(t, pg, pp) + * p: page to convert + */ + static void +-mswap(pg) +- PAGE *pg; ++mswap(PAGE *pg) + { + char *p; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_delete.c b/src/plugins/kdb/db2/libdb2/btree/bt_delete.c +index 28cc24d15a..f8dd59e85a 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_delete.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_delete.c +@@ -59,10 +59,7 @@ static int __bt_stkacq __P((BTREE *, PAGE **, CURSOR *)); + * Return RET_SPECIAL if the key is not found. + */ + int +-__bt_delete(dbp, key, flags) +- const DB *dbp; +- const DBT *key; +- u_int flags; ++__bt_delete(const DB *dbp, const DBT *key, u_int flags) + { + BTREE *t; + CURSOR *c; +@@ -140,10 +137,7 @@ __bt_delete(dbp, key, flags) + * 0 on success, 1 on failure + */ + static int +-__bt_stkacq(t, hp, c) +- BTREE *t; +- PAGE **hp; +- CURSOR *c; ++__bt_stkacq(BTREE *t, PAGE **hp, CURSOR *c) + { + BINTERNAL *bi; + EPG *e; +@@ -288,9 +282,7 @@ ret: mpool_put(t->bt_mp, h, 0); + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + static int +-__bt_bdelete(t, key) +- BTREE *t; +- const DBT *key; ++__bt_bdelete(BTREE *t, const DBT *key) + { + EPG *e; + PAGE *h; +@@ -375,9 +367,7 @@ loop: if ((e = __bt_search(t, key, &exact)) == NULL) + * mpool_put's the page + */ + static int +-__bt_pdelete(t, h) +- BTREE *t; +- PAGE *h; ++__bt_pdelete(BTREE *t, PAGE *h) + { + BINTERNAL *bi; + PAGE *pg; +@@ -471,11 +461,7 @@ __bt_pdelete(t, h) + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_dleaf(t, key, h, idx) +- BTREE *t; +- const DBT *key; +- PAGE *h; +- u_int idx; ++__bt_dleaf(BTREE *t, const DBT *key, PAGE *h, u_int idx) + { + BLEAF *bl; + indx_t cnt, *ip, offset; +@@ -536,11 +522,7 @@ __bt_dleaf(t, key, h, idx) + * RET_SUCCESS, RET_ERROR. + */ + static int +-__bt_curdel(t, key, h, idx) +- BTREE *t; +- const DBT *key; +- PAGE *h; +- u_int idx; ++__bt_curdel(BTREE *t, const DBT *key, PAGE *h, u_int idx) + { + CURSOR *c; + EPG e; +@@ -635,9 +617,7 @@ dup2: c->pg.pgno = e.page->pgno; + * h: page to be deleted + */ + int +-__bt_relink(t, h) +- BTREE *t; +- PAGE *h; ++__bt_relink(BTREE *t, PAGE *h) + { + PAGE *pg; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_get.c b/src/plugins/kdb/db2/libdb2/btree/bt_get.c +index b6318211a1..012a341b25 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_get.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_get.c +@@ -60,11 +60,7 @@ static char sccsid[] = "@(#)bt_get.c 8.6 (Berkeley) 7/20/94"; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__bt_get(dbp, key, data, flags) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int flags; ++__bt_get(const DB *dbp, const DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_open.c b/src/plugins/kdb/db2/libdb2/btree/bt_open.c +index d5809a5a93..a2910422eb 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_open.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_open.c +@@ -90,10 +90,8 @@ static int tmp __P((void)); + * + */ + DB * +-__bt_open(fname, flags, mode, openinfo, dflags) +- const char *fname; +- int flags, mode, dflags; +- const BTREEINFO *openinfo; ++__bt_open(const char *fname, int flags, int mode, const BTREEINFO *openinfo, ++ int dflags) + { + struct stat sb; + BTMETA m; +@@ -353,8 +351,7 @@ err: if (t) { + * RET_ERROR, RET_SUCCESS + */ + static int +-nroot(t) +- BTREE *t; ++nroot(BTREE *t) + { + PAGE *meta, *root; + db_pgno_t npg; +@@ -459,8 +456,7 @@ byteorder() + } + + int +-__bt_fd(dbp) +- const DB *dbp; ++__bt_fd(const DB *dbp) + { + BTREE *t; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c b/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c +index 8b1f597912..8301b5d19d 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c +@@ -77,12 +77,7 @@ static char sccsid[] = "@(#)bt_overflow.c 8.5 (Berkeley) 7/16/94"; + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_get(t, p, ssz, buf, bufsz) +- BTREE *t; +- void *p; +- size_t *ssz; +- void **buf; +- size_t *bufsz; ++__ovfl_get(BTREE *t, void *p, size_t *ssz, void **buf, size_t *bufsz) + { + PAGE *h; + db_pgno_t pg; +@@ -136,10 +131,7 @@ __ovfl_get(t, p, ssz, buf, bufsz) + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_put(t, dbt, pg) +- BTREE *t; +- const DBT *dbt; +- db_pgno_t *pg; ++__ovfl_put(BTREE *t, const DBT *dbt, db_pgno_t *pg) + { + PAGE *h, *last; + void *p; +@@ -190,9 +182,7 @@ __ovfl_put(t, dbt, pg) + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_delete(t, p) +- BTREE *t; +- void *p; ++__ovfl_delete(BTREE *t, void *p) + { + PAGE *h; + db_pgno_t pg; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_page.c b/src/plugins/kdb/db2/libdb2/btree/bt_page.c +index 3663cf7f93..38aa39acfb 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_page.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_page.c +@@ -57,9 +57,7 @@ static char sccsid[] = "@(#)bt_page.c 8.4 (Berkeley) 11/2/95"; + * mpool_put's the page. + */ + int +-__bt_free(t, h) +- BTREE *t; +- PAGE *h; ++__bt_free(BTREE *t, PAGE *h) + { + /* Insert the page at the head of the free list. */ + h->prevpg = P_INVALID; +@@ -83,9 +81,7 @@ __bt_free(t, h) + * Pointer to a page, NULL on error. + */ + PAGE * +-__bt_new(t, npg) +- BTREE *t; +- db_pgno_t *npg; ++__bt_new(BTREE *t, db_pgno_t *npg) + { + PAGE *h; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_put.c b/src/plugins/kdb/db2/libdb2/btree/bt_put.c +index 7d6592841a..1303c0baef 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_put.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_put.c +@@ -64,11 +64,7 @@ static EPG *bt_fast __P((BTREE *, const DBT *, const DBT *, int *)); + * tree and R_NOOVERWRITE specified. + */ + int +-__bt_put(dbp, key, data, flags) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int flags; ++__bt_put(const DB *dbp, DBT *key, const DBT *data, u_int flags) + { + BTREE *t; + DBT tkey, tdata; +@@ -272,10 +268,7 @@ u_long bt_cache_hit, bt_cache_miss; + * EPG for new record or NULL if not found. + */ + static EPG * +-bt_fast(t, key, data, exactp) +- BTREE *t; +- const DBT *key, *data; +- int *exactp; ++bt_fast(BTREE *t, const DBT *key, const DBT *data, int *exactp) + { + PAGE *h; + u_int32_t nbytes; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_search.c b/src/plugins/kdb/db2/libdb2/btree/bt_search.c +index c633d14dc6..ed512ccb65 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_search.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_search.c +@@ -63,10 +63,7 @@ static int __bt_sprev __P((BTREE *, PAGE *, const DBT *, int *)); + * the bt_cur field of the tree. A pointer to the field is returned. + */ + EPG * +-__bt_search(t, key, exactp) +- BTREE *t; +- const DBT *key; +- int *exactp; ++__bt_search(BTREE *t, const DBT *key, int *exactp) + { + PAGE *h; + indx_t base, idx, lim; +@@ -148,11 +145,7 @@ next: BT_PUSH(t, h->pgno, idx); + * If an exact match found. + */ + static int +-__bt_snext(t, h, key, exactp) +- BTREE *t; +- PAGE *h; +- const DBT *key; +- int *exactp; ++__bt_snext(BTREE *t, PAGE *h, const DBT *key, int *exactp) + { + BINTERNAL *bi; + EPG e; +@@ -228,11 +221,7 @@ __bt_snext(t, h, key, exactp) + * If an exact match found. + */ + static int +-__bt_sprev(t, h, key, exactp) +- BTREE *t; +- PAGE *h; +- const DBT *key; +- int *exactp; ++__bt_sprev(BTREE *t, PAGE *h, const DBT *key, int *exactp) + { + BINTERNAL *bi; + EPG e; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_seq.c b/src/plugins/kdb/db2/libdb2/btree/bt_seq.c +index 2c8c2de96c..97db44abc8 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_seq.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_seq.c +@@ -102,10 +102,7 @@ static int bt_rseq_prev(BTREE *, EPG *); + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + int +-__bt_seq(dbp, key, data, flags) +- const DB *dbp; +- DBT *key, *data; +- u_int flags; ++__bt_seq(const DB *dbp, DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG e; +@@ -179,11 +176,7 @@ __bt_seq(dbp, key, data, flags) + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + static int +-__bt_seqset(t, ep, key, flags) +- BTREE *t; +- EPG *ep; +- DBT *key; +- int flags; ++__bt_seqset(BTREE *t, EPG *ep, DBT *key, int flags) + { + PAGE *h; + db_pgno_t pg; +@@ -273,10 +266,7 @@ __bt_seqset(t, ep, key, flags) + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + static int +-__bt_seqadv(t, ep, flags) +- BTREE *t; +- EPG *ep; +- int flags; ++__bt_seqadv(BTREE *t, EPG *ep, int flags) + { + CURSOR *c; + PAGE *h; +@@ -495,11 +485,7 @@ bt_rseq_prev(BTREE *t, EPG *ep) + * or RET_SPECIAL if no such key exists. + */ + static int +-__bt_first(t, key, erval, exactp) +- BTREE *t; +- const DBT *key; +- EPG *erval; +- int *exactp; ++__bt_first(BTREE *t, const DBT *key, EPG *erval, int *exactp) + { + PAGE *h, *hprev; + EPG *ep, save; +@@ -596,10 +582,7 @@ __bt_first(t, key, erval, exactp) + * index: page index + */ + void +-__bt_setcur(t, pgno, idx) +- BTREE *t; +- db_pgno_t pgno; +- u_int idx; ++__bt_setcur(BTREE *t, db_pgno_t pgno, u_int idx) + { + /* Lose any already deleted key. */ + if (t->bt_cursor.key.data != NULL) { +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_split.c b/src/plugins/kdb/db2/libdb2/btree/bt_split.c +index c7e4e72a90..8901bd64be 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_split.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_split.c +@@ -79,13 +79,8 @@ u_long bt_rootsplit, bt_split, bt_sortsplit, bt_pfxsaved; + * RET_ERROR, RET_SUCCESS + */ + int +-__bt_split(t, sp, key, data, flags, ilen, argskip) +- BTREE *t; +- PAGE *sp; +- const DBT *key, *data; +- int flags; +- size_t ilen; +- u_int32_t argskip; ++__bt_split(BTREE *t, PAGE *sp, const DBT *key, const DBT *data, int flags, ++ size_t ilen, u_int32_t argskip) + { + BINTERNAL *bi = NULL; + BLEAF *bl = NULL, *tbl; +@@ -345,11 +340,7 @@ err2: mpool_put(t->bt_mp, l, 0); + * Pointer to page in which to insert or NULL on error. + */ + static PAGE * +-bt_page(t, h, lp, rp, skip, ilen) +- BTREE *t; +- PAGE *h, **lp, **rp; +- indx_t *skip; +- size_t ilen; ++bt_page(BTREE *t, PAGE *h, PAGE **lp, PAGE **rp, indx_t *skip, size_t ilen) + { + PAGE *l, *r, *tp; + db_pgno_t npg; +@@ -450,11 +441,7 @@ bt_page(t, h, lp, rp, skip, ilen) + * Pointer to page in which to insert or NULL on error. + */ + static PAGE * +-bt_root(t, h, lp, rp, skip, ilen) +- BTREE *t; +- PAGE *h, **lp, **rp; +- indx_t *skip; +- size_t ilen; ++bt_root(BTREE *t, PAGE *h, PAGE **lp, PAGE **rp, indx_t *skip, size_t ilen) + { + PAGE *l, *r, *tp; + db_pgno_t lnpg, rnpg; +@@ -497,9 +484,7 @@ bt_root(t, h, lp, rp, skip, ilen) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_rroot(t, h, l, r) +- BTREE *t; +- PAGE *h, *l, *r; ++bt_rroot(BTREE *t, PAGE *h, PAGE *l, PAGE *r) + { + char *dest; + +@@ -537,9 +522,7 @@ bt_rroot(t, h, l, r) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_broot(t, h, l, r) +- BTREE *t; +- PAGE *h, *l, *r; ++bt_broot(BTREE *t, PAGE *h, PAGE *l, PAGE *r) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -617,11 +600,7 @@ bt_broot(t, h, l, r) + * Pointer to page in which to insert. + */ + static PAGE * +-bt_psplit(t, h, l, r, pskip, ilen) +- BTREE *t; +- PAGE *h, *l, *r; +- indx_t *pskip; +- size_t ilen; ++bt_psplit(BTREE *t, PAGE *h, PAGE *l, PAGE *r, indx_t *pskip, size_t ilen) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -796,9 +775,7 @@ bt_psplit(t, h, l, r, pskip, ilen) + * RET_SUCCESS, RET_ERROR. + */ + static int +-bt_preserve(t, pg) +- BTREE *t; +- db_pgno_t pg; ++bt_preserve(BTREE *t, db_pgno_t pg) + { + PAGE *h; + +@@ -824,8 +801,7 @@ bt_preserve(t, pg) + * all the way back to bt_split/bt_rroot and it's not very clean. + */ + static recno_t +-rec_total(h) +- PAGE *h; ++rec_total(PAGE *h) + { + recno_t recs; + indx_t nxt, top; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_utils.c b/src/plugins/kdb/db2/libdb2/btree/bt_utils.c +index be2f24f219..13d1f2c84f 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_utils.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_utils.c +@@ -64,11 +64,8 @@ static char sccsid[] = "@(#)bt_utils.c 8.8 (Berkeley) 7/20/94"; + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_ret(t, e, key, rkey, data, rdata, copy) +- BTREE *t; +- EPG *e; +- DBT *key, *rkey, *data, *rdata; +- int copy; ++__bt_ret(BTREE *t, EPG *e, DBT *key, DBT *rkey, DBT *data, DBT *rdata, ++ int copy) + { + BLEAF *bl; + void *p; +@@ -150,10 +147,7 @@ dataonly: + * > 0 if k1 is > record + */ + int +-__bt_cmp(t, k1, e) +- BTREE *t; +- const DBT *k1; +- EPG *e; ++__bt_cmp(BTREE *t, const DBT *k1, EPG *e) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -213,8 +207,7 @@ __bt_cmp(t, k1, e) + * > 0 if a is > b + */ + int +-__bt_defcmp(a, b) +- const DBT *a, *b; ++__bt_defcmp(const DBT *a, const DBT *b) + { + size_t len; + u_char *p1, *p2; +@@ -243,8 +236,7 @@ __bt_defcmp(a, b) + * Number of bytes needed to distinguish b from a. + */ + size_t +-__bt_defpfx(a, b) +- const DBT *a, *b; ++__bt_defpfx(const DBT *a, const DBT *b) + { + u_char *p1, *p2; + size_t cnt, len; +diff --git a/src/plugins/kdb/db2/libdb2/db/db.c b/src/plugins/kdb/db2/libdb2/db/db.c +index fba7795342..f85484f077 100644 +--- a/src/plugins/kdb/db2/libdb2/db/db.c ++++ b/src/plugins/kdb/db2/libdb2/db/db.c +@@ -45,11 +45,8 @@ static char sccsid[] = "@(#)db.c 8.4 (Berkeley) 2/21/94"; + #include "db-int.h" + + DB * +-kdb2_dbopen(fname, flags, mode, type, openinfo) +- const char *fname; +- int flags, mode; +- DBTYPE type; +- const void *openinfo; ++kdb2_dbopen(const char *fname, int flags, int mode, DBTYPE type, ++ const void *openinfo) + { + + #define DB_FLAGS (DB_LOCK | DB_SHMEM | DB_TXN) +@@ -74,7 +71,7 @@ kdb2_dbopen(fname, flags, mode, type, openinfo) + } + + static int +-__dberr() ++__dberr(void) + { + return (RET_ERROR); + } +@@ -86,14 +83,15 @@ __dberr() + * dbp: pointer to the DB structure. + */ + void +-__dbpanic(dbp) +- DB *dbp; ++__dbpanic(DB *dbp) + { + /* The only thing that can succeed is a close. */ +- dbp->del = (int (*)())__dberr; +- dbp->fd = (int (*)())__dberr; +- dbp->get = (int (*)())__dberr; +- dbp->put = (int (*)())__dberr; +- dbp->seq = (int (*)())__dberr; +- dbp->sync = (int (*)())__dberr; ++ dbp->del = (int (*)(const struct __db *, const DBT *, u_int))__dberr; ++ dbp->fd = (int (*)(const struct __db *))__dberr; ++ dbp->get = (int (*)(const struct __db *, const DBT *, DBT *, ++ u_int))__dberr; ++ dbp->put = (int (*)(const struct __db *, DBT *, const DBT *, ++ u_int))__dberr; ++ dbp->seq = (int (*)(const struct __db *, DBT *, DBT *, u_int))__dberr; ++ dbp->sync = (int (*)(const struct __db *, u_int))__dberr; + } +diff --git a/src/plugins/kdb/db2/libdb2/hash/dbm.c b/src/plugins/kdb/db2/libdb2/hash/dbm.c +index 4878cbc0b6..2dca256dc3 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/dbm.c ++++ b/src/plugins/kdb/db2/libdb2/hash/dbm.c +@@ -69,8 +69,7 @@ static DBM *__cur_db; + static void no_open_db __P((void)); + + int +-kdb2_dbminit(file) +- char *file; ++kdb2_dbminit(char *file) + { + if (__cur_db != NULL) + (void)kdb2_dbm_close(__cur_db); +@@ -82,8 +81,7 @@ kdb2_dbminit(file) + } + + datum +-kdb2_fetch(key) +- datum key; ++kdb2_fetch(datum key) + { + datum item; + +@@ -111,8 +109,7 @@ kdb2_firstkey() + } + + datum +-kdb2_nextkey(key) +- datum key; ++kdb2_nextkey(datum key) + { + datum item; + +@@ -126,8 +123,7 @@ kdb2_nextkey(key) + } + + int +-kdb2_delete(key) +- datum key; ++kdb2_delete(datum key) + { + if (__cur_db == NULL) { + no_open_db(); +@@ -137,8 +133,7 @@ kdb2_delete(key) + } + + int +-kdb2_store(key, dat) +- datum key, dat; ++kdb2_store(datum key, datum dat) + { + if (__cur_db == NULL) { + no_open_db(); +@@ -159,9 +154,7 @@ no_open_db() + * NULL on failure + */ + DBM * +-kdb2_dbm_open(file, flags, mode) +- const char *file; +- int flags, mode; ++kdb2_dbm_open(const char *file, int flags, int mode) + { + HASHINFO info; + char path[MAXPATHLEN]; +@@ -183,8 +176,7 @@ kdb2_dbm_open(file, flags, mode) + * Nothing. + */ + void +-kdb2_dbm_close(db) +- DBM *db; ++kdb2_dbm_close(DBM *db) + { + (void)(db->close)(db); + } +@@ -195,9 +187,7 @@ kdb2_dbm_close(db) + * NULL on failure + */ + datum +-kdb2_dbm_fetch(db, key) +- DBM *db; +- datum key; ++kdb2_dbm_fetch(DBM *db, datum key) + { + datum retval; + int status; +@@ -226,8 +216,7 @@ kdb2_dbm_fetch(db, key) + * NULL on failure + */ + datum +-kdb2_dbm_firstkey(db) +- DBM *db; ++kdb2_dbm_firstkey(DBM *db) + { + int status; + datum retkey; +@@ -254,8 +243,7 @@ kdb2_dbm_firstkey(db) + * NULL on failure + */ + datum +-kdb2_dbm_nextkey(db) +- DBM *db; ++kdb2_dbm_nextkey(DBM *db) + { + int status; + datum retkey; +@@ -282,9 +270,7 @@ kdb2_dbm_nextkey(db) + * <0 failure + */ + int +-kdb2_dbm_delete(db, key) +- DBM *db; +- datum key; ++kdb2_dbm_delete(DBM *db, datum key) + { + int status; + +@@ -310,10 +296,7 @@ kdb2_dbm_delete(db, key) + * 1 if DBM_INSERT and entry exists + */ + int +-kdb2_dbm_store(db, key, content, flags) +- DBM *db; +- datum key, content; +- int flags; ++kdb2_dbm_store(DBM *db, datum key, datum content, int flags) + { + #ifdef NEED_COPY + DBT k, c; +@@ -331,8 +314,7 @@ kdb2_dbm_store(db, key, content, flags) + } + + int +-kdb2_dbm_error(db) +- DBM *db; ++kdb2_dbm_error(DBM *db) + { + HTAB *hp; + +@@ -341,8 +323,7 @@ kdb2_dbm_error(db) + } + + int +-kdb2_dbm_clearerr(db) +- DBM *db; ++kdb2_dbm_clearerr(DBM *db) + { + HTAB *hp; + +@@ -352,8 +333,7 @@ kdb2_dbm_clearerr(db) + } + + int +-kdb2_dbm_dirfno(db) +- DBM *db; ++kdb2_dbm_dirfno(DBM *db) + { + return(((HTAB *)db->internal)->fp); + } +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c +index 686a960c96..9528b62538 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash.c +@@ -95,10 +95,8 @@ u_int32_t hash_accesses, hash_collisions, hash_expansions, hash_overflows, + /* OPEN/CLOSE */ + + extern DB * +-__kdb2_hash_open(file, flags, mode, info, dflags) +- const char *file; +- int flags, mode, dflags; +- const HASHINFO *info; /* Special directives for create */ ++__kdb2_hash_open(const char *file, int flags, int mode, const HASHINFO *info, ++ int dflags) + { + struct stat statbuf; + DB *dbp; +@@ -261,8 +259,7 @@ error0: + } + + static int32_t +-hash_close(dbp) +- DB *dbp; ++hash_close(DB *dbp) + { + HTAB *hashp; + int32_t retval; +@@ -277,8 +274,7 @@ hash_close(dbp) + } + + static int32_t +-hash_fd(dbp) +- const DB *dbp; ++hash_fd(const DB *dbp) + { + HTAB *hashp; + +@@ -295,10 +291,7 @@ hash_fd(dbp) + + /************************** LOCAL CREATION ROUTINES **********************/ + static HTAB * +-init_hash(hashp, file, info) +- HTAB *hashp; +- const char *file; +- const HASHINFO *info; ++init_hash(HTAB *hashp, const char *file, const HASHINFO *info) + { + struct stat statbuf; + +@@ -350,9 +343,7 @@ init_hash(hashp, file, info) + * Returns 0 on No Error + */ + static int32_t +-init_htab(hashp, nelem) +- HTAB *hashp; +- int32_t nelem; ++init_htab(HTAB *hashp, int32_t nelem) + { + int32_t l2, nbuckets; + +@@ -404,9 +395,7 @@ init_htab(hashp, nelem) + * Functions to get/put hash header. We access the file directly. + */ + static u_int32_t +-hget_header(hashp, page_size) +- HTAB *hashp; +- u_int32_t page_size; ++hget_header(HTAB *hashp, u_int32_t page_size) + { + u_int32_t num_copied; + u_int8_t *hdr_dest; +@@ -432,8 +421,7 @@ hget_header(hashp, page_size) + } + + static void +-hput_header(hashp) +- HTAB *hashp; ++hput_header(HTAB *hashp) + { + HASHHDR *whdrp; + #if DB_BYTE_ORDER == DB_LITTLE_ENDIAN +@@ -463,8 +451,7 @@ hput_header(hashp) + * structure, freeing all allocated space. + */ + static int32_t +-hdestroy(hashp) +- HTAB *hashp; ++hdestroy(HTAB *hashp) + { + int32_t save_errno; + +@@ -550,9 +537,7 @@ hdestroy(hashp) + * -1 ERROR + */ + static int32_t +-hash_sync(dbp, flags) +- const DB *dbp; +- u_int32_t flags; ++hash_sync(const DB *dbp, u_int32_t flags) + { + HTAB *hashp; + +@@ -571,8 +556,7 @@ hash_sync(dbp, flags) + * -1 indicates that errno should be set + */ + static int32_t +-flush_meta(hashp) +- HTAB *hashp; ++flush_meta(HTAB *hashp) + { + int32_t i; + +@@ -608,11 +592,7 @@ flush_meta(hashp) + /* *** make sure this is true! */ + + static int32_t +-hash_get(dbp, key, data, flag) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int32_t flag; ++hash_get(const DB *dbp, const DBT *key, DBT *data, u_int32_t flag) + { + HTAB *hashp; + +@@ -625,11 +605,7 @@ hash_get(dbp, key, data, flag) + } + + static int32_t +-hash_put(dbp, key, data, flag) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int32_t flag; ++hash_put(const DB *dbp, DBT *key, const DBT *data, u_int32_t flag) + { + HTAB *hashp; + +@@ -647,10 +623,7 @@ hash_put(dbp, key, data, flag) + } + + static int32_t +-hash_delete(dbp, key, flag) +- const DB *dbp; +- const DBT *key; +- u_int32_t flag; /* Ignored */ ++hash_delete(const DB *dbp, const DBT *key, u_int32_t flag) + { + HTAB *hashp; + +@@ -671,11 +644,7 @@ hash_delete(dbp, key, flag) + * Assume that hashp has been set in wrapper routine. + */ + static int32_t +-hash_access(hashp, action, key, val) +- HTAB *hashp; +- ACTION action; +- const DBT *key; +- DBT *val; ++hash_access(HTAB *hashp, ACTION action, const DBT *key, DBT *val) + { + DBT page_key, page_val; + CURSOR cursor; +@@ -792,8 +761,7 @@ found: __get_item_done(hashp, &cursor); + + /* ****************** CURSORS ********************************** */ + CURSOR * +-__cursor_creat(dbp) +- const DB *dbp; ++__cursor_creat(const DB *dbp) + { + CURSOR *new_curs; + HTAB *hashp; +@@ -824,11 +792,7 @@ __cursor_creat(dbp) + } + + static int32_t +-cursor_get(dbp, cursorp, key, val, flags) +- const DB *dbp; +- CURSOR *cursorp; +- DBT *key, *val; +- u_int32_t flags; ++cursor_get(const DB *dbp, CURSOR *cursorp, DBT *key, DBT *val, u_int32_t flags) + { + HTAB *hashp; + ITEM_INFO item_info; +@@ -897,10 +861,7 @@ cursor_get(dbp, cursorp, key, val, flags) + } + + static int32_t +-cursor_delete(dbp, cursor, flags) +- const DB *dbp; +- CURSOR *cursor; +- u_int32_t flags; ++cursor_delete(const DB *dbp, CURSOR *cursor, u_int32_t flags) + { + /* XXX this is empirically determined, so it might not be completely + correct, but it seems to work. At the very least it fixes +@@ -913,10 +874,7 @@ cursor_delete(dbp, cursor, flags) + } + + static int32_t +-hash_seq(dbp, key, val, flag) +- const DB *dbp; +- DBT *key, *val; +- u_int32_t flag; ++hash_seq(const DB *dbp, DBT *key, DBT *val, u_int32_t flag) + { + HTAB *hashp; + +@@ -940,8 +898,7 @@ hash_seq(dbp, key, val, flag) + * -1 ==> Error + */ + int32_t +-__expand_table(hashp) +- HTAB *hashp; ++__expand_table(HTAB *hashp) + { + u_int32_t old_bucket, new_bucket; + int32_t spare_ndx; +@@ -980,10 +937,7 @@ __expand_table(hashp) + } + + u_int32_t +-__call_hash(hashp, k, len) +- HTAB *hashp; +- int8_t *k; +- int32_t len; ++__call_hash(HTAB *hashp, int8_t *k, int32_t len) + { + u_int32_t n, bucket; + +@@ -999,8 +953,7 @@ __call_hash(hashp, k, len) + * Hashp->hdr needs to be byteswapped. + */ + static void +-swap_header_copy(srcp, destp) +- HASHHDR *srcp, *destp; ++swap_header_copy(HASHHDR *srcp, HASHHDR *destp) + { + int32_t i; + +@@ -1025,8 +978,7 @@ swap_header_copy(srcp, destp) + } + + static void +-swap_header(hashp) +- HTAB *hashp; ++swap_header(HTAB *hashp) + { + HASHHDR *hdrp; + int32_t i; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c b/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c +index 4b95278f53..6befb7a57e 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c +@@ -83,10 +83,7 @@ static int32_t collect_data __P((HTAB *, PAGE16 *, int32_t)); + * -1 ==> ERROR + */ + int32_t +-__big_insert(hashp, pagep, key, val) +- HTAB *hashp; +- PAGE16 *pagep; +- const DBT *key, *val; ++__big_insert(HTAB *hashp, PAGE16 *pagep, const DBT *key, const DBT *val) + { + size_t key_size, val_size; + indx_t key_move_bytes, val_move_bytes; +@@ -185,11 +182,7 @@ __big_delete(hashp, pagep, ndx) + * -1 error + */ + int32_t +-__find_bigpair(hashp, cursorp, key, size) +- HTAB *hashp; +- CURSOR *cursorp; +- int8_t *key; +- int32_t size; ++__find_bigpair(HTAB *hashp, CURSOR *cursorp, int8_t *key, int32_t size) + { + PAGE16 *pagep, *hold_pagep; + db_pgno_t next_pgno; +@@ -257,11 +250,7 @@ __find_bigpair(hashp, cursorp, key, size) + * Fill in the key and data for this big pair. + */ + int32_t +-__big_keydata(hashp, pagep, key, val, ndx) +- HTAB *hashp; +- PAGE16 *pagep; +- DBT *key, *val; +- int32_t ndx; ++__big_keydata(HTAB *hashp, PAGE16 *pagep, DBT *key, DBT *val, int32_t ndx) + { + ITEM_INFO ii; + PAGE16 *key_pagep; +@@ -315,11 +304,8 @@ __get_bigkey(hashp, pagep, ndx, key) + * Return the big key and data indicated in item_info. + */ + int32_t +-__big_return(hashp, item_info, val, on_bigkey_page) +- HTAB *hashp; +- ITEM_INFO *item_info; +- DBT *val; +- int32_t on_bigkey_page; ++__big_return(HTAB *hashp, ITEM_INFO *item_info, DBT *val, ++ int32_t on_bigkey_page) + { + PAGE16 *pagep; + db_pgno_t next_pgno; +@@ -366,11 +352,7 @@ __big_return(hashp, item_info, val, on_bigkey_page) + * Return total length of data; -1 if error. + */ + static int32_t +-collect_key(hashp, pagep, len, last_page) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t len; +- db_pgno_t *last_page; ++collect_key(HTAB *hashp, PAGE16 *pagep, int32_t len, db_pgno_t *last_page) + { + PAGE16 *next_pagep; + int32_t totlen, retval; +@@ -434,10 +416,7 @@ collect_key(hashp, pagep, len, last_page) + * Return total length of data; -1 if error. + */ + static int32_t +-collect_data(hashp, pagep, len) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t len; ++collect_data(HTAB *hashp, PAGE16 *pagep, int32_t len) + { + PAGE16 *next_pagep; + int32_t totlen, retval; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_func.c b/src/plugins/kdb/db2/libdb2/hash/hash_func.c +index 1dee694608..f169be685e 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_func.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_func.c +@@ -66,9 +66,7 @@ u_int32_t (*__default_hash) __P((const void *, size_t)) = hash4; + + #if 0 + static u_int32_t +-hash1(key, len) +- const void *key; +- size_t len; ++hash1(const void *key, size_t len) + { + u_int32_t h; + u_int8_t *k; +@@ -88,9 +86,7 @@ hash1(key, len) + #define dcharhash(h, c) ((h) = 0x63c63cd9*(h) + 0x9c39c33d + (c)) + + static u_int32_t +-hash2(key, len) +- const void *key; +- size_t len; ++hash2(const void *key, size_t len) + { + u_int32_t h; + u_int8_t *e, c, *k; +@@ -116,9 +112,7 @@ hash2(key, len) + * Ozan Yigit's original sdbm hash. + */ + static u_int32_t +-hash3(key, len) +- const void *key; +- size_t len; ++hash3(const void *key, size_t len) + { + u_int32_t n, loop; + u_int8_t *k; +@@ -159,9 +153,7 @@ hash3(key, len) + + /* Chris Torek's hash function. */ + static u_int32_t +-hash4(key, len) +- const void *key; +- size_t len; ++hash4(const void *key, size_t len) + { + u_int32_t h, loop; + const u_int8_t *k; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_log2.c b/src/plugins/kdb/db2/libdb2/hash/hash_log2.c +index 8c710e5d21..7fdfd854d2 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_log2.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_log2.c +@@ -44,8 +44,7 @@ static char sccsid[] = "@(#)hash_log2.c 8.4 (Berkeley) 11/7/95"; + #include "extern.h" + + u_int32_t +-__kdb2_log2(num) +- u_int32_t num; ++__kdb2_log2(u_int32_t num) + { + u_int32_t i, limit; + +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_page.c b/src/plugins/kdb/db2/libdb2/hash/hash_page.c +index 0da357108a..dba29e0cb5 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_page.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_page.c +@@ -84,11 +84,8 @@ static void account_page(HTAB *, db_pgno_t, int); + #endif + + u_int32_t +-__get_item(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + db_pgno_t next_pgno; + int32_t i; +@@ -159,9 +156,7 @@ __get_item(hashp, cursorp, key, val, item_info) + } + + u_int32_t +-__get_item_reset(hashp, cursorp) +- HTAB *hashp; +- CURSOR *cursorp; ++__get_item_reset(HTAB *hashp, CURSOR *cursorp) + { + if (cursorp->pagep) + __put_page(hashp, cursorp->pagep, A_RAW, 0); +@@ -174,9 +169,7 @@ __get_item_reset(hashp, cursorp) + } + + u_int32_t +-__get_item_done(hashp, cursorp) +- HTAB *hashp; +- CURSOR *cursorp; ++__get_item_done(HTAB *hashp, CURSOR *cursorp) + { + if (cursorp->pagep) + __put_page(hashp, cursorp->pagep, A_RAW, 0); +@@ -190,11 +183,8 @@ __get_item_done(hashp, cursorp) + } + + u_int32_t +-__get_item_first(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item_first(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + __get_item_reset(hashp, cursorp); + cursorp->bucket = 0; +@@ -206,11 +196,8 @@ __get_item_first(hashp, cursorp, key, val, item_info) + * just returns the page number and index of the bigkey pointer pair. + */ + u_int32_t +-__get_item_next(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item_next(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + int status; + +@@ -224,9 +211,7 @@ __get_item_next(hashp, cursorp, key, val, item_info) + * Put a non-big pair on a page. + */ + static void +-putpair(p, key, val) +- PAGE8 *p; +- const DBT *key, *val; ++putpair(PAGE8 *p, const DBT *key, const DBT *val) + { + u_int16_t *pagep, n, off; + +@@ -275,10 +260,7 @@ prev_realkey(pagep, n) + * -1 error + */ + extern int32_t +-__delpair(hashp, cursorp, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- ITEM_INFO *item_info; ++__delpair(HTAB *hashp, CURSOR *cursorp, ITEM_INFO *item_info) + { + PAGE16 *pagep; + indx_t ndx; +@@ -412,9 +394,7 @@ __delpair(hashp, cursorp, item_info) + } + + extern int32_t +-__split_page(hashp, obucket, nbucket) +- HTAB *hashp; +- u_int32_t obucket, nbucket; ++__split_page(HTAB *hashp, u_int32_t obucket, u_int32_t nbucket) + { + DBT key, val; + ITEM_INFO old_ii, new_ii; +@@ -661,9 +641,7 @@ add_bigptr(hashp, item_info, big_pgno) + * NULL on error + */ + extern PAGE16 * +-__add_ovflpage(hashp, pagep) +- HTAB *hashp; +- PAGE16 *pagep; ++__add_ovflpage(HTAB *hashp, PAGE16 *pagep) + { + PAGE16 *new_pagep; + u_int16_t ovfl_num; +@@ -768,10 +746,7 @@ page_init(hashp, pagep, pgno, type) + } + + int32_t +-__new_page(hashp, addr, addr_type) +- HTAB *hashp; +- u_int32_t addr; +- int32_t addr_type; ++__new_page(HTAB *hashp, u_int32_t addr, int32_t addr_type) + { + db_pgno_t paddr; + PAGE16 *pagep; +@@ -804,10 +779,7 @@ __new_page(hashp, addr, addr_type) + } + + int32_t +-__delete_page(hashp, pagep, page_type) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t page_type; ++__delete_page(HTAB *hashp, PAGE16 *pagep, int32_t page_type) + { + if (page_type == A_OVFL) + __free_ovflpage(hashp, pagep); +@@ -815,9 +787,7 @@ __delete_page(hashp, pagep, page_type) + } + + static u_int8_t +-is_bitmap_pgno(hashp, pgno) +- HTAB *hashp; +- db_pgno_t pgno; ++is_bitmap_pgno(HTAB *hashp, db_pgno_t pgno) + { + int32_t i; + +@@ -828,10 +798,7 @@ is_bitmap_pgno(hashp, pgno) + } + + void +-__pgin_routine(pg_cookie, pgno, page) +- void *pg_cookie; +- db_pgno_t pgno; +- void *page; ++__pgin_routine(void *pg_cookie, db_pgno_t pgno, void *page) + { + HTAB *hashp; + PAGE16 *pagep; +@@ -868,10 +835,7 @@ __pgin_routine(pg_cookie, pgno, page) + } + + void +-__pgout_routine(pg_cookie, pgno, page) +- void *pg_cookie; +- db_pgno_t pgno; +- void *page; ++__pgout_routine(void *pg_cookie, db_pgno_t pgno, void *page) + { + HTAB *hashp; + PAGE16 *pagep; +@@ -905,10 +869,7 @@ __pgout_routine(pg_cookie, pgno, page) + * -1 ==>failure + */ + extern int32_t +-__put_page(hashp, pagep, addr_type, is_dirty) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t addr_type, is_dirty; ++__put_page(HTAB *hashp, PAGE16 *pagep, int32_t addr_type, int32_t is_dirty) + { + #if DEBUG_SLOW + account_page(hashp, +@@ -924,10 +885,7 @@ __put_page(hashp, pagep, addr_type, is_dirty) + * -1 indicates FAILURE + */ + extern PAGE16 * +-__get_page(hashp, addr, addr_type) +- HTAB *hashp; +- u_int32_t addr; +- int32_t addr_type; ++__get_page(HTAB *hashp, u_int32_t addr, int32_t addr_type) + { + PAGE16 *pagep; + db_pgno_t paddr; +@@ -958,8 +916,7 @@ __get_page(hashp, addr, addr_type) + } + + static void +-swap_page_header_in(pagep) +- PAGE16 *pagep; ++swap_page_header_in(PAGE16 *pagep) + { + u_int32_t i; + +@@ -977,8 +934,7 @@ swap_page_header_in(pagep) + } + + static void +-swap_page_header_out(pagep) +- PAGE16 *pagep; ++swap_page_header_out(PAGE16 *pagep) + { + u_int32_t i; + +@@ -1001,9 +957,7 @@ swap_page_header_out(pagep) + * once they are read in. + */ + extern int32_t +-__ibitmap(hashp, pnum, nbits, ndx) +- HTAB *hashp; +- int32_t pnum, nbits, ndx; ++__ibitmap(HTAB *hashp, int32_t pnum, int32_t nbits, int32_t ndx) + { + u_int32_t *ip; + int32_t clearbytes, clearints; +@@ -1027,8 +981,7 @@ __ibitmap(hashp, pnum, nbits, ndx) + } + + static u_int32_t +-first_free(map) +- u_int32_t map; ++first_free(u_int32_t map) + { + u_int32_t i, mask; + +@@ -1044,8 +997,7 @@ first_free(map) + * returns 0 on error + */ + static u_int16_t +-overflow_page(hashp) +- HTAB *hashp; ++overflow_page(HTAB *hashp) + { + u_int32_t *freep; + u_int32_t bit, first_page, free_bit, free_page, i, in_use_bits, j; +@@ -1206,9 +1158,7 @@ found: + + #ifdef DEBUG + int +-bucket_to_page(hashp, n) +- HTAB *hashp; +- int n; ++bucket_to_page(HTAB *hashp, int n) + { + int ret_val; + +@@ -1219,9 +1169,7 @@ bucket_to_page(hashp, n) + } + + int32_t +-oaddr_to_page(hashp, n) +- HTAB *hashp; +- int n; ++oaddr_to_page(HTAB *hashp, int n) + { + int ret_val, temp; + +@@ -1234,9 +1182,7 @@ oaddr_to_page(hashp, n) + #endif /* DEBUG */ + + static indx_t +-page_to_oaddr(hashp, pgno) +- HTAB *hashp; +- db_pgno_t pgno; ++page_to_oaddr(HTAB *hashp, db_pgno_t pgno) + { + int32_t sp, ret_val; + +@@ -1268,9 +1214,7 @@ page_to_oaddr(hashp, pgno) + * Mark this overflow page as free. + */ + extern void +-__free_ovflpage(hashp, pagep) +- HTAB *hashp; +- PAGE16 *pagep; ++__free_ovflpage(HTAB *hashp, PAGE16 *pagep) + { + u_int32_t *freep; + u_int32_t bit_address, free_page, free_bit; +@@ -1307,9 +1251,7 @@ __free_ovflpage(hashp, pagep) + } + + static u_int32_t * +-fetch_bitmap(hashp, ndx) +- HTAB *hashp; +- int32_t ndx; ++fetch_bitmap(HTAB *hashp, int32_t ndx) + { + if (ndx >= hashp->nmaps) + return (NULL); +@@ -1322,10 +1264,7 @@ fetch_bitmap(hashp, ndx) + + #ifdef DEBUG_SLOW + static void +-account_page(hashp, pgno, inout) +- HTAB *hashp; +- db_pgno_t pgno; +- int inout; ++account_page(HTAB *hashp, db_pgno_t pgno, int inout) + { + static struct { + db_pgno_t pgno; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hsearch.c b/src/plugins/kdb/db2/libdb2/hash/hsearch.c +index 02ff7ef843..ffcdfcf294 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hsearch.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hsearch.c +@@ -50,8 +50,7 @@ static DB *dbp = NULL; + static ENTRY retval; + + extern int +-hcreate(nel) +- u_int nel; ++hcreate(u_int nel) + { + HASHINFO info; + +@@ -66,9 +65,7 @@ hcreate(nel) + } + + extern ENTRY * +-hsearch(item, action) +- ENTRY item; +- ACTION action; ++hsearch(ENTRY item, ACTION action) + { + DBT key, val; + int status; +@@ -98,7 +95,7 @@ hsearch(item, action) + } + + extern void +-hdestroy() ++hdestroy(void) + { + if (dbp) { + (void)(dbp->close)(dbp); +diff --git a/src/plugins/kdb/db2/libdb2/mpool/mpool.c b/src/plugins/kdb/db2/libdb2/mpool/mpool.c +index 0fcfd4ac2b..028fb180ca 100644 +--- a/src/plugins/kdb/db2/libdb2/mpool/mpool.c ++++ b/src/plugins/kdb/db2/libdb2/mpool/mpool.c +@@ -56,10 +56,7 @@ static int mpool_write __P((MPOOL *, BKT *)); + * Initialize a memory pool. + */ + MPOOL * +-mpool_open(key, fd, pagesize, maxcache) +- void *key; +- int fd; +- db_pgno_t pagesize, maxcache; ++mpool_open(void *key, int fd, db_pgno_t pagesize, db_pgno_t maxcache) + { + struct stat sb; + MPOOL *mp; +@@ -96,11 +93,8 @@ mpool_open(key, fd, pagesize, maxcache) + * Initialize input/output filters. + */ + void +-mpool_filter(mp, pgin, pgout, pgcookie) +- MPOOL *mp; +- void (*pgin) __P((void *, db_pgno_t, void *)); +- void (*pgout) __P((void *, db_pgno_t, void *)); +- void *pgcookie; ++mpool_filter(MPOOL *mp, void (*pgin) __P((void *, db_pgno_t, void *)), ++ void (*pgout) __P((void *, db_pgno_t, void *)), void *pgcookie) + { + mp->pgin = pgin; + mp->pgout = pgout; +@@ -112,10 +106,7 @@ mpool_filter(mp, pgin, pgout, pgcookie) + * Get a new page of memory. + */ + void * +-mpool_new(mp, pgnoaddr, flags) +- MPOOL *mp; +- db_pgno_t *pgnoaddr; +- u_int flags; ++mpool_new(MPOOL *mp, db_pgno_t *pgnoaddr, u_int flags) + { + struct _hqh *head; + BKT *bp; +@@ -149,9 +140,7 @@ mpool_new(mp, pgnoaddr, flags) + } + + int +-mpool_delete(mp, page) +- MPOOL *mp; +- void *page; ++mpool_delete(MPOOL *mp, void *page) + { + struct _hqh *head; + BKT *bp; +@@ -180,10 +169,7 @@ mpool_delete(mp, page) + * Get a page. + */ + void * +-mpool_get(mp, pgno, flags) +- MPOOL *mp; +- db_pgno_t pgno; +- u_int flags; /* XXX not used? */ ++mpool_get(MPOOL *mp, db_pgno_t pgno, u_int flags) + { + struct _hqh *head; + BKT *bp; +@@ -278,10 +264,7 @@ mpool_get(mp, pgno, flags) + * Return a page. + */ + int +-mpool_put(mp, page, flags) +- MPOOL *mp; +- void *page; +- u_int flags; ++mpool_put(MPOOL *mp, void *page, u_int flags) + { + BKT *bp; + +@@ -307,8 +290,7 @@ mpool_put(mp, page, flags) + * Close the buffer pool. + */ + int +-mpool_close(mp) +- MPOOL *mp; ++mpool_close(MPOOL *mp) + { + BKT *bp; + +@@ -328,8 +310,7 @@ mpool_close(mp) + * Sync the pool to disk. + */ + int +-mpool_sync(mp) +- MPOOL *mp; ++mpool_sync(MPOOL *mp) + { + BKT *bp; + +@@ -348,8 +329,7 @@ mpool_sync(mp) + * Get a page from the cache (or create one). + */ + static BKT * +-mpool_bkt(mp) +- MPOOL *mp; ++mpool_bkt(MPOOL *mp) + { + struct _hqh *head; + BKT *bp; +@@ -407,9 +387,7 @@ new: if ((bp = (BKT *)malloc(sizeof(BKT) + mp->pagesize)) == NULL) + * Write a page to disk. + */ + static int +-mpool_write(mp, bp) +- MPOOL *mp; +- BKT *bp; ++mpool_write(MPOOL *mp, BKT *bp) + { + off_t off; + +@@ -451,9 +429,7 @@ mpool_write(mp, bp) + * Lookup a page in the cache. + */ + static BKT * +-mpool_look(mp, pgno) +- MPOOL *mp; +- db_pgno_t pgno; ++mpool_look(MPOOL *mp, db_pgno_t pgno) + { + struct _hqh *head; + BKT *bp; +@@ -478,8 +454,7 @@ mpool_look(mp, pgno) + * Print out cache statistics. + */ + void +-mpool_stat(mp) +- MPOOL *mp; ++mpool_stat(MPOOL *mp) + { + BKT *bp; + int cnt; +@@ -520,8 +495,7 @@ mpool_stat(mp) + } + #else + void +-mpool_stat(mp) +- MPOOL *mp; ++mpool_stat(MPOOL *mp) + { + } + #endif +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_close.c b/src/plugins/kdb/db2/libdb2/recno/rec_close.c +index 4ef4dd1bae..b858e5c909 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_close.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_close.c +@@ -59,8 +59,7 @@ static char sccsid[] = "@(#)rec_close.c 8.9 (Berkeley) 11/18/94"; + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_close(dbp) +- DB *dbp; ++__rec_close(DB *dbp) + { + BTREE *t; + int status; +@@ -108,9 +107,7 @@ __rec_close(dbp) + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_sync(dbp, flags) +- const DB *dbp; +- u_int flags; ++__rec_sync(const DB *dbp, u_int flags) + { + struct iovec iov[2]; + BTREE *t; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_delete.c b/src/plugins/kdb/db2/libdb2/recno/rec_delete.c +index b69c9ad742..7e574df28e 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_delete.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_delete.c +@@ -61,10 +61,7 @@ static int rec_rdelete __P((BTREE *, recno_t)); + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__rec_delete(dbp, key, flags) +- const DB *dbp; +- const DBT *key; +- u_int flags; ++__rec_delete(const DB *dbp, const DBT *key, u_int flags) + { + BTREE *t; + recno_t nrec; +@@ -117,9 +114,7 @@ einval: errno = EINVAL; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + static int +-rec_rdelete(t, nrec) +- BTREE *t; +- recno_t nrec; ++rec_rdelete(BTREE *t, recno_t nrec) + { + EPG *e; + PAGE *h; +@@ -151,10 +146,7 @@ rec_rdelete(t, nrec) + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_dleaf(t, h, idx) +- BTREE *t; +- PAGE *h; +- u_int32_t idx; ++__rec_dleaf(BTREE *t, PAGE *h, u_int32_t idx) + { + RLEAF *rl; + indx_t *ip, cnt, offset; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_get.c b/src/plugins/kdb/db2/libdb2/recno/rec_get.c +index 230b2d4f54..c89cb556fc 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_get.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_get.c +@@ -60,11 +60,7 @@ static char sccsid[] = "@(#)rec_get.c 8.9 (Berkeley) 8/18/94"; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__rec_get(dbp, key, data, flags) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int flags; ++__rec_get(const DB *dbp, const DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +@@ -119,9 +115,7 @@ __rec_get(dbp, key, data, flags) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_fpipe(t, top) +- BTREE *t; +- recno_t top; ++__rec_fpipe(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -175,9 +169,7 @@ __rec_fpipe(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_vpipe(t, top) +- BTREE *t; +- recno_t top; ++__rec_vpipe(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -232,9 +224,7 @@ __rec_vpipe(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_fmap(t, top) +- BTREE *t; +- recno_t top; ++__rec_fmap(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -282,9 +272,7 @@ __rec_fmap(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_vmap(t, top) +- BTREE *t; +- recno_t top; ++__rec_vmap(BTREE *t, recno_t top) + { + DBT data; + u_char *sp, *ep; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_open.c b/src/plugins/kdb/db2/libdb2/recno/rec_open.c +index b0daa7c021..de3fc3f4d0 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_open.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_open.c +@@ -56,10 +56,8 @@ static char sccsid[] = "@(#)rec_open.c 8.12 (Berkeley) 11/18/94"; + #include "recno.h" + + DB * +-__rec_open(fname, flags, mode, openinfo, dflags) +- const char *fname; +- int flags, mode, dflags; +- const RECNOINFO *openinfo; ++__rec_open(const char *fname, int flags, int mode, const RECNOINFO *openinfo, ++ int dflags) + { + BTREE *t; + BTREEINFO btopeninfo; +@@ -228,8 +226,7 @@ err: sverrno = errno; + } + + int +-__rec_fd(dbp) +- const DB *dbp; ++__rec_fd(const DB *dbp) + { + BTREE *t; + +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_put.c b/src/plugins/kdb/db2/libdb2/recno/rec_put.c +index c53c9578e5..8456f1dbf6 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_put.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_put.c +@@ -59,11 +59,7 @@ static char sccsid[] = "@(#)rec_put.c 8.7 (Berkeley) 8/18/94"; + * already in the tree and R_NOOVERWRITE specified. + */ + int +-__rec_put(dbp, key, data, flags) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int flags; ++__rec_put(const DB *dbp, DBT *key, const DBT *data, u_int flags) + { + BTREE *t; + DBT fdata, tdata; +@@ -187,11 +183,7 @@ einval: errno = EINVAL; + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_iput(t, nrec, data, flags) +- BTREE *t; +- recno_t nrec; +- const DBT *data; +- u_int flags; ++__rec_iput(BTREE *t, recno_t nrec, const DBT *data, u_int flags) + { + DBT tdata; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_search.c b/src/plugins/kdb/db2/libdb2/recno/rec_search.c +index 244d79f36d..55e5ba879b 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_search.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_search.c +@@ -61,10 +61,7 @@ static char sccsid[] = "@(#)rec_search.c 8.4 (Berkeley) 7/14/94"; + * the bt_cur field of the tree. A pointer to the field is returned. + */ + EPG * +-__rec_search(t, recno, op) +- BTREE *t; +- recno_t recno; +- enum SRCHOP op; ++__rec_search(BTREE *t, recno_t recno, enum SRCHOP op) + { + indx_t idx; + PAGE *h; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_seq.c b/src/plugins/kdb/db2/libdb2/recno/rec_seq.c +index 8af1378c34..cf48ea24d7 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_seq.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_seq.c +@@ -58,10 +58,7 @@ static char sccsid[] = "@(#)rec_seq.c 8.3 (Berkeley) 7/14/94"; + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + int +-__rec_seq(dbp, key, data, flags) +- const DB *dbp; +- DBT *key, *data; +- u_int flags; ++__rec_seq(const DB *dbp, DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_utils.c b/src/plugins/kdb/db2/libdb2/recno/rec_utils.c +index f757a724f5..2eaa39b4a3 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_utils.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_utils.c +@@ -59,11 +59,7 @@ static char sccsid[] = "@(#)rec_utils.c 8.6 (Berkeley) 7/16/94"; + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_ret(t, e, nrec, key, data) +- BTREE *t; +- EPG *e; +- recno_t nrec; +- DBT *key, *data; ++__rec_ret(BTREE *t, EPG *e, recno_t nrec, DBT *key, DBT *data) + { + RLEAF *rl; + void *p; +diff --git a/src/plugins/kdb/db2/libdb2/test/dbtest.c b/src/plugins/kdb/db2/libdb2/test/dbtest.c +index 5d76b1ddf9..04bf34b90d 100644 +--- a/src/plugins/kdb/db2/libdb2/test/dbtest.c ++++ b/src/plugins/kdb/db2/libdb2/test/dbtest.c +@@ -121,9 +121,7 @@ DB *XXdbp; /* Global for gdb. */ + u_long XXlineno; /* Fast breakpoint for gdb. */ + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern int optind; + extern char *optarg; +@@ -380,8 +378,7 @@ lkey: switch (command) { + #define NOOVERWRITE "put failed, would overwrite key\n" + + void +-compare(db1, db2) +- DBT *db1, *db2; ++compare(DBT *db1, DBT *db2) + { + size_t len; + u_char *p1, *p2; +@@ -402,9 +399,7 @@ compare(db1, db2) + } + + void +-get(dbp, kp) +- DB *dbp; +- DBT *kp; ++get(DB *dbp, DBT *kp) + { + DBT data; + +@@ -437,9 +432,7 @@ get(dbp, kp) + } + + void +-getdata(dbp, kp, dp) +- DB *dbp; +- DBT *kp, *dp; ++getdata(DB *dbp, DBT *kp, DBT *dp) + { + switch (dbp->get(dbp, kp, dp, flags)) { + case 0: +@@ -454,9 +447,7 @@ getdata(dbp, kp, dp) + } + + void +-put(dbp, kp, dp) +- DB *dbp; +- DBT *kp, *dp; ++put(DB *dbp, DBT *kp, DBT *dp) + { + switch (dbp->put(dbp, kp, dp, flags)) { + case 0: +@@ -473,9 +464,7 @@ put(dbp, kp, dp) + } + + void +-rem(dbp, kp) +- DB *dbp; +- DBT *kp; ++rem(DB *dbp, DBT *kp) + { + switch (dbp->del(dbp, kp, flags)) { + case 0: +@@ -502,8 +491,7 @@ rem(dbp, kp) + } + + void +-synk(dbp) +- DB *dbp; ++synk(DB *dbp) + { + switch (dbp->sync(dbp, flags)) { + case 0: +@@ -515,9 +503,7 @@ synk(dbp) + } + + void +-seq(dbp, kp) +- DB *dbp; +- DBT *kp; ++seq(DB *dbp, DBT *kp) + { + DBT data; + +@@ -551,10 +537,7 @@ seq(dbp, kp) + } + + void +-dump(dbp, rev, recurse) +- DB *dbp; +- int rev; +- int recurse; ++dump(DB *dbp, int rev, int recurse) + { + DBT key, data; + int lflags, nflags; +@@ -588,8 +571,7 @@ done: return; + } + + void +-unlinkpg(dbp) +- DB *dbp; ++unlinkpg(DB *dbp) + { + BTREE *t = dbp->internal; + PAGE *h = NULL; +@@ -623,8 +605,7 @@ cleanup: + } + + u_int +-setflags(s) +- char *s; ++setflags(char *s) + { + char *p; + +@@ -648,8 +629,7 @@ setflags(s) + } + + char * +-sflags(lflags) +- int lflags; ++sflags(int lflags) + { + switch (lflags) { + case R_CURSOR: return ("R_CURSOR"); +@@ -667,8 +647,7 @@ sflags(lflags) + } + + DBTYPE +-dbtype(s) +- char *s; ++dbtype(char *s) + { + if (!strcmp(s, "btree")) + return (DB_BTREE); +@@ -681,9 +660,7 @@ dbtype(s) + } + + void * +-setinfo(db_type, s) +- DBTYPE db_type; +- char *s; ++setinfo(DBTYPE db_type, char *s) + { + static BTREEINFO ib; + static HASHINFO ih; +@@ -777,9 +754,7 @@ setinfo(db_type, s) + } + + void * +-rfile(name, lenp) +- char *name; +- size_t *lenp; ++rfile(char *name, size_t *lenp) + { + struct stat sb; + void *p; +@@ -806,9 +781,7 @@ rfile(name, lenp) + } + + void * +-xmalloc(text, len) +- char *text; +- size_t len; ++xmalloc(char *text, size_t len) + { + void *p; + +diff --git a/src/plugins/kdb/db2/pol_xdr.c b/src/plugins/kdb/db2/pol_xdr.c +index e8576337c8..448d4b0f51 100644 +--- a/src/plugins/kdb/db2/pol_xdr.c ++++ b/src/plugins/kdb/db2/pol_xdr.c +@@ -82,7 +82,7 @@ xdr_osa_policy_ent_rec(XDR *xdrs, osa_policy_ent_t objp) + if (!xdr_short(xdrs, &objp->n_tl_data)) + return (FALSE); + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) ++ (xdrproc_t)xdr_krb5_tl_data)) + return FALSE; + } + return (TRUE); +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c +index 0b56ba86a7..7ddea923a3 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c +@@ -186,8 +186,8 @@ static struct _cmd_table { + * The function cmd_lookup returns the structure matching the + * command name and returns NULL if nothing matches. + */ +-static struct _cmd_table *cmd_lookup(name) +- char *name; ++static struct _cmd_table * ++cmd_lookup(const char *name) + { + int i; + +diff --git a/src/plugins/kdb/lmdb/kdb_lmdb.c b/src/plugins/kdb/lmdb/kdb_lmdb.c +index bd288e2236..dbab7967c6 100644 +--- a/src/plugins/kdb/lmdb/kdb_lmdb.c ++++ b/src/plugins/kdb/lmdb/kdb_lmdb.c +@@ -468,13 +468,13 @@ error: + } + + static krb5_error_code +-klmdb_lib_init() ++klmdb_lib_init(void) + { + return 0; + } + + static krb5_error_code +-klmdb_lib_cleanup() ++klmdb_lib_cleanup(void) + { + return 0; + } +diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c +index f4d4380d5b..8d14091f38 100644 +--- a/src/plugins/kdb/test/kdb_test.c ++++ b/src/plugins/kdb/test/kdb_test.c +@@ -312,13 +312,13 @@ make_strings(char **stringattrs, krb5_db_entry *ent) + } + + static krb5_error_code +-test_init() ++test_init(void) + { + return 0; + } + + static krb5_error_code +-test_cleanup() ++test_cleanup(void) + { + return 0; + } +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 8cdc40bfb4..f5aade34cc 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -3471,7 +3471,7 @@ load_pkcs11_module(krb5_context context, const char *modname, + CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR); + struct errinfo einfo = EMPTY_ERRINFO; + const char *errmsg = NULL; +- void (*sym)(); ++ void (*sym)(void); + long err; + CK_RV rv; + +@@ -3490,7 +3490,7 @@ load_pkcs11_module(krb5_context context, const char *modname, + goto error; + } + +- getflist = (CK_RV (*)())sym; ++ getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym; + rv = (*getflist)(p11p); + if (rv != CKR_OK) { + TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv)); +diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c +index 96b0307d78..ecffd3d7ee 100644 +--- a/src/plugins/preauth/spake/t_vectors.c ++++ b/src/plugins/preauth/spake/t_vectors.c +@@ -439,7 +439,7 @@ run_test(const struct test *t) + } + + int +-main() ++main(void) + { + size_t i; + +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index 926aa94706..2fa6dce8eb 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -54,9 +54,8 @@ static void ktest_free_reply_key_pack(krb5_context context, + static void ktest_free_kkdcp_message(krb5_context context, + krb5_kkdcp_message *val); + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + krb5_data code; + krb5_error_code retval; +diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c +index 26c064e67d..f4e754b1cc 100644 +--- a/src/tests/asn.1/krb5_encode_test.c ++++ b/src/tests/asn.1/krb5_encode_test.c +@@ -37,7 +37,7 @@ krb5_context test_context; + int error_count = 0; + int do_trval = 0; + int first_trval = 1; +-int trval2(); ++int trval2(FILE *, unsigned char *, int, int, int *); + + static void + encoder_print_results(krb5_data *code, char *typestring, char *description) +@@ -51,7 +51,7 @@ encoder_print_results(krb5_data *code, char *typestring, char *description) + else + printf("\n"); + printf("encode_krb5_%s%s:\n", typestring, description); +- r = trval2(stdout, code->data, code->length, 0, &rlen); ++ r = trval2(stdout, (uint8_t *)code->data, code->length, 0, &rlen); + printf("\n"); + if (rlen < 0 || (unsigned int) rlen != code->length) { + printf("Error: length mismatch: was %d, parsed %d\n", +@@ -72,9 +72,8 @@ encoder_print_results(krb5_data *code, char *typestring, char *description) + ktest_destroy_data(&code); + } + +-static void PRS(argc, argv) +- int argc; +- char **argv; ++static void ++PRS(int argc, char **argv) + { + extern char *optarg; + int optchar; +@@ -107,9 +106,7 @@ static void PRS(argc, argv) + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + krb5_data *code; + krb5_error_code retval; +diff --git a/src/tests/asn.1/t_trval.c b/src/tests/asn.1/t_trval.c +index 57d8253880..009ed5bb9e 100644 +--- a/src/tests/asn.1/t_trval.c ++++ b/src/tests/asn.1/t_trval.c +@@ -36,7 +36,8 @@ + -DSTANDALONE code. */ + #include "trval.c" + +-static void usage() ++static void ++usage(void) + { + fprintf(stderr, "Usage: trval [--types] [--krb5] [--krb5decode] [--hex] [-notypebytes] [file]\n"); + exit(1); +@@ -46,10 +47,8 @@ static void usage() + * Returns true if the option was selected. Allow "-option" and + * "--option" syntax, since we used to accept only "-option" + */ +-static +-int check_option(word, option) +- char *word; +- char *option; ++static int ++check_option(char *word, char *option) + { + if (word[0] != '-') + return 0; +@@ -60,9 +59,8 @@ int check_option(word, option) + return 1; + } + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + int optflg = 1; + FILE *fp; +diff --git a/src/tests/asn.1/trval.c b/src/tests/asn.1/trval.c +index c14bcdeb69..e0e58cc19e 100644 +--- a/src/tests/asn.1/trval.c ++++ b/src/tests/asn.1/trval.c +@@ -120,7 +120,8 @@ int trval2 (FILE *, unsigned char *, int, int, int *); + + /****************************************************************************/ + +-static int convert_nibble(int ch) ++static int ++convert_nibble(int ch) + { + if (isdigit(ch)) + return (ch - '0'); +@@ -131,9 +132,8 @@ static int convert_nibble(int ch) + return -1; + } + +-int trval(fin, fout) +- FILE *fin; +- FILE *fout; ++int ++trval(FILE *fin, FILE *fout) + { + unsigned char *p; + unsigned int maxlen; +@@ -169,12 +169,8 @@ int trval(fin, fout) + return(r); + } + +-int trval2(fp, enc, len, lev, rlen) +- FILE *fp; +- unsigned char *enc; +- int len; +- int lev; +- int *rlen; ++int ++trval2(FILE *fp, unsigned char *enc, int len, int lev, int *rlen) + { + int l, eid, elen, xlen, r, rlen2 = 0; + int rlen_ext = 0; +@@ -248,10 +244,8 @@ context_restart: + return(r); + } + +-int decode_len(fp, enc, len) +- FILE *fp; +- unsigned char *enc; +- int len; ++int ++decode_len(FILE *fp, unsigned char *enc, int len) + { + int rlen; + int i; +@@ -270,12 +264,8 @@ int decode_len(fp, enc, len) + /* + * This is the printing function for bit strings + */ +-int do_prim_bitstring(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_bitstring(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + long num = 0; +@@ -297,12 +287,8 @@ int do_prim_bitstring(fp, tag, enc, len, lev) + /* + * This is the printing function for integers + */ +-int do_prim_int(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_int(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + long num = 0; +@@ -327,12 +313,8 @@ int do_prim_int(fp, tag, enc, len, lev) + * This is the printing function which we use if it's a string or + * other other type which is best printed as a string + */ +-int do_prim_string(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_string(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + +@@ -349,12 +331,8 @@ int do_prim_string(fp, tag, enc, len, lev) + return 1; + } + +-int do_prim(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int n; + int i; +@@ -396,12 +374,8 @@ int do_prim(fp, tag, enc, len, lev) + return(OK); + } + +-int do_cons(fp, enc, len, lev, rlen) +- FILE *fp; +- unsigned char *enc; +- int len; +- int lev; +- int *rlen; ++int ++do_cons(FILE *fp, unsigned char *enc, int len, int lev, int *rlen) + { + int n; + int r = 0; +@@ -430,9 +404,8 @@ struct typestring_table { + int new_appl; + }; + +-static char *lookup_typestring(table, key1, key2) +- struct typestring_table *table; +- int key1, key2; ++static char * ++lookup_typestring(struct typestring_table *table, int key1, int key2) + { + struct typestring_table *ent; + +@@ -700,10 +673,8 @@ struct typestring_table krb5_fields[] = { + }; + #endif + +-void print_tag_type(fp, eid, lev) +- FILE *fp; +- int eid; +- int lev; ++void ++print_tag_type(FILE *fp, int eid, int lev) + { + int tag = eid & ID_TAG; + int do_space = 1; +diff --git a/src/tests/conccache.c b/src/tests/conccache.c +index 7b0ca6300c..9fe5305761 100644 +--- a/src/tests/conccache.c ++++ b/src/tests/conccache.c +@@ -110,7 +110,7 @@ refresh_cache(krb5_context context) + } + + static pid_t +-spawn_cred_subprocess() ++spawn_cred_subprocess(void) + { + krb5_context context; + pid_t pid; +@@ -133,7 +133,7 @@ spawn_cred_subprocess() + } + + static pid_t +-spawn_refresh_subprocess() ++spawn_refresh_subprocess(void) + { + krb5_context context; + pid_t pid; +diff --git a/src/tests/create/kdb5_mkdums.c b/src/tests/create/kdb5_mkdums.c +index 7c0666601c..61ca9f67a2 100644 +--- a/src/tests/create/kdb5_mkdums.c ++++ b/src/tests/create/kdb5_mkdums.c +@@ -56,9 +56,7 @@ struct mblock { + int set_dbname_help (char *, char *); + + static void +-usage(who, status) +- char *who; +- int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_create [-d dbpathname] [-r realmname]\n", +@@ -83,9 +81,7 @@ static krb5_boolean manual_mkey = FALSE; + void add_princ (krb5_context, char *); + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern char *optarg; + int optchar, i, n; +@@ -209,9 +205,7 @@ main(argc, argv) + } + + void +-add_princ(context, str_newprinc) +- krb5_context context; +- char * str_newprinc; ++add_princ(krb5_context context, char *str_newprinc) + { + krb5_error_code retval; + krb5_principal newprinc; +@@ -317,9 +311,7 @@ error: /* Do cleanup of newentry regardless of error */ + } + + int +-set_dbname_help(pname, dbname) +- char *pname; +- char *dbname; ++set_dbname_help(char *pname, char *dbname) + { + krb5_error_code retval; + krb5_data pwd, scratch; +diff --git a/src/tests/forward.c b/src/tests/forward.c +index 7327cc9e62..90f359a586 100644 +--- a/src/tests/forward.c ++++ b/src/tests/forward.c +@@ -51,7 +51,7 @@ check(krb5_error_code code) + } + + int +-main() ++main(void) + { + krb5_ccache cc; + krb5_creds mcred, tgt, *fcred; +diff --git a/src/tests/gss-threads/gss-client.c b/src/tests/gss-threads/gss-client.c +index c0cf25ddaa..8c006c2915 100644 +--- a/src/tests/gss-threads/gss-client.c ++++ b/src/tests/gss-threads/gss-client.c +@@ -68,7 +68,7 @@ + static int verbose = 1; + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-client [-port port] [-mech mechanism] [-d]\n"); + fprintf(stderr, " [-seq] [-noreplay] [-nomutual]"); +@@ -134,7 +134,7 @@ get_server_info(char *host, u_short port) + * displayed and -1 is returned. + */ + static int +-connect_to_server() ++connect_to_server(void) + { + int s; + +diff --git a/src/tests/gss-threads/gss-server.c b/src/tests/gss-threads/gss-server.c +index a9f980edb2..e0a37738e4 100644 +--- a/src/tests/gss-threads/gss-server.c ++++ b/src/tests/gss-threads/gss-server.c +@@ -74,7 +74,7 @@ + #endif + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-server [-port port] [-verbose] [-once]"); + #ifdef _WIN32 +diff --git a/src/tests/gssapi/reload.c b/src/tests/gssapi/reload.c +index 4fe3565406..00bda32330 100644 +--- a/src/tests/gssapi/reload.c ++++ b/src/tests/gssapi/reload.c +@@ -64,7 +64,7 @@ load_gssapi(void) + } + + int +-main() ++main(void) + { + void *support; + +diff --git a/src/tests/gssapi/t_add_cred.c b/src/tests/gssapi/t_add_cred.c +index 68b37e3ed9..7ab52d6449 100644 +--- a/src/tests/gssapi/t_add_cred.c ++++ b/src/tests/gssapi/t_add_cred.c +@@ -43,7 +43,7 @@ + #include "common.h" + + int +-main() ++main(void) + { + OM_uint32 minor, major; + gss_cred_id_t cred1, cred2; +diff --git a/src/tests/gssapi/t_enctypes.c b/src/tests/gssapi/t_enctypes.c +index 3fd31e2f8c..3325db7696 100644 +--- a/src/tests/gssapi/t_enctypes.c ++++ b/src/tests/gssapi/t_enctypes.c +@@ -47,7 +47,7 @@ + */ + + static void +-usage() ++usage(void) + { + errout("Usage: t_enctypes [-i initenctypes] [-a accenctypes] " + "targetname"); +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index 8192935099..a052b8ab6e 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -547,7 +547,7 @@ try_accept(void *value, size_t len) + + /* Accept contexts using superficially valid but truncated encapsulations. */ + static void +-test_short_encapsulation() ++test_short_encapsulation(void) + { + /* Include just the initial application tag, to see if we overrun reading + * the sequence length. */ +diff --git a/src/tests/gssapi/t_oid.c b/src/tests/gssapi/t_oid.c +index 1c9d394167..64253133d2 100644 +--- a/src/tests/gssapi/t_oid.c ++++ b/src/tests/gssapi/t_oid.c +@@ -129,7 +129,7 @@ oid_equal(gss_OID o1, gss_OID o2) + } + + int +-main() ++main(void) + { + size_t i; + OM_uint32 major, minor; +diff --git a/src/tests/gssapi/t_spnego.c b/src/tests/gssapi/t_spnego.c +index 2483228b1b..4091739f83 100644 +--- a/src/tests/gssapi/t_spnego.c ++++ b/src/tests/gssapi/t_spnego.c +@@ -195,7 +195,7 @@ test_mskrb_oid(gss_name_t tname, gss_cred_id_t acred) + /* Check that we return a compatibility NegTokenInit2 message containing + * NegHints for an empty initiator token. */ + static void +-test_neghints() ++test_neghints(void) + { + OM_uint32 major, minor; + gss_buffer_desc itok = GSS_C_EMPTY_BUFFER, atok; +diff --git a/src/tests/hammer/kdc5_hammer.c b/src/tests/hammer/kdc5_hammer.c +index 8220fd97bd..76ef527ccf 100644 +--- a/src/tests/hammer/kdc5_hammer.c ++++ b/src/tests/hammer/kdc5_hammer.c +@@ -68,9 +68,7 @@ int get_tgt + krb5_ccache); + + static void +-usage(who, status) +-char *who; +-int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_check [-c cachename] [-r realmname]\n", +@@ -100,9 +98,7 @@ struct h_timer tgs_req_times = { 0.0, 1000000.0, -1.0, 0 }; + tstart_time.tv_usec))/1000000.0))) + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + krb5_ccache ccache = NULL; + char *cache_name = NULL; /* -f option */ +@@ -271,11 +267,8 @@ main(argc, argv) + + + static krb5_error_code +-get_server_key(context, server, enctype, key) +- krb5_context context; +- krb5_principal server; +- krb5_enctype enctype; +- krb5_keyblock ** key; ++get_server_key(krb5_context context, krb5_principal server, ++ krb5_enctype enctype, krb5_keyblock **key) + { + krb5_error_code retval; + krb5_encrypt_block eblock; +@@ -311,15 +304,10 @@ cleanup_salt: + return retval; + } + +-int verify_cs_pair(context, p_client_str, p_client, service, hostname, +- p_num, c_depth, s_depth, ccache) +- krb5_context context; +- char *p_client_str; +- krb5_principal p_client; +- char * service; +- char * hostname; +- int p_num, c_depth, s_depth; +- krb5_ccache ccache; ++int ++verify_cs_pair(krb5_context context, char *p_client_str, ++ krb5_principal p_client, char *service, char *hostname, ++ int p_num, int c_depth, int s_depth, krb5_ccache ccache) + { + krb5_error_code retval; + krb5_creds creds; +@@ -433,11 +421,9 @@ cleanup: + return retval; + } + +-int get_tgt (context, p_client_str, p_client, ccache) +- krb5_context context; +- char *p_client_str; +- krb5_principal *p_client; +- krb5_ccache ccache; ++int ++get_tgt(krb5_context context, char *p_client_str, krb5_principal *p_client, ++ krb5_ccache ccache) + { + long lifetime = KRB5_DEFAULT_LIFE; /* -l option */ + krb5_error_code code; +diff --git a/src/tests/kdbtest.c b/src/tests/kdbtest.c +index 3f61f3e83b..6459c3390f 100644 +--- a/src/tests/kdbtest.c ++++ b/src/tests/kdbtest.c +@@ -271,7 +271,7 @@ iter_pol_handler(void *data, osa_policy_ent_t pol) + } + + int +-main() ++main(void) + { + krb5_db_entry *ent; + osa_policy_ent_t pol; +diff --git a/src/tests/misc/test_getpw.c b/src/tests/misc/test_getpw.c +index 6031e15035..59ff5d3a5d 100644 +--- a/src/tests/misc/test_getpw.c ++++ b/src/tests/misc/test_getpw.c +@@ -32,7 +32,7 @@ + #include + #include + +-int main() ++int main(void) + { + uid_t my_uid; + struct passwd *pwd, pwx; +diff --git a/src/tests/plugorder.c b/src/tests/plugorder.c +index e1245e4765..a2b7e34eea 100644 +--- a/src/tests/plugorder.c ++++ b/src/tests/plugorder.c +@@ -77,7 +77,7 @@ blt3(krb5_context context, int maj_ver, int min_ver, krb5_plugin_vtable vtable) + } + + int +-main() ++main(void) + { + krb5_plugin_initvt_fn *modules = NULL, *mod; + struct krb5_pwqual_vtable_st vt; +diff --git a/src/tests/shlib/t_loader.c b/src/tests/shlib/t_loader.c +index 29481a7be2..203f023f69 100644 +--- a/src/tests/shlib/t_loader.c ++++ b/src/tests/shlib/t_loader.c +@@ -180,7 +180,7 @@ static void do_close(void *libhandle) + + #endif + +-int main() ++int main(void) + { + void *celib, *k5lib, *gsslib, *celib2; + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 82b05ff0da..908f926405 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -860,7 +860,7 @@ func_not_supported(void) + } + + static char * +-get_rcfilename() ++get_rcfilename(void) + { + struct passwd *pw; + const char *home = NULL; +diff --git a/src/tests/t_inetd.c b/src/tests/t_inetd.c +index d22cf31ffa..3790467c7b 100644 +--- a/src/tests/t_inetd.c ++++ b/src/tests/t_inetd.c +@@ -59,16 +59,15 @@ + + char *progname; + +-static void usage() ++static void ++usage(void) + { + fprintf(stderr, "%s: port program argv0 argv1 ...\n", progname); + exit(1); + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + unsigned short port; + char *path; +diff --git a/src/tests/test1.c b/src/tests/test1.c +index aed656ebe3..b213a349bf 100644 +--- a/src/tests/test1.c ++++ b/src/tests/test1.c +@@ -31,7 +31,7 @@ unsigned char key_two[8] = { 0xea, 0x89, 0x57, 0x76, 0x5b, 0xcd, 0x0d, 0x34 }; + + extern void dump_data(); + +-tkt_test_1() ++tkt_test_1(void) + { + krb5_data *data; + krb5_ticket tk_in, *tk_out; +@@ -185,7 +185,7 @@ tkt_test_1() + + + +-main() ++main(void) + { + krb5_init_ets(); + tkt_test_1(); +diff --git a/src/tests/verify/kdb5_verify.c b/src/tests/verify/kdb5_verify.c +index 3b152baed6..d53e92ad45 100644 +--- a/src/tests/verify/kdb5_verify.c ++++ b/src/tests/verify/kdb5_verify.c +@@ -50,9 +50,7 @@ struct mblock { + int set_dbname_help (krb5_context, char *, char *); + + static void +-usage(who, status) +- char *who; +- int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_check [-d dbpathname] [-r realmname]\n", +@@ -78,9 +76,7 @@ static krb5_boolean manual_mkey = FALSE; + int check_princ (krb5_context, char *); + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern char *optarg; + int optchar, i, n; +@@ -221,9 +217,7 @@ main(argc, argv) + } + + int +-check_princ(context, str_princ) +- krb5_context context; +- char * str_princ; ++check_princ(krb5_context context, char *str_princ) + { + krb5_error_code retval; + krb5_db_entry *kdbe = NULL; +@@ -343,10 +337,7 @@ out: + } + + int +-set_dbname_help(context, pname, dbname) +- krb5_context context; +- char *pname; +- char *dbname; ++set_dbname_help(krb5_context context, char *pname, char *dbname) + { + krb5_error_code retval; + krb5_data pwd, scratch; +diff --git a/src/util/et/error_message.c b/src/util/et/error_message.c +index 7dc02a34ea..13ad3af6a2 100644 +--- a/src/util/et/error_message.c ++++ b/src/util/et/error_message.c +@@ -82,7 +82,7 @@ void com_err_terminate(void) + #endif + + static char * +-get_thread_buffer () ++get_thread_buffer(void) + { + char *cp; + cp = k5_getspecific(K5_KEY_COM_ERR); +diff --git a/src/util/et/test_et.c b/src/util/et/test_et.c +index 9faf10f460..2002e5ff46 100644 +--- a/src/util/et/test_et.c ++++ b/src/util/et/test_et.c +@@ -17,7 +17,8 @@ extern const char *error_table_name (errcode_t); + extern int sys_nerr; + #endif + +-int main() ++int ++main(void) + { + printf("Before initiating error table:\n\n"); + #ifndef EXPORT_LIST +diff --git a/src/util/profile/prof_init.c b/src/util/profile/prof_init.c +index cc92248f42..077c852e49 100644 +--- a/src/util/profile/prof_init.c ++++ b/src/util/profile/prof_init.c +@@ -103,7 +103,7 @@ init_load_module(const char *modspec, profile_t *ret_profile) + struct errinfo einfo = { 0 }; + prf_lib_handle_t lib_handle = NULL; + struct plugin_file_handle *plhandle = NULL; +- void *cbdata = NULL, (*fptr)(); ++ void *cbdata = NULL, (*fptr)(void); + int have_lock = 0, have_cbdata = 0; + struct profile_vtable vtable = { 1 }; /* Set minor_ver to 1, rest null. */ + errcode_t err; +diff --git a/src/util/profile/t_profile.c b/src/util/profile/t_profile.c +index b0e715ba02..bffd115618 100644 +--- a/src/util/profile/t_profile.c ++++ b/src/util/profile/t_profile.c +@@ -72,7 +72,7 @@ write_file(const char *name, int nlines, ...) + /* Regression test for #2685 (profile iterator breaks when modifications + * made) */ + static void +-test_iterate() ++test_iterate(void) + { + profile_t p; + void *iter; +@@ -129,7 +129,7 @@ test_iterate() + * global shared profiles list. + */ + static void +-test_shared() ++test_shared(void) + { + profile_t a, b; + struct utimbuf times; +@@ -164,7 +164,7 @@ test_shared() + /* Regression test for #2950 (profile_clear_relation not reflected within + * handle where deletion is performed) */ + static void +-test_clear() ++test_clear(void) + { + profile_t p; + const char *names[] = { "test section 1", "quux", NULL }; +@@ -183,7 +183,7 @@ test_clear() + } + + static void +-test_include() ++test_include(void) + { + profile_t p; + const char *names[] = { "test section 1", "bar", NULL }; +@@ -237,7 +237,7 @@ test_include() + + /* Test syntactic independence of included profile files. */ + static void +-test_independence() ++test_independence(void) + { + profile_t p; + const char *names1[] = { "sec1", "var", "a", NULL }; +@@ -264,7 +264,7 @@ test_independence() + + /* Regression test for #7971 (deleted sections should not be iterable) */ + static void +-test_delete_section() ++test_delete_section(void) + { + profile_t p; + const char *sect[] = { "test section 1", NULL }; +@@ -290,7 +290,7 @@ test_delete_section() + /* Regression test for #7971 (profile_clear_relation() error with deleted node + * at end of value set) */ + static void +-test_delete_clear_relation() ++test_delete_clear_relation(void) + { + profile_t p; + const char *names[] = { "test section 1", "testkey", NULL }; +@@ -305,7 +305,7 @@ test_delete_clear_relation() + + /* Test that order of relations is preserved if some relations are deleted. */ + static void +-test_delete_ordering() ++test_delete_ordering(void) + { + profile_t p; + const char *names[] = { "test section 1", "testkey", NULL }; +@@ -329,7 +329,7 @@ test_delete_ordering() + /* Regression test for #8431 (profile_flush_to_file erroneously changes flag + * state on source object) */ + static void +-test_flush_to_file() ++test_flush_to_file(void) + { + profile_t p; + +@@ -349,7 +349,7 @@ test_flush_to_file() + /* Regression test for #7863 (multiply-specified subsections should + * be merged) */ + static void +-test_merge_subsections() ++test_merge_subsections(void) + { + profile_t p; + const char *n1[] = { "test section 2", "child_section2", "child", NULL }; +@@ -374,7 +374,7 @@ test_merge_subsections() + } + + int +-main() ++main(void) + { + test_iterate(); + test_shared(); +diff --git a/src/util/profile/test_load.c b/src/util/profile/test_load.c +index cb870eff93..fe2d1e3e72 100644 +--- a/src/util/profile/test_load.c ++++ b/src/util/profile/test_load.c +@@ -29,7 +29,7 @@ + #include "prof_int.h" + + int +-main() ++main(void) + { + profile_t pr, pr2; + const char *files[] = { "./modtest.conf", NULL }; +diff --git a/src/util/profile/test_parse.c b/src/util/profile/test_parse.c +index 9f2631e949..0532254e8c 100644 +--- a/src/util/profile/test_parse.c ++++ b/src/util/profile/test_parse.c +@@ -11,9 +11,8 @@ + + void dump_profile (struct profile_node *root, int level); + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + struct profile_node *root; + unsigned long retval; +diff --git a/src/util/profile/test_profile.c b/src/util/profile/test_profile.c +index 6f6fcc7ac5..31b1063951 100644 +--- a/src/util/profile/test_profile.c ++++ b/src/util/profile/test_profile.c +@@ -19,8 +19,8 @@ const char *program_name = "test_profile"; + #define PRINT_VALUE 1 + #define PRINT_VALUES 2 + +-static void do_batchmode(profile) +- profile_t profile; ++static void ++do_batchmode(profile_t profile) + { + errcode_t retval; + int argc, ret; +@@ -108,10 +108,8 @@ static void do_batchmode(profile) + + } + +- +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + profile_t profile; + long retval; +diff --git a/src/util/profile/test_vtable.c b/src/util/profile/test_vtable.c +index 9a0b2278a7..a7b6f54ae9 100644 +--- a/src/util/profile/test_vtable.c ++++ b/src/util/profile/test_vtable.c +@@ -232,7 +232,8 @@ struct profile_vtable full_vtable = { + full_flush + }; + +-int main() ++int ++main(void) + { + profile_t profile; + char **values, *str, *name, *value; +diff --git a/src/util/ss/error.c b/src/util/ss/error.c +index b5768a62b7..e5cd1b2d12 100644 +--- a/src/util/ss/error.c ++++ b/src/util/ss/error.c +@@ -33,8 +33,8 @@ + #include "com_err.h" + #include "copyright.h" + +-char * ss_name(sci_idx) +- int sci_idx; ++char * ++ss_name(int sci_idx) + { + ss_data *infop; + +@@ -50,7 +50,8 @@ char * ss_name(sci_idx) + } + } + +-void ss_error (int sci_idx, long code, const char * fmt, ...) ++void ++ss_error(int sci_idx, long code, const char *fmt, ...) + { + char *whoami; + va_list pvar; +@@ -61,10 +62,8 @@ void ss_error (int sci_idx, long code, const char * fmt, ...) + va_end(pvar); + } + +-void ss_perror (sci_idx, code, msg) /* for compatibility */ +- int sci_idx; +- long code; +- char const *msg; ++void ++ss_perror(int sci_idx, long code, char const *msg) /* for compatibility */ + { + ss_error (sci_idx, code, "%s", msg); + } +diff --git a/src/util/ss/execute_cmd.c b/src/util/ss/execute_cmd.c +index c06ee56547..065c24148b 100644 +--- a/src/util/ss/execute_cmd.c ++++ b/src/util/ss/execute_cmd.c +@@ -52,11 +52,9 @@ + * Notes: + */ + +-static int check_request_table (rqtbl, argc, argv, sci_idx) +- ss_request_table *rqtbl; +- int argc; +- char *argv[]; +- int sci_idx; ++static int ++check_request_table(ss_request_table *rqtbl, int argc, char *argv[], ++ int sci_idx) + { + ss_request_entry *request; + ss_data *info; +@@ -101,10 +99,8 @@ static int check_request_table (rqtbl, argc, argv, sci_idx) + * Notes: + */ + +-static int really_execute_command (sci_idx, argc, argv) +- int sci_idx; +- int argc; +- char **argv[]; ++static int ++really_execute_command(int sci_idx, int argc, char **argv[]) + { + ss_request_table **rqtbl; + ss_data *info; +@@ -135,9 +131,7 @@ static int really_execute_command (sci_idx, argc, argv) + */ + + int +-ss_execute_command(sci_idx, argv) +- int sci_idx; +- char *argv[]; ++ss_execute_command(int sci_idx, char *argv[]) + { + unsigned int i, argc; + char **argp; +@@ -172,9 +166,8 @@ ss_execute_command(sci_idx, argv) + * Notes: + */ + +-int ss_execute_line (sci_idx, line_ptr) +- int sci_idx; +- char *line_ptr; ++int ++ss_execute_line(int sci_idx, char *line_ptr) + { + char **argv; + int argc, ret; +diff --git a/src/util/ss/help.c b/src/util/ss/help.c +index 6d333c9710..747fde5351 100644 +--- a/src/util/ss/help.c ++++ b/src/util/ss/help.c +@@ -15,11 +15,8 @@ + #include "copyright.h" + + +-void ss_help (argc, argv, sci_idx, info_ptr) +- int argc; +- char const * const *argv; +- int sci_idx; +- pointer info_ptr; ++void ++ss_help(int argc, char const * const *argv, int sci_idx, pointer info_ptr) + { + char buffer[MAXPATHLEN]; + char const *request_name; +@@ -81,15 +78,11 @@ got_it: + ss_page_stdin(); + default: + (void) close(fd); /* what can we do if it fails? */ +-#ifdef WAIT_USES_INT +- while (wait((int *)NULL) != child) { +-#else +- while (wait((union wait *)NULL) != child) { +-#endif +- /* do nothing if wrong pid */ +- }; +- } ++ while (wait(NULL) != child) { ++ /* do nothing if wrong pid */ ++ }; + } ++} + + #ifndef USE_DIRENT_H + #include +@@ -97,60 +90,56 @@ got_it: + #include + #endif + +- void ss_add_info_dir(sci_idx, info_dir, code_ptr) +- int sci_idx; +- char *info_dir; +- int *code_ptr; +- { +- ss_data *info; +- DIR *d; +- int n_dirs; +- char **dirs; ++void ++ss_add_info_dir(int sci_idx, char *info_dir, int *code_ptr) ++{ ++ ss_data *info; ++ DIR *d; ++ int n_dirs; ++ char **dirs; + +- info = ss_info(sci_idx); +- if ((info_dir == NULL) || (*info_dir == '\0')) { +- *code_ptr = SS_ET_NO_INFO_DIR; +- return; +- } +- if ((d = opendir(info_dir)) == (DIR *)NULL) { +- *code_ptr = errno; +- return; +- } +- closedir(d); +- dirs = info->info_dirs; +- for (n_dirs = 0; dirs[n_dirs] != (char *)NULL; n_dirs++) +- ; /* get number of non-NULL dir entries */ +- dirs = (char **)realloc((char *)dirs, +- (unsigned)(n_dirs + 2)*sizeof(char *)); +- if (dirs == (char **)NULL) { +- info->info_dirs = (char **)NULL; +- *code_ptr = errno; +- return; +- } +- info->info_dirs = dirs; +- dirs[n_dirs + 1] = (char *)NULL; +- dirs[n_dirs] = strdup(info_dir); +- *code_ptr = 0; ++ info = ss_info(sci_idx); ++ if ((info_dir == NULL) || (*info_dir == '\0')) { ++ *code_ptr = SS_ET_NO_INFO_DIR; ++ return; ++ } ++ if ((d = opendir(info_dir)) == (DIR *)NULL) { ++ *code_ptr = errno; ++ return; + } ++ closedir(d); ++ dirs = info->info_dirs; ++ for (n_dirs = 0; dirs[n_dirs] != (char *)NULL; n_dirs++) ++ ; /* get number of non-NULL dir entries */ ++ dirs = (char **)realloc((char *)dirs, ++ (unsigned)(n_dirs + 2)*sizeof(char *)); ++ if (dirs == (char **)NULL) { ++ info->info_dirs = (char **)NULL; ++ *code_ptr = errno; ++ return; ++ } ++ info->info_dirs = dirs; ++ dirs[n_dirs + 1] = (char *)NULL; ++ dirs[n_dirs] = strdup(info_dir); ++ *code_ptr = 0; ++} + +- void ss_delete_info_dir(sci_idx, info_dir, code_ptr) +- int sci_idx; +- char *info_dir; +- int *code_ptr; +- { +- char **i_d; +- char **info_dirs; ++void ++ss_delete_info_dir(int sci_idx, char *info_dir, int *code_ptr) ++{ ++ char **i_d; ++ char **info_dirs; + +- info_dirs = ss_info(sci_idx)->info_dirs; +- for (i_d = info_dirs; *i_d; i_d++) { +- if (!strcmp(*i_d, info_dir)) { +- while (*i_d) { +- *i_d = *(i_d+1); +- i_d++; +- } +- *code_ptr = 0; +- return; ++ info_dirs = ss_info(sci_idx)->info_dirs; ++ for (i_d = info_dirs; *i_d; i_d++) { ++ if (!strcmp(*i_d, info_dir)) { ++ while (*i_d) { ++ *i_d = *(i_d+1); ++ i_d++; + } ++ *code_ptr = 0; ++ return; + } +- *code_ptr = SS_ET_NO_INFO_DIR; + } ++ *code_ptr = SS_ET_NO_INFO_DIR; ++} +diff --git a/src/util/ss/invocation.c b/src/util/ss/invocation.c +index 378bc3e927..7736c957d4 100644 +--- a/src/util/ss/invocation.c ++++ b/src/util/ss/invocation.c +@@ -36,12 +36,10 @@ + _ss_table[sci_idx], make sure you change the allocation routine to + not assume there are no null pointers in the middle of the + array. */ +-int ss_create_invocation(subsystem_name, version_string, info_ptr, +- request_table_ptr, code_ptr) +- char *subsystem_name, *version_string; +- char *info_ptr; +- ss_request_table *request_table_ptr; +- int *code_ptr; ++int ++ss_create_invocation(char *subsystem_name, char *version_string, ++ char *info_ptr, ss_request_table *request_table_ptr, ++ int *code_ptr) + { + int sci_idx; + ss_data *new_table; +@@ -115,8 +113,7 @@ int ss_create_invocation(subsystem_name, version_string, info_ptr, + } + + void +-ss_delete_invocation(sci_idx) +- int sci_idx; ++ss_delete_invocation(int sci_idx) + { + ss_data *t; + int ignored_code; +diff --git a/src/util/ss/list_rqs.c b/src/util/ss/list_rqs.c +index c0882bf908..8376e21be8 100644 +--- a/src/util/ss/list_rqs.c ++++ b/src/util/ss/list_rqs.c +@@ -21,15 +21,8 @@ static char const twentyfive_spaces[26] = + static char const NL[2] = "\n"; + + void +-ss_list_requests(argc, argv, sci_idx, info_ptr) +- int argc; +- const char * const *argv; +- int sci_idx; +-#ifdef __STDC__ +- void *info_ptr; +-#else +- char *info_ptr; +-#endif ++ss_list_requests(int argc, const char * const *argv, int sci_idx, ++ void *info_ptr) + { + ss_request_entry *entry; + char const *const *name; +diff --git a/src/util/ss/listen.c b/src/util/ss/listen.c +index fe18475447..79f258fbc4 100644 +--- a/src/util/ss/listen.c ++++ b/src/util/ss/listen.c +@@ -28,7 +28,8 @@ static jmp_buf listen_jmpb; + + #ifdef NO_READLINE + /* Dumb replacement for readline when we don't have support for a real one. */ +-static char *readline(const char *prompt) ++static char * ++readline(const char *prompt) + { + struct termios termbuf; + char input[BUFSIZ]; +@@ -49,20 +50,21 @@ static char *readline(const char *prompt) + } + + /* No-op replacement for add_history() when we have no readline support. */ +-static void add_history(const char *line) ++static void ++add_history(const char *line) + { + } + #endif + +-static void listen_int_handler(signo) +- int signo; ++static void ++listen_int_handler(int signo) + { + putc('\n', stdout); + longjmp(listen_jmpb, 1); + } + +-int ss_listen (sci_idx) +- int sci_idx; ++int ++ss_listen(int sci_idx) + { + char *cp; + ss_data *info; +@@ -83,12 +85,12 @@ int ss_listen (sci_idx) + info->abort = 0; + + #ifdef POSIX_SIGNALS +- csig.sa_handler = (void (*)())0; ++ csig.sa_handler = (void (*)(int))0; + sigemptyset(&nmask); + sigaddset(&nmask, SIGINT); + sigprocmask(SIG_BLOCK, &nmask, &omask); + #else +- sig_cont = (void (*)())0; ++ sig_cont = (void (*)(int))0; + mask = sigblock(sigmask(SIGINT)); + #endif + +@@ -115,7 +117,7 @@ int ss_listen (sci_idx) + nsig.sa_handler = listen_int_handler; /* fgets is not signal-safe */ + osig = csig; + sigaction(SIGCONT, &nsig, &csig); +- if ((void (*)())csig.sa_handler==(void (*)())listen_int_handler) ++ if ((void (*)(int))csig.sa_handler==(void (*)(int))listen_int_handler) + csig = osig; + #else + old_sig_cont = sig_cont; +@@ -166,20 +168,16 @@ egress: + return code; + } + +-void ss_abort_subsystem(sci_idx, code) +- int sci_idx; +- int code; ++void ++ss_abort_subsystem(int sci_idx, int code) + { + ss_info(sci_idx)->abort = 1; + ss_info(sci_idx)->exit_status = code; + + } + +-void ss_quit(argc, argv, sci_idx, infop) +- int argc; +- char const * const *argv; +- int sci_idx; +- pointer infop; ++void ++ss_quit(int argc, char const * const *argv, int sci_idx, pointer infop) + { + ss_abort_subsystem(sci_idx, 0); + } +diff --git a/src/util/ss/pager.c b/src/util/ss/pager.c +index 3e47ed3993..255c721ad1 100644 +--- a/src/util/ss/pager.c ++++ b/src/util/ss/pager.c +@@ -10,13 +10,13 @@ + #include "copyright.h" + #include + #include ++#include + #include + #include + #include + + static char MORE[] = "more"; + extern char *_ss_pager_name; +-extern char *getenv(); + + /* + * this needs a *lot* of work.... +@@ -25,10 +25,10 @@ extern char *getenv(); + * handle SIGINT sensibly + * allow finer control -- put-page-break-here + */ +-void ss_page_stdin(); ++void ss_page_stdin(void); + + #ifndef NO_FORK +-int ss_pager_create() ++int ss_pager_create(void) + { + int filedes[2]; + +@@ -56,7 +56,7 @@ int ss_pager_create() + } + } + #else /* don't fork */ +-int ss_pager_create() ++int ss_pager_create(void) + { + int fd; + fd = open("/dev/tty", O_WRONLY, 0); +@@ -66,7 +66,7 @@ int ss_pager_create() + } + #endif + +-void ss_page_stdin() ++void ss_page_stdin(void) + { + int i; + #ifdef POSIX_SIGNALS +diff --git a/src/util/ss/parse.c b/src/util/ss/parse.c +index 78a831bf36..6fb031cdcd 100644 +--- a/src/util/ss/parse.c ++++ b/src/util/ss/parse.c +@@ -53,10 +53,8 @@ enum parse_mode { WHITESPACE, TOKEN, QUOTED_STRING }; + #define NEW_ARGV(old,n) (char **)realloc((char *)old, \ + (unsigned)(n+2)*sizeof(char*)) + +-char **ss_parse (sci_idx, line_ptr, argc_ptr) +- int sci_idx; +- char *line_ptr; +- int *argc_ptr; ++char ** ++ss_parse(int sci_idx, char *line_ptr, int *argc_ptr) + { + char **argv, *cp; + char **newargv; +diff --git a/src/util/ss/prompt.c b/src/util/ss/prompt.c +index 5aa2ad6140..48e57d6702 100644 +--- a/src/util/ss/prompt.c ++++ b/src/util/ss/prompt.c +@@ -11,16 +11,13 @@ + #include "ss_internal.h" + + void +-ss_set_prompt(sci_idx, new_prompt) +- int sci_idx; +- char *new_prompt; ++ss_set_prompt(int sci_idx, char *new_prompt) + { + ss_info(sci_idx)->prompt = new_prompt; + } + + char * +-ss_get_prompt(sci_idx) +- int sci_idx; ++ss_get_prompt(int sci_idx) + { + return(ss_info(sci_idx)->prompt); + } +diff --git a/src/util/ss/request_tbl.c b/src/util/ss/request_tbl.c +index 03cde1b7d0..fc4461bb00 100644 +--- a/src/util/ss/request_tbl.c ++++ b/src/util/ss/request_tbl.c +@@ -11,11 +11,7 @@ + #define ssrt ss_request_table /* for some readable code... */ + + void +-ss_add_request_table(sci_idx, rqtbl_ptr, position, code_ptr) +- int sci_idx; +- ssrt *rqtbl_ptr; +- int position; /* 1 -> becomes second... */ +- int *code_ptr; ++ss_add_request_table(int sci_idx, ssrt *rqtbl_ptr, int position, int *code_ptr) + { + ss_data *info; + int i, size; +@@ -44,10 +40,7 @@ ss_add_request_table(sci_idx, rqtbl_ptr, position, code_ptr) + } + + void +-ss_delete_request_table(sci_idx, rqtbl_ptr, code_ptr) +- int sci_idx; +- ssrt *rqtbl_ptr; +- int *code_ptr; ++ss_delete_request_table(int sci_idx, ssrt *rqtbl_ptr, int *code_ptr) + { + ss_data *info; + ssrt **rt1, **rt2; +diff --git a/src/util/ss/requests.c b/src/util/ss/requests.c +index aa6752fa11..651f2201d2 100644 +--- a/src/util/ss/requests.c ++++ b/src/util/ss/requests.c +@@ -9,7 +9,7 @@ + #include + #include "ss_internal.h" + +-#define DECLARE(name) void name(argc,argv,sci_idx,info_ptr)int argc,sci_idx;const char * const *argv; pointer info_ptr; ++#define DECLARE(name) void name(int argc, const char *const *argv, int sci_idx, pointer info_ptr) + + /* + * ss_self_identify -- assigned by default to the "." request +diff --git a/src/util/ss/ss.h b/src/util/ss/ss.h +index 38d8974e3c..faac0d97c1 100644 +--- a/src/util/ss/ss.h ++++ b/src/util/ss/ss.h +@@ -48,7 +48,6 @@ typedef struct _ss_rp_options { /* DEFAULT VALUES */ + void ss_help __SS_PROTO; + void ss_list_requests __SS_PROTO; + void ss_quit __SS_PROTO; +-char *ss_current_request(); + char *ss_name(int); + void ss_error (int, long, char const *, ...) + #if !defined(__cplusplus) && (__GNUC__ > 2) +diff --git a/src/util/ss/ss_internal.h b/src/util/ss/ss_internal.h +index 1f5ddfff91..cdd88af218 100644 +--- a/src/util/ss/ss_internal.h ++++ b/src/util/ss/ss_internal.h +@@ -84,8 +84,7 @@ typedef struct _ss_data { /* init values */ + #define ss_info(sci_idx) (_ss_table[sci_idx]) + #define ss_current_request(sci_idx,code_ptr) \ + (*code_ptr=0,ss_info(sci_idx)->current_request) +-void ss_unknown_function(); +-void ss_delete_info_dir(); ++void ss_delete_info_dir(int, char *, int *); + char **ss_parse (int, char *, int *); + ss_abbrev_info *ss_abbrev_initialize (char *, int *); + void ss_page_stdin (void); +diff --git a/src/util/support/plugins.c b/src/util/support/plugins.c +index 0850565687..253b118dcb 100644 +--- a/src/util/support/plugins.c ++++ b/src/util/support/plugins.c +@@ -240,13 +240,13 @@ krb5int_get_plugin_data(struct plugin_file_handle *h, const char *csymname, + + long KRB5_CALLCONV + krb5int_get_plugin_func(struct plugin_file_handle *h, const char *csymname, +- void (**sym_out)(), struct errinfo *ep) ++ void (**sym_out)(void), struct errinfo *ep) + { + void *dptr = NULL; + long ret = get_sym(h, csymname, &dptr, ep); + + if (!ret) +- *sym_out = (void (*)())dptr; ++ *sym_out = (void (*)(void))dptr; + return ret; + } + +@@ -552,7 +552,7 @@ krb5int_get_plugin_dir_func (struct plugin_dir_handle *dirhandle, + struct errinfo *ep) + { + long err = 0; +- void (**p)() = NULL; ++ void (**p)(void) = NULL; + size_t count = 0; + + /* XXX Do we need to add a leading "_" to the symbol name on any +@@ -569,10 +569,10 @@ krb5int_get_plugin_dir_func (struct plugin_dir_handle *dirhandle, + int i = 0; + + for (i = 0; !err && (dirhandle->files[i] != NULL); i++) { +- void (*sym)() = NULL; ++ void (*sym)(void) = NULL; + + if (krb5int_get_plugin_func (dirhandle->files[i], symname, &sym, ep) == 0) { +- void (**newp)() = NULL; ++ void (**newp)(void) = NULL; + + count++; + newp = realloc (p, ((count + 1) * sizeof (*p))); /* +1 for NULL */ +diff --git a/src/util/support/t_hashtab.c b/src/util/support/t_hashtab.c +index f51abc4f19..d90d5d9d02 100644 +--- a/src/util/support/t_hashtab.c ++++ b/src/util/support/t_hashtab.c +@@ -104,7 +104,7 @@ const uint64_t vectors[64] = { + }; + + static void +-test_siphash() ++test_siphash(void) + { + uint8_t seq[64]; + uint64_t k0, k1, hval; +@@ -122,7 +122,7 @@ test_siphash() + } + + static void +-test_hashtab() ++test_hashtab(void) + { + int st; + struct k5_hashtab *ht; +@@ -168,7 +168,7 @@ test_hashtab() + } + + int +-main() ++main(void) + { + test_siphash(); + test_hashtab(); +diff --git a/src/util/support/t_hex.c b/src/util/support/t_hex.c +index a586a1bc89..40e6aa2327 100644 +--- a/src/util/support/t_hex.c ++++ b/src/util/support/t_hex.c +@@ -137,7 +137,8 @@ struct { + { "F8F9FAFBFCFDFEFF", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8, 1 }, + }; + +-int main() ++int ++main(void) + { + size_t i; + char *hex; +diff --git a/src/util/support/t_json.c b/src/util/support/t_json.c +index 1f229247b4..bacca6f8da 100644 +--- a/src/util/support/t_json.c ++++ b/src/util/support/t_json.c +@@ -86,7 +86,7 @@ check(int pred, const char *str) + } + + static void +-test_array() ++test_array(void) + { + k5_json_string v1; + k5_json_number v2; +diff --git a/src/util/support/t_k5buf.c b/src/util/support/t_k5buf.c +index 734b2720c0..18e7e9b7be 100644 +--- a/src/util/support/t_k5buf.c ++++ b/src/util/support/t_k5buf.c +@@ -54,7 +54,7 @@ check_buf(struct k5buf *buf, const char *name) + } + + static void +-test_basic() ++test_basic(void) + { + struct k5buf buf; + char storage[1024]; +@@ -76,7 +76,7 @@ test_basic() + } + + static void +-test_realloc() ++test_realloc(void) + { + struct k5buf buf; + char data[1024]; +@@ -132,7 +132,7 @@ test_realloc() + } + + static void +-test_overflow() ++test_overflow(void) + { + struct k5buf buf; + char storage[10]; +@@ -153,7 +153,7 @@ test_overflow() + } + + static void +-test_error() ++test_error(void) + { + struct k5buf buf; + char storage[1]; +@@ -173,7 +173,7 @@ test_error() + } + + static void +-test_truncate() ++test_truncate(void) + { + struct k5buf buf; + +@@ -188,7 +188,7 @@ test_truncate() + } + + static void +-test_binary() ++test_binary(void) + { + struct k5buf buf; + char data[] = { 'a', 0, 'b' }, *s; +@@ -205,7 +205,7 @@ test_binary() + } + + static void +-test_fmt() ++test_fmt(void) + { + struct k5buf buf; + char storage[10], data[1024]; +@@ -246,7 +246,7 @@ test_fmt() + } + + int +-main() ++main(void) + { + test_basic(); + test_realloc(); +diff --git a/src/util/support/t_unal.c b/src/util/support/t_unal.c +index f67cd31edf..6d097f0f83 100644 +--- a/src/util/support/t_unal.c ++++ b/src/util/support/t_unal.c +@@ -2,7 +2,8 @@ + #undef NDEBUG + #include "k5-platform.h" + +-int main () ++int ++main(void) + { + /* Test some low-level assumptions the Kerberos code depends + on. */ +-- +2.45.1 + diff --git a/0017-Fix-two-unlikely-memory-leaks.patch b/0017-Fix-two-unlikely-memory-leaks.patch new file mode 100644 index 0000000..09fedb7 --- /dev/null +++ b/0017-Fix-two-unlikely-memory-leaks.patch @@ -0,0 +1,206 @@ +From ee66c1feedb57ce06ce51aaa823f9a61f564c58e Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 5 Mar 2024 19:53:07 -0500 +Subject: [PATCH] Fix two unlikely memory leaks + +In gss_krb5int_make_seal_token_v3(), one of the bounds checks (which +could probably never be triggered) leaks plain.data. Fix this leak +and use current practices for cleanup throughout the function. + +In xmt_rmtcallres() (unused within the tree and likely elsewhere), +store port_ptr into crp->port_ptr as soon as it is allocated; +otherwise it could leak if the subsequent xdr_u_int32() operation +fails. + +(cherry picked from commit c5f9c816107f70139de11b38aa02db2f1774ee0d) +--- + src/lib/gssapi/krb5/k5sealv3.c | 56 +++++++++++++++------------------- + src/lib/rpc/pmap_rmt.c | 10 +++--- + 2 files changed, 29 insertions(+), 37 deletions(-) + +diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c +index 1fcbdfbb87..d3210c1107 100644 +--- a/src/lib/gssapi/krb5/k5sealv3.c ++++ b/src/lib/gssapi/krb5/k5sealv3.c +@@ -65,7 +65,7 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + int conf_req_flag, int toktype) + { + size_t bufsize = 16; +- unsigned char *outbuf = 0; ++ unsigned char *outbuf = NULL; + krb5_error_code err; + int key_usage; + unsigned char acceptor_flag; +@@ -75,9 +75,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + size_t ec; + unsigned short tok_id; +- krb5_checksum sum; ++ krb5_checksum sum = { 0 }; + krb5_key key; + krb5_cksumtype cksumtype; ++ krb5_data plain = empty_data(); ++ ++ token->value = NULL; ++ token->length = 0; + + acceptor_flag = ctx->initiate ? 0 : FLAG_SENDER_IS_ACCEPTOR; + key_usage = (toktype == KG_TOK_WRAP_MSG +@@ -107,14 +111,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + + if (toktype == KG_TOK_WRAP_MSG && conf_req_flag) { +- krb5_data plain; + krb5_enc_data cipher; + size_t ec_max; + size_t encrypt_size; + + /* 300: Adds some slop. */ +- if (SIZE_MAX - 300 < message->length) +- return ENOMEM; ++ if (SIZE_MAX - 300 < message->length) { ++ err = ENOMEM; ++ goto cleanup; ++ } + ec_max = SIZE_MAX - message->length - 300; + if (ec_max > 0xffff) + ec_max = 0xffff; +@@ -126,20 +131,20 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + err = alloc_data(&plain, message->length + 16 + ec); + if (err) +- return err; ++ goto cleanup; + + /* Get size of ciphertext. */ + encrypt_size = krb5_encrypt_size(plain.length, key->keyblock.enctype); + if (encrypt_size > SIZE_MAX / 2) { + err = ENOMEM; +- goto error; ++ goto cleanup; + } + bufsize = 16 + encrypt_size; + /* Allocate space for header plus encrypted data. */ + outbuf = gssalloc_malloc(bufsize); + if (outbuf == NULL) { +- free(plain.data); +- return ENOMEM; ++ err = ENOMEM; ++ goto cleanup; + } + + /* TOK_ID */ +@@ -164,11 +169,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + cipher.ciphertext.length = bufsize - 16; + cipher.enctype = key->keyblock.enctype; + err = krb5_k_encrypt(context, key, key_usage, 0, &plain, &cipher); +- zap(plain.data, plain.length); +- free(plain.data); +- plain.data = 0; + if (err) +- goto error; ++ goto cleanup; + + /* Now that we know we're returning a valid token.... */ + ctx->seq_send++; +@@ -181,7 +183,6 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + /* If the rotate fails, don't worry about it. */ + #endif + } else if (toktype == KG_TOK_WRAP_MSG && !conf_req_flag) { +- krb5_data plain; + size_t cksumsize; + + /* Here, message is the application-supplied data; message2 is +@@ -193,21 +194,19 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + wrap_with_checksum: + err = alloc_data(&plain, message->length + 16); + if (err) +- return err; ++ goto cleanup; + + err = krb5_c_checksum_length(context, cksumtype, &cksumsize); + if (err) +- goto error; ++ goto cleanup; + + assert(cksumsize <= 0xffff); + + bufsize = 16 + message2->length + cksumsize; + outbuf = gssalloc_malloc(bufsize); + if (outbuf == NULL) { +- free(plain.data); +- plain.data = 0; + err = ENOMEM; +- goto error; ++ goto cleanup; + } + + /* TOK_ID */ +@@ -239,23 +238,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + if (message2->length) + memcpy(outbuf + 16, message2->value, message2->length); + +- sum.contents = outbuf + 16 + message2->length; +- sum.length = cksumsize; +- + err = krb5_k_make_checksum(context, cksumtype, key, + key_usage, &plain, &sum); +- zap(plain.data, plain.length); +- free(plain.data); +- plain.data = 0; + if (err) { + zap(outbuf,bufsize); +- goto error; ++ goto cleanup; + } + if (sum.length != cksumsize) + abort(); + memcpy(outbuf + 16 + message2->length, sum.contents, cksumsize); +- krb5_free_checksum_contents(context, &sum); +- sum.contents = 0; + /* Now that we know we're actually generating the token... */ + ctx->seq_send++; + +@@ -285,12 +276,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + + token->value = outbuf; + token->length = bufsize; +- return 0; ++ outbuf = NULL; ++ err = 0; + +-error: ++cleanup: ++ krb5_free_checksum_contents(context, &sum); ++ zapfree(plain.data, plain.length); + gssalloc_free(outbuf); +- token->value = NULL; +- token->length = 0; + return err; + } + +diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c +index 434e4eea65..f55ca46c60 100644 +--- a/src/lib/rpc/pmap_rmt.c ++++ b/src/lib/rpc/pmap_rmt.c +@@ -161,12 +161,12 @@ xdr_rmtcallres( + caddr_t port_ptr; + + port_ptr = (caddr_t)(void *)crp->port_ptr; +- if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), +- (xdrproc_t)xdr_u_int32) && +- xdr_u_int32(xdrs, &crp->resultslen)) { +- crp->port_ptr = (uint32_t *)(void *)port_ptr; ++ if (!xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), ++ (xdrproc_t)xdr_u_int32)) ++ return (FALSE); ++ crp->port_ptr = (uint32_t *)(void *)port_ptr; ++ if (xdr_u_int32(xdrs, &crp->resultslen)) + return ((*(crp->xdr_results))(xdrs, crp->results_ptr)); +- } + return (FALSE); + } + +-- +2.45.1 + diff --git a/0018-Fix-unimportant-memory-leaks.patch b/0018-Fix-unimportant-memory-leaks.patch new file mode 100644 index 0000000..0697f06 --- /dev/null +++ b/0018-Fix-unimportant-memory-leaks.patch @@ -0,0 +1,2316 @@ +From c8d8cab52172a934bdad1041448b43bc15acf441 Mon Sep 17 00:00:00 2001 +From: Steve Grubb +Date: Thu, 13 Jul 2023 16:22:30 -0400 +Subject: [PATCH] Fix unimportant memory leaks + +Eliminate memory leaks detected through static analysis and manual +review. These leaks are unlikely to happen repeatedly in long-running +processes. + +[jrische@redhat.com: fixed many additional leaks] +[ghudson@mit.edu: fixed additional leaks; edited for style; removed +some unused ksu functions; rewrote commit message] + +(cherry picked from commit 6c5471176f5266564fbc8a7e02f03b4b042202f8) +--- + src/appl/gss-sample/gss-client.c | 367 ++++++++---------- + src/appl/gss-sample/gss-server.c | 3 +- + src/clients/klist/klist.c | 59 +-- + src/clients/ksu/authorization.c | 134 +++---- + src/clients/ksu/ccache.c | 283 +++++--------- + src/clients/ksu/heuristic.c | 128 +++--- + src/clients/ksu/krb_auth_su.c | 134 ++----- + src/clients/ksu/ksu.h | 6 - + src/clients/ksu/main.c | 3 +- + src/kadmin/cli/keytab.c | 6 +- + src/kadmin/ktutil/ktutil.c | 1 + + src/kprop/kpropd.c | 21 +- + src/lib/gssapi/krb5/export_cred.c | 4 +- + src/lib/gssapi/krb5/val_cred.c | 6 +- + src/lib/kadm5/srv/server_kdb.c | 7 +- + src/lib/krb5/ccache/cc_kcm.c | 4 + + src/lib/krb5/ccache/ccfns.c | 12 +- + src/lib/krb5/keytab/kt_file.c | 3 +- + src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c | 8 +- + 19 files changed, 517 insertions(+), 672 deletions(-) + +diff --git a/src/appl/gss-sample/gss-client.c b/src/appl/gss-sample/gss-client.c +index 0722ae196f..2cfcfc6cc5 100644 +--- a/src/appl/gss-sample/gss-client.c ++++ b/src/appl/gss-sample/gss-client.c +@@ -182,180 +182,148 @@ client_establish_context(int s, char *service_name, OM_uint32 gss_flags, + char *username, char *password, + gss_ctx_id_t *gss_context, OM_uint32 *ret_flags) + { +- if (auth_flag) { +- gss_buffer_desc send_tok, recv_tok, *token_ptr; +- gss_name_t target_name; +- OM_uint32 maj_stat, min_stat, init_sec_min_stat; +- int token_flags; +- gss_cred_id_t cred = GSS_C_NO_CREDENTIAL; +- gss_name_t gss_username = GSS_C_NO_NAME; +- gss_OID_set_desc mechs, *mechsp = GSS_C_NO_OID_SET; +- +- if (spnego) { +- mechs.elements = &gss_spnego_mechanism_oid_desc; +- mechs.count = 1; +- mechsp = &mechs; +- } else if (oid != GSS_C_NO_OID) { +- mechs.elements = oid; +- mechs.count = 1; +- mechsp = &mechs; +- } else { +- mechs.elements = NULL; +- mechs.count = 0; +- } ++ int result = -1, st; ++ gss_buffer_desc send_tok, recv_tok, pwbuf, *token_ptr; ++ gss_name_t target_name = GSS_C_NO_NAME, gss_username = GSS_C_NO_NAME; ++ OM_uint32 maj_stat, min_stat, init_sec_min_stat; ++ int token_flags; ++ gss_cred_id_t cred = GSS_C_NO_CREDENTIAL; ++ gss_OID_set_desc mechs, neg_mechs, *mechsp = GSS_C_NO_OID_SET; ++ ++ if (!auth_flag) ++ return send_token(s, TOKEN_NOOP, empty_token); ++ ++ if (spnego) { ++ mechs.elements = &gss_spnego_mechanism_oid_desc; ++ mechs.count = 1; ++ mechsp = &mechs; ++ } else if (oid != GSS_C_NO_OID) { ++ mechs.elements = oid; ++ mechs.count = 1; ++ mechsp = &mechs; ++ } else { ++ mechs.elements = NULL; ++ mechs.count = 0; ++ } + +- if (username != NULL) { +- send_tok.value = username; +- send_tok.length = strlen(username); ++ if (username != NULL) { ++ send_tok.value = username; ++ send_tok.length = strlen(username); + +- maj_stat = gss_import_name(&min_stat, &send_tok, +- (gss_OID) gss_nt_user_name, +- &gss_username); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("parsing client name", maj_stat, min_stat); +- return -1; +- } +- } +- +- if (password != NULL) { +- gss_buffer_desc pwbuf; +- +- pwbuf.value = password; +- pwbuf.length = strlen(password); +- +- maj_stat = gss_acquire_cred_with_password(&min_stat, +- gss_username, +- &pwbuf, 0, +- mechsp, GSS_C_INITIATE, +- &cred, NULL, NULL); +- } else if (gss_username != GSS_C_NO_NAME) { +- maj_stat = gss_acquire_cred(&min_stat, +- gss_username, 0, +- mechsp, GSS_C_INITIATE, +- &cred, NULL, NULL); +- } else +- maj_stat = GSS_S_COMPLETE; ++ maj_stat = gss_import_name(&min_stat, &send_tok, ++ (gss_OID) gss_nt_user_name, &gss_username); + if (maj_stat != GSS_S_COMPLETE) { +- display_status("acquiring creds", maj_stat, min_stat); +- gss_release_name(&min_stat, &gss_username); +- return -1; ++ display_status("parsing client name", maj_stat, min_stat); ++ goto cleanup; + } +- if (spnego && oid != GSS_C_NO_OID) { +- gss_OID_set_desc neg_mechs; +- +- neg_mechs.elements = oid; +- neg_mechs.count = 1; ++ } + +- maj_stat = gss_set_neg_mechs(&min_stat, cred, &neg_mechs); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("setting neg mechs", maj_stat, min_stat); +- gss_release_name(&min_stat, &gss_username); +- gss_release_cred(&min_stat, &cred); +- return -1; +- } +- } +- gss_release_name(&min_stat, &gss_username); +- +- /* +- * Import the name into target_name. Use send_tok to save +- * local variable space. +- */ +- send_tok.value = service_name; +- send_tok.length = strlen(service_name); +- maj_stat = gss_import_name(&min_stat, &send_tok, +- (gss_OID) gss_nt_service_name, +- &target_name); ++ if (password != NULL) { ++ pwbuf.value = password; ++ pwbuf.length = strlen(password); ++ ++ maj_stat = gss_acquire_cred_with_password(&min_stat, gss_username, ++ &pwbuf, 0, mechsp, ++ GSS_C_INITIATE, &cred, NULL, ++ NULL); ++ } else if (gss_username != GSS_C_NO_NAME) { ++ maj_stat = gss_acquire_cred(&min_stat, gss_username, 0, mechsp, ++ GSS_C_INITIATE, &cred, NULL, NULL); ++ } else { ++ maj_stat = GSS_S_COMPLETE; ++ } ++ if (maj_stat != GSS_S_COMPLETE) { ++ display_status("acquiring creds", maj_stat, min_stat); ++ goto cleanup; ++ } ++ if (spnego && oid != GSS_C_NO_OID) { ++ neg_mechs.elements = oid; ++ neg_mechs.count = 1; ++ maj_stat = gss_set_neg_mechs(&min_stat, cred, &neg_mechs); + if (maj_stat != GSS_S_COMPLETE) { +- display_status("parsing name", maj_stat, min_stat); +- return -1; ++ display_status("setting neg mechs", maj_stat, min_stat); ++ goto cleanup; + } ++ } + +- if (!v1_format) { +- if (send_token(s, TOKEN_NOOP | TOKEN_CONTEXT_NEXT, empty_token) < +- 0) { +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } +- } ++ /* Import the name into target_name. Use send_tok to save local variable ++ * space. */ ++ send_tok.value = service_name; ++ send_tok.length = strlen(service_name); ++ maj_stat = gss_import_name(&min_stat, &send_tok, ++ (gss_OID) gss_nt_service_name, &target_name); ++ if (maj_stat != GSS_S_COMPLETE) { ++ display_status("parsing name", maj_stat, min_stat); ++ goto cleanup; ++ } + +- /* +- * Perform the context-establishement loop. +- * +- * On each pass through the loop, token_ptr points to the token +- * to send to the server (or GSS_C_NO_BUFFER on the first pass). +- * Every generated token is stored in send_tok which is then +- * transmitted to the server; every received token is stored in +- * recv_tok, which token_ptr is then set to, to be processed by +- * the next call to gss_init_sec_context. +- * +- * GSS-API guarantees that send_tok's length will be non-zero +- * if and only if the server is expecting another token from us, +- * and that gss_init_sec_context returns GSS_S_CONTINUE_NEEDED if +- * and only if the server has another token to send us. +- */ +- +- token_ptr = GSS_C_NO_BUFFER; +- *gss_context = GSS_C_NO_CONTEXT; +- +- do { +- maj_stat = gss_init_sec_context(&init_sec_min_stat, +- cred, gss_context, +- target_name, mechs.elements, +- gss_flags, 0, +- NULL, /* channel bindings */ +- token_ptr, NULL, /* mech type */ +- &send_tok, ret_flags, +- NULL); /* time_rec */ +- +- if (token_ptr != GSS_C_NO_BUFFER) +- free(recv_tok.value); +- +- if (send_tok.length != 0) { +- if (verbose) +- printf("Sending init_sec_context token (size=%d)...", +- (int) send_tok.length); +- if (send_token(s, v1_format ? 0 : TOKEN_CONTEXT, &send_tok) < +- 0) { +- (void) gss_release_buffer(&min_stat, &send_tok); +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } ++ if (!v1_format) { ++ if (send_token(s, TOKEN_NOOP | TOKEN_CONTEXT_NEXT, empty_token) < 0) ++ goto cleanup; ++ } ++ ++ /* ++ * Perform the context-establishment loop. ++ * ++ * On each pass through the loop, token_ptr points to the token to send to ++ * the server (or GSS_C_NO_BUFFER on the first pass). Every generated ++ * token is stored in send_tok which is then transmitted to the server; ++ * every received token is stored in recv_tok, which token_ptr is then set ++ * to, to be processed by the next call to gss_init_sec_context. ++ * ++ * GSS-API guarantees that send_tok's length will be non-zero if and only ++ * if the server is expecting another token from us, and that ++ * gss_init_sec_context returns GSS_S_CONTINUE_NEEDED if and only if the ++ * server has another token to send us. ++ */ ++ ++ token_ptr = GSS_C_NO_BUFFER; ++ *gss_context = GSS_C_NO_CONTEXT; ++ ++ do { ++ maj_stat = gss_init_sec_context(&init_sec_min_stat, cred, gss_context, ++ target_name, mechs.elements, gss_flags, ++ 0, NULL, token_ptr, NULL, &send_tok, ++ ret_flags, NULL); ++ ++ if (token_ptr != GSS_C_NO_BUFFER) ++ free(recv_tok.value); ++ ++ if (send_tok.length > 0) { ++ if (verbose) { ++ printf("Sending init_sec_context token (size=%d)...", ++ (int) send_tok.length); + } ++ st = send_token(s, v1_format ? 0 : TOKEN_CONTEXT, &send_tok); + (void) gss_release_buffer(&min_stat, &send_tok); ++ if (st < 0) ++ goto cleanup; ++ } + +- if (maj_stat != GSS_S_COMPLETE +- && maj_stat != GSS_S_CONTINUE_NEEDED) { +- display_status("initializing context", maj_stat, +- init_sec_min_stat); +- (void) gss_release_name(&min_stat, &target_name); +- (void) gss_release_cred(&min_stat, &cred); +- if (*gss_context != GSS_C_NO_CONTEXT) +- gss_delete_sec_context(&min_stat, gss_context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ if (maj_stat != GSS_S_COMPLETE && maj_stat != GSS_S_CONTINUE_NEEDED) { ++ display_status("initializing context", maj_stat, ++ init_sec_min_stat); ++ goto cleanup; ++ } + +- if (maj_stat == GSS_S_CONTINUE_NEEDED) { +- if (verbose) +- printf("continue needed..."); +- if (recv_token(s, &token_flags, &recv_tok) < 0) { +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } +- token_ptr = &recv_tok; +- } ++ if (maj_stat == GSS_S_CONTINUE_NEEDED) { + if (verbose) +- printf("\n"); +- } while (maj_stat == GSS_S_CONTINUE_NEEDED); ++ printf("continue needed..."); ++ if (recv_token(s, &token_flags, &recv_tok) < 0) ++ goto cleanup; ++ token_ptr = &recv_tok; ++ } ++ if (verbose) ++ printf("\n"); ++ } while (maj_stat == GSS_S_CONTINUE_NEEDED); + +- (void) gss_release_cred(&min_stat, &cred); +- (void) gss_release_name(&min_stat, &target_name); +- } else { +- if (send_token(s, TOKEN_NOOP, empty_token) < 0) +- return -1; +- } ++ result = 0; + +- return 0; ++cleanup: ++ (void) gss_release_name(&min_stat, &gss_username); ++ (void) gss_release_cred(&min_stat, &cred); ++ (void) gss_release_name(&min_stat, &target_name); ++ return result; + } + + static void +@@ -436,11 +404,11 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + { + gss_ctx_id_t context = GSS_C_NO_CONTEXT; + gss_buffer_desc in_buf, out_buf; +- int s, state; ++ int s = -1, result = -1, state; + OM_uint32 ret_flags; + OM_uint32 maj_stat, min_stat; +- gss_name_t src_name, targ_name; +- gss_buffer_desc sname, tname; ++ gss_name_t src_name = GSS_C_NO_NAME, targ_name = GSS_C_NO_NAME; ++ gss_buffer_desc sname = GSS_C_EMPTY_BUFFER, tname = GSS_C_EMPTY_BUFFER; + OM_uint32 lifetime; + gss_OID mechanism, name_type; + int is_local; +@@ -454,14 +422,13 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + + /* Open connection */ + if ((s = connect_to_server(host, port)) < 0) +- return -1; ++ goto cleanup; + + /* Establish context */ + if (client_establish_context(s, service_name, gss_flags, auth_flag, + v1_format, oid, username, password, + &context, &ret_flags) < 0) { +- (void) closesocket(s); +- return -1; ++ goto cleanup; + } + + if (auth_flag && verbose) { +@@ -475,19 +442,19 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + &is_local, &is_open); + if (maj_stat != GSS_S_COMPLETE) { + display_status("inquiring context", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + + maj_stat = gss_display_name(&min_stat, src_name, &sname, &name_type); + if (maj_stat != GSS_S_COMPLETE) { + display_status("displaying source name", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + maj_stat = gss_display_name(&min_stat, targ_name, &tname, + (gss_OID *) NULL); + if (maj_stat != GSS_S_COMPLETE) { + display_status("displaying target name", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("\"%.*s\" to \"%.*s\", lifetime %d, flags %x, %s, %s\n", + (int) sname.length, (char *) sname.value, +@@ -496,15 +463,10 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + (is_local) ? "locally initiated" : "remotely initiated", + (is_open) ? "open" : "closed"); + +- (void) gss_release_name(&min_stat, &src_name); +- (void) gss_release_name(&min_stat, &targ_name); +- (void) gss_release_buffer(&min_stat, &sname); +- (void) gss_release_buffer(&min_stat, &tname); +- + maj_stat = gss_oid_to_str(&min_stat, name_type, &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("Name type of source name is %.*s.\n", + (int) oid_name.length, (char *) oid_name.value); +@@ -515,13 +477,13 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + mechanism, &mech_names); + if (maj_stat != GSS_S_COMPLETE) { + display_status("inquiring mech names", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + + maj_stat = gss_oid_to_str(&min_stat, mechanism, &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("Mechanism %.*s supports %d names\n", + (int) oid_name.length, (char *) oid_name.value, +@@ -533,7 +495,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + &mech_names->elements[i], &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf(" %d: %.*s\n", (int) i, + (int) oid_name.length, (char *) oid_name.value); +@@ -558,10 +520,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + &in_buf, &state, &out_buf); + if (maj_stat != GSS_S_COMPLETE) { + display_status("wrapping message", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; ++ goto cleanup; + } else if (encrypt_flag && !state) { + fprintf(stderr, "Warning! Message not encrypted.\n"); + } +@@ -575,22 +534,15 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + (wrap_flag ? TOKEN_WRAPPED : 0) | + (encrypt_flag ? TOKEN_ENCRYPTED : 0) | + (mic_flag ? TOKEN_SEND_MIC : 0))), +- &out_buf) < 0) { +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ &out_buf) < 0) ++ goto cleanup; ++ + if (out_buf.value != in_buf.value) + (void) gss_release_buffer(&min_stat, &out_buf); + + /* Read signature block into out_buf */ +- if (recv_token(s, &token_flags, &out_buf) < 0) { +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ if (recv_token(s, &token_flags, &out_buf) < 0) ++ goto cleanup; + + if (mic_flag) { + /* Verify signature block */ +@@ -598,10 +550,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + &out_buf, &qop_state); + if (maj_stat != GSS_S_COMPLETE) { + display_status("verifying signature", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; ++ goto cleanup; + } + + if (verbose) +@@ -621,23 +570,17 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, + if (!v1_format) + (void) send_token(s, TOKEN_NOOP, empty_token); + +- if (auth_flag) { +- /* Delete context */ +- maj_stat = gss_delete_sec_context(&min_stat, &context, &out_buf); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("deleting context", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } +- +- (void) gss_release_buffer(&min_stat, &out_buf); +- } +- +- (void) closesocket(s); ++ result = 0; + +- return 0; ++cleanup: ++ (void) gss_release_name(&min_stat, &src_name); ++ (void) gss_release_name(&min_stat, &targ_name); ++ (void) gss_release_buffer(&min_stat, &sname); ++ (void) gss_release_buffer(&min_stat, &tname); ++ (void) gss_delete_sec_context(&min_stat, &context, GSS_C_NO_BUFFER); ++ if (s >= 0) ++ (void) closesocket(s); ++ return result; + } + + static void +diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c +index 0e9c857e56..4ba864d9fb 100644 +--- a/src/appl/gss-sample/gss-server.c ++++ b/src/appl/gss-sample/gss-server.c +@@ -138,13 +138,12 @@ server_acquire_creds(char *service_name, gss_OID mech, + } + maj_stat = gss_acquire_cred(&min_stat, server_name, 0, mechs, GSS_C_ACCEPT, + server_creds, NULL, NULL); ++ (void) gss_release_name(&min_stat, &server_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("acquiring credentials", maj_stat, min_stat); + return -1; + } + +- (void) gss_release_name(&min_stat, &server_name); +- + return 0; + } + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index c797b1698f..b5ae96a843 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -469,20 +469,21 @@ do_ccache() + static int + show_ccache(krb5_ccache cache) + { +- krb5_cc_cursor cur; ++ krb5_cc_cursor cur = NULL; + krb5_creds creds; +- krb5_principal princ; ++ krb5_principal princ = NULL; + krb5_error_code ret; ++ int status = 1; + + ret = krb5_cc_get_principal(context, cache, &princ); + if (ret) { + com_err(progname, ret, ""); +- return 1; ++ goto cleanup; + } + ret = krb5_unparse_name(context, princ, &defname); + if (ret) { + com_err(progname, ret, _("while unparsing principal name")); +- return 1; ++ goto cleanup; + } + + printf(_("Ticket cache: %s:%s\nDefault principal: %s\n\n"), +@@ -498,27 +499,33 @@ show_ccache(krb5_ccache cache) + ret = krb5_cc_start_seq_get(context, cache, &cur); + if (ret) { + com_err(progname, ret, _("while starting to retrieve tickets")); +- return 1; ++ goto cleanup; + } + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (show_config || !krb5_is_config_principal(context, creds.server)) + show_credential(&creds); + krb5_free_cred_contents(context, &creds); + } +- krb5_free_principal(context, princ); +- krb5_free_unparsed_name(context, defname); +- defname = NULL; + if (ret == KRB5_CC_END) { + ret = krb5_cc_end_seq_get(context, cache, &cur); ++ cur = NULL; + if (ret) { + com_err(progname, ret, _("while finishing ticket retrieval")); +- return 1; ++ goto cleanup; + } +- return 0; + } else { + com_err(progname, ret, _("while retrieving a ticket")); +- return 1; ++ goto cleanup; + } ++ ++ status = 0; ++ ++cleanup: ++ if (cur != NULL) ++ (void)krb5_cc_end_seq_get(context, cache, &cur); ++ krb5_free_principal(context, princ); ++ krb5_free_unparsed_name(context, defname); ++ return status; + } + + /* Return 0 if cache is accessible, present, and unexpired; return 1 if not. */ +@@ -526,15 +533,18 @@ static int + check_ccache(krb5_ccache cache) + { + krb5_error_code ret; +- krb5_cc_cursor cur; ++ krb5_cc_cursor cur = NULL; + krb5_creds creds; +- krb5_principal princ; +- krb5_boolean found_tgt, found_current_tgt, found_current_cred; ++ krb5_principal princ = NULL; ++ krb5_boolean found_tgt = FALSE, found_current_tgt = FALSE; ++ krb5_boolean found_current_cred = FALSE; + +- if (krb5_cc_get_principal(context, cache, &princ) != 0) +- return 1; +- if (krb5_cc_start_seq_get(context, cache, &cur) != 0) +- return 1; ++ ret = krb5_cc_get_principal(context, cache, &princ); ++ if (ret) ++ goto cleanup; ++ ret = krb5_cc_start_seq_get(context, cache, &cur); ++ if (ret) ++ goto cleanup; + found_tgt = found_current_tgt = found_current_cred = FALSE; + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (is_local_tgt(creds.server, &princ->realm)) { +@@ -547,12 +557,17 @@ check_ccache(krb5_ccache cache) + } + krb5_free_cred_contents(context, &creds); + } +- krb5_free_principal(context, princ); + if (ret != KRB5_CC_END) +- return 1; +- if (krb5_cc_end_seq_get(context, cache, &cur) != 0) +- return 1; ++ goto cleanup; ++ ret = krb5_cc_end_seq_get(context, cache, &cur); ++ cur = NULL; + ++cleanup: ++ if (cur != NULL) ++ (void)krb5_cc_end_seq_get(context, cache, &cur); ++ krb5_free_principal(context, princ); ++ if (ret) ++ return 1; + /* If the cache contains at least one local TGT, require that it be + * current. Otherwise accept any current cred. */ + if (found_tgt) +diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c +index 17a8a8f2f0..1f2650c2ab 100644 +--- a/src/clients/ksu/authorization.c ++++ b/src/clients/ksu/authorization.c +@@ -28,7 +28,17 @@ + + #include "ksu.h" + +-static void auth_cleanup (FILE *, FILE *, char *); ++static void ++free_fcmd_list(char **list) ++{ ++ size_t i; ++ ++ if (list == NULL) ++ return; ++ for (i = 0; i < MAX_CMD && list[i] != NULL; i++) ++ free(list[i]); ++ free(list); ++} + + krb5_boolean + fowner(FILE *fp, uid_t uid) +@@ -52,10 +62,10 @@ fowner(FILE *fp, uid_t uid) + + /* + * Given a Kerberos principal "principal", and a local username "luser", +- * determine whether user is authorized to login according to the +- * authorization files ~luser/.k5login" and ~luser/.k5users. Returns TRUE +- * if authorized, FALSE if not authorized. +- * ++ * determine whether user is authorized to login according to the authorization ++ * files ~luser/.k5login" and ~luser/.k5users. Set *ok to TRUE if authorized, ++ * FALSE if not authorized. Return 0 if the authorization check succeeded ++ * (regardless of its result), non-zero if it encountered an error. + */ + + krb5_error_code +@@ -64,7 +74,7 @@ krb5_authorization(krb5_context context, krb5_principal principal, + char **out_fcmd) + { + struct passwd *pwd; +- char *princname; ++ char *princname = NULL; + int k5login_flag =0; + int k5users_flag =0; + krb5_boolean retbool =FALSE; +@@ -76,7 +86,7 @@ krb5_authorization(krb5_context context, krb5_principal principal, + + /* no account => no access */ + if ((pwd = getpwnam(luser)) == NULL) +- return 0; ++ goto cleanup; + + retval = krb5_unparse_name(context, principal, &princname); + if (retval) +@@ -93,22 +103,19 @@ krb5_authorization(krb5_context context, krb5_principal principal, + + /* k5login and k5users must be owned by target user or root */ + if (!k5login_flag){ +- if ((login_fp = fopen(k5login_path, "r")) == NULL) +- return 0; +- if ( fowner(login_fp, pwd->pw_uid) == FALSE) { +- fclose(login_fp); +- return 0; +- } ++ login_fp = fopen(k5login_path, "r"); ++ if (login_fp == NULL) ++ goto cleanup; ++ if (fowner(login_fp, pwd->pw_uid) == FALSE) ++ goto cleanup; + } + + if (!k5users_flag){ +- if ((users_fp = fopen(k5users_path, "r")) == NULL) { +- return 0; +- } +- if ( fowner(users_fp, pwd->pw_uid) == FALSE){ +- fclose(users_fp); +- return 0; +- } ++ users_fp = fopen(k5users_path, "r"); ++ if (users_fp == NULL) ++ goto cleanup; ++ if (fowner(users_fp, pwd->pw_uid) == FALSE) ++ goto cleanup; + } + + if (auth_debug){ +@@ -127,10 +134,8 @@ krb5_authorization(krb5_context context, krb5_principal principal, + princname); + + retval = k5login_lookup(login_fp, princname, &retbool); +- if (retval) { +- auth_cleanup(users_fp, login_fp, princname); +- return retval; +- } ++ if (retval) ++ goto cleanup; + if (retbool) { + if (cmd) + *out_fcmd = xstrdup(cmd); +@@ -140,10 +145,8 @@ krb5_authorization(krb5_context context, krb5_principal principal, + if ((!k5users_flag) && (retbool == FALSE) ){ + retval = k5users_lookup (users_fp, princname, + cmd, &retbool, out_fcmd); +- if(retval) { +- auth_cleanup(users_fp, login_fp, princname); +- return retval; +- } ++ if (retval) ++ goto cleanup; + } + + if (k5login_flag && k5users_flag){ +@@ -159,8 +162,14 @@ krb5_authorization(krb5_context context, krb5_principal principal, + } + + *ok =retbool; +- auth_cleanup(users_fp, login_fp, princname); +- return 0; ++ ++cleanup: ++ if (users_fp != NULL) ++ fclose(users_fp); ++ if (login_fp != NULL) ++ fclose(login_fp); ++ free(princname); ++ return retval; + } + + /*********************************************************** +@@ -320,10 +329,11 @@ krb5_boolean + fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + { + char * err; +- char ** tmp_fcmd; ++ char ** tmp_fcmd = NULL; + char * path_ptr, *path; + char * lp, * tc; + int i=0; ++ krb5_boolean ok = FALSE; + + tmp_fcmd = (char **) xcalloc (MAX_CMD, sizeof(char *)); + +@@ -331,7 +341,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + tmp_fcmd[0] = xstrdup(fcmd); + tmp_fcmd[1] = NULL; + *out_fcmd = tmp_fcmd; +- return TRUE; ++ tmp_fcmd = NULL; + }else{ + /* must be either full path or just the cmd name */ + if (strchr(fcmd, '/')){ +@@ -339,7 +349,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + "either full path or just the cmd name\n"), + fcmd, KRB5_USERS_NAME); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + #ifndef CMD_PATH +@@ -347,7 +357,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + "the cmd name, CMD_PATH must be defined \n"), + fcmd, KRB5_USERS_NAME, fcmd); + *out_err = err; +- return FALSE; ++ goto cleanup; + #else + + path = xstrdup (CMD_PATH); +@@ -361,7 +371,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + asprintf(&err, _("Error: bad entry - %s in %s file, CMD_PATH " + "contains no paths \n"), fcmd, KRB5_USERS_NAME); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + i=0; +@@ -370,7 +380,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + asprintf(&err, _("Error: bad path %s in CMD_PATH for %s must " + "start with '/' \n"), tc, KRB5_USERS_NAME ); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + tmp_fcmd[i] = xasprintf("%s/%s", tc, fcmd); +@@ -381,10 +391,15 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + + tmp_fcmd[i] = NULL; + *out_fcmd = tmp_fcmd; +- return TRUE; +- ++ tmp_fcmd = NULL; + #endif /* CMD_PATH */ + } ++ ++ ok = TRUE; ++ ++cleanup: ++ free_fcmd_list(tmp_fcmd); ++ return ok; + } + + /******************************************** +@@ -503,41 +518,42 @@ int + match_commands(char *fcmd, char *cmd, krb5_boolean *match, + char **cmd_out, char **err_out) + { +- char ** fcmd_arr; ++ char ** fcmd_arr = NULL; + char * err; + char * cmd_temp; ++ int result = 1; + + if(fcmd_resolve(fcmd, &fcmd_arr, &err )== FALSE ){ + *err_out = err; +- return 1; ++ goto cleanup; + } + + if (cmd_single( cmd ) == TRUE){ + if (!cmd_arr_cmp_postfix(fcmd_arr, cmd)){ /* found */ +- +- if(find_first_cmd_that_exists( fcmd_arr,&cmd_temp,&err)== TRUE){ +- *match = TRUE; +- *cmd_out = cmd_temp; +- return 0; +- }else{ ++ if (!find_first_cmd_that_exists(fcmd_arr, &cmd_temp, &err)) { + *err_out = err; +- return 1; ++ goto cleanup; + } +- }else{ ++ ++ *match = TRUE; ++ *cmd_out = cmd_temp; ++ } else { + *match = FALSE; +- return 0; + } + }else{ + if (!cmd_arr_cmp(fcmd_arr, cmd)){ /* found */ + *match = TRUE; + *cmd_out = xstrdup(cmd); +- return 0; + } else{ + *match = FALSE; +- return 0; + } + } + ++ result = 0; ++ ++cleanup: ++ free_fcmd_list(fcmd_arr); ++ return result; + } + + /********************************************************* +@@ -563,10 +579,7 @@ get_line(FILE *fp, char **out_line) + } + else { + chunk_count ++; +- if(!( line = (char *) realloc( line, +- chunk_count * sizeof(char) * BUFSIZ))){ +- return ENOMEM; +- } ++ line = xrealloc(line, chunk_count * BUFSIZ); + + line_ptr = line + (BUFSIZ -1) *( chunk_count -1) ; + } +@@ -652,17 +665,6 @@ get_next_token (char **lnext) + return out_ptr; + } + +-static void +-auth_cleanup(FILE *users_fp, FILE *login_fp, char *princname) +-{ +- +- free (princname); +- if (users_fp) +- fclose(users_fp); +- if (login_fp) +- fclose(login_fp); +-} +- + void + init_auth_names(char *pw_dir) + { +diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c +index cca9ce2dfc..76cb1d6aa4 100644 +--- a/src/clients/ksu/ccache.c ++++ b/src/clients/ksu/ccache.c +@@ -40,6 +40,18 @@ copies the default cache into the secondary cache, + + ************************************************************************/ + ++static void ++free_creds_list(krb5_context context, krb5_creds **list) ++{ ++ size_t i; ++ ++ if (list == NULL) ++ return; ++ for (i = 0; list[i]; i++) ++ krb5_free_creds(context, list[i]); ++ free(list); ++} ++ + void show_credential(krb5_context, krb5_creds *, krb5_ccache); + + /* modifies only the cc_other, the algorithm may look a bit funny, +@@ -53,20 +65,19 @@ krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, + krb5_boolean restrict_creds, krb5_principal primary_principal, + krb5_boolean *stored) + { +- int i=0; + krb5_error_code retval=0; + krb5_creds ** cc_def_creds_arr = NULL; + krb5_creds ** cc_other_creds_arr = NULL; + + if (ks_ccache_is_initialized(context, cc_def)) { +- if((retval = krb5_get_nonexp_tkts(context,cc_def,&cc_def_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc_def, &cc_def_creds_arr); ++ if (retval) ++ goto cleanup; + } + + retval = krb5_cc_initialize(context, cc_target, target_principal); + if (retval) +- return retval; ++ goto cleanup; + + if (restrict_creds) { + retval = krb5_store_some_creds(context, cc_target, cc_def_creds_arr, +@@ -79,22 +90,9 @@ krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, + cc_other_creds_arr); + } + +- if (cc_def_creds_arr){ +- while (cc_def_creds_arr[i]){ +- krb5_free_creds(context, cc_def_creds_arr[i]); +- i++; +- } +- } +- +- i=0; +- +- if(cc_other_creds_arr){ +- while (cc_other_creds_arr[i]){ +- krb5_free_creds(context, cc_other_creds_arr[i]); +- i++; +- } +- } +- ++cleanup: ++ free_creds_list(context, cc_def_creds_arr); ++ free_creds_list(context, cc_other_creds_arr); + return retval; + } + +@@ -184,32 +182,29 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, + { + + krb5_creds creds, temp_tktq, temp_tkt; +- krb5_creds **temp_creds; ++ krb5_creds **temp_creds = NULL; + krb5_error_code retval=0; + krb5_cc_cursor cur; + int count = 0; + int chunk_count = 1; + +- if ( ! ( temp_creds = (krb5_creds **) malloc( CHUNK * sizeof(krb5_creds *)))){ +- return ENOMEM; +- } +- +- ++ temp_creds = xcalloc(CHUNK, sizeof(*temp_creds)); + memset(&temp_tktq, 0, sizeof(temp_tktq)); + memset(&temp_tkt, 0, sizeof(temp_tkt)); + memset(&creds, 0, sizeof(creds)); + + /* initialize the cursor */ +- if ((retval = krb5_cc_start_seq_get(context, cc, &cur))) { +- return retval; +- } ++ retval = krb5_cc_start_seq_get(context, cc, &cur); ++ if (retval) ++ goto cleanup; + + while (!(retval = krb5_cc_next_cred(context, cc, &cur, &creds))){ + + if (!krb5_is_config_principal(context, creds.server) && + (retval = krb5_check_exp(context, creds.times))){ ++ krb5_free_cred_contents(context, &creds); + if (retval != KRB5KRB_AP_ERR_TKT_EXPIRED){ +- return retval; ++ goto cleanup; + } + if (auth_debug){ + fprintf(stderr,"krb5_ccache_copy: CREDS EXPIRED:\n"); +@@ -219,19 +214,19 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, + } + } + else { /* these credentials didn't expire */ +- +- if ((retval = krb5_copy_creds(context, &creds, +- &temp_creds[count]))){ +- return retval; +- } ++ retval = krb5_copy_creds(context, &creds, &temp_creds[count]); ++ krb5_free_cred_contents(context, &creds); ++ temp_creds[count+1] = NULL; ++ if (retval) ++ goto cleanup; + count ++; + + if (count == (chunk_count * CHUNK -1)){ + chunk_count ++; +- if (!(temp_creds = (krb5_creds **) realloc(temp_creds, +- chunk_count * CHUNK * sizeof(krb5_creds *)))){ +- return ENOMEM; +- } ++ ++ temp_creds = xrealloc(temp_creds, ++ chunk_count * CHUNK * ++ sizeof(*temp_creds)); + } + } + +@@ -239,13 +234,15 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, + + temp_creds[count] = NULL; + *creds_array = temp_creds; ++ temp_creds = NULL; + + if (retval == KRB5_CC_END) { + retval = krb5_cc_end_seq_get(context, cc, &cur); + } + ++cleanup: ++ free_creds_list(context, temp_creds); + return retval; +- + } + + krb5_error_code +@@ -315,122 +312,33 @@ printtime(krb5_timestamp ts) + printf("%s", fmtbuf); + } + +- +-krb5_error_code +-krb5_get_login_princ(const char *luser, char ***princ_list) +-{ +- struct stat sbuf; +- struct passwd *pwd; +- char pbuf[MAXPATHLEN]; +- FILE *fp; +- char * linebuf; +- char *newline; +- int gobble, result; +- char ** buf_out; +- struct stat st_temp; +- int count = 0, chunk_count = 1; +- +- /* no account => no access */ +- +- if ((pwd = getpwnam(luser)) == NULL) { +- return 0; +- } +- result = snprintf(pbuf, sizeof(pbuf), "%s/.k5login", pwd->pw_dir); +- if (SNPRINTF_OVERFLOW(result, sizeof(pbuf))) { +- fprintf(stderr, _("home directory path for %s too long\n"), luser); +- exit (1); +- } +- +- if (stat(pbuf, &st_temp)) { /* not accessible */ +- return 0; +- } +- +- +- /* open ~/.k5login */ +- if ((fp = fopen(pbuf, "r")) == NULL) { +- return 0; +- } +- /* +- * For security reasons, the .k5login file must be owned either by +- * the user himself, or by root. Otherwise, don't grant access. +- */ +- if (fstat(fileno(fp), &sbuf)) { +- fclose(fp); +- return 0; +- } +- if ((sbuf.st_uid != pwd->pw_uid) && sbuf.st_uid) { +- fclose(fp); +- return 0; +- } +- +- /* check each line */ +- +- +- if( !(linebuf = (char *) calloc (BUFSIZ, sizeof(char)))) return ENOMEM; +- +- if (!(buf_out = (char **) malloc( CHUNK * sizeof(char *)))) return ENOMEM; +- +- while ( fgets(linebuf, BUFSIZ, fp) != NULL) { +- /* null-terminate the input string */ +- linebuf[BUFSIZ-1] = '\0'; +- newline = NULL; +- /* nuke the newline if it exists */ +- if ((newline = strchr(linebuf, '\n'))) +- *newline = '\0'; +- +- buf_out[count] = linebuf; +- count ++; +- +- if (count == (chunk_count * CHUNK -1)){ +- chunk_count ++; +- if (!(buf_out = (char **) realloc(buf_out, +- chunk_count * CHUNK * sizeof(char *)))){ +- return ENOMEM; +- } +- } +- +- /* clean up the rest of the line if necessary */ +- if (!newline) +- while (((gobble = getc(fp)) != EOF) && gobble != '\n'); +- +- if( !(linebuf = (char *) calloc (BUFSIZ, sizeof(char)))) return ENOMEM; +- } +- +- buf_out[count] = NULL; +- *princ_list = buf_out; +- fclose(fp); +- return 0; +-} +- + void + show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) + { + krb5_error_code retval; +- char *name, *sname, *flags; ++ char *name = NULL, *sname = NULL, *defname = NULL, *flags; + int first = 1; +- krb5_principal princ; +- char * defname; ++ krb5_principal princ = NULL; + int show_flags =1; + + retval = krb5_unparse_name(context, cred->client, &name); + if (retval) { + com_err(prog_name, retval, _("while unparsing client name")); +- return; ++ goto cleanup; + } + retval = krb5_unparse_name(context, cred->server, &sname); + if (retval) { + com_err(prog_name, retval, _("while unparsing server name")); +- free(name); +- return; ++ goto cleanup; + } + + if ((retval = krb5_cc_get_principal(context, cc, &princ))) { + com_err(prog_name, retval, _("while retrieving principal name")); +- return; ++ goto cleanup; + } + if ((retval = krb5_unparse_name(context, princ, &defname))) { + com_err(prog_name, retval, _("while unparsing principal name")); +- return; ++ goto cleanup; + } + + if (!cred->times.starttime) +@@ -468,8 +376,12 @@ show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) + } + } + putchar('\n'); ++ ++cleanup: + free(name); + free(sname); ++ free(defname); ++ krb5_free_principal(context, princ); + } + + /* Create a random string suitable for a filename extension. */ +@@ -501,37 +413,26 @@ krb5_ccache_overwrite(krb5_context context, krb5_ccache ccs, krb5_ccache cct, + krb5_principal primary_principal) + { + krb5_error_code retval=0; +- krb5_principal temp_principal; ++ krb5_principal defprinc = NULL, princ; + krb5_creds ** ccs_creds_arr = NULL; +- int i=0; + + if (ks_ccache_is_initialized(context, ccs)) { +- if ((retval = krb5_get_nonexp_tkts(context, ccs, &ccs_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, ccs, &ccs_creds_arr); ++ if (retval) ++ goto cleanup; + } + +- if (ks_ccache_is_initialized(context, cct)) { +- if ((retval = krb5_cc_get_principal(context, cct, &temp_principal))){ +- return retval; +- } +- }else{ +- temp_principal = primary_principal; +- } +- +- if ((retval = krb5_cc_initialize(context, cct, temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_get_principal(context, cct, &defprinc); ++ princ = (retval == 0) ? defprinc : primary_principal; ++ retval = krb5_cc_initialize(context, cct, princ); ++ if (retval) ++ goto cleanup; + + retval = krb5_store_all_creds(context, cct, ccs_creds_arr, NULL); + +- if (ccs_creds_arr){ +- while (ccs_creds_arr[i]){ +- krb5_free_creds(context, ccs_creds_arr[i]); +- i++; +- } +- } +- ++cleanup: ++ free_creds_list(context, ccs_creds_arr); ++ krb5_free_principal(context, defprinc); + return retval; + } + +@@ -585,45 +486,40 @@ krb5_error_code + krb5_ccache_filter(krb5_context context, krb5_ccache cc, krb5_principal prst) + { + +- int i=0; + krb5_error_code retval=0; +- krb5_principal temp_principal; ++ krb5_principal temp_principal = NULL; + krb5_creds ** cc_creds_arr = NULL; + const char * cc_name; + krb5_boolean stored; + +- cc_name = krb5_cc_get_name(context, cc); ++ if (!ks_ccache_is_initialized(context, cc)) ++ return 0; + +- if (ks_ccache_is_initialized(context, cc)) { +- if (auth_debug) { +- fprintf(stderr,"putting cache %s through a filter for -z option\n", cc_name); +- } ++ if (auth_debug) { ++ cc_name = krb5_cc_get_name(context, cc); ++ fprintf(stderr, "putting cache %s through a filter for -z option\n", ++ cc_name); ++ } + +- if ((retval = krb5_get_nonexp_tkts(context, cc, &cc_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc, &cc_creds_arr); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_cc_get_principal(context, cc, &temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_get_principal(context, cc, &temp_principal); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_cc_initialize(context, cc, temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_initialize(context, cc, temp_principal); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_store_some_creds(context, cc, cc_creds_arr, +- NULL, prst, &stored))){ +- return retval; +- } ++ retval = krb5_store_some_creds(context, cc, cc_creds_arr, NULL, prst, ++ &stored); + +- if (cc_creds_arr){ +- while (cc_creds_arr[i]){ +- krb5_free_creds(context, cc_creds_arr[i]); +- i++; +- } +- } +- } +- return 0; ++cleanup: ++ free_creds_list(context, cc_creds_arr); ++ krb5_free_principal(context, temp_principal); ++ return retval; + } + + krb5_boolean +@@ -654,17 +550,20 @@ krb5_error_code + krb5_find_princ_in_cache(krb5_context context, krb5_ccache cc, + krb5_principal princ, krb5_boolean *found) + { +- krb5_error_code retval; ++ krb5_error_code retval = 0; + krb5_creds ** creds_list = NULL; + + if (ks_ccache_is_initialized(context, cc)) { +- if ((retval = krb5_get_nonexp_tkts(context, cc, &creds_list))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc, &creds_list); ++ if (retval) ++ goto cleanup; + } + + *found = krb5_find_princ_in_cred_list(context, creds_list, princ); +- return 0; ++ ++cleanup: ++ free_creds_list(context, creds_list); ++ return retval; + } + + krb5_boolean +diff --git a/src/clients/ksu/heuristic.c b/src/clients/ksu/heuristic.c +index e906de8ef0..6ed94eb887 100644 +--- a/src/clients/ksu/heuristic.c ++++ b/src/clients/ksu/heuristic.c +@@ -149,28 +149,31 @@ filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) + + *k5users_filt_list = NULL; + +- if (! k5users_list){ ++ if (k5users_list == NULL) + return 0; +- } + + while(k5users_list[i]){ ++ free(out_cmd); ++ out_cmd = NULL; + + retval= k5users_lookup(fp, k5users_list[i], cmd, &found, &out_cmd); + if (retval) +- return retval; ++ goto cleanup; + + if (found == FALSE){ + free (k5users_list[i]); + k5users_list[i] = NULL; +- if (out_cmd) gb_err = out_cmd; ++ if (out_cmd) { ++ gb_err = out_cmd; ++ out_cmd = NULL; ++ } + } else + found_count ++; + + i++; + } + +- if (! (temp_filt_list = (char **) calloc(found_count +1, sizeof (char*)))) +- return ENOMEM; ++ temp_filt_list = xcalloc(found_count + 1, sizeof(*temp_filt_list)); + + for(j= 0, k=0; j < i; j++ ) { + if (k5users_list[j]){ +@@ -184,7 +187,10 @@ filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) + free (k5users_list); + + *k5users_filt_list = temp_filt_list; +- return 0; ++ ++cleanup: ++ free(out_cmd); ++ return retval; + } + + krb5_error_code +@@ -318,7 +324,7 @@ get_closest_principal(krb5_context context, char **plist, + + retval = krb5_parse_name(context, plist[i], &temp_client); + if (retval) +- return retval; ++ goto cleanup; + + pnelem = krb5_princ_size(context, temp_client); + +@@ -346,6 +352,7 @@ get_closest_principal(krb5_context context, char **plist, + if(best_client){ + if(krb5_princ_size(context, best_client) > + krb5_princ_size(context, temp_client)){ ++ krb5_free_principal(context, best_client); + best_client = temp_client; + } + }else +@@ -358,9 +365,12 @@ get_closest_principal(krb5_context context, char **plist, + if (best_client) { + *found = TRUE; + *client = best_client; ++ best_client = NULL; + } + +- return 0; ++cleanup: ++ krb5_free_principal(context, best_client); ++ return retval; + } + + /**************************************************************** +@@ -471,6 +481,7 @@ find_princ_in_list(krb5_context context, krb5_principal princ, char **plist, + i++; + } + ++ free(princname); + return 0; + + } +@@ -498,11 +509,9 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + { + + princ_info princ_trials[10]; +- krb5_principal cc_def_princ = NULL; +- krb5_principal temp_client; +- krb5_principal target_client; +- krb5_principal source_client; +- krb5_principal end_server; ++ krb5_principal cc_def_princ = NULL, temp_client = NULL; ++ krb5_principal target_client = NULL, source_client = NULL; ++ krb5_principal end_server = NULL; + krb5_error_code retval; + char ** aplist =NULL; + krb5_boolean found = FALSE; +@@ -519,54 +528,59 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + if (ks_ccache_is_initialized(context, cc_source)) { + retval = krb5_cc_get_principal(context, cc_source, &cc_def_princ); + if (retval) +- return retval; ++ goto cleanup; + } + + retval=krb5_parse_name(context, target_user, &target_client); + if (retval) +- return retval; ++ goto cleanup; + + retval=krb5_parse_name(context, source_user, &source_client); + if (retval) +- return retval; ++ goto cleanup; + +- if (source_uid == 0){ +- if (target_uid != 0) +- *client = target_client; /* this will be used to restrict +- the cache copty */ +- else { +- if(cc_def_princ) +- *client = cc_def_princ; +- else +- *client = target_client; ++ if (source_uid == 0) { ++ if (target_uid != 0) { ++ /* This will be used to restrict the cache copy. */ ++ *client = target_client; ++ target_client = NULL; ++ } else if (cc_def_princ != NULL) { ++ *client = cc_def_princ; ++ cc_def_princ = NULL; ++ } else { ++ *client = target_client; ++ target_client = NULL; + } +- + if (auth_debug) + printf(" GET_best_princ_for_target: via source_uid == 0\n"); +- +- return 0; ++ goto cleanup; + } + + /* from here on, the code is for source_uid != 0 */ + + if (source_uid && (source_uid == target_uid)){ +- if(cc_def_princ) ++ if (cc_def_princ != NULL) { + *client = cc_def_princ; +- else ++ cc_def_princ = NULL; ++ } else { + *client = target_client; ++ target_client = NULL; ++ } + if (auth_debug) + printf("GET_best_princ_for_target: via source_uid == target_uid\n"); +- return 0; ++ goto cleanup; + } + + /* Become root, then target for looking at .k5login.*/ + if (krb5_seteuid(0) || krb5_seteuid(target_uid) ) { +- return errno; ++ retval = errno; ++ goto cleanup; + } + + /* if .k5users and .k5login do not exist */ + if (stat(k5login_path, &tb) && stat(k5users_path, &tb) ){ + *client = target_client; ++ target_client = NULL; + + if (cmd) + *path_out = NOT_AUTHORIZED; +@@ -574,26 +588,25 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + if (auth_debug) + printf(" GET_best_princ_for_target: via no auth files path\n"); + +- return 0; ++ goto cleanup; + }else{ + retval = get_authorized_princ_names(target_user, cmd, &aplist); + if (retval) +- return retval; ++ goto cleanup; + + /* .k5users or .k5login exist, but no authorization */ + if ((!aplist) || (!aplist[0])) { + *path_out = NOT_AUTHORIZED; + if (auth_debug) + printf("GET_best_princ_for_target: via empty auth files path\n"); +- return 0; ++ goto cleanup; + } + } + + retval = krb5_sname_to_principal(context, hostname, NULL, + KRB5_NT_SRV_HST, &end_server); + if (retval) +- return retval; +- ++ goto cleanup; + + /* first see if default principal of the source cache + * can get us in, then the target_user@realm, then the +@@ -616,7 +629,7 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + retval= find_princ_in_list(context, princ_trials[i].p, aplist, + &found); + if (retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + princ_trials[i].found = TRUE; +@@ -625,12 +638,13 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + princ_trials[i].p, + end_server, &found); + if (retval) +- return retval; ++ goto cleanup; + if (found == TRUE){ +- *client = princ_trials[i].p; ++ retval = krb5_copy_principal(context, princ_trials[i].p, ++ client); + if (auth_debug) + printf("GET_best_princ_for_target: via ticket file, choice #%d\n", i); +- return 0; ++ goto cleanup; + } + } + } +@@ -643,21 +657,23 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + while (aplist[i]){ + retval = krb5_parse_name(context, aplist[i], &temp_client); + if (retval) +- return retval; ++ goto cleanup; + + retval = find_either_ticket (context, cc_source, temp_client, + end_server, &found); + if (retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + if (auth_debug) + printf("GET_best_princ_for_target: via ticket file, choice: any ok ticket \n" ); + *client = temp_client; +- return 0; ++ temp_client = NULL; ++ goto cleanup; + } + + krb5_free_principal(context, temp_client); ++ temp_client = NULL; + + i++; + } +@@ -668,11 +684,11 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + + for (i=0; i < count; i ++){ + if (princ_trials[i].found == TRUE){ +- *client = princ_trials[i].p; ++ retval = krb5_copy_principal(context, princ_trials[i].p, client); + + if (auth_debug) + printf("GET_best_princ_for_target: via prompt passwd list choice #%d \n",i); +- return 0; ++ goto cleanup; + } + } + +@@ -682,7 +698,7 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + retval=krb5_copy_principal(context, princ_trials[i].p, + &temp_client); + if(retval) +- return retval; ++ goto cleanup; + + /* get the client name that is the closest + to the three princ in trials */ +@@ -690,15 +706,15 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + retval=get_closest_principal(context, aplist, &temp_client, + &found); + if(retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + *client = temp_client; ++ temp_client = NULL; + if (auth_debug) + printf("GET_best_princ_for_target: via prompt passwd list choice: approximation of princ in trials # %d \n",i); +- return 0; ++ goto cleanup; + } +- krb5_free_principal(context, temp_client); + } + } + +@@ -709,5 +725,13 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, + printf( "GET_best_princ_for_target: out of luck, can't get appropriate default principal\n"); + + *path_out = NOT_AUTHORIZED; +- return 0; ++ retval = 0; ++ ++cleanup: ++ krb5_free_principal(context, cc_def_princ); ++ krb5_free_principal(context, target_client); ++ krb5_free_principal(context, source_client); ++ krb5_free_principal(context, temp_client); ++ krb5_free_principal(context, end_server); ++ return retval; + } +diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c +index db10251f95..68cfe6b0ed 100644 +--- a/src/clients/ksu/krb_auth_su.c ++++ b/src/clients/ksu/krb_auth_su.c +@@ -37,33 +37,31 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + char *target_user, krb5_ccache cc, int *path_passwd, + uid_t target_uid) + { +- krb5_principal client; ++ krb5_principal client = NULL; + krb5_verify_init_creds_opt vfy_opts; +- krb5_creds tgt, tgtq; ++ krb5_creds tgt = { 0 }, tgtq = { 0 }; + krb5_error_code retval =0; + int got_it = 0; + krb5_boolean zero_password; ++ krb5_boolean ok = FALSE; + + *path_passwd = 0; +- memset(&tgtq, 0, sizeof(tgtq)); +- memset(&tgt, 0, sizeof(tgt)); + + if ((retval= krb5_copy_principal(context, client_pname, &client))){ + com_err(prog_name, retval, _("while copying client principal")); +- return (FALSE) ; ++ goto cleanup; + } + + if ((retval= krb5_copy_principal(context, client, &tgtq.client))){ + com_err(prog_name, retval, _("while copying client principal")); +- return (FALSE) ; ++ goto cleanup; + } + + if ((retval = ksu_tgtname(context, krb5_princ_realm(context, client), + krb5_princ_realm(context, client), + &tgtq.server))){ + com_err(prog_name, retval, _("while creating tgt for local realm")); +- krb5_free_principal(context, client); +- return (FALSE) ; ++ goto cleanup; + } + + if (auth_debug){ dump_principal(context, "local tgt principal name", tgtq.server ); } +@@ -77,7 +75,7 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + if ((retval != KRB5_CC_NOTFOUND) && + (retval != KRB5KRB_AP_ERR_TKT_EXPIRED)){ + com_err(prog_name, retval, _("while retrieving creds from cache")); +- return (FALSE) ; ++ goto cleanup; + } + } else{ + got_it = 1; +@@ -88,7 +86,7 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + #ifdef GET_TGT_VIA_PASSWD + if (krb5_seteuid(0)||krb5_seteuid(target_uid)) { + com_err("ksu", errno, _("while switching to target uid")); +- return FALSE; ++ goto cleanup; + } + + +@@ -102,19 +100,19 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + &tgt) == FALSE) { + krb5_seteuid(0); + +- return FALSE; ++ goto cleanup; + } + *path_passwd = 1; + if (krb5_seteuid(0)) { + com_err("ksu", errno, _("while reclaiming root uid")); +- return FALSE; ++ goto cleanup; + } + + #else + plain_dump_principal (context, client); + fprintf(stderr, + _("does not have any appropriate tickets in the cache.\n")); +- return FALSE; ++ goto cleanup; + + #endif /* GET_TGT_VIA_PASSWD */ + +@@ -126,10 +124,16 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + &vfy_opts); + if (retval) { + com_err(prog_name, retval, _("while verifying ticket for server")); +- return (FALSE); ++ goto cleanup; + } + +- return (TRUE); ++ ok = TRUE; ++ ++cleanup: ++ krb5_free_principal(context, client); ++ krb5_free_cred_contents(context, &tgt); ++ krb5_free_cred_contents(context, &tgtq); ++ return ok; + } + + krb5_boolean +@@ -137,11 +141,12 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + krb5_get_init_creds_opt *options, + krb5_boolean *zero_password, krb5_creds *creds_out) + { ++ krb5_boolean ok = FALSE; + krb5_error_code code; +- krb5_creds creds; ++ krb5_creds creds = { 0 }; + krb5_timestamp now; + unsigned int pwsize; +- char password[255], *client_name, prompt[255]; ++ char password[255], prompt[255], *client_name = NULL; + int result; + + *zero_password = FALSE; +@@ -150,14 +155,14 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + + if ((code = krb5_unparse_name(context, client, &client_name))) { + com_err (prog_name, code, _("when unparsing name")); +- return (FALSE); ++ goto cleanup; + } + + memset(&creds, 0, sizeof(creds)); + + if ((code = krb5_timeofday(context, &now))) { + com_err(prog_name, code, _("while getting time of day")); +- return (FALSE); ++ goto cleanup; + } + + result = snprintf(prompt, sizeof(prompt), _("Kerberos password for %s: "), +@@ -166,7 +171,7 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + fprintf(stderr, + _("principal name %s too long for internal buffer space\n"), + client_name); +- return FALSE; ++ goto cleanup; + } + + pwsize = sizeof(password); +@@ -175,13 +180,13 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + if (code ) { + com_err(prog_name, code, _("while reading password for '%s'\n"), + client_name); +- return (FALSE); ++ goto cleanup; + } + + if ( pwsize == 0) { + fprintf(stderr, _("No password given\n")); + *zero_password = TRUE; +- return (FALSE); ++ goto cleanup; + } + + code = krb5_get_init_creds_password(context, &creds, client, password, +@@ -195,13 +200,19 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + fprintf(stderr, _("%s: Password incorrect\n"), prog_name); + else + com_err(prog_name, code, _("while getting initial credentials")); +- return (FALSE); ++ goto cleanup; + } +- if (creds_out != NULL) ++ if (creds_out != NULL) { + *creds_out = creds; +- else +- krb5_free_cred_contents(context, &creds); +- return (TRUE); ++ memset(&creds, 0, sizeof(creds)); ++ } ++ ++ ok = TRUE; ++ ++cleanup: ++ krb5_free_cred_contents(context, &creds); ++ free(client_name); ++ return ok; + } + + void +@@ -213,8 +224,10 @@ dump_principal(krb5_context context, char *str, krb5_principal p) + if ((retval = krb5_unparse_name(context, p, &stname))) { + fprintf(stderr, _(" %s while unparsing name\n"), + error_message(retval)); ++ return; + } + fprintf(stderr, " %s: %s\n", str, stname); ++ free(stname); + } + + void +@@ -226,71 +239,8 @@ plain_dump_principal (krb5_context context, krb5_principal p) + if ((retval = krb5_unparse_name(context, p, &stname))) { + fprintf(stderr, _(" %s while unparsing name\n"), + error_message(retval)); ++ return; + } + fprintf(stderr, "%s ", stname); +-} +- +- +-/********************************************************************** +-returns the principal that is closest to client. plist contains +-a principal list obtained from .k5login and parhaps .k5users file. +-This routine gets called before getting the password for a tgt. +-A principal is picked that has the best chance of getting in. +- +-**********************************************************************/ +- +-krb5_error_code +-get_best_principal(krb5_context context, char **plist, krb5_principal *client) +-{ +- krb5_error_code retval =0; +- krb5_principal temp_client, best_client = NULL; +- +- int i = 0, nelem; +- +- if (! plist ) return 0; +- +- nelem = krb5_princ_size(context, *client); +- +- while(plist[i]){ +- +- if ((retval = krb5_parse_name(context, plist[i], &temp_client))){ +- return retval; +- } +- +- if (data_eq(*krb5_princ_realm(context, *client), +- *krb5_princ_realm(context, temp_client))) { +- +- if (nelem && +- krb5_princ_size(context, *client) > 0 && +- krb5_princ_size(context, temp_client) > 0) { +- krb5_data *p1 = +- krb5_princ_component(context, *client, 0); +- krb5_data *p2 = +- krb5_princ_component(context, temp_client, 0); +- +- if (data_eq(*p1, *p2)) { +- +- if (auth_debug){ +- fprintf(stderr, +- "get_best_principal: compare with %s\n", +- plist[i]); +- } +- +- if(best_client){ +- if(krb5_princ_size(context, best_client) > +- krb5_princ_size(context, temp_client)){ +- best_client = temp_client; +- } +- }else{ +- best_client = temp_client; +- } +- } +- } +- +- } +- i++; +- } +- +- if (best_client) *client = best_client; +- return 0; ++ free(stname); + } +diff --git a/src/clients/ksu/ksu.h b/src/clients/ksu/ksu.h +index 66fb4bcc6a..32ce11cb85 100644 +--- a/src/clients/ksu/ksu.h ++++ b/src/clients/ksu/ksu.h +@@ -92,9 +92,6 @@ extern void plain_dump_principal + extern krb5_error_code krb5_parse_lifetime + (char *, long *); + +-extern krb5_error_code get_best_principal +-(krb5_context, char **, krb5_principal *); +- + /* ccache.c */ + extern krb5_error_code krb5_ccache_copy + (krb5_context, krb5_ccache, krb5_principal, krb5_ccache, +@@ -117,9 +114,6 @@ extern krb5_error_code krb5_check_exp + + extern char *flags_string (krb5_creds *); + +-extern krb5_error_code krb5_get_login_princ +-(const char *, char ***); +- + extern void show_credential + (krb5_context, krb5_creds *, krb5_ccache); + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 2a351662c8..77703a6a2b 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -1002,7 +1002,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, + if (retval) { + com_err(prog_name, retval, + _("while generating part of the target ccache name")); +- return retval; ++ goto cleanup; + } + if (asprintf(&ccname, "%s.%s", target, sym) < 0) { + retval = ENOMEM; +@@ -1014,6 +1014,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, + free(sym); + } while (ks_ccache_name_is_initialized(context, ccname)); + retval = krb5_cc_resolve(context, ccname, &ccache); ++ free(ccname); + } else { + /* Look for a cache in the collection that we can reuse. */ + retval = krb5_cc_cache_match(context, princ, &ccache); +diff --git a/src/kadmin/cli/keytab.c b/src/kadmin/cli/keytab.c +index 26f340af31..976c8969e8 100644 +--- a/src/kadmin/cli/keytab.c ++++ b/src/kadmin/cli/keytab.c +@@ -363,7 +363,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + { + krb5_principal princ = NULL; + krb5_keytab_entry entry; +- krb5_kt_cursor cursor; ++ krb5_kt_cursor cursor = NULL; + enum { UNDEF, SPEC, HIGH, ALL, OLD } mode; + int code, did_something; + krb5_kvno kvno; +@@ -443,6 +443,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + _("while temporarily ending keytab scan")); + goto cleanup; + } ++ cursor = NULL; + code = krb5_kt_remove_entry(context, keytab, &entry); + if (code != 0) { + com_err(whoami, code, _("while deleting entry from keytab")); +@@ -471,6 +472,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + com_err(whoami, code, _("while ending keytab scan")); + goto cleanup; + } ++ cursor = NULL; + + /* + * If !did_someting then mode must be OLD or we would have +@@ -483,6 +485,8 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + } + + cleanup: ++ if (cursor != NULL) ++ (void)krb5_kt_end_seq_get(context, keytab, &cursor); + krb5_free_principal(context, princ); + } + +diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c +index 87a69ca145..a1c17d154d 100644 +--- a/src/kadmin/ktutil/ktutil.c ++++ b/src/kadmin/ktutil/ktutil.c +@@ -254,6 +254,7 @@ ktutil_list(int argc, char *argv[]) + buf, sizeof(buf)))) { + com_err(argv[0], retval, + _("While converting enctype to string")); ++ free(pname); + return; + } + printf(" (%s) ", buf); +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index f883ae2df8..9a4826e441 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -1300,19 +1300,20 @@ static krb5_boolean + authorized_principal(krb5_context context, krb5_principal p, + krb5_enctype auth_etype) + { +- char *name, *ptr, buf[1024]; ++ krb5_boolean ok = FALSE; ++ char *name = NULL, *ptr, buf[1024]; + krb5_error_code retval; +- FILE *acl_file; ++ FILE *acl_file = NULL; + int end; + krb5_enctype acl_etype; + + retval = krb5_unparse_name(context, p, &name); + if (retval) +- return FALSE; ++ goto cleanup; + + acl_file = fopen(acl_file_name, "r"); + if (acl_file == NULL) +- return FALSE; ++ goto cleanup; + + while (!feof(acl_file)) { + if (!fgets(buf, sizeof(buf), acl_file)) +@@ -1342,14 +1343,16 @@ authorized_principal(krb5_context context, krb5_principal p, + (acl_etype != auth_etype))) + continue; + +- free(name); +- fclose(acl_file); +- return TRUE; ++ ok = TRUE; ++ goto cleanup; + } + } ++ ++cleanup: + free(name); +- fclose(acl_file); +- return FALSE; ++ if (acl_file != NULL) ++ fclose(acl_file); ++ return ok; + } + + static void +diff --git a/src/lib/gssapi/krb5/export_cred.c b/src/lib/gssapi/krb5/export_cred.c +index 96a408c237..bf5cede54a 100644 +--- a/src/lib/gssapi/krb5/export_cred.c ++++ b/src/lib/gssapi/krb5/export_cred.c +@@ -447,8 +447,10 @@ krb5_gss_export_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + + /* Validate and lock cred_handle. */ + status = krb5_gss_validate_cred_1(minor_status, cred_handle, context); +- if (status != GSS_S_COMPLETE) ++ if (status != GSS_S_COMPLETE) { ++ krb5_free_context(context); + return status; ++ } + cred = (krb5_gss_cred_id_t)cred_handle; + + if (json_kgcred(context, cred, &jcred)) +diff --git a/src/lib/gssapi/krb5/val_cred.c b/src/lib/gssapi/krb5/val_cred.c +index 83e7634106..d4b070f8c0 100644 +--- a/src/lib/gssapi/krb5/val_cred.c ++++ b/src/lib/gssapi/krb5/val_cred.c +@@ -35,6 +35,7 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + krb5_gss_cred_id_t cred; + krb5_error_code code; + krb5_principal princ; ++ krb5_boolean same; + + cred = (krb5_gss_cred_id_t) cred_handle; + k5_mutex_lock(&cred->lock); +@@ -45,12 +46,13 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + *minor_status = code; + return(GSS_S_DEFECTIVE_CREDENTIAL); + } +- if (!krb5_principal_compare(context, princ, cred->name->princ)) { ++ same = krb5_principal_compare(context, princ, cred->name->princ); ++ (void)krb5_free_principal(context, princ); ++ if (!same) { + k5_mutex_unlock(&cred->lock); + *minor_status = KG_CCACHE_NOMATCH; + return(GSS_S_DEFECTIVE_CREDENTIAL); + } +- (void)krb5_free_principal(context, princ); + } + *minor_status = 0; + return GSS_S_COMPLETE; +diff --git a/src/lib/kadm5/srv/server_kdb.c b/src/lib/kadm5/srv/server_kdb.c +index 2ec80a0f2b..4efcaf9941 100644 +--- a/src/lib/kadm5/srv/server_kdb.c ++++ b/src/lib/kadm5/srv/server_kdb.c +@@ -67,11 +67,10 @@ krb5_error_code kdb_init_master(kadm5_server_handle_t handle, + if (ret) + goto done; + +- if ((ret = krb5_db_fetch_mkey_list(handle->context, master_princ, +- &master_keyblock))) { ++ ret = krb5_db_fetch_mkey_list(handle->context, master_princ, ++ &master_keyblock); ++ if (ret) + krb5_db_fini(handle->context); +- return (ret); +- } + + done: + if (r == NULL) +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index c93e7c78e5..1f917d49bb 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -992,10 +992,14 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, + if (cursor == NULL) + goto cleanup; + cursor->uuids = uuids; ++ uuids = NULL; + cursor->creds = creds; ++ creds = NULL; + *cursor_out = (krb5_cc_cursor)cursor; + + cleanup: ++ free_cred_list(creds); ++ free_uuid_list(uuids); + kcmreq_free(&req); + return ret; + } +diff --git a/src/lib/krb5/ccache/ccfns.c b/src/lib/krb5/ccache/ccfns.c +index e0eb39a612..9b755f0e36 100644 +--- a/src/lib/krb5/ccache/ccfns.c ++++ b/src/lib/krb5/ccache/ccfns.c +@@ -198,18 +198,18 @@ k5_build_conf_principals(krb5_context context, krb5_ccache id, + if (principal) { + ret = krb5_unparse_name(context, principal, &pname); + if (ret) +- return ret; ++ goto cleanup; + } + + ret = krb5_build_principal(context, &cred->server, + sizeof(conf_realm) - 1, conf_realm, + conf_name, name, pname, (char *)NULL); +- krb5_free_unparsed_name(context, pname); +- if (ret) { +- krb5_free_principal(context, client); +- return ret; +- } ++ if (ret) ++ goto cleanup; + ret = krb5_copy_principal(context, client, &cred->client); ++ ++cleanup: ++ krb5_free_unparsed_name(context, pname); + krb5_free_principal(context, client); + return ret; + } +diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c +index f3ea28c8ec..8fd1505115 100644 +--- a/src/lib/krb5/keytab/kt_file.c ++++ b/src/lib/krb5/keytab/kt_file.c +@@ -456,15 +456,16 @@ krb5_ktfile_start_seq_get(krb5_context context, krb5_keytab id, krb5_kt_cursor * + return ENOMEM; + } + *fileoff = KTSTARTOFF(id); +- *cursorp = (krb5_kt_cursor)fileoff; + KTITERS(id)++; + if (KTITERS(id) == 0) { + /* Wrapped?! */ + KTITERS(id)--; + KTUNLOCK(id); ++ free(fileoff); + k5_setmsg(context, KRB5_KT_IOERR, "Too many keytab iterators active"); + return KRB5_KT_IOERR; /* XXX */ + } ++ *cursorp = (krb5_kt_cursor)fileoff; + KTUNLOCK(id); + + return 0; +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +index 753929b06d..f7fad27867 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +@@ -271,16 +271,18 @@ krb5_ldap_delete_realm (krb5_context context, char *lrealm) + for (ent = ldap_first_entry (ld, result); ent != NULL; + ent = ldap_next_entry (ld, ent)) { + if ((values = ldap_get_values(ld, ent, "krbPrincipalName")) != NULL) { +- for (i = 0; values[i] != NULL; ++i) { ++ for (i = 0; values[i] != NULL && !st; ++i) { + krb5_parse_name(context, values[i], &principal); + if (principal_in_realm_2(principal, lrealm) == 0) { + st=krb5_ldap_delete_principal(context, principal); +- if (st && st != KRB5_KDB_NOENTRY) +- goto cleanup; ++ if (st == KRB5_KDB_NOENTRY) ++ st = 0; + } + krb5_free_principal(context, principal); + } + ldap_value_free(values); ++ if (st) ++ goto cleanup; + } + } + } +-- +2.45.1 + diff --git a/0019-Remove-klist-s-defname-global-variable.patch b/0019-Remove-klist-s-defname-global-variable.patch new file mode 100644 index 0000000..1cf7d80 --- /dev/null +++ b/0019-Remove-klist-s-defname-global-variable.patch @@ -0,0 +1,71 @@ +From 05bb6d9c729a3c6a4ba35270368bc0f6e1875ad0 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Mon, 8 Jan 2024 16:52:27 +0100 +Subject: [PATCH] Remove klist's defname global variable + +Addition of a "cleanup" section in kinit's show_ccache() function as +part of commit 6c5471176f5266564fbc8a7e02f03b4b042202f8 introduced a +double-free bug, because defname is a global variable. After the +first call, successive calls may take place with a dangling pointer in +defname, which will be freed if krb5_cc_get_principal() fails. + +Convert "defname" to a local variable initialized at the beginning of +show_ccache(). + +[ghudson@mit.edu: edited commit message] + +(cherry picked from commit 5b00197227231943bd2305328c8260dd0b0dbcf0) +--- + src/clients/klist/klist.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index b5ae96a843..b5808e5c93 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -53,7 +53,6 @@ int show_flags = 0, show_time = 0, status_only = 0, show_keys = 0; + int show_etype = 0, show_addresses = 0, no_resolve = 0, print_version = 0; + int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0; + int show_config = 0; +-char *defname; + char *progname; + krb5_timestamp now; + unsigned int timestamp_width; +@@ -62,7 +61,7 @@ krb5_context context; + + static krb5_boolean is_local_tgt(krb5_principal princ, krb5_data *realm); + static char *etype_string(krb5_enctype ); +-static void show_credential(krb5_creds *); ++static void show_credential(krb5_creds *, const char *); + + static void list_all_ccaches(void); + static int list_ccache(krb5_ccache); +@@ -473,6 +472,7 @@ show_ccache(krb5_ccache cache) + krb5_creds creds; + krb5_principal princ = NULL; + krb5_error_code ret; ++ char *defname = NULL; + int status = 1; + + ret = krb5_cc_get_principal(context, cache, &princ); +@@ -503,7 +503,7 @@ show_ccache(krb5_ccache cache) + } + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (show_config || !krb5_is_config_principal(context, creds.server)) +- show_credential(&creds); ++ show_credential(&creds, defname); + krb5_free_cred_contents(context, &creds); + } + if (ret == KRB5_CC_END) { +@@ -676,7 +676,7 @@ print_config_data(int col, krb5_data *data) + } + + static void +-show_credential(krb5_creds *cred) ++show_credential(krb5_creds *cred, const char *defname) + { + krb5_error_code ret; + krb5_ticket *tkt = NULL; +-- +2.45.1 + diff --git a/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch b/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch new file mode 100644 index 0000000..1674fd6 --- /dev/null +++ b/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch @@ -0,0 +1,34 @@ +From d7bcca2a215de880f4419afc450a96a747d48560 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 27 Oct 2023 00:44:53 -0400 +Subject: [PATCH] End connection on KDC_ERR_SVC_UNAVAILABLE + +In sendto_kdc.c:service_fds(), if a message handler indicates that a +message should be discarded, kill the connection so we don't continue +waiting on it for more data. + +ticket: 7899 +(cherry picked from commit ca80f64c786341d5871ae1de18142e62af64f7b9) +--- + src/lib/krb5/os/sendto_kdc.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 0f4bf23a95..262edf09b4 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -1440,7 +1440,10 @@ service_fds(krb5_context context, struct select_state *selstate, + if (msg_handler != NULL) { + krb5_data reply = make_data(state->in.buf, state->in.pos); + +- stop = (msg_handler(context, &reply, msg_handler_data) != 0); ++ if (!msg_handler(context, &reply, msg_handler_data)) { ++ kill_conn(context, state, selstate); ++ stop = 0; ++ } + } + + if (stop) { +-- +2.46.0 + diff --git a/0021-Add-request_timeout-configuration-parameter.patch b/0021-Add-request_timeout-configuration-parameter.patch new file mode 100644 index 0000000..5b84513 --- /dev/null +++ b/0021-Add-request_timeout-configuration-parameter.patch @@ -0,0 +1,226 @@ +From a07b3ae29fd972c40e30b95f6bcc8fb3ed4d9991 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 26 Oct 2023 14:20:34 -0400 +Subject: [PATCH] Add request_timeout configuration parameter + +Add a parameter to limit the total amount of time taken for a KDC or +password change request. + +ticket: 9106 (new) +(cherry picked from commit 802318cda963456b3ed7856c836e89da891483be) +--- + doc/admin/conf_files/krb5_conf.rst | 9 ++++++ + src/include/k5-int.h | 2 ++ + src/lib/krb5/krb/init_ctx.c | 14 +++++++- + src/lib/krb5/os/sendto_kdc.c | 51 ++++++++++++++++++++---------- + 4 files changed, 58 insertions(+), 18 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index a33711d918..65fb592d98 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -356,6 +356,15 @@ The libdefaults section may contain any of the following relations: + (:ref:`duration` string.) Sets the default renewable lifetime + for initial ticket requests. The default value is 0. + ++**request_timeout** ++ (:ref:`duration` string.) Sets the maximum total time for KDC or ++ password change requests. This timeout does not affect the ++ intervals between requests, so setting a low timeout may result in ++ fewer requests being attempted and/or some servers not being ++ contacted. A value of 0 indicates no specific maximum, in which ++ case requests will time out if no server responds after several ++ tries. The default value is 0. (New in release 1.22.) ++ + **spake_preauth_groups** + A whitespace or comma-separated list of words which specifies the + groups allowed for SPAKE preauthentication. The possible values +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index b3e07945c1..69d6a6f569 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -296,6 +296,7 @@ typedef unsigned char u_char; + #define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" + #define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" + #define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups" ++#define KRB5_CONF_REQUEST_TIMEOUT "request_timeout" + #define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime" + #define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit" + #define KRB5_CONF_UNLOCKITER "unlockiter" +@@ -1200,6 +1201,7 @@ struct _krb5_context { + kdb5_dal_handle *dal_handle; + /* allowable clock skew */ + krb5_deltat clockskew; ++ krb5_deltat req_timeout; + krb5_flags kdc_default_options; + krb5_flags library_options; + krb5_boolean profile_secure; +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 2b5abcd817..582a2945ff 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -157,7 +157,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + krb5_context ctx = 0; + krb5_error_code retval; + int tmp; +- char *plugin_dir = NULL; ++ char *plugin_dir = NULL, *timeout_str = NULL; + + /* Verify some assumptions. If the assumptions hold and the + compiler is optimizing, this should result in no code being +@@ -240,6 +240,17 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); + ctx->clockskew = tmp; + ++ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS, ++ KRB5_CONF_REQUEST_TIMEOUT, NULL, NULL, ++ &timeout_str); ++ if (retval) ++ goto cleanup; ++ if (timeout_str != NULL) { ++ retval = krb5_string_to_deltat(timeout_str, &ctx->req_timeout); ++ if (retval) ++ goto cleanup; ++ } ++ + get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK, + &tmp); + ctx->kdc_default_options = tmp; +@@ -281,6 +292,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + + cleanup: + profile_release_string(plugin_dir); ++ profile_release_string(timeout_str); + krb5_free_context(ctx); + return retval; + } +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 262edf09b4..98247a1089 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -1395,34 +1395,41 @@ get_endtime(time_ms endtime, struct conn_state *conns) + + static krb5_boolean + service_fds(krb5_context context, struct select_state *selstate, +- time_ms interval, struct conn_state *conns, ++ time_ms interval, time_ms timeout, struct conn_state *conns, + struct select_state *seltemp, const krb5_data *realm, + int (*msg_handler)(krb5_context, const krb5_data *, void *), + void *msg_handler_data, struct conn_state **winner_out) + { + int e, selret = 0; +- time_ms endtime; ++ time_ms curtime, interval_end, endtime; + struct conn_state *state; + + *winner_out = NULL; + +- e = get_curtime_ms(&endtime); ++ e = get_curtime_ms(&curtime); + if (e) + return TRUE; +- endtime += interval; ++ interval_end = curtime + interval; + + e = 0; + while (selstate->nfds > 0) { +- e = cm_select_or_poll(selstate, get_endtime(endtime, conns), +- seltemp, &selret); ++ endtime = get_endtime(interval_end, conns); ++ /* Don't wait longer than the whole request should last. */ ++ if (timeout && endtime > timeout) ++ endtime = timeout; ++ e = cm_select_or_poll(selstate, endtime, seltemp, &selret); + if (e == EINTR) + continue; + if (e != 0) + break; + +- if (selret == 0) +- /* Timeout, return to caller. */ ++ if (selret == 0) { ++ /* We timed out. Stop if we hit the overall request timeout. */ ++ if (timeout && (get_curtime_ms(&curtime) || curtime >= timeout)) ++ return TRUE; ++ /* Otherwise return to the caller to send the next request. */ + return FALSE; ++ } + + /* Got something on a socket, process it. */ + for (state = conns; state != NULL; state = state->next) { +@@ -1495,7 +1502,7 @@ k5_sendto(krb5_context context, const krb5_data *message, + void *msg_handler_data) + { + int pass; +- time_ms delay; ++ time_ms delay, timeout = 0; + krb5_error_code retval; + struct conn_state *conns = NULL, *state, **tailptr, *next, *winner; + size_t s; +@@ -1505,6 +1512,13 @@ k5_sendto(krb5_context context, const krb5_data *message, + + *reply = empty_data(); + ++ if (context->req_timeout) { ++ retval = get_curtime_ms(&timeout); ++ if (retval) ++ return retval; ++ timeout += 1000 * context->req_timeout; ++ } ++ + /* One for use here, listing all our fds in use, and one for + * temporary use in service_fds, for the fds of interest. */ + sel_state = malloc(2 * sizeof(*sel_state)); +@@ -1532,8 +1546,9 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, 1000, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + } + } + +@@ -1545,13 +1560,13 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, ++ done = service_fds(context, sel_state, 1000, timeout, conns, seltemp, + realm, msg_handler, msg_handler_data, &winner); + } + + /* Wait for two seconds at the end of the first pass. */ + if (!done) { +- done = service_fds(context, sel_state, 2000, conns, seltemp, ++ done = service_fds(context, sel_state, 2000, timeout, conns, seltemp, + realm, msg_handler, msg_handler_data, &winner); + } + +@@ -1562,15 +1577,17 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, 1000, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + if (sel_state->nfds == 0) + break; + } + /* Wait for the delay backoff at the end of this pass. */ + if (!done) { +- done = service_fds(context, sel_state, delay, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, delay, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + } + if (sel_state->nfds == 0) + break; +-- +2.46.0 + diff --git a/0022-Wait-indefinitely-on-KDC-TCP-connections.patch b/0022-Wait-indefinitely-on-KDC-TCP-connections.patch new file mode 100644 index 0000000..26b884b --- /dev/null +++ b/0022-Wait-indefinitely-on-KDC-TCP-connections.patch @@ -0,0 +1,138 @@ +From 1da153d97d7fb30a44fca35f9b71b8f4ed5385b9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 26 Oct 2023 16:26:42 -0400 +Subject: [PATCH] Wait indefinitely on KDC TCP connections + +When making a KDC or password change request, wait indefinitely +(limited only by request_timeout if set) once a KDC has accepted a TCP +connection. + +ticket: 9105 (new) +(cherry picked from commit 6436a3808061da787a43c6810f5f0370cdfb6e36) +--- + doc/admin/conf_files/krb5_conf.rst | 2 +- + src/lib/krb5/os/sendto_kdc.c | 50 ++++++++++++++++-------------- + 2 files changed, 27 insertions(+), 25 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 65fb592d98..b7284c47df 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -357,7 +357,7 @@ The libdefaults section may contain any of the following relations: + for initial ticket requests. The default value is 0. + + **request_timeout** +- (:ref:`duration` string.) Sets the maximum total time for KDC or ++ (:ref:`duration` string.) Sets the maximum total time for KDC and + password change requests. This timeout does not affect the + intervals between requests, so setting a low timeout may result in + fewer requests being attempted and/or some servers not being +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 98247a1089..924f5b2d26 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -134,7 +134,6 @@ struct conn_state { + krb5_data callback_buffer; + size_t server_index; + struct conn_state *next; +- time_ms endtime; + krb5_boolean defer; + struct { + const char *uri_path; +@@ -344,15 +343,19 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime, + struct select_state *out, int *sret) + { + #ifndef USE_POLL +- struct timeval tv; ++ struct timeval tv, *tvp; + #endif + krb5_error_code retval; + time_ms curtime, interval; + +- retval = get_curtime_ms(&curtime); +- if (retval != 0) +- return retval; +- interval = (curtime < endtime) ? endtime - curtime : 0; ++ if (endtime != 0) { ++ retval = get_curtime_ms(&curtime); ++ if (retval != 0) ++ return retval; ++ interval = (curtime < endtime) ? endtime - curtime : 0; ++ } else { ++ interval = -1; ++ } + + /* We don't need a separate copy of the selstate for poll, but use one for + * consistency with how we use select. */ +@@ -361,9 +364,14 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime, + #ifdef USE_POLL + *sret = poll(out->fds, out->nfds, interval); + #else +- tv.tv_sec = interval / 1000; +- tv.tv_usec = interval % 1000 * 1000; +- *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, &tv); ++ if (interval != -1) { ++ tv.tv_sec = interval / 1000; ++ tv.tv_usec = interval % 1000 * 1000; ++ tvp = &tv; ++ } else { ++ tvp = NULL; ++ } ++ *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, tvp); + #endif + + return (*sret < 0) ? SOCKET_ERRNO : 0; +@@ -1099,11 +1107,6 @@ service_tcp_connect(krb5_context context, const krb5_data *realm, + } + + conn->state = WRITING; +- +- /* Record this connection's timeout for service_fds. */ +- if (get_curtime_ms(&conn->endtime) == 0) +- conn->endtime += 10000; +- + return conn->service_write(context, realm, conn, selstate); + } + +@@ -1378,19 +1381,18 @@ kill_conn: + return FALSE; + } + +-/* Return the maximum of endtime and the endtime fields of all currently active +- * TCP connections. */ +-static time_ms +-get_endtime(time_ms endtime, struct conn_state *conns) ++/* Return true if conns contains any states with connected TCP sockets. */ ++static krb5_boolean ++any_tcp_connections(struct conn_state *conns) + { + struct conn_state *state; + + for (state = conns; state != NULL; state = state->next) { +- if ((state->state == READING || state->state == WRITING) && +- state->endtime > endtime) +- endtime = state->endtime; ++ if (state->addr.transport != UDP && ++ (state->state == READING || state->state == WRITING)) ++ return TRUE; + } +- return endtime; ++ return FALSE; + } + + static krb5_boolean +@@ -1413,9 +1415,9 @@ service_fds(krb5_context context, struct select_state *selstate, + + e = 0; + while (selstate->nfds > 0) { +- endtime = get_endtime(interval_end, conns); ++ endtime = any_tcp_connections(conns) ? 0 : interval_end; + /* Don't wait longer than the whole request should last. */ +- if (timeout && endtime > timeout) ++ if (timeout && (!endtime || endtime > timeout)) + endtime = timeout; + e = cm_select_or_poll(selstate, endtime, seltemp, &selret); + if (e == EINTR) +-- +2.46.0 + diff --git a/0023-Remove-PKINIT-RSA-support.patch b/0023-Remove-PKINIT-RSA-support.patch new file mode 100644 index 0000000..7672f02 --- /dev/null +++ b/0023-Remove-PKINIT-RSA-support.patch @@ -0,0 +1,1297 @@ +From 4f008362334dc2d66d67453448061e19feda889d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 26 Nov 2023 17:42:34 -0500 +Subject: [PATCH] Remove PKINIT RSA support + +RSA mode is no longer needed for interoperability. Reduce the attack +surface of clients and KDCs by removing support for it. + +ticket: 9108 (new) +(cherry picked from commit 401f584526e501b68e7516c17d8e467883f8f210) +--- + doc/user/user_commands/kinit.rst | 4 - + src/plugins/preauth/pkinit/pkinit.h | 2 - + src/plugins/preauth/pkinit/pkinit_clnt.c | 235 +++----- + src/plugins/preauth/pkinit/pkinit_crypto.h | 39 -- + .../preauth/pkinit/pkinit_crypto_openssl.c | 504 ------------------ + src/plugins/preauth/pkinit/pkinit_lib.c | 2 - + src/plugins/preauth/pkinit/pkinit_srv.c | 208 +++----- + src/plugins/preauth/pkinit/pkinit_trace.h | 9 - + src/tests/t_pkinit.py | 7 - + src/windows/leash/htmlhelp/html/KINIT.htm | 3 - + 10 files changed, 131 insertions(+), 882 deletions(-) + +diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst +index 5b105e35a5..d947e83cc6 100644 +--- a/doc/user/user_commands/kinit.rst ++++ b/doc/user/user_commands/kinit.rst +@@ -193,10 +193,6 @@ OPTIONS + **X509_anchors**\ =\ *value* + specify where to find trusted X509 anchor information + +- **flag_RSA_PROTOCOL**\ [**=yes**] +- specify use of RSA, rather than the default Diffie-Hellman +- protocol +- + **disable_freshness**\ [**=yes**] + disable sending freshness tokens (for testing purposes only) + +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 66f92d8f03..5ab0f4bc28 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -146,7 +146,6 @@ typedef struct _pkinit_plg_opts { + int require_eku; /* require EKU checking (default is true) */ + int accept_secondary_eku;/* accept secondary EKU (default is false) */ + int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ +- int dh_or_rsa; /* selects DH or RSA based pkinit */ + int require_crl_checking; /* require CRL for a CA (default is false) */ + int require_freshness; /* require freshness token (default is false) */ + int disable_freshness; /* disable freshness token on client for testing */ +@@ -160,7 +159,6 @@ typedef struct _pkinit_req_opts { + int require_eku; + int accept_secondary_eku; + int allow_upn; +- int dh_or_rsa; + int require_crl_checking; + int dh_size; /* initial request DH modulus size (default=1024) */ + int require_hostname_match; +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index ea9ba454df..54e7537600 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -191,7 +191,6 @@ pkinit_as_req_create(krb5_context context, + krb5_auth_pack auth_pack; + krb5_pa_pk_as_req *req = NULL; + krb5_algorithm_identifier **cmstypes = NULL; +- int protocol = reqctx->opts->dh_or_rsa; + + pkiDebug("pkinit_as_req_create pa_type = %d\n", reqctx->pa_type); + +@@ -214,29 +213,14 @@ pkinit_as_req_create(krb5_context context, + if (retval) + goto cleanup; + +- switch(protocol) { +- case DH_PROTOCOL: +- TRACE_PKINIT_CLIENT_REQ_DH(context); +- pkiDebug("as_req: DH key transport algorithm\n"); ++ TRACE_PKINIT_CLIENT_REQ_DH(context); + +- /* create client-side DH keys */ +- retval = client_create_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- reqctx->opts->dh_size, &spki); +- auth_pack.clientPublicValue = spki; +- if (retval != 0) { +- pkiDebug("failed to create dh parameters\n"); +- goto cleanup; +- } +- break; +- case RSA_PROTOCOL: +- TRACE_PKINIT_CLIENT_REQ_RSA(context); +- pkiDebug("as_req: RSA key transport algorithm\n"); +- break; +- default: +- pkiDebug("as_req: unknown key transport protocol %d\n", +- protocol); +- retval = -1; ++ /* create client-side DH keys */ ++ retval = client_create_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ reqctx->idctx, reqctx->opts->dh_size, &spki); ++ auth_pack.clientPublicValue = spki; ++ if (retval != 0) { ++ pkiDebug("failed to create dh parameters\n"); + goto cleanup; + } + +@@ -553,49 +537,34 @@ pkinit_as_rep_parse(krb5_context context, + return retval; + } + +- switch(kdc_reply->choice) { +- case choice_pa_pk_as_rep_dhInfo: +- pkiDebug("as_rep: DH key transport algorithm\n"); ++ if (kdc_reply->choice != choice_pa_pk_as_rep_dhInfo) { ++ pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); ++ retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ + #ifdef DEBUG_ASN1 +- print_buffer_bin(kdc_reply->u.dh_Info.dhSignedData.data, +- kdc_reply->u.dh_Info.dhSignedData.length, "/tmp/client_kdc_signeddata"); ++ print_buffer_bin(kdc_reply->u.dh_Info.dhSignedData.data, ++ kdc_reply->u.dh_Info.dhSignedData.length, ++ "/tmp/client_kdc_signeddata"); + #endif +- if ((retval = cms_signeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, CMS_SIGN_SERVER, +- reqctx->opts->require_crl_checking, +- (unsigned char *) +- kdc_reply->u.dh_Info.dhSignedData.data, +- kdc_reply->u.dh_Info.dhSignedData.length, +- (unsigned char **)&dh_data.data, +- &dh_data.length, +- NULL, NULL, NULL)) != 0) { +- pkiDebug("failed to verify pkcs7 signed data\n"); +- TRACE_PKINIT_CLIENT_REP_DH_FAIL(context); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_REP_DH(context); +- break; +- case choice_pa_pk_as_rep_encKeyPack: +- pkiDebug("as_rep: RSA key transport algorithm\n"); +- if ((retval = cms_envelopeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, pa_type, +- reqctx->opts->require_crl_checking, +- (unsigned char *) +- kdc_reply->u.encKeyPack.data, +- kdc_reply->u.encKeyPack.length, +- (unsigned char **)&dh_data.data, +- &dh_data.length)) != 0) { +- pkiDebug("failed to verify pkcs7 enveloped data\n"); +- TRACE_PKINIT_CLIENT_REP_RSA_FAIL(context); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_REP_RSA(context); +- break; +- default: +- pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); +- retval = -1; ++ retval = cms_signeddata_verify(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, reqctx->idctx, ++ CMS_SIGN_SERVER, ++ reqctx->opts->require_crl_checking, ++ (unsigned char *) ++ kdc_reply->u.dh_Info.dhSignedData.data, ++ kdc_reply->u.dh_Info.dhSignedData.length, ++ (unsigned char **)&dh_data.data, ++ &dh_data.length, ++ NULL, NULL, NULL); ++ if (retval) { ++ pkiDebug("failed to verify pkcs7 signed data\n"); ++ TRACE_PKINIT_CLIENT_REP_DH_FAIL(context); + goto cleanup; + } ++ TRACE_PKINIT_CLIENT_REP_DH(context); ++ + retval = krb5_build_principal_ext(context, &kdc_princ, + request->server->realm.length, + request->server->realm.data, +@@ -632,116 +601,54 @@ pkinit_as_rep_parse(krb5_context context, + + OCTETDATA_TO_KRB5DATA(&dh_data, &k5data); + +- switch(kdc_reply->choice) { +- case choice_pa_pk_as_rep_dhInfo: + #ifdef DEBUG_ASN1 +- print_buffer_bin(dh_data.data, dh_data.length, +- "/tmp/client_dh_key"); ++ print_buffer_bin(dh_data.data, dh_data.length, "/tmp/client_dh_key"); + #endif +- if ((retval = k5int_decode_krb5_kdc_dh_key_info(&k5data, +- &kdc_dh)) != 0) { +- pkiDebug("failed to decode kdc_dh_key_info\n"); +- goto cleanup; +- } +- +- /* client after KDC reply */ +- if ((retval = client_process_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- (unsigned char *) +- kdc_dh->subjectPublicKey.data, +- kdc_dh->subjectPublicKey.length, +- &client_key, &client_key_len)) != 0) { +- pkiDebug("failed to process dh params\n"); +- goto cleanup; +- } +- +- /* If we have a KDF algorithm ID, call the algorithm agility KDF... */ +- if (kdc_reply->u.dh_Info.kdfID) { +- secret.length = client_key_len; +- secret.data = (char *)client_key; +- +- retval = pkinit_alg_agility_kdf(context, &secret, +- kdc_reply->u.dh_Info.kdfID, +- request->client, request->server, +- etype, encoded_request, +- (krb5_data *)as_rep, key_block); +- +- if (retval) { +- pkiDebug("failed to create key pkinit_alg_agility_kdf %s\n", +- error_message(retval)); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_KDF_ALG(context, kdc_reply->u.dh_Info.kdfID, +- key_block); ++ retval = k5int_decode_krb5_kdc_dh_key_info(&k5data, &kdc_dh); ++ if (retval) { ++ pkiDebug("failed to decode kdc_dh_key_info\n"); ++ goto cleanup; ++ } + +- /* ...otherwise, use the older octetstring2key function. */ +- } else { ++ /* client after KDC reply */ ++ retval = client_process_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ reqctx->idctx, ++ (unsigned char *)kdc_dh->subjectPublicKey.data, ++ kdc_dh->subjectPublicKey.length, &client_key, ++ &client_key_len); ++ if (retval) { ++ pkiDebug("failed to process dh params\n"); ++ goto cleanup; ++ } + +- retval = pkinit_octetstring2key(context, etype, client_key, +- client_key_len, key_block); +- if (retval) { +- pkiDebug("failed to create key pkinit_octetstring2key %s\n", +- error_message(retval)); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_KDF_OS2K(context, key_block); +- } ++ /* If we have a KDF algorithm ID, call the algorithm agility KDF. */ ++ if (kdc_reply->u.dh_Info.kdfID) { ++ secret.length = client_key_len; ++ secret.data = (char *)client_key; + +- break; +- case choice_pa_pk_as_rep_encKeyPack: +-#ifdef DEBUG_ASN1 +- print_buffer_bin(dh_data.data, dh_data.length, +- "/tmp/client_key_pack"); +-#endif +- retval = k5int_decode_krb5_reply_key_pack(&k5data, &key_pack); ++ retval = pkinit_alg_agility_kdf(context, &secret, ++ kdc_reply->u.dh_Info.kdfID, ++ request->client, request->server, ++ etype, encoded_request, ++ (krb5_data *)as_rep, key_block); + if (retval) { +- pkiDebug("failed to decode reply_key_pack\n"); ++ pkiDebug("failed to create key pkinit_alg_agility_kdf %s\n", ++ error_message(retval)); + goto cleanup; + } +- retval = krb5_c_make_checksum(context, +- key_pack->asChecksum.checksum_type, +- &key_pack->replyKey, +- KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, +- encoded_request, &cksum); ++ TRACE_PKINIT_CLIENT_KDF_ALG(context, kdc_reply->u.dh_Info.kdfID, ++ key_block); ++ ++ } else { ++ /* Otherwise, use the older octetstring2key function. */ ++ retval = pkinit_octetstring2key(context, etype, client_key, ++ client_key_len, key_block); + if (retval) { +- pkiDebug("failed to make a checksum\n"); ++ pkiDebug("failed to create key pkinit_octetstring2key %s\n", ++ error_message(retval)); + goto cleanup; + } +- +- if ((cksum.length != key_pack->asChecksum.length) || +- k5_bcmp(cksum.contents, key_pack->asChecksum.contents, +- cksum.length) != 0) { +- TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(context, &cksum, +- &key_pack->asChecksum); +- pkiDebug("failed to match the checksums\n"); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", +- encoded_request->length); +- print_buffer(encoded_request->data, encoded_request->length); +- pkiDebug("encrypting key (%d)\n", key_pack->replyKey.length); +- print_buffer(key_pack->replyKey.contents, +- key_pack->replyKey.length); +- pkiDebug("received checksum type=%d size=%d ", +- key_pack->asChecksum.checksum_type, +- key_pack->asChecksum.length); +- print_buffer(key_pack->asChecksum.contents, +- key_pack->asChecksum.length); +- pkiDebug("expected checksum type=%d size=%d ", +- cksum.checksum_type, cksum.length); +- print_buffer(cksum.contents, cksum.length); +-#endif +- goto cleanup; +- } else +- pkiDebug("checksums match\n"); +- +- krb5_copy_keyblock_contents(context, &key_pack->replyKey, +- key_block); +- TRACE_PKINIT_CLIENT_REP_RSA_KEY(context, key_block, &cksum); +- +- break; +- default: +- pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); +- goto cleanup; ++ TRACE_PKINIT_CLIENT_KDF_OS2K(context, key_block); + } + + retval = 0; +@@ -1286,7 +1193,6 @@ pkinit_client_req_init(krb5_context context, + + reqctx->opts->require_eku = plgctx->opts->require_eku; + reqctx->opts->accept_secondary_eku = plgctx->opts->accept_secondary_eku; +- reqctx->opts->dh_or_rsa = plgctx->opts->dh_or_rsa; + reqctx->opts->allow_upn = plgctx->opts->allow_upn; + reqctx->opts->require_crl_checking = plgctx->opts->require_crl_checking; + reqctx->opts->disable_freshness = plgctx->opts->disable_freshness; +@@ -1457,11 +1363,6 @@ handle_gic_opt(krb5_context context, + retval = add_string_to_array(context, &plgctx->idopts->anchors, value); + if (retval) + return retval; +- } else if (strcmp(attr, "flag_RSA_PROTOCOL") == 0) { +- if (strcmp(value, "yes") == 0) { +- pkiDebug("Setting flag to use RSA_PROTOCOL\n"); +- plgctx->opts->dh_or_rsa = RSA_PROTOCOL; +- } + } else if (strcmp(attr, "disable_freshness") == 0) { + if (strcmp(value, "yes") == 0) + plgctx->opts->disable_freshness = 1; +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 8bdbea8e95..04199b45a4 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -181,45 +181,6 @@ krb5_error_code cms_signeddata_verify + int *is_signed); /* OUT + receives whether message is signed */ + +-/* +- * this function creates a CMS message where eContentType is EnvelopedData +- */ +-krb5_error_code cms_envelopeddata_create +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_preauthtype pa_type, /* IN */ +- unsigned char *key_pack, /* IN +- contains DER encoded ReplyKeyPack */ +- unsigned int key_pack_len, /* IN +- contains length of key_pack */ +- unsigned char **envel_data, /* OUT +- receives DER encoded encKeyPack */ +- unsigned int *envel_data_len); /* OUT +- receives length of envel_data */ +- +-/* +- * this function creates a CMS message where eContentType is EnvelopedData +- */ +-krb5_error_code cms_envelopeddata_verify +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_preauthtype pa_type, /* IN */ +- int require_crl_checking, /* IN +- specifies whether CRL checking should be +- strictly enforced */ +- unsigned char *envel_data, /* IN +- contains DER encoded encKeyPack */ +- unsigned int envel_data_len, /* IN +- contains length of envel_data */ +- unsigned char **signed_data, /* OUT +- receives ReplyKeyPack */ +- unsigned int *signed_data_len); /* OUT +- receives length of signed_data */ +- + /* + * This function retrieves the signer's identity, in a form that could + * be passed back in to a future invocation of this module as a candidate +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f5aade34cc..26fa9184b3 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -66,26 +66,14 @@ static krb5_error_code create_signature + (unsigned char **, unsigned int *, unsigned char *, unsigned int, + EVP_PKEY *pkey); + +-static krb5_error_code pkinit_decode_data +-(krb5_context context, pkinit_identity_crypto_context cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded, +- unsigned int *decoded_len); +- + #ifdef DEBUG_DH + static void print_dh(DH *, char *); + static void print_pubkey(BIGNUM *, char *); + #endif + +-static int prepare_enc_data +-(const uint8_t *indata, int indata_len, uint8_t **outdata, int *outdata_len); +- + static int openssl_callback (int, X509_STORE_CTX *); + static int openssl_callback_ignore_crls (int, X509_STORE_CTX *); + +-static int pkcs7_decrypt +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, +- unsigned char **data_out, unsigned int *len_out); +- + static ASN1_OBJECT * pkinit_pkcs7type2oid + (pkinit_plg_crypto_context plg_cryptoctx, int pkcs7_type); + +@@ -115,20 +103,12 @@ static krb5_error_code pkinit_sign_data_pkcs11 + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); +-static krb5_error_code pkinit_decode_data_pkcs11 +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded_data, +- unsigned int *decoded_data_len); + #endif /* WITHOUT_PKCS11 */ + + static krb5_error_code pkinit_sign_data_fs + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); +-static krb5_error_code pkinit_decode_data_fs +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded_data, +- unsigned int *decoded_data_len); + + static krb5_error_code + create_krb5_invalidCertificates(krb5_context context, +@@ -140,10 +120,6 @@ create_krb5_invalidCertificates(krb5_context context, + static krb5_error_code + create_identifiers_from_stack(STACK_OF(X509) *sk, + krb5_external_principal_identifier *** ids); +-static int +-wrap_signeddata(unsigned char *data, unsigned int data_len, +- unsigned char **out, unsigned int *out_len); +- + static const char * + pkcs11err(int err); + +@@ -2177,177 +2153,6 @@ cleanup: + return retval; + } + +-krb5_error_code +-cms_envelopeddata_create(krb5_context context, +- pkinit_plg_crypto_context plgctx, +- pkinit_req_crypto_context reqctx, +- pkinit_identity_crypto_context idctx, +- krb5_preauthtype pa_type, +- unsigned char *key_pack, +- unsigned int key_pack_len, +- unsigned char **out, +- unsigned int *out_len) +-{ +- +- krb5_error_code retval = ENOMEM; +- PKCS7 *p7 = NULL; +- BIO *in = NULL; +- unsigned char *p = NULL, *signed_data = NULL, *enc_data = NULL; +- int signed_data_len = 0, enc_data_len = 0, flags = PKCS7_BINARY; +- STACK_OF(X509) *encerts = NULL; +- const EVP_CIPHER *cipher = NULL; +- +- retval = cms_signeddata_create(context, plgctx, reqctx, idctx, +- CMS_ENVEL_SERVER, key_pack, key_pack_len, +- &signed_data, +- (unsigned int *)&signed_data_len); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- +- /* check we have client's certificate */ +- if (reqctx->received_cert == NULL) { +- retval = KRB5KDC_ERR_PREAUTH_FAILED; +- goto cleanup; +- } +- encerts = sk_X509_new_null(); +- sk_X509_push(encerts, reqctx->received_cert); +- +- cipher = EVP_des_ede3_cbc(); +- in = BIO_new(BIO_s_mem()); +- prepare_enc_data(signed_data, signed_data_len, &enc_data, +- &enc_data_len); +- retval = BIO_write(in, enc_data, enc_data_len); +- if (retval != enc_data_len) { +- pkiDebug("BIO_write only wrote %d\n", retval); +- goto cleanup; +- } +- +- p7 = PKCS7_encrypt(encerts, in, cipher, flags); +- if (p7 == NULL) { +- retval = oerr(context, 0, _("Failed to encrypt PKCS7 object")); +- goto cleanup; +- } +- p7->d.enveloped->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_signed); +- +- *out_len = i2d_PKCS7(p7, NULL); +- if (!*out_len || (p = *out = malloc(*out_len)) == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- retval = i2d_PKCS7(p7, &p); +- if (!retval) { +- retval = oerr(context, 0, _("Failed to DER encode PKCS7")); +- goto cleanup; +- } +- retval = 0; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(*out, *out_len, "/tmp/kdc_enveloped_data"); +-#endif +- +-cleanup: +- if (p7 != NULL) +- PKCS7_free(p7); +- if (in != NULL) +- BIO_free(in); +- free(signed_data); +- free(enc_data); +- if (encerts != NULL) +- sk_X509_free(encerts); +- +- return retval; +-} +- +-krb5_error_code +-cms_envelopeddata_verify(krb5_context context, +- pkinit_plg_crypto_context plg_cryptoctx, +- pkinit_req_crypto_context req_cryptoctx, +- pkinit_identity_crypto_context id_cryptoctx, +- krb5_preauthtype pa_type, +- int require_crl_checking, +- unsigned char *enveloped_data, +- unsigned int enveloped_data_len, +- unsigned char **data, +- unsigned int *data_len) +-{ +- krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; +- PKCS7 *p7 = NULL; +- const unsigned char *p = enveloped_data; +- unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; +- unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(enveloped_data, enveloped_data_len, +- "/tmp/client_envelopeddata"); +-#endif +- /* decode received PKCS7 message */ +- if ((p7 = d2i_PKCS7(NULL, &p, (int)enveloped_data_len)) == NULL) { +- retval = oerr(context, 0, _("Failed to decode PKCS7")); +- goto cleanup; +- } +- +- /* verify that the received message is PKCS7 EnvelopedData message */ +- if (OBJ_obj2nid(p7->type) != NID_pkcs7_enveloped || +- p7->d.enveloped == NULL || +- p7->d.enveloped->enc_data->enc_data == NULL) { +- pkiDebug("Expected id-enveloped PKCS7 msg (received type = %d)\n", +- OBJ_obj2nid(p7->type)); +- krb5_set_error_message(context, retval, "wrong oid\n"); +- goto cleanup; +- } +- +- /* decrypt received PKCS7 message */ +- if (pkcs7_decrypt(context, id_cryptoctx, p7, &tmp_buf, &tmp_buf_len)) { +- pkiDebug("PKCS7 decryption successful\n"); +- } else { +- retval = oerr(context, 0, _("Failed to decrypt PKCS7 message")); +- goto cleanup; +- } +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); +-#endif +- /* verify PKCS7 SignedData message */ +- /* Wrap the signed data to make decoding easier in the verify routine. */ +- retval = wrap_signeddata(tmp_buf, tmp_buf_len, &tmp_buf2, &tmp_buf2_len); +- if (retval) { +- pkiDebug("failed to encode signeddata\n"); +- goto cleanup; +- } +- vfy_buf = tmp_buf2; +- vfy_buf_len = tmp_buf2_len; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(vfy_buf, vfy_buf_len, "/tmp/client_enc_keypack2"); +-#endif +- +- retval = cms_signeddata_verify(context, plg_cryptoctx, req_cryptoctx, +- id_cryptoctx, CMS_ENVEL_SERVER, +- require_crl_checking, +- vfy_buf, vfy_buf_len, +- data, data_len, NULL, NULL, NULL); +- +- if (!retval) +- pkiDebug("PKCS7 Verification Success\n"); +- else { +- pkiDebug("PKCS7 Verification Failure\n"); +- goto cleanup; +- } +- +- retval = 0; +- +-cleanup: +- +- if (p7 != NULL) +- PKCS7_free(p7); +- free(tmp_buf); +- free(tmp_buf2); +- +- return retval; +-} +- + static krb5_error_code + crypto_retrieve_X509_sans(krb5_context context, + pkinit_plg_crypto_context plgctx, +@@ -3398,70 +3203,6 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) + + } + +-static int +-wrap_signeddata(unsigned char *data, unsigned int data_len, +- unsigned char **out, unsigned int *out_len) +-{ +- +- unsigned int orig_len = 0, oid_len = 0, tot_len = 0; +- ASN1_OBJECT *oid = NULL; +- unsigned char *p = NULL; +- +- /* Get length to wrap the original data with SEQUENCE tag */ +- tot_len = orig_len = ASN1_object_size(1, (int)data_len, V_ASN1_SEQUENCE); +- +- /* Add the signedData OID and adjust lengths */ +- oid = OBJ_nid2obj(NID_pkcs7_signed); +- oid_len = i2d_ASN1_OBJECT(oid, NULL); +- +- tot_len = ASN1_object_size(1, (int)(orig_len+oid_len), V_ASN1_SEQUENCE); +- +- p = *out = malloc(tot_len); +- if (p == NULL) return -1; +- +- ASN1_put_object(&p, 1, (int)(orig_len+oid_len), +- V_ASN1_SEQUENCE, V_ASN1_UNIVERSAL); +- +- i2d_ASN1_OBJECT(oid, &p); +- +- ASN1_put_object(&p, 1, (int)data_len, 0, V_ASN1_CONTEXT_SPECIFIC); +- memcpy(p, data, data_len); +- +- *out_len = tot_len; +- +- return 0; +-} +- +-static int +-prepare_enc_data(const uint8_t *indata, int indata_len, uint8_t **outdata, +- int *outdata_len) +-{ +- int tag, class; +- long tlen, slen; +- const uint8_t *p = indata, *oldp; +- +- if (ASN1_get_object(&p, &slen, &tag, &class, indata_len) & 0x80) +- return EINVAL; +- if (tag != V_ASN1_SEQUENCE) +- return EINVAL; +- +- oldp = p; +- if (ASN1_get_object(&p, &tlen, &tag, &class, slen) & 0x80) +- return EINVAL; +- p += tlen; +- slen -= (p - oldp); +- +- if (ASN1_get_object(&p, &tlen, &tag, &class, slen) & 0x80) +- return EINVAL; +- +- *outdata = malloc(tlen); +- if (*outdata == NULL) +- return ENOMEM; +- memcpy(*outdata, p, tlen); +- *outdata_len = tlen; +- return 0; +-} +- + #ifndef WITHOUT_PKCS11 + static struct plugin_file_handle * + load_pkcs11_module(krb5_context context, const char *modname, +@@ -3780,169 +3521,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + } + #endif + +-static krb5_error_code +-pkinit_decode_data_fs(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, unsigned int *decoded_data_len) +-{ +- X509 *cert = sk_X509_value(id_cryptoctx->my_certs, +- id_cryptoctx->cert_index); +- EVP_PKEY *pkey = id_cryptoctx->my_key; +- EVP_PKEY_CTX *ctx = NULL; +- uint8_t *buf = NULL; +- size_t buf_len = 0; +- int ok; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (cert != NULL && !X509_check_private_key(cert, pkey)) { +- pkiDebug("private key does not match certificate\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- +- ctx = EVP_PKEY_CTX_new(pkey, NULL); +- if (ctx == NULL) +- return KRB5KDC_ERR_PREAUTH_FAILED; +- +- ok = EVP_PKEY_decrypt_init(ctx); +- if (!ok) +- goto cleanup; +- +- /* Get the length of the eventual output. */ +- ok = EVP_PKEY_decrypt(ctx, NULL, &buf_len, data, data_len); +- if (!ok) { +- pkiDebug("unable to decrypt received data\n"); +- goto cleanup; +- } +- +- buf = malloc(buf_len); +- if (buf == NULL) { +- ok = 0; +- goto cleanup; +- } +- +- ok = EVP_PKEY_decrypt(ctx, buf, &buf_len, data, data_len); +- if (!ok) { +- pkiDebug("unable to decrypt received data\n"); +- goto cleanup; +- } +- +- *decoded_data = buf; +- *decoded_data_len = buf_len; +- buf = NULL; +-cleanup: +- zapfree(buf, buf_len); +- EVP_PKEY_CTX_free(ctx); +- return ok ? 0 : KRB5KDC_ERR_PREAUTH_FAILED; +-} +- +-#ifndef WITHOUT_PKCS11 +-/* +- * When using the ActivCard Linux pkcs11 library (v2.0.1), the decrypt function +- * fails. By inserting an extra function call, which serves nothing but to +- * change the stack, we were able to work around the issue. If the ActivCard +- * library is fixed in the future, this function can be inlined back into the +- * caller. +- */ +-static CK_RV +-pkinit_C_Decrypt(pkinit_identity_crypto_context id_cryptoctx, +- CK_BYTE_PTR pEncryptedData, +- CK_ULONG ulEncryptedDataLen, +- CK_BYTE_PTR pData, +- CK_ULONG_PTR pulDataLen) +-{ +- CK_RV rv = CKR_OK; +- +- rv = id_cryptoctx->p11->C_Decrypt(id_cryptoctx->session, pEncryptedData, +- ulEncryptedDataLen, pData, pulDataLen); +- if (rv == CKR_OK) { +- pkiDebug("pData %p *pulDataLen %d\n", (void *) pData, +- (int) *pulDataLen); +- } +- return rv; +-} +- +-static krb5_error_code +-pkinit_decode_data_pkcs11(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, +- unsigned int *decoded_data_len) +-{ +- CK_OBJECT_HANDLE obj; +- CK_ULONG len; +- CK_MECHANISM mech; +- uint8_t *cp; +- int r; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (pkinit_open_session(context, id_cryptoctx)) { +- pkiDebug("can't open pkcs11 session\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- +- pkinit_find_private_key(id_cryptoctx, CKA_DECRYPT, &obj); +- +- mech.mechanism = CKM_RSA_PKCS; +- mech.pParameter = NULL; +- mech.ulParameterLen = 0; +- +- if ((r = id_cryptoctx->p11->C_DecryptInit(id_cryptoctx->session, &mech, +- obj)) != CKR_OK) { +- pkiDebug("C_DecryptInit: 0x%x\n", (int) r); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- pkiDebug("data_len = %d\n", data_len); +- cp = malloc((size_t) data_len); +- if (cp == NULL) +- return ENOMEM; +- len = data_len; +- pkiDebug("session %p edata %p edata_len %d data %p datalen @%p %d\n", +- (void *) id_cryptoctx->session, (void *) data, (int) data_len, +- (void *) cp, (void *) &len, (int) len); +- r = pkinit_C_Decrypt(id_cryptoctx, (CK_BYTE_PTR) data, (CK_ULONG) data_len, +- cp, &len); +- if (r != CKR_OK) { +- pkiDebug("C_Decrypt: %s\n", pkcs11err(r)); +- if (r == CKR_BUFFER_TOO_SMALL) +- pkiDebug("decrypt %d needs %d\n", (int) data_len, (int) len); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- pkiDebug("decrypt %d -> %d\n", (int) data_len, (int) len); +- *decoded_data_len = len; +- *decoded_data = cp; +- +- return 0; +-} +-#endif +- +-krb5_error_code +-pkinit_decode_data(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, unsigned int *decoded_data_len) +-{ +- krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (id_cryptoctx->pkcs11_method != 1) +- retval = pkinit_decode_data_fs(context, id_cryptoctx, data, data_len, +- decoded_data, decoded_data_len); +-#ifndef WITHOUT_PKCS11 +- else +- retval = pkinit_decode_data_pkcs11(context, id_cryptoctx, data, +- data_len, decoded_data, decoded_data_len); +-#endif +- +- return retval; +-} +- + static krb5_error_code + pkinit_sign_data_fs(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, +@@ -5617,88 +5195,6 @@ cleanup: + return retval; + } + +-/* Originally based on OpenSSL's PKCS7_dataDecode(), now modified to remove the +- * use of BIO objects and to fit the PKINIT internal interfaces. */ +-static int +-pkcs7_decrypt(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, +- unsigned char **data_out, unsigned int *len_out) +-{ +- krb5_error_code ret; +- int ok = 0, plaintext_len = 0, final_len; +- unsigned int keylen = 0, eklen = 0, blocksize; +- unsigned char *ek = NULL, *tkey = NULL, *plaintext = NULL, *use_key; +- ASN1_OCTET_STRING *data_body = p7->d.enveloped->enc_data->enc_data; +- const EVP_CIPHER *evp_cipher; +- EVP_CIPHER_CTX *evp_ctx = NULL; +- X509_ALGOR *enc_alg = p7->d.enveloped->enc_data->algorithm; +- STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; +- PKCS7_RECIP_INFO *ri = NULL; +- +- *data_out = NULL; +- *len_out = 0; +- +- p7->state = PKCS7_S_HEADER; +- +- /* RFC 4556 section 3.2.3.2 requires that there be exactly one +- * recipientInfo. */ +- if (sk_PKCS7_RECIP_INFO_num(rsk) != 1) { +- pkiDebug("invalid number of EnvelopedData RecipientInfos\n"); +- return 0; +- } +- ri = sk_PKCS7_RECIP_INFO_value(rsk, 0); +- +- evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); +- if (evp_cipher == NULL) +- goto cleanup; +- keylen = EVP_CIPHER_key_length(evp_cipher); +- blocksize = EVP_CIPHER_block_size(evp_cipher); +- +- evp_ctx = EVP_CIPHER_CTX_new(); +- if (evp_ctx == NULL) +- goto cleanup; +- if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || +- EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) +- goto cleanup; +- +- /* Generate a random symmetric key to avoid exposing timing data if RSA +- * decryption fails the padding check. */ +- tkey = malloc(keylen); +- if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) +- goto cleanup; +- +- /* Decrypt the secret key with the private key. */ +- ret = pkinit_decode_data(context, id_cryptoctx, +- ASN1_STRING_get0_data(ri->enc_key), +- ASN1_STRING_length(ri->enc_key), &ek, &eklen); +- use_key = (ret || eklen != keylen) ? tkey : ek; +- +- /* Allocate a plaintext buffer and decrypt data_body into it. */ +- plaintext = malloc(data_body->length + blocksize); +- if (plaintext == NULL) +- goto cleanup; +- if (!EVP_DecryptInit(evp_ctx, NULL, use_key, NULL)) +- goto cleanup; +- if (!EVP_DecryptUpdate(evp_ctx, plaintext, &plaintext_len, +- data_body->data, data_body->length)) +- goto cleanup; +- if (!EVP_DecryptFinal(evp_ctx, plaintext + plaintext_len, &final_len)) +- goto cleanup; +- plaintext_len += final_len; +- +- *len_out = plaintext_len; +- *data_out = plaintext; +- plaintext = NULL; +- ok = 1; +- +-cleanup: +- EVP_CIPHER_CTX_free(evp_ctx); +- zapfree(plaintext, plaintext_len); +- zapfree(ek, eklen); +- zapfree(tkey, keylen); +- return ok; +-} +- + #ifdef DEBUG_DH + static void + print_dh(DH * dh, char *msg) +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 4c3d46bf5a..19db695a4d 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -50,7 +50,6 @@ pkinit_init_req_opts(pkinit_req_opts **reqopts) + opts->require_eku = 1; + opts->accept_secondary_eku = 0; + opts->allow_upn = 0; +- opts->dh_or_rsa = DH_PROTOCOL; + opts->require_crl_checking = 0; + opts->dh_size = PKINIT_DEFAULT_DH_MIN_BITS; + +@@ -79,7 +78,6 @@ pkinit_init_plg_opts(pkinit_plg_opts **plgopts) + + opts->require_eku = 1; + opts->accept_secondary_eku = 0; +- opts->dh_or_rsa = DH_PROTOCOL; + opts->allow_upn = 0; + opts->require_crl_checking = 0; + opts->require_freshness = 0; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 768a4e559f..aab21f951c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -821,132 +821,55 @@ pkinit_server_return_padata(krb5_context context, + retval = ENOMEM; + goto cleanup; + } +- /* let's assume it's RSA. we'll reset it to DH if needed */ +- rep->choice = choice_pa_pk_as_rep_encKeyPack; + +- if (reqctx->rcv_auth_pack != NULL && +- reqctx->rcv_auth_pack->clientPublicValue.length > 0) { +- rep->choice = choice_pa_pk_as_rep_dhInfo; +- +- pkiDebug("received DH key delivery AS REQ\n"); +- retval = server_process_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- &dh_pubkey, &dh_pubkey_len, +- &server_key, &server_key_len); +- if (retval) { +- pkiDebug("failed to process/create dh parameters\n"); +- goto cleanup; +- } +- +- /* +- * This is DH, so don't generate the key until after we +- * encode the reply, because the encoded reply is needed +- * to generate the key in some cases. +- */ +- +- dhkey_info.subjectPublicKey.length = dh_pubkey_len; +- dhkey_info.subjectPublicKey.data = (char *)dh_pubkey; +- dhkey_info.nonce = request->nonce; +- dhkey_info.dhKeyExpiration = 0; +- +- retval = k5int_encode_krb5_kdc_dh_key_info(&dhkey_info, +- &encoded_dhkey_info); +- if (retval) { +- pkiDebug("encode_krb5_kdc_dh_key_info failed\n"); +- goto cleanup; +- } +-#ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- "/tmp/kdc_dh_key_info"); +-#endif +- +- retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- CMS_SIGN_SERVER, +- (unsigned char *) +- encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- (unsigned char **) +- &rep->u.dh_Info.dhSignedData.data, +- &rep->u.dh_Info.dhSignedData.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- +- } else { +- pkiDebug("received RSA key delivery AS REQ\n"); +- +- init_krb5_reply_key_pack(&key_pack); +- if (key_pack == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } ++ if (reqctx->rcv_auth_pack == NULL || ++ reqctx->rcv_auth_pack->clientPublicValue.length == 0) { ++ retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, retval, _("Unsupported PKINIT RSA request")); ++ goto cleanup; ++ } + +- retval = krb5_c_make_random_key(context, enctype, &key_pack->replyKey); +- if (retval) { +- pkiDebug("unable to make a session key\n"); +- goto cleanup; +- } ++ rep->choice = choice_pa_pk_as_rep_dhInfo; + +- retval = krb5_c_make_checksum(context, 0, &key_pack->replyKey, +- KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, +- req_pkt, &key_pack->asChecksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); +- print_buffer(key_pack->asChecksum.contents, +- key_pack->asChecksum.length); +- pkiDebug("encrypting key (%d)\n", key_pack->replyKey.length); +- print_buffer(key_pack->replyKey.contents, key_pack->replyKey.length); +-#endif ++ retval = server_process_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ plgctx->idctx, &dh_pubkey, &dh_pubkey_len, ++ &server_key, &server_key_len); ++ if (retval) { ++ pkiDebug("failed to process/create dh parameters\n"); ++ goto cleanup; ++ } + +- retval = k5int_encode_krb5_reply_key_pack(key_pack, +- &encoded_key_pack); +- if (retval) { +- pkiDebug("failed to encode reply_key_pack\n"); +- goto cleanup; +- } ++ dhkey_info.subjectPublicKey.length = dh_pubkey_len; ++ dhkey_info.subjectPublicKey.data = (char *)dh_pubkey; ++ dhkey_info.nonce = request->nonce; ++ dhkey_info.dhKeyExpiration = 0; + +- rep->choice = choice_pa_pk_as_rep_encKeyPack; +- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- padata->pa_type, +- (unsigned char *) +- encoded_key_pack->data, +- encoded_key_pack->length, +- (unsigned char **) +- &rep->u.encKeyPack.data, +- &rep->u.encKeyPack.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 enveloped data: %s\n", +- error_message(retval)); +- goto cleanup; +- } ++ retval = k5int_encode_krb5_kdc_dh_key_info(&dhkey_info, ++ &encoded_dhkey_info); ++ if (retval) { ++ pkiDebug("encode_krb5_kdc_dh_key_info failed\n"); ++ goto cleanup; ++ } + #ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)encoded_key_pack->data, +- encoded_key_pack->length, +- "/tmp/kdc_key_pack"); +- print_buffer_bin(rep->u.encKeyPack.data, rep->u.encKeyPack.length, +- "/tmp/kdc_enc_key_pack"); ++ print_buffer_bin((unsigned char *)encoded_dhkey_info->data, ++ encoded_dhkey_info->length, "/tmp/kdc_dh_key_info"); + #endif + +- retval = cb->replace_reply_key(context, rock, &key_pack->replyKey, +- FALSE); +- if (retval) +- goto cleanup; ++ retval = cms_signeddata_create(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ CMS_SIGN_SERVER, ++ (unsigned char *)encoded_dhkey_info->data, ++ encoded_dhkey_info->length, ++ (unsigned char **) ++ &rep->u.dh_Info.dhSignedData.data, ++ &rep->u.dh_Info.dhSignedData.length); ++ if (retval) { ++ pkiDebug("failed to create pkcs7 signed data\n"); ++ goto cleanup; + } + +- if (rep->choice == choice_pa_pk_as_rep_dhInfo && +- ((reqctx->rcv_auth_pack != NULL && +- reqctx->rcv_auth_pack->supportedKDFs != NULL))) { +- ++ if (reqctx->rcv_auth_pack != NULL && ++ reqctx->rcv_auth_pack->supportedKDFs != NULL) { + /* If using the alg-agility KDF, put the algorithm in the reply + * before encoding it. + */ +@@ -973,41 +896,36 @@ pkinit_server_return_padata(krb5_context context, + "/tmp/kdc_as_rep"); + #endif + +- /* If this is DH, we haven't computed the key yet, so do it now. */ +- if (rep->choice == choice_pa_pk_as_rep_dhInfo) { +- +- /* If mutually supported KDFs were found, use the algorithm agility +- * KDF. */ +- if (rep->u.dh_Info.kdfID) { +- secret.data = (char *)server_key; +- secret.length = server_key_len; ++ /* If mutually supported KDFs were found, use the algorithm agility KDF. */ ++ if (rep->u.dh_Info.kdfID) { ++ secret.data = (char *)server_key; ++ secret.length = server_key_len; + +- retval = pkinit_alg_agility_kdf(context, &secret, +- rep->u.dh_Info.kdfID, +- request->client, request->server, +- enctype, req_pkt, out_data, +- &reply_key); +- if (retval) { +- pkiDebug("pkinit_alg_agility_kdf failed: %s\n", +- error_message(retval)); +- goto cleanup; +- } ++ retval = pkinit_alg_agility_kdf(context, &secret, rep->u.dh_Info.kdfID, ++ request->client, request->server, ++ enctype, req_pkt, out_data, ++ &reply_key); ++ if (retval) { ++ pkiDebug("pkinit_alg_agility_kdf failed: %s\n", ++ error_message(retval)); ++ goto cleanup; ++ } + +- /* Otherwise, use the older octetstring2key() function */ +- } else { +- retval = pkinit_octetstring2key(context, enctype, server_key, ++ /* Otherwise, use the older octetstring2key() function */ ++ } else { ++ retval = pkinit_octetstring2key(context, enctype, server_key, + server_key_len, &reply_key); +- if (retval) { +- pkiDebug("pkinit_octetstring2key failed: %s\n", +- error_message(retval)); +- goto cleanup; +- } +- } +- retval = cb->replace_reply_key(context, rock, &reply_key, FALSE); +- if (retval) ++ if (retval) { ++ pkiDebug("pkinit_octetstring2key failed: %s\n", ++ error_message(retval)); + goto cleanup; ++ } + } + ++ retval = cb->replace_reply_key(context, rock, &reply_key, FALSE); ++ if (retval) ++ goto cleanup; ++ + *send_pa = malloc(sizeof(krb5_pa_data)); + if (*send_pa == NULL) { + retval = ENOMEM; +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 5ee39c085c..d385759145 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -58,19 +58,10 @@ + TRACE(c, "PKINIT client verified DH reply") + #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ + TRACE(c, "PKINIT client could not verify DH reply") +-#define TRACE_PKINIT_CLIENT_REP_RSA(c) \ +- TRACE(c, "PKINIT client verified RSA reply") +-#define TRACE_PKINIT_CLIENT_REP_RSA_KEY(c, keyblock, cksum) \ +- TRACE(c, "PKINIT client retrieved reply key {keyblock} from RSA " \ +- "reply (checksum {cksum})", keyblock, cksum) +-#define TRACE_PKINIT_CLIENT_REP_RSA_FAIL(c) \ +- TRACE(c, "PKINIT client could not verify RSA reply") + #define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \ + TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum) + #define TRACE_PKINIT_CLIENT_REQ_DH(c) \ + TRACE(c, "PKINIT client making DH request") +-#define TRACE_PKINIT_CLIENT_REQ_RSA(c) \ +- TRACE(c, "PKINIT client making RSA request") + #define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \ + TRACE(c, "PKINIT client config accepts KDC dNSName SAN {str}", host) + #define TRACE_PKINIT_CLIENT_SAN_MATCH_DNSNAME(c, host) \ +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index ec2356ea22..62e6c426d3 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -179,13 +179,6 @@ id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', + id_env = realm.special_env('idconf', False, krb5_conf=id_conf) + realm.kinit(realm.user_princ, expected_trace=msgs, env=id_env) + +-# Try again using RSA instead of DH. +-mark('FILE identity, no password, RSA') +-realm.pkinit(realm.user_princ, flags=['-X', 'flag_RSA_PROTOCOL=yes'], +- expected_trace=('PKINIT client making RSA request', +- 'PKINIT client verified RSA reply')) +-realm.klist(realm.user_princ) +- + # Test a DH parameter renegotiation by temporarily setting a 4096-bit + # minimum on the KDC. (Preauth type 16 is PKINIT PA_PK_AS_REQ; + # 109 is PKINIT TD_DH_PARAMETERS; 133 is FAST PA-FX-COOKIE.) +diff --git a/src/windows/leash/htmlhelp/html/KINIT.htm b/src/windows/leash/htmlhelp/html/KINIT.htm +index eeee211a6e..46cb4a3ad8 100644 +--- a/src/windows/leash/htmlhelp/html/KINIT.htm ++++ b/src/windows/leash/htmlhelp/html/KINIT.htm +@@ -146,9 +146,6 @@ default credentials cache may vary between systems. If the KRB5CCNAME en + -S service_name + specify an alternate service name to use when getting initial + tickets. +- +- flag_RSA_PROTOCOL[=yes] +- specify use of RSA, rather than the default Diffie-Hellman protocol. + + +

ENVIRONMENT

+-- +2.46.0 + diff --git a/0024-Fix-various-issues-detected-by-static-analysis.patch b/0024-Fix-various-issues-detected-by-static-analysis.patch new file mode 100644 index 0000000..ebab90b --- /dev/null +++ b/0024-Fix-various-issues-detected-by-static-analysis.patch @@ -0,0 +1,265 @@ +From 3999883b9745bfd7065d41ff05b19e56bcb2e791 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 6 Sep 2024 17:18:11 +0200 +Subject: [PATCH] Fix various issues detected by static analysis + +In klists's show_credential(), ensure that the column counter doesn't +decrease if printf() fails. + +In process_k5beta7_princ(), bounds-check the e_length field. + +In ndr_enc_delegation_info(), initialize b so it is always valid for +the cleanup handler. + +In krb5_dbe_def_decrypt_key_data(), change the flow control so ret is +always set by the end of the function. Return KRB5_KDB_INVALIDKEYSIZE +if there isn't enough data in the first key_data_contents field or if +the serialized key length is invalid. + +In svcauth_gss_validate(), expand rpchdr to accomodate the header plus +MAX_AUTH_BYTES. + +In svcudp_reply(), change slen to unsigned to match the return type of +XDR_GETPOS() and eliminate an unnecessary check for slen >= 0. + +In krb5int_pthread_loaded()(), remove pthread_equal() from the weak +symbol checks. It is implemented as an inline function in some glibc +versions, which makes the comparison "&pthread_equal == 0" always +false. + +[ghudson@mit.edu: further modified krb5_dbe_def_decrypt_key_data() for +clarity; added detail to commit message] + +(cherry picked from commit a96541981ee34c8642ddeb6101b98e883e41c6e5) +--- + src/clients/klist/klist.c | 12 ++++----- + src/kadmin/dbutil/dump.c | 5 ++++ + src/kdc/ndr.c | 2 +- + src/lib/kdb/decrypt_key.c | 54 ++++++++++++++++++++------------------ + src/lib/rpc/svc_auth_gss.c | 5 +++- + src/lib/rpc/svc_udp.c | 13 ++++----- + src/util/support/threads.c | 2 -- + 7 files changed, 51 insertions(+), 42 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index b5808e5c93..ba9539fd23 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -681,7 +681,7 @@ show_credential(krb5_creds *cred, const char *defname) + krb5_error_code ret; + krb5_ticket *tkt = NULL; + char *name = NULL, *sname = NULL, *tktsname, *flags; +- int extra_field = 0, ccol = 0, i; ++ int extra_field = 0, ccol = 0, i, r; + krb5_boolean is_config = krb5_is_config_principal(context, cred->server); + + ret = krb5_unparse_name(context, cred->client, &name); +@@ -711,11 +711,11 @@ show_credential(krb5_creds *cred, const char *defname) + fputs("config: ", stdout); + ccol = 8; + for (i = 1; i < cred->server->length; i++) { +- ccol += printf("%s%.*s%s", +- i > 1 ? "(" : "", +- (int)cred->server->data[i].length, +- cred->server->data[i].data, +- i > 1 ? ")" : ""); ++ r = printf("%s%.*s%s", i > 1 ? "(" : "", ++ (int)cred->server->data[i].length, ++ cred->server->data[i].data, i > 1 ? ")" : ""); ++ if (r >= 0) ++ ccol += r; + } + fputs(" = ", stdout); + ccol += 3; +diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c +index 4d6cc0bdf9..feb053d834 100644 +--- a/src/kadmin/dbutil/dump.c ++++ b/src/kadmin/dbutil/dump.c +@@ -704,6 +704,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, + + dbentry->len = u1; + dbentry->n_key_data = u4; ++ ++ if (u5 > UINT16_MAX) { ++ load_err(fname, *linenop, _("invalid principal extra data size")); ++ goto fail; ++ } + dbentry->e_length = u5; + + if (kp != NULL) { +diff --git a/src/kdc/ndr.c b/src/kdc/ndr.c +index d438408ee2..38be9fe42a 100644 +--- a/src/kdc/ndr.c ++++ b/src/kdc/ndr.c +@@ -242,7 +242,7 @@ ndr_enc_delegation_info(struct pac_s4u_delegation_info *in, krb5_data *out) + { + krb5_error_code ret; + size_t i; +- struct k5buf b; ++ struct k5buf b = EMPTY_K5BUF; + struct encoded_wchars pt_encoded = { 0 }, *tss_encoded = NULL; + uint32_t pointer = 0; + +diff --git a/src/lib/kdb/decrypt_key.c b/src/lib/kdb/decrypt_key.c +index 82bbed6312..21aa3742b1 100644 +--- a/src/lib/kdb/decrypt_key.c ++++ b/src/lib/kdb/decrypt_key.c +@@ -60,7 +60,7 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey, + krb5_keyblock *dbkey_out, + krb5_keysalt *keysalt_out) + { +- krb5_error_code ret; ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; + int16_t keylen; + krb5_enc_data cipher; + krb5_data plain = empty_data(); +@@ -74,36 +74,38 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey, + if (mkey == NULL) + return KRB5_KDB_BADSTORED_MKEY; + +- if (kd->key_data_contents[0] != NULL && kd->key_data_length[0] >= 2) { +- keylen = load_16_le(kd->key_data_contents[0]); +- if (keylen < 0) +- return EINVAL; +- cipher.enctype = ENCTYPE_UNKNOWN; +- cipher.ciphertext = make_data(kd->key_data_contents[0] + 2, +- kd->key_data_length[0] - 2); +- ret = alloc_data(&plain, kd->key_data_length[0] - 2); +- if (ret) +- goto cleanup; ++ if (kd->key_data_contents[0] == NULL || kd->key_data_length[0] < 2) ++ return KRB5_KDB_INVALIDKEYSIZE; + +- ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain); +- if (ret) +- goto cleanup; ++ keylen = load_16_le(kd->key_data_contents[0]); ++ if (keylen < 0) ++ return KRB5_KDB_INVALIDKEYSIZE; + +- /* Make sure the plaintext has at least as many bytes as the true ke +- * length (it may have more due to padding). */ +- if ((unsigned int)keylen > plain.length) { +- ret = KRB5_CRYPTO_INTERNAL; +- if (ret) +- goto cleanup; +- } ++ cipher.enctype = ENCTYPE_UNKNOWN; ++ cipher.ciphertext = make_data(kd->key_data_contents[0] + 2, ++ kd->key_data_length[0] - 2); ++ ret = alloc_data(&plain, kd->key_data_length[0] - 2); ++ if (ret) ++ goto cleanup; + +- kb.magic = KV5M_KEYBLOCK; +- kb.enctype = kd->key_data_type[0]; +- kb.length = keylen; +- kb.contents = (uint8_t *)plain.data; +- plain = empty_data(); ++ ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain); ++ if (ret) ++ goto cleanup; ++ ++ /* Make sure the plaintext has at least as many bytes as the true key ++ * length (it may have more due to padding). */ ++ if ((unsigned int)keylen > plain.length) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ if (ret) ++ goto cleanup; + } + ++ kb.magic = KV5M_KEYBLOCK; ++ kb.enctype = kd->key_data_type[0]; ++ kb.length = keylen; ++ kb.contents = (uint8_t *)plain.data; ++ plain = empty_data(); ++ + /* Decode salt data. */ + if (keysalt_out != NULL) { + if (kd->key_data_ver == 2) { +diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c +index 98d601c8ab..4f1d2911b0 100644 +--- a/src/lib/rpc/svc_auth_gss.c ++++ b/src/lib/rpc/svc_auth_gss.c +@@ -297,7 +297,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + struct opaque_auth *oa; + gss_buffer_desc rpcbuf, checksum; + OM_uint32 maj_stat, min_stat, qop_state; +- u_char rpchdr[128]; ++ u_char rpchdr[32 + MAX_AUTH_BYTES]; + int32_t *buf; + + log_debug("in svcauth_gss_validate()"); +@@ -315,6 +315,8 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + return (FALSE); + + buf = (int32_t *)(void *)rpchdr; ++ ++ /* Write the 32 first bytes of the header. */ + IXDR_PUT_LONG(buf, msg->rm_xid); + IXDR_PUT_ENUM(buf, msg->rm_direction); + IXDR_PUT_LONG(buf, msg->rm_call.cb_rpcvers); +@@ -323,6 +325,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + IXDR_PUT_LONG(buf, msg->rm_call.cb_proc); + IXDR_PUT_ENUM(buf, oa->oa_flavor); + IXDR_PUT_LONG(buf, oa->oa_length); ++ + if (oa->oa_length) { + memcpy((caddr_t)buf, oa->oa_base, oa->oa_length); + buf += RNDUP(oa->oa_length) / sizeof(int32_t); +diff --git a/src/lib/rpc/svc_udp.c b/src/lib/rpc/svc_udp.c +index 8ecbdf2b33..3aff277eb7 100644 +--- a/src/lib/rpc/svc_udp.c ++++ b/src/lib/rpc/svc_udp.c +@@ -248,8 +248,9 @@ static bool_t svcudp_reply( + { + struct svcudp_data *su = su_data(xprt); + XDR *xdrs = &su->su_xdrs; +- int slen; ++ u_int slen; + bool_t stat = FALSE; ++ ssize_t r; + + xdrproc_t xdr_results = NULL; + caddr_t xdr_location = 0; +@@ -272,12 +273,12 @@ static bool_t svcudp_reply( + if (xdr_replymsg(xdrs, msg) && + (!has_args || + (SVCAUTH_WRAP(xprt->xp_auth, xdrs, xdr_results, xdr_location)))) { +- slen = (int)XDR_GETPOS(xdrs); +- if (sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0, +- (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen) +- == slen) { ++ slen = XDR_GETPOS(xdrs); ++ r = sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0, ++ (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen); ++ if (r >= 0 && (u_int)r == slen) { + stat = TRUE; +- if (su->su_cache && slen >= 0) { ++ if (su->su_cache) { + cache_set(xprt, (uint32_t) slen); + } + } +diff --git a/src/util/support/threads.c b/src/util/support/threads.c +index be7e4c2e3f..4ded805b79 100644 +--- a/src/util/support/threads.c ++++ b/src/util/support/threads.c +@@ -118,7 +118,6 @@ struct tsd_block { + # pragma weak pthread_mutex_destroy + # pragma weak pthread_mutex_init + # pragma weak pthread_self +-# pragma weak pthread_equal + # pragma weak pthread_getspecific + # pragma weak pthread_setspecific + # pragma weak pthread_key_create +@@ -151,7 +150,6 @@ int krb5int_pthread_loaded (void) + || &pthread_mutex_destroy == 0 + || &pthread_mutex_init == 0 + || &pthread_self == 0 +- || &pthread_equal == 0 + /* Any program that's really multithreaded will have to be + able to create threads. */ + || &pthread_create == 0 +-- +2.46.0 + diff --git a/0025-Generate-and-verify-message-MACs-in-libkrad.patch b/0025-Generate-and-verify-message-MACs-in-libkrad.patch new file mode 100644 index 0000000..58c9352 --- /dev/null +++ b/0025-Generate-and-verify-message-MACs-in-libkrad.patch @@ -0,0 +1,629 @@ +From ea02fd7bb79861b8e36517c7c95af821a16657c4 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 22 Aug 2024 17:15:50 +0200 +Subject: [PATCH] Generate and verify message MACs in libkrad + +Implement some of the measures specified in +draft-ietf-radext-deprecating-radius-03 for mitigating the BlastRADIUS +attack (CVE-2024-3596): + +* Include a Message-Authenticator MAC as the first attribute when + generating a packet of type Access-Request, Access-Reject, + Access-Accept, or Access-Challenge (sections 5.2.1 and 5.2.4), if + the secret is non-empty. (An empty secret indicates the use of Unix + domain socket transport.) + +* Validate the Message-Authenticator MAC in received packets, if + present. + +FreeRADIUS enforces Message-Authenticator as of versions 3.2.5 and +3.0.27. libkrad must generate Message-Authenticator attributes in +order to remain compatible with these implementations. + +[ghudson@mit.edu: adjusted style and naming; simplified some +functions; edited commit message] + +ticket: 9142 (new) +tags: pullup +target_version: 1.21-next + +(cherry picked from commit 871125fea8ce0370a972bf65f7d1de63f619b06c) +--- + src/include/k5-int.h | 5 + + src/lib/crypto/krb/checksum_hmac_md5.c | 28 ++++ + src/lib/crypto/libk5crypto.exports | 1 + + src/lib/krad/attr.c | 17 ++ + src/lib/krad/attrset.c | 59 +++++-- + src/lib/krad/internal.h | 7 +- + src/lib/krad/packet.c | 206 +++++++++++++++++++++++-- + src/lib/krad/t_attrset.c | 2 +- + src/lib/krad/t_daemon.py | 3 +- + src/lib/krad/t_packet.c | 11 ++ + src/tests/t_otp.py | 3 + + 11 files changed, 311 insertions(+), 31 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 69d6a6f569..b7789a2dd8 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2403,4 +2403,9 @@ krb5_boolean + k5_sname_compare(krb5_context context, krb5_const_principal sname, + krb5_const_principal princ); + ++/* Generate an HMAC-MD5 keyed checksum as specified by RFC 2104. */ ++krb5_error_code ++k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output); ++ + #endif /* _KRB5_INT_H */ +diff --git a/src/lib/crypto/krb/checksum_hmac_md5.c b/src/lib/crypto/krb/checksum_hmac_md5.c +index ec024f3966..a809388549 100644 +--- a/src/lib/crypto/krb/checksum_hmac_md5.c ++++ b/src/lib/crypto/krb/checksum_hmac_md5.c +@@ -92,3 +92,31 @@ cleanup: + free(hash_iov); + return ret; + } ++ ++krb5_error_code ++k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output) ++{ ++ krb5_error_code ret; ++ const struct krb5_hash_provider *hash = &krb5int_hash_md5; ++ krb5_keyblock keyblock = { 0 }; ++ krb5_data hashed_key; ++ uint8_t hkeybuf[16]; ++ krb5_crypto_iov iov; ++ ++ /* Hash the key if it is longer than the block size. */ ++ if (key->length > hash->blocksize) { ++ hashed_key = make_data(hkeybuf, sizeof(hkeybuf)); ++ iov.flags = KRB5_CRYPTO_TYPE_DATA; ++ iov.data = *key; ++ ret = hash->hash(&iov, 1, &hashed_key); ++ if (ret) ++ return ret; ++ key = &hashed_key; ++ } ++ ++ keyblock.magic = KV5M_KEYBLOCK; ++ keyblock.length = key->length; ++ keyblock.contents = (uint8_t *)key->data; ++ return krb5int_hmac_keyblock(hash, &keyblock, data, num_data, output); ++} +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index d8ffa63304..00e0ce1812 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -102,3 +102,4 @@ krb5_c_prfplus + krb5_c_derive_prfplus + k5_enctype_to_ssf + krb5int_c_deprecated_enctype ++k5_hmac_md5 +diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c +index 42d354a3b5..65ed1d35e7 100644 +--- a/src/lib/krad/attr.c ++++ b/src/lib/krad/attr.c +@@ -125,6 +125,23 @@ static const attribute_record attributes[UCHAR_MAX] = { + {"NAS-Port-Type", 4, 4, NULL, NULL}, + {"Port-Limit", 4, 4, NULL, NULL}, + {"Login-LAT-Port", 1, MAX_ATTRSIZE, NULL, NULL}, ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Password-Retry */ ++ {NULL, 0, 0, NULL, NULL}, /* Prompt */ ++ {NULL, 0, 0, NULL, NULL}, /* Connect-Info */ ++ {NULL, 0, 0, NULL, NULL}, /* Configuration-Token */ ++ {NULL, 0, 0, NULL, NULL}, /* EAP-Message */ ++ {"Message-Authenticator", MD5_DIGEST_SIZE, MD5_DIGEST_SIZE, NULL, NULL}, + }; + + /* Encode User-Password attribute. */ +diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c +index 6ec031e320..e5457ebfd7 100644 +--- a/src/lib/krad/attrset.c ++++ b/src/lib/krad/attrset.c +@@ -164,15 +164,44 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy) + return 0; + } + ++/* Place an encoded attributes into outbuf at position *i. Increment *i by the ++ * length of the encoding. */ ++static krb5_error_code ++append_attr(krb5_context ctx, const char *secret, ++ const uint8_t *auth, krad_attr type, const krb5_data *data, ++ uint8_t outbuf[MAX_ATTRSETSIZE], size_t *i, krb5_boolean *is_fips) ++{ ++ uint8_t buffer[MAX_ATTRSIZE]; ++ size_t attrlen; ++ krb5_error_code retval; ++ ++ retval = kr_attr_encode(ctx, secret, auth, type, data, buffer, &attrlen, ++ is_fips); ++ if (retval) ++ return retval; ++ ++ if (attrlen > MAX_ATTRSETSIZE - *i - 2) ++ return EMSGSIZE; ++ ++ outbuf[(*i)++] = type; ++ outbuf[(*i)++] = attrlen + 2; ++ memcpy(outbuf + *i, buffer, attrlen); ++ *i += attrlen; ++ ++ return 0; ++} ++ + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, +- const unsigned char *auth, ++ const uint8_t *auth, krb5_boolean add_msgauth, + unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, + krb5_boolean *is_fips) + { +- unsigned char buffer[MAX_ATTRSIZE]; + krb5_error_code retval; +- size_t i = 0, attrlen; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const uint8_t zeroes[MD5_DIGEST_SIZE] = { 0 }; ++ krb5_data zerodata; ++ size_t i = 0; + attr *a; + + if (set == NULL) { +@@ -180,19 +209,21 @@ kr_attrset_encode(const krad_attrset *set, const char *secret, + return 0; + } + +- K5_TAILQ_FOREACH(a, &set->list, list) { +- retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr, +- buffer, &attrlen, is_fips); +- if (retval != 0) ++ if (add_msgauth) { ++ /* Encode Message-Authenticator as the first attribute, per ++ * draft-ietf-radext-deprecating-radius-03 section 5.2. */ ++ zerodata = make_data((uint8_t *)zeroes, MD5_DIGEST_SIZE); ++ retval = append_attr(set->ctx, secret, auth, msgauth_type, &zerodata, ++ outbuf, &i, is_fips); ++ if (retval) + return retval; ++ } + +- if (i + attrlen + 2 > MAX_ATTRSETSIZE) +- return EMSGSIZE; +- +- outbuf[i++] = a->type; +- outbuf[i++] = attrlen + 2; +- memcpy(&outbuf[i], buffer, attrlen); +- i += attrlen; ++ K5_TAILQ_FOREACH(a, &set->list, list) { ++ retval = append_attr(set->ctx, secret, auth, a->type, &a->attr, ++ outbuf, &i, is_fips); ++ if (retval) ++ return retval; + } + + *outlen = i; +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index a17b6f39b1..ca66f3ec68 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -49,6 +49,8 @@ + #define UCHAR_MAX 255 + #endif + ++#define MD5_DIGEST_SIZE 16 ++ + /* RFC 2865 */ + #define MAX_ATTRSIZE (UCHAR_MAX - 2) + #define MAX_ATTRSETSIZE (KRAD_PACKET_SIZE_MAX - 20) +@@ -79,10 +81,11 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + krad_attr type, const krb5_data *in, + unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); + +-/* Encode the attributes into the buffer. */ ++/* Encode set into outbuf. If add_msgauth is true, include a zeroed ++ * Message-Authenticator as the first attribute. */ + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, +- const unsigned char *auth, ++ const uint8_t *auth, krb5_boolean add_msgauth, + unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, + krb5_boolean *is_fips); + +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index c5446b890c..3c1a4d507e 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -36,6 +36,7 @@ + typedef unsigned char uchar; + + /* RFC 2865 */ ++#define MSGAUTH_SIZE (2 + MD5_DIGEST_SIZE) + #define OFFSET_CODE 0 + #define OFFSET_ID 1 + #define OFFSET_LENGTH 2 +@@ -222,6 +223,106 @@ packet_set_attrset(krb5_context ctx, const char *secret, krad_packet *pkt) + return kr_attrset_decode(ctx, &tmp, secret, pkt_auth(pkt), &pkt->attrset); + } + ++/* Determine if a packet requires a Message-Authenticator attribute. */ ++static inline krb5_boolean ++requires_msgauth(const char *secret, krad_code code) ++{ ++ /* If no secret is provided, assume that the transport is a UNIX socket. ++ * Message-Authenticator is required only on UDP and TCP connections. */ ++ if (*secret == '\0') ++ return FALSE; ++ ++ /* ++ * Per draft-ietf-radext-deprecating-radius-03 sections 5.2.1 and 5.2.4, ++ * Message-Authenticator is required in Access-Request packets and all ++ * potential responses when UDP or TCP transport is used. ++ */ ++ return code == krad_code_name2num("Access-Request") || ++ code == krad_code_name2num("Access-Reject") || ++ code == krad_code_name2num("Access-Accept") || ++ code == krad_code_name2num("Access-Challenge"); ++} ++ ++/* Check if the packet has a Message-Authenticator attribute. */ ++static inline krb5_boolean ++has_pkt_msgauth(const krad_packet *pkt) ++{ ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ ++ return krad_attrset_get(pkt->attrset, msgauth_type, 0) != NULL; ++} ++ ++/* Return the beginning of the Message-Authenticator attribute in pkt, or NULL ++ * if no such attribute is present. */ ++static const uint8_t * ++lookup_msgauth_addr(const krad_packet *pkt) ++{ ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ size_t i; ++ uint8_t *p; ++ ++ i = OFFSET_ATTR; ++ while (i + 2 < pkt->pkt.length) { ++ p = (uint8_t *)offset(&pkt->pkt, i); ++ if (msgauth_type == *p) ++ return p; ++ i += p[1]; ++ } ++ ++ return NULL; ++} ++ ++/* ++ * Calculate the message authenticator MAC for pkt as specified in RFC 2869 ++ * section 5.14, placing the result in mac_out. Use the provided authenticator ++ * auth, which may be from pkt or from a corresponding request. ++ */ ++static krb5_error_code ++calculate_mac(const char *secret, const krad_packet *pkt, ++ const uint8_t auth[AUTH_FIELD_SIZE], ++ uint8_t mac_out[MD5_DIGEST_SIZE]) ++{ ++ uint8_t zeroed_msgauth[MSGAUTH_SIZE]; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const uint8_t *msgauth_attr, *msgauth_end, *pkt_end; ++ krb5_crypto_iov input[5]; ++ krb5_data ksecr, mac; ++ ++ msgauth_attr = lookup_msgauth_addr(pkt); ++ if (msgauth_attr == NULL) ++ return EINVAL; ++ msgauth_end = msgauth_attr + MSGAUTH_SIZE; ++ pkt_end = (const uint8_t *)pkt->pkt.data + pkt->pkt.length; ++ ++ /* Read code, id, and length from the packet. */ ++ input[0].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[0].data = make_data(pkt->pkt.data, OFFSET_AUTH); ++ ++ /* Read the provided authenticator. */ ++ input[1].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[1].data = make_data((uint8_t *)auth, AUTH_FIELD_SIZE); ++ ++ /* Read any attributes before Message-Authenticator. */ ++ input[2].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[2].data = make_data(pkt_attr(pkt), msgauth_attr - pkt_attr(pkt)); ++ ++ /* Read Message-Authenticator with the data bytes all set to zero, per RFC ++ * 2869 section 5.14. */ ++ zeroed_msgauth[0] = msgauth_type; ++ zeroed_msgauth[1] = MSGAUTH_SIZE; ++ memset(zeroed_msgauth + 2, 0, MD5_DIGEST_SIZE); ++ input[3].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[3].data = make_data(zeroed_msgauth, MSGAUTH_SIZE); ++ ++ /* Read any attributes after Message-Authenticator. */ ++ input[4].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[4].data = make_data((uint8_t *)msgauth_end, pkt_end - msgauth_end); ++ ++ mac = make_data(mac_out, MD5_DIGEST_SIZE); ++ ksecr = string2data((char *)secret); ++ return k5_hmac_md5(&ksecr, input, 5, &mac); ++} ++ + ssize_t + krad_packet_bytes_needed(const krb5_data *buffer) + { +@@ -255,6 +356,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + krad_packet *pkt; + uchar id; + size_t attrset_len; ++ krb5_boolean msgauth_required; + + pkt = packet_new(); + if (pkt == NULL) { +@@ -274,9 +376,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + if (retval != 0) + goto error; + ++ /* Determine if Message-Authenticator is required. */ ++ msgauth_required = (*secret != '\0' && ++ code == krad_code_name2num("Access-Request")); ++ + /* Encode the attributes. */ +- retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt), +- &attrset_len, &pkt->is_fips); ++ retval = kr_attrset_encode(set, secret, pkt_auth(pkt), msgauth_required, ++ pkt_attr(pkt), &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -285,6 +391,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + pkt_code_set(pkt, code); + pkt_len_set(pkt, pkt->pkt.length); + ++ if (msgauth_required) { ++ /* Calculate and set the Message-Authenticator MAC. */ ++ retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2); ++ if (retval != 0) ++ goto error; ++ } ++ + /* Copy the attrset for future use. */ + retval = packet_set_attrset(ctx, secret, pkt); + if (retval != 0) +@@ -307,14 +420,19 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + krb5_error_code retval; + krad_packet *pkt; + size_t attrset_len; ++ krb5_boolean msgauth_required; + + pkt = packet_new(); + if (pkt == NULL) + return ENOMEM; + ++ /* Determine if Message-Authenticator is required. */ ++ msgauth_required = requires_msgauth(secret, code); ++ + /* Encode the attributes. */ +- retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt), +- &attrset_len, &pkt->is_fips); ++ retval = kr_attrset_encode(set, secret, pkt_auth(request), ++ msgauth_required, pkt_attr(pkt), &attrset_len, ++ &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -330,6 +448,18 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + if (retval != 0) + goto error; + ++ if (msgauth_required) { ++ /* ++ * Calculate and replace the Message-Authenticator MAC. Per RFC 2869 ++ * section 5.14, use the authenticator from the request, not from the ++ * response. ++ */ ++ retval = calculate_mac(secret, pkt, pkt_auth(request), ++ pkt_attr(pkt) + 2); ++ if (retval != 0) ++ goto error; ++ } ++ + /* Copy the attrset for future use. */ + retval = packet_set_attrset(ctx, secret, pkt); + if (retval != 0) +@@ -343,6 +473,34 @@ error: + return retval; + } + ++/* Verify the Message-Authenticator value in pkt, using the provided ++ * authenticator (which may be from pkt or from a corresponding request). */ ++static krb5_error_code ++verify_msgauth(const char *secret, const krad_packet *pkt, ++ const uint8_t auth[AUTH_FIELD_SIZE]) ++{ ++ uint8_t mac[MD5_DIGEST_SIZE]; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const krb5_data *msgauth; ++ krb5_error_code retval; ++ ++ msgauth = krad_packet_get_attr(pkt, msgauth_type, 0); ++ if (msgauth == NULL) ++ return ENODATA; ++ ++ retval = calculate_mac(secret, pkt, auth, mac); ++ if (retval) ++ return retval; ++ ++ if (msgauth->length != MD5_DIGEST_SIZE) ++ return EMSGSIZE; ++ ++ if (k5_bcmp(mac, msgauth->data, MD5_DIGEST_SIZE) != 0) ++ return EBADMSG; ++ ++ return 0; ++} ++ + /* Decode a packet. */ + static krb5_error_code + decode_packet(krb5_context ctx, const char *secret, const krb5_data *buffer, +@@ -394,21 +552,35 @@ krad_packet_decode_request(krb5_context ctx, const char *secret, + krad_packet **reqpkt) + { + const krad_packet *tmp = NULL; ++ krad_packet *req; + krb5_error_code retval; + +- retval = decode_packet(ctx, secret, buffer, reqpkt); +- if (cb != NULL && retval == 0) { ++ retval = decode_packet(ctx, secret, buffer, &req); ++ if (retval) ++ return retval; ++ ++ /* Verify Message-Authenticator if present. */ ++ if (has_pkt_msgauth(req)) { ++ retval = verify_msgauth(secret, req, pkt_auth(req)); ++ if (retval) { ++ krad_packet_free(req); ++ return retval; ++ } ++ } ++ ++ if (cb != NULL) { + for (tmp = (*cb)(data, FALSE); tmp != NULL; tmp = (*cb)(data, FALSE)) { + if (pkt_id_get(*reqpkt) == pkt_id_get(tmp)) + break; + } +- } + +- if (cb != NULL && (retval != 0 || tmp != NULL)) +- (*cb)(data, TRUE); ++ if (tmp != NULL) ++ (*cb)(data, TRUE); ++ } + ++ *reqpkt = req; + *duppkt = tmp; +- return retval; ++ return 0; + } + + krb5_error_code +@@ -435,9 +607,17 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + break; + } + +- /* If the authenticator matches, then the response is valid. */ +- if (memcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) == 0) +- break; ++ /* Verify the response authenticator. */ ++ if (k5_bcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) != 0) ++ continue; ++ ++ /* Verify Message-Authenticator if present. */ ++ if (has_pkt_msgauth(*rsppkt)) { ++ if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0) ++ continue; ++ } ++ ++ break; + } + } + +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 4cdb8b7d8e..f9c66509bd 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -63,7 +63,7 @@ main(void) + noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp)); + + /* Encode attrset. */ +- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len, ++ noerror(kr_attrset_encode(set, "foo", auth, FALSE, buffer, &encode_len, + &is_fips)); + krad_attrset_free(set); + +diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py +index 4a3de079c7..647d4894eb 100755 +--- a/src/lib/krad/t_daemon.py ++++ b/src/lib/krad/t_daemon.py +@@ -40,6 +40,7 @@ DICTIONARY = """ + ATTRIBUTE\tUser-Name\t1\tstring + ATTRIBUTE\tUser-Password\t2\toctets + ATTRIBUTE\tNAS-Identifier\t32\tstring ++ATTRIBUTE\tMessage-Authenticator\t80\toctets + """ + + class TestServer(server.Server): +@@ -52,7 +53,7 @@ class TestServer(server.Server): + if key == "User-Password": + passwd = [pkt.PwDecrypt(x) for x in pkt[key]] + +- reply = self.CreateReplyPacket(pkt) ++ reply = self.CreateReplyPacket(pkt, message_authenticator=True) + if passwd == ['accept']: + reply.code = packet.AccessAccept + else: +diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c +index c22489144f..104b6507a2 100644 +--- a/src/lib/krad/t_packet.c ++++ b/src/lib/krad/t_packet.c +@@ -172,6 +172,9 @@ main(int argc, const char **argv) + krb5_data username, password; + krb5_boolean auth = FALSE; + krb5_context ctx; ++ const krad_packet *dupreq; ++ const krb5_data *encpkt; ++ krad_packet *decreq; + + username = string2data("testUser"); + +@@ -184,9 +187,17 @@ main(int argc, const char **argv) + + password = string2data("accept"); + noerror(make_packet(ctx, &username, &password, &packets[ACCEPT_PACKET])); ++ encpkt = krad_packet_encode(packets[ACCEPT_PACKET]); ++ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL, ++ &dupreq, &decreq)); ++ krad_packet_free(decreq); + + password = string2data("reject"); + noerror(make_packet(ctx, &username, &password, &packets[REJECT_PACKET])); ++ encpkt = krad_packet_encode(packets[REJECT_PACKET]); ++ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL, ++ &dupreq, &decreq)); ++ krad_packet_free(decreq); + + memset(&hints, 0, sizeof(hints)); + hints.ai_family = AF_INET; +diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py +index c3b820a411..dd5cdc5c26 100755 +--- a/src/tests/t_otp.py ++++ b/src/tests/t_otp.py +@@ -49,6 +49,7 @@ ATTRIBUTE User-Name 1 string + ATTRIBUTE User-Password 2 octets + ATTRIBUTE Service-Type 6 integer + ATTRIBUTE NAS-Identifier 32 string ++ATTRIBUTE Message-Authenticator 80 octets + ''' + + class RadiusDaemon(Process): +@@ -97,6 +98,8 @@ class RadiusDaemon(Process): + reply.code = packet.AccessReject + replyq['reply'] = False + ++ reply.add_message_authenticator() ++ + outq.put(replyq) + if addr is None: + sock.send(reply.ReplyPacket()) +-- +2.46.0 + diff --git a/0026-PKINIT-ECDH-support.patch b/0026-PKINIT-ECDH-support.patch new file mode 100644 index 0000000..14c86be --- /dev/null +++ b/0026-PKINIT-ECDH-support.patch @@ -0,0 +1,1027 @@ +From 5af8bb21de29e3b9a0d5b2001fab71ea102f7990 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 12 May 2023 15:38:46 -0400 +Subject: [PATCH] PKINIT ECDH support + +Add support for elliptic curve key exchange to PKINIT (RFC 5349 +section 4). Extend pkinit_dh_min_bits to allow the string values +"P-256", "P-384", and "P-521", using rough finite-field strength +equivalents to rank them relative to the Oakley Diffie-Hellman groups. + +When processing TD-DH-PARAMETERS on the client, only accept the three +Oakley groups or the three supported elliptic curve groups. +Previously we accepted any Diffie-Hellman parameters that passed +EVP_PKEY_param_check()/DH_check() and had equal or better bit strength +to the original proposal. + +ticket: 9095 (new) +(cherry picked from commit 0f870b1bcad960fd5319a3f97aafd7f4a289e2fb) +--- + doc/admin/conf_files/kdc_conf.rst | 7 +- + doc/admin/conf_files/krb5_conf.rst | 7 +- + src/plugins/preauth/pkinit/pkinit.h | 6 +- + src/plugins/preauth/pkinit/pkinit_clnt.c | 17 +- + src/plugins/preauth/pkinit/pkinit_constants.c | 27 + + src/plugins/preauth/pkinit/pkinit_crypto.h | 7 + + .../preauth/pkinit/pkinit_crypto_openssl.c | 470 ++++++++++++------ + .../preauth/pkinit/pkinit_crypto_openssl.h | 4 +- + src/plugins/preauth/pkinit/pkinit_lib.c | 3 - + src/plugins/preauth/pkinit/pkinit_srv.c | 17 +- + src/plugins/preauth/pkinit/pkinit_trace.h | 11 + + src/tests/t_pkinit.py | 12 + + 12 files changed, 405 insertions(+), 183 deletions(-) + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 846c58ed82..fb0593f281 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -768,8 +768,11 @@ For information about the syntax of some of these options, see + be specified multiple times. + + **pkinit_dh_min_bits** +- Specifies the minimum number of bits the KDC is willing to accept +- for a client's Diffie-Hellman key. The default is 2048. ++ Specifies the minimum strength of Diffie-Hellman group the KDC is ++ willing to accept for key exchange. Valid values in order of ++ increasing strength are 1024, 2048, P-256, 4096, P-384, and P-521. ++ The default is 2048. (P-256, P-384, and P-521 are new in release ++ 1.22.) + + **pkinit_allow_upn** + Specifies that the KDC is willing to accept client certificates +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index b7284c47df..dca52e1426 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -1131,9 +1131,10 @@ PKINIT krb5.conf options + option is not recommended. + + **pkinit_dh_min_bits** +- Specifies the size of the Diffie-Hellman key the client will +- attempt to use. The acceptable values are 1024, 2048, and 4096. +- The default is 2048. ++ Specifies the group of the Diffie-Hellman key the client will ++ attempt to use. The acceptable values are 1024, 2048, P-256, ++ 4096, P-384, and P-521. The default is 2048. (P-256, P-384, and ++ P-521 are new in release 1.22.) + + **pkinit_identities** + Specifies the location(s) to be used to find the user's X.509 +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 5ab0f4bc28..7ba7155bb4 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -59,6 +59,10 @@ + + #define PKINIT_DEFAULT_DH_MIN_BITS 2048 + #define PKINIT_DH_MIN_CONFIG_BITS 1024 ++/* Rough finite-field bit strength equivalents for the elliptic curve groups */ ++#define PKINIT_DH_P256_BITS 3072 ++#define PKINIT_DH_P384_BITS 7680 ++#define PKINIT_DH_P521_BITS 15360 + + #define KRB5_CONF_KDCDEFAULTS "kdcdefaults" + #define KRB5_CONF_LIBDEFAULTS "libdefaults" +@@ -101,8 +105,6 @@ static inline void pkiDebug (const char *fmt, ...) { } + #define OCTETDATA_TO_KRB5DATA(octd, k5d) \ + (k5d)->length = (octd)->length; (k5d)->data = (char *)(octd)->data; + +-extern const krb5_data dh_oid; +- + /* + * notes about crypto contexts: + * +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 54e7537600..b08022a214 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -681,7 +681,7 @@ pkinit_client_profile(krb5_context context, + const krb5_data *realm) + { + const char *configured_identity; +- char *eku_string = NULL; ++ char *eku_string = NULL, *minbits = NULL; + + pkiDebug("pkinit_client_profile %p %p %p %p\n", + context, plgctx, reqctx, realm); +@@ -690,17 +690,10 @@ pkinit_client_profile(krb5_context context, + KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING, + reqctx->opts->require_crl_checking, + &reqctx->opts->require_crl_checking); +- pkinit_libdefault_integer(context, realm, +- KRB5_CONF_PKINIT_DH_MIN_BITS, +- reqctx->opts->dh_size, +- &reqctx->opts->dh_size); +- if (reqctx->opts->dh_size != 1024 && reqctx->opts->dh_size != 2048 +- && reqctx->opts->dh_size != 4096) { +- pkiDebug("%s: invalid value (%d) for pkinit_dh_min_bits, " +- "using default value (%d) instead\n", __FUNCTION__, +- reqctx->opts->dh_size, PKINIT_DEFAULT_DH_MIN_BITS); +- reqctx->opts->dh_size = PKINIT_DEFAULT_DH_MIN_BITS; +- } ++ pkinit_libdefault_string(context, realm, KRB5_CONF_PKINIT_DH_MIN_BITS, ++ &minbits); ++ reqctx->opts->dh_size = parse_dh_min_bits(context, minbits); ++ free(minbits); + pkinit_libdefault_string(context, realm, + KRB5_CONF_PKINIT_EKU_CHECKING, + &eku_string); +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 1da482e0b4..10f8688ec2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -320,6 +320,33 @@ static const uint8_t o4096[] = { + 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF + }; + ++/* Named curve prime256v1 (1.2.840.10045.3.1.7) as parameters for RFC 3279 ++ * section 2.3.5 id-ecPublicKey */ ++static const uint8_t p256[] = { ++ 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07 ++}; ++ ++/* Named curve secp384r1 (1.3.132.0.34, from RFC 5480 section 2.1.1.1) as ++ * parameters for RFC 3279 section 2.3.5 id-ecPublicKey */ ++static const uint8_t p384[] = { ++ 0x06, 0x05, 0x2B, 0x81, 0x04, 0x00, 0x22 ++}; ++ ++/* Named curve secp521r1 (1.3.132.0.35, from RFC 5480 section 2.1.1.1) as ++ * parameters for RFC 3279 section 2.3.5 id-ecPublicKey */ ++static const uint8_t p521[] = { ++ 0x06, 0x05, 0x2B, 0x81, 0x04, 0x00, 0x23 ++}; ++ + const krb5_data oakley_1024 = { KV5M_DATA, sizeof(o1024), (char *)o1024 }; + const krb5_data oakley_2048 = { KV5M_DATA, sizeof(o2048), (char *)o2048 }; + const krb5_data oakley_4096 = { KV5M_DATA, sizeof(o4096), (char *)o4096 }; ++const krb5_data ec_p256 = { KV5M_DATA, sizeof(p256), (char *)p256 }; ++const krb5_data ec_p384 = { KV5M_DATA, sizeof(p384), (char *)p384 }; ++const krb5_data ec_p521 = { KV5M_DATA, sizeof(p521), (char *)p521 }; ++ ++/* RFC 3279 section 2.3.3 dhpublicnumber (1.2.840.10046.2.1) */ ++const krb5_data dh_oid = { 0, 7, "\x2A\x86\x48\xce\x3e\x02\x01" }; ++ ++/* RFC 3279 section 2.3.5 id-ecPublicKey (1.2.840.10045.2.1) */ ++const krb5_data ec_oid = { 0, 7, "\x2A\x86\x48\xCE\x3D\x02\x01" }; +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 04199b45a4..fd876e4850 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -568,6 +568,11 @@ extern const krb5_data sha512_id; + extern const krb5_data oakley_1024; + extern const krb5_data oakley_2048; + extern const krb5_data oakley_4096; ++extern const krb5_data ec_p256; ++extern const krb5_data ec_p384; ++extern const krb5_data ec_p521; ++extern const krb5_data dh_oid; ++extern const krb5_data ec_oid; + + /** + * An ordered set of OIDs, stored as krb5_data, of KDF algorithms +@@ -590,4 +595,6 @@ crypto_req_cert_matching_data(krb5_context context, + pkinit_req_crypto_context reqctx, + pkinit_cert_matching_data **md_out); + ++int parse_dh_min_bits(krb5_context context, const char *str); ++ + #endif /* _PKINIT_CRYPTO_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 26fa9184b3..f6d494bd11 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -181,6 +181,15 @@ compat_get0_DH(const EVP_PKEY *pkey) + + } + ++#define EVP_PKEY_get0_EC_KEY compat_get0_EC ++static EC_KEY * ++compat_get0_EC(const EVP_PKEY *pkey) ++{ ++ if (pkey->type != EVP_PKEY_EC) ++ return NULL; ++ return pkey->pkey.ec; ++} ++ + /* Return true if the cert c includes a key usage which doesn't include u. + * Define using direct member access for pre-1.1. */ + #define ku_reject(c, u) \ +@@ -260,37 +269,11 @@ decode_bn_der(const uint8_t *der, size_t len) + return bn; + } + +-#if OPENSSL_VERSION_NUMBER >= 0x10100000L +-static int +-params_valid(EVP_PKEY *params) +-{ +- EVP_PKEY_CTX *ctx; +- int result; +- +- ctx = EVP_PKEY_CTX_new(params, NULL); +- if (ctx == NULL) +- return 0; +- result = EVP_PKEY_param_check(ctx); +- EVP_PKEY_CTX_free(ctx); +- return result == 1; +-} +-#else +-static int +-params_valid(EVP_PKEY *params) +-{ +- DH *dh; +- int codes; +- +- dh = EVP_PKEY_get0_DH(params); +- return (dh == NULL) ? 0 : (DH_check(dh, &codes) && codes == 0); +-} +-#endif +- + #if OPENSSL_VERSION_NUMBER >= 0x10100000L + + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + static EVP_PKEY * +-decode_dh_params(const krb5_data *params_der) ++decode_params(const krb5_data *params_der, const char *type) + { + EVP_PKEY *pkey = NULL; + const uint8_t *inptr = (uint8_t *)params_der->data; +@@ -298,7 +281,7 @@ decode_dh_params(const krb5_data *params_der) + OSSL_DECODER_CTX *dctx; + int ok; + +- dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, "DER", "type-specific", "DHX", ++ dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, "DER", "type-specific", type, + EVP_PKEY_KEY_PARAMETERS, NULL, NULL); + if (dctx == NULL) + return NULL; +@@ -307,7 +290,15 @@ decode_dh_params(const krb5_data *params_der) + OSSL_DECODER_CTX_free(dctx); + return ok ? pkey : NULL; + } ++ ++static EVP_PKEY * ++decode_dh_params(const krb5_data *params_der) ++{ ++ return decode_params(params_der, "DHX"); ++} ++ + #else ++ + static EVP_PKEY * + decode_dh_params(const krb5_data *params_der) + { +@@ -320,6 +311,7 @@ decode_dh_params(const krb5_data *params_der) + DH_free(dh); + return pkey; + } ++ + #endif + + static krb5_error_code +@@ -520,6 +512,39 @@ cleanup: + + #endif /* OPENSSL_VERSION_NUMBER < 0x10100000L */ + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++static EVP_PKEY * ++decode_ec_params(const krb5_data *params_der) ++{ ++ return decode_params(params_der, "EC"); ++} ++ ++#else /* OPENSSL_VERSION_NUMBER < 0x30000000L */ ++ ++static EVP_PKEY * ++decode_ec_params(const krb5_data *params_der) ++{ ++ const uint8_t *p = (uint8_t *)params_der->data; ++ EC_KEY *eckey; ++ EVP_PKEY *pkey; ++ ++ eckey = d2i_ECParameters(NULL, &p, params_der->length); ++ if (eckey == NULL) ++ return NULL; ++ pkey = EVP_PKEY_new(); ++ if (pkey != NULL) { ++ if (!EVP_PKEY_set1_EC_KEY(pkey, eckey)) { ++ EVP_PKEY_free(pkey); ++ pkey = NULL; ++ } ++ } ++ EC_KEY_free(eckey); ++ return pkey; ++} ++ ++#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ ++ + /* Attempt to specify padded Diffie-Hellman result derivation. Don't error out + * if this fails since we also detect short results and adjust them. */ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L +@@ -551,7 +576,8 @@ dh_result(EVP_PKEY *pkey, EVP_PKEY *peer, + EVP_PKEY_CTX *derive_ctx = NULL; + int ok = 0; + uint8_t *buf = NULL; +- size_t len, dh_size = EVP_PKEY_get_size(pkey); ++ size_t len, result_size; ++ krb5_boolean ecc = (EVP_PKEY_id(pkey) == EVP_PKEY_EC); + + *result_out = NULL; + *len_out = 0; +@@ -561,24 +587,39 @@ dh_result(EVP_PKEY *pkey, EVP_PKEY *peer, + goto cleanup; + if (EVP_PKEY_derive_init(derive_ctx) <= 0) + goto cleanup; +- set_padded_derivation(derive_ctx); ++ if (!ecc) ++ set_padded_derivation(derive_ctx); + if (EVP_PKEY_derive_set_peer(derive_ctx, peer) <= 0) + goto cleanup; + +- buf = malloc(dh_size); ++ if (ecc) { ++ if (EVP_PKEY_derive(derive_ctx, NULL, &result_size) <= 0) ++ goto cleanup; ++ } else { ++ /* ++ * For finite-field Diffie-Hellman we must ensure that the result ++ * matches the key size (normally through padded derivation, but that ++ * isn't supported by OpenSSL 1.0 so we must check). ++ */ ++ result_size = EVP_PKEY_get_size(pkey); ++ } ++ buf = malloc(result_size); + if (buf == NULL) + goto cleanup; +- len = dh_size; ++ len = result_size; + if (EVP_PKEY_derive(derive_ctx, buf, &len) <= 0) + goto cleanup; +- if (len < dh_size) { /* only possible without padded derivation */ +- memmove(buf + (dh_size - len), buf, len); +- memset(buf, 0, dh_size - len); ++ ++ /* If we couldn't specify padded derivation for finite-field DH we may need ++ * to fix up the result by right-shifting it within the buffer. */ ++ if (len < result_size) { ++ memmove(buf + (result_size - len), buf, len); ++ memset(buf, 0, result_size - len); + } + + ok = 1; + *result_out = buf; +- *len_out = dh_size; ++ *len_out = result_size; + buf = NULL; + + cleanup: +@@ -592,13 +633,21 @@ static int + dh_pubkey_der(EVP_PKEY *pkey, uint8_t **pubkey_out, unsigned int *len_out) + { + BIGNUM *pubkey_bn = NULL; +- int len, ok; +- uint8_t *buf; +- +- if (!EVP_PKEY_get_bn_param(pkey, OSSL_PKEY_PARAM_PUB_KEY, &pubkey_bn)) +- return 0; +- ok = encode_bn_der(pubkey_bn, &buf, &len); +- BN_free(pubkey_bn); ++ int len, ok = 0; ++ uint8_t *buf, *outptr; ++ ++ if (EVP_PKEY_id(pkey) == EVP_PKEY_EC) { ++ len = i2d_PublicKey(pkey, NULL); ++ if (len > 0 && (outptr = buf = malloc(len)) != NULL) { ++ (void)i2d_PublicKey(pkey, &outptr); ++ ok = 1; ++ } ++ } else { ++ if (!EVP_PKEY_get_bn_param(pkey, OSSL_PKEY_PARAM_PUB_KEY, &pubkey_bn)) ++ return 0; ++ ok = encode_bn_der(pubkey_bn, &buf, &len); ++ BN_free(pubkey_bn); ++ } + if (ok) { + *pubkey_out = buf; + *len_out = len; +@@ -610,19 +659,33 @@ static int + dh_pubkey_der(EVP_PKEY *pkey, uint8_t **pubkey_out, unsigned int *len_out) + { + const DH *dh; ++ EC_KEY *eckey; /* can be const when OpenSSL 1.0 dropped */ + const BIGNUM *pubkey_bn; +- uint8_t *buf; ++ uint8_t *buf, *outptr; + int len; + + dh = EVP_PKEY_get0_DH(pkey); +- if (dh == NULL) +- return 0; +- DH_get0_key(dh, &pubkey_bn, NULL); +- if (!encode_bn_der(pubkey_bn, &buf, &len)) +- return 0; +- *pubkey_out = buf; +- *len_out = len; +- return 1; ++ if (dh != NULL) { ++ DH_get0_key(dh, &pubkey_bn, NULL); ++ if (!encode_bn_der(pubkey_bn, &buf, &len)) ++ return 0; ++ *pubkey_out = buf; ++ *len_out = len; ++ return 1; ++ } ++ ++ eckey = EVP_PKEY_get0_EC_KEY(pkey); ++ if (eckey != NULL) { ++ len = i2o_ECPublicKey(eckey, NULL); ++ if (len > 0 && (outptr = buf = malloc(len)) != NULL) { ++ (void)i2o_ECPublicKey(eckey, &outptr); ++ *pubkey_out = buf; ++ *len_out = len; ++ return 1; ++ } ++ } ++ ++ return 0; + } + #endif + +@@ -686,17 +749,23 @@ compose_dh_pkey(EVP_PKEY *params, const uint8_t *pubkey_der, size_t der_len) + if (pkey == NULL) + goto cleanup; + +- pubkey_bn = decode_bn_der(pubkey_der, der_len); +- if (pubkey_bn == NULL) +- goto cleanup; +- binlen = EVP_PKEY_get_size(pkey); +- pubkey_bin = malloc(binlen); +- if (pubkey_bin == NULL) +- goto cleanup; +- if (BN_bn2binpad(pubkey_bn, pubkey_bin, binlen) != binlen) +- goto cleanup; +- if (EVP_PKEY_set1_encoded_public_key(pkey, pubkey_bin, binlen) != 1) +- goto cleanup; ++ if (EVP_PKEY_id(params) == EVP_PKEY_EC) { ++ if (d2i_PublicKey(EVP_PKEY_id(params), &pkey, &pubkey_der, ++ der_len) == NULL) ++ goto cleanup; ++ } else { ++ pubkey_bn = decode_bn_der(pubkey_der, der_len); ++ if (pubkey_bn == NULL) ++ goto cleanup; ++ binlen = EVP_PKEY_get_size(pkey); ++ pubkey_bin = malloc(binlen); ++ if (pubkey_bin == NULL) ++ goto cleanup; ++ if (BN_bn2binpad(pubkey_bn, pubkey_bin, binlen) != binlen) ++ goto cleanup; ++ if (EVP_PKEY_set1_encoded_public_key(pkey, pubkey_bin, binlen) != 1) ++ goto cleanup; ++ } + + pkey_ret = pkey; + pkey = NULL; +@@ -741,29 +810,60 @@ static EVP_PKEY * + compose_dh_pkey(EVP_PKEY *params, const uint8_t *pubkey_der, size_t der_len) + { + DH *dhparams, *dh = NULL; +- EVP_PKEY *pkey = NULL; ++ EVP_PKEY *pkey = NULL, *pkey_ret = NULL; + BIGNUM *pubkey_bn = NULL; ++ EC_KEY *params_eckey, *eckey = NULL; ++ const EC_GROUP *group; ++ ++ if (EVP_PKEY_id(params) == EVP_PKEY_EC) { ++ /* We would like to use EVP_PKEY_copy_parameters() and d2i_PublicKey(), ++ * but the latter is broken in OpenSSL 1.1.0-1.1.1a for EC keys. */ ++ params_eckey = EVP_PKEY_get0_EC_KEY(params); ++ if (params_eckey == NULL) ++ goto cleanup; ++ group = EC_KEY_get0_group(params_eckey); ++ eckey = EC_KEY_new(); ++ if (eckey == NULL) ++ goto cleanup; ++ if (!EC_KEY_set_group(eckey, group)) ++ goto cleanup; ++ if (o2i_ECPublicKey(&eckey, &pubkey_der, der_len) == NULL) ++ goto cleanup; ++ pkey = EVP_PKEY_new(); ++ if (pkey == NULL) ++ return NULL; ++ if (!EVP_PKEY_assign(pkey, EVP_PKEY_EC, eckey)) { ++ EVP_PKEY_free(pkey); ++ return NULL; ++ } ++ eckey = NULL; ++ } else { ++ pubkey_bn = decode_bn_der(pubkey_der, der_len); ++ if (pubkey_bn == NULL) ++ goto cleanup; + +- pubkey_bn = decode_bn_der(pubkey_der, der_len); +- if (pubkey_bn == NULL) +- goto cleanup; ++ dhparams = EVP_PKEY_get0_DH(params); ++ if (dhparams == NULL) ++ goto cleanup; ++ dh = dup_dh_params(dhparams); ++ if (dh == NULL) ++ goto cleanup; ++ if (!DH_set0_key(dh, pubkey_bn, NULL)) ++ goto cleanup; ++ pubkey_bn = NULL; + +- dhparams = EVP_PKEY_get0_DH(params); +- if (dhparams == NULL) +- goto cleanup; +- dh = dup_dh_params(dhparams); +- if (dh == NULL) +- goto cleanup; +- if (!DH_set0_key(dh, pubkey_bn, NULL)) +- goto cleanup; +- pubkey_bn = NULL; ++ pkey = dh_to_pkey(&dh); ++ } + +- pkey = dh_to_pkey(&dh); ++ pkey_ret = pkey; ++ pkey = NULL; + + cleanup: + BN_free(pubkey_bn); + DH_free(dh); +- return pkey; ++ EC_KEY_free(eckey); ++ EVP_PKEY_free(pkey); ++ return pkey_ret; + } + + #endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ +@@ -1032,7 +1132,6 @@ pkinit_init_req_crypto(pkinit_req_crypto_context *cryptoctx) + memset(ctx, 0, sizeof(*ctx)); + + ctx->client_pkey = NULL; +- ctx->received_params = NULL; + ctx->received_cert = NULL; + + *cryptoctx = ctx; +@@ -1054,7 +1153,6 @@ pkinit_fini_req_crypto(pkinit_req_crypto_context req_cryptoctx) + + pkiDebug("%s: freeing ctx at %p\n", __FUNCTION__, req_cryptoctx); + EVP_PKEY_free(req_cryptoctx->client_pkey); +- EVP_PKEY_free(req_cryptoctx->received_params); + X509_free(req_cryptoctx->received_cert); + + free(req_cryptoctx); +@@ -1258,9 +1356,9 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx) + + static int + try_import_group(krb5_context context, const krb5_data *params, +- const char *name, EVP_PKEY **pkey_out) ++ const char *name, krb5_boolean ec, EVP_PKEY **pkey_out) + { +- *pkey_out = decode_dh_params(params); ++ *pkey_out = ec ? decode_ec_params(params) : decode_dh_params(params); + if (*pkey_out == NULL) + TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name); + return (*pkey_out != NULL) ? 1 : 0; +@@ -1271,12 +1369,15 @@ pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx) + { + int n = 0; + +- n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", ++ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", FALSE, + &plgctx->dh_1024); +- n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", ++ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", FALSE, + &plgctx->dh_2048); +- n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", ++ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", FALSE, + &plgctx->dh_4096); ++ n += try_import_group(context, &ec_p256, "P-256", TRUE, &plgctx->ec_p256); ++ n += try_import_group(context, &ec_p384, "P-384", TRUE, &plgctx->ec_p384); ++ n += try_import_group(context, &ec_p521, "P-521", TRUE, &plgctx->ec_p521); + + if (n == 0) { + pkinit_fini_dh_params(plgctx); +@@ -1294,7 +1395,11 @@ pkinit_fini_dh_params(pkinit_plg_crypto_context plgctx) + EVP_PKEY_free(plgctx->dh_1024); + EVP_PKEY_free(plgctx->dh_2048); + EVP_PKEY_free(plgctx->dh_4096); ++ EVP_PKEY_free(plgctx->ec_p256); ++ EVP_PKEY_free(plgctx->ec_p384); ++ EVP_PKEY_free(plgctx->ec_p521); + plgctx->dh_1024 = plgctx->dh_2048 = plgctx->dh_4096 = NULL; ++ plgctx->ec_p256 = plgctx->ec_p384 = plgctx->ec_p521 = NULL; + } + + static krb5_error_code +@@ -2711,6 +2816,62 @@ cleanup: + return ret; + } + ++/* Return the equivalent finite-field bit strength of pkey if it matches a ++ * well-known group, or -1 if it doesn't. */ ++static int ++check_dh_wellknown(pkinit_plg_crypto_context cryptoctx, EVP_PKEY *pkey) ++{ ++ int nbits = EVP_PKEY_get_bits(pkey); ++ ++ if (nbits == 1024 && EVP_PKEY_parameters_eq(cryptoctx->dh_1024, pkey) == 1) ++ return nbits; ++ if (nbits == 2048 && EVP_PKEY_parameters_eq(cryptoctx->dh_2048, pkey) == 1) ++ return nbits; ++ if (nbits == 4096 && EVP_PKEY_parameters_eq(cryptoctx->dh_4096, pkey) == 1) ++ return nbits; ++ if (nbits == 256 && EVP_PKEY_parameters_eq(cryptoctx->ec_p256, pkey) == 1) ++ return PKINIT_DH_P256_BITS; ++ if (nbits == 384 && EVP_PKEY_parameters_eq(cryptoctx->ec_p384, pkey) == 1) ++ return PKINIT_DH_P384_BITS; ++ if (nbits == 521 && EVP_PKEY_parameters_eq(cryptoctx->ec_p521, pkey) == 1) ++ return PKINIT_DH_P521_BITS; ++ return -1; ++} ++ ++/* Return a short description of the Diffie-Hellman group with the given ++ * finite-field group size equivalent. */ ++static const char * ++group_desc(int dh_bits) ++{ ++ switch (dh_bits) { ++ case PKINIT_DH_P256_BITS: return "P-256"; ++ case PKINIT_DH_P384_BITS: return "P-384"; ++ case PKINIT_DH_P521_BITS: return "P-521"; ++ case 1024: return "1024-bit DH"; ++ case 2048: return "2048-bit DH"; ++ case 4096: return "4096-bit DH"; ++ } ++ return "(unknown)"; ++} ++ ++static EVP_PKEY * ++choose_dh_group(pkinit_plg_crypto_context plg_cryptoctx, int dh_size) ++{ ++ if (dh_size == 1024) ++ return plg_cryptoctx->dh_1024; ++ if (dh_size == 2048) ++ return plg_cryptoctx->dh_2048; ++ if (dh_size == 4096) ++ return plg_cryptoctx->dh_4096; ++ if (dh_size == PKINIT_DH_P256_BITS) ++ return plg_cryptoctx->ec_p256; ++ if (dh_size == PKINIT_DH_P384_BITS) ++ return plg_cryptoctx->ec_p384; ++ if (dh_size == PKINIT_DH_P521_BITS) ++ return plg_cryptoctx->ec_p521; ++ return NULL; ++} ++ + krb5_error_code + client_create_dh(krb5_context context, + pkinit_plg_crypto_context plg_cryptoctx, +@@ -2723,16 +2884,10 @@ client_create_dh(krb5_context context, + + *spki_out = empty_data(); + +- if (cryptoctx->received_params != NULL) +- params = cryptoctx->received_params; +- else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024) +- params = plg_cryptoctx->dh_1024; +- else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048) +- params = plg_cryptoctx->dh_2048; +- else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096) +- params = plg_cryptoctx->dh_4096; +- else ++ params = choose_dh_group(plg_cryptoctx, dh_size); ++ if (params == NULL) + goto cleanup; ++ TRACE_PKINIT_DH_PROPOSING_GROUP(context, group_desc(dh_size)); + + pkey = generate_dh_pkey(params); + if (pkey == NULL) +@@ -2772,8 +2927,11 @@ client_process_dh(krb5_context context, + server_pkey = compose_dh_pkey(cryptoctx->client_pkey, + subjectPublicKey_data, + subjectPublicKey_length); +- if (server_pkey == NULL) ++ if (server_pkey == NULL) { ++ retval = KRB5_PREAUTH_FAILED; ++ k5_setmsg(context, retval, _("Cannot compose PKINIT KDC public key")); + goto cleanup; ++ } + + if (!dh_result(cryptoctx->client_pkey, server_pkey, + &client_key, &client_key_len)) +@@ -2797,20 +2955,6 @@ cleanup: + return retval; + } + +-/* Return 1 if dh is a permitted well-known group, otherwise return 0. */ +-static int +-check_dh_wellknown(pkinit_plg_crypto_context cryptoctx, EVP_PKEY *pkey, +- int nbits) +-{ +- if (nbits == 1024) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_1024, pkey) == 1; +- else if (nbits == 2048) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_2048, pkey) == 1; +- else if (nbits == 4096) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_4096, pkey) == 1; +- return 0; +-} +- + krb5_error_code + server_check_dh(krb5_context context, + pkinit_plg_crypto_context cryptoctx, +@@ -2820,7 +2964,7 @@ server_check_dh(krb5_context context, + int minbits) + { + EVP_PKEY *client_pkey = NULL; +- int dh_prime_bits; ++ int dh_bits; + krb5_error_code retval = KRB5KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED; + + client_pkey = decode_spki(client_spki); +@@ -2829,16 +2973,15 @@ server_check_dh(krb5_context context, + goto cleanup; + } + +- /* KDC SHOULD check to see if the key parameters satisfy its policy */ +- dh_prime_bits = EVP_PKEY_get_bits(client_pkey); +- if (minbits && dh_prime_bits < minbits) { +- pkiDebug("client sent dh params with %d bits, we require %d\n", +- dh_prime_bits, minbits); ++ dh_bits = check_dh_wellknown(cryptoctx, client_pkey); ++ if (dh_bits == -1 || dh_bits < minbits) { ++ TRACE_PKINIT_DH_REJECTING_GROUP(context, group_desc(dh_bits), ++ group_desc(minbits)); + goto cleanup; + } ++ TRACE_PKINIT_DH_RECEIVED_GROUP(context, group_desc(dh_bits)); + +- if (check_dh_wellknown(cryptoctx, client_pkey, dh_prime_bits)) +- retval = 0; ++ retval = 0; + + cleanup: + if (retval == 0) +@@ -3023,9 +3166,20 @@ pkinit_create_td_dh_parameters(krb5_context context, + krb5_algorithm_identifier alg_1024 = { dh_oid, oakley_1024 }; + krb5_algorithm_identifier alg_2048 = { dh_oid, oakley_2048 }; + krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 }; +- krb5_algorithm_identifier *alglist[4]; ++ krb5_algorithm_identifier alg_p256 = { ec_oid, ec_p256 }; ++ krb5_algorithm_identifier alg_p384 = { ec_oid, ec_p384 }; ++ krb5_algorithm_identifier alg_p521 = { ec_oid, ec_p521 }; ++ krb5_algorithm_identifier *alglist[7]; + + i = 0; ++ if (plg_cryptoctx->ec_p256 != NULL && ++ opts->dh_min_bits <= PKINIT_DH_P256_BITS) ++ alglist[i++] = &alg_p256; ++ if (plg_cryptoctx->ec_p384 != NULL && ++ opts->dh_min_bits <= PKINIT_DH_P384_BITS) ++ alglist[i++] = &alg_p384; ++ if (plg_cryptoctx->ec_p521 != NULL) ++ alglist[i++] = &alg_p521; + if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048) + alglist[i++] = &alg_2048; + if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096) +@@ -3110,13 +3264,10 @@ pkinit_process_td_dh_params(krb5_context context, + { + krb5_error_code retval = KRB5KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED; + EVP_PKEY *params = NULL; +- int i, dh_prime_bits, old_dh_size; ++ int i, dh_bits, old_dh_size; + + pkiDebug("dh parameters\n"); + +- EVP_PKEY_free(req_cryptoctx->received_params); +- req_cryptoctx->received_params = NULL; +- + old_dh_size = *new_dh_size; + + for (i = 0; algId[i] != NULL; i++) { +@@ -3124,36 +3275,22 @@ pkinit_process_td_dh_params(krb5_context context, + EVP_PKEY_free(params); + params = NULL; + +- /* Skip any parameters for algorithms other than DH. */ +- if (algId[i]->algorithm.length != dh_oid.length || +- memcmp(algId[i]->algorithm.data, dh_oid.data, dh_oid.length)) +- continue; +- +- params = decode_dh_params(&algId[i]->parameters); ++ if (data_eq(algId[i]->algorithm, dh_oid)) ++ params = decode_dh_params(&algId[i]->parameters); ++ else if (data_eq(algId[i]->algorithm, ec_oid)) ++ params = decode_ec_params(&algId[i]->parameters); + if (params == NULL) + continue; +- dh_prime_bits = EVP_PKEY_get_bits(params); +- /* Skip any parameters shorter than the previous size. */ +- if (dh_prime_bits < old_dh_size) +- continue; +- pkiDebug("client sent %d DH bits server prefers %d DH bits\n", +- *new_dh_size, dh_prime_bits); + +- /* If this is one of our well-known groups, just save the new size; we +- * will use our own copy of the parameters. */ +- if (check_dh_wellknown(cryptoctx, params, dh_prime_bits)) { +- *new_dh_size = dh_prime_bits; +- retval = 0; +- goto cleanup; +- } ++ dh_bits = check_dh_wellknown(cryptoctx, params); ++ /* Skip any parameters shorter than the previous size or unknown. */ ++ if (dh_bits == -1 || dh_bits < old_dh_size) ++ continue; ++ TRACE_PKINIT_DH_NEGOTIATED_GROUP(context, group_desc(dh_bits)); + +- /* If the parameters aren't well-known but check out, save them. */ +- if (params_valid(params)) { +- req_cryptoctx->received_params = params; +- params = NULL; +- retval = 0; +- goto cleanup; +- } ++ *new_dh_size = dh_bits; ++ retval = 0; ++ goto cleanup; + } + + cleanup: +@@ -5329,3 +5466,40 @@ crypto_req_cert_matching_data(krb5_context context, + return get_matching_data(context, plgctx, reqctx, reqctx->received_cert, + md_out); + } ++ ++/* ++ * Historically, the strength of PKINIT key exchange has been determined by the ++ * pkinit_dh_min_bits variable, which gives a finite field size. With the ++ * addition of ECDH support, we allow the string values P-256, P-384, and P-521 ++ * for this config variable, represented with the rough equivalent bit ++ * strengths for finite fields. ++ */ ++int ++parse_dh_min_bits(krb5_context context, const char *str) ++{ ++ char *endptr; ++ long n; ++ ++ if (str == NULL) ++ return PKINIT_DEFAULT_DH_MIN_BITS; ++ ++ n = strtol(str, &endptr, 0); ++ if (endptr == str) { ++ if (strcasecmp(str, "P-256") == 0) ++ return PKINIT_DH_P256_BITS; ++ else if (strcasecmp(str, "P-384") == 0) ++ return PKINIT_DH_P384_BITS; ++ else if (strcasecmp(str, "P-521") == 0) ++ return PKINIT_DH_P521_BITS; ++ } else { ++ if (n == 1024) ++ return 1024; ++ else if (n > 1024 && n <= 2048) ++ return 2048; ++ else if (n > 2048 && n <= 4096) ++ return 4096; ++ } ++ ++ TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str); ++ return PKINIT_DEFAULT_DH_MIN_BITS; ++} +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +index c807f044ac..b7a3358800 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +@@ -99,6 +99,9 @@ struct _pkinit_plg_crypto_context { + EVP_PKEY *dh_1024; + EVP_PKEY *dh_2048; + EVP_PKEY *dh_4096; ++ EVP_PKEY *ec_p256; ++ EVP_PKEY *ec_p384; ++ EVP_PKEY *ec_p521; + ASN1_OBJECT *id_pkinit_authData; + ASN1_OBJECT *id_pkinit_DHKeyData; + ASN1_OBJECT *id_pkinit_rkeyData; +@@ -113,7 +116,6 @@ struct _pkinit_plg_crypto_context { + struct _pkinit_req_crypto_context { + X509 *received_cert; + EVP_PKEY *client_pkey; +- EVP_PKEY *received_params; + }; + + #endif /* _PKINIT_CRYPTO_OPENSSL_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 19db695a4d..25965eb5d2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -33,9 +33,6 @@ + + #define FAKECERT + +-const krb5_data dh_oid = { 0, 7, "\x2A\x86\x48\xce\x3e\x02\x01" }; +- +- + krb5_error_code + pkinit_init_req_opts(pkinit_req_opts **reqopts) + { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index aab21f951c..e22bcb195b 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -988,7 +988,7 @@ static krb5_error_code + pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) + { + krb5_error_code retval; +- char *eku_string = NULL, *ocsp_check = NULL; ++ char *eku_string = NULL, *ocsp_check = NULL, *minbits = NULL; + + pkiDebug("%s: entered for realm %s\n", __FUNCTION__, plgctx->realmname); + retval = pkinit_kdcdefault_string(context, plgctx->realmname, +@@ -1033,17 +1033,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) + goto errout; + } + +- pkinit_kdcdefault_integer(context, plgctx->realmname, +- KRB5_CONF_PKINIT_DH_MIN_BITS, +- PKINIT_DEFAULT_DH_MIN_BITS, +- &plgctx->opts->dh_min_bits); +- if (plgctx->opts->dh_min_bits < PKINIT_DH_MIN_CONFIG_BITS) { +- pkiDebug("%s: invalid value (%d < %d) for pkinit_dh_min_bits, " +- "using default value (%d) instead\n", __FUNCTION__, +- plgctx->opts->dh_min_bits, PKINIT_DH_MIN_CONFIG_BITS, +- PKINIT_DEFAULT_DH_MIN_BITS); +- plgctx->opts->dh_min_bits = PKINIT_DEFAULT_DH_MIN_BITS; +- } ++ pkinit_kdcdefault_string(context, plgctx->realmname, ++ KRB5_CONF_PKINIT_DH_MIN_BITS, &minbits); ++ plgctx->opts->dh_min_bits = parse_dh_min_bits(context, minbits); ++ free(minbits); + + pkinit_kdcdefault_boolean(context, plgctx->realmname, + KRB5_CONF_PKINIT_ALLOW_UPN, +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index d385759145..1c1ceb5a41 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -83,6 +83,17 @@ + + #define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \ + TRACE(c, "PKINIT key exchange group {str} unsupported", name) ++#define TRACE_PKINIT_DH_INVALID_MIN_BITS(c, str) \ ++ TRACE(c, "Invalid pkinit_dh_min_bits value {str}, using default", str) ++#define TRACE_PKINIT_DH_NEGOTIATED_GROUP(c, desc) \ ++ TRACE(c, "PKINIT accepting KDC key exchange group preference {str}", desc) ++#define TRACE_PKINIT_DH_PROPOSING_GROUP(c, desc) \ ++ TRACE(c, "PKINIT using {str} key exchange group", desc) ++#define TRACE_PKINIT_DH_RECEIVED_GROUP(c, desc) \ ++ TRACE(c, "PKINIT received {str} key from client for key exchange", desc) ++#define TRACE_PKINIT_DH_REJECTING_GROUP(c, desc, mindesc) \ ++ TRACE(c, "PKINIT client key has group {str}, need at least {str}", \ ++ desc, mindesc) + + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 62e6c426d3..f8f2debc1b 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -172,6 +172,15 @@ realm.pkinit(realm.user_princ, expected_trace=msgs) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + ++# Test each Diffie-Hellman group except 1024-bit (which doesn't work ++# in OpenSSL 3.0) and the default 2048-bit group. ++for g in ('4096', 'P-256', 'P-384', 'P-521'): ++ mark('Diffie-Hellman group ' + g) ++ group_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': g}}} ++ group_env = realm.special_env(g, True, krb5_conf=group_conf) ++ realm.pkinit(realm.user_princ, expected_trace=('PKINIT using ' + g,), ++ env=group_env) ++ + # Try using multiple configured pkinit_identities, to make sure we + # fall back to the second one when the first one cannot be read. + id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', +@@ -190,11 +199,14 @@ realm.start_kdc(env=minbits_env) + msgs = ('Sending unauthenticated request', + '/Additional pre-authentication required', + 'Preauthenticating using KDC method data', ++ 'PKINIT using 2048-bit DH key exchange group', + 'Preauth module pkinit (16) (real) returned: 0/Success', + ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', + '/Key parameters not accepted', + 'Preauth tryagain input types (16): 109, PA-FX-COOKIE (133)', ++ 'PKINIT accepting KDC key exchange group preference P-384', + 'trying again with KDC-provided parameters', ++ 'PKINIT using P-384 key exchange group', + 'Preauth module pkinit (16) tryagain returned: 0/Success', + ' preauth for next request: PA-PK-AS-REQ (16), PA-FX-COOKIE (133)') + realm.pkinit(realm.user_princ, expected_trace=msgs) +-- +2.47.1 + diff --git a/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch b/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch new file mode 100644 index 0000000..140a2e5 --- /dev/null +++ b/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch @@ -0,0 +1,78 @@ +From 43d10f1580c033fe706470e7588c720ac7854918 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 21 Jun 2023 18:27:11 +0200 +Subject: [PATCH] Add ecdsa-with-sha512/256 to supportedCMSTypes + +Elliptic curve certificates are already supported for PKINIT +pre-authentication, but their associated signature types aren't +advertized. Add ecdsa-with-sha512 and ecdsa-with-sha256 OIDs to the +supportedCMSTypes list sent by the client. + +[ghudson@mit.edu: edited commit message] + +ticket: 9100 (new) +(cherry picked from commit 9913e5c92c4e5cb76d6ae58386f744766d2e6454) +--- + src/plugins/preauth/pkinit/pkinit_constants.c | 38 +++++++++++++++++++ + 1 file changed, 38 insertions(+) + +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 10f8688ec2..905e90d29c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -64,14 +64,52 @@ static char sha512WithRSAEncr_oid[9] = { + 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d + }; + ++/* RFC 3279 ecdsa-with-SHA1: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) 1 */ ++static char ecdsaWithSha1_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x01 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA256: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 2 */ ++static char ecdsaWithSha256_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA384: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 3 */ ++static char ecdsaWithSha384_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x03 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA512: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 4 */ ++static char ecdsaWithSha512_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x04 ++}; ++ + const krb5_data sha256WithRSAEncr_id = { + KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid + }; + const krb5_data sha512WithRSAEncr_id = { + KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid + }; ++const krb5_data ecdsaWithSha1_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha1_oid), ecdsaWithSha1_oid ++}; ++const krb5_data ecdsaWithSha256_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha256_oid), ecdsaWithSha256_oid ++}; ++const krb5_data ecdsaWithSha384_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha384_oid), ecdsaWithSha384_oid ++}; ++const krb5_data ecdsaWithSha512_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha512_oid), ecdsaWithSha512_oid ++}; + + krb5_data const * const supported_cms_algs[] = { ++ &ecdsaWithSha512_id, ++ &ecdsaWithSha256_id, + &sha512WithRSAEncr_id, + &sha256WithRSAEncr_id, + NULL +-- +2.47.1 + diff --git a/0028-Get-rid-of-pkinit_crypto_openssl.h.patch b/0028-Get-rid-of-pkinit_crypto_openssl.h.patch new file mode 100644 index 0000000..993e823 --- /dev/null +++ b/0028-Get-rid-of-pkinit_crypto_openssl.h.patch @@ -0,0 +1,264 @@ +From fba4cbf0bc50569b8ea6d1e1c3303eaab84935e1 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 30 Jul 2023 01:07:38 -0400 +Subject: [PATCH] Get rid of pkinit_crypto_openssl.h + +Fold pkinit_crypto_openssl.h into the one source file where it was +used. Also clean up the include of , as htonl() is no +longer used after commit 1c87ce6c44a9de0824580a2d72a8a202237e01f4. + +(cherry picked from commit b3352945fb8836f8b4095e0b8aad04b54aca3152) +--- + src/plugins/preauth/pkinit/deps | 2 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 85 +++++++++++- + .../preauth/pkinit/pkinit_crypto_openssl.h | 121 ------------------ + 3 files changed, 83 insertions(+), 125 deletions(-) + delete mode 100644 src/plugins/preauth/pkinit/pkinit_crypto_openssl.h + +diff --git a/src/plugins/preauth/pkinit/deps b/src/plugins/preauth/pkinit/deps +index 58320aa801..b6f4476fe8 100644 +--- a/src/plugins/preauth/pkinit/deps ++++ b/src/plugins/preauth/pkinit/deps +@@ -112,4 +112,4 @@ pkinit_crypto_openssl.so pkinit_crypto_openssl.po $(OUTPRE)pkinit_crypto_openssl + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/krb5/preauth_plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + pkcs11.h pkinit.h pkinit_accessor.h pkinit_crypto.h \ +- pkinit_crypto_openssl.c pkinit_crypto_openssl.h pkinit_trace.h ++ pkinit_crypto_openssl.c pkinit_trace.h +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f6d494bd11..ae8599d5a2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -30,20 +30,99 @@ + */ + + #include "k5-int.h" +-#include "pkinit_crypto_openssl.h" + #include "k5-buf.h" + #include "k5-err.h" + #include "k5-hex.h" +-#include ++#include "pkinit.h" + #include +-#include + ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include ++#include + #include + #endif + ++#define DN_BUF_LEN 256 ++#define MAX_CREDS_ALLOWED 20 ++ ++struct _pkinit_cred_info { ++ char *name; ++ X509 *cert; ++ EVP_PKEY *key; ++#ifndef WITHOUT_PKCS11 ++ CK_BYTE_PTR cert_id; ++ int cert_id_len; ++#endif ++}; ++typedef struct _pkinit_cred_info *pkinit_cred_info; ++ ++struct _pkinit_identity_crypto_context { ++ pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; ++ STACK_OF(X509) *my_certs; /* available user certs */ ++ char *identity; /* identity name for user cert */ ++ int cert_index; /* cert to use out of available certs*/ ++ EVP_PKEY *my_key; /* available user keys if in filesystem */ ++ STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ ++ STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ ++ STACK_OF(X509_CRL) *revoked; /* available crls */ ++ int pkcs11_method; ++ krb5_prompter_fct prompter; ++ void *prompter_data; ++#ifndef WITHOUT_PKCS11 ++ char *p11_module_name; ++ CK_SLOT_ID slotid; ++ char *token_label; ++ char *cert_label; ++ /* These are crypto-specific. */ ++ struct plugin_file_handle *p11_module; ++ CK_SESSION_HANDLE session; ++ CK_FUNCTION_LIST_PTR p11; ++ uint8_t *cert_id; ++ size_t cert_id_len; ++ CK_MECHANISM_TYPE mech; ++#endif ++ krb5_boolean defer_id_prompt; ++ pkinit_deferred_id *deferred_ids; ++}; ++ ++struct _pkinit_plg_crypto_context { ++ EVP_PKEY *dh_1024; ++ EVP_PKEY *dh_2048; ++ EVP_PKEY *dh_4096; ++ EVP_PKEY *ec_p256; ++ EVP_PKEY *ec_p384; ++ EVP_PKEY *ec_p521; ++ ASN1_OBJECT *id_pkinit_authData; ++ ASN1_OBJECT *id_pkinit_DHKeyData; ++ ASN1_OBJECT *id_pkinit_rkeyData; ++ ASN1_OBJECT *id_pkinit_san; ++ ASN1_OBJECT *id_ms_san_upn; ++ ASN1_OBJECT *id_pkinit_KPClientAuth; ++ ASN1_OBJECT *id_pkinit_KPKdc; ++ ASN1_OBJECT *id_ms_kp_sc_logon; ++ ASN1_OBJECT *id_kp_serverAuth; ++}; ++ ++struct _pkinit_req_crypto_context { ++ X509 *received_cert; ++ EVP_PKEY *client_pkey; ++}; ++ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +deleted file mode 100644 +index b7a3358800..0000000000 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h ++++ /dev/null +@@ -1,121 +0,0 @@ +-/* +- * COPYRIGHT (C) 2006,2007 +- * THE REGENTS OF THE UNIVERSITY OF MICHIGAN +- * ALL RIGHTS RESERVED +- * +- * Permission is granted to use, copy, create derivative works +- * and redistribute this software and such derivative works +- * for any purpose, so long as the name of The University of +- * Michigan is not used in any advertising or publicity +- * pertaining to the use of distribution of this software +- * without specific, written prior authorization. If the +- * above copyright notice or any other identification of the +- * University of Michigan is included in any copy of any +- * portion of this software, then the disclaimer below must +- * also be included. +- * +- * THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION +- * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY +- * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF +- * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING +- * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF +- * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE +- * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE +- * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR +- * CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING +- * OUT OF OR IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN +- * IF IT HAS BEEN OR IS HEREAFTER ADVISED OF THE POSSIBILITY OF +- * SUCH DAMAGES. +- */ +- +-#ifndef _PKINIT_CRYPTO_OPENSSL_H +-#define _PKINIT_CRYPTO_OPENSSL_H +- +-#include "pkinit.h" +- +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#if OPENSSL_VERSION_NUMBER >= 0x30000000L +-#include +-#include +-#endif +- +-#define DN_BUF_LEN 256 +-#define MAX_CREDS_ALLOWED 20 +- +-struct _pkinit_cred_info { +- char *name; +- X509 *cert; +- EVP_PKEY *key; +-#ifndef WITHOUT_PKCS11 +- CK_BYTE_PTR cert_id; +- int cert_id_len; +-#endif +-}; +-typedef struct _pkinit_cred_info * pkinit_cred_info; +- +-struct _pkinit_identity_crypto_context { +- pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; +- STACK_OF(X509) *my_certs; /* available user certs */ +- char *identity; /* identity name for user cert */ +- int cert_index; /* cert to use out of available certs*/ +- EVP_PKEY *my_key; /* available user keys if in filesystem */ +- STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ +- STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ +- STACK_OF(X509_CRL) *revoked; /* available crls */ +- int pkcs11_method; +- krb5_prompter_fct prompter; +- void *prompter_data; +-#ifndef WITHOUT_PKCS11 +- char *p11_module_name; +- CK_SLOT_ID slotid; +- char *token_label; +- char *cert_label; +- /* These are crypto-specific */ +- struct plugin_file_handle *p11_module; +- CK_SESSION_HANDLE session; +- CK_FUNCTION_LIST_PTR p11; +- uint8_t *cert_id; +- size_t cert_id_len; +- CK_MECHANISM_TYPE mech; +-#endif +- krb5_boolean defer_id_prompt; +- pkinit_deferred_id *deferred_ids; +-}; +- +-struct _pkinit_plg_crypto_context { +- EVP_PKEY *dh_1024; +- EVP_PKEY *dh_2048; +- EVP_PKEY *dh_4096; +- EVP_PKEY *ec_p256; +- EVP_PKEY *ec_p384; +- EVP_PKEY *ec_p521; +- ASN1_OBJECT *id_pkinit_authData; +- ASN1_OBJECT *id_pkinit_DHKeyData; +- ASN1_OBJECT *id_pkinit_rkeyData; +- ASN1_OBJECT *id_pkinit_san; +- ASN1_OBJECT *id_ms_san_upn; +- ASN1_OBJECT *id_pkinit_KPClientAuth; +- ASN1_OBJECT *id_pkinit_KPKdc; +- ASN1_OBJECT *id_ms_kp_sc_logon; +- ASN1_OBJECT *id_kp_serverAuth; +-}; +- +-struct _pkinit_req_crypto_context { +- X509 *received_cert; +- EVP_PKEY *client_pkey; +-}; +- +-#endif /* _PKINIT_CRYPTO_OPENSSL_H */ +-- +2.47.1 + diff --git a/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch b/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch new file mode 100644 index 0000000..a328431 --- /dev/null +++ b/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch @@ -0,0 +1,157 @@ +From 1b01057df4c2223fbf92be44f1e764207208ef03 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 26 Feb 2024 19:03:38 -0500 +Subject: [PATCH] Use SoftHSMv2 for PKCS11 PKINIT tests + +Instead of softpkcs11, use SoftHSMv2 to mock the PKCS11 token for +PKINIT tests. Use pkcs11-tool from OpenSC to initialize the token and +import a certificate and key. SoftHSM does not support PIN-less +tokens (see https://github.com/opendnssec/SoftHSMv2/issues/480) so +remove that test for now. + +(cherry picked from commit 8ab61608236883fdc5c2d43f4bd1ff2094401d19) +--- + .github/workflows/build.yml | 2 +- + src/tests/t_pkinit.py | 82 ++++++++++++++++++++----------------- + 2 files changed, 45 insertions(+), 39 deletions(-) + +diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml +index 68a4788adb..d7ae86b150 100644 +--- a/.github/workflows/build.yml ++++ b/.github/workflows/build.yml +@@ -33,7 +33,7 @@ jobs: + if: startsWith(matrix.os, 'ubuntu') + run: | + sudo apt-get update -qq +- sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh ++ sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh softhsm2 opensc + pip3 install pyrad + - name: Build + env: +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index f8f2debc1b..4435746429 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -1,11 +1,10 @@ + from k5test import * ++import re + + # Skip this test if pkinit wasn't built. + if not pkinit_enabled: + skip_rest('PKINIT tests', 'PKINIT module not built') + +-soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so') +- + # Construct a krb5.conf fragment configuring pkinit. + user_pem = os.path.join(pkinit_certs, 'user.pem') + privkey_pem = os.path.join(pkinit_certs, 'privkey.pem') +@@ -55,9 +54,6 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 + p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 + p12_generic_identity = 'PKCS12:%s' % generic_p12 + p12_enc_identity = 'PKCS12:%s' % user_enc_p12 +-p11_identity = 'PKCS11:' + soft_pkcs11 +-p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 + +- ':slotid=1:token=SoftToken (token)') + + # Start a realm with the test kdb module for the following UPN SAN tests. + realm = K5Realm(kdc_conf=alias_kdc_conf, create_kdb=False, pkinit=True) +@@ -389,53 +385,63 @@ realm.klist(realm.user_princ) + realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'], + expected_code=1, expected_msg='Preauthentication failed while') + +-softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc') +-realm.env['SOFTPKCS11RC'] = softpkcs11rc ++softhsm2 = '/usr/lib/softhsm/libsofthsm2.so' ++if not os.path.exists(softhsm2): ++ skip_rest('PKCS11 tests', 'SoftHSMv2 required') ++pkcs11_tool = which('pkcs11-tool') ++if not pkcs11_tool: ++ skip_rest('PKCS11 tests', 'pkcs11-tool from OpenSC required') ++tool_cmd = [pkcs11_tool, '--module', softhsm2] ++ ++# Prepare a SoftHSM token. ++softhsm2_conf = os.path.join(realm.testdir, 'softhsm2.conf') ++softhsm2_tokens = os.path.join(realm.testdir, 'tokens') ++os.mkdir(softhsm2_tokens) ++realm.env['SOFTHSM2_CONF'] = softhsm2_conf ++with open(softhsm2_conf, 'w') as f: ++ f.write('directories.tokendir = %s\n' % softhsm2_tokens) ++realm.run(tool_cmd + ['--init-token', '--label', 'user', ++ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin']) ++realm.run(tool_cmd + ['-w', user_pem, '-y', 'cert']) ++realm.run(tool_cmd + ['-w', privkey_pem, '-y', 'privkey', ++ '-l', '--pin', 'userpin']) ++ ++# Extract the slot ID generated by SoftHSM. ++out = realm.run(tool_cmd + ['-L']) ++m = re.search(r'slot ID 0x([0-9a-f]+)\n', out) ++if not m: ++ fail('could not extract slot ID from SoftHSM token') ++slot_id = int(m.group(1), 16) ++ ++p11_attr = 'X509_user_identity=PKCS11:' + softhsm2 ++p11_token_identity = ('PKCS11:module_name=%s:slotid=%d:token=user' % ++ (softhsm2, slot_id)) + +-# PKINIT with PKCS11: identity, with no need for a PIN. +-mark('PKCS11 identity, no PIN') +-conf = open(softpkcs11rc, 'w') +-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem)) +-conf.close() +-# Expect to succeed without having to supply any more information. +-realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity]) ++mark('PKCS11 identity, with PIN (prompter)') ++realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin') + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + +-# PKINIT with PKCS11: identity, with a PIN supplied by the prompter. +-mark('PKCS11 identity, with PIN (prompter)') +-os.remove(softpkcs11rc) +-conf = open(softpkcs11rc, 'w') +-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, +- privkey_enc_pem)) +-conf.close() +-# Expect failure if the responder does nothing, and there's no prompter ++mark('PKCS11 identity, unavailable PIN') + realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity, +- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ], +- expected_code=2) +-realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity], +- password='encrypted') +-realm.klist(realm.user_princ) +-realm.run([kvno, realm.host_princ]) ++ '-X', p11_attr, realm.user_princ], expected_code=2) + +-# Supply the wrong PIN. + mark('PKCS11 identity, wrong PIN') + expected_trace = ('PKINIT client has no configured identity; giving up',) + realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity], ++ flags=['-X', p11_attr], + password='wrong', expected_code=1, expected_trace=expected_trace) + + # PKINIT with PKCS11: identity, with a PIN supplied by the responder. +-# Supply the response in raw form. ++# Supply the response in raw form. Expect the PIN_COUNT_LOW flag (1) ++# to be set due to the previous test. + mark('PKCS11 identity, with PIN (responder)') +-realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity, +- '-r', 'pkinit={"%s": "encrypted"}' % p11_token_identity, +- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ]) ++realm.run(['./responder', '-x', 'pkinit={"%s": 1}' % p11_token_identity, ++ '-r', 'pkinit={"%s": "userpin"}' % p11_token_identity, ++ '-X', p11_attr, realm.user_princ]) + # Supply the response through the convenience API. +-realm.run(['./responder', '-X', 'X509_user_identity=%s' % p11_identity, +- '-p', '%s=%s' % (p11_token_identity, 'encrypted'), ++realm.run(['./responder', '-X', p11_attr, ++ '-p', '%s=%s' % (p11_token_identity, 'userpin'), + realm.user_princ]) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) +-- +2.47.1 + diff --git a/0030-Simplify-PKINIT-cert-representation.patch b/0030-Simplify-PKINIT-cert-representation.patch new file mode 100644 index 0000000..1bd8d64 --- /dev/null +++ b/0030-Simplify-PKINIT-cert-representation.patch @@ -0,0 +1,202 @@ +From b0315d30f066c4241fcecc33dd9e4d1c7c28b9d8 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 9 Feb 2024 17:32:40 -0500 +Subject: [PATCH] Simplify PKINIT cert representation + +In the _pkinit_identity_crypto_context structure, the my_certs field +is a stack which only ever contains one cert and is only ever used to +retrieve that one cert. The cert_index field is always 0. Replace +these fields with a my_cert field pointing directly to the X509 +certificate. + +Simplify crypto_cert_select_default() by making it call +crypto_cert_select() with index 0 after verifying the certificate +count. + +(cherry picked from commit f95dfb7908456f9563cee66706216a21df8d791f) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 74 +++++-------------- + 1 file changed, 20 insertions(+), 54 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index ae8599d5a2..da59cb1e02 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -73,10 +73,9 @@ typedef struct _pkinit_cred_info *pkinit_cred_info; + + struct _pkinit_identity_crypto_context { + pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; +- STACK_OF(X509) *my_certs; /* available user certs */ ++ X509 *my_cert; /* selected user or KDC cert */ + char *identity; /* identity name for user cert */ +- int cert_index; /* cert to use out of available certs*/ +- EVP_PKEY *my_key; /* available user keys if in filesystem */ ++ EVP_PKEY *my_key; /* selected cert key if in filesystem */ + STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ + STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ + STACK_OF(X509_CRL) *revoked; /* available crls */ +@@ -1489,8 +1488,7 @@ pkinit_init_certs(pkinit_identity_crypto_context ctx) + + for (i = 0; i < MAX_CREDS_ALLOWED; i++) + ctx->creds[i] = NULL; +- ctx->my_certs = NULL; +- ctx->cert_index = 0; ++ ctx->my_cert = NULL; + ctx->my_key = NULL; + ctx->trustedCAs = NULL; + ctx->intermediateCAs = NULL; +@@ -1506,8 +1504,8 @@ pkinit_fini_certs(pkinit_identity_crypto_context ctx) + if (ctx == NULL) + return; + +- if (ctx->my_certs != NULL) +- sk_X509_pop_free(ctx->my_certs, X509_free); ++ if (ctx->my_cert != NULL) ++ X509_free(ctx->my_cert); + + if (ctx->my_key != NULL) + EVP_PKEY_free(ctx->my_key); +@@ -1696,7 +1694,6 @@ cms_signeddata_create(krb5_context context, + ASN1_OCTET_STRING *digest = NULL; + unsigned int alg_len = 0, digest_len = 0; + unsigned char *y = NULL; +- X509 *cert = NULL; + ASN1_OBJECT *oid = NULL, *oid_copy; + + /* Start creating PKCS7 data. */ +@@ -1715,7 +1712,7 @@ cms_signeddata_create(krb5_context context, + if (oid == NULL) + goto cleanup; + +- if (id_cryptoctx->my_certs != NULL) { ++ if (id_cryptoctx->my_cert != NULL) { + X509_STORE *certstore = NULL; + X509_STORE_CTX *certctx; + STACK_OF(X509) *certstack = NULL; +@@ -1726,8 +1723,6 @@ cms_signeddata_create(krb5_context context, + if ((cert_stack = sk_X509_new_null()) == NULL) + goto cleanup; + +- cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index); +- + certstore = X509_STORE_new(); + if (certstore == NULL) + goto cleanup; +@@ -1736,7 +1731,7 @@ cms_signeddata_create(krb5_context context, + certctx = X509_STORE_CTX_new(); + if (certctx == NULL) + goto cleanup; +- X509_STORE_CTX_init(certctx, certstore, cert, ++ X509_STORE_CTX_init(certctx, certstore, id_cryptoctx->my_cert, + id_cryptoctx->intermediateCAs); + X509_STORE_CTX_trusted_stack(certctx, id_cryptoctx->trustedCAs); + if (!X509_verify_cert(certctx)) { +@@ -1764,13 +1759,13 @@ cms_signeddata_create(krb5_context context, + if (!ASN1_INTEGER_set(p7si->version, 1)) + goto cleanup; + if (!X509_NAME_set(&p7si->issuer_and_serial->issuer, +- X509_get_issuer_name(cert))) ++ X509_get_issuer_name(id_cryptoctx->my_cert))) + goto cleanup; + /* because ASN1_INTEGER_set is used to set a 'long' we will do + * things the ugly way. */ + ASN1_INTEGER_free(p7si->issuer_and_serial->serial); + if (!(p7si->issuer_and_serial->serial = +- ASN1_INTEGER_dup(X509_get_serialNumber(cert)))) ++ ASN1_INTEGER_dup(X509_get_serialNumber(id_cryptoctx->my_cert)))) + goto cleanup; + + /* will not fill-out EVP_PKEY because it's on the smartcard */ +@@ -3311,7 +3306,7 @@ pkinit_check_kdc_pkid(krb5_context context, + PKCS7_ISSUER_AND_SERIAL *is = NULL; + const unsigned char *p = pdid_buf; + int status = 1; +- X509 *kdc_cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index); ++ X509 *kdc_cert = id_cryptoctx->my_cert; + + *valid_kdcPkId = 0; + pkiDebug("found kdcPkId in AS REQ\n"); +@@ -4783,7 +4778,8 @@ cleanup: + } + + /* +- * Set the certificate in idctx->creds[cred_index] as the selected certificate. ++ * Set the certificate in idctx->creds[cred_index] as the selected certificate, ++ * stealing pointers from it. + */ + krb5_error_code + crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx, +@@ -4795,20 +4791,17 @@ crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx, + return ENOENT; + + ci = idctx->creds[cred_index]; +- /* copy the selected cert into our id_cryptoctx */ +- if (idctx->my_certs != NULL) +- sk_X509_pop_free(idctx->my_certs, X509_free); +- idctx->my_certs = sk_X509_new_null(); +- sk_X509_push(idctx->my_certs, ci->cert); +- free(idctx->identity); ++ ++ idctx->my_cert = ci->cert; ++ ci->cert = NULL; ++ + /* hang on to the selected credential name */ ++ free(idctx->identity); + if (ci->name != NULL) + idctx->identity = strdup(ci->name); + else + idctx->identity = NULL; + +- ci->cert = NULL; /* Don't free it twice */ +- idctx->cert_index = 0; + if (idctx->pkcs11_method != 1) { + idctx->my_key = ci->key; + ci->key = NULL; /* Don't free it twice */ +@@ -4837,41 +4830,14 @@ crypto_cert_select_default(krb5_context context, + + retval = crypto_cert_get_count(id_cryptoctx, &cert_count); + if (retval) +- goto errout; ++ return retval; + + if (cert_count != 1) { + TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count); +- retval = EINVAL; +- goto errout; +- } +- /* copy the selected cert into our id_cryptoctx */ +- if (id_cryptoctx->my_certs != NULL) { +- sk_X509_pop_free(id_cryptoctx->my_certs, X509_free); ++ return EINVAL; + } +- id_cryptoctx->my_certs = sk_X509_new_null(); +- sk_X509_push(id_cryptoctx->my_certs, id_cryptoctx->creds[0]->cert); +- id_cryptoctx->creds[0]->cert = NULL; /* Don't free it twice */ +- id_cryptoctx->cert_index = 0; +- /* hang on to the selected credential name */ +- if (id_cryptoctx->creds[0]->name != NULL) +- id_cryptoctx->identity = strdup(id_cryptoctx->creds[0]->name); +- else +- id_cryptoctx->identity = NULL; + +- if (id_cryptoctx->pkcs11_method != 1) { +- id_cryptoctx->my_key = id_cryptoctx->creds[0]->key; +- id_cryptoctx->creds[0]->key = NULL; /* Don't free it twice */ +- } +-#ifndef WITHOUT_PKCS11 +- else { +- id_cryptoctx->cert_id = id_cryptoctx->creds[0]->cert_id; +- id_cryptoctx->creds[0]->cert_id = NULL; /* Don't free it twice */ +- id_cryptoctx->cert_id_len = id_cryptoctx->creds[0]->cert_id_len; +- } +-#endif +- retval = 0; +-errout: +- return retval; ++ return crypto_cert_select(context, id_cryptoctx, 0); + } + + +-- +2.47.1 + diff --git a/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch b/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch new file mode 100644 index 0000000..920a6a8 --- /dev/null +++ b/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch @@ -0,0 +1,1768 @@ +From e7172ce0283b06f5208237535a086424d71d846b Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 21 Feb 2024 15:29:02 -0500 +Subject: [PATCH] Support PKCS11 EC client certs in PKINIT + +Move the digest computation and DigestInfo encoding from +cms_signeddata_create() to pkinit_sign_data_pkcs11(), and +conditionalize the DigestInfo encoding on the key type. Use CKM_ECDSA +instead of CKM_RSA_PKCS for EC keys, and convert the resulting +signature from the PKS11 encoding to the ASN.1 encoding required by +CMS. + +Regenerate the test certificates with an additional EC client cert. +Add test cases for EC client certs with and without PKCS11. + +ticket: 9112 (new) +(cherry picked from commit f745c9a9bd6c0c73b944182173f1ac305d03dc3a) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 319 +++++++++++------- + src/tests/pkinit-certs/ca.pem | 32 +- + src/tests/pkinit-certs/eckey.pem | 5 + + src/tests/pkinit-certs/ecuser.pem | 24 ++ + src/tests/pkinit-certs/generic.p12 | Bin 2469 -> 2560 bytes + src/tests/pkinit-certs/generic.pem | 38 +-- + src/tests/pkinit-certs/kdc.pem | 32 +- + src/tests/pkinit-certs/make-certs.sh | 11 +- + src/tests/pkinit-certs/privkey-enc.pem | 60 ++-- + src/tests/pkinit-certs/privkey.pem | 55 +-- + src/tests/pkinit-certs/user-enc.p12 | Bin 2829 -> 2920 bytes + src/tests/pkinit-certs/user-upn.p12 | Bin 2821 -> 2912 bytes + src/tests/pkinit-certs/user-upn.pem | 32 +- + src/tests/pkinit-certs/user-upn2.p12 | Bin 2805 -> 2896 bytes + src/tests/pkinit-certs/user-upn2.pem | 34 +- + src/tests/pkinit-certs/user-upn3.p12 | Bin 2821 -> 2912 bytes + src/tests/pkinit-certs/user-upn3.pem | 32 +- + src/tests/pkinit-certs/user.p12 | Bin 2829 -> 2920 bytes + src/tests/pkinit-certs/user.pem | 30 +- + src/tests/t_pkinit.py | 20 ++ + 20 files changed, 437 insertions(+), 287 deletions(-) + create mode 100644 src/tests/pkinit-certs/eckey.pem + create mode 100644 src/tests/pkinit-certs/ecuser.pem + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index da59cb1e02..4accfc2664 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -93,7 +93,6 @@ struct _pkinit_identity_crypto_context { + CK_FUNCTION_LIST_PTR p11; + uint8_t *cert_id; + size_t cert_id_len; +- CK_MECHANISM_TYPE mech; + #endif + krb5_boolean defer_id_prompt; + pkinit_deferred_id *deferred_ids; +@@ -283,7 +282,6 @@ compat_get0_EC(const EVP_PKEY *pkey) + #if OPENSSL_VERSION_NUMBER < 0x30000000L + /* OpenSSL 3.0 changes several preferred function names. */ + #define EVP_PKEY_parameters_eq EVP_PKEY_cmp_parameters +-#define EVP_MD_CTX_get0_md EVP_MD_CTX_md + #define EVP_PKEY_get_size EVP_PKEY_size + #define EVP_PKEY_get_bits EVP_PKEY_bits + +@@ -1683,17 +1681,12 @@ cms_signeddata_create(krb5_context context, + STACK_OF(X509) * cert_stack = NULL; + ASN1_OCTET_STRING *digest_attr = NULL; + EVP_MD_CTX *ctx; +- const EVP_MD *md_tmp = NULL; +- unsigned char md_data[EVP_MAX_MD_SIZE], md_data2[EVP_MAX_MD_SIZE]; +- unsigned char *digestInfo_buf = NULL, *abuf = NULL; +- unsigned int md_len, md_len2, alen, digestInfo_len; ++ unsigned char md_data[EVP_MAX_MD_SIZE], *abuf = NULL; ++ unsigned int md_len, alen; + STACK_OF(X509_ATTRIBUTE) * sk; + unsigned char *sig = NULL; + unsigned int sig_len = 0; + X509_ALGOR *alg = NULL; +- ASN1_OCTET_STRING *digest = NULL; +- unsigned int alg_len = 0, digest_len = 0; +- unsigned char *y = NULL; + ASN1_OBJECT *oid = NULL, *oid_copy; + + /* Start creating PKCS7 data. */ +@@ -1795,7 +1788,6 @@ cms_signeddata_create(krb5_context context, + goto cleanup; + EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); + EVP_DigestUpdate(ctx, data, data_len); +- md_tmp = EVP_MD_CTX_get0_md(ctx); + EVP_DigestFinal_ex(ctx, md_data, &md_len); + EVP_MD_CTX_free(ctx); + +@@ -1820,63 +1812,8 @@ cms_signeddata_create(krb5_context context, + if (abuf == NULL) + goto cleanup2; + +-#ifndef WITHOUT_PKCS11 +- /* +- * Some tokens can only do RSAEncryption without a hash. To compute +- * sha256WithRSAEncryption, encode the algorithm ID for the hash +- * function and the hash value into an ASN.1 value of type DigestInfo: +- * DigestInfo ::= SEQUENCE { +- * digestAlgorithm AlgorithmIdentifier, +- * digest OCTET STRING +- * } +- */ +- if (id_cryptoctx->pkcs11_method == 1 && +- id_cryptoctx->mech == CKM_RSA_PKCS) { +- pkiDebug("mech = CKM_RSA_PKCS\n"); +- ctx = EVP_MD_CTX_new(); +- if (ctx == NULL) +- goto cleanup; +- EVP_DigestInit_ex(ctx, md_tmp, NULL); +- EVP_DigestUpdate(ctx, abuf, alen); +- EVP_DigestFinal_ex(ctx, md_data2, &md_len2); +- EVP_MD_CTX_free(ctx); +- +- alg = X509_ALGOR_new(); +- if (alg == NULL) +- goto cleanup2; +- X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha256), V_ASN1_NULL, NULL); +- alg_len = i2d_X509_ALGOR(alg, NULL); +- +- digest = ASN1_OCTET_STRING_new(); +- if (digest == NULL) +- goto cleanup2; +- ASN1_OCTET_STRING_set(digest, md_data2, (int)md_len2); +- digest_len = i2d_ASN1_OCTET_STRING(digest, NULL); +- +- digestInfo_len = ASN1_object_size(1, (int)(alg_len + digest_len), +- V_ASN1_SEQUENCE); +- y = digestInfo_buf = malloc(digestInfo_len); +- if (digestInfo_buf == NULL) +- goto cleanup2; +- ASN1_put_object(&y, 1, (int)(alg_len + digest_len), V_ASN1_SEQUENCE, +- V_ASN1_UNIVERSAL); +- i2d_X509_ALGOR(alg, &y); +- i2d_ASN1_OCTET_STRING(digest, &y); +-#ifdef DEBUG_SIG +- pkiDebug("signing buffer\n"); +- print_buffer(digestInfo_buf, digestInfo_len); +- print_buffer_bin(digestInfo_buf, digestInfo_len, "/tmp/pkcs7_tosign"); +-#endif +- retval = pkinit_sign_data(context, id_cryptoctx, digestInfo_buf, +- digestInfo_len, &sig, &sig_len); +- } else +-#endif +- { +- pkiDebug("mech = %s\n", +- id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA256_RSA_PKCS" : "FS"); +- retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, +- &sig, &sig_len); +- } ++ retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, ++ &sig, &sig_len); + #ifdef DEBUG_SIG + print_buffer(sig, sig_len); + #endif +@@ -1930,14 +1867,6 @@ cms_signeddata_create(krb5_context context, + + cleanup2: + if (p7si) { +-#ifndef WITHOUT_PKCS11 +- if (id_cryptoctx->pkcs11_method == 1 && +- id_cryptoctx->mech == CKM_RSA_PKCS) { +- free(digestInfo_buf); +- if (digest != NULL) +- ASN1_OCTET_STRING_free(digest); +- } +-#endif + if (alg != NULL) + X509_ALGOR_free(alg); + } +@@ -3657,8 +3586,7 @@ cleanup: + * Look for a key that's: + * 1. private + * 2. capable of the specified operation (usually signing or decrypting) +- * 3. RSA (this may be wrong but it's all we can do for now) +- * 4. matches the id of the cert we chose ++ * 3. matches the id of the cert we chose + * + * You must call pkinit_get_certs before calling pkinit_find_private_key + * (that's because we need the ID of the private key) +@@ -3678,7 +3606,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + CK_OBJECT_CLASS cls; + CK_ATTRIBUTE attrs[4]; + CK_ULONG count; +- CK_KEY_TYPE keytype; + unsigned int nattrs = 0; + int r; + #ifdef PKINIT_USE_KEY_USAGE +@@ -3705,12 +3632,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + nattrs++; + #endif + +- keytype = CKK_RSA; +- attrs[nattrs].type = CKA_KEY_TYPE; +- attrs[nattrs].pValue = &keytype; +- attrs[nattrs].ulValueLen = sizeof keytype; +- nattrs++; +- + attrs[nattrs].type = CKA_ID; + attrs[nattrs].pValue = id_cryptoctx->cert_id; + attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len; +@@ -3749,6 +3670,116 @@ pkinit_sign_data_fs(krb5_context context, + } + + #ifndef WITHOUT_PKCS11 ++/* ++ * DER-encode a DigestInfo sequence containing the algorithm md and the digest ++ * mdbytes. ++ * ++ * DigestInfo ::= SEQUENCE { ++ * digestAlgorithm AlgorithmIdentifier, ++ * digest OCTET STRING ++ * } ++ */ ++static krb5_error_code ++encode_digestinfo(krb5_context context, const EVP_MD *md, ++ const uint8_t *mdbytes, size_t mdlen, ++ uint8_t **encoding_out, size_t *len_out) ++{ ++ krb5_boolean ok = FALSE; ++ X509_ALGOR *alg = NULL; ++ ASN1_OCTET_STRING *digest = NULL; ++ uint8_t *buf, *p; ++ int alg_len, digest_len, len; ++ ++ *encoding_out = NULL; ++ *len_out = 0; ++ ++ alg = X509_ALGOR_new(); ++ if (alg == NULL || ++ !X509_ALGOR_set0(alg, OBJ_nid2obj(EVP_MD_nid(md)), V_ASN1_NULL, NULL)) ++ goto cleanup; ++ alg_len = i2d_X509_ALGOR(alg, NULL); ++ if (alg_len < 0) ++ goto cleanup; ++ ++ digest = ASN1_OCTET_STRING_new(); ++ if (digest == NULL || !ASN1_OCTET_STRING_set(digest, mdbytes, mdlen)) ++ goto cleanup; ++ digest_len = i2d_ASN1_OCTET_STRING(digest, NULL); ++ if (digest_len < 0) ++ goto cleanup; ++ ++ len = ASN1_object_size(1, alg_len + digest_len, V_ASN1_SEQUENCE); ++ p = buf = malloc(len); ++ if (buf == NULL) ++ goto cleanup; ++ ASN1_put_object(&p, 1, alg_len + digest_len, V_ASN1_SEQUENCE, ++ V_ASN1_UNIVERSAL); ++ i2d_X509_ALGOR(alg, &p); ++ i2d_ASN1_OCTET_STRING(digest, &p); ++ ++ *encoding_out = buf; ++ *len_out = len; ++ ok = TRUE; ++ ++cleanup: ++ X509_ALGOR_free(alg); ++ ASN1_OCTET_STRING_free(digest); ++ if (!ok) ++ return oerr(context, 0, _("Failed to DER encode DigestInfo")); ++ return 0; ++} ++ ++/* Extract the r and s values from a PKCS11 ECDSA signature and re-encode them ++ * in the DER representation of an ECDSA-Sig-Value for use in CMS. */ ++static krb5_error_code ++convert_pkcs11_ecdsa_sig(krb5_context context, ++ const uint8_t *p11sig, unsigned int p11siglen, ++ uint8_t **sig_out, unsigned int *sig_len_out) ++{ ++ krb5_boolean ok = FALSE; ++ BIGNUM *r = NULL, *s = NULL; ++ ECDSA_SIG *sig = NULL; ++ int len; ++ uint8_t *p; ++ ++ *sig_out = NULL; ++ *sig_len_out = 0; ++ ++ if (p11siglen % 2 != 0) ++ return EINVAL; ++ ++ /* Extract the r and s values from the PKCS11 signature. */ ++ r = BN_bin2bn(p11sig, p11siglen / 2, NULL); ++ s = BN_bin2bn(p11sig + p11siglen / 2, p11siglen / 2, NULL); ++ if (r == NULL || s == NULL) ++ goto cleanup; ++ ++ /* Create an ECDSA-Sig-Value object and transfer ownership of r and s. */ ++ sig = ECDSA_SIG_new(); ++ if (sig == NULL || !ECDSA_SIG_set0(sig, r, s)) ++ goto cleanup; ++ r = s = NULL; ++ ++ /* DER-encode the ECDSA-Sig-Value object. */ ++ len = i2d_ECDSA_SIG(sig, NULL); ++ if (len < 0) ++ goto cleanup; ++ p = *sig_out = malloc(len); ++ if (*sig_out == NULL) ++ goto cleanup; ++ *sig_len_out = len; ++ i2d_ECDSA_SIG(sig, &p); ++ ok = TRUE; ++ ++cleanup: ++ BN_free(r); ++ BN_free(s); ++ ECDSA_SIG_free(sig); ++ if (!ok) ++ return oerr(context, 0, _("Failed to convert PKCS11 ECDSA signature")); ++ return 0; ++} ++ + static krb5_error_code + pkinit_sign_data_pkcs11(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, +@@ -3757,27 +3788,88 @@ pkinit_sign_data_pkcs11(krb5_context context, + unsigned char **sig, + unsigned int *sig_len) + { ++ krb5_error_code ret; + CK_OBJECT_HANDLE obj; + CK_ULONG len; + CK_MECHANISM mech; +- unsigned char *cp; ++ CK_SESSION_HANDLE session; ++ CK_FUNCTION_LIST_PTR p11; ++ CK_ATTRIBUTE attr; ++ CK_KEY_TYPE keytype; ++ EVP_MD_CTX *ctx; ++ const EVP_MD *md = EVP_sha256(); ++ unsigned int mdlen; ++ uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input; ++ size_t dinfo_len, input_len; + int r; + ++ *sig = NULL; ++ *sig_len = 0; ++ + if (pkinit_open_session(context, id_cryptoctx)) { + pkiDebug("can't open pkcs11 session\n"); + return KRB5KDC_ERR_PREAUTH_FAILED; + } ++ p11 = id_cryptoctx->p11; ++ session = id_cryptoctx->session; + +- pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ if (ret) ++ return ret; ++ ++ attr.type = CKA_KEY_TYPE; ++ attr.pValue = &keytype; ++ attr.ulValueLen = sizeof(keytype); ++ r = p11->C_GetAttributeValue(session, obj, &attr, 1); ++ if (r) { ++ pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r)); ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ ++ /* ++ * We would ideally use CKM_SHA256_RSA_PKCS and CKM_ECDSA_SHA256, but ++ * historically many cards seem to be confused about whether they are ++ * capable of mechanisms or not. To be safe we compute the digest ++ * ourselves and use CKM_RSA_PKCS and CKM_ECDSA. ++ */ ++ ctx = EVP_MD_CTX_new(); ++ if (ctx == NULL) { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); ++ EVP_DigestUpdate(ctx, data, data_len); ++ EVP_DigestFinal_ex(ctx, mdbuf, &mdlen); ++ EVP_MD_CTX_free(ctx); + +- mech.mechanism = id_cryptoctx->mech; ++ if (keytype == CKK_RSA) { ++ /* For RSA we must also encode the digest in a DigestInfo sequence. */ ++ mech.mechanism = CKM_RSA_PKCS; ++ ret = encode_digestinfo(context, md, mdbuf, mdlen, &dinfo, &dinfo_len); ++ if (ret) ++ goto cleanup; ++ input = dinfo; ++ input_len = dinfo_len; ++ } else if (keytype == CKK_EC) { ++ mech.mechanism = CKM_ECDSA; ++ input = mdbuf; ++ input_len = mdlen; ++ } else { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, ret, ++ _("PKCS11 certificate has unsupported key type %lu"), ++ keytype); ++ goto cleanup; ++ } + mech.pParameter = NULL; + mech.ulParameterLen = 0; + +- if ((r = id_cryptoctx->p11->C_SignInit(id_cryptoctx->session, &mech, +- obj)) != CKR_OK) { ++ r = p11->C_SignInit(session, &mech, obj); ++ if (r != CKR_OK) { + pkiDebug("C_SignInit: %s\n", pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } + + /* +@@ -3785,28 +3877,38 @@ pkinit_sign_data_pkcs11(krb5_context context, + * get that. So guess, and if it's too small, re-malloc. + */ + len = PK_SIGLEN_GUESS; +- cp = malloc((size_t) len); +- if (cp == NULL) +- return ENOMEM; ++ sigbuf = k5alloc(len, &ret); ++ if (sigbuf == NULL) ++ goto cleanup; + +- r = id_cryptoctx->p11->C_Sign(id_cryptoctx->session, data, +- (CK_ULONG) data_len, cp, &len); ++ r = p11->C_Sign(session, input, input_len, sigbuf, &len); + if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) { +- free(cp); ++ free(sigbuf); + pkiDebug("C_Sign realloc %d\n", (int) len); +- cp = malloc((size_t) len); +- r = id_cryptoctx->p11->C_Sign(id_cryptoctx->session, data, +- (CK_ULONG) data_len, cp, &len); ++ sigbuf = k5alloc(len, &ret); ++ if (sigbuf == NULL) ++ goto cleanup; ++ r = p11->C_Sign(session, input, input_len, sigbuf, &len); + } + if (r != CKR_OK) { + pkiDebug("C_Sign: %s\n", pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } +- pkiDebug("sign %d -> %d\n", (int) data_len, (int) len); +- *sig_len = len; +- *sig = cp; + +- return 0; ++ if (keytype == CKK_EC) { ++ /* PKCS11 ECDSA signatures must be re-encoded for CMS. */ ++ ret = convert_pkcs11_ecdsa_sig(context, sigbuf, len, sig, sig_len); ++ } else { ++ *sig_len = len; ++ *sig = sigbuf; ++ sigbuf = NULL; ++ } ++ ++cleanup: ++ free(dinfo); ++ free(sigbuf); ++ return ret; + } + #endif + +@@ -4388,15 +4490,6 @@ pkinit_get_certs_pkcs11(krb5_context context, + return 0; + } + +- /* +- * We'd like to use CKM_SHA256_RSA_PKCS for signing if it's available, but +- * historically many cards seem to be confused about whether they are +- * capable of mechanisms or not. The safe thing seems to be to ignore the +- * mechanism list, always use CKM_RSA_PKCS and calculate the sha256 digest +- * ourselves. +- */ +- id_cryptoctx->mech = CKM_RSA_PKCS; +- + cls = CKO_CERTIFICATE; + attrs[0].type = CKA_CLASS; + attrs[0].pValue = &cls; +diff --git a/src/tests/pkinit-certs/ca.pem b/src/tests/pkinit-certs/ca.pem +index 63d31c1f5f..6c782bcde5 100644 +--- a/src/tests/pkinit-certs/ca.pem ++++ b/src/tests/pkinit-certs/ca.pem +@@ -3,27 +3,27 @@ MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx + FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG + A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz + dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug +-b3RoZXJ3aXNlMB4XDTIxMTAwODIxMTEzMFoXDTMyMDkyMDIxMTEzMFowgacxCzAJ ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owgacxCzAJ + BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i + cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl + cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk + byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC +-ggEBAM+lV5iaVats0yBFN4FBe6bovloNe3d0F9qMuhKqlECv6cFra75gSGmHJz6t +-GTK8zITU7sni429azTZC9IQnUt/2lW8dWzpZD1T5Vt1DYvYFqVzjhNfzeEDK88ig +-ENfzaX/cY2P76arJr0cewGaauzaux8heYW1CjBxWmk6kWq4aD+5jggchvBeOGEE2 +-NkV3MPbXut8fu+3NzuuIG7Z0ilwQv+KUvQ8QQb9VCwdsDh/ERsQ4loC9P4jtuWCJ +-ikIE78GxDcOMoC1ftJtW/mBCS2iCHipXrp2BDDJMyHxZjHpl0VoDR7koWGtD3sos +-EwUkXVvWIuKs432h2dXQ+u8HaBsCAwEAAaOCARgwggEUMB0GA1UdDgQWBBT0F6X7 +-1QRftDiSeNSY3bks3nK0IzCB1AYDVR0jBIHMMIHJgBT0F6X71QRftDiSeNSY3bks +-3nK0I6GBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 ++ggEBAJv9Sbc2QSbHWnZjk55JfeOdPGUsmKOcT/N7C0/0mOQq4tUCmha7ntpBoIJd ++UBDhMQayG3QHruQX7aogtOx8hoLoLUaNKgxzEZ0OLbDRMc2M+vTDpBROITGI1KPv ++QtthlS4ocqKvqBCze66N9LufzAju61CyKdB3pCykPrgDVVScfsZ1t2zCbK0SF2cf ++ZAdIyCLoGLeQ95/NL3SIx0CX9gU47AVmBkSQ+LExJRhbUSIg+puKbqJ0XVILR1B2 ++ezgik2ObFND0hsRUS4v8pKnIDz0HXR2AneTESY+atjbzzelGA2zH86p4tLg0PanQ ++4x4+gpkQhzSr5Cmi3QX4XahSrmUCAwEAAaOCARgwggEUMB0GA1UdDgQWBBSSP/pz ++leX5zVcZ9hpI5GG2eQ+pqjCB1AYDVR0jBIHMMIHJgBSSP/pzleX5zVcZ9hpI5GG2 ++eQ+pqqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 + dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ + bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 + IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE +-AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBT2FJVPS+U +-0MXa1HUOETuUPrVff7VeIvyAPm9IgX1zNbCvktCc4d7ErNB3P5ng8aZz4MKqwzuX +-HVhUxbF7JKfyUI41lcixPG+k+U9mzBJaozWT+K1OhdUF//mGPxaxe5jyUhDiQArD +-/6vulX0/B+1iuIa1sCfoeelzqQcYHqhZdWn6bBdcDWNARHIXWs5zPeKA975+d5TW +-rofE7T8nNQJvcZoVjCSfcYXhP82D/0sA+wPCt3fgbBZdvJ89xwvIlzBtiwC++Zbe +-37Rt5av0+ykpR7nmh2jyG+ItzE73nYKdBrUI5J6JLSbUcQTw4jeXHwDULUHZ6fXg +-TBEM2v1VW4Df ++AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAfx04Uqh0D ++myOR1PSqEEbMWJxZXYoESnjjH4Co4doceVBTuKix/2lplD4wcvA7aMXpmkvGfP38 ++dPrN1jvGd4bi/djTuxab9qB7rOeswAt+NyVHReUmuIMwgcW1UD7HXErg4EsOMjGD ++2XGhJYxGnwdURmnFwoO3yLLwo5K+C4rqPm3PbnI3W0sCA+IXepQTxuXK3dSplMMm ++0Pejw3es2s3oI9WaD2JRXvFuylw4UWYX+cyFRb+wN55Gh0rPVdxDhKCkbWNt/gTi ++/DbC+5pyQXkmy07OEGrmh4+5ae9hwejr9AukF2IZJB+oFP4i1mt9xyAOXImnWOzB ++SdHD08WHl5Gq + -----END CERTIFICATE----- +diff --git a/src/tests/pkinit-certs/eckey.pem b/src/tests/pkinit-certs/eckey.pem +new file mode 100644 +index 0000000000..14c2efd2ac +--- /dev/null ++++ b/src/tests/pkinit-certs/eckey.pem +@@ -0,0 +1,5 @@ ++-----BEGIN PRIVATE KEY----- ++MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgSB3T7ihe3JUeIKZI ++PCDqATKN/dNugQsaC5AKiBPC6ymhRANCAAQy0E88e1CX16/2wL2T+nE0pmlb7wBM ++0hOh6m3m2uDbVsAIRJfhEjHWsT2ODCoBvGDV6vBeIOUjE/Ro9EwnYBW5 ++-----END PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/ecuser.pem b/src/tests/pkinit-certs/ecuser.pem +new file mode 100644 +index 0000000000..585e53d8c5 +--- /dev/null ++++ b/src/tests/pkinit-certs/ecuser.pem +@@ -0,0 +1,24 @@ ++-----BEGIN CERTIFICATE----- ++MIIECDCCAvCgAwIBAgIBBDANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz ++dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owSjELMAkG ++A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF ++U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE ++MtBPPHtQl9ev9sC9k/pxNKZpW+8ATNIToept5trg21bACESX4RIx1rE9jgwqAbxg ++1erwXiDlIxP0aPRMJ2AVuaOCAWQwggFgMB0GA1UdDgQWBBR5MaRx7ub5YBwsS0CF ++Li18nsl49zCB1AYDVR0jBIHMMIHJgBSSP/pzleX5zVcZ9hpI5GG2eQ+pqqGBraSB ++qjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNV ++BAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQ ++S0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3Vp ++dGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNV ++HRMBAf8EAjAAMDkGA1UdEQQyMDCgLgYGKwYBBQICoCQwIqANGwtLUkJURVNULkNP ++TaERMA+gAwIBAaEIMAYbBHVzZXIwEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG ++9w0BAQsFAAOCAQEAfwlONLYPo0BNN2NyQZM3wkoldvFqidcoZiYALOcBcmllMP7H ++XQ/+en4TmbKR0RUJN6AjR9yEo92fHAYOB2L7AzR8AkOiRLjp/Pdg5kUHFTdKenTK ++DvpeiJELz9chk/vaMv1T9qvOwH2bVAyS8GrUc5n0ui5F61PrquLAmm+dpKyHDY60 ++DdFaebS2gYsmy4bBv0mgcMZ+ZXnzXYmLNtdVQ3SgVGO7M8eyCqPbe/o0Lw4Gz+l0 ++xgpFkptdlEogsOaJBzjrgWyBnWw6MkyyLiSY+iOxFpBGkwCxi1gtQwbcp4gMwaxc ++p5+JPM/JBfglBX1lpRhhxL8EGQvpryN9MT530w== ++-----END CERTIFICATE----- +diff --git a/src/tests/pkinit-certs/generic.p12 b/src/tests/pkinit-certs/generic.p12 +index 35c27415bcb07c479990133882655bce3fe3bd72..55a248137ca7b82654252808422e97337ed95a6a 100644 +GIT binary patch +delta 2529 +zcmV<72_E*P6Mz&VFoFsE0s#Xsf(fz)2`Yw2hW8Bt2LYgh38Msp37;^637e53JAbV+ +z63K|{jPm6S=lRhUG)C?|)hzs!}J6Z>esz%vM91VoEu)Pmv^_jw4QQ*{P;%zdH= +z8s3InWP5X2dL3JP%_r_AH_wr3!haB>cU&;sQHeY0h(*0{Urg+^g7yVKn`IE0+Y~a< +z<+xCb5BfX!dU%zZc~;wYZFOctxMS?Ch*eD^8-zy8#7*(m&=G8Yhq%X1&fk&#wqvO` +z_dV6f%Lq>$}y?fWJ0eZbaT_3xCB5v<1XX +zhesXP-h3le9uU$XQav@c@^ng6qjNOuTgo57tfg;nGUhmeDh5PY6l0w(`tmfVgVRd9 +zI*Dp$(4kaUY$_|u8*tJ)z~Krm!cf$))c$ks%D6w-z)!1oA_bqAdZA}A1PNl78+^by +zVRwaGflgdSeO1RqxQGi;-G4bE0H%>kz6g9{O9DNB5M5tLz%C?ula24llm} +zuabL^!h`a+uPu%ySk>~=QyaYKaBuM-cq;N~+Yx$45s+L!{%M=B-hZOqUNh4Z-0?vO-hD#{!>=(UZ$|e*T(Ppu?Da=)T;Z(vy(zB2AS5Op(0bOE%ijXo4T48j +zaWpTAg-^G1r}2Wp1*k*bZcWwf`iU-QS;py!e2L#5(1)IJP}}evf+~Y&;L^{uM-p#P +z$CG)Ic1TsdW7ZAj_9OvHhVSGr5Tr)o_wWooY?lqp0j8d)wxI&i!7%mWDC=nXromP*=gpE(B1cq6 +z@&j;>({0S<2hI|cciYPo@g%a*p@w1QGgUypb46QUs!RVP9)D=_dWE&lLg-u?xw~PV +z8h$a6Har0<@wSwfG;mYk()2u9489&2LgL1C(X*xX1j1|82eY!A`42Tp_64UG7SgBu +z%wrY}ctA8@Orn_s)L0sRiOYhfl{V{IX +zM*Nb94b`ZcV1L~qp38AGXFWP*5hp^{z@{c)LZAu9VXKJ{o5DhRdf!Y&dE}=hwC#io +zYZtdIiA~U5r(Up^;hSx%T>+Jy<}L55P1hamg|^{b1f$(AuO#g5sY1S!!RH0q+MJHB +z4KRWQga!#JhDe6@4FLxMpn?T;1cC)|FoFebFoFeX27e1GhDe6@4FL=a0Ro_c1u-y! +z1uZaF1_>&LNQUz5YzW6GvH2i8WJEF=@#Jf&|c95Qocq9uI_J +zuEKYIs(pnOmNhS39%39z*|>! +zQn!$n2&<*PQxpN5z%hjmlZIh7OhJBIERDLutbco%u}C>L6m-jbjU`E0z4N4hv7qv} +z^8gz +zK!5#Z(o{x~w1P9(r4Li1M%kTWTj4^9LM>3^D&+%>&>Wli9sfvq8guK6okCa1xutOKr6 +ze5ic%+9n`|zI{F%*l8Fr;ljDGAvLV0jf_)^F#+Z_s_@|PN(w%P!=LYJK87-dtKya2 +z-ou2tBdt^%>*Aqa4Oz$fR`pK-Kt1~8U({s7fQm9sgMRC|HbAW@!MkNsfz< +zs3^xE3`}tjOvaZ`mTy27G6T*&3x76}mvTS&uHM)V*>8 +zLvM!WSi)FK>L5EKYmVS=wl>j?$b4-)uQ5|+rMxsUIRUb~2(_i}gtCLG(Lj^DK^6HR +z9|Bvq^{Tc`3RDQ#EExyBL%EMeJ0A)4WmSkOXqfGF$5-3gA<;I^%nD!<^?!uBBky_h +zDtHZ3Hq?a{K8#>eqP`A1yryjk_q9*A{X2bwX11sbz$$Y)U2w$6y=G^r0u5K6r-Qq$ +zhmU#{eAbmCy5=l7y`BIj6sdNhVHC%_79bPl +ziqj1XqSWmBQHa9luW4F^7k`C(;)-1%xig{k$ZRTikT+J#^4~y14n$+@8>ZlRhjX@X +zGv{`|4XV@GM}bVDI$XXh4edI-nqiEw2@N*ip5xg23vTl~U@sV*_`HJxr#5B4$dV6v +zj=|^1mfn3wd(>scr_%*luv9D=!6_Jf0%mi@W8$z1!3`<@lUmc73wTM| +ztMxU2wp4lXT+wF?cD6j|rz=JhmfCBDAl-Ij#Q0W%F$P)3fwn}<2+d$G9GIQzMh!YN +zAmjmBVsnk6AgHmakbkjQY;aSX$`ujO5N8damZY7qviDEls~HZTCkILT#rJxJnsB*n +zR>-H**-OEFgmF#KsXF__e;4CL7kK-*wNi<+Exq~-VcGD9%`qh~BL)d7hDe6@4FL%i +zF%|?A!W!(19gkH}sK#VEJUUJdl+OXWFhMXeFbxI?V1`HmWi|r@0s#d81RywUr7PU4+J&7;H`yIZWU8rteK!mx%-j>llc3nny_xmpD&=el80aE%9m{fV68_AYFzhm@kKP%T=aiATz>)K7usww +z(0*{b68eczuAI2a3uHsb3Zn_F)9~g+LCvtun(x>N9_kuVVuYlA^cxgA()Q^}p{@VX +z(pQJ#h!L# +zvT%~2SR2lMq2|uvwt-65uo+g%PdM+yCR*0d3<~^2SWHuSkyu|U{2*phDUa6z^!f#K +z&e!gf!i)wC0}3Cr;t4QJ>qXxqtd29tYZ!QSIJXcb1=)#Zz@NztpMM)iLM4FN{(b4O +z7;Y8sDSuKgUUFZq^5D#5vcVSW7Jv7Yd(aBQZLxL`TMK);Odg}Pn?i_&$%=^rbRuT) +z1@-3i4P15rwSp}Q52aT>>NISAeYnh|qF(@TkGZY4j&#|GeCZ}Hv|Wo|3Ildq{En?` +z33W*|;8`HbhQf?M^M5j}nDMonW~5ihFn!pqa@$I}d3&;Sf_zYJf +zK3966V3l`s?KpMq7Xkws7rQ0uNx?O)nr5OZ&sjxPS8n6V!bbhl+S`tADP6n()KD|d +z-4;CP6oPK*x2YwH4h?UM!7FQ+S?s;2-TRK1t94vz+%<~h=YKH5b;L89yyIr-R20Xh +zS{BJAi-^$up9m8hh*-25HX~YLbxrHdA82beU_`X^W`y^J_2X$56A1j~=kc`==Z_+T +zu7n}%#;**bdW+$vg-Mi7)lR@16R`>eP+7#cXM{AT8(O1C6<8Jjm?oO_Dk+uOv3t&g +zP!zO+$`Utaxql8|%C$?vj}~CsWJnUybmONs+6V!t>=}LX3`Ea~#O_UYaY4adZ=6kJ +zWazr~1Ui&-TH9eCh?b{xL&MfNVV`KjC{9Nh#fgY%F57NeV`~Z=1e&f>y{fZPK8Y+& +z12BRGIR*(ThDe6@4FLxMpn?S|1cC)7FoFdlFoFdh27e1GhDe6@4FL=a0Ro_c1m-Y; +z1mZ9p1_~;MNQUxYm$0NS^prVcA%SO0uwo +zHTQ=?Wn+3w3*FrDC(OA-xz1k4gg0%e7 +zE|q{bGT1^9c;Po6)t2QAoislaez~##_3so3$~8c|6ThDALVuQ_`csrzZi7niVJ9&B&mxm=-_q))60k=1>ymZmg$D41NgWqT6$()f5qclF-{owN-!( +zDNM-9lt=)MEIj|1m8It)GAoJ%qaW@RZQc!WT>eKQbxMSUwCCXnn=J7dW==)=q%_QmbS-PsoBVmQ8#q>Z^57uw%&$COK#CU_J%s^HpCp-Pso +zsVG6ZqD#N95LV4&Mw?3o*)hrMz~EOMuzxqgdGzSOzDoDF?Pkop!&U7s;C7a9@Bi+r +zp!&vTiAsBFWBiz9fh!LHbIQHHOQPIy8weJzOs7nB3foOb*z7OelAz +zF$EsP@)6NmCAs=uFa;EVKna5xx0wGC#1`kHKO_2-y{6nHp9b*qZx8n~sZv2}KYy=9 +z;~-}X`6hf1FeQEp+V1&}(%k_e+XYC3sTNhk<2T!iAyy{PA(IYE9GAHj(LQE#V91#~ +zMpN1OiY)j(O~~5A3sooGn~qp$_FCm)P6?T^VJIP^FO{K4O+egG1sF_F)0>`OQOio4 +zjE6GDi!3W7g|OZ^z;M7OTLGbU+pY!hzrsCEIoUkENh3X5HhDb9>|ytO0Stc +z@^I;i)OpS|&hTxBQ&rT4S3nmdg~fDy@qjnF^LgIQbKcXMGfqm}?RX#B>Gf;lzxO}jM- +z^t@NcdY7+{Q-)q4=Ko$b^?&x{b!znTkhh!0ERCBt;t0ez_1?u1D*pnqDZ~gg>wdj_ +zDezCIv8*1y!-2=uWr$XJ4OSw>q5$^1c@yM?IK-sh^c19jqpxi*kgsE^^W-y_Nejad +zd3khp1|E-OCe?G*$q+&?|L(>VjwhpmXG}Pxk5vO(Qyn{y81;~`)PL~7xU*N-!)((Q +zs!t34$4XA5po!lQq66@%NADy&c}(Eg2(@_lQp3?MRq!|?PO=AXq;qSylg+*;=831x +zV?Dd^3!*hvgv4ud@Ta2hPE24|C@l*$Kh8kG4%2x!jBss%!yz?NiaKJR*V?l>TPY!I +zH_XRAWAxGcTje&~Pg*f0Fe3&DDuzgg_YDCF6)_eB6wv3{Iz-K-_+dQJ5g?!#l~?ug +zDljoHAutIB1uG5%0vZJX1QbP$4lejcX32OA_0p;gH()NMq7(!OS_-~il6^%c0s;sC +Dy- privkey.pem + openssl rsa -in privkey.pem -out privkey-enc.pem -des3 -passout pass:encrypted + ++# Generate an EC private key. ++openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:P-256 > eckey.pem ++ + # Generate a "CA" certificate. + SUBJECT=ca openssl req -config openssl.cnf -new -x509 -extensions exts_ca \ + -set_serial 1 -days $DAYS -key privkey.pem -out ca.pem + + serial=2 + gen_cert() { +- SUBJECT=$1 openssl req -config openssl.cnf -new -key privkey.pem -out csr ++ keyfile=${4-privkey.pem} ++ SUBJECT=$1 openssl req -config openssl.cnf -new -key $keyfile -out csr + SUBJECT=$1 openssl x509 -extfile openssl.cnf -extensions $2 \ + -set_serial $serial -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ + -in csr -out $3 +@@ -152,6 +156,9 @@ gen_cert user exts_client user.pem + gen_pkcs12 user.pem user.p12 + gen_pkcs12 user.pem user-enc.p12 encrypted + ++# Generate an EC client certificate. ++gen_cert user exts_client ecuser.pem eckey.pem ++ + # Generate a client certificate and PKCS#12 bundle with a UPN SAN. + gen_cert user exts_upn_client user-upn.pem + gen_pkcs12 user-upn.pem user-upn.p12 +diff --git a/src/tests/pkinit-certs/privkey-enc.pem b/src/tests/pkinit-certs/privkey-enc.pem +index 29d2f3d38c..fd36246ed4 100644 +--- a/src/tests/pkinit-certs/privkey-enc.pem ++++ b/src/tests/pkinit-certs/privkey-enc.pem +@@ -1,30 +1,30 @@ +------BEGIN RSA PRIVATE KEY----- +-Proc-Type: 4,ENCRYPTED +-DEK-Info: DES-EDE3-CBC,5FFF1E71BFFB65E3 +- +-p89x5YEL+Mb6IPZXEkkr0KC4Wj+JtgE3VKdTT0wEcRD74QVv+dbbZt62WgmpJtId +-ph0Ial2z5Mws8L/aTkPdW2H/bEroApLu4TfUV+w67KcWgrc8gOg73d6gEObqx8li +-qGbs7FC1cI1WfDfnNOnCbD66e5+bTI8fDuchaieNRqzROd9RHhmlBHgylTmf55us +-laGuwLq2cZk/+Xz0M8PPx07uauGkAK0fyfifn/JR3PsGsE9s334osVQMjbjyT0VE +-rm8HGm3PvZHHDUnkOh7AGKyEtsIa5fJAULUjugp2lQJqOigC4HVn8a33xfLI0F1+ +-2nH9MZ+Ap1rtI1cJX8CDn/Ij9oFt01scLxynYekYej11zFiR6qHC0sspxu0Yi8l0 +-puBPXCI0GzyF9I53ukjGeibTtssz5yw1r+2oVasR4bvfXczPjqTQCBsPSUayNNhw +-RgT7k4QTY2OlrK/5XdILBzBlsvfndXgGOwEDw4YE7PMzMmz69vPMK7CfedUqtuXq +-bGBks58tzeOa4NSfVDOuFLI+LMkoYWMSjPGD/I0trX41xCU+O6PZOnDyt5ZWl1Tm +-klJpsB7rUcwsP8d4w4QGhyyV6Mo2MTlnTILr4CwwvmDMBch3yzwbfKdeywsFQh0S +-NMrG3aYNO7csRRTD6aGvYcBCbavWq7Ujsb/fV7SOIS26f4VEqewvOFlFEXm66zaz +-GJ0IcjtNHYNIIIW4690djxPqlGgbIZTblBSBlT+iOW5HrhXvrLeMmwAPxInU5dK+ +-ypk2MGc4SzemkDi8H9jDW3dwbgcvVD9wn0glhVLQKWvP6F73UUdVEXMCZ+960xnR +-gxeEwDdIpzXNadWdON1kRbqI2KesRY/XQErGHDOvf2gNSM9V2gPz+5humvcu3mXY +-r4537On4+IdzetEVtI7D0slgojs+jN8waigpkLFB5RVl8PnzblMuWOkHNA86rrp+ +-h6wNqv9kHLgPjpAyB1l/7w4VqXLXeC4PdaGc2fcpdNWOncUnHROmDmYvdTocqhIF +-bAsEFV7QZoTgDB7J6vLsmbtfawtHMSb81V/wTJWRrtY/gJCrkJXR2pTYAZlPX6vK +-aK7K2NuhJFMnrQD+kxsrloSEyfsZmHtk0mAVXJw4wSxlH3eGQ+Jphb/M2wtsnWV1 +-w0fehxL2Vd5SyBBctAGhUirhRngbOO/E8IioymrziQ88vJZs2DxvbuNG4WKTuTwj +-CIggXohCNKdqrwL2HAynm2FVEWhbKrQwe4kjZc64WjccR4cy9vv+dxFfrKl+vZ1o +-Wvb0WXND7fiSBrPo7OfaYM5HjrcvIRP1AtMuArhuQYVARmawUG0l7dFLN97Rh9M+ +-Ud9vBIfQYlubnTGVVm/5xrUh2isQbp2vrZLfMrUNXMQm0vSxKgGkAxqNUuklJC06 +-LvCtEWMYXiBmB1zP4khwCHmHB+/E1gHBAutCzhpPu86ayEtNHBHIFkqKvZSg/UuZ +-+ygDdTJV00I2neIdeQcyG+vPg6huIDIHpG5u6eQn5sLqVkhr+apeNcskMWpdkpFS +-Lo62KUZDR3yB83ne63c3IGex0hWhVojJOAxykpGp6OD9uFn6Xn7x2Q== +------END RSA PRIVATE KEY----- ++-----BEGIN ENCRYPTED PRIVATE KEY----- ++MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIBw7aG13XYxwCAggA ++MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECPWyEPoKz4WhBIIEyKHdx+pkDxax ++dCCUZHsJ54boZxh+7f7xmO9Rjm+6+3cE+WCjPsiGHPUDtOXLxWwcrG0RAmA1GmrE ++yZbclwEMF8LcWQ3EUDMCJXBs7CEtA4XDH+EW1KsZwP+cA53ZFFikGj3sW6Ix5GLi ++Df311Eumhp3GABU57siNn+tMZJAorInth5lXBJFQoE3KJbBrSN9iQKZTOpgr4G3B ++G+qzBwrUKnZrGIp42t8op4VkB8sA6xoHh/huJB5pNygt9OZUQ+xdxvNQq+5/kJ2I ++mP/JRPSuN4GtnNA4fBB6tPv8t0L8hActkWlQ1rSJwWnWge3t4r5/3FBcAbl+zq3k ++t8A0LWgjsiQRmlKRN7GrzorOUKFv+7YAq6rc1Ek79qitUgEiFkwZZySt5+yPstMW ++vpaq2V0yDHf5Ds9uXffprhSAjnfXdT4NTg5eMeH65OEedUpVVzHauoGfFkDGaq8L ++8XgWPZPaz6GQFpU5SGk8FZn0OLLJHnHQDYo+ViL2XSuuqY8Jd7fmpzqVoHOU8k9Q ++/ONKW+E6uvkpNH6NbknceA/ip1bcdfwA/uRBckXjCc5uR0oB18M4UQPuKlcGev39 ++mcdlvzQJxl2EWbB8ULazzuzOVfCAEwKc96qOkDAY94CB69f/KhBOd2QqHzdxrQ+3 +++K+YduhbfP49Vxaq4NIklS/kSSv4GEBHzEwtFxX4oqN4Er+UkBSB423nvlkSLd1g ++tR4M30lJyzmHtOEpSOZYLakviz36ZOCV/DsxrfziNG/0RB/mPLm/B5L+StqjJrTY ++Pjo3QHKb+6ShhTi+jZ8tqXa68+TZO3Q7eTgqrcn8mq9jfama0KQF/13kmUsrFXTS ++wk/nbSP10z+MhO68z7o3j+Q0Co/cXkQke4slvc3DqLNvpQdDMPLKQVxtkPBq5czr ++dbk5K2GYFLNWO5Tv2RgBGomznoAGSolz5ozIqxffVHAK4NGfhihgLO/6GujDANVz ++EX/2/IacRg0L0x7//O/GHomiFvWYnDbHhRNicERe/ji1TCxJ5glqntFjOXDumwi6 ++f+mQWNWlQWtKq0IOnlHrBB+vqykAj+e+FROqJjuNI6hu4CNnrBK3Hf+NY+rXdn7l ++iCTD3ojdufqo0JDZe8dXea+B7Zu7WNAxnpW8D018DJxR2hoBvT4Po1CBaHLfxAkT ++ZGeXMjp1vZ348xBSppFpIpYjFRQBeBgSezzA66o3YIcDeHu2bTzg73DiUXNgV3RG ++OyJHmsOmN9Gax/Cx4z6/Ff7seisXpIMRU9TDrRCFKAcPHXAl3R4L6guK0I5OGwz3 ++GSMxsx3PGitj0x+1ynW/Tf+EJQD33ognc+kuQfNL0XW2tNJoibZIs1WgdbDwD9RD ++X7rbb9GfSJlQUnBFG/EKU7SGmFZUVMz7we8vckZ1PfeIKfH7OWrZ2i1WxIF2WO1K ++BX4TXp0KKt+aCwf1GInQ/6aYgh5g8W2iKuz2HJeZIN+ohciNmpOynsFmHGXdbvnO ++Kw+msZEQb5AvhXf4ToiSwZLSwq3qAILN8fOQQ9ta1DjJuUtITpe6ys9xhlnriUkm ++KrY50GkimLdD6XszC2uNulAuh3o0nZplqxC9IOLh+uasEU/+xqtwTaaYBljTpH2C ++8FPAEFFUVy6lsngJEQvdjw== ++-----END ENCRYPTED PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/privkey.pem b/src/tests/pkinit-certs/privkey.pem +index 007b6275df..2a25dc19cf 100644 +--- a/src/tests/pkinit-certs/privkey.pem ++++ b/src/tests/pkinit-certs/privkey.pem +@@ -1,27 +1,28 @@ +------BEGIN RSA PRIVATE KEY----- +-MIIEoAIBAAKCAQEAz6VXmJpVq2zTIEU3gUF7pui+Wg17d3QX2oy6EqqUQK/pwWtr +-vmBIaYcnPq0ZMrzMhNTuyeLjb1rNNkL0hCdS3/aVbx1bOlkPVPlW3UNi9gWpXOOE +-1/N4QMrzyKAQ1/Npf9xjY/vpqsmvRx7AZpq7Nq7HyF5hbUKMHFaaTqRarhoP7mOC +-ByG8F44YQTY2RXcw9te63x+77c3O64gbtnSKXBC/4pS9DxBBv1ULB2wOH8RGxDiW +-gL0/iO25YImKQgTvwbENw4ygLV+0m1b+YEJLaIIeKleunYEMMkzIfFmMemXRWgNH +-uShYa0PeyiwTBSRdW9Yi4qzjfaHZ1dD67wdoGwIDAQABAoIBAEpnKYMR0h6xyNjo +-VGIpT6BYB1UHPbVo0N9Ly6TCoIqpPe5DioDVyTye5A4OQlgu1G3ISqPme6478ApA +-ZZMw7/42QgdlknnOzbKaAWkZK02Sa8RP9hrXL8CvuDisOjzXCHd7RdXevzSmPfsS +-5sgdK3YFnKqMPwbCcKf61CHXvHJjWGuTIHIRh8P7gJelA4ahO0kYQ8aRXv3ldquO +-ukSI5gyk9CN+aAHqt25kEmt9oOgk+8kfKpnk+5gkOCY2YOFDDckD7nL1VIIrDxwG +-SmU598qjVwycDairWUY8uSuPCOLgbvDM9N8cERDMsyNQL63GE8ZZyHZsJ3Pbwdfs +-JVHh5ekCgYEA/CwhaT9D0WQ49GQdeI7aqazHEYDmqPdE2/qbmr67tPMZzX8AAk9j +-r4aMT+oIdtIMPdoQNNcBP6NYZLlAoMbLoAzHmWJnF5/YWLnS2Wg9OuXUOBn3jk1l +-SWelJfAKGeBld5fpSLTdHjRAwJrNCX+mc0IZIiEw2IvGUPgKGX08bX8CgYEA0swx +-xCDgvfoaKueInw/rUIcKxrSxK3pDhaR01Dg2pwSo7Vj9W01zf33qe+mjma6+U2SB +-fk+/O2VXDuEOmVDLwvp6PkmUeRE5PyH7urTMEjy5ELNGiZd9zHoG/zJnRgPwTjuW +-yguvjVGJwI1IvmODuA7Xc7iHFlvGNuxXZjPkS2UCgYA0nFxoIdvbTsaXLl/7rAow +-xixOGY+GBvil0HYwZcSxrtpeRjXRRZDtqOuTLKeRaqdFLD6fV5AaH9EsSn4STQdk +-n+XwuVf61M2FTVeRJi9IH3UUM06zsLAGDYqmDJt+5JMmzVnNYnaTe6FazbEjXy9x +-8oNd3IDdXOQGNomc4cT+rwKBgBbABOr25Wp7cJGK1XrdO/c/69DQNYLMujbVLeqt +-enCCFz0uaoGNFVcAHutqpsZyToYvha49KxVc9Y1cirfPOX58i+7nAAgk7Lm8kC9x +-Tcj2Fr8PqiA1YlVMIi8uoGi1Ch1XXwnFQxgMYcKPPPeXQ+L8bxJFKwcltnm8/h3A +-ofXlAn9AW6fYZLSzOfNQTMnuukhuAtZcEW9NlJHbej305zK89J66S8wroQs5iOla +-5GG+S4YaZh5sVGw+mnS+FCw7cQCUk40kXwX3yTrxlX1qGSCFCQnFdJow+5NVg4D+ +-dzDKzniH71OZZFxTqiiz76XxiaW/rS1uOfP/WSVR9NBLpV5n +------END RSA PRIVATE KEY----- ++-----BEGIN PRIVATE KEY----- ++MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQCb/Um3NkEmx1p2 ++Y5OeSX3jnTxlLJijnE/zewtP9JjkKuLVApoWu57aQaCCXVAQ4TEGsht0B67kF+2q ++ILTsfIaC6C1GjSoMcxGdDi2w0THNjPr0w6QUTiExiNSj70LbYZUuKHKir6gQs3uu ++jfS7n8wI7utQsinQd6QspD64A1VUnH7GdbdswmytEhdnH2QHSMgi6Bi3kPefzS90 ++iMdAl/YFOOwFZgZEkPixMSUYW1EiIPqbim6idF1SC0dQdns4IpNjmxTQ9IbEVEuL ++/KSpyA89B10dgJ3kxEmPmrY2883pRgNsx/OqeLS4ND2p0OMePoKZEIc0q+Qpot0F +++F2oUq5lAgMBAAECggEADwzB9vY6FPa46KE01dm7VqGN+SjzVR24rQIbFkzAD4t/ ++tRN6MGVLrz0TsmA0YFyJsV6vvWMcYY9Zc8eSDRr6k1i5PYxTGT5k3aVHjT6xsmY+ ++tCzIANmE5FWSRnrIFYh1ry1h2gZejbXzYeT6TrvdIKOEepWl6SIR6eiy0Ggp7G7C ++SjlpT96ZtdE2RnlvcxcACtwhe3vPbkLmTCOEqeZ6LHCHIHiK4KdJgJ08OjU7Kgsr +++vmnwTJsH5s0b5IIznfWajO4JNOpqjzFDjDctGYBwp5xF4zu3u4bKe9aleM0q/jl ++ZkibxLsFAh3Xkh89nxr3E6oBLm0F8r8M7PK5wpMShQKBgQDAipf6T6XUY+ugkKw+ ++301LyoAch6WV9oT6uOJsAttmcUpUr6NXhRT3OM4oqyYsAc5JW2wbz+n6lED3j6Ez ++QEKSIFrYpjrYr9D7hqvISI9JT0PhVSPXECfifEyIR9xmLvV9WQq7NRCJMi26X9ab ++Grqpw1HNlPA/rdcc/dY0p25DlwKBgQDPZqxSnwnTa6X+r0UdR8l6kc9VuESotpbE ++0ziF222bpXmZ2GKiEU1buFORHih/e3yDvKvq+p2apyUKnEEVQg/TL8/Jzya7fEOI ++lTXcNQ/f78ef+nwEAxdRVQkWXFWHvvKUHm1rGCIY7zeOLnQ9JjBQkgG8zhUamAP1 ++owLBBTstYwKBgQC+yNX9Du0HvpbdfF1g0025OwekvXiDV0m/UnHxiwcxxDJeJceZ ++0mHK8nu9apGha4ynvbIrAOMdC8gwRh76NMOCHhNGt7h5vAU9Jt2S0OtCPgvJ/N5N ++nVGYJ4iCRYqLqh5QvWlXxSYEfDc5hPuWp26tBsBJEDrbLnuH27JkbD9jMwKBgQCM ++f1VFMw+I9WehvEHpr/PA4H2/5/A7ClXgR+YGZ7s8sUBLA9btSyNIevnBWNi+Y3za ++ETm1GMkjNw9UvL0qFXJ68eylHXtzjp6BK/MslZWHcfudWCYi4aUuJ5jcWPhn2Oaj ++iGk/Hz4Z/hN4cee0dOZN7lrW+BQ7y7cC88at00lfWQKBgQC7YeW02aUPw9jMJh1x ++lDfBh+E5sdRwRQIvh3BuyTd+m/LI+3b9RSy+LIL2KFJucwKm9zR9fy33tHF2S5En ++Q+inhyXfOEygal5Rzxe3Pfx+pGZbzr6IXkhquHtjuFBwJJCrSeR66V2xDmzJfCj4 ++TY+CzwOJ/EltH4ZjPwEmE0S7+w== ++-----END PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/user-enc.p12 b/src/tests/pkinit-certs/user-enc.p12 +index 1cc3aa3da67160fd9298b9e2d624a80c5225245b..69780bf82d1452d5dcac91e5be550f5eee876583 100644 +GIT binary patch +delta 2892 +zcmV-S3$yf%7U&itFoFwY0s#Xsf(sf32`Yw2hW8Bt2LYgh3kw8-3kNWQ3j>iNJAYJI +zdvzN7hNA)k2mpYB1u&JU7+xCwe0Kqqz8d_+6eNN5bCxnq;S}(P;s|YSOhpyniUDCM +z$(1g#xF>v`h_!Z%^c0Yt!ew3_&P4(J0{#(9L7ePjfyd?bB;_QXFR7CVbnjKE +zff_LH>L^0?(6j~#3lev>bjhWkNPqvbKN_||)xXx>C4@AfTFlZU&lEHPKi4d4nj{f+ +zP!qS+8ibCntvC-FbX2Bh1;e5rJ^2HAbUA`MID37ixE)(i7Ff}3>6U!A7&UF;M}TrV +zs}FygKNP+*;c1FU9mKlF^p}|GEw>3l&8?f;h5;kVci=EJL){2P?KXfBQh!XdFp%kd +z*Ocb%wx_0U2R5IZ6yZz5d98E>a-~6_Nzx7S^X30+Efi5p^xb?~9+l&zoMeqIyzty9 +zzsz@?=R*_{cx2I*TK8_AuFLy??NA&|dO~=b>}Z8gy-$;V6$A;>=0#FrJ9Jh^u8)2W +zt?+rI1Fh%@eL0#j)BLG)A3wR#E)w3fN%6wZm#@DhR=+YxKGK(9yT*!=-Ns++Ssg0N3T2 +zKq%m4iv@P~LQo^`Mo(vF<$H-+DTiQc__AMQ#@XpYeg-&|lK+0f`+xn?YDUnk!*m-S +z;3?iZQ;n6bCF)Qt5(ITP`w+u&Ly;u}uQ1cMO&(bc!cfKO(a7W1_to~F^2+x*NgW)a +zRgZ@G)H!U6`FfcAt1chDfZQqj=#Y%;epbIDezJsIK-L+yD*p{<_X+yO+c(edMB^wL)S(YO~>7lcBt24a8iz +z>BqxgH5kvEzcWp$^y>%zfu0v_^AWYG6ydYCMdBu*~jpcY$>CJvKJs_U)yy}@2d4 +zseJR~7;BP{vz-tmn*ed*fv=l$4IYo;0VNXLW0o&Q!hbzT8q!Cnf0=w_#lXRiI)uQh +zV%mHI&J^p_;AT_-H)BKz?DO2vN05+sYJzW4{Ma%7L9plT_fE45Nv3yqwF;+zhVQTO +zpOQc^lLD9bh12?4t8>L1*vVNL%HEQGQ^g7Iqzw08Z-Z}ai+*rY33XPO~LIe+^&!Lx#pTd1JNYDu^}EZyH0 +z$TBU>AwxbT4nFscHMfohn3#mbtq1>m!CLz7(PkxiHtbu7bgqiuh(zg{?jAs}eZzI% +zFoFey1_>&LNQU+thDZTr0|Wso1Q7OWhVDa0j>1F2`SnsQsFehQ1kfy2Q!4pK76IBl` +z;zFNdALdBbb<1BjS7BgZ(Uvwb_x)%e2gv`eSYyFYtolD-;4XL1$)~RR)=d7Pt9XT2 +z;H%o^nkJ=d$#!Bj@GdAIKg$I2neN|tFeWg{;Q5)7zZpSn;T1olS+KVY_lBjjwSTe) +zb)VtP1PSkBMrT6Ioku_4UD?1eYXo!w@)n$E=yr0DHeN_iT)WQ6>M^o-i+u>O9PoIg +zAGit!#=pHqe(^&@p}lf=ph>TGzR7daU+;xp%fM56%$^@8^LiN>2W8{#gG*mrwrQTCXiGT6C0P}9P +zs|HR1en}U7kxre1`Zf~z=zusxmp&0{@$79lWY4|Pg;*&g_Oe+p8NJOzK_L!6qxHN1 +z?Wo5%?qF-5mPXn6j1@^xU2U4-hu3KNU$R*4M1)ga?HW~OZ>B1>f>cal_H>l{EfYi(x*>vJWha%>%~F<{Y3;G~g=5W0 +zNP;AzGh~ceJN%XEcgTUHj%>^4C#ZxH?6p$Mqsj%0UB(oLJ@l>MUVqg|)dT=|$YBt( +zu2-yM-d8h1I*-*B1twRw?8)`M&%5?ZL)4|XXI)mEAX@=CT2zIQ?xLXZbZ=q$w|RNc +zZ>3Z*V+x9d8*W<~L~B*X-R_HY{J-_qK&HaBE?`9LaGp#ZD$Om(@(Ey?#+yaX4a>b#%;z-;9V$w~Zhztczb-lw^6M1A3tw?M@RWNlUS#ne~ROieMk?E65E{^AK +z7h#?hzu<-)YhJC=Yew$y%NLL*@kQxtPEqNegvafKM+CXxV1H3%kxZd0Z?KMjenWP2 +zDEQZC;eP=48N|TQyell~0OIZYWa1A0K=#U@plX6Lw4tVn=FBwtcl==!VhSZ>7a#GL +zeLF|Y>4kb43XBgD=c(8lo0cmG5qOT1mNt)#aYl&g8eo(_C@x%x=Z0?)2V4r^U|~%j +zwef5hK?t&1Cx5gs-#K!O$Fo6@oZR^_4{UsI +z_6exMhy7&>jRUy#zp9Kzw!Qn~s3Tj;OJ%7vk6=QC$ObT%xXiHLaQjioZwiaA<0ClW +zwggOa)Wf1nmF08GoHj59|z3`)c&@iDicIM+kgJ +zRISnBfo4M)P>kfKHzfzj!^f^60#?=KX|!FK2seV>)(=(-F(oh~1_>&LNQU+@7L67nFoFvS0s#Xsf(p+D2`Yw2hW8Bt2LYgh3cv({3cN6a3b>IXJAYaW +zkCdOgiwFV&2mpYB1u!3O<&^}aGBO*zs#A~w5-^3s&_cc&jq;YL57~y$hvIsVoE;K_ +z@z;j^#4S|l0+R+;ItHJprmPBs9a_CK@fJSNtw`GPWz{liz2|+I@@I=qN +zd*k07Kk-OlQ37X@O=rz$K8j9)sDGPk-J>07oO@p^2gA5p`z!5za|7wrxe^F4OVF>Xh1Hq{RgYQb-)_;_0(RzORrqP +zH-6>9rCa#pY~43l3lM}D^Of?GJR5SgvoXe*9$n}6%d~(8ikvS`(#B<(zkf$~%Lonm +zNfw1+O)XYi?faC|BPm2d9_|?t7S{=Ai6*tpKfHTW$n&0tGKGpq#c70A92fv&u=zpl +zndE=f^VVig+2W8a6z{qV5}E0L^?@yQ(w=_afPb8CzW<$heOh7oL&Bp!JVA(4`j!s% +zx?fmOzd<+D;8wY*a3Q5ymw&$?>x3h&8^CM`GvEb?bI<46b@_&FrCy5mUzL7?O +z75ZMcP~PA0fwL>T(tjNAt}i#t^{zcGAz$K1>g*LjbfwlZDxSI=f3@WTNBRvsniHoJ +zrf`Aw?(*vKOp;T9&*{>E?K{SpwH17yQf5N|SCfKDNiq!E!Kg0z0xGTa87-U-d{!(c +zOck-NH6ki*cGdv_BJYIDt1zG2GRSfp(v|3ukshay-y5XaAb(9oViC?Tq3k5i`Feri +zttHdosBb8hps5^^GXj>(m2-YD;2H7o=p>1+rtl&MShE!M2?ed!cM9FV+zrx08{dcg +z$P_4=1NVpARU=pkQzG@(0n8E$!qClc>?KM@^_=a-tr@90VCRgJK0TybnLc+Qssc&Z +zXfn=HIBPvYFn0)M_`f4e;hA?uo%xSz0OeW +zNFM_sq}piLP@uBVmRVni#!=stFR|Ks&x8Q}?A;OK`2ejw&Tj(Xhx_g=L!>2WVRs-z +zGh6W&y&1fnPPNbM)lHyo;rWG^)bHE>E{|PL^ +zqx$n%KM`zvAgWp^r!U~!wxypufmE8|);fuwpKp5XXz~8Je^dVJD= +zOMjqU-55=b#50HSV6Y3_+?CRuZf!2M)0P$P%bi%ACPtPF;+gqmM41S)bV{HH*6?l7 +zFoFd+1_>&LNQU?#%Ea+EPCb^EOHXH_=gdD)Xp+~Q2LY2kYjfS}$1nj95o?56!tflz0;}d?$ieK^6&}s%L3Jl^~}=VgTY4GhW%*_#a|; +zj@K33^y1^ +zK#A=G{dRZu_!rdMFb6QVMS(Ip`>W|< +z4z!ekC+@j>Qjlx8(qW-9zHdj|;^B76#Ng{%EWjRq(IuJ6<)&awN4K+UwwNJ;UgX}E +zcaJ_73k>u#l9eP;Li?1Szkl)Oo#2|EAHYvAy25&G%=FCq2i{a!yl36`>q*b8T+*;s +zGejdSSpV~R13c(;mCzMMN6iU9ob!=eBh3r+awrj_y=yEp3JoOQx6Z$xK1o|4KRZDM +zQBnXVwZ>=c$&42g?R^ZF45)g&{)y-{_@gyo?dqxX9ErtT{JxI*8-G*_P}pLrW-1E$ +zHaN5nvDs*jbx_bgcL_D@$4QnDKIv6ws`(`gn9V-+tiycOjA@wP5X_WY$OELGX +z5KUX5YQ@_olJG;^oZ2yRmCnEb1D`a+vxyqG-vy~yGiouy808|&S{7?MV?BdI~5 +z$r$t9jm4bXD^b)>rkVn3#X)v{8>DuBwKbv=IxjOWC+r+8lMwH&{W6*4g#n;A; +zO4M7AXKtNumgi-Bj**jJ?fCr5H|=aBrlV9HN^WPkhM=+(yMNVi^GonVr&qU7AC9>b +z49|BZN0T}tH2DM}@daN982O;;XiJbw%m1(>&0zStXTCHiqL~wKB?P27Kz?h){H&yT +z0a6!f5zd}BisU?Bf9`(d956SlCT>3gvm?yLEEgOHleI(q&4=!s~U)JFb`+L~}IiD*+*g0&iUOsbSGYgzb>NdTp +zqqUpm?qjji{*LRy^gF1p#_?VHi4*L7pt_M9egYpb2L19^P%~?_Q6MTIso>1niUlBz +z&LNQUXqJJ21=NG&!mOU3kJ +zFflM8FbM_)D-Ht!8U+9Z6sQzP_9i;N@>ZIW53D_

e+>;wo&%Za_$K5C!>0tf)< +Cv^tIe + +diff --git a/src/tests/pkinit-certs/user-upn.p12 b/src/tests/pkinit-certs/user-upn.p12 +index bf47384a8a654fa77d9d9161c801292292ccf4ab..e91cc8a0c04869d6cf9d66f5b1b051e9f3f6ac58 100644 +GIT binary patch +delta 2884 +zcmV-K3%m4%7T^{lFoFwQ0s#Xsf(sG`2`Yw2hW8Bt2LYgh3j+j#3jZ*I3j2{FJAXS! +z*@zwch1miE2mpYB1t^994w-1MgeIP0Shaj_WdPD*<`ao4RB4%B;1!qUi4&p(CDJ;S)D+_sG5VV~ +zQ$)uegg-)nY>J@=`X=55yd*|FF1h2T?_^$o;jzHLsjhabCH_1ucm<4^|1)>iEPp)l +zr`fWM_jd&6^poG?mz%Xq#a40WKPFn(tA{`_dWfKHg0-O<52jv5Q93&va(_@T3CUj< +z0WY&G7%<~VqQ@)3_!$**I?b)=vizO@^WQRD>b+MudQ}{)4vvgomus3Di-i09fLtc+ +z-@6;hAFAv$JCwV0#Qwkzw4gup&uc9{IQXP*mmZ3|aHIBk1EhHL{5PG-IM}|iqFq*# +zTzie!)o?eYrcWJV8pynY)qg1cN-hb-i$7d|Xg&|At@X!`uGqu$VvXYj(63TzYiT*e +zzW?uzBT%#jm7P0PLD3XAQq9F4uLwUsBh?d!2y?u4^5CNAf!qRUU$VQVyK#iF_TP~B +z#onH-o7tzcO6Q^v7GcM`(gz_*e5VOL8@m5}KSnn=rP`yTs7AlY-G5#76XN2TW%<;| +zGoyMDsL9-cF4Xpe-W5T+Uth$S-ql98cUnVq>Fu!0m}q&99V|Vo@OB-Jqh;JGF3lTl +zvmeBJsI*#7V2pY%RTS&g!XUO!Vv>U!_Gxc&XQxd)6Vl|xvPV*NZcZ|!>8=+@_J^zd +z9wjwHLS)!-9u#h@0DrRg5ix4vy>8NYpgnyo-c>t$;4lh^dK4cFHi5Db5SD*&_r}nE +zb@WLfb~v1}6lu6hAY|QXKAGFH_e#O)?iYYb%+{9Gb~n3Lw910jG8+H1C+Si~eJNkt +zy{Cn@nO?tKx*Jc2CypM;3C5Z)4>l}6nPzpM+EoUGx1|H;+JBOrINg(y!@Qtu+=tKH +zmuO}7joP%Ttf`54n~u$-R@L^0b?dmZ8^S3-NKF-!Xh*$WxmaR*5M;R&u#Fl$H2hD{ +zwIM{B+CWT%(V?I^>XtmqmeR>KDCIFNHWpyaa|`t$5m}*g +zK>&|Ey{Z|rxBD#9Abq+Up(9cq2#O?&gp~B8mu@ +zAhNB4+O5c#8OB5Wub0v^LYpy+YvD>1~DmyCA^7g%D +zFAAxaq1oCJ*#e;kqPUvQB?{$)UCWtFos&tE6ngi`#J(zz5BT3#jp;8k^KwF}Mx&M%q=hNf(NuFoFey1_>&L +zNQU+thDZTr0|Wso1Q5U)0W`6LNiYv(7JIIJGrI(W1klCz!q3{|#X5KUyo}{Ke$8*4 +z&z8gsBnxa}BkX@Nu7*?GShxRsy(nf4M1NX$7U7f*_v;_v8QmAi1RA=90>Q6mk>K0H +z#oV_k5pRI;GVQ3j<_i&6FF@?OiYbr0)nN~B0s-eZp5E>oV_kZd6{)+kM5N6N?Ld3H +z)wfb0M94{)uRKzoHZUlqQQ{`;zEjVeTbOk-Mt}G& +z!k=6|Mjv480NzyfPdJIgH0@|a0zl$H>5Af0Dne8-zz4}2lHd!s3 +zxSf>)2GJi2L?K|q`h_O#om>P@(Vb=sW3vWx9xU|H8mxx +z6`(10w19d!;Gs`p2)_6Hl$RK`TEV!p)VPK! +zaxWY{)O03zer|)d_jRj(krvwkkSyN(Nh-WRmF#Qp>Jy!6>^RCj-Npj)j(_z>y@QU- +z@ZL#n!*Zsb&e&}8Rg@SJl5p|B7l(u1YJ(3tl-#D_t_yL08PNf15V2}X)#%GD2*o9PK3%fNCJ*_+= +z%xwkK;lE=s`le+~$?pnn34dok-|t4dj=d{~HrZq*Li94h5LRg+?=$WT*{8sh(pWO; +zx4S(^BW~+)O`Mt*c>{9;je)afv!lqC@}XAxj=mGhXt4NR2R;a7!SOWb$nSJCjeA_^ +z8`)x3k+zM~B(Pl+i3OFdw$_7b0uOA@8<-%=1$m2$wl7Ili8G~0T{II* +z)Mkvjg@Tuz5BIgMk9$ViI62{JqE>~?qz!0*3CZk477 +zouHyH@yBwvdw;FKYYH>yE~}|^QYs(;?8`w5)-WxH@SgoCFKDpSStZV*Oll+`gp&LNQU<5RG#b4BEJ^04G$AzyQk*SVS?I1uWrC}u~MGWb!KEd3HOLs +z1vIdCmj9fXy&snurXzgb$5TcD!>K45?spJD`)LcPDS6?a;V`RNpkjf`EoBh??RTlK +zh#hCXlH;295z7xk!RW`#2Q)Ldjem0>WbPylh7u9DMA``T!d19RnS;bk#uauLlP^WH +zKr2J}sUw8JM}#iNO|VH +zR4xW^b$*AM-mS+(-PO-kX_m@{K<)}Cx}IT^la`VVIVrkTV5%o6Ay#2R8Gm&i@n79z +zMbt?rY=qLv@A2$}MWsJj7#)`LB6Fc>iB5mgaDRksov6|o?YhvA=5QPUwqt8gPxXm@ +zR_v)ai(Uik*bb`DQSA(I#xt|$#v~V3ot*8sDww1rNSiodn=fVmod!NYECS3>?B`l4 +zC9_gt>z615h!;`Y)47ErO@DLZp?MNZ_5Ff_svYCM@Z87f#e9llSG=s7vqkKA{x@24 +zAVHwi9Lk{D(6=eEA%KS{p?QMBW;vLeF4d(a+;9T5J>N-hUruMt&Th(NZX; +zg;H3BzJdyILh*xPTJA$FnWa>4#A|v2o(ajRc^g2K@{+AKE$`~-#P(nh!v**PJe7C3 +z5_&Y5eczza5Qm@ocj@WYs%2J6H1Isdq_%)2l)_`knW#8;tT=){0p6uFqfI#J^T298IsQ +z>I$oO)gY?L%QiQOULxj$9;TxW2Y=Wjja17-rN}yw#1v{vNuhG1XVYTnq3NV0hn?>i +zO}u9T7vs~SBvUb7|BD&zbC>M(@O_=3VZdYIA-K57Xq{W +zgEb$eyZnkRT?lF3gg`Yn;`GqP_vCc{mR^{i!AHxKO^qcyAr#HKLym1G=Weg&=3^|K +z>rS<d`@~O{(9z`ZiTM?@dR*2yj!7Q3+L9Y=oJz%W-V7M76z? +z?R_NTw?*Y%k(hWGe-P+8Xyu18Tkzz-&8A65YgT>Eu^NU)aO;dKf+zvIh^!8ssUq`v +zG>S>q@Zu)SaYQJydZt+TmR>5$RB*L2L)*Iql1J@C5{SP9k06@-k=3HjQN5y=Z!6>M +z#MH3t|9_5JmWH8lzjUZp;8L7rnh;$az|w6Ql{t|{YprFA_j_1tr^r=ZC0*U&Vlo(SJ1cWrAPSUH^wc|vrE)kR +z?cXa(1TcEN!ANk0%zj|K^A`j$w&^r-JHUqN9e==jAPlP4|2}*i-^~N4H&WVuhuT%A +z4NMZ&L +zNQUwUr|R0tf&Ef&{?f0joUStwUh9&a46T=}L4X(YEZ)q{^&| +zq_O=fhFO=twxQ)i)ictPugP1)@GE?0LfiE&BG71HBSVhv4uLQHv@U5l-RAD{8y8ew +z$5lp>NU4?E)-f#wzD?C0;y)WCTktzeYkxwzZ6!-?eFHm^IZqD~<*I#5Nm>zFieKX4 +zO`ivDk`gO$>PnSjZ?5Mm(X-u4F30DqM2^|IdlXJ&GbBH20*}-6w#G^`AzC{)_^YHP +zYZO5Hp=lJ6h_}SZDxfLEq+N}72EF?itd)kRNzkGDZ$6hI%(z6HFW0v0u%S(N#D6-K +z^~oTy%zj-t7kvAJc2uses017pyZX<;A%Boo`8qmbTi-;1Y+P^ZT$r@+d$}-C_11}k +zfrtB;5(a*fFE1)5s&uvNSj+0tb8mv+xa%9e2KE^w+Ijx)k2w}!L7tY$fzGi}k&=h< +zHNO?Z#O9U!sJ_o|ao5U3273fijemRY*`f^vpTa)i2!~LXZU(As)(9D_7Y)|eqjCXJ +zH8YOtem%7=RzGk|{=Hx6<)X^22cHo>GlVeqnJ4Cx@&=xW$QMPWQH|mS>K3e?{2A4V +zo*wZS(hJ~bzc-m{j=qs!VdsL@a`-J2_N-Q!cSRq)_?OXZ9Cq+ +z&Ips&2Y!=ahQ?`+ayi9Cs0&Erow>HN1Zgtzvp0=9+&N9_eJYxc1dE89j*Yn +z)|1D*i0XXN?4up^9FyflGJn%K275);(YWZ@?;KEO!*;z)*ooRISbfMiBQXq+%Ya5T +zJ}?c3Bl?+2vj^j|HI{X2Bd}oimixhfqwh;U8G+h2>f0Q?OZ|!sc5U +zk@CXsqV9GQB7#ZXO#_4Tn4C|v7d;I#TrGIYR-@TSyxZGTI(6;mbh7%m!`Oh +zp?ib=*@9t{)p*Q@-+$p6e&>}M9yyg&uxh)h!YB_Wx&J(J9Zt>v*YcD7#86EfZ)P}{ +zCieiXHI$g@Tc?Mr?S&DO7lTDtTLZvS1~(hg>zX6ltsNC&M3bF!r(|O1P}3^VN`zT{ +zj0dB54PR&b<-8RtzF0iRs-tOYOm)n?zi-6OiEbwohaba|vVTXOL+zixO!r@D#@Cex +zyX_Fl^JboqR&${ijvoYRRO~gCD7Uux+4z?Z4iEO6kyED0K!0J(j;{pWhDVT)5y02p +z(W*ESKWz=@q+Gl;1SZiKkK*Ha*_1VSL(vd1!nf6TIjp87EpQ5&e%;PYJq4CDW2$Zw +zs|Uo6aqZ?yK!19mroKn~4oT|Yj&p^PpwjvlPv)oF(oKp%i`YpnX`Xl;*rBO(B|=NC +zcggoj46fA+7bww@VI%k0<Cb&LNQUZgIobWQ|@8X)gWKEkQls>5bGmj`vYHd#Y+?jX9h9+CF}@qc4jy(~E9 +zpC_weF&>28nIZ!*fA{&swafGQ*5rKdRYOSQdo8_GT-n@a>i2Yojm{FE2EOp-w)#9^ +z+aT%9DN95w(w!}IyA{L&Xyz6qPM(ESsd9zoJPs6@lICqC2}?Z4=_`B}1$DpDXlR6Z +zSTB419!46STDltqpl^sfG=FbYlwneSTp_q?8}f)xbZ9{O9-Wb>tHawa_MLqYC|2J( +zX)OGzDQLN~OEm}F`&j#osd(ZVMA*NvLxKFU0)G;xk^mpU!-s%mf}lN)*%Ltli!tr9 +zE2P3!^=Y1X$0i=iokHU795Xm8+ZSG3jrI$D6OR#Gi_?zXobn~Dh<^rWm1JEZEg?$5 +z2jamsVE$12jr9St4^>^4sZxh>LgApOHi}EckX77*F=0pDc-U~>y%iu+NFU#)8Rix% +zj&nnj7M?bw8Alfcj!W)BJm(gb?6>s(XYaUQ_e0D;+psl*K~&|egZI(KmpbQq0wwT9 +zu+AcxvTNZN-+??(+J80aN;}ltl455DT(q0J%D+wlDj+y7L=8bgAq=WQ>L{sB0*YzN +z^+)0y0b6gxGG?EN6$SD>CA-H2V0K*v!X1fNu4(}Oi)O+bk6x#Iq!&*=9o00PU5=iV +z9MlzT!gs3Lwxzi2AqC_9Br94g*UekyjX?7ZvMchRD&Y$WAyF$_0r*Rfw +zziFU*CGJps%QP4;8Fg?z(0J};G!9N(iOJ`lZqJ1!R)6#f9>qS&!Y@bPO-Ok?W#xQW +zfQA(`0ap?-cEq|o^9&yEt}k?4XkTLsZ#KZVcj^jx#{>xi(zUS;nlI2x9N{&<`LL++ +zcAEvFpE{Y%E#pxg!Od}^K)d-hGcmHExdQLw*v@q5`nes|RvFM|#ilZYbPU4$p^@y} +z&z#I@bANa=I5gyY{59I)|8d1yw6UzTq9rOIjx8o9I;El`(POGpLu=+>{f#2MwaY_3 +z7^25e>dIDS{ZBt#ai!_n5yXH~^tOBhr_@$CKi44oqzJAHl}~@&t0VqulbPSEcBF;k +z>2$wH5qqPbKawRqB4j9ttg?JOiH+o9>s|1qzke!$9d*3;%M7g +z29-{jz*kZ+Kcq{SjLN;n4Ber1K4yDXYzWr+FoFey1_>&LNQU+thDZTr0|Wso1Q6z? +zUxJolb~{rn@ALfyA$A0U1kj)Bvt1ZK@Ci6CVTSS$(6{2;mb9_6ogc%2c%FRB0Na)r +z*%_E<-(3CfoWq-JeM2LC3qAF09L +zg{J|A1^Xaq=epb>O)~!z=%%-`yOXl3%PjAvF)FBpL%PQ8wTn<)p=DR)-dB_0il)sdbjsGpBc)#n@$o$#SnZI(Vvx(l2?*rJ%SpcdNjjQlrd=@Beh+$_|6F +z8@Tz~KUJ!eZqW~?AV$XyLUVIO%YSv(JkC{tT#X%aYc-b9(YI*AI#| +z@MwIoBm5eVk#W`oKz6qodHvmIS>8*z%=9UmJ|M-{*v1k`kwThPN|G=ssmY6 +zdlK$V$NK_C^k`Q0!lno85{Vus_qos^`Lp0zfxv(h17en6C*u(a08qe@1AkqVn0)b} +z_Xt97qce$VS@%WK!5l~<&G+JOPggXM5_*(NH(7lp8{Jpo+{LndeBBFeK|Qn +z9UGVTdha8uxo_%X9MFciV&krC4;DpRftzbyI!nYxd{sPcCixi!0qFJckW+X*!~7dN +z#qLCJS{#C^lb%_p>cE3Gff5>B7@+UaH2G|x!e5o5P%R%B6vqemlYj0D+)w-FeI>(* +z0Z%64=+!6EARd(`dHMu&ZEii^ztJXgr@}do_>hq1`p{HS5F~=?zcN*LufsIudMT_~!-%1k2Z3CDO0m;OS8?o*&w56(0V%Y*=| +z&6KdgoIuBBWarFK(|-&5b6I2rue5K;BNY@TV|7>-A62B=7|2=;u_KME9kfRGO7R!8 +zk!=M>VYHe3w$voveBEaD`6q1-Cq1zx1)QL{#hAICUqkOdQrii@<%vvEX91z>D9Io3 +z3%c+cI9lYE^hh^AiBrSmRh~J=uQ6BwGHyUW)6{>GMKCjH$A4cY;o4ZsWe1;L-{B`) +zTrX5nB)#PSQGLx(y_osNPd*Bwj48Brqm=*ep +z7?tQkxb##(ZQ^)93Wc5!#dewm80kEjmklRcG6?}+1z!$p^Jk2Oe_JMX8L;k`RGGFE7$_Hv%ZKPxRiZAvez?hfXPXwNwRuE|3@d +zdj-&lv42j6S5hNDUC;L)_JH0QA@L78%wofg%ep^s#(#TzP%4Z8>ZGBHIXyyhuf+Yi +zM3xX3mKikVT7r?YF(oh~1_>&LNQU; +zK`=2e4F(BdhDZTr0|WvA1povfY+(!i_~~rbp^C#yt5i7iN(PLf-J39FdDrAamk=e% +S1PFt)bqU_LN^6M%0tf&&^grJK + +delta 2776 +zcmV;}3Mci@7WEY(FoFv40s#Xsf(o|=2`Yw2hW8Bt2LYgh3aA8v3ZyWC3ZRi9JAWcz +zf~^6)AbAJ`;A0$m*A;RX;&9P-0dy)<6ic +zG=h9$G2!QdbYEt*c?gO$3`@bOmrgFTNbozB-NlAbC*A{yONXB%C_apWVt=m9^0h7* +z*?3em;(mZ;7{UgE*^=bjWp>G~J#?Y+fR&bKOal3mkO%VC^-Ez^Tk8yxwt7m@$;k^;0mt_~ybp!1yQU@#i`pO1MtTs{ +zHabcX7Ry$2vhmv`Raz3Nzo_aqaaVrklIl$iB97R)5GILb_*Bm3(tkzSOZ)b5IhLV7 +z18HncR{#Q20j`Stv^2^zY5kap#QcGe)b@%+qc}wgP6{)5*#!`fl6PU3Upn+Y_>xI? +zfsjk#HF2&lV3}zfBU)o)!zbAoc4>XEe{teOdJ`-fdj_FqS(o2cJn=r>OJ5eFGs^UA +zapCv&3$#-VW8S6m_kSVO^*h@>eY1IxY_S>As<^a_01O26Sx}H}kyWj$CxawScc*|AAAe{9 +zE+JcamabwG8GPkvRP>l1i1{nU9ta}Wl71H(N-t0As?rI_ioj9#*!5o~ENbw6tO5hG +z$96!&YHs%wueZBZZw~*KH!_B$eD!={Sx&YtHN9{DcYo_^N`ke0kAu4+P79utHa89c +z)AD9LSXCcQk>ILDAq!Cfu$AR&MFu_)?2$ppSyA%@PB`#*g44cDw0%9-HQGd1v3Py +z!ce6Hu^TKIN5~#rt1B%m&$NZYd9MrmQl4b$k2uObMpm28DcZrrFKb0Ttm4Z2?`Q(F +zY^;>9Q8MHLYey(85vpj4+l32cdPWo+D)#OH>VIitq~FY;9jCJ6a<5avCVO;E08r5D +zSG1l{Im&na{@&BN_g=`GVh&oM-8}MDDtLe6FoFd+1_>&LNQUF0tf&Ef&{<-evNXlq#YlqN^2`ojQQ9HmKs6}GRF+G2Q)*HSg$iMnU<^r9LrFn +zxi_;d5j$8#-aZkrIi>3j7q|(a0XUem=tm>Nb}nNxMG>I*-+F&f%b8U(1IS|gXKI0z +zFqNT6(Uj?AS^2AJmXzFr2W;!B{>^Vx&VLDIh>r(e)E6P|2-iR>d>%7cst +z)|fk0e>A-5)~Ixb{jf)u9d~a@$;Ue2b^hwuq!?WlOW8*!jho)y!_O^q*bU7c_&t<0|Hy@G1@YR$7(n^F&19)$qXKz?Bqhq@W8l>{Q&u<#ZCP82KH)Zf>7(T?yuy +zXGoA2<9<3(Utt;Q&~`^Cg8(aT@!^O2o{iyARMlt@BwEh=#p{5sNEwe>u@1xM!xTPf +z{cjB@R6p(a@P3Tzkch>oX42R~BYzdsH}hF&%B1a4xaXUzQeob>0h-;WoL>f`C=2-_ +z+?HS_8A~=i`NAu?^bO3bj5;Q9@Gq7~^Ezf+@(rSg07VgwuECIbZu9FRm7ybGqUAL? +zR7yl-`Mf>i#7>75pi=AqG=Igf3~}5q2<2ovXnupwoF<{75Ez +zcV`RFb)ap&F4!IxgZ}Me7xPecHIT$;Q6FA-BMHlMvro#iGlRxRNtMA?I}Nif~s +z4xB9LTy+J=1(d(NNEkKNHx!^IF!m3CTL_mzG|Lm+qD#hqIO$qkUa<6w>vOZJ&Ak)9 +zN9Gi+Vr#_!jC`(#_W~`|?DPU%e!rq@$nOpuW~Fb(C(B{$pmqr(14Jj*1voMah#X2 +zmbl}dO-0R!J+{rgTo_kufNZGxL%bD_65DP2ItQG>BBz|#;LGers8fS6-vgfP3riv2 +zIZ5_@26Y$`o!RCwn1Axwp*XLPl>P=SHk2ynIw={bF+x}_sPmTws$a&G)P=(L9xEf; +zLPH|=&mn<~cDxN6=Po497XG1E?JW*UhV{X1RCR1iD1=jyWv0E3aE>pobEv=0<_32+ +zfoWJj=tC~)VmD*yV*N{+a=kfqsTn~yI}%5e#(gjwrk&Dk34dHu2g3JU_0P{wwL5KT +zZ@2G(NB2WIg(L2M;cy}50ifkZ_}n54Y{8^Ua&N;Qj_?d(r3t?4b6YK*80jMHh03Qu +zi&_K*!^0bGY=gwLu&4S_qj}z*{LmQ_iVGA~-#u+1D@-*0F=c?J48^)^MHR#YRH$6} +zb>a!@^}Ar-RDX?L8!uaR;urhhC76Vioep{Xi+w@7ilod#-zzV7IhLo*t)6x^n*!>% +z1_9G$)o=iRWiOWc!_9H_>^;Ksn0YIJakz9$%BFxPdh@PzCrU2PF(oh~1_>&LNQUgB +z!rN`BrcJ^Ohe`m!y#xb>NQ{#(`z%T5F!2#O*G>G~9Y1B$tAF^=D7^!~(#BjZx-F{G +z^x3%g?|7?Hkd{-0YH5t*Rdo2X?|+3mcuxvN;&S>5_1eT(qT(x52zq^KY|HMES@+&E +zp!Oqh18~73Vp*Jp3(0&@a@|uNWKk>z{D%AcItdZY^Q#tZFXI%q0IEm0FKXhy*5b$9 +z+GasSZ7Fl=*a3g~>TXLBMNrC1VdF*^x+r|ZH_Gzcqm)*qrnyv-YX?aX*MDZ~tFG0` +z^Ke2l!1Q9x;ujYQwbTgiZxgrgH`#P(qDO`2T*ft8T4RjoRc83{mS8JoxEB~7#0gjx +z+tive>B*VgSOs(>1U%w4T=s!cQ1y~?fv+v$>AJGg8w`s<(0GUVEe>-f_*GXPbEwZJ +z@TMDrtzx^BDv>4R!-4YvFn`WcgvasTcH1OTNqcoV8kt$B82tUtpRiX$PQ)wkp5{t} +z)?p3fYtv6h{E7BP@YDq^^hGRwEr+;3?2}{(tSvt7&zZ^>#H`F!949k<-xpr{{;9zp +zDtV?e)Ry1e!i7Jg&*k>7dmwW#q#n;eOt8Mx%Rd2aKpl4~ym)!RCx2F~-z|>d?Q54S +zbh=;Es8wX9H~AcxB!gd`Yv{dKYv3SYZtJFuhy-=%I~N%?7_12a2`8#qO9;)}q}s|? +z6Yq8WI{r_8M%lK?@{uRJ*8bV(rwV?^+S5(8saz4Wa{@(sx!?tewL#bxkvN$jInMZ<~N077QsX0f*s0n@MRO0ggV)O{+MYL52| +zD_Qu^Iq=$v;`lIbEE}^!yO4Pu2NTKNpCM~vyDd#ZW{_f=T68I`1G!n9V|6E;0xWK$ +zMVJJi5@$HHpOZKnrm+wnGJ%P0|5h5YAJ}NwwC8lGJ&%vDG=GT=v(9PE(Uw7P +z0!+ZeJmezUaISwf0TkR2jcE8>$`w#S7f_v0R974kk%QiJp8inpuCXe~j&U$j#DPM; +zvba{UI+?eG*q-}vzr1$h?MM(Ib!)FpJS;+BY&HpTa%DiJgy~x$CJp7`XQi8 +z*lml!5T65{Op0>wuHAP*c>)PwVIyE2gb)~?eZWlbJ!p2-RLHg)RE>m|lR|}Q{=U%0 +zo}D~Q!ZtM}jTp-co>k#HE^0ZnM*G{j*Xs{zpJAwD_6*z5T?7Wi +zypIqyqWoQX1?O<$Oww!WKN@+P0NUjRx;gnk&KISm<5rUiP7k`UFoFey1_>&L +zNQU+thDZTr0|Wso1P~jF*+0)PkEs!3QR2j6R$>H#1kglS1&YtSg;OpOm6~NrtV4vPWlld2Ews(yNbZxe(4nR+$T))-e8N?d$b$9^!ypWdooRD +z6pI1Qs15?;T?5@i>UJA=nyNu0m?ps+lm98_Zo0A+t+e}RpX+!f>G3{Hg^u6fo4LT1 +z4Y{a#T+mMYnY#W{qU{X@B!6T|m%Isc9UEo8>zV^Z9L9?17w>9Ujg30PUkpbf5*il) +z&|Zg>8MV)WoRDJd#ewUABq5SACj~6S38u#ULT-rG&N*DdJ@Hn+EX<9U)cEl5v2mVi +zmqUCjZU-u2d&A^l!nNL>Tjtf +zJkzy;9b{e}lVX%pscpa}CD|T&4_lG8*YS?dpSkncWepv2e&;2HS{*4*!|BT*m2A?f +zyjVW1HUQ(_M3rpp5R3I>q#~s-)|9FwJ%rOTwxl2FMp&4tsCFbTVXO2tVoG)vz`fmN +z)R<$E#pT35KAYbTw|@bcx$u3h{1odhts-|_3YJ4Ayla(y0OOI4`C7W%+BMtMu9DR +zLN@8T_7`usWF{4ezK+d|fuB@k4tw^8R!x#XZ^&}mz29aP_raW@!^P-{vLMa|@PF|S +zhs(}tr|&S{zJE{7YU?ak8oNr`=W`fgsS4~&^0h#~(VJRT +zNzH~lq@$yZ(W^@?`c_n0MVf0+f4^>KZJcWBRpBJ1NoZM-&i&-9Xoe! +zmv9edP|3x)fnY^m)?k@H>w04+$h`_@j98wtxMb_Y2{QVtv2Vhjf7qLrz^P +zzfCU6R%@{mG9Yn6kX(&PQbCcl4jzWK;LKYtF(oh~1_>&LNQUg +zWkVjqlI}v+>hWZNZUj*Kq67$ty|isR%^-9F0tf)%!(&YV + +delta 2792 +zcmV_>MN{htcbO{qC=J&uM?~NGanbgE-J*^bff< +zUL85U4k$LojjclJ{^#hk69ix0P=6p3{W=cW@;J}jXSEPY*K)tO5KXO= +zDp34gOZf$JI>T(od;fQLTl{d}D?LMSYm|boNM-&DpOI*gNxdhZ}bdPsP-V3jIx6 +zS#YC|Y%#Qcz2$cGZXgSwA( +zp^gh0BF&;oP;t5r`vDq}MSpv(oTT?XWo$BF3HTfG#Cm-G$X#COyar;r`l_yWRsuyp +zjrLZxM$trJR(FC|;&F1_fvv +zlT~jFp~Eovc#$rZ%#NJT+P;Ef80Oaf9R{ +zOpW_P@)6@t2VYKWW}3x8$#CYa;%anc&G^~Ur2V-rd#L>n7J)~*jORUD0N#m1LiDFl +zB&?Q*64N(fqjrGx*oF|qZ|R<>da*~kLSkj=XRG<@r3LG9Z`*3FTNX%lmC5B4T~(J> +zFv-n}iKXB3?7ZeYuYc&9GS74XBxDCRdBBF|yIE$fUxbe0K(Obu;3tumH)59PWVH*+ +zz+FmMZ^+~l+V!l1r0ZO}N2<6B_PMH&?VYqs=-LS%mX1X@sp)x{beSD;A)~7{YY~TU-k$-{C;hMVpNq;mVqC$gb{2Xtz#6@FT +z{VWSY?mme#0Q8+1Z2R$5&R0^uNckWNtn&l62raaz_Rv@fJ}H`6N6&t$-qmQZi`0V~WS +z!noU8xPAZ|(OodN!Y_ylW^%s>!I$n`^*O|{`Nql$VSjtzYgo;WtVGwfOGr;9?$|xB +zcs%xxE&&}izyxcgm)2gfVyWCAT`*z4tvURt&T~Yv;4D~@cMQ$sbGeT!7+;p0p5QBw +zMU{9IVf{eaHyT}&Q{kmv1!msC>y;CP;=8GdD!=>6MDu6%gpdLzN`zEs=jdV7SuMgm +zSef9I4u8xGa&@P0{hVpaizD*w9ysr@;s~)?UPY$$=xMStm%-8_cVQq(W*E)bMfTx~ +ztiPTUhk1JJr{K03MHZ?_uNADjS{qhZS>Plq2pIDcZSe +zpdVNTFx+6=J0GuhMj`dM%6hP&L +zNQUr;S>kF`=lUV`cN+L-;%3g5Ai66u6H%n +zyfg~`$Gs>R{QVz)tROl(k}JU-jqD62a~NzC212U{n)$nAgsnGjoPsM7R6NMA=VGH` +z1j%@$TqOIpqreVYF{_P#Ld?sZIQVS;Qh)J`TkyOxjU_HwSFW=@1+yU&O+4(~e1pZW +zdrC+`8zsTaGDfQt#7I&Pa#$O{DyBOl>_Jl1(9c*lL@BH;OO#5bXtm5nX3C~*Pn69s +z(^4r6qXFwhf*ZDy)ZtW;)ENRkjc|#NpZ6iLJ2cnU$Z46(*w{@+^tC{nR=N4%9T-0{S0Vv +zuITX0>W_bbsp#~8>rIdGj%n76kYuf?>yX)bEPeHczbHA2m#H;(n|w!Q4IVX6sU98{ +zOlrpj6Q_77iXS2=oFm3wmI_q=!GG|ZxMyJfm@W36)BqdDmFEysiCoWFs0h{Aeqqmk +z8T93$tHeqtTnPI#ZNj;&P@qq&2+!E8(q%k0HF{#(jwR}m)3Lz()!)7BPi*u-*p#b3 +zrLNe1(4tB%&d^e8d{#t$ImMt?Vq-)VFbRK@T_Yiahm~7)-B&pd8gxPtU4O8w+P>aQ +zP9X72&~lV9$Qpdl3;-#jyHYb%NM)NxL<$lo(9#%8c!mweqK8`i&|Ky0)}^G8PW(W%*6#;qkrM4%*TGa!?K +zU|cE2f76znLD#xzxyn;rmw)6%EH1ek2QS*J((#_RgTyYO#?@-CqoKDk8tM{t+BZ0R +zg9e9H38hKach1c+6Xf9Da}2?$V5Rk*R98)aLVp2^8bXx7{A@Q2pHfZvEV%u|jMOGg +z|5PWJ_$G1qmwVcOOVwerb<|Tx^TT^v%SaCo(O%3gTXbk?e!y16>VF;94g#dwH|PI- +z&D1MMKVRu0{ryL$acyjbc`LtxcnT{VX0HU%g2@&XrH+ZW=-~P-Jc7{3rh)|t*!EFi!P9*YBAtW +zbu`)yVVz9dAb+fy*IJEkVq7w={{*u3gh?3@!K+(YG^T3vjiU}7w=Z08`s6Gaw5p&LNQU^P7i4fG53N5i(Gig<+?Lnz6wQE*r&6Z2;KdIR$HEXY^tyJwjg4on9 +zMJuYqtgX~N&$;(J_uQAi7vJB@&r8m4oG3IN?nn)yLF3`vP&&~_t;i!r5G^PV4~K*C +za9T7TPLqI=2dt3wb?!M|9Ta8@$m(?5~;_Tn(<8A}joBO+BcSlahN)>Sb`>t=)-(^SR2L)txY=xAE~PHoHBCf4M{bH>2S9jw`4h +zp*y-jx&|=Tq_=vX$0AY-B-pr{O3}~!a^QKw^rZP3r!8E~<4%RzRnXkH>9XmKSZbP{ +zaaJ*AU$QA*L~%RS_EQGj1G`WJ7DmgunlvxDG={jJ?-epJse!y@ZR4+bx9Q?#sdYwy +z(7k9q)PNjgxszN|6iPwUknCR*%y^Qb?DE%DYvjQ3 +z;KupDH-(s?Jv+im0i-zOqS_h7X4{%q6B3|6&!@UWm^wW2r4xF|mkdExn4~66{`CzT4_Ik**^1`!x}fTzV|8m{TK6!0MWB(ZeY4tK0dLjcMvPD +z8=e*&*4XH*4v{Q1h2g%3Fjv;yT>}EoVd?9-HI&GSk%Pt~SySOzU&y5j-YW|H(ymTw +z1G_2NB0UR=mJj{oPOpv^O!d8MXu(!8&w(wML`8o+#dIfwKC>RJ9>RAeghupBEai$e +zDAKej36GGn{2TIG%!~-Q_PI^YR3oQST)AK%A#{^(z(2e>rf&a3&by;mOTa8+PRRHa +z-^wA_U+>r+QFr5+>p5s|pY~>EwSm#>qOt)Nqf@6CP_M$KA*G}bcej!gwJ3*zQPO)Q +zcE!oFOtiDpne0?jxphVJByH8c!ib0&g7|*$$1HXsrD_TFzB +zrG_#(dx(zjH@7`{%)6&?2CWGV#oyFiC}F9*)?V`SkA$n6*urPvef#ZVsuY@aE~mwi +zfLZVOxpYs34^{3ih{Iwt3J%MBwsDN@US3n{4IdSbxOu_vBq_M10eI@=J1FX`4=u}h +z7b!WZmn^TKx7NOwvR(EQJ?-AwVb|>(+HxQ(@}fss)htL6&IySIxFV|d4-b9Yvz_(c +zePf1g3;EKwCW`Pgu}r&Nwiw5>4p0$1R|F@Ad*9EUAwqU`H_$DzHS;+yy>Dy~SPv!$ +zmkq}>$Zz^V(#udwpnHpk)p-ziT_zvT@iwpeM(IX2bbCL*f55n1LQdori~D(0GUh8Zi4OfiR-)p|AgM +zGN5_DFy>1zgV-~8AVb3azHBo_up_yK-RX|#8f(whe3lu~8= +z>Rlx#>}5YmM^rEltM^1$Xx)9`wo{qb10o*m>Xy`;bHRtlM} +zZ;NN)^q}BNTvndhQ?@$yS|;Tr^u4BaFvdS%HZ>EM%wHSflx2KCj%7vqE=Pto+rN*9 +z21WA>{xOJ{T7d8o7MV7X>L|Ta>(!)@?25=6nd{r1Bn1O;w^^R6q@iNUl@~<5k`Grt +zt4cy_*okVY%WdtrNQM1KuBWpb4Qesv1*;K^T|9@TnSs3eA(Cz^54=Z((46M|;%oLh +zsGs_@Lgj^K@yCR&!=s>ti(hn0WJ!%oQvB59o(Pc&NTW!ES)k-IY(7i~q|CgZoa^hR +zQpq1!Sdc(15I4h>i5jn(4Ky68x6iUWOuL_jt-H+BCnoZ@!V6GiN0MNg=y}@`g*u-V +zC)cuzj#&nkk&<;b>Wyz$fnuR;6uI%S@#E=E`^qe-8I#gnaKxnOFO0(}fzq(wH~hi+ +zdekEzl#@Io`zB#+ajLT>%~{Ny&d-aFH~-)&gKw0$UWsSsw6{_YrsbR_+(F>MMOwP2 +zv?S-H0J1o)Pna!}jc7d%4wbSOX;bOs>ThE@)4%djgrNvZ>mhajjy`1?f&q|iuLRhg +zehh18kl}yP!G|X@Gm`KYlGDk1(~HZc=c<6J@dww{aY6Qrty97R-B72@4@2yDEvsVN +zO4TxnDDsD0ykJu8oaM>2W3)f`ZQz-jz(%KYh03WnD*OU=$~!l(X{Fk9?CXlr$jMxw +z&4YBg{$w3lr2MG!+jmk%$X#1C8hxEuGbq80I?zu!86*YbN3dx1@2fmAim6hvO+bIU +z#eRn3Ab^rg46S~M7s6vR<;i88WSP<^qe8v(HjtYp^i7<5*IA5%6fE#3@S1XdAl86m +zcpPdhk!Is}%eVyhaMQ}v|MGKVO_?U$M<;JZw1H8T)I+1KkgCQz*|>4xv5+eESa~~w +zV(ssuMzr>CN1hjN$@^xrtY35-fSQH~hi%0jk0IU8KN60+SAoZC8d-GF!Wx7^TelGeO~Jnmk|pA+8J`#v2b8;L#Ri&lNt +zFZi?Wu)s7TQiBF!^rGT_I1$NYEv&1L-zUwHU&}h&7dNZD3|-tI&0n9m0L_9i2rN6l +zDRGS|+@7L67nFoFvS0s#Xsf(p+D2`Yw2hW8Bt2LYgh3cv({3cN6a3b>IXJAc~$ +z04;L?h2;VQ2mpYB1u#k{e>HFuQb-0@)w8+8*DP{D$KG=;=xRl2uvKUP-SRRE%$NKP +z_D;2NCAhd^?|QhcbJ5E7c`-26TMzdlG-H?6^IBeoE0#e|QM2rw&&DIM3C+3&2a0ll +zpPL`9ji3aw?(A~Q_bH5QAB`HfT~I=G`cK>^k-~8=RAs!fh8npjTx1 +zio`$Z>ZF=$DSVbD4xi;!NC!?`eIqFD35= +zQc_8A~;(#IIWCvOKf`P&2)Js($WT +z1z-??Ow@SVupz2ChgP2^Y=0o#*~e?*$0TAcDclj?IADVt8o^gntLJZBu=o +zlRp{i%IZDaPfUE-$LP%)Ua~T(Bdt0G=DGbexi&hghHP;^^f<}zRlnJ3GgV60GtOPk +zcib>&Ab~e+Z6==732Fcs!<-3gh>(3UIWk_h>u`vv-;vJvM|KhjTN9G*@n5_xbZnmMK +zlqp0G!V*18sL0-95F*8PQnOybN@p#c%kb*&^aa55JSKbSAd@qO=Ht +z422L +zEQT%EbQpx1)#*Gv)47 +z!L`_0ZJB+>X&W4?m4Xpk&GUR45OCpS-Ac@br?bG$K5WOH27l@cvz6M|^4ikdCcj~? +z@A&ePKz3o=>_;pjNUjLI{a*i~A2Cm`&wy=Wnk}HZ!)%{@qd4Cdgv0g1#?}yCqq93|4$^$^+_&k +zJa~z}zH{53ynke+y3lMnjQq2xp0Aelu-HmWXLFfn2Zo%7n87xsG^uG}b2CZ*u1s9Z +zdy6l*(2{|l#uH(Fg~MQyrygWvH^>pmCkM|1n_(Oa%d6l_c*y)EJe|rcT48Q$4-q9{ +zd;$`4t5f-+&fM5}8vs44&d`E*VzZ!Kx~GhFv9KFoMt^WQmMpIlho1dt%_BO(+`2Lp +zatNwfJ+p4vZMjP*m8(};v7%^J>Z;rDPy{%kK4LhfuLy_D30LYt***zyVP-NnNeD<@ +zGY~g=yXsBrn_X=!tmk!)LM6?HS%;t(HMJ%Q_8-enJgcrn_sO6=M%6GmrDCuouDW~1p-LREA&0BHSeEKQnj3ME3_){Ru4kMWs9nx6eJ4`1vHrOoBO6WNZGR{?^ +zEfRoM=%swpDejYTaEFI0cJp^Ht@L%c+@lQy^nXs75zrK4$%sP!y)m<*xW9H%@fLjRzS +zFoFd+1_>&LNQUeJ7Gnm8p68cPkyaMp;ydm +z;5`lZ-8TBOTClg{8b2gEfR$AC$(l*<$HmjXkv +zk2XU*+fTwXqcsMYaZ3q-p;PK((PrSVUOgD!_f+ +zxEwhbf?;sTV9;{2qj=e+thVm4&q+rqRZvI3E$OXDELB<0qt8X4|WJgR& +zA;mly>0fgus?*HuYZkDa8&PzLYY`{)VN|6AD5DVz9hPB0H|cXeKd~iK$$60*1@6KW +z6781`Wt^~gq(V@LHV`!^8UF^$=qzP9Z~St~brXD2cffcLQ)%SW+3k{*m46rbsM@(z +zVmdvB5fH3}m=m^afNN7hu#6Tv465|&pl|0QVo8cOgDzsf96G6OAIc1>JH)_kiJ%CKS4>>XVItK +z0df&%Ir0A#%dzm{a-{xL-+y}K1k-jf%0*=Wi*tj00J0}10?%6)ypUZJ9ksJA^uCwA +zU5oo_6hE*n7H%zwo}j{S>kkC#VGo5P%uaH-y; +z9xeJ!zLp4E-us08h0F``IjL9Q%D-E<6S*Z@f^7;~n+PU-j1vc-W`Anul8%C=xSb5u +z7r0>5j^Of_V(=`5Jkb~jw{)rQzSz?lmA1B5fIF^AldA0&srn(q6$tx(<>kN35n4cE +z?Y`#QJY`_$YGKyHz0lTxyY@^*MkI>@K_P<$huaWnmtRl$s=QCNW>Q)%O~1b7x8OZa>s!LI}xafM3IiiEeV1X6v0v^m&_bRB7S;B9{kMdqBpB#o;WHIcK +zXZti{8yqh{hTB(4Q&s{4ZNd91F&>cQH%{n1i;7|BuXezD%73Buu9D%H$?>u=EQI*3@^(1e84N*6QZYbr+~cRYKueVXW#rd?}8~s6XVg0MS^}l +z>j!&zJjkZ0C0Bijh>6a2w@ocN@A@brXHXZn+AJ3kASY`zaQm-BZ>L{LVlV^$8R&lo +z$7k~Gs8nAN#(&H;;d!1sK~d&LNQUXqJJ21=NG&!mOU3kJ +zFflM8FbM_)D-Ht!8U+9Z6sSLOY_+{}*ZArxG2W!WZkmtKW&{Xzdz-Lrn>2+20tf&? +Cp*q$8 + +diff --git a/src/tests/pkinit-certs/user.pem b/src/tests/pkinit-certs/user.pem +index 182ea599ac..7493de52c1 100644 +--- a/src/tests/pkinit-certs/user.pem ++++ b/src/tests/pkinit-certs/user.pem +@@ -3,26 +3,26 @@ MIIE0zCCA7ugAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx + FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG + A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz + dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug +-b3RoZXJ3aXNlMB4XDTIxMTAwODIxMTEzMFoXDTMyMDkyMDIxMTEzMFowSjELMAkG ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owSjELMAkG + A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF + U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB +-CgKCAQEAz6VXmJpVq2zTIEU3gUF7pui+Wg17d3QX2oy6EqqUQK/pwWtrvmBIaYcn +-Pq0ZMrzMhNTuyeLjb1rNNkL0hCdS3/aVbx1bOlkPVPlW3UNi9gWpXOOE1/N4QMrz +-yKAQ1/Npf9xjY/vpqsmvRx7AZpq7Nq7HyF5hbUKMHFaaTqRarhoP7mOCByG8F44Y +-QTY2RXcw9te63x+77c3O64gbtnSKXBC/4pS9DxBBv1ULB2wOH8RGxDiWgL0/iO25 +-YImKQgTvwbENw4ygLV+0m1b+YEJLaIIeKleunYEMMkzIfFmMemXRWgNHuShYa0Pe +-yiwTBSRdW9Yi4qzjfaHZ1dD67wdoGwIDAQABo4IBZDCCAWAwHQYDVR0OBBYEFPQX +-pfvVBF+0OJJ41JjduSzecrQjMIHUBgNVHSMEgcwwgcmAFPQXpfvVBF+0OJJ41Jjd +-uSzecrQjoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz ++CgKCAQEAm/1JtzZBJsdadmOTnkl94508ZSyYo5xP83sLT/SY5Cri1QKaFrue2kGg ++gl1QEOExBrIbdAeu5BftqiC07HyGgugtRo0qDHMRnQ4tsNExzYz69MOkFE4hMYjU ++o+9C22GVLihyoq+oELN7ro30u5/MCO7rULIp0HekLKQ+uANVVJx+xnW3bMJsrRIX ++Zx9kB0jIIugYt5D3n80vdIjHQJf2BTjsBWYGRJD4sTElGFtRIiD6m4puonRdUgtH ++UHZ7OCKTY5sU0PSGxFRLi/ykqcgPPQddHYCd5MRJj5q2NvPN6UYDbMfzqni0uDQ9 ++qdDjHj6CmRCHNKvkKaLdBfhdqFKuZQIDAQABo4IBZDCCAWAwHQYDVR0OBBYEFJI/ +++nOV5fnNVxn2GkjkYbZ5D6mqMIHUBgNVHSMEgcwwgcmAFJI/+nOV5fnNVxn2Gkjk ++YbZ5D6mqoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz + ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM + IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu + aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P + BAQDAgPoMAwGA1UdEwEB/wQCMAAwOQYDVR0RBDIwMKAuBgYrBgEFAgKgJDAioA0b + C0tSQlRFU1QuQ09NoREwD6ADAgEBoQgwBhsEdXNlcjASBgNVHSUECzAJBgcrBgEF +-AgMEMA0GCSqGSIb3DQEBCwUAA4IBAQAOBeCDK6Eg6Cu8TZ7xeAw2AbTpaW04nNSV +-Fmm0aIskMgLl2a5KEmalG7rnArRXv5IZVYFjJ6X0MzjOx+BgaGUCvN8jz1fuO3Hp +-iGhxPDzKjFMWJeY/z5bQRueSI6RCC8DzH8iPdlPUQ8ZhnukhY1Vt47wqraf197uT +-0XP21qQr1uRY+ZcLSBKZuKe9ZP3ijh57MOLvYDdAFxVp77JLznpk+oU18ujAtYgZ +-7naIGYtSQRkIi970jk82hSpc9B/KN8UcDuo+DQHWPQaDf39s30qoxooZBoue5ipp +-LQHuVaX5Hoi83cWbsVluce/JsW8GfbuC8+8CosAmzJly183f8++9 ++AgMEMA0GCSqGSIb3DQEBCwUAA4IBAQBRWsxPb9miF9xf8rEIfVko0qBy8doEJsPE ++IVD9Jz/Ml/TBZRLbi1b94l15Fto/Z6XKf8jrnBs4krf6tU2D5PUZXZYZ6tr/2kkY ++IpmoOkEoQX8gtcZfaq2OJzsKHnAJT159EVydyYahHU66i4aNvho74oAafrVTyk8B ++PHCHFs0MUct8DoNwrbnfH0cjqEdVOmjjvBN0yA+RxOa543XnQqkSmCuIJKoD6pUa ++07rE372iERgIjDnzCogiEo9cCBBqDfgsbr0ah1QbWJTJvnsFuxT43tBNurRjNPoX ++Jj6xAzhQLCuvqtKtWlAUOHut18YbVGXVT+3tm7+C6iA44JvMl9m1 + -----END CERTIFICATE----- +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 4435746429..91d4630a0a 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -7,8 +7,10 @@ if not pkinit_enabled: + + # Construct a krb5.conf fragment configuring pkinit. + user_pem = os.path.join(pkinit_certs, 'user.pem') ++ecuser_pem = os.path.join(pkinit_certs, 'ecuser.pem') + privkey_pem = os.path.join(pkinit_certs, 'privkey.pem') + privkey_enc_pem = os.path.join(pkinit_certs, 'privkey-enc.pem') ++privkey_ec_pem = os.path.join(pkinit_certs, 'eckey.pem') + user_p12 = os.path.join(pkinit_certs, 'user.p12') + user_enc_p12 = os.path.join(pkinit_certs, 'user-enc.p12') + user_upn_p12 = os.path.join(pkinit_certs, 'user-upn.p12') +@@ -42,6 +44,7 @@ alias_kdc_conf = {'realms': {'$realm': { + + file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) + file_enc_identity = 'FILE:%s,%s' % (user_pem, privkey_enc_pem) ++ec_identity = 'FILE:%s,%s' % (ecuser_pem, privkey_ec_pem) + dir_identity = 'DIR:%s' % path + dir_enc_identity = 'DIR:%s' % path_enc + dir_file_identity = 'FILE:%s,%s' % (os.path.join(path, 'user.crt'), +@@ -177,6 +180,11 @@ for g in ('4096', 'P-256', 'P-384', 'P-521'): + realm.pkinit(realm.user_princ, expected_trace=('PKINIT using ' + g,), + env=group_env) + ++# Test with an EC client cert. ++mark('EC client cert') ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % ec_identity]) ++ + # Try using multiple configured pkinit_identities, to make sure we + # fall back to the second one when the first one cannot be read. + id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', +@@ -446,4 +454,16 @@ realm.run(['./responder', '-X', p11_attr, + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + ++mark('PKCS11 identity, EC client cert') ++shutil.rmtree(softhsm2_tokens) ++os.mkdir(softhsm2_tokens) ++realm.run(tool_cmd + ['--init-token', '--label', 'user', ++ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin']) ++realm.run(tool_cmd + ['-w', ecuser_pem, '-y', 'cert']) ++realm.run(tool_cmd + ['-w', privkey_ec_pem, '-y', 'privkey', ++ '-l', '--pin', 'userpin']) ++realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin') ++realm.klist(realm.user_princ) ++realm.run([kvno, realm.host_princ]) ++ + success('PKINIT tests') +-- +2.47.1 + diff --git a/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch b/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch new file mode 100644 index 0000000..b529921 --- /dev/null +++ b/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch @@ -0,0 +1,599 @@ +From e43c05e7b0b93401dd68fc3ec3186c3a455b04ea Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 23 Feb 2024 13:51:26 -0500 +Subject: [PATCH] Improve PKCS11 error reporting in PKINIT + +Create a helper p11err() to set extended error message for failed +PKCS11 operations, and use it instead of pkiDebug() and pkcs11error(). + +ticket: 9113 (new) +(cherry picked from commit 98afb314d13939cbee19c69885dcb655db8460da) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 262 ++++++++++-------- + src/plugins/preauth/pkinit/pkinit_trace.h | 9 - + 2 files changed, 142 insertions(+), 129 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 4accfc2664..402bf1b9b3 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -161,9 +161,11 @@ static krb5_error_code pkinit_create_sequence_of_principal_identifiers + int type, krb5_pa_data ***e_data_out); + + #ifndef WITHOUT_PKCS11 +-static krb5_error_code pkinit_find_private_key +-(pkinit_identity_crypto_context, CK_ATTRIBUTE_TYPE usage, +- CK_OBJECT_HANDLE *objp); ++static krb5_error_code ++pkinit_find_private_key(krb5_context context, ++ pkinit_identity_crypto_context id_cryptoctx, ++ CK_ATTRIBUTE_TYPE usage, ++ CK_OBJECT_HANDLE *objp); + static krb5_error_code pkinit_login + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + CK_TOKEN_INFO *tip, const char *password); +@@ -180,6 +182,8 @@ static krb5_error_code pkinit_sign_data_pkcs11 + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); ++ ++static krb5_error_code p11err(krb5_context context, CK_RV rv, const char *op); + #endif /* WITHOUT_PKCS11 */ + + static krb5_error_code pkinit_sign_data_fs +@@ -197,9 +201,6 @@ create_krb5_invalidCertificates(krb5_context context, + static krb5_error_code + create_identifiers_from_stack(STACK_OF(X509) *sk, + krb5_external_principal_identifier *** ids); +-static const char * +-pkcs11err(int err); +- + + #if OPENSSL_VERSION_NUMBER < 0x10100000L + +@@ -944,8 +945,9 @@ cleanup: + + #endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ + ++#ifndef WITHOUT_PKC11 + static struct pkcs11_errstrings { +- short code; ++ CK_RV code; + char *text; + } pkcs11_errstrings[] = { + { 0x0, "ok" }, +@@ -1035,6 +1037,7 @@ static struct pkcs11_errstrings { + { 0x200, "function rejected" }, + { -1, NULL } + }; ++#endif + + MAKE_INIT_FUNCTION(pkinit_openssl_init); + +@@ -1563,6 +1566,8 @@ pkinit_fini_pkcs11(pkinit_identity_crypto_context ctx) + free(ctx->token_label); + free(ctx->cert_id); + free(ctx->cert_label); ++ ctx->p11_module_name = ctx->token_label = ctx->cert_label = NULL; ++ ctx->cert_id = NULL; + #endif + } + +@@ -3344,48 +3349,53 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) + } + + #ifndef WITHOUT_PKCS11 +-static struct plugin_file_handle * ++static krb5_error_code + load_pkcs11_module(krb5_context context, const char *modname, +- CK_FUNCTION_LIST_PTR_PTR p11p) ++ struct plugin_file_handle **handle_out, ++ CK_FUNCTION_LIST_PTR_PTR p11_out) + { + struct plugin_file_handle *handle = NULL; +- CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR); ++ CK_RV rv, (*getflist)(CK_FUNCTION_LIST_PTR_PTR); + struct errinfo einfo = EMPTY_ERRINFO; +- const char *errmsg = NULL; ++ const char *errmsg = NULL, *failure; + void (*sym)(void); + long err; +- CK_RV rv; + + TRACE_PKINIT_PKCS11_OPEN(context, modname); + err = krb5int_open_plugin(modname, &handle, &einfo); + if (err) { +- errmsg = k5_get_error(&einfo, err); +- TRACE_PKINIT_PKCS11_OPEN_FAILED(context, errmsg); ++ failure = _("Cannot load PKCS11 module"); + goto error; + } + + err = krb5int_get_plugin_func(handle, "C_GetFunctionList", &sym, &einfo); + if (err) { +- errmsg = k5_get_error(&einfo, err); +- TRACE_PKINIT_PKCS11_GETSYM_FAILED(context, errmsg); ++ failure = _("Cannot find C_GetFunctionList in PKCS11 module"); + goto error; + } + + getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym; +- rv = (*getflist)(p11p); ++ rv = (*getflist)(p11_out); + if (rv != CKR_OK) { +- TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv)); ++ failure = _("Cannot retrieve function list in PKCS11 module"); + goto error; + } + +- return handle; ++ *handle_out = handle; ++ return 0; + + error: +- k5_free_error(&einfo, errmsg); ++ if (err) { ++ errmsg = k5_get_error(&einfo, err); ++ k5_setmsg(context, err, _("%s: %s"), failure, errmsg); ++ } else { ++ err = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, err, "%s", failure); ++ } + k5_clear_error(&einfo); + if (handle != NULL) + krb5int_close_plugin(handle); +- return NULL; ++ return err; + } + + static krb5_error_code +@@ -3393,12 +3403,13 @@ pkinit_login(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, + CK_TOKEN_INFO *tip, const char *password) + { ++ krb5_error_code ret = 0; ++ CK_RV rv; + krb5_data rdat; + char *prompt; + const char *warning; + krb5_prompt kprompt; + krb5_prompt_type prompt_type; +- int r = 0; + + if (tip->flags & CKF_PROTECTED_AUTHENTICATION_PATH) { + rdat.data = NULL; +@@ -3407,7 +3418,7 @@ pkinit_login(krb5_context context, + rdat.data = strdup(password); + rdat.length = strlen(password); + } else if (id_cryptoctx->prompter == NULL) { +- r = KRB5_LIBOS_CANTREADPWD; ++ ret = KRB5_LIBOS_CANTREADPWD; + rdat.data = NULL; + } else { + if (tip->flags & CKF_USER_PIN_LOCKED) +@@ -3431,31 +3442,28 @@ pkinit_login(krb5_context context, + + /* PROMPTER_INVOCATION */ + k5int_set_prompt_types(context, &prompt_type); +- r = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data, +- NULL, NULL, 1, &kprompt); ++ ret = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data, ++ NULL, NULL, 1, &kprompt); + k5int_set_prompt_types(context, 0); + free(prompt); + } + +- if (r == 0) { +- r = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER, +- (u_char *) rdat.data, rdat.length); +- +- if (r != CKR_OK) { +- TRACE_PKINIT_PKCS11_LOGIN_FAILED(context, pkcs11err(r)); +- r = KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ if (!ret) { ++ rv = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER, ++ (uint8_t *)rdat.data, rdat.length); ++ if (rv != CKR_OK) ++ ret = p11err(context, rv, "C_Login"); + } + free(rdat.data); + +- return r; ++ return ret; + } + + static krb5_error_code + pkinit_open_session(krb5_context context, + pkinit_identity_crypto_context cctx) + { +- CK_ULONG i, pret; ++ CK_ULONG i, rv; + unsigned char *cp; + size_t label_len; + CK_ULONG count = 0; +@@ -3469,30 +3477,35 @@ pkinit_open_session(krb5_context context, + return 0; /* session already open */ + + /* Load module */ +- cctx->p11_module = load_pkcs11_module(context, cctx->p11_module_name, +- &cctx->p11); +- if (cctx->p11_module == NULL) +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = load_pkcs11_module(context, cctx->p11_module_name, &cctx->p11_module, ++ &cctx->p11); ++ if (ret) ++ goto cleanup; + + /* Init */ +- pret = cctx->p11->C_Initialize(NULL); +- if (pret != CKR_OK) { +- pkiDebug("C_Initialize: %s\n", pkcs11err(pret)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_Initialize(NULL); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_Initialize"); ++ goto cleanup; + } + + /* Get the list of available slots */ +- if (cctx->p11->C_GetSlotList(TRUE, NULL, &count) != CKR_OK) +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_GetSlotList(TRUE, NULL, &count); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetSlotList"); ++ goto cleanup; ++ } + if (count == 0) { + TRACE_PKINIT_PKCS11_NO_TOKEN(context); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } +- slotlist = calloc(count, sizeof(CK_SLOT_ID)); ++ slotlist = k5calloc(count, sizeof(CK_SLOT_ID), &ret); + if (slotlist == NULL) +- return ENOMEM; +- if (cctx->p11->C_GetSlotList(TRUE, slotlist, &count) != CKR_OK) { +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ rv = cctx->p11->C_GetSlotList(TRUE, slotlist, &count); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetSlotList"); + goto cleanup; + } + +@@ -3503,19 +3516,17 @@ pkinit_open_session(krb5_context context, + continue; + + /* Open session */ +- pret = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION, +- NULL, NULL, &cctx->session); +- if (pret != CKR_OK) { +- pkiDebug("C_OpenSession: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION, ++ NULL, NULL, &cctx->session); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_OpenSession"); + goto cleanup; + } + + /* Get token info */ +- pret = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo); +- if (pret != CKR_OK) { +- pkiDebug("C_GetTokenInfo: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetTokenInfo"); + goto cleanup; + } + +@@ -3577,6 +3588,10 @@ pkinit_open_session(krb5_context context, + + ret = 0; + cleanup: ++ /* On error, finalize the PKCS11 fields to ensure that we don't mistakenly ++ * short-circuit with success on the next call. */ ++ if (ret) ++ pkinit_fini_pkcs11(cctx); + free(slotlist); + free(p11name); + return ret; +@@ -3598,16 +3613,17 @@ cleanup: + * If there are more than one, we just take the first one. + */ + +-krb5_error_code +-pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, ++static krb5_error_code ++pkinit_find_private_key(krb5_context context, ++ pkinit_identity_crypto_context id_cryptoctx, + CK_ATTRIBUTE_TYPE usage, + CK_OBJECT_HANDLE *objp) + { + CK_OBJECT_CLASS cls; + CK_ATTRIBUTE attrs[4]; + CK_ULONG count; ++ CK_RV rv; + unsigned int nattrs = 0; +- int r; + #ifdef PKINIT_USE_KEY_USAGE + CK_BBOOL true_false; + #endif +@@ -3637,18 +3653,21 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len; + nattrs++; + +- r = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, nattrs); +- if (r != CKR_OK) { +- pkiDebug("krb5_pkinit_sign_data: C_FindObjectsInit: %s\n", +- pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, ++ nattrs); ++ if (rv != CKR_OK) ++ return p11err(context, rv, _("C_FindObjectsInit")); + +- r = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, &count); ++ rv = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, ++ &count); + id_cryptoctx->p11->C_FindObjectsFinal(id_cryptoctx->session); +- pkiDebug("found %d private keys (%s)\n", (int)count, pkcs11err(r)); +- if (r != CKR_OK || count < 1) ++ if (rv != CKR_OK) ++ return p11err(context, rv, _("C_FindObjects")); ++ if (count < 1) { ++ k5_setmsg(context, KRB5KDC_ERR_PREAUTH_FAILED, ++ _("Found no private keys in PKCS11 token")); + return KRB5KDC_ERR_PREAUTH_FAILED; ++ } + return 0; + } + #endif +@@ -3796,34 +3815,32 @@ pkinit_sign_data_pkcs11(krb5_context context, + CK_FUNCTION_LIST_PTR p11; + CK_ATTRIBUTE attr; + CK_KEY_TYPE keytype; ++ CK_RV rv; + EVP_MD_CTX *ctx; + const EVP_MD *md = EVP_sha256(); + unsigned int mdlen; + uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input; + size_t dinfo_len, input_len; +- int r; + + *sig = NULL; + *sig_len = 0; + +- if (pkinit_open_session(context, id_cryptoctx)) { +- pkiDebug("can't open pkcs11 session\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ ret = pkinit_open_session(context, id_cryptoctx); ++ if (ret) ++ return ret; + p11 = id_cryptoctx->p11; + session = id_cryptoctx->session; + +- ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ ret = pkinit_find_private_key(context, id_cryptoctx, CKA_SIGN, &obj); + if (ret) + return ret; + + attr.type = CKA_KEY_TYPE; + attr.pValue = &keytype; + attr.ulValueLen = sizeof(keytype); +- r = p11->C_GetAttributeValue(session, obj, &attr, 1); +- if (r) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, &attr, 1); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -3865,10 +3882,9 @@ pkinit_sign_data_pkcs11(krb5_context context, + mech.pParameter = NULL; + mech.ulParameterLen = 0; + +- r = p11->C_SignInit(session, &mech, obj); +- if (r != CKR_OK) { +- pkiDebug("C_SignInit: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_SignInit(session, &mech, obj); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_SignInit"); + goto cleanup; + } + +@@ -3881,18 +3897,17 @@ pkinit_sign_data_pkcs11(krb5_context context, + if (sigbuf == NULL) + goto cleanup; + +- r = p11->C_Sign(session, input, input_len, sigbuf, &len); +- if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) { ++ rv = p11->C_Sign(session, input, input_len, sigbuf, &len); ++ if (rv == CKR_BUFFER_TOO_SMALL || ++ (rv == CKR_OK && len >= PK_SIGLEN_GUESS)) { + free(sigbuf); +- pkiDebug("C_Sign realloc %d\n", (int) len); + sigbuf = k5alloc(len, &ret); + if (sigbuf == NULL) + goto cleanup; +- r = p11->C_Sign(session, input, input_len, sigbuf, &len); ++ rv = p11->C_Sign(session, input, input_len, sigbuf, &len); + } +- if (r != CKR_OK) { +- pkiDebug("C_Sign: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_Sign"); + goto cleanup; + } + +@@ -4348,13 +4363,14 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) + } + + static krb5_error_code +-load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, +- pkinit_identity_opts *idopts, pkinit_cred_info *cred_out) ++load_one_cert(krb5_context context, CK_FUNCTION_LIST_PTR p11, ++ CK_SESSION_HANDLE session, pkinit_identity_opts *idopts, ++ pkinit_cred_info *cred_out) + { + krb5_error_code ret; + CK_ATTRIBUTE attrs[2]; + CK_BYTE_PTR cert = NULL, cert_id = NULL; +- CK_RV pret; ++ CK_RV rv; + const unsigned char *cp; + CK_OBJECT_HANDLE obj; + CK_ULONG count; +@@ -4364,8 +4380,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + *cred_out = NULL; + + /* Look for X.509 cert. */ +- pret = p11->C_FindObjects(session, &obj, 1, &count); +- if (pret != CKR_OK || count <= 0) ++ rv = p11->C_FindObjects(session, &obj, 1, &count); ++ if (rv != CKR_OK || count <= 0) + return 0; + + /* Get cert and id len. */ +@@ -4375,10 +4391,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + attrs[1].type = CKA_ID; + attrs[1].pValue = NULL; + attrs[1].ulValueLen = 0; +- pret = p11->C_GetAttributeValue(session, obj, attrs, 2); +- if (pret != CKR_OK && pret != CKR_BUFFER_TOO_SMALL) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, attrs, 2); ++ if (rv != CKR_OK && rv != CKR_BUFFER_TOO_SMALL) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -4393,10 +4408,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + attrs[0].pValue = cert; + attrs[1].type = CKA_ID; + attrs[1].pValue = cert_id; +- pret = p11->C_GetAttributeValue(session, obj, attrs, 2); +- if (pret != CKR_OK) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, attrs, 2); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -4406,7 +4420,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + cp = (unsigned char *)cert; + x = d2i_X509(NULL, &cp, (int)attrs[0].ulValueLen); + if (x == NULL) { +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = oerr(context, 0, ++ _("Failed to decode X509 certificate from PKCS11 token")); + goto cleanup; + } + +@@ -4444,7 +4459,7 @@ pkinit_get_certs_pkcs11(krb5_context context, + int i; + unsigned int nattrs; + krb5_error_code ret; +- CK_RV pret; ++ CK_RV rv; + + /* Copy stuff from idopts -> id_cryptoctx */ + if (idopts->p11_module_name != NULL) { +@@ -4516,16 +4531,16 @@ pkinit_get_certs_pkcs11(krb5_context context, + nattrs++; + } + +- pret = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, +- nattrs); +- if (pret != CKR_OK) { +- pkiDebug("C_FindObjectsInit: %s\n", pkcs11err(pret)); ++ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, ++ nattrs); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_FindObjectsInit"); + return KRB5KDC_ERR_PREAUTH_FAILED; + } + + for (i = 0; i < MAX_CREDS_ALLOWED; i++) { +- ret = load_one_cert(id_cryptoctx->p11, id_cryptoctx->session, idopts, +- &id_cryptoctx->creds[i]); ++ ret = load_one_cert(context, id_cryptoctx->p11, id_cryptoctx->session, ++ idopts, &id_cryptoctx->creds[i]); + if (ret) + return ret; + if (id_cryptoctx->creds[i] == NULL) +@@ -5510,19 +5525,26 @@ print_pubkey(BIGNUM * key, char *msg) + } + #endif + +-static const char * +-pkcs11err(int err) ++#ifndef WITHOUT_PKCS11 ++static krb5_error_code ++p11err(krb5_context context, CK_RV rv, const char *op) + { ++ krb5_error_code code = KRB5KDC_ERR_PREAUTH_FAILED; + int i; ++ const char *msg; + +- for (i = 0; pkcs11_errstrings[i].text != NULL; i++) +- if (pkcs11_errstrings[i].code == err) ++ for (i = 0; pkcs11_errstrings[i].text != NULL; i++) { ++ if (pkcs11_errstrings[i].code == rv) + break; +- if (pkcs11_errstrings[i].text != NULL) +- return (pkcs11_errstrings[i].text); ++ } ++ msg = pkcs11_errstrings[i].text; ++ if (msg == NULL) ++ msg = "unknown PKCS11 error"; + +- return "unknown PKCS11 error"; ++ krb5_set_error_message(context, code, _("PKCS11 error (%s): %s"), op, msg); ++ return code; + } ++#endif + + /* + * Add an item to the pkinit_identity_crypto_context's list of deferred +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 1c1ceb5a41..1faa6816d7 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -98,21 +98,12 @@ + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) + +-#define TRACE_PKINIT_PKCS11_GETFLIST_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS11 C_GetFunctionList failed: {str}", errstr) +-#define TRACE_PKINIT_PKCS11_GETSYM_FAILED(c, errstr) \ +- TRACE(c, "PKINIT unable to find PKCS11 plugin symbol " \ +- "C_GetFunctionList: {str}", errstr) +-#define TRACE_PKINIT_PKCS11_LOGIN_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS11 C_Login failed: {str}", errstr) + #define TRACE_PKINIT_PKCS11_NO_MATCH_TOKEN(c) \ + TRACE(c, "PKINIT PKCS#11 module has no matching tokens") + #define TRACE_PKINIT_PKCS11_NO_TOKEN(c) \ + TRACE(c, "PKINIT PKCS#11 module shows no slots with tokens") + #define TRACE_PKINIT_PKCS11_OPEN(c, name) \ + TRACE(c, "PKINIT opening PKCS#11 module \"{str}\"", name) +-#define TRACE_PKINIT_PKCS11_OPEN_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS#11 module open failed: {str}", errstr) + #define TRACE_PKINIT_PKCS11_SLOT(c, slot, len, label) \ + TRACE(c, "PKINIT PKCS#11 slotid {int} token {lenstr}", \ + slot, len, label) +-- +2.47.1 + diff --git a/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch b/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch new file mode 100644 index 0000000..71b30d1 --- /dev/null +++ b/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch @@ -0,0 +1,61 @@ +From 946f7dba8cea3d2ed0e68c5e7594cbd7e1364609 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 1 Aug 2024 10:56:07 +0200 +Subject: [PATCH] Set missing mask flags for kdb5_util operations + +Set KADM5_TL_DATA for the use_mkey and update_princ_encryption +commands. (Commit c877f13c8985d820583b0d7ac1bb4c5dc36e677e did this +for the add_new_mkey and purge_mkeys commands.) Set appropriate flags +for the add_random_key command. + +[ghudson@mit.edu: combined two commits; pruned out proposed mask flag +additions for values represented within key data or tl-data (like +KADM5_MKVNO), as those flags are currently only used in the kadm5 +protocol, not to communicate with the KDB module] + +ticket: 9158 (new) +(cherry picked from commit 4ed7da378940198cf4415f86d4eb013de6ac6455) +--- + src/kadmin/dbutil/kdb5_mkey.c | 4 +++- + src/kadmin/dbutil/kdb5_util.c | 3 +++ + 2 files changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c +index aceb0a9b80..ac5c51d05e 100644 +--- a/src/kadmin/dbutil/kdb5_mkey.c ++++ b/src/kadmin/dbutil/kdb5_mkey.c +@@ -525,6 +525,8 @@ kdb5_use_mkey(int argc, char *argv[]) + goto cleanup_return; + } + ++ master_entry->mask |= KADM5_TL_DATA; ++ + if ((retval = krb5_db_put_principal(util_context, master_entry))) { + com_err(progname, retval, + _("while adding master key entry to the database")); +@@ -814,7 +816,7 @@ update_princ_encryption_1(void *cb, krb5_db_entry *ent) + goto fail; + } + +- ent->mask |= KADM5_KEY_DATA; ++ ent->mask |= KADM5_KEY_DATA | KADM5_TL_DATA; + + if ((retval = krb5_db_put_principal(util_context, ent))) { + com_err(progname, retval, _("while updating principal '%s' key data " +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index 55d529fa4c..afc817891b 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -600,6 +600,9 @@ add_random_key(int argc, char **argv) + exit_status++; + return; + } ++ ++ dbent->mask |= KADM5_ATTRIBUTES | KADM5_KEY_DATA | KADM5_TL_DATA; ++ + ret = krb5_db_put_principal(util_context, dbent); + krb5_db_free_principal(util_context, dbent); + if (ret) { +-- +2.47.1 + diff --git a/0034-Prevent-overflow-when-calculating-ulog-block-size.patch b/0034-Prevent-overflow-when-calculating-ulog-block-size.patch new file mode 100644 index 0000000..d288951 --- /dev/null +++ b/0034-Prevent-overflow-when-calculating-ulog-block-size.patch @@ -0,0 +1,64 @@ +From 9b669dd42b28e7900f5ccac2816204e7d04ea23c Mon Sep 17 00:00:00 2001 +From: Zoltan Borbely +Date: Tue, 28 Jan 2025 16:39:25 -0500 +Subject: [PATCH] Prevent overflow when calculating ulog block size + +In kdb_log.c:resize(), log an error and fail if the update size is +larger than the largest possible block size (2^16-1). + +CVE-2025-24528: + +In MIT krb5 release 1.7 and later with incremental propagation +enabled, an authenticated attacker can cause kadmind to write beyond +the end of the mapped region for the iprop log file, likely causing a +process crash. + +[ghudson@mit.edu: edited commit message and added CVE description] + +ticket: 9159 (new) +tags: pullup +target_version: 1.21-next + +(cherry picked from commit 78ceba024b64d49612375be4a12d1c066b0bfbd0) +--- + src/lib/kdb/kdb_log.c | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c +index e9b95fce59..c805ebd988 100644 +--- a/src/lib/kdb/kdb_log.c ++++ b/src/lib/kdb/kdb_log.c +@@ -183,7 +183,7 @@ extend_file_to(int fd, unsigned int new_size) + */ + static krb5_error_code + resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd, +- unsigned int recsize) ++ unsigned int recsize, const kdb_incr_update_t *upd) + { + unsigned int new_block, new_size; + +@@ -195,6 +195,12 @@ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd, + new_block *= ULOG_BLOCK; + new_size += ulogentries * new_block; + ++ if (new_block > UINT16_MAX) { ++ syslog(LOG_ERR, _("ulog overflow caused by principal %.*s"), ++ upd->kdb_princ_name.utf8str_t_len, ++ upd->kdb_princ_name.utf8str_t_val); ++ return KRB5_LOG_ERROR; ++ } + if (new_size > MAXLOGLEN) + return KRB5_LOG_ERROR; + +@@ -291,7 +297,7 @@ store_update(kdb_log_context *log_ctx, kdb_incr_update_t *upd) + recsize = sizeof(kdb_ent_header_t) + upd_size; + + if (recsize > ulog->kdb_block) { +- retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize); ++ retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize, upd); + if (retval) + return retval; + } +-- +2.48.1 + diff --git a/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch b/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch new file mode 100644 index 0000000..4c2ba40 --- /dev/null +++ b/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch @@ -0,0 +1,327 @@ +From c617915958a5cb05463713adcf03b6a0e0512ac3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 16 Dec 2022 18:31:07 -0500 +Subject: [PATCH] Don't issue session keys with deprecated enctypes + +A paper by Tom Tervoort noted that rc4-hmac pre-hashes the input for +its checksum and GSS operations before applying HMAC, and is therefore +potentially vulnerable to hash collision attacks if a protocol +contains a restricted signing oracle. + +In light of these potential attacks, begin the functional deprecation +of DES3 and RC4 by disallowing their use as session key enctypes by +default. Add the variables allow_des3 and allow_rc4 in case +negotiability of these enctypes for session keys needs to be turned +back on, with the expectation that in future releases the enctypes +will be more comprehensively deprecated. + +ticket: 9081 +(cherry picked from commit 1b57a4d134bbd0e7c52d5885a92eccc815726463) +--- + doc/admin/conf_files/krb5_conf.rst | 12 ++++++++++++ + doc/admin/enctypes.rst | 23 +++++++++++++++++++--- + src/include/k5-int.h | 4 ++++ + src/kdc/kdc_util.c | 10 ++++++++++ + src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++++++++++----------- + src/lib/krb5/krb/init_ctx.c | 10 ++++++++++ + src/tests/gssapi/t_enctypes.py | 5 +++-- + src/tests/t_etype_info.py | 5 +++-- + src/tests/t_sesskeynego.py | 28 +++++++++++++++++++++++++-- + src/util/k5test.py | 9 ++++++++- + 10 files changed, 116 insertions(+), 21 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index dca52e1426..d51fd3ce7e 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,6 +95,18 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + ++**allow_des3** ++ Permit the KDC to issue tickets with des3-cbc-sha1 session keys. ++ In future releases, this flag will allow des3-cbc-sha1 to be used ++ at all. The default value for this tag is false. (Added in ++ release 1.21.) ++ ++**allow_rc4** ++ Permit the KDC to issue tickets with arcfour-hmac session keys. ++ In future releases, this flag will allow arcfour-hmac to be used ++ at all. The default value for this tag is false. (Added in ++ release 1.21.) ++ + **allow_weak_crypto** + If this flag is set to false, then weak encryption types (as noted + in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index c4d5499d3b..2b4ed7da0b 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -48,12 +48,15 @@ Session key selection + The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of +-enctypes. ++enctypes. Starting in krb5-1.21, all services are assumed to support ++aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session ++keys will not be issued by default. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +-issue for service tickets for that principal. See :ref:`set_string` +-in :ref:`kadmin(1)` for details. ++issue for service tickets for that principal, overriding the service's ++long-term keys and the assumption of aes256-cts-hmac-sha1-96 support. ++See :ref:`set_string` in :ref:`kadmin(1)` for details. + + + Choosing enctypes for a service +@@ -87,6 +90,20 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + ++**allow_des3** ++ was added in release 1.21 and defaults to *false*. Unless this ++ flag is set to *true*, the KDC will not issue tickets with ++ des3-cbc-sha1 session keys. In a future release, this flag will ++ control whether des3-cbc-sha1 is permitted in similar fashion to ++ weak enctypes. ++ ++**allow_rc4** ++ was added in release 1.21 and defaults to *false*. Unless this ++ flag is set to *true*, the KDC will not issue tickets with ++ arcfour-hmac session keys. In a future release, this flag will ++ control whether arcfour-hmac is permitted in similar fashion to ++ weak enctypes. ++ + **permitted_enctypes** + controls the set of enctypes that a service will permit for + session keys and for ticket and authenticator encryption. The KDC +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index b7789a2dd8..d0a263aa7d 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -181,6 +181,8 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" ++#define KRB5_CONF_ALLOW_DES3 "allow_des3" ++#define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" + #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" +@@ -1241,6 +1243,8 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; ++ krb5_boolean allow_des3; ++ krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; + enum dns_canonhost dns_canonicalize_hostname; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 93415ba862..c7b6e4090d 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1108,6 +1108,16 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + if (!krb5_is_permitted_enctype(context, ktype[i])) + continue; + ++ /* ++ * Prevent these deprecated enctypes from being used as session keys ++ * unless they are explicitly allowed. In the future they will be more ++ * comprehensively disabled and eventually removed. ++ */ ++ if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) ++ continue; ++ if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) ++ continue; ++ + if (dbentry_supports_enctype(context, server, ktype[i])) + return ktype[i]; + } +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 1b420a3ac2..ea089f0fcc 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1582,22 +1582,31 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + (*prompter)(context, data, 0, banner, 0, 0); + } + +-/* Display a warning via the prompter if des3-cbc-sha1 was used for either the +- * reply key or the session key. */ ++/* Display a warning via the prompter if a deprecated enctype was used for ++ * either the reply key or the session key. */ + static void +-warn_des3(krb5_context context, krb5_init_creds_context ctx, +- krb5_enctype as_key_enctype) ++warn_deprecated(krb5_context context, krb5_init_creds_context ctx, ++ krb5_enctype as_key_enctype) + { +- const char *banner; ++ krb5_enctype etype; ++ char encbuf[128], banner[256]; + +- if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 && +- ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1) +- return; + if (ctx->prompter == NULL) + return; + +- banner = _("Warning: encryption type des3-cbc-sha1 used for " +- "authentication is weak and will be disabled"); ++ if (krb5int_c_deprecated_enctype(as_key_enctype)) ++ etype = as_key_enctype; ++ else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype)) ++ etype = ctx->cred.keyblock.enctype; ++ else ++ return; ++ ++ if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0) ++ return; ++ snprintf(banner, sizeof(banner), ++ _("Warning: encryption type %s used for authentication is " ++ "deprecated and will be disabled"), encbuf); ++ + /* PROMPTER_INVOCATION */ + (*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL); + } +@@ -1848,7 +1857,7 @@ init_creds_step_reply(krb5_context context, + ctx->complete = TRUE; + warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, + ctx->in_tkt_service, ctx->reply); +- warn_des3(context, ctx, encrypting_key.enctype); ++ warn_deprecated(context, ctx, encrypting_key.enctype); + + cleanup: + krb5_free_pa_data(context, kdc_padata); +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 582a2945ff..a32f8dbf03 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -220,6 +220,16 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + ++ retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); ++ if (retval) ++ goto cleanup; ++ ctx->allow_des3 = tmp; ++ ++ retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); ++ if (retval) ++ goto cleanup; ++ ctx->allow_rc4 = tmp; ++ + retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index 2f95d89967..e6bde47afc 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -10,8 +10,9 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, ++supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' ++conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', ++ 'allow_des3': 'true', 'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index a6f538b66d..75d9621dd6 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,8 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts rc4-hmac' +-conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} ++supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' ++conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++ 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + + realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth', +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 9024aee838..5a213617b5 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -25,6 +25,8 @@ conf3 = {'libdefaults': { + 'default_tkt_enctypes': 'aes128-cts', + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} ++conf5 = {'libdefaults': {'allow_rc4': 'true'}} ++conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -54,10 +56,12 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'aes128-cts,aes256-cts']) + test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + +-# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. ++# 3b: Skip RC4 (as the KDC does not allow it for session keys by ++# default) and negotiate aes128-cts session key, with only an aes256 ++# long-term service key. + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) +-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + realm.stop() + + # 4: Check that permitted_enctypes is a default for session key enctypes. +@@ -67,4 +71,24 @@ realm.run([kvno, 'user'], + expected_trace=('etypes requested in TGS request: aes256-cts',)) + realm.stop() + ++# 5: allow_rc4 permits negotiation of rc4-hmac session key. ++realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) ++realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) ++test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') ++realm.stop() ++ ++# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. ++realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) ++realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) ++test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') ++realm.stop() ++ ++# 7: default config negotiates aes256-sha1 session key for RC4-only service. ++realm = K5Realm(create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) ++test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac') ++realm.stop() ++ + success('sesskeynego') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index d823653aa0..8e5f5ba8e9 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1338,9 +1338,16 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + ++ # Exercise the DES3 enctype. ++ ('des3', None, ++ {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, ++ {'realms': {'$realm': { ++ 'supported_enctypes': 'des3-cbc-sha1:normal', ++ 'master_key_type': 'des3-cbc-sha1'}}}), ++ + # Exercise the arcfour enctype. + ('arcfour', None, +- {'libdefaults': {'permitted_enctypes': 'rc4'}}, ++ {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'arcfour-hmac:normal', + 'master_key_type': 'arcfour-hmac'}}}), +-- +2.49.0 + diff --git a/0036-downstream-Remove-3des-support-cumulative-1.patch b/0036-downstream-Remove-3des-support-cumulative-1.patch new file mode 100644 index 0000000..4911619 --- /dev/null +++ b/0036-downstream-Remove-3des-support-cumulative-1.patch @@ -0,0 +1,260 @@ +From b0993b57dbe584f9308cc7773b930efe76e19ba3 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 4 Apr 2025 15:08:36 +0200 +Subject: [PATCH] [downstream] Remove 3des support (cumulative 1) + +Remove mentions for the triple-DES encryption type which were added +since the previous downstream patch. +--- + README | 15 +++++++-------- + doc/admin/conf_files/krb5_conf.rst | 6 ------ + doc/admin/enctypes.rst | 11 ++--------- + doc/mitK5features.rst | 5 ++--- + src/include/k5-int.h | 2 -- + src/kdc/kdc_util.c | 2 -- + src/lib/krb5/krb/init_ctx.c | 5 ----- + src/man/krb5.conf.man | 6 ------ + src/tests/gssapi/t_enctypes.py | 5 ++--- + src/tests/t_etype_info.py | 4 ++-- + src/tests/t_sesskeynego.py | 8 -------- + src/util/k5test.py | 7 ------- + 12 files changed, 15 insertions(+), 61 deletions(-) + +diff --git a/README b/README +index 6d6f7f16e3..9341bd3dd8 100644 +--- a/README ++++ b/README +@@ -81,11 +81,11 @@ Triple-DES and RC4 transitions + ------------------------------ + + Beginning with the krb5-1.21 release, the KDC will not issue tickets +-with triple-DES or RC4 session keys unless explicitly configured using +-the new allow_des3 and allow_rc4 variables in [libdefaults]. To +-facilitate the negotiation of session keys, the KDC will assume that +-all services can handle aes256-sha1 session keys unless the service +-principal has a session_enctypes string attribute. ++with RC4 session keys unless explicitly configured using the new ++allow_rc4 variable in [libdefaults]. To facilitate the negotiation of ++session keys, the KDC will assume that all services can handle ++aes256-sha1 session keys unless the service principal has a ++session_enctypes string attribute. + + Beginning with the krb5-1.19 release, a warning will be issued if + initial credentials are acquired using the des3-cbc-sha1 encryption +@@ -164,9 +164,8 @@ Developer experience: + + Protocol evolution: + +-* The KDC will no longer issue tickets with RC4 or triple-DES session +- keys unless explicitly configured with the new allow_rc4 or +- allow_des3 variables respectively. ++* The KDC will no longer issue tickets with RC4 session keys unless ++ explicitly configured with the new allow_rc4 variable. + + * The KDC will assume that all services can handle aes256-sha1 session + keys unless the service principal has a session_enctypes string +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index d51fd3ce7e..d20dcf18e3 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,12 +95,6 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + +-**allow_des3** +- Permit the KDC to issue tickets with des3-cbc-sha1 session keys. +- In future releases, this flag will allow des3-cbc-sha1 to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- + **allow_rc4** + Permit the KDC to issue tickets with arcfour-hmac session keys. + In future releases, this flag will allow arcfour-hmac to be used +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index 2b4ed7da0b..6ce4638d5e 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -49,8 +49,8 @@ The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of + enctypes. Starting in krb5-1.21, all services are assumed to support +-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session +-keys will not be issued by default. ++aes256-cts-hmac-sha1-96; also, arcfour-hmac session keys will not be ++issued by default. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +@@ -90,13 +90,6 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + +-**allow_des3** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- des3-cbc-sha1 session keys. In a future release, this flag will +- control whether des3-cbc-sha1 is permitted in similar fashion to +- weak enctypes. +- + **allow_rc4** + was added in release 1.21 and defaults to *false*. Unless this + flag is set to *true*, the KDC will not issue tickets with +diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst +index cad0855724..64d746b0af 100644 +--- a/doc/mitK5features.rst ++++ b/doc/mitK5features.rst +@@ -659,9 +659,8 @@ Release 1.21 + + * Protocol evolution: + +- - The KDC will no longer issue tickets with RC4 or triple-DES +- session keys unless explicitly configured with the new allow_rc4 +- or allow_des3 variables respectively. ++ - The KDC will no longer issue tickets with RC4 session keys unless ++ explicitly configured with the new allow_rc4 variable. + + - The KDC will assume that all services can handle aes256-sha1 + session keys unless the service principal has a session_enctypes +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index d0a263aa7d..82a763298d 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -181,7 +181,6 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" +-#define KRB5_CONF_ALLOW_DES3 "allow_des3" + #define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" +@@ -1243,7 +1242,6 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; +- krb5_boolean allow_des3; + krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index c7b6e4090d..bafcf5f728 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1113,8 +1113,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + * unless they are explicitly allowed. In the future they will be more + * comprehensively disabled and eventually removed. + */ +- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) +- continue; + if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) + continue; + +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index a32f8dbf03..82aba64c5e 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -220,11 +220,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_des3 = tmp; +- + retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index 6c0e9aff8c..4b53988712 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -178,12 +178,6 @@ kdc.conf(5), but it is not a recommended practice. + The libdefaults section may contain any of the following relations: + .INDENT 0.0 + .TP +-\fBallow_des3\fP +-Permit the KDC to issue tickets with des3\-cbc\-sha1 session keys. +-In future releases, this flag will allow des3\-cbc\-sha1 to be used +-at all. The default value for this tag is false. (Added in +-release 1.21.) +-.TP + \fBallow_rc4\fP + Permit the KDC to issue tickets with arcfour\-hmac session keys. + In future releases, this flag will allow arcfour\-hmac to be used +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index e6bde47afc..1bb8c40b6b 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -10,9 +10,8 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', +- 'allow_des3': 'true', 'allow_rc4': 'true'}, ++supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 75d9621dd6..e82ff7ff07 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,7 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++supported_enctypes = 'aes128-cts rc4-hmac' ++conf = {'libdefaults': {'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 5a213617b5..c7dba0ff5b 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -26,7 +26,6 @@ conf3 = {'libdefaults': { + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} + conf5 = {'libdefaults': {'allow_rc4': 'true'}} +-conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) + test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + realm.stop() + +-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. +-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) +-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- + # 7: default config negotiates aes256-sha1 session key for RC4-only service. + realm = K5Realm(create_host=False, get_creds=False) + realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 8e5f5ba8e9..b953827018 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1338,13 +1338,6 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + +- # Exercise the DES3 enctype. +- ('des3', None, +- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, +- {'realms': {'$realm': { +- 'supported_enctypes': 'des3-cbc-sha1:normal', +- 'master_key_type': 'des3-cbc-sha1'}}}), +- + # Exercise the arcfour enctype. + ('arcfour', None, + {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, +-- +2.49.0 + diff --git a/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch b/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch new file mode 100644 index 0000000..2d9a6cc --- /dev/null +++ b/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch @@ -0,0 +1,692 @@ +From 9d03713af124c2096d071ba36893018da8d71655 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Tue, 14 Jan 2025 13:31:11 +0100 +Subject: [PATCH] Add PKINIT paChecksum2 from MS-PKCA v20230920 + +In 2023, Microsoft updated MS-PKCA to add the optional paChecksum2 +element in the PKAuthenticator sequence. This checksum accepts SHA-1, +SHA-256, SHA-384, and SHA-512 digests. + +In Windows Server 2025, this checksum becomes mandatory when using +PKINIT with FFDH (but strangely not with ECDH if SHA-1 is configured as +allowed). + +[ghudson@mit.edu: refactored crypto interfaces to reduce complexity of +calling code] + +ticket: 9166 (new) +(cherry picked from commit 310793ba63782af5ffa3a95d20e41f8f03ca7e00) +--- + src/include/k5-int-pkinit.h | 25 ++-- + src/lib/krb5/asn.1/asn1_k_encode.c | 18 ++- + src/plugins/preauth/pkinit/pkinit.h | 1 + + src/plugins/preauth/pkinit/pkinit_clnt.c | 41 +++---- + src/plugins/preauth/pkinit/pkinit_constants.c | 42 +++++-- + src/plugins/preauth/pkinit/pkinit_crypto.h | 24 +++- + .../preauth/pkinit/pkinit_crypto_openssl.c | 116 +++++++++++++++++- + src/plugins/preauth/pkinit/pkinit_kdf_test.c | 4 +- + src/plugins/preauth/pkinit/pkinit_lib.c | 16 ++- + src/plugins/preauth/pkinit/pkinit_srv.c | 38 ++---- + src/plugins/preauth/pkinit/pkinit_trace.h | 5 +- + src/tests/asn.1/krb5_decode_test.c | 2 +- + src/tests/asn.1/ktest.c | 7 +- + src/tests/asn.1/ktest_equal.c | 2 +- + src/tests/asn.1/pkinit_encode.out | 2 +- + src/tests/asn.1/pkinit_trval.out | 2 +- + 16 files changed, 250 insertions(+), 95 deletions(-) + +diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h +index 915904e518..cf6b1f99c5 100644 +--- a/src/include/k5-int-pkinit.h ++++ b/src/include/k5-int-pkinit.h +@@ -36,21 +36,28 @@ + * pkinit structures + */ + +-/* PKAuthenticator */ +-typedef struct _krb5_pk_authenticator { +- krb5_int32 cusec; /* (0..999999) */ +- krb5_timestamp ctime; +- krb5_int32 nonce; /* (0..4294967295) */ +- krb5_checksum paChecksum; +- krb5_data *freshnessToken; +-} krb5_pk_authenticator; +- + /* AlgorithmIdentifier */ + typedef struct _krb5_algorithm_identifier { + krb5_data algorithm; /* OID */ + krb5_data parameters; /* Optional */ + } krb5_algorithm_identifier; + ++/* PAChecksum2 */ ++typedef struct _krb5_pachecksum2 { ++ krb5_data checksum; ++ krb5_algorithm_identifier algorithmIdentifier; ++} krb5_pachecksum2; ++ ++/* PKAuthenticator */ ++typedef struct _krb5_pk_authenticator { ++ krb5_int32 cusec; /* (0..999999) */ ++ krb5_timestamp ctime; ++ krb5_int32 nonce; /* (0..4294967295) */ ++ krb5_data paChecksum; ++ krb5_data *freshnessToken; /* Optional */ ++ krb5_pachecksum2 *paChecksum2; /* Optional */ ++} krb5_pk_authenticator; ++ + /** AuthPack from RFC 4556*/ + typedef struct _krb5_auth_pack { + krb5_pk_authenticator pkAuthenticator; +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 5378b5c23b..cf7b500837 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -1394,20 +1394,30 @@ DEFSEQTYPE(pkinit_supp_pub_info, krb5_pkinit_supp_pub_info, + MAKE_ENCODER(encode_krb5_pkinit_supp_pub_info, pkinit_supp_pub_info); + MAKE_ENCODER(encode_krb5_sp80056a_other_info, sp80056a_other_info); + +-/* A krb5_checksum encoded as an OCTET STRING, for PKAuthenticator. */ +-DEFCOUNTEDTYPE(ostring_checksum, krb5_checksum, contents, length, octetstring); ++DEFFIELD(pachecksum2_0, krb5_pachecksum2, checksum, 0, ostring_data); ++DEFFIELD(pachecksum2_1, krb5_pachecksum2, algorithmIdentifier, 1, ++ algorithm_identifier); ++static const struct atype_info *pachecksum2_fields[] = { ++ &k5_atype_pachecksum2_0, &k5_atype_pachecksum2_1 ++}; ++DEFSEQTYPE(pachecksum2, krb5_pachecksum2, pachecksum2_fields); ++ ++DEFPTRTYPE(pachecksum2_ptr, pachecksum2); ++DEFOPTIONALZEROTYPE(opt_pachecksum2_ptr, pachecksum2_ptr); + + DEFFIELD(pk_authenticator_0, krb5_pk_authenticator, cusec, 0, int32); + DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time); + DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32); + DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3, +- ostring_checksum); ++ ostring_data); + DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4, + opt_ostring_data_ptr); ++DEFFIELD(pk_authenticator_5, krb5_pk_authenticator, paChecksum2, 5, ++ opt_pachecksum2_ptr); + static const struct atype_info *pk_authenticator_fields[] = { + &k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1, + &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3, +- &k5_atype_pk_authenticator_4 ++ &k5_atype_pk_authenticator_4, &k5_atype_pk_authenticator_5 + }; + DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); + +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 7ba7155bb4..a1564b6df2 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -338,6 +338,7 @@ void free_krb5_external_principal_identifier(krb5_external_principal_identifier + void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in); + void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in); + void free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in); ++void free_pachecksum2(krb5_context context, krb5_pachecksum2 **in); + krb5_error_code pkinit_copy_krb5_data(krb5_data *dst, const krb5_data *src); + + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index b08022a214..433f477538 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -56,10 +56,9 @@ use_content_info(krb5_context context, pkinit_req_context req, + static krb5_error_code + pkinit_as_req_create(krb5_context context, pkinit_context plgctx, + pkinit_req_context reqctx, krb5_timestamp ctsec, +- krb5_int32 cusec, krb5_ui_4 nonce, +- const krb5_checksum *cksum, +- krb5_principal client, krb5_principal server, +- krb5_data **as_req); ++ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum, ++ const krb5_pachecksum2 *cksum2, krb5_principal client, ++ krb5_principal server, krb5_data **as_req); + + static krb5_error_code + pkinit_as_rep_parse(krb5_context context, pkinit_context plgctx, +@@ -89,7 +88,8 @@ pa_pkinit_gen_req(krb5_context context, + krb5_timestamp ctsec = 0; + krb5_int32 cusec = 0; + krb5_ui_4 nonce = 0; +- krb5_checksum cksum; ++ krb5_data cksum = empty_data(); ++ krb5_pachecksum2 *cksum2 = NULL; + krb5_data *der_req = NULL; + krb5_pa_data **return_pa_data = NULL; + +@@ -118,15 +118,10 @@ pa_pkinit_gen_req(krb5_context context, + goto cleanup; + } + +- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req, +- &cksum); ++ retval = crypto_generate_checksums(context, der_req, &cksum, &cksum2); + if (retval) + goto cleanup; +- TRACE_PKINIT_CLIENT_REQ_CHECKSUM(context, &cksum); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", der_req->length); +- print_buffer(der_req->data, der_req->length); +-#endif ++ TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(context, &cksum, cksum2); + + retval = cb->get_preauth_time(context, rock, TRUE, &ctsec, &cusec); + if (retval) +@@ -140,7 +135,8 @@ pa_pkinit_gen_req(krb5_context context, + nonce = request->nonce; + + retval = pkinit_as_req_create(context, plgctx, reqctx, ctsec, cusec, +- nonce, &cksum, request->client, request->server, &out_data); ++ nonce, &cksum, cksum2, request->client, ++ request->server, &out_data); + if (retval) { + pkiDebug("error %d on pkinit_as_req_create; aborting PKINIT\n", + (int) retval); +@@ -168,23 +164,19 @@ pa_pkinit_gen_req(krb5_context context, + + cleanup: + krb5_free_data(context, der_req); +- krb5_free_checksum_contents(context, &cksum); ++ krb5_free_data_contents(context, &cksum); ++ free_pachecksum2(context, &cksum2); + krb5_free_data(context, out_data); + krb5_free_pa_data(context, return_pa_data); + return retval; + } + + static krb5_error_code +-pkinit_as_req_create(krb5_context context, +- pkinit_context plgctx, +- pkinit_req_context reqctx, +- krb5_timestamp ctsec, +- krb5_int32 cusec, +- krb5_ui_4 nonce, +- const krb5_checksum * cksum, +- krb5_principal client, +- krb5_principal server, +- krb5_data ** as_req) ++pkinit_as_req_create(krb5_context context, pkinit_context plgctx, ++ pkinit_req_context reqctx, krb5_timestamp ctsec, ++ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum, ++ const krb5_pachecksum2 *cksum2, krb5_principal client, ++ krb5_principal server, krb5_data **as_req) + { + krb5_error_code retval = ENOMEM; + krb5_data spki = empty_data(), *coded_auth_pack = NULL; +@@ -202,6 +194,7 @@ pkinit_as_req_create(krb5_context context, + auth_pack.pkAuthenticator.paChecksum = *cksum; + if (!reqctx->opts->disable_freshness) + auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; ++ auth_pack.pkAuthenticator.paChecksum2 = (krb5_pachecksum2 *)cksum2; + auth_pack.clientDHNonce.length = 0; + auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; + +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 905e90d29c..a32b373c32 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -34,25 +34,49 @@ + + /* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */ +-static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; ++static char kdf_sha1[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; + /* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */ +-static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; ++static char kdf_sha256[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; + /* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */ +-static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; ++static char kdf_sha512[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; + +-const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid }; +-const krb5_data sha256_id = { KV5M_DATA, sizeof(sha256_oid), sha256_oid }; +-const krb5_data sha512_id = { KV5M_DATA, sizeof(sha512_oid), sha512_oid }; ++const krb5_data kdf_sha1_id = { KV5M_DATA, sizeof(kdf_sha1), kdf_sha1 }; ++const krb5_data kdf_sha256_id = { KV5M_DATA, sizeof(kdf_sha256), kdf_sha256 }; ++const krb5_data kdf_sha512_id = { KV5M_DATA, sizeof(kdf_sha512), kdf_sha512 }; + + krb5_data const * const supported_kdf_alg_ids[] = { +- &sha256_id, +- &sha1_id, +- &sha512_id, ++ &kdf_sha256_id, ++ &kdf_sha1_id, ++ &kdf_sha512_id, + NULL + }; + ++/* RFC 3370 sha-1: iso(1) identified-organization(3) oiw(14) secsig(3) ++ * algorithm(2) 26 */ ++static char cms_sha1[] = { 0x2b, 0x0e, 0x03, 0x02, 0x1a }; ++/* RFC 5754 id-sha256: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 1 */ ++static char cms_sha256[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01 ++}; ++/* RFC 5754 id-sha384: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 2 */ ++static char cms_sha384[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02 ++}; ++/* RFC 5754 id-sha512: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 3 */ ++static char cms_sha512[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03 ++}; ++ ++const krb5_data cms_sha1_id = { KV5M_DATA, sizeof(cms_sha1), cms_sha1 }; ++const krb5_data cms_sha256_id = { KV5M_DATA, sizeof(cms_sha256), cms_sha256 }; ++const krb5_data cms_sha384_id = { KV5M_DATA, sizeof(cms_sha384), cms_sha384 }; ++const krb5_data cms_sha512_id = { KV5M_DATA, sizeof(cms_sha512), cms_sha512 }; ++ + /* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) + * rsadsi(113549) pkcs(1) 1 11 */ + static char sha256WithRSAEncr_oid[9] = { +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index fd876e4850..3b12e904b1 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -562,9 +562,13 @@ pkinit_alg_agility_kdf(krb5_context context, + krb5_data *pk_as_rep, + krb5_keyblock *key_block); + +-extern const krb5_data sha1_id; +-extern const krb5_data sha256_id; +-extern const krb5_data sha512_id; ++extern const krb5_data kdf_sha1_id; ++extern const krb5_data kdf_sha256_id; ++extern const krb5_data kdf_sha512_id; ++extern const krb5_data cms_sha1_id; ++extern const krb5_data cms_sha256_id; ++extern const krb5_data cms_sha384_id; ++extern const krb5_data cms_sha512_id; + extern const krb5_data oakley_1024; + extern const krb5_data oakley_2048; + extern const krb5_data oakley_4096; +@@ -597,4 +601,18 @@ crypto_req_cert_matching_data(krb5_context context, + + int parse_dh_min_bits(krb5_context context, const char *str); + ++/* Generate a SHA-1 checksum over body in *cksum1_out and a SHA-256 checksum ++ * over body in *cksum2_out with appropriate metadata. */ ++krb5_error_code ++crypto_generate_checksums(krb5_context context, const krb5_data *body, ++ krb5_data *cksum1_out, ++ krb5_pachecksum2 **cksum2_out); ++ ++/* Verify the SHA-1 checksum in cksum1 and the tagged checksum in cksum2. ++ * cksum2 may be NULL, in which case only cksum1 is verified. */ ++krb5_error_code ++crypto_verify_checksums(krb5_context context, krb5_data *body, ++ const krb5_data *cksum1, ++ const krb5_pachecksum2 *cksum2); ++ + #endif /* _PKINIT_CRYPTO_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 402bf1b9b3..429b7d202c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -2616,11 +2616,11 @@ cleanup: + static const EVP_MD * + algid_to_md(const krb5_data *alg_id) + { +- if (data_eq(*alg_id, sha1_id)) ++ if (data_eq(*alg_id, kdf_sha1_id)) + return EVP_sha1(); +- if (data_eq(*alg_id, sha256_id)) ++ if (data_eq(*alg_id, kdf_sha256_id)) + return EVP_sha256(); +- if (data_eq(*alg_id, sha512_id)) ++ if (data_eq(*alg_id, kdf_sha512_id)) + return EVP_sha512(); + return NULL; + } +@@ -5663,3 +5663,113 @@ parse_dh_min_bits(krb5_context context, const char *str) + TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str); + return PKINIT_DEFAULT_DH_MIN_BITS; + } ++ ++/* Return the OpenSSL message digest type matching the given CMS OID, or NULL ++ * if it doesn't match any of the CMS OIDs we know about. */ ++static const EVP_MD * ++md_from_cms_oid(const krb5_data *alg_id) ++{ ++ if (data_eq(*alg_id, cms_sha1_id)) ++ return EVP_sha1(); ++ if (data_eq(*alg_id, cms_sha256_id)) ++ return EVP_sha256(); ++ if (data_eq(*alg_id, cms_sha384_id)) ++ return EVP_sha384(); ++ if (data_eq(*alg_id, cms_sha512_id)) ++ return EVP_sha512(); ++ return NULL; ++} ++ ++/* Compute a message digest of the given type over body, placing the result in ++ * *digest_out in allocated storage. Return true on success. */ ++static krb5_boolean ++make_digest(const krb5_data *body, const EVP_MD *md, krb5_data *digest_out) ++{ ++ krb5_error_code ret; ++ krb5_data d; ++ ++ if (md == NULL) ++ return FALSE; ++ ret = alloc_data(&d, EVP_MD_size(md)); ++ if (ret) ++ return FALSE; ++ if (!EVP_Digest(body->data, body->length, (uint8_t *)d.data, &d.length, md, ++ NULL)) { ++ free(d.data); ++ return FALSE; ++ } ++ *digest_out = d; ++ return TRUE; ++} ++ ++/* Return true if digest verifies for the given body and message digest ++ * type. */ ++static krb5_boolean ++check_digest(const krb5_data *body, const EVP_MD *md, const krb5_data *digest) ++{ ++ unsigned int digest_len; ++ uint8_t buf[EVP_MAX_MD_SIZE]; ++ ++ if (md == NULL) ++ return FALSE; ++ if (!EVP_Digest(body->data, body->length, buf, &digest_len, md, NULL)) ++ return FALSE; ++ return (digest->length == digest_len && ++ CRYPTO_memcmp(digest->data, buf, digest_len) == 0); ++} ++ ++krb5_error_code ++crypto_generate_checksums(krb5_context context, const krb5_data *body, ++ krb5_data *cksum1_out, krb5_pachecksum2 **cksum2_out) ++{ ++ krb5_data cksum1 = empty_data(); ++ krb5_pachecksum2 *cksum2 = NULL; ++ krb5_error_code ret; ++ ++ if (!make_digest(body, EVP_sha1(), &cksum1)) ++ goto fail; ++ ++ cksum2 = k5alloc(sizeof(*cksum2), &ret); ++ if (cksum2 == NULL) ++ goto fail; ++ ++ if (!make_digest(body, EVP_sha256(), &cksum2->checksum)) ++ goto fail; ++ ++ if (krb5int_copy_data_contents(context, &cms_sha256_id, ++ &cksum2->algorithmIdentifier.algorithm)) ++ goto fail; ++ ++ cksum2->algorithmIdentifier.parameters = empty_data(); ++ ++ *cksum1_out = cksum1; ++ *cksum2_out = cksum2; ++ return 0; ++ ++fail: ++ krb5_free_data_contents(context, &cksum1); ++ free_pachecksum2(context, &cksum2); ++ return KRB5_CRYPTO_INTERNAL; ++} ++ ++krb5_error_code ++crypto_verify_checksums(krb5_context context, krb5_data *body, ++ const krb5_data *cksum1, ++ const krb5_pachecksum2 *cksum2) ++{ ++ const EVP_MD *md; ++ ++ /* RFC 4556 doesn't say what error to return if the checksum doesn't match. ++ * Windows returns this one. */ ++ if (!check_digest(body, EVP_sha1(), cksum1)) ++ return KRB5KRB_AP_ERR_MODIFIED; ++ ++ if (cksum2 == NULL) ++ return 0; ++ ++ md = md_from_cms_oid(&cksum2->algorithmIdentifier.algorithm); ++ if (!check_digest(body, md, &cksum2->checksum)) ++ return KRB5KRB_AP_ERR_MODIFIED; ++ ++ return 0; ++} +diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +index 99c93ac128..dd6e8d7503 100644 +--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c ++++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +@@ -126,7 +126,7 @@ main(int argc, char **argv) + + /* TEST 1: SHA-1/AES */ + /* set up algorithm id */ +- alg_id.algorithm = sha1_id; ++ alg_id.algorithm = kdf_sha1_id; + + enctype = enctype_aes; + +@@ -157,7 +157,7 @@ main(int argc, char **argv) + + /* TEST 2: SHA-256/AES */ + /* set up algorithm id */ +- alg_id.algorithm = sha256_id; ++ alg_id.algorithm = kdf_sha256_id; + + enctype = enctype_aes; + +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 25965eb5d2..891f47fd26 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -29,6 +29,7 @@ + * SUCH DAMAGES. + */ + ++#include "k5-int.h" + #include "pkinit.h" + + #define FAKECERT +@@ -119,8 +120,9 @@ free_krb5_auth_pack(krb5_auth_pack **in) + { + if ((*in) == NULL) return; + krb5_free_data_contents(NULL, &(*in)->clientPublicValue); +- free((*in)->pkAuthenticator.paChecksum.contents); ++ free((*in)->pkAuthenticator.paChecksum.data); + krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken); ++ free_pachecksum2(NULL, &(*in)->pkAuthenticator.paChecksum2); + if ((*in)->supportedCMSTypes != NULL) + free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes)); + if ((*in)->supportedKDFs) { +@@ -196,6 +198,18 @@ free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in) + free(*in); + } + ++void ++free_pachecksum2(krb5_context context, krb5_pachecksum2 **in) ++{ ++ if (*in == NULL) ++ return; ++ krb5_free_data_contents(context, &(*in)->checksum); ++ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.algorithm); ++ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.parameters); ++ free(*in); ++ *in = NULL; ++} ++ + void + init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) + { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index e22bcb195b..f558308483 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -428,11 +428,12 @@ pkinit_server_verify_padata(krb5_context context, + krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL}; + krb5_pa_pk_as_req *reqp = NULL; + krb5_auth_pack *auth_pack = NULL; ++ krb5_pk_authenticator *pka; + pkinit_kdc_context plgctx = NULL; + pkinit_kdc_req_context reqctx = NULL; + krb5_checksum cksum = {0, 0, 0, NULL}; + krb5_data *der_req = NULL; +- krb5_data k5data, *ftoken; ++ krb5_data k5data; + int is_signed = 1; + krb5_pa_data **e_data = NULL; + krb5_kdcpreauth_modreq modreq = NULL; +@@ -524,8 +525,9 @@ pkinit_server_verify_padata(krb5_context context, + pkiDebug("failed to decode krb5_auth_pack\n"); + goto cleanup; + } ++ pka = &auth_pack->pkAuthenticator; + +- retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); ++ retval = krb5_check_clockskew(context, pka->ctime); + if (retval) + goto cleanup; + +@@ -548,36 +550,14 @@ pkinit_server_verify_padata(krb5_context context, + goto cleanup; + } + der_req = cb->request_body(context, rock); +- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req, +- &cksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } +- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || +- k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents, +- cksum.length) != 0) { +- pkiDebug("failed to match the checksum\n"); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("received checksum type=%d size=%d ", +- auth_pack->pkAuthenticator.paChecksum.checksum_type, +- auth_pack->pkAuthenticator.paChecksum.length); +- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, +- auth_pack->pkAuthenticator.paChecksum.length); +- pkiDebug("expected checksum type=%d size=%d ", +- cksum.checksum_type, cksum.length); +- print_buffer(cksum.contents, cksum.length); +-#endif + +- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; ++ retval = crypto_verify_checksums(context, der_req, &pka->paChecksum, ++ pka->paChecksum2); ++ if (retval) + goto cleanup; +- } + +- ftoken = auth_pack->pkAuthenticator.freshnessToken; +- if (ftoken != NULL) { +- retval = cb->check_freshness_token(context, rock, ftoken); ++ if (pka->freshnessToken != NULL) { ++ retval = cb->check_freshness_token(context, rock, pka->freshnessToken); + if (retval) + goto cleanup; + valid_freshness_token = TRUE; +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 1faa6816d7..7b68d4b3b1 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -58,8 +58,9 @@ + TRACE(c, "PKINIT client verified DH reply") + #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ + TRACE(c, "PKINIT client could not verify DH reply") +-#define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \ +- TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum) ++#define TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(c, ck1, ck2) \ ++ TRACE(c, "PKINIT client computed checksums: {hexdata} {hexdata}", \ ++ ck1, &(ck2)->checksum) + #define TRACE_PKINIT_CLIENT_REQ_DH(c) \ + TRACE(c, "PKINIT client making DH request") + #define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \ +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index 2fa6dce8eb..f47849abad 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -1174,7 +1174,7 @@ main(int argc, char **argv) + /* decode_krb5_auth_pack */ + { + setup(krb5_auth_pack,ktest_make_sample_auth_pack); +- decode_run("krb5_auth_pack","","30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61", ++ decode_run("krb5_auth_pack","","30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61", + acc.decode_krb5_auth_pack, + ktest_equal_auth_pack,ktest_free_auth_pack); + ktest_empty_auth_pack(&ref); +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index d37e4fa7e6..7f54aa3184 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -700,9 +700,7 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) + p->cusec = SAMPLE_USEC; + p->ctime = SAMPLE_TIME; + p->nonce = SAMPLE_NONCE; +- ktest_make_sample_checksum(&p->paChecksum); +- /* We don't encode the checksum type, only the contents. */ +- p->paChecksum.checksum_type = 0; ++ ktest_make_sample_data(&p->paChecksum); + p->freshnessToken = ealloc(sizeof(krb5_data)); + ktest_make_sample_data(p->freshnessToken); + } +@@ -1604,8 +1602,7 @@ ktest_empty_pa_otp_req(krb5_pa_otp_req *p) + static void + ktest_empty_pk_authenticator(krb5_pk_authenticator *p) + { +- ktest_empty_checksum(&p->paChecksum); +- p->paChecksum.contents = NULL; ++ ktest_empty_data(&p->paChecksum); + krb5_free_data(NULL, p->freshnessToken); + p->freshnessToken = NULL; + } +diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c +index b48a0285d2..13786dd1e5 100644 +--- a/src/tests/asn.1/ktest_equal.c ++++ b/src/tests/asn.1/ktest_equal.c +@@ -844,7 +844,7 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref, + p = p && scalar_equal(cusec); + p = p && scalar_equal(ctime); + p = p && scalar_equal(nonce); +- p = p && struct_equal(paChecksum, ktest_equal_checksum); ++ p = p && data_eq(ref->paChecksum, var->paChecksum); + return p; + } + +diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out +index 6ec7aaa36a..a764182e15 100644 +--- a/src/tests/asn.1/pkinit_encode.out ++++ b/src/tests/asn.1/pkinit_encode.out +@@ -1,7 +1,7 @@ + encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 +-encode_krb5_auth_pack: 30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 ++encode_krb5_auth_pack: 30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A + encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 + encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 +diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out +index 46f4a34108..c47bd71f67 100644 +--- a/src/tests/asn.1/pkinit_trval.out ++++ b/src/tests/asn.1/pkinit_trval.out +@@ -38,7 +38,7 @@ encode_krb5_auth_pack: + . . [0] [Integer] 123456 + . . [1] [Generalized Time] "19940610060317Z" + . . [2] [Integer] 42 +-. . [3] [Octet String] "1234" ++. . [3] [Octet String] "krb5data" + . . [4] [Octet String] "krb5data" + . [1] [Octet String] "pvalue" + . [2] [Sequence/Sequence Of] +-- +2.49.0 + diff --git a/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch b/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch new file mode 100644 index 0000000..4b49867 --- /dev/null +++ b/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch @@ -0,0 +1,381 @@ +From 33afd2a6cfdf87d153170b41fbabfb92be49c422 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 10 Apr 2025 10:04:22 +0200 +Subject: [PATCH] [downstream] Do not block HMAC-MD4/5 in FIPS mode + +To ensure RC4 HMAC-MD5 was not used in FIPS mode, access to HMAC-MD4/5 +was not allowed in this mode. However, since we provide the +"radius_md5_fips_override" configuration parameter to allow using RADIUS +regardless to the FIPS restrictions, we should allow HMAC-MD5 to be used +too in this case, because it is required for the newly supported +Message-Authenticator attribute. + +A FIPS mode check is added in calculate_mac() which will fail if +"radius_md5_fips_override" is not true. It will not affect interactions +between krb5kdc and ipa-otpd, because the Message-Authenticator +attribute is not generated in this case. +--- + src/lib/crypto/krb/crypto_int.h | 9 +++ + src/lib/crypto/openssl/Makefile.in | 9 ++- + src/lib/crypto/openssl/common.c | 80 +++++++++++++++++++ + .../crypto/openssl/hash_provider/hash_evp.c | 62 ++------------ + src/lib/crypto/openssl/hmac.c | 15 ++-- + src/lib/krad/packet.c | 19 +++-- + 6 files changed, 120 insertions(+), 74 deletions(-) + create mode 100644 src/lib/crypto/openssl/common.c + +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index 1ee4b30e02..ff67b6bd35 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -36,6 +36,9 @@ + + #include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++#include ++ + /* + * OpenSSL 3.0 relegates MD4 and RC4 to the legacy provider, which must be + * explicitly loaded into a library context. Performing this loading within a +@@ -660,4 +663,10 @@ iov_cursor_advance(struct iov_cursor *c, size_t nblocks) + c->out_pos += nblocks * c->block_size; + } + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++krb5_error_code k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx); ++ ++#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */ ++ + #endif /* CRYPTO_INT_H */ +diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in +index 8e4cdb8bbf..cc131000bd 100644 +--- a/src/lib/crypto/openssl/Makefile.in ++++ b/src/lib/crypto/openssl/Makefile.in +@@ -8,21 +8,24 @@ STLIBOBJS=\ + hmac.o \ + kdf.o \ + pbkdf2.o \ +- sha256.o ++ sha256.o \ ++ common.o + + OBJS=\ + $(OUTPRE)cmac.$(OBJEXT) \ + $(OUTPRE)hmac.$(OBJEXT) \ + $(OUTPRE)kdf.$(OBJEXT) \ + $(OUTPRE)pbkdf2.$(OBJEXT) \ +- $(OUTPRE)sha256.$(OBJEXT) ++ $(OUTPRE)sha256.$(OBJEXT) \ ++ $(OUTPRE)common.$(OBJEXT) + + SRCS=\ + $(srcdir)/cmac.c \ + $(srcdir)/hmac.c \ + $(srcdir)/kdf.c \ + $(srcdir)/pbkdf2.c \ +- $(srcdir)/sha256.c ++ $(srcdir)/sha256.c \ ++ $(srcdir)/common.c + + SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ +diff --git a/src/lib/crypto/openssl/common.c b/src/lib/crypto/openssl/common.c +new file mode 100644 +index 0000000000..ced43fd54c +--- /dev/null ++++ b/src/lib/crypto/openssl/common.c +@@ -0,0 +1,80 @@ ++#include "crypto_int.h" ++ ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++#include ++#include ++#include ++#include ++ ++typedef struct ossl_legacy_context { ++ bool initialized; ++ OSSL_LIB_CTX *libctx; ++ OSSL_PROVIDER *default_provider; ++ OSSL_PROVIDER *legacy_provider; ++} ossl_legacy_context_t; ++ ++static thread_local ossl_legacy_context_t g_ossl_legacy_ctx; ++ ++static krb5_error_code ++init_ossl_legacy_ctx(ossl_legacy_context_t *ctx) ++{ ++ ctx->libctx = OSSL_LIB_CTX_new(); ++ if (!ctx->libctx) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Load both legacy and default provider as both may be needed. */ ++ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); ++ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); ++ ++ if (!(ctx->default_provider && ctx->legacy_provider)) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ ctx->initialized = true; ++ return 0; ++} ++ ++static void ++deinit_ossl_legacy_ctx(ossl_legacy_context_t *ctx) ++{ ++ if (ctx->legacy_provider) ++ OSSL_PROVIDER_unload(ctx->legacy_provider); ++ ++ if (ctx->default_provider) ++ OSSL_PROVIDER_unload(ctx->default_provider); ++ ++ if (ctx->libctx) ++ OSSL_LIB_CTX_free(ctx->libctx); ++ ++ ctx->initialized = false; ++} ++ ++krb5_error_code ++k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx) ++{ ++ krb5_error_code err; ++ ++ if (!FIPS_mode()) { ++ if (libctx) ++ *libctx = NULL; ++ err = 0; ++ goto end; ++ } ++ ++ if (!g_ossl_legacy_ctx.initialized) { ++ err = init_ossl_legacy_ctx(&g_ossl_legacy_ctx); ++ if (err) { ++ deinit_ossl_legacy_ctx(&g_ossl_legacy_ctx); ++ goto end; ++ } ++ } ++ ++ if (libctx) ++ *libctx = g_ossl_legacy_ctx.libctx; ++ err = 0; ++ ++end: ++ return err; ++} ++ ++#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */ +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index eb2e693e9f..2fd5d383d6 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -44,48 +44,7 @@ + #define EVP_MD_CTX_free EVP_MD_CTX_destroy + #endif + +-#include + #include +-#include +- +-typedef struct ossl_lib_md_context { +- OSSL_LIB_CTX *libctx; +- OSSL_PROVIDER *default_provider; +- OSSL_PROVIDER *legacy_provider; +-} ossl_md_context_t; +- +-static thread_local ossl_md_context_t *ossl_md_ctx = NULL; +- +-static krb5_error_code +-init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo) +-{ +- ctx->libctx = OSSL_LIB_CTX_new(); +- if (!ctx->libctx) +- return KRB5_CRYPTO_INTERNAL; +- +- /* Load both legacy and default provider as both may be needed. */ +- ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); +- ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); +- +- if (!(ctx->default_provider && ctx->legacy_provider)) +- return KRB5_CRYPTO_INTERNAL; +- +- return 0; +-} +- +-static void +-deinit_ossl_ctx(ossl_md_context_t *ctx) +-{ +- if (ctx->legacy_provider) +- OSSL_PROVIDER_unload(ctx->legacy_provider); +- +- if (ctx->default_provider) +- OSSL_PROVIDER_unload(ctx->default_provider); +- +- if (ctx->libctx) +- OSSL_LIB_CTX_free(ctx->libctx); +-} +- + + static krb5_error_code + hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, +@@ -120,25 +79,14 @@ hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data, + krb5_data *output) + { + krb5_error_code err; ++ OSSL_LIB_CTX *ossl_libctx; + EVP_MD *md = NULL; + +- if (!ossl_md_ctx) { +- ossl_md_ctx = malloc(sizeof(ossl_md_context_t)); +- if (!ossl_md_ctx) { +- err = ENOMEM; +- goto end; +- } +- +- err = init_ossl_md_ctx(ossl_md_ctx, algo); +- if (err) { +- deinit_ossl_ctx(ossl_md_ctx); +- free(ossl_md_ctx); +- ossl_md_ctx = NULL; +- goto end; +- } +- } ++ err = k5_get_ossl_legacy_libctx(&ossl_libctx); ++ if (err) ++ goto end; + +- md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL); ++ md = EVP_MD_fetch(ossl_libctx, algo, NULL); + if (!md) { + err = KRB5_CRYPTO_INTERNAL; + goto end; +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index 25a419d73a..8f9e88fec9 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -59,7 +59,6 @@ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include +-#include + #else + #include + #endif +@@ -112,11 +111,7 @@ map_digest(const struct krb5_hash_provider *hash) + return EVP_sha256(); + else if (hash == &krb5int_hash_sha384) + return EVP_sha384(); +- +- if (FIPS_mode()) +- return NULL; +- +- if (hash == &krb5int_hash_md5) ++ else if (hash == &krb5int_hash_md5) + return EVP_md5(); + else if (hash == &krb5int_hash_md4) + return EVP_md4(); +@@ -138,13 +133,19 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, + EVP_MAC_CTX *ctx = NULL; + OSSL_PARAM params[2], *p = params; + size_t i = 0, md_len; ++ OSSL_LIB_CTX *ossl_libctx; ++ krb5_error_code err; + + if (md == NULL || keyblock->length > hash->blocksize) + return KRB5_CRYPTO_INTERNAL; + if (output->length < hash->hashsize) + return KRB5_BAD_MSIZE; + +- mac = EVP_MAC_fetch(NULL, "HMAC", NULL); ++ err = k5_get_ossl_legacy_libctx(&ossl_libctx); ++ if (err) ++ return err; ++ ++ mac = EVP_MAC_fetch(ossl_libctx, "HMAC", NULL); + if (mac == NULL) + return KRB5_CRYPTO_INTERNAL; + +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index 3c1a4d507e..b95c99df65 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -278,7 +278,7 @@ lookup_msgauth_addr(const krad_packet *pkt) + * auth, which may be from pkt or from a corresponding request. + */ + static krb5_error_code +-calculate_mac(const char *secret, const krad_packet *pkt, ++calculate_mac(krb5_context ctx, const char *secret, const krad_packet *pkt, + const uint8_t auth[AUTH_FIELD_SIZE], + uint8_t mac_out[MD5_DIGEST_SIZE]) + { +@@ -288,6 +288,10 @@ calculate_mac(const char *secret, const krad_packet *pkt, + krb5_crypto_iov input[5]; + krb5_data ksecr, mac; + ++ /* Do not use HMAC-MD5 if not explicitly allowed */ ++ if (kr_use_fips(ctx)) ++ return KRB5_CRYPTO_INTERNAL; ++ + msgauth_attr = lookup_msgauth_addr(pkt); + if (msgauth_attr == NULL) + return EINVAL; +@@ -393,7 +397,8 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + + if (msgauth_required) { + /* Calculate and set the Message-Authenticator MAC. */ +- retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2); ++ retval = calculate_mac(ctx, secret, pkt, pkt_auth(pkt), ++ pkt_attr(pkt) + 2); + if (retval != 0) + goto error; + } +@@ -454,7 +459,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + * section 5.14, use the authenticator from the request, not from the + * response. + */ +- retval = calculate_mac(secret, pkt, pkt_auth(request), ++ retval = calculate_mac(ctx, secret, pkt, pkt_auth(request), + pkt_attr(pkt) + 2); + if (retval != 0) + goto error; +@@ -476,7 +481,7 @@ error: + /* Verify the Message-Authenticator value in pkt, using the provided + * authenticator (which may be from pkt or from a corresponding request). */ + static krb5_error_code +-verify_msgauth(const char *secret, const krad_packet *pkt, ++verify_msgauth(krb5_context ctx, const char *secret, const krad_packet *pkt, + const uint8_t auth[AUTH_FIELD_SIZE]) + { + uint8_t mac[MD5_DIGEST_SIZE]; +@@ -488,7 +493,7 @@ verify_msgauth(const char *secret, const krad_packet *pkt, + if (msgauth == NULL) + return ENODATA; + +- retval = calculate_mac(secret, pkt, auth, mac); ++ retval = calculate_mac(ctx, secret, pkt, auth, mac); + if (retval) + return retval; + +@@ -561,7 +566,7 @@ krad_packet_decode_request(krb5_context ctx, const char *secret, + + /* Verify Message-Authenticator if present. */ + if (has_pkt_msgauth(req)) { +- retval = verify_msgauth(secret, req, pkt_auth(req)); ++ retval = verify_msgauth(ctx, secret, req, pkt_auth(req)); + if (retval) { + krad_packet_free(req); + return retval; +@@ -613,7 +618,7 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + + /* Verify Message-Authenticator if present. */ + if (has_pkt_msgauth(*rsppkt)) { +- if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0) ++ if (verify_msgauth(ctx, secret, *rsppkt, pkt_auth(tmp)) != 0) + continue; + } + +-- +2.49.0 + diff --git a/0039-Fix-strchr-conformance-to-C23.patch b/0039-Fix-strchr-conformance-to-C23.patch new file mode 100644 index 0000000..ed2cfa7 --- /dev/null +++ b/0039-Fix-strchr-conformance-to-C23.patch @@ -0,0 +1,189 @@ +From 1761e06398e4f043e4f540f57131c37fcc53a1b9 Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Wed, 10 Dec 2025 10:42:02 +0200 +Subject: [PATCH] Fix strchr() conformance to C23 + +C23 7.28.5.1 specifies search functions such as strchr() as generic, +returning const char * if the first argument is of type const char *. +Fix uses of strchr() to conform to this change. + +[jrische@redhat.com: altered changes to avoid casts; fixed an +additional case] +[ghudson@mit.edu: condensed some declarations; rewrote commit message] + +ticket: 9191 (new) +(cherry picked from commit 6cd8580d823585d50ee4f30efd9f7e855823a369) +--- + src/lib/krb5/ccache/ccbase.c | 4 ++-- + src/lib/krb5/os/expand_path.c | 3 ++- + src/lib/krb5/os/locate_kdc.c | 15 +++++++-------- + src/plugins/preauth/pkinit/pkinit_crypto.h | 2 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 6 +++--- + src/plugins/preauth/pkinit/pkinit_identity.c | 2 +- + src/plugins/preauth/pkinit/pkinit_matching.c | 2 +- + src/tests/responder.c | 3 +-- + 8 files changed, 18 insertions(+), 19 deletions(-) + +diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c +index 5a01320832..1aada91b5e 100644 +--- a/src/lib/krb5/ccache/ccbase.c ++++ b/src/lib/krb5/ccache/ccbase.c +@@ -201,8 +201,8 @@ krb5_cc_register(krb5_context context, const krb5_cc_ops *ops, + krb5_error_code KRB5_CALLCONV + krb5_cc_resolve (krb5_context context, const char *name, krb5_ccache *cache) + { +- char *pfx, *cp; +- const char *resid; ++ char *pfx; ++ const char *cp, *resid; + unsigned int pfxlen; + krb5_error_code err; + const krb5_cc_ops *ops; +diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c +index 5cbccf08c8..6569b8820b 100644 +--- a/src/lib/krb5/os/expand_path.c ++++ b/src/lib/krb5/os/expand_path.c +@@ -454,7 +454,8 @@ k5_expand_path_tokens_extra(krb5_context context, const char *path_in, + { + krb5_error_code ret; + struct k5buf buf; +- char *tok_begin, *tok_end, *tok_val, **extra_tokens = NULL, *path; ++ const char *tok_begin, *tok_end; ++ char *tok_val, **extra_tokens = NULL, *path; + const char *path_left; + size_t nargs = 0, i; + va_list ap; +diff --git a/src/lib/krb5/os/locate_kdc.c b/src/lib/krb5/os/locate_kdc.c +index edca5ac7eb..47e15c849f 100644 +--- a/src/lib/krb5/os/locate_kdc.c ++++ b/src/lib/krb5/os/locate_kdc.c +@@ -188,8 +188,8 @@ oom: + } + + static void +-parse_uri_if_https(const char *host_or_uri, k5_transport *transport, +- const char **host, const char **uri_path) ++parse_uri_if_https(char *host_or_uri, k5_transport *transport, ++ char **host, const char **uri_path) + { + char *cp; + +@@ -229,8 +229,7 @@ locate_srv_conf_1(krb5_context context, const krb5_data *realm, + k5_transport transport, int udpport) + { + const char *realm_srv_names[4]; +- char **hostlist = NULL, *realmstr = NULL, *host = NULL; +- const char *hostspec; ++ char **hostlist = NULL, *realmstr = NULL, *host = NULL, *hostspec; + krb5_error_code code; + int i, default_port; + +@@ -535,8 +534,8 @@ prof_locate_server(krb5_context context, const krb5_data *realm, + * Return a NULL *host_out if there are any problems parsing the URI. + */ + static void +-parse_uri_fields(const char *uri, k5_transport *transport_out, +- const char **host_out, int *primary_out) ++parse_uri_fields(char *uri, k5_transport *transport_out, ++ char **host_out, int *primary_out) + + { + k5_transport transport; +@@ -604,8 +603,8 @@ locate_uri(krb5_context context, const krb5_data *realm, + krb5_error_code ret; + k5_transport transport, host_trans; + struct srv_dns_entry *answers, *entry; +- char *host; +- const char *host_field, *path; ++ char *host, *host_field; ++ const char *path; + int port, def_port, primary; + + ret = k5_make_uri_query(context, realm, req_service, &answers); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 3b12e904b1..99e2394040 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -456,7 +456,7 @@ krb5_error_code crypto_load_cas_and_crls + defines the storage type (file, directory, etc) */ + int catype, /* IN + defines the ca type (anchor, intermediate, crls) */ +- char *id); /* IN ++ const char *id); /* IN + defines the location (filename, directory name, etc) */ + + /* +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 429b7d202c..6013080afc 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -4956,7 +4956,7 @@ load_cas_and_crls(krb5_context context, + pkinit_req_crypto_context req_cryptoctx, + pkinit_identity_crypto_context id_cryptoctx, + int catype, +- char *filename) ++ const char *filename) + { + STACK_OF(X509_INFO) *sk = NULL; + STACK_OF(X509) *ca_certs = NULL; +@@ -5114,7 +5114,7 @@ load_cas_and_crls_dir(krb5_context context, + pkinit_req_crypto_context req_cryptoctx, + pkinit_identity_crypto_context id_cryptoctx, + int catype, +- char *dirname) ++ const char *dirname) + { + krb5_error_code retval = EINVAL; + DIR *d = NULL; +@@ -5166,7 +5166,7 @@ crypto_load_cas_and_crls(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, + int idtype, + int catype, +- char *id) ++ const char *id) + { + switch (idtype) { + case IDTYPE_FILE: +diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c +index a5a979f279..b06d519c66 100644 +--- a/src/plugins/preauth/pkinit/pkinit_identity.c ++++ b/src/plugins/preauth/pkinit/pkinit_identity.c +@@ -474,7 +474,7 @@ process_option_ca_crl(krb5_context context, + const char *value, + int catype) + { +- char *residual; ++ const char *residual; + unsigned int typelen; + int idtype; + +diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c +index b42485a50a..5a7f2ba3fa 100644 +--- a/src/plugins/preauth/pkinit/pkinit_matching.c ++++ b/src/plugins/preauth/pkinit/pkinit_matching.c +@@ -263,7 +263,7 @@ parse_rule_component(krb5_context context, + char err_buf[128]; + int ret; + struct keyword_desc *kw, *nextkw; +- char *nk; ++ const char *nk; + int found_next_kw = 0; + char *value = NULL; + size_t len; +diff --git a/src/tests/responder.c b/src/tests/responder.c +index 82f870ea5d..4221a20283 100644 +--- a/src/tests/responder.c ++++ b/src/tests/responder.c +@@ -282,8 +282,7 @@ responder(krb5_context ctx, void *rawdata, krb5_responder_context rctx) + /* Provide a particular response for an OTP challenge. */ + if (data->otp_answer != NULL) { + if (krb5_responder_otp_get_challenge(ctx, rctx, &ochl) == 0) { +- key = strchr(data->otp_answer, '='); +- if (key != NULL) { ++ if (strchr(data->otp_answer, '=') != NULL) { + /* Make a copy of the answer that we can chop up. */ + key = strdup(data->otp_answer); + if (key == NULL) +-- +2.51.1 + diff --git a/0040-automated-fast.patch b/0040-automated-fast.patch new file mode 100644 index 0000000..5a64233 --- /dev/null +++ b/0040-automated-fast.patch @@ -0,0 +1,226 @@ +From 3baf9b93dc1dfe38585722c71d7268304cb4a01a Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Sun, 21 Sep 2025 11:14:51 +0300 +Subject: libkrb5: in case PKINIT is configured, attempt Anonymous + PKINIT for FAST + +If auto_fast_armor is configured for the realm or globally, optimistically +assume that Anonymous PKINIT is supported as well and try to obtain it for +FAST use in case no pre-made FAST channel was established by the caller. + +This behavior will automatically enable use of passwordless pre-authentication +methods which rely on FAST channel presence in deployments such as FreeIPA. + +Notably, Microsoft Active Directory KDCs do not support Anonymous PKINIT. For +these deployments only a machine account (host keytab) can be used to build a +FAST channel. However, libkrb5 does not have access to /etc/krb5.keytab in a +general case. + +Signed-off-by: Alexander Bokovoy +--- + src/lib/krb5/krb/fast.c | 118 ++++++++++++++++++++++++++++++++++++++++ + src/lib/krb5/krb/fast.h | 2 + + src/man/krb5.conf.man | 13 +++++ + 3 files changed, 133 insertions(+) + +diff --git a/src/lib/krb5/krb/fast.c b/src/lib/krb5/krb/fast.c +index 62c9f0841..ee2e08189 100644 +--- a/src/lib/krb5/krb/fast.c ++++ b/src/lib/krb5/krb/fast.c +@@ -168,6 +168,109 @@ krb5int_fast_prep_req_body(krb5_context context, + return retval; + } + ++static krb5_boolean ++fast_is_pkinit_allowed(krb5_context context, krb5_data *realm) ++{ ++ int value; ++ krb5_error_code retval = EINVAL; ++ char realmstr[1024]; ++ const char *option = "auto_fast_armor"; ++ const int def_value = FALSE; ++ ++ if (realm != NULL && realm->length > sizeof(realmstr)-1) ++ return FALSE; ++ ++ if (realm != NULL) { ++ strncpy(realmstr, realm->data, realm->length); ++ realmstr[realm->length] = '\0'; ++ ++ retval = profile_get_boolean(context->profile, ++ KRB5_CONF_REALMS, realmstr, ++ option, def_value, &value); ++ } ++ ++ return retval ? FALSE : value; ++ ++} ++ ++static krb5_error_code ++fast_acquire_pkinit_armor(krb5_context context, ++ struct krb5int_fast_request_state *state, ++ krb5_get_init_creds_opt *opt, krb5_kdc_req *request) ++{ ++ krb5_context ctx; ++ krb5_get_init_creds_opt *options = NULL; ++ krb5_error_code retval = 0; ++ krb5_data *target_realm = &request->server->realm; ++ krb5_creds creds; ++ krb5_principal anon_princ = NULL; ++ krb5_ccache out_cc; ++ ++ /* short circuit, we are asked to perform Anonymous PKINIT already */ ++ if (opt->flags & KRB5_GET_INIT_CREDS_OPT_ANONYMOUS) { ++ return EINVAL; ++ } ++ ++ /* skip realms which do not allow use of automated FAST armor */ ++ if (!fast_is_pkinit_allowed(context, target_realm)) { ++ return EINVAL; ++ } ++ ++ retval = krb5_init_context(&ctx); ++ if (retval != 0) { ++ return retval; ++ } ++ retval = krb5_get_init_creds_opt_alloc(ctx, &options); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ krb5_get_init_creds_opt_set_anonymous(options, 1); ++ retval = krb5_cc_new_unique(ctx, "MEMORY", NULL, &out_cc); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_get_init_creds_opt_set_out_ccache(ctx, options, out_cc); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_build_principal_ext(ctx, &anon_princ, ++ target_realm->length, target_realm->data, ++ strlen(KRB5_WELLKNOWN_NAMESTR), ++ KRB5_WELLKNOWN_NAMESTR, ++ strlen(KRB5_ANONYMOUS_PRINCSTR), ++ KRB5_ANONYMOUS_PRINCSTR, 0); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_get_init_creds_password(ctx, &creds, anon_princ, 0, ++ NULL /* no prompter */, NULL, ++ 0, NULL /* service name */, ++ options); ++ if (retval == 0) { ++ state->fast_state_flags |= KRB5INT_FAST_OWN_ARMOR; ++ state->armor_ccache = out_cc; ++ } ++cleanup: ++ if (retval != 0 && out_cc != NULL) { ++ (void) krb5_cc_destroy(ctx, out_cc); ++ } ++ if (retval == 0) { ++ krb5_free_cred_contents(ctx, &creds); ++ } ++ if (options != NULL) { ++ krb5_get_init_creds_opt_free(ctx, options); ++ } ++ if (anon_princ != NULL) { ++ krb5_free_principal(ctx, anon_princ); ++ } ++ krb5_free_context(ctx); ++ ++ return retval; ++} ++ + krb5_error_code + krb5int_fast_as_armor(krb5_context context, + struct krb5int_fast_request_state *state, +@@ -178,10 +281,20 @@ krb5int_fast_as_armor(krb5_context context, + krb5_principal target_principal = NULL; + krb5_data *target_realm; + const char *ccname = k5_gic_opt_get_fast_ccache_name(opt); ++ char *fast_ccname = NULL; + krb5_flags fast_flags; + + krb5_clear_error_message(context); + target_realm = &request->server->realm; ++ if (ccname == NULL) { ++ retval = fast_acquire_pkinit_armor(context, state, opt, request); ++ if (retval == 0) { ++ retval = krb5_cc_get_full_name(context, state->armor_ccache, &fast_ccname); ++ if (retval == 0 && fast_ccname != NULL) ++ ccname = fast_ccname; ++ } ++ retval = 0; ++ } + if (ccname != NULL) { + TRACE_FAST_ARMOR_CCACHE(context, ccname); + state->fast_state_flags |= KRB5INT_FAST_ARMOR_AVAIL; +@@ -220,6 +333,8 @@ krb5int_fast_as_armor(krb5_context context, + krb5_cc_close(context, ccache); + if (target_principal) + krb5_free_principal(context, target_principal); ++ if (fast_ccname) ++ free(fast_ccname); + return retval; + } + +@@ -615,6 +730,9 @@ krb5int_fast_free_state(krb5_context context, + /*We are responsible for none of the store in the fast_outer_req*/ + krb5_free_keyblock(context, state->armor_key); + krb5_free_fast_armor(context, state->armor); ++ if (state->fast_state_flags & KRB5INT_FAST_OWN_ARMOR) { ++ krb5_cc_destroy(context, state->armor_ccache); ++ } + free(state); + } + +diff --git a/src/lib/krb5/krb/fast.h b/src/lib/krb5/krb/fast.h +index 7156ea203..e5fe8bd54 100644 +--- a/src/lib/krb5/krb/fast.h ++++ b/src/lib/krb5/krb/fast.h +@@ -34,6 +34,7 @@ struct krb5int_fast_request_state { + krb5_kdc_req fast_outer_request; + krb5_keyblock *armor_key; /*non-null means fast is in use*/ + krb5_fast_armor *armor; ++ krb5_ccache armor_ccache; + krb5_ui_4 fast_state_flags; + krb5_ui_4 fast_options; + krb5_int32 nonce; +@@ -41,6 +42,7 @@ struct krb5int_fast_request_state { + + #define KRB5INT_FAST_DO_FAST (1l<<0) /* Perform FAST */ + #define KRB5INT_FAST_ARMOR_AVAIL (1l<<1) ++#define KRB5INT_FAST_OWN_ARMOR (1l<<2) + + krb5_error_code + krb5int_fast_prep_req_body(krb5_context context, +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index d4caa2bd3..ac7649647 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -650,6 +650,19 @@ primary KDC, in case the user\(aqs password has just been changed, and + the updated database has not been propagated to the replica + servers yet. New in release 1.19. + .TP ++\fBauto_fast_armor\fP ++If this flag is true, then initial ticket request will use Anonymous ++PKINIT to protect the communication as a FAST channel in case an application ++did not provide its own FAST channel. This is useful for deployments where ++pre-authentication methods require use of the FAST channel, such as ++passwordless methods provided by FreeIPA. Microsoft Active Directory ++implementation of PKINIT does not support Anonymous PKINIT feature. ++As a result, \fIauto_fast_armor\fP defaults to false. ++.sp ++Use of \fIauto_fast_armor = true\fP requires properly configured PKINIT and ++WELLKNOWN/ANONYMOUS principal defined on the KDC side. Consult KDC documentation ++for details. ++.TP + \fBv4_instance_convert\fP + This subsection allows the administrator to configure exceptions + to the \fBdefault_domain\fP mapping rule. It contains V4 instances +-- +2.51.0 + diff --git a/0041-bail-if-prompter-is-not-specified-but-required.patch b/0041-bail-if-prompter-is-not-specified-but-required.patch new file mode 100644 index 0000000..d1a3dc7 --- /dev/null +++ b/0041-bail-if-prompter-is-not-specified-but-required.patch @@ -0,0 +1,40 @@ +From ff580d9cf86202d45454a6b6f53accc22cb40b62 Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Sun, 19 Oct 2025 18:14:29 +0300 +Subject: [PATCH] bail if prompter is not specified but required + +GSSAPI gss_init_sec_context() may trigger credential re-initialization +if the cred in ccache is expired. If automatic FAST armor is in use, +we'd request Anonymous PKINIT and use it as an armor and this will +enable seeing pre-authentication methods which require armor presence. + +OTP is one of such methods and its use requires prompter to be set, +but GSSAPI cannot specify a prompter and thus we should fail any +pre-auth where a prompter wasn't passed. + +PKINIT PKCS11 and SAM-2 preauth methods use KRB5_LIBOS_CANTREADPWD while PKINIT +and gic_pwd.c use EIO. Use EIO here because we technically attempt to read a +PIN rather than a password. + +Signed-off-by: Alexander Bokovoy +--- + src/lib/krb5/krb/preauth_otp.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c +index 07ffc15c2..48003da62 100644 +--- a/src/lib/krb5/krb/preauth_otp.c ++++ b/src/lib/krb5/krb/preauth_otp.c +@@ -479,6 +479,9 @@ doprompt(krb5_context context, krb5_prompter_fct prompter, void *prompter_data, + krb5_error_code retval; + krb5_prompt_type prompt_type = KRB5_PROMPT_TYPE_PREAUTH; + ++ if (prompter == NULL) ++ return EIO; ++ + if (prompttxt == NULL || out == NULL) + return EINVAL; + +-- +2.51.0 + diff --git a/2010-007-patch.txt b/2010-007-patch.txt deleted file mode 100644 index b1c3793..0000000 --- a/2010-007-patch.txt +++ /dev/null @@ -1,202 +0,0 @@ -Index: krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c -=================================================================== ---- krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (revision 24455) -+++ krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (working copy) -@@ -691,8 +691,7 @@ - krb5_reply_key_pack *key_pack = NULL; - krb5_reply_key_pack_draft9 *key_pack9 = NULL; - krb5_data *encoded_key_pack = NULL; -- unsigned int num_types; -- krb5_cksumtype *cksum_types = NULL; -+ krb5_cksumtype cksum_type; - - pkinit_kdc_context plgctx; - pkinit_kdc_req_context reqctx; -@@ -882,14 +881,25 @@ - retval = ENOMEM; - goto cleanup; - } -- /* retrieve checksums for a given enctype of the reply key */ -- retval = krb5_c_keyed_checksum_types(context, -- encrypting_key->enctype, &num_types, &cksum_types); -- if (retval) -- goto cleanup; - -- /* pick the first of acceptable enctypes for the checksum */ -- retval = krb5_c_make_checksum(context, cksum_types[0], -+ switch (encrypting_key->enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ cksum_type = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ cksum_type = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ retval = krb5int_c_mandatory_cksumtype(context, -+ encrypting_key->enctype, -+ &cksum_type); -+ if (retval) -+ goto cleanup; -+ break; -+ } -+ -+ retval = krb5_c_make_checksum(context, cksum_type, - encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, - req_pkt, &key_pack->asChecksum); - if (retval) { -@@ -1033,7 +1043,6 @@ - krb5_free_data(context, encoded_key_pack); - free(dh_pubkey); - free(server_key); -- free(cksum_types); - - switch ((int)padata->pa_type) { - case KRB5_PADATA_PK_AS_REQ: -Index: krb5-1.8/src/lib/crypto/krb/cksumtypes.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/cksumtypes.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/cksumtypes.c (working copy) -@@ -101,7 +101,7 @@ - - { CKSUMTYPE_MD5_HMAC_ARCFOUR, - "md5-hmac-rc4", { 0 }, "Microsoft MD5 HMAC", -- NULL, &krb5int_hash_md5, -+ &krb5int_enc_arcfour, &krb5int_hash_md5, - krb5int_hmacmd5_checksum, NULL, - 16, 16, 0 }, - }; -Index: krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (working copy) -@@ -35,6 +35,13 @@ - { - if (ctp->flags & CKSUM_UNKEYED) - return FALSE; -+ /* Stream ciphers do not play well with RFC 3961 key derivation, so be -+ * conservative with RC4. */ -+ if ((ktp->etype == ENCTYPE_ARCFOUR_HMAC || -+ ktp->etype == ENCTYPE_ARCFOUR_HMAC_EXP) && -+ ctp->ctype != CKSUMTYPE_HMAC_MD5_ARCFOUR && -+ ctp->ctype != CKSUMTYPE_MD5_HMAC_ARCFOUR) -+ return FALSE; - return (!ctp->enc || ktp->enc == ctp->enc); - } - -Index: krb5-1.8/src/lib/crypto/krb/dk/derive.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/dk/derive.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/dk/derive.c (working copy) -@@ -91,6 +91,8 @@ - blocksize = enc->block_size; - keybytes = enc->keybytes; - -+ if (blocksize == 1) -+ return KRB5_BAD_ENCTYPE; - if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) - return KRB5_CRYPTO_INTERNAL; - -Index: krb5-1.8/src/lib/gssapi/krb5/util_crypt.c -=================================================================== ---- krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (revision 24455) -+++ krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (working copy) -@@ -119,10 +119,22 @@ - if (code != 0) - return code; - -- code = (*kaccess.mandatory_cksumtype)(context, subkey->keyblock.enctype, -- cksumtype); -- if (code != 0) -- return code; -+ switch (subkey->keyblock.enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ *cksumtype = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ *cksumtype = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ code = (*kaccess.mandatory_cksumtype)(context, -+ subkey->keyblock.enctype, -+ cksumtype); -+ if (code != 0) -+ return code; -+ break; -+ } - - switch (subkey->keyblock.enctype) { - case ENCTYPE_DES_CBC_MD5: -Index: krb5-1.8/src/lib/krb5/krb/pac.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/pac.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/pac.c (working copy) -@@ -582,6 +582,8 @@ - checksum.checksum_type = load_32_le(p); - checksum.length = checksum_data.length - PAC_SIGNATURE_DATA_LENGTH; - checksum.contents = p + PAC_SIGNATURE_DATA_LENGTH; -+ if (!krb5_c_is_keyed_cksum(checksum.checksum_type)) -+ return KRB5KRB_AP_ERR_INAPP_CKSUM; - - pac_data.length = pac->data.length; - pac_data.data = malloc(pac->data.length); -Index: krb5-1.8/src/lib/krb5/krb/preauth2.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/preauth2.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/preauth2.c (working copy) -@@ -1578,7 +1578,9 @@ - - cksum = sc2->sam_cksum; - -- while (*cksum) { -+ for (; *cksum; cksum++) { -+ if (!krb5_c_is_keyed_cksum((*cksum)->checksum_type)) -+ continue; - /* Check this cksum */ - retval = krb5_c_verify_checksum(context, as_key, - KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM, -@@ -1592,7 +1594,6 @@ - } - if (valid_cksum) - break; -- cksum++; - } - - if (!valid_cksum) { -Index: krb5-1.8/src/lib/krb5/krb/mk_safe.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/mk_safe.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/mk_safe.c (working copy) -@@ -215,10 +215,28 @@ - for (i = 0; i < nsumtypes; i++) - if (auth_context->safe_cksumtype == sumtypes[i]) - break; -- if (i == nsumtypes) -- i = 0; -- sumtype = sumtypes[i]; - krb5_free_cksumtypes (context, sumtypes); -+ if (i < nsumtypes) -+ sumtype = auth_context->safe_cksumtype; -+ else { -+ switch (enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ sumtype = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ sumtype = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ retval = krb5int_c_mandatory_cksumtype(context, enctype, -+ &sumtype); -+ if (retval) { -+ CLEANUP_DONE(); -+ goto error; -+ } -+ break; -+ } -+ } - } - if ((retval = krb5_mk_safe_basic(context, userdata, key, &replaydata, - plocal_fulladdr, premote_fulladdr, diff --git a/Add-German-translation.patch b/Add-German-translation.patch deleted file mode 100644 index bb3ecb3..0000000 --- a/Add-German-translation.patch +++ /dev/null @@ -1,9333 +0,0 @@ -From 914be6ccfa5e3cb52d0e0e72720eca8f2e528250 Mon Sep 17 00:00:00 2001 -From: Chris Leick -Date: Wed, 6 Apr 2016 18:14:40 -0400 -Subject: [PATCH] Add German translation - -ticket: 8515 (new) -(cherry picked from commit 0c9a4d9734c29a77d3c7ac267e8e885a75f44b4f) ---- - src/po/Makefile.in | 2 +- - src/po/de.po | 9301 ++++++++++++++++++++++++++++++++++++++++++++++++++++ - 2 files changed, 9302 insertions(+), 1 deletion(-) - create mode 100644 src/po/de.po - -diff --git a/src/po/Makefile.in b/src/po/Makefile.in -index fdaf872a1..6753447dc 100644 ---- a/src/po/Makefile.in -+++ b/src/po/Makefile.in -@@ -18,7 +18,7 @@ ETSRCS= $(BUILDTOP)/lib/gssapi/generic/gssapi_err_generic.c \ - $(BUILDTOP)/lib/krb5/error_tables/kv5m_err.c \ - $(BUILDTOP)/lib/krb5/error_tables/krb524_err.c - # This is a placeholder until we have an actual translation. --CATALOGS=en_US.mo -+CATALOGS=en_US.mo de.mo - - .SUFFIXES: .po .mo - .po.mo: -diff --git a/src/po/de.po b/src/po/de.po -new file mode 100644 -index 000000000..2144d7833 ---- /dev/null -+++ b/src/po/de.po -@@ -0,0 +1,9301 @@ -+# German translation of mit-krb5. -+# This file is distributed under the same license as the mit-krb5 package. -+# Copyright (C) 1985-2013 by the Massachusetts Institute of Technology. -+# Copyright (C) of this file 2014-2016 Chris Leick . -+# -+msgid "" -+msgstr "" -+"Project-Id-Version: mit-krb5 13.2\n" -+"Report-Msgid-Bugs-To: krbdev@mit.edu\n" -+"POT-Creation-Date: 2015-05-06 14:59-0400\n" -+"PO-Revision-Date: 2016-04-07 08:15+0200\n" -+"Last-Translator: Chris Leick \n" -+"Language-Team: German \n" -+"Language: de\n" -+"MIME-Version: 1.0\n" -+"Content-Type: text/plain; charset=UTF-8\n" -+"Content-Transfer-Encoding: 8bit\n" -+"Plural-Forms: nplurals=2; plural=n != 1;\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:62 -+#, c-format -+msgid "Usage: %s [-A] [-q] [-c cache_name]\n" -+msgstr "Aufruf: %s [-A] [-q] [-c Zwischenspeichername]\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:63 -+#, c-format -+msgid "\t-A destroy all credential caches in collection\n" -+msgstr "\t-A vernichtet alle Anmeldedatenzwischenspeicher in der Sammlung.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:64 -+#, c-format -+msgid "\t-q quiet mode\n" -+msgstr "\t-q stiller Modus\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:65 -+#: ../../src/clients/kswitch/kswitch.c:45 -+#, c-format -+msgid "\t-c specify name of credentials cache\n" -+msgstr "\t-c gibt den Namen des Zwischenspeichers für Anmeldedaten an.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:98 -+#: ../../src/clients/kinit/kinit.c:383 ../../src/clients/ksu/main.c:284 -+#, c-format -+msgid "Only one -c option allowed\n" -+msgstr "Nur eine »-c«-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:105 -+#: ../../src/clients/kinit/kinit.c:412 ../../src/clients/klist/klist.c:182 -+#, c-format -+msgid "Kerberos 4 is no longer supported\n" -+msgstr "Kerberos 4 wird nicht mehr unterstützt.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:126 -+#: ../../src/clients/klist/klist.c:253 ../../src/clients/ksu/main.c:131 -+#: ../../src/clients/ksu/main.c:137 ../../src/clients/kswitch/kswitch.c:97 -+#: ../../src/kadmin/ktutil/ktutil.c:52 ../../src/kdc/main.c:926 -+#: ../../src/slave/kprop.c:102 ../../src/slave/kpropd.c:1052 -+msgid "while initializing krb5" -+msgstr "beim Initialisieren von Krb5" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:133 -+msgid "while listing credential caches" -+msgstr "beim Auflisten der Anmeldedatenzwischenspeicher" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:140 -+msgid "composing ccache name" -+msgstr "Ccache-Name wird zusammengesetzt." -+ -+#: ../../src/clients/kdestroy/kdestroy.c:145 -+#, c-format -+msgid "while destroying cache %s" -+msgstr "beim Zerstören des Zwischenspeichers %s" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:157 -+#: ../../src/clients/kswitch/kswitch.c:104 -+#, c-format -+msgid "while resolving %s" -+msgstr "beim Auflösen von %s" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:163 -+#: ../../src/clients/kinit/kinit.c:501 ../../src/clients/klist/klist.c:460 -+msgid "while getting default ccache" -+msgstr "beim Holen des Standard-Ccaches" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:170 ../../src/clients/ksu/main.c:986 -+msgid "while destroying cache" -+msgstr "beim Zerstören des Zwischenspeichers" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:173 -+#, c-format -+msgid "Ticket cache NOT destroyed!\n" -+msgstr "Ticketzwischenspeicher NICHT vernichtet!\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:175 -+#, c-format -+msgid "Ticket cache %cNOT%c destroyed!\n" -+msgstr "Ticketzwischenspeicher %cNICHT%c vernichtet!\n" -+ -+#: ../../src/clients/kinit/kinit.c:213 -+#, c-format -+msgid "\t-V verbose\n" -+msgstr "\t-V detaillierte Ausgabe\n" -+ -+#: ../../src/clients/kinit/kinit.c:214 -+#, c-format -+msgid "\t-l lifetime\n" -+msgstr "\t-l Lebensdauer\n" -+ -+#: ../../src/clients/kinit/kinit.c:215 -+#, c-format -+msgid "\t-s start time\n" -+msgstr "\t-s Startzeit\n" -+ -+#: ../../src/clients/kinit/kinit.c:216 -+#, c-format -+msgid "\t-r renewable lifetime\n" -+msgstr "\t-r verlängerbare Lebensdauer\n" -+ -+#: ../../src/clients/kinit/kinit.c:217 -+#, c-format -+msgid "\t-f forwardable\n" -+msgstr "\t-f weiterleitbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:218 -+#, c-format -+msgid "\t-F not forwardable\n" -+msgstr "\t-F nicht weiterleitbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:219 -+#, c-format -+msgid "\t-p proxiable\n" -+msgstr "\t-p Proxy nutzbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:220 -+#, c-format -+msgid "\t-P not proxiable\n" -+msgstr "\t-P Proxy nicht nutzbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:221 -+#, c-format -+msgid "\t-n anonymous\n" -+msgstr "\t-n anonym\n" -+ -+#: ../../src/clients/kinit/kinit.c:222 -+#, c-format -+msgid "\t-a include addresses\n" -+msgstr "\t-a bezieht Adressen ein.\n" -+ -+#: ../../src/clients/kinit/kinit.c:223 -+#, c-format -+msgid "\t-A do not include addresses\n" -+msgstr "\t-a bezieht Adressen nicht ein.\n" -+ -+#: ../../src/clients/kinit/kinit.c:224 -+#, c-format -+msgid "\t-v validate\n" -+msgstr "\t-v überprüft\n" -+ -+#: ../../src/clients/kinit/kinit.c:225 -+#, c-format -+msgid "\t-R renew\n" -+msgstr "\t-R erneuert\n" -+ -+#: ../../src/clients/kinit/kinit.c:226 -+#, c-format -+msgid "\t-C canonicalize\n" -+msgstr "\t-C bringt in Normalform\n" -+ -+#: ../../src/clients/kinit/kinit.c:227 -+#, c-format -+msgid "\t-E client is enterprise principal name\n" -+msgstr "\t-E Client ist der Principal-Name des Unternehmens\n" -+ -+#: ../../src/clients/kinit/kinit.c:228 -+#, c-format -+msgid "\t-k use keytab\n" -+msgstr "\t-k verwendet Schlüsseltabelle\n" -+ -+#: ../../src/clients/kinit/kinit.c:229 -+#, c-format -+msgid "\t-i use default client keytab (with -k)\n" -+msgstr "\t-i verwendet die Standardschlüsseltabelle des Clients (mit -k).\n" -+ -+#: ../../src/clients/kinit/kinit.c:230 -+#, c-format -+msgid "\t-t filename of keytab to use\n" -+msgstr "\t-t Dateiname der zu verwendenden Schlüsseltabelle\n" -+ -+#: ../../src/clients/kinit/kinit.c:231 -+#, c-format -+msgid "\t-c Kerberos 5 cache name\n" -+msgstr "\t-c Kerberos-5-Zwischenspeichername\n" -+ -+#: ../../src/clients/kinit/kinit.c:232 -+#, c-format -+msgid "\t-S service\n" -+msgstr "\t-S Dienst\n" -+ -+#: ../../src/clients/kinit/kinit.c:233 -+#, c-format -+msgid "\t-T armor credential cache\n" -+msgstr "\t-T gehärteter Anmeldedatenzwischenspeicher\n" -+ -+#: ../../src/clients/kinit/kinit.c:234 -+#, c-format -+msgid "\t-X [=]\n" -+msgstr "\t-X [=]\n" -+ -+#: ../../src/clients/kinit/kinit.c:301 ../../src/clients/kinit/kinit.c:309 -+#, c-format -+msgid "Bad lifetime value %s\n" -+msgstr "falscher Wert für die Lebensdauer %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:343 -+#, c-format -+msgid "Bad start time value %s\n" -+msgstr "falscher Wert für die Startzeit %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:362 -+#, c-format -+msgid "Only one -t option allowed.\n" -+msgstr "Nur eine -t-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:370 -+#, c-format -+msgid "Only one armor_ccache\n" -+msgstr "nur ein gehärteter Ccache\n" -+ -+#: ../../src/clients/kinit/kinit.c:391 -+#, c-format -+msgid "Only one -I option allowed\n" -+msgstr "Nur eine -I-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:401 -+msgid "while adding preauth option" -+msgstr "beim Hinzufügen der Option »preauth«" -+ -+#: ../../src/clients/kinit/kinit.c:425 -+#, c-format -+msgid "Only one of -f and -F allowed\n" -+msgstr "Nur eine der Optionen -f und -F ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:430 -+#, c-format -+msgid "Only one of -p and -P allowed\n" -+msgstr "Nur eine der Optionen -p und -P ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:435 -+#, c-format -+msgid "Only one of -a and -A allowed\n" -+msgstr "Nur eine der Optionen -a und -A ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:440 -+#, c-format -+msgid "Only one of -t and -i allowed\n" -+msgstr "Nur eine der Optionen -t und-i ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:447 -+#, c-format -+msgid "keytab specified, forcing -k\n" -+msgstr "Schlüsseltabelle angegeben, -k wird erzwungen\n" -+ -+#: ../../src/clients/kinit/kinit.c:451 ../../src/clients/klist/klist.c:221 -+#, c-format -+msgid "Extra arguments (starting with \"%s\").\n" -+msgstr "zusätzliche Argumente (beginnend mit »%s«)\n" -+ -+#: ../../src/clients/kinit/kinit.c:480 -+msgid "while initializing Kerberos 5 library" -+msgstr "beim Initialisieren der Kerberos-5-Bibliothek" -+ -+#: ../../src/clients/kinit/kinit.c:488 ../../src/clients/kinit/kinit.c:644 -+#, c-format -+msgid "resolving ccache %s" -+msgstr "Ccache %s wird ermittelt" -+ -+#: ../../src/clients/kinit/kinit.c:493 -+#, c-format -+msgid "Using specified cache: %s\n" -+msgstr "Angegebener Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:515 ../../src/clients/kinit/kinit.c:595 -+#: ../../src/clients/kpasswd/kpasswd.c:28 ../../src/clients/ksu/main.c:238 -+#, c-format -+msgid "when parsing name %s" -+msgstr "wenn der Name %s ausgewertet wird" -+ -+#: ../../src/clients/kinit/kinit.c:523 ../../src/kadmin/dbutil/kdb5_util.c:307 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:391 -+#: ../../src/slave/kprop.c:203 -+msgid "while getting default realm" -+msgstr "beim Holen des Standard-Realms" -+ -+#: ../../src/clients/kinit/kinit.c:535 -+msgid "while building principal" -+msgstr "beim Erstellen des Principals" -+ -+#: ../../src/clients/kinit/kinit.c:543 -+msgid "When resolving the default client keytab" -+msgstr "beim Auflösen der Standardschlüsseltabelle des Clients" -+ -+#: ../../src/clients/kinit/kinit.c:550 -+msgid "When determining client principal name from keytab" -+msgstr "beim Bestimmen des Dienst-Principal-Namens anhand der Schlüsseltabelle" -+ -+#: ../../src/clients/kinit/kinit.c:559 -+msgid "when creating default server principal name" -+msgstr "wenn der Standard-Principal-Name des Servers erstellt wird" -+ -+#: ../../src/clients/kinit/kinit.c:566 -+#, c-format -+msgid "(principal %s)" -+msgstr "(Principal %s)" -+ -+#: ../../src/clients/kinit/kinit.c:569 -+msgid "for local services" -+msgstr "für lokale Dienste" -+ -+#: ../../src/clients/kinit/kinit.c:590 ../../src/clients/kpasswd/kpasswd.c:42 -+#, c-format -+msgid "Unable to identify user\n" -+msgstr "Benutzer kann nicht identifiziert werden\n" -+ -+#: ../../src/clients/kinit/kinit.c:605 ../../src/clients/kswitch/kswitch.c:116 -+#, c-format -+msgid "while searching for ccache for %s" -+msgstr "beim Suchen nach Ccache für %s" -+ -+#: ../../src/clients/kinit/kinit.c:611 -+#, c-format -+msgid "Using existing cache: %s\n" -+msgstr "Existierender Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:620 -+msgid "while generating new ccache" -+msgstr "beim Erstellen von neuem Ccache" -+ -+#: ../../src/clients/kinit/kinit.c:624 -+#, c-format -+msgid "Using new cache: %s\n" -+msgstr "Neuer Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:636 -+#, c-format -+msgid "Using default cache: %s\n" -+msgstr "Standardzwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:649 -+#, c-format -+msgid "Using specified input cache: %s\n" -+msgstr "Angegebener Eingabezwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:657 ../../src/clients/ksu/krb_auth_su.c:160 -+msgid "when unparsing name" -+msgstr "beim Rückgängigmachen der Auswertung des Namens" -+ -+#: ../../src/clients/kinit/kinit.c:661 -+#, c-format -+msgid "Using principal: %s\n" -+msgstr "verwendeter Principal: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:752 -+msgid "getting local addresses" -+msgstr "Lokale Adressen werden geholt." -+ -+#: ../../src/clients/kinit/kinit.c:771 -+#, c-format -+msgid "while setting up KDB keytab for realm %s" -+msgstr "beim Einrichten der KDB-Schlüsseltabelle für Realm %s" -+ -+#: ../../src/clients/kinit/kinit.c:780 ../../src/clients/kvno/kvno.c:201 -+#, c-format -+msgid "resolving keytab %s" -+msgstr "Schlüsseltabelle wird ermittelt: %s" -+ -+#: ../../src/clients/kinit/kinit.c:785 -+#, c-format -+msgid "Using keytab: %s\n" -+msgstr "Schlüsseltabelle wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:789 -+msgid "resolving default client keytab" -+msgstr "Standardschlüsseltabelle des Clients wird ermittelt." -+ -+#: ../../src/clients/kinit/kinit.c:799 -+#, c-format -+msgid "while setting '%s'='%s'" -+msgstr "beim Setzen von »%s«=»%s«" -+ -+#: ../../src/clients/kinit/kinit.c:804 -+#, c-format -+msgid "PA Option %s = %s\n" -+msgstr "PA-Option %s = %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:849 -+msgid "getting initial credentials" -+msgstr "Anfängliche Anmeldedaten werden geholt." -+ -+#: ../../src/clients/kinit/kinit.c:852 -+msgid "validating credentials" -+msgstr "Anmeldedaten werden geprüft." -+ -+#: ../../src/clients/kinit/kinit.c:855 -+msgid "renewing credentials" -+msgstr "Anmeldedaten werden erneuert." -+ -+#: ../../src/clients/kinit/kinit.c:860 -+#, c-format -+msgid "%s: Password incorrect while %s\n" -+msgstr "%s: Passwort bei %s falsch\n" -+ -+#: ../../src/clients/kinit/kinit.c:863 -+#, c-format -+msgid "while %s" -+msgstr "bei %s" -+ -+#: ../../src/clients/kinit/kinit.c:871 ../../src/slave/kprop.c:224 -+#, c-format -+msgid "when initializing cache %s" -+msgstr "beim Initialisieren des Zwischenspeichers %s" -+ -+#: ../../src/clients/kinit/kinit.c:876 -+#, c-format -+msgid "Initialized cache\n" -+msgstr "initialisierter Zwischenspeicher\n" -+ -+#: ../../src/clients/kinit/kinit.c:880 -+msgid "while storing credentials" -+msgstr "beim Speichern der Anmeldedaten" -+ -+#: ../../src/clients/kinit/kinit.c:884 -+#, c-format -+msgid "Stored credentials\n" -+msgstr "gespeicherte Anmeldedaten\n" -+ -+#: ../../src/clients/kinit/kinit.c:891 -+msgid "while switching to new ccache" -+msgstr "beim Wechsel zum neuen Ccache" -+ -+#: ../../src/clients/kinit/kinit.c:946 -+#, c-format -+msgid "Authenticated to Kerberos v5\n" -+msgstr "Authentifiziert für Kerberos v5\n" -+ -+#: ../../src/clients/klist/klist.c:91 -+#, c-format -+msgid "" -+"Usage: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] [-a [-n]]] [-k [-t] [-K]] " -+"[name]\n" -+msgstr "" -+"Aufruf: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] [-a [-n]]] [-k [-t] [-" -+"K]] [Name]\n" -+ -+#: ../../src/clients/klist/klist.c:93 -+#, c-format -+msgid "\t-c specifies credentials cache\n" -+msgstr "\t-c gibt den Anmeldedatenzwischenspeicher an\n" -+ -+#: ../../src/clients/klist/klist.c:94 -+#, c-format -+msgid "\t-k specifies keytab\n" -+msgstr "\t-k gibt die Schlüsseltabelle an.\n" -+ -+#: ../../src/clients/klist/klist.c:95 -+#, c-format -+msgid "\t (Default is credentials cache)\n" -+msgstr "\t (Voreinstellung ist Anmeldedatenzwischenspeicher)\n" -+ -+#: ../../src/clients/klist/klist.c:96 -+#, c-format -+msgid "\t-i uses default client keytab if no name given\n" -+msgstr "" -+"\t-i verwendet die Standardschlüsseltabelle des Clients, falls kein Name " -+"angegeben wurde.\n" -+ -+#: ../../src/clients/klist/klist.c:97 -+#, c-format -+msgid "\t-l lists credential caches in collection\n" -+msgstr "\t-l listet gesammelte Anmeldedatenzwischenspeicher auf.\n" -+ -+#: ../../src/clients/klist/klist.c:98 -+#, c-format -+msgid "\t-A shows content of all credential caches\n" -+msgstr "\t-A zeigt den Inhalt aller Anmeldedatenzwischenspeicher an.\n" -+ -+#: ../../src/clients/klist/klist.c:99 -+#, c-format -+msgid "\t-e shows the encryption type\n" -+msgstr "\t-e zeigt den Verschlüsselungstyp.\n" -+ -+#: ../../src/clients/klist/klist.c:100 -+#, c-format -+msgid "\t-V shows the Kerberos version and exits\n" -+msgstr "\t-V zeigt die Kerberos-Version und wird beendet.\n" -+ -+#: ../../src/clients/klist/klist.c:101 -+#, c-format -+msgid "\toptions for credential caches:\n" -+msgstr "\tOptionen für Anmeldedatenzwischenspeicher:\n" -+ -+#: ../../src/clients/klist/klist.c:102 -+#, c-format -+msgid "\t\t-d shows the submitted authorization data types\n" -+msgstr "\t\t-d zeigt die übertragenen Autorisierungsdatentypen.\n" -+ -+#: ../../src/clients/klist/klist.c:104 -+#, c-format -+msgid "\t\t-f shows credentials flags\n" -+msgstr "t\t-f zeigt die Anmeldedatenschalter.\n" -+ -+#: ../../src/clients/klist/klist.c:105 -+#, c-format -+msgid "\t\t-s sets exit status based on valid tgt existence\n" -+msgstr "" -+"\t\t-s setzt den Exit-Status auf Basis der Existenz eines gültigen TGTs.\n" -+ -+#: ../../src/clients/klist/klist.c:107 -+#, c-format -+msgid "\t\t-a displays the address list\n" -+msgstr "\t\t-a zeigt die Adressliste.\n" -+ -+#: ../../src/clients/klist/klist.c:108 -+#, c-format -+msgid "\t\t\t-n do not reverse-resolve\n" -+msgstr "\t\t\t-n löst nicht rückwärts auf.\n" -+ -+#: ../../src/clients/klist/klist.c:109 -+#, c-format -+msgid "\toptions for keytabs:\n" -+msgstr "\tOptionen für Schlüsseltabellen:\n" -+ -+#: ../../src/clients/klist/klist.c:110 -+#, c-format -+msgid "\t\t-t shows keytab entry timestamps\n" -+msgstr "\t\t-t zeigt die Zeitstempel der Schlüsseltabelleneinträge.\n" -+ -+#: ../../src/clients/klist/klist.c:111 -+#, c-format -+msgid "\t\t-K shows keytab entry keys\n" -+msgstr "\t\t-K zeigt die Schlüssel der Schlüsseltabelleneinträge.\n" -+ -+#: ../../src/clients/klist/klist.c:230 -+#, c-format -+msgid "%s version %s\n" -+msgstr "%s Version %s\n" -+ -+#: ../../src/clients/klist/klist.c:282 -+msgid "while getting default client keytab" -+msgstr "beim Holen der Standardschlüsseltabelle des Clients" -+ -+#: ../../src/clients/klist/klist.c:287 -+msgid "while getting default keytab" -+msgstr "beim Holen der Standardschlüsseltabelle" -+ -+#: ../../src/clients/klist/klist.c:292 ../../src/kadmin/cli/keytab.c:108 -+#, c-format -+msgid "while resolving keytab %s" -+msgstr "beim Ermitteln der Schlüsseltabelle %s" -+ -+#: ../../src/clients/klist/klist.c:298 ../../src/kadmin/cli/keytab.c:92 -+msgid "while getting keytab name" -+msgstr "beim Holen des Schlüsseltabellennamens" -+ -+#: ../../src/clients/klist/klist.c:305 ../../src/kadmin/cli/keytab.c:399 -+msgid "while starting keytab scan" -+msgstr "beim Start des Schlüsseltabellen-Scans" -+ -+#: ../../src/clients/klist/klist.c:326 ../../src/clients/klist/klist.c:500 -+#: ../../src/clients/ksu/ccache.c:465 ../../src/kadmin/dbutil/dump.c:550 -+msgid "while unparsing principal name" -+msgstr "beim Rückgängigmachen des Auswertens des Principal-Namens" -+ -+#: ../../src/clients/klist/klist.c:350 ../../src/kadmin/cli/keytab.c:443 -+msgid "while scanning keytab" -+msgstr "beim Scannen der Schlüsseltabelle" -+ -+#: ../../src/clients/klist/klist.c:354 ../../src/kadmin/cli/keytab.c:448 -+msgid "while ending keytab scan" -+msgstr "beim Beenden des Schlüsseltabellen-Scans" -+ -+#: ../../src/clients/klist/klist.c:371 ../../src/clients/klist/klist.c:434 -+msgid "while listing ccache collection" -+msgstr "beim Aufführen der Ccache-Sammlung" -+ -+#: ../../src/clients/klist/klist.c:411 -+msgid "(Expired)" -+msgstr "(abgelaufen)" -+ -+#: ../../src/clients/klist/klist.c:466 -+#, c-format -+msgid "while resolving ccache %s" -+msgstr "beim Ermitteln des Ccaches %s" -+ -+#: ../../src/clients/klist/klist.c:504 -+#, c-format -+msgid "" -+"Ticket cache: %s:%s\n" -+"Default principal: %s\n" -+"\n" -+msgstr "" -+"Ticketzwischenspeicher: %s:%s\n" -+"Standard-Principal: %s\n" -+"\n" -+ -+#: ../../src/clients/klist/klist.c:518 -+msgid "while starting to retrieve tickets" -+msgstr "während das Abfragen der Tickets beginnt" -+ -+#: ../../src/clients/klist/klist.c:539 -+msgid "while finishing ticket retrieval" -+msgstr "während das Abfragem der Tickets endet" -+ -+#: ../../src/clients/klist/klist.c:545 -+msgid "while closing ccache" -+msgstr "beim Schließen des Ccaches" -+ -+#: ../../src/clients/klist/klist.c:555 -+msgid "while retrieving a ticket" -+msgstr "beim Abfragen eines Tickets" -+ -+#: ../../src/clients/klist/klist.c:667 ../../src/clients/ksu/ccache.c:450 -+#: ../../src/slave/kpropd.c:1225 ../../src/slave/kpropd.c:1285 -+msgid "while unparsing client name" -+msgstr "beim Rückgängigmachen des Auswertens des Client-Namens" -+ -+#: ../../src/clients/klist/klist.c:672 ../../src/clients/ksu/ccache.c:455 -+#: ../../src/slave/kprop.c:240 -+msgid "while unparsing server name" -+msgstr "beim Rückgängigmachen des Auswertens des Server-Namens" -+ -+#: ../../src/clients/klist/klist.c:701 ../../src/clients/ksu/ccache.c:480 -+#, c-format -+msgid "\tfor client %s" -+msgstr "\tfür Client %s" -+ -+#: ../../src/clients/klist/klist.c:713 ../../src/clients/ksu/ccache.c:489 -+msgid "renew until " -+msgstr "erneuern bis " -+ -+#: ../../src/clients/klist/klist.c:730 ../../src/clients/ksu/ccache.c:499 -+#, c-format -+msgid "Flags: %s" -+msgstr "Schalter: %s" -+ -+#: ../../src/clients/klist/klist.c:749 -+#, c-format -+msgid "Etype (skey, tkt): %s, " -+msgstr "Etype (Skey, TKT): %s, " -+ -+#: ../../src/clients/klist/klist.c:766 -+#, c-format -+msgid "AD types: " -+msgstr "AD-Typen" -+ -+#: ../../src/clients/klist/klist.c:783 -+#, c-format -+msgid "\tAddresses: (none)\n" -+msgstr "\tAdressen: (keine)\n" -+ -+#: ../../src/clients/klist/klist.c:785 -+#, c-format -+msgid "\tAddresses: " -+msgstr "\tAdressen: " -+ -+#: ../../src/clients/klist/klist.c:818 -+#, c-format -+msgid "broken address (type %d length %d)" -+msgstr "kaputte Adresse (Typ %d Länge %d)" -+ -+#: ../../src/clients/klist/klist.c:838 -+#, c-format -+msgid "unknown addrtype %d" -+msgstr "unbekannter »addrtype« %d" -+ -+#: ../../src/clients/klist/klist.c:847 -+#, c-format -+msgid "unprintable address (type %d, error %d %s)" -+msgstr "nicht druckbare Adresse (Typ %d Fehler %d %s)" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:12 ../../src/lib/krb5/krb/gic_pwd.c:396 -+msgid "Enter new password" -+msgstr "Geben Sie ein neues Passwort ein." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:13 ../../src/lib/krb5/krb/gic_pwd.c:404 -+msgid "Enter it again" -+msgstr "Geben Sie es erneut ein." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:33 -+#, c-format -+msgid "Unable to identify user from password file\n" -+msgstr "" -+"Der Benutzer kann nicht anhand der Passwortdatei identifiziert werden.\n" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:65 -+#, c-format -+msgid "usage: %s [principal]\n" -+msgstr "Aufruf: %s [Principal]\n" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:73 -+msgid "initializing kerberos library" -+msgstr "Kerberos-Bibliothek wird initialisiert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:77 -+msgid "allocating krb5_get_init_creds_opt" -+msgstr "krb5_get_init_creds_opt wird reserviert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:92 -+msgid "opening default ccache" -+msgstr "Standard-Ccache wird geöffnet." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:97 -+msgid "getting principal from ccache" -+msgstr "Principal wird vom Ccache geholt." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:104 -+msgid "while setting FAST ccache" -+msgstr "beim Setzen des FAST-Ccaches" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:111 -+msgid "closing ccache" -+msgstr "Ccache wird geschlossen." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:118 -+msgid "parsing client name" -+msgstr "Client-Name wird ausgewertet." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:135 -+msgid "Password incorrect while getting initial ticket" -+msgstr "Passwort beim Holen des anfänglichen Tickets falsch" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:137 -+msgid "getting initial ticket" -+msgstr "Anfängliches Ticket wird geholt." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:144 -+msgid "while reading password" -+msgstr "beim Lesen des Passworts" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:152 -+msgid "changing password" -+msgstr "Passwort wird geändert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:174 -+#: ../lib/kadm5/chpass_util_strings.c:30 -+#, c-format -+msgid "Password changed.\n" -+msgstr "Passwort geändert\n" -+ -+#: ../../src/clients/ksu/authorization.c:369 -+#, c-format -+msgid "" -+"Error: bad entry - %s in %s file, must be either full path or just the cmd " -+"name\n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s muss entweder ein vollständiger " -+"Pfad oder nur ein Befehlsname sein.\n" -+ -+#: ../../src/clients/ksu/authorization.c:377 -+#, c-format -+msgid "" -+"Error: bad entry - %s in %s file, since %s is just the cmd name, CMD_PATH " -+"must be defined \n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s. Da %s nur ein Befehlsname ist, " -+"muss CMD_PATH definiert sein.\n" -+ -+#: ../../src/clients/ksu/authorization.c:392 -+#, c-format -+msgid "Error: bad entry - %s in %s file, CMD_PATH contains no paths \n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s. CMD_PATH enthält keine Pfade.\n" -+ -+#: ../../src/clients/ksu/authorization.c:401 -+#, c-format -+msgid "Error: bad path %s in CMD_PATH for %s must start with '/' \n" -+msgstr "Fehler: falscher Pfad %s in CMD_PATH für %s muss mit »/« beginnen\n" -+ -+#: ../../src/clients/ksu/authorization.c:517 -+msgid "Error: not found -> " -+msgstr "Fehler: nicht gefunden -> " -+ -+#: ../../src/clients/ksu/authorization.c:723 -+#, c-format -+msgid "home directory name `%s' too long, can't search for .k5login\n" -+msgstr "" -+"Name des Home-Verzeichnisses »%s« ist zu lang, Suche nach .k5login nicht " -+"möglich\n" -+ -+#: ../../src/clients/ksu/ccache.c:368 -+#, c-format -+msgid "home directory path for %s too long\n" -+msgstr "Home-Verzeichnispfad für %s zu lang\n" -+ -+#: ../../src/clients/ksu/ccache.c:461 -+msgid "while retrieving principal name" -+msgstr "beim Abfragen des Principal-Namens" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:57 -+#: ../../src/clients/ksu/krb_auth_su.c:62 ../../src/slave/kprop.c:247 -+msgid "while copying client principal" -+msgstr "beim Kopieren des Client-Principals" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:69 -+msgid "while creating tgt for local realm" -+msgstr "beim Erstellen des TGTs für lokalen Realm" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:84 -+msgid "while retrieving creds from cache" -+msgstr "beim Abfragen der Anmeldedaten aus dem Zwischenspeicher" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:95 -+msgid "while switching to target uid" -+msgstr "beim Umschalten auf die Ziel-UID" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:100 -+#, c-format -+msgid "" -+"WARNING: Your password may be exposed if you enter it here and are logged \n" -+msgstr "" -+"WARNUNG: Ihr Passwort könnte offengelegt werden, falls Sie es hier eingeben " -+"und\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:102 -+#, c-format -+msgid " in remotely using an unsecure (non-encrypted) channel. \n" -+msgstr "" -+" in der Ferne mittels eines unsicheren (unverschlüsselten) Kanals\n" -+" angemeldet sind.\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:114 ../../src/clients/ksu/main.c:464 -+msgid "while reclaiming root uid" -+msgstr "beim erneuten Beanspruchen der Root-UID" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:121 -+#, c-format -+msgid "does not have any appropriate tickets in the cache.\n" -+msgstr "hat keine geeigneten Tickets im Zwischenspeicher.\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:133 -+msgid "while verifying ticket for server" -+msgstr "beim Prüfen des Tickets für Server" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:167 -+msgid "while getting time of day" -+msgstr "beim Holen der Tageszeit" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:171 -+#, c-format -+msgid "Kerberos password for %s: " -+msgstr "Kerberos-Passwort für %s: " -+ -+#: ../../src/clients/ksu/krb_auth_su.c:175 -+#, c-format -+msgid "principal name %s too long for internal buffer space\n" -+msgstr "Principal-Name %s für den internen Pufferbereich zu groß\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:184 -+#, c-format -+msgid "while reading password for '%s'\n" -+msgstr "beim Lesen des Passworts für »%s«\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:191 -+#, c-format -+msgid "No password given\n" -+msgstr "kein Passwort angegeben\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:204 -+#, c-format -+msgid "%s: Password incorrect\n" -+msgstr "%s: Passwort falsch\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:206 -+msgid "while getting initial credentials" -+msgstr "beim Holen der Anfangsanmeldedaten" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:226 -+#: ../../src/clients/ksu/krb_auth_su.c:240 -+#, c-format -+msgid " %s while unparsing name\n" -+msgstr "%s beim Rückgängigmachen der Namensauswertung\n" -+ -+#: ../../src/clients/ksu/main.c:68 -+#, c-format -+msgid "" -+"Usage: %s [target user] [-n principal] [-c source cachename] [-k] [-D] [-r " -+"time] [-pf] [-l lifetime] [-zZ] [-q] [-e command [args... ] ] [-a " -+"[args... ] ]\n" -+msgstr "" -+"Aufruf: %s [Zielbenutzer] [-n Principal] [-c Quellenzwischenspeichername] [-" -+"k] [-D] [-r Zeit] [-pf] [-l Lebensdauer] [-zZ] [-q] [-e Befehl [Argumente " -+"…] ] [-a [Argumente …] ]\n" -+ -+#: ../../src/clients/ksu/main.c:147 -+msgid "" -+"program name too long - quitting to avoid triggering system logging bugs" -+msgstr "" -+"Programmname zu lang – wird beendet, um das Auslösen von " -+"Systemprotokollierungsfehlern zu vermeiden" -+ -+#: ../../src/clients/ksu/main.c:173 -+msgid "while allocating memory" -+msgstr "bei Reservieren von Speicher" -+ -+#: ../../src/clients/ksu/main.c:186 -+msgid "while setting euid to source user" -+msgstr "beim Setzen der EUID auf dem Quellbenutzer" -+ -+#: ../../src/clients/ksu/main.c:196 ../../src/clients/ksu/main.c:231 -+#, c-format -+msgid "Bad lifetime value (%s hours?)\n" -+msgstr "falscher Wert für Lebensdauer (%s Stunden?)\n" -+ -+#: ../../src/clients/ksu/main.c:208 ../../src/clients/ksu/main.c:292 -+msgid "when gathering parameters" -+msgstr "beim Zusammenstellen der Parameter" -+ -+#: ../../src/clients/ksu/main.c:251 -+#, c-format -+msgid "-z option is mutually exclusive with -Z.\n" -+msgstr "Die Optionen -z und -Z schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/ksu/main.c:259 -+#, c-format -+msgid "-Z option is mutually exclusive with -z.\n" -+msgstr "Die Optionen -Z und -z schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/ksu/main.c:272 -+#, c-format -+msgid "while looking for credentials cache %s" -+msgstr "beim Suchen nach dem Anmeldedatenzwischenspeicher %s" -+ -+#: ../../src/clients/ksu/main.c:278 -+#, c-format -+msgid "malformed credential cache name %s\n" -+msgstr "falsch gebildeter Anmeldedatenzwischenspeichername %s\n" -+ -+# ksu ist eine Kerberos-Variante von su -+#: ../../src/clients/ksu/main.c:336 -+#, c-format -+msgid "ksu: who are you?\n" -+msgstr "ksu: Wer sind Sie?\n" -+ -+#: ../../src/clients/ksu/main.c:340 -+#, c-format -+msgid "Your uid doesn't match your passwd entry?!\n" -+msgstr "Ihre UID passt nicht zu Ihrem Passworteintrag.\n" -+ -+#: ../../src/clients/ksu/main.c:355 -+#, c-format -+msgid "ksu: unknown login %s\n" -+msgstr "ksu: unbekannter Anmeldename %s\n" -+ -+#: ../../src/clients/ksu/main.c:375 -+msgid "while getting source cache" -+msgstr "beim Holen des Quellenzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:381 ../../src/clients/kvno/kvno.c:194 -+msgid "while opening ccache" -+msgstr "beim Öffnen des Ccaches" -+ -+#: ../../src/clients/ksu/main.c:389 -+msgid "while selecting the best principal" -+msgstr "beim Auswählen des besten Principals" -+ -+#: ../../src/clients/ksu/main.c:397 -+msgid "while returning to source uid after finding best principal" -+msgstr "" -+"bei der Rückkehr zur Quell-UID, nachdem der beste Principal gefunden wurde" -+ -+#: ../../src/clients/ksu/main.c:417 -+#, c-format -+msgid "account %s: authorization failed\n" -+msgstr "Konto %s: Autorisierung fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:442 -+msgid "while parsing temporary name" -+msgstr "beim Auswertens des temporären Namens" -+ -+#: ../../src/clients/ksu/main.c:447 -+msgid "while creating temporary cache" -+msgstr "bei Erstellen des temporären Zwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:453 ../../src/clients/ksu/main.c:693 -+#, c-format -+msgid "while copying cache %s to %s" -+msgstr "beim Kopieren des Zwischenspeichers %s nach %s" -+ -+#: ../../src/clients/ksu/main.c:471 -+#, c-format -+msgid "" -+"WARNING: Your password may be exposed if you enter it here and are logged\n" -+msgstr "" -+"WARNUNG: Ihr Passwort könnte offengelegt werden, falls Sie es hier eingeben " -+"und\n" -+ -+#: ../../src/clients/ksu/main.c:473 -+#, c-format -+msgid " in remotely using an unsecure (non-encrypted) channel.\n" -+msgstr "" -+" in der Ferne über einen unsicheren (unverschlüsselten) Kanal " -+"angemeldet\n" -+"sind.\n" -+ -+#: ../../src/clients/ksu/main.c:479 -+#, c-format -+msgid "Goodbye\n" -+msgstr "Auf Wiedersehen\n" -+ -+#: ../../src/clients/ksu/main.c:483 -+#, c-format -+msgid "Could not get a tgt for " -+msgstr "Es konnte kein TGT geholt werden für " -+ -+#: ../../src/clients/ksu/main.c:505 -+#, c-format -+msgid "Authentication failed.\n" -+msgstr "Authentifizierung fehlgeschlagen.\n" -+ -+#: ../../src/clients/ksu/main.c:513 -+msgid "When unparsing name" -+msgstr "beim Rückgängigmachen der Namensauswertung" -+ -+#: ../../src/clients/ksu/main.c:517 -+#, c-format -+msgid "Authenticated %s\n" -+msgstr "Authentifiziert %s\n" -+ -+#: ../../src/clients/ksu/main.c:524 -+msgid "while switching to target for authorization check" -+msgstr "beim Wechsel des Ziels der Autorisierungsprüfung" -+ -+#: ../../src/clients/ksu/main.c:531 -+msgid "while checking authorization" -+msgstr "beim Prüfen der Autorisierung" -+ -+#: ../../src/clients/ksu/main.c:537 -+msgid "while switching back from target after authorization check" -+msgstr "beim Zurückwechsel vom Ziel nach der Autorisierungsprüfung" -+ -+#: ../../src/clients/ksu/main.c:544 -+#, c-format -+msgid "Account %s: authorization for %s for execution of\n" -+msgstr "Konto %s: Autorisierung für %s zum Ausführen von\n" -+ -+#: ../../src/clients/ksu/main.c:546 -+#, c-format -+msgid " %s successful\n" -+msgstr " %s erfolgreich\n" -+ -+#: ../../src/clients/ksu/main.c:552 -+#, c-format -+msgid "Account %s: authorization for %s successful\n" -+msgstr "Konto %s: Autorisierung für %s erfolgreich\n" -+ -+#: ../../src/clients/ksu/main.c:564 -+#, c-format -+msgid "Account %s: authorization for %s for execution of %s failed\n" -+msgstr "Konto %s: Autorisierung für %s zum Ausführen von %s fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:572 -+#, c-format -+msgid "Account %s: authorization of %s failed\n" -+msgstr "Konto %s: Autorisierung von %s fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:587 -+msgid "while calling cc_filter" -+msgstr "beim Aufruf von »cc_filter«" -+ -+#: ../../src/clients/ksu/main.c:595 -+msgid "while erasing target cache" -+msgstr "bei Löschen des Zielzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:615 -+#, c-format -+msgid "ksu: permission denied (shell).\n" -+msgstr "ksu: Zugriff verweigert (Shell)\n" -+ -+#: ../../src/clients/ksu/main.c:624 -+#, c-format -+msgid "ksu: couldn't set environment variable USER\n" -+msgstr "ksu: Umgebungsvariable USER kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:630 -+#, c-format -+msgid "ksu: couldn't set environment variable HOME\n" -+msgstr "ksu: Umgebungsvariable HOME kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:635 -+#, c-format -+msgid "ksu: couldn't set environment variable SHELL\n" -+msgstr "ksu: Umgebungsvariable SHELL kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:646 -+#, c-format -+msgid "ksu: initgroups failed.\n" -+msgstr "ksu: »initgroups« fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:651 -+#, c-format -+msgid "Leaving uid as %s (%ld)\n" -+msgstr "UID bleibt %s (%ld)\n" -+ -+#: ../../src/clients/ksu/main.c:654 -+#, c-format -+msgid "Changing uid to %s (%ld)\n" -+msgstr "UID wird zu %s (%ld) geändert\n" -+ -+#: ../../src/clients/ksu/main.c:680 -+msgid "while getting name of target ccache" -+msgstr "beim Holen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:700 -+#, c-format -+msgid "%s does not have correct permissions for %s, %s aborted" -+msgstr "%s hat nicht die korrekten Rechte für %s, %s wird abgebrochen." -+ -+#: ../../src/clients/ksu/main.c:721 -+#, c-format -+msgid "Internal error: command %s did not get resolved\n" -+msgstr "Interner Fehler: Befehl %s wurde nicht aufgelöst\n" -+ -+#: ../../src/clients/ksu/main.c:738 ../../src/clients/ksu/main.c:774 -+#, c-format -+msgid "while trying to execv %s" -+msgstr "beim Versuch von »execv %s«" -+ -+#: ../../src/clients/ksu/main.c:764 -+msgid "while calling waitpid" -+msgstr "beim Aufruf von »waitpid«" -+ -+#: ../../src/clients/ksu/main.c:769 -+msgid "while trying to fork." -+msgstr "beim Versuch zu verzweigen." -+ -+#: ../../src/clients/ksu/main.c:791 -+msgid "while reading cache name from ccache" -+msgstr "beim Lesen des Zwischenspeichernamens aus dem Ccache" -+ -+#: ../../src/clients/ksu/main.c:797 -+#, c-format -+msgid "ksu: couldn't set environment variable %s\n" -+msgstr "ksu: Umgebungsvariable %s kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:820 -+#, c-format -+msgid "while clearing the value of %s" -+msgstr "beim Leeren des Werts von %s" -+ -+#: ../../src/clients/ksu/main.c:828 -+msgid "while resetting target ccache name" -+msgstr "beim Zurücksetzen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:842 -+msgid "while determining target ccache name" -+msgstr "beim Bestimmen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:881 -+msgid "while generating part of the target ccache name" -+msgstr "beim Erzeugen eines Teils des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:887 -+msgid "while allocating memory for the target ccache name" -+msgstr "beim Reservieren von Speicher für den Ziel-Ccache-Namen" -+ -+#: ../../src/clients/ksu/main.c:906 -+msgid "while creating new target ccache" -+msgstr "bei Erstellen von neuem Ziel-Ccache" -+ -+#: ../../src/clients/ksu/main.c:912 -+msgid "while initializing target cache" -+msgstr "beim Initialisieren des Zielzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:952 -+#, c-format -+msgid "terminal name %s too long\n" -+msgstr "Terminal-Name %s ist zu lang.\n" -+ -+#: ../../src/clients/ksu/main.c:980 -+msgid "while changing to target uid for destroying ccache" -+msgstr "beim Ändern der Ziel-UID für das Zerstören von Ccache" -+ -+#: ../../src/clients/kswitch/kswitch.c:44 -+#, c-format -+msgid "Usage: %s {-c cache_name | -p principal}\n" -+msgstr "Aufruf: %s {-c Zwischenspeichername | -p Principal}\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:46 -+#, c-format -+msgid "\t-p specify name of principal\n" -+msgstr "\t-p gibt den Namen des Principals an.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:69 -+#, c-format -+msgid "Only one -c or -p option allowed\n" -+msgstr "Nur eine der Optionen -c oder -p ist erlaubt.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:88 -+#, c-format -+msgid "One of -c or -p must be specified\n" -+msgstr "Entweder -c oder -p muss angegeben werden.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:110 ../../src/clients/kvno/kvno.c:211 -+#: ../../src/clients/kvno/kvno.c:245 ../../src/kadmin/cli/keytab.c:350 -+#: ../../src/kadmin/dbutil/kdb5_util.c:576 -+#, c-format -+msgid "while parsing principal name %s" -+msgstr "beim Auswerten des Principal-Namens %s" -+ -+#: ../../src/clients/kswitch/kswitch.c:124 -+msgid "while switching to credential cache" -+msgstr "beim Wechsel auf den Anmeldedatenzwischenspeicher" -+ -+#: ../../src/clients/kvno/kvno.c:46 -+#, c-format -+msgid "usage: %s [-C] [-u] [-c ccache] [-e etype]\n" -+msgstr "Aufruf: %s [-C] [-u] [-c Ccache] [-e Etype]\n" -+ -+#: ../../src/clients/kvno/kvno.c:47 -+#, c-format -+msgid "\t[-k keytab] [-S sname] [-U for_user [-P]]\n" -+msgstr "\t[-k Schlüsseltabelle] [-S Sname] [-U für_Benutzer [-P]]\n" -+ -+#: ../../src/clients/kvno/kvno.c:48 -+#, c-format -+msgid "\tservice1 service2 ...\n" -+msgstr "\tDienst1 Dienst2 …\n" -+ -+#: ../../src/clients/kvno/kvno.c:103 ../../src/clients/kvno/kvno.c:111 -+#, c-format -+msgid "Options -u and -S are mutually exclusive\n" -+msgstr "Die Optionen -u und -S schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/kvno/kvno.c:126 -+#, c-format -+msgid "Option -P (constrained delegation) requires keytab to be specified\n" -+msgstr "" -+"Die Option -P (eingeschränkte Abtretung) erfordert zur Angabe eine " -+"Schlüsseltabelle.\n" -+ -+#: ../../src/clients/kvno/kvno.c:130 -+#, c-format -+msgid "" -+"Option -P (constrained delegation) requires option -U (protocol transition)\n" -+msgstr "" -+"Die Option -P (eingeschränkte Abtretung) erfordert die Option -U " -+"(Protokollübergang)\n" -+ -+#: ../../src/clients/kvno/kvno.c:175 ../../src/kadmin/cli/kadmin.c:280 -+msgid "while initializing krb5 library" -+msgstr "beim Initialisieren der Krb5-Bibliothek" -+ -+#: ../../src/clients/kvno/kvno.c:182 -+msgid "while converting etype" -+msgstr "bei der Etype-Umwandlung" -+ -+#: ../../src/clients/kvno/kvno.c:218 -+msgid "while getting client principal name" -+msgstr "beim Holen des Client-Principal-Namens" -+ -+#: ../../src/clients/kvno/kvno.c:256 -+#, c-format -+msgid "while formatting parsed principal name for '%s'" -+msgstr "beim Formatieren des ausgewerteten Principal-Namens für »%s«" -+ -+#: ../../src/clients/kvno/kvno.c:267 -+msgid "client and server principal names must match" -+msgstr "Die Principal-Namen von Client und Server müssen übereinstimmen." -+ -+#: ../../src/clients/kvno/kvno.c:284 -+#, c-format -+msgid "while getting credentials for %s" -+msgstr "beim Holen der Anmeldedaten für %s" -+ -+#: ../../src/clients/kvno/kvno.c:291 -+#, c-format -+msgid "while decoding ticket for %s" -+msgstr "beim Dekodieren des Tickets für %s" -+ -+#: ../../src/clients/kvno/kvno.c:302 -+#, c-format -+msgid "while decrypting ticket for %s" -+msgstr "beim Entschlüsseln des Tickets für %s" -+ -+#: ../../src/clients/kvno/kvno.c:306 -+#, c-format -+msgid "%s: kvno = %d, keytab entry valid\n" -+msgstr "%s: KVNO = %d, Schlüsseltabelleneintrag gültig\n" -+ -+#: ../../src/clients/kvno/kvno.c:324 -+#, c-format -+msgid "%s: constrained delegation failed" -+msgstr "%s: eingeschränkte Abtretung fehlgeschlagen" -+ -+#: ../../src/clients/kvno/kvno.c:330 -+#, c-format -+msgid "%s: kvno = %d\n" -+msgstr "%s: KVNO = %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:118 -+#, c-format -+msgid "" -+"Usage: %s [-r realm] [-p principal] [-q query] [clnt|local args]\n" -+"\tclnt args: [-s admin_server[:port]] [[-c ccache]|[-k [-t keytab]]]|[-n]\n" -+"\tlocal args: [-x db_args]* [-d dbname] [-e \"enc:salt ...\"] [-m]\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"Aufruf: %s [-r Realm] [-p Principal] [-q Abfrage] [clnt|lokale Argumente]\n" -+"\tclnt Argumente: [-s Admin-Server[:Port]] [[-c Ccache]|\n" -+"\t[-k [-t Schlüsseltabelle]]]|[-n] lokale Argumente: [-x DB-Argumente]*\n" -+"\t[-d Datenbankname] [-e \"enc:Salt …\"] [-m]\n" -+"wobei\n" -+"\t[-x DB-Argumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente\n" -+"\tist. Die unterstützten Argumente finden Sie in den jeweiligen " -+"\tDatenbankdokumentationen\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:292 ../../src/kadmin/cli/kadmin.c:333 -+#, c-format -+msgid "%s: Cannot initialize. Not enough memory\n" -+msgstr "%s: Zu wenig Speicher zum Initialisieren\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:353 ../../src/kadmin/cli/kadmin.c:804 -+#: ../../src/kadmin/cli/kadmin.c:1084 ../../src/kadmin/cli/kadmin.c:1634 -+#: ../../src/kadmin/cli/keytab.c:159 ../../src/kadmin/dbutil/kdb5_util.c:591 -+#, c-format -+msgid "while parsing keysalts %s" -+msgstr "beim Auswerten der Schlüssel-Salts %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:376 -+#, c-format -+msgid "%s: unable to get default realm\n" -+msgstr "%s: Standard-Realm kann nicht geholt werden\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:396 -+msgid "while opening default credentials cache" -+msgstr "beim Öffnen des Standardanmeldedatenzwischenspeichers" -+ -+#: ../../src/kadmin/cli/kadmin.c:402 -+#, c-format -+msgid "while opening credentials cache %s" -+msgstr "beim Öffnen des Anmeldedatenzwischenspeichers %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:424 ../../src/kadmin/cli/kadmin.c:479 -+#: ../../src/kadmin/cli/kadmin.c:487 ../../src/kadmin/cli/kadmin.c:494 -+#, c-format -+msgid "%s: out of memory\n" -+msgstr "%s: Speicherplatz reicht nicht aus\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:433 ../../src/kadmin/cli/kadmin.c:448 -+#: ../../src/slave/kpropd.c:681 -+msgid "while canonicalizing principal name" -+msgstr "während der Principal-Name in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:442 -+msgid "creating host service principal" -+msgstr "Principal des Rechnerdienstes wird erstellt" -+ -+#: ../../src/kadmin/cli/kadmin.c:455 -+#, c-format -+msgid "%s: unable to canonicalize principal\n" -+msgstr "%s: Principal kann nicht in die normale Form gebracht werden\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:499 -+#, c-format -+msgid "%s: unable to figure out a principal name\n" -+msgstr "%s: Es kann kein Principal-Name herausgefunden werden.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:507 -+msgid "while setting up logging" -+msgstr "beim Einrichten der Protokollierung" -+ -+#: ../../src/kadmin/cli/kadmin.c:516 -+#, c-format -+msgid "Authenticating as principal %s with existing credentials.\n" -+msgstr "Authentifizierung als Principal %s mit existierenden Anmeldedaten\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:522 -+#, c-format -+msgid "Authenticating as principal %s with password; anonymous requested.\n" -+msgstr "" -+"Authentifizierung als Principal %s mit Passwort; Anonymität erwünscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:529 -+#, c-format -+msgid "Authenticating as principal %s with keytab %s.\n" -+msgstr "Authentifizierung als Principal %s mit Schlüsseltabelle %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:532 -+#, c-format -+msgid "Authenticating as principal %s with default keytab.\n" -+msgstr "Authentifizierung als Principal %s mit Standardschlüsseltabelle\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:538 -+#, c-format -+msgid "Authenticating as principal %s with password.\n" -+msgstr "Authentifizierung als Principal %s mit Passwort\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:546 ../../src/slave/kpropd.c:728 -+#, c-format -+msgid "while initializing %s interface" -+msgstr "beim Initialisieren der Schnittstelle %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:560 -+#, c-format -+msgid "while closing ccache %s" -+msgstr "beim Schließen von Ccache %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:566 -+msgid "while mapping update log" -+msgstr "beim Abbilden des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/cli/kadmin.c:581 -+msgid "while unlocking locked database" -+msgstr "beim Entsperren der Datenbank" -+ -+#: ../../src/kadmin/cli/kadmin.c:590 -+msgid "Administration credentials NOT DESTROYED.\n" -+msgstr "Verwaltungsanmeldedaten NICHT VERNICHTET\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:639 -+#, c-format -+msgid "usage: delete_principal [-force] principal\n" -+msgstr "Aufruf: delete_principal [-force] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:644 ../../src/kadmin/cli/kadmin.c:819 -+msgid "while parsing principal name" -+msgstr "beim Auswerten des Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:650 ../../src/kadmin/cli/kadmin.c:825 -+#: ../../src/kadmin/cli/kadmin.c:1217 ../../src/kadmin/cli/kadmin.c:1339 -+#: ../../src/kadmin/cli/kadmin.c:1409 ../../src/kadmin/cli/kadmin.c:1858 -+#: ../../src/kadmin/cli/kadmin.c:1902 ../../src/kadmin/cli/kadmin.c:1948 -+#: ../../src/kadmin/cli/kadmin.c:1988 -+msgid "while canonicalizing principal" -+msgstr "während der Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:654 -+#, c-format -+msgid "Are you sure you want to delete the principal \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie den Principal »%s« löschen möchten? (yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:658 -+#, c-format -+msgid "Principal \"%s\" not deleted\n" -+msgstr "Principal »%s« nicht gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:665 -+#, c-format -+msgid "while deleting principal \"%s\"" -+msgstr "beim Löschen von Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:668 -+#, c-format -+msgid "Principal \"%s\" deleted.\n" -+msgstr "Principal »%s« gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:669 -+#, c-format -+msgid "" -+"Make sure that you have removed this principal from all ACLs before " -+"reusing.\n" -+msgstr "" -+"Stellen Sie sicher, dass Sie diesen Principal aus allen ACLs entfernt haben, " -+"bevor Sie ihn erneut benutzen.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:686 -+#, c-format -+msgid "usage: rename_principal [-force] old_principal new_principal\n" -+msgstr "Aufruf: rename_principal [-force] alter_Principal neuer_Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:693 -+msgid "while parsing old principal name" -+msgstr "beim Auswerten des alten Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:699 -+msgid "while parsing new principal name" -+msgstr "beim Auswerten des neuen Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:705 -+msgid "while canonicalizing old principal" -+msgstr "während der alte Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:711 -+msgid "while canonicalizing new principal" -+msgstr "während der neue Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:715 -+#, c-format -+msgid "" -+"Are you sure you want to rename the principal \"%s\" to \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie den Principal »%s« in »%s« umbenennen möchten? " -+"(yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:719 -+#, c-format -+msgid "Principal \"%s\" not renamed\n" -+msgstr "Principal »%s« wurde nicht umbenannt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:726 -+#, c-format -+msgid "while renaming principal \"%s\" to \"%s\"" -+msgstr "beim Umbenennen von Principal »%s« in »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:730 -+#, c-format -+msgid "Principal \"%s\" renamed to \"%s\".\n" -+msgstr "Principal »%s« wurde in »%s« umbenannt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:731 -+#, c-format -+msgid "" -+"Make sure that you have removed the old principal from all ACLs before " -+"reusing.\n" -+msgstr "" -+"Stellen Sie sicher, dass Sie den alten Principal aus allen ACLs entfernt " -+"haben, bevor Sie ihn erneut benutzen.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:746 -+#, c-format -+msgid "" -+"usage: change_password [-randkey] [-keepold] [-e keysaltlist] [-pw password] " -+"principal\n" -+msgstr "" -+"Aufruf: change_password [-randkey] [-keepold] [-e Schlüssel-Salt-Liste] [-pw " -+"Passwort] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:772 -+msgid "change_password: missing db argument" -+msgstr "change_password: fehlendes Datenbankargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:778 -+#, c-format -+msgid "change_password: Not enough memory\n" -+msgstr "change_password: zu wenig Speicher\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:786 -+msgid "change_password: missing password arg" -+msgstr "change_password: fehlendes Passwortargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:797 -+msgid "change_password: missing keysaltlist arg" -+msgstr "change_password: fehlendes Schlüssel-Salt-Listenargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:813 -+msgid "missing principal name" -+msgstr "fehlender Principal-Name" -+ -+#: ../../src/kadmin/cli/kadmin.c:837 ../../src/kadmin/cli/kadmin.c:874 -+#, c-format -+msgid "while changing password for \"%s\"." -+msgstr "beim Ändern des Passworts von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:840 ../../src/kadmin/cli/kadmin.c:877 -+#, c-format -+msgid "Password for \"%s\" changed.\n" -+msgstr "Passwort von »%s« geändert\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:846 ../../src/kadmin/cli/kadmin.c:1290 -+#, c-format -+msgid "while randomizing key for \"%s\"." -+msgstr "beim Erzeugen eines zufälligen Schlüssels für »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:849 -+#, c-format -+msgid "Key for \"%s\" randomized.\n" -+msgstr "Es wurde ein zufälliger Schlüssel für %s erzeugt\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:854 ../../src/kadmin/cli/kadmin.c:1250 -+#, c-format -+msgid "Enter password for principal \"%s\"" -+msgstr "Geben Sie das Passwort für Principal »%s« ein." -+ -+#: ../../src/kadmin/cli/kadmin.c:856 ../../src/kadmin/cli/kadmin.c:1252 -+#, c-format -+msgid "Re-enter password for principal \"%s\"" -+msgstr "Geben Sie das Passwort für Principal »%s« erneut ein." -+ -+#: ../../src/kadmin/cli/kadmin.c:861 ../../src/kadmin/cli/kadmin.c:1256 -+#, c-format -+msgid "while reading password for \"%s\"." -+msgstr "beim Lesen des Passworts von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:915 -+#, c-format -+msgid "Not enough memory\n" -+msgstr "Speicher reicht nicht aus\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:945 ../../src/kadmin/dbutil/kdb5_util.c:623 -+msgid "while getting time" -+msgstr "beim Holen der Zeit" -+ -+#: ../../src/kadmin/cli/kadmin.c:994 ../../src/kadmin/cli/kadmin.c:1007 -+#: ../../src/kadmin/cli/kadmin.c:1020 ../../src/kadmin/cli/kadmin.c:1033 -+#: ../../src/kadmin/cli/kadmin.c:1546 ../../src/kadmin/cli/kadmin.c:1558 -+#: ../../src/kadmin/cli/kadmin.c:1601 ../../src/kadmin/cli/kadmin.c:1618 -+#, c-format -+msgid "Invalid date specification \"%s\".\n" -+msgstr "ungültige Datumsangabe »%s«\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1118 ../../src/kadmin/cli/kadmin.c:1333 -+#: ../../src/kadmin/cli/kadmin.c:1404 ../../src/kadmin/cli/kadmin.c:1852 -+#: ../../src/kadmin/cli/kadmin.c:1896 ../../src/kadmin/cli/kadmin.c:1942 -+#: ../../src/kadmin/cli/kadmin.c:1982 -+msgid "while parsing principal" -+msgstr "beim Auswerten des Principals" -+ -+#: ../../src/kadmin/cli/kadmin.c:1127 -+#, c-format -+msgid "usage: add_principal [options] principal\n" -+msgstr "Aufruf: add_principal [Optionen] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1128 ../../src/kadmin/cli/kadmin.c:1155 -+#: ../../src/kadmin/cli/kadmin.c:1657 -+#, c-format -+msgid "\toptions are:\n" -+msgstr "\tEs gibt folgende Optionen:\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1130 -+#, c-format -+msgid "" -+"\t\t[-randkey|-nokey] [-x db_princ_args]* [-expire expdate] [-pwexpire " -+"pwexpdate] [-maxlife maxtixlife]\n" -+"\t\t[-kvno kvno] [-policy policy] [-clearpolicy]\n" -+"\t\t[-pw password] [-maxrenewlife maxrenewlife]\n" -+"\t\t[-e keysaltlist]\n" -+"\t\t[{+|-}attribute]\n" -+msgstr "" -+"\t\t[-randkey|-nokey] [-x DB-Principal-Argumente]* [-expire Ablaufdatum] [-" -+"pwexpire Passwortablaufdatum] [-maxlife maximale_Ticketlebensdauer]\n" -+"\t\t[-kvno KVNO] [-policy Richtlinie] [-clearpolicy]\n" -+"\t\t[-pw Passwort] [-maxrenewlife maximale_Dauer_bis_zum_Erneuern]\n" -+"\t\t[-e Schlüssel-Salt-Liste]\n" -+"\t\t[{+|-}Attribut]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1136 -+#, c-format -+msgid "\tattributes are:\n" -+msgstr "\tEs gibt folgende Attribute:\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1138 ../../src/kadmin/cli/kadmin.c:1164 -+#, c-format -+msgid "" -+"\t\tallow_postdated allow_forwardable allow_tgs_req allow_renewable\n" -+"\t\tallow_proxiable allow_dup_skey allow_tix requires_preauth\n" -+"\t\trequires_hwauth needchange allow_svr password_changing_service\n" -+"\t\tok_as_delegate ok_to_auth_as_delegate no_auth_data_required\n" -+"\n" -+"where,\n" -+"\t[-x db_princ_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"\t\tallow_postdated allow_forwardable allow_tgs_req allow_renewable\n" -+"\t\tallow_proxiable allow_dup_skey allow_tix requires_preauth\n" -+"\t\trequires_hwauth needchange allow_svr password_changing_service\n" -+"\t\tok_as_delegate ok_to_auth_as_delegate no_auth_data_required\n" -+"\n" -+"wobei\n" -+"\t[-x DB-Principal-Argumente]* - eine beliebige Zahl\n" -+"\tdatenbankspezifischer Argumente ist.\n" -+"\t\t\tDie unterstützten Argumente finden Sie in der jeweiligen\n" -+"Datenbankdokumentation.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1154 -+#, c-format -+msgid "usage: modify_principal [options] principal\n" -+msgstr "Aufruf: modify_principal [Optionen] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1157 -+#, c-format -+msgid "" -+"\t\t[-x db_princ_args]* [-expire expdate] [-pwexpire pwexpdate] [-maxlife " -+"maxtixlife]\n" -+"\t\t[-kvno kvno] [-policy policy] [-clearpolicy]\n" -+"\t\t[-maxrenewlife maxrenewlife] [-unlock] [{+|-}attribute]\n" -+msgstr "" -+"\t\t[-x DB-Principal-Argumente]* [-expire Ablaufdatum] [-pwexpire " -+"Passwortablaufdatum] [-maxlife maximale_Ticketlebensdauer]\n" -+"\t\t[-kvno KVNO] [-policy Richtlinie] [-clearpolicy]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern] [-unlock] [{+|-}" -+"Attribut]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1224 ../../src/kadmin/cli/kadmin.c:1362 -+#, c-format -+msgid "WARNING: policy \"%s\" does not exist\n" -+msgstr "WARNUNG: Richtlinie »%s« existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1230 -+#, c-format -+msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" -+msgstr "" -+"HINWEIS: Für %s wurde keine Richtlinie angegeben, es wird »default« " -+"zugewiesen\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1235 -+#, c-format -+msgid "WARNING: no policy specified for %s; defaulting to no policy\n" -+msgstr "" -+"WARNUNG: Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " -+"»keine\n" -+"Richtlinie« verwandt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1276 -+#, c-format -+msgid "Admin server does not support -nokey while creating \"%s\"\n" -+msgstr "" -+"Der Administrationsrechner unterstützt beim Erstellen von »%s« kein -nokey\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1298 -+#, c-format -+msgid "while clearing DISALLOW_ALL_TIX for \"%s\"." -+msgstr "beim Löschen von DISALLOW_ALL_TIX für »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1345 -+#, c-format -+msgid "while getting \"%s\"." -+msgstr "beim Holen von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1371 -+#, c-format -+msgid "while modifying \"%s\"." -+msgstr "beim Ändern von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1375 -+#, c-format -+msgid "Principal \"%s\" modified.\n" -+msgstr "Principal »%s« wurde geändert.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1396 -+#, c-format -+msgid "usage: get_principal [-terse] principal\n" -+msgstr "Aufruf: get_principal [-terse] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1415 -+#, c-format -+msgid "while retrieving \"%s\"." -+msgstr "beim Abfragen von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1420 ../../src/kadmin/cli/kadmin.c:1425 -+msgid "while unparsing principal" -+msgstr "beim Rückgängigmachen der Auswertung des Principals" -+ -+#: ../../src/kadmin/cli/kadmin.c:1429 -+#, c-format -+msgid "Principal: %s\n" -+msgstr "Principal: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1430 -+#, c-format -+msgid "Expiration date: %s\n" -+msgstr "Ablaufdatum: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1431 ../../src/kadmin/cli/kadmin.c:1433 -+#: ../../src/kadmin/cli/kadmin.c:1444 -+msgid "[never]" -+msgstr "[niemals]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1432 -+#, c-format -+msgid "Last password change: %s\n" -+msgstr "Letzte Passwortänderung: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1434 -+#, c-format -+msgid "Password expiration date: %s\n" -+msgstr "Passwortablaufdatum: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1436 ../../src/kadmin/cli/kadmin.c:1478 -+msgid "[none]" -+msgstr "[keins]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1437 -+#, c-format -+msgid "Maximum ticket life: %s\n" -+msgstr "maximale Ticketlebensdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1438 -+#, c-format -+msgid "Maximum renewable life: %s\n" -+msgstr "maximale verlängerbare Lebensdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1440 -+#, c-format -+msgid "Last modified: %s (%s)\n" -+msgstr "zuletzt geändert: %s (%s)\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1442 -+#, c-format -+msgid "Last successful authentication: %s\n" -+msgstr "letzte erfolgreiche Authentifizierung: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1448 -+#, c-format -+msgid "Failed password attempts: %d\n" -+msgstr "Fehlgeschlagene Anmeldeversuche: %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1450 -+#, c-format -+msgid "Number of keys: %d\n" -+msgstr "Anzahl der Schlüssel: %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1457 -+#, c-format -+msgid "" -+msgstr "" -+ -+#: ../../src/kadmin/cli/kadmin.c:1464 -+#, c-format -+msgid "" -+msgstr "" -+ -+#: ../../src/kadmin/cli/kadmin.c:1470 -+#, c-format -+msgid "MKey: vno %d\n" -+msgstr "MKey: vno %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1472 -+#, c-format -+msgid "Attributes:" -+msgstr "Attribute:" -+ -+#: ../../src/kadmin/cli/kadmin.c:1480 -+msgid " [does not exist]" -+msgstr " [existiert nicht]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1481 -+#, c-format -+msgid "Policy: %s%s\n" -+msgstr "Richtlinie: %s%s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1517 -+#, c-format -+msgid "usage: get_principals [expression]\n" -+msgstr "Aufruf: get_principals [Ausdruck]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1522 ../../src/kadmin/cli/kadmin.c:1794 -+msgid "while retrieving list." -+msgstr "beim Abfragen der Liste." -+ -+#: ../../src/kadmin/cli/kadmin.c:1647 -+#, c-format -+msgid "%s: parser lost count!\n" -+msgstr "%s: Auswertungsprogramm verlor Anzahl!\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1656 -+#, c-format -+msgid "usage; %s [options] policy\n" -+msgstr "Aufruf: %s [Optionen] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1659 -+#, c-format -+msgid "" -+"\t\t[-maxlife time] [-minlife time] [-minlength length]\n" -+"\t\t[-minclasses number] [-history number]\n" -+"\t\t[-maxfailure number] [-failurecountinterval time]\n" -+"\t\t[-allowedkeysalts keysalts]\n" -+msgstr "" -+"\t\t[-maxlife Zeit] [-minlife Zeit] [-minlength Länge]\n" -+"\t\t[-minclasses Anzahl] [-history Nummer]\n" -+"\t\t[-maxfailure Anzahl] [-failurecountinterval Zeit]\n" -+"\t\t[-allowedkeysalts Schlüssel-Salts]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1663 -+#, c-format -+msgid "\t\t[-lockoutduration time]\n" -+msgstr "\t\t[-lockoutduration Dauer]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1682 -+#, c-format -+msgid "while creating policy \"%s\"." -+msgstr "beim Erstellen der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1703 -+#, c-format -+msgid "while modifying policy \"%s\"." -+msgstr "beim Ändern der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1715 -+#, c-format -+msgid "usage: delete_policy [-force] policy\n" -+msgstr "Aufruf: delete_policy [-force] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1719 -+#, c-format -+msgid "Are you sure you want to delete the policy \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie die Richtlinie »%s« löschen möchten? (yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:1723 -+#, c-format -+msgid "Policy \"%s\" not deleted.\n" -+msgstr "Richtlinie »%s« nicht gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1729 -+#, c-format -+msgid "while deleting policy \"%s\"" -+msgstr "bei Löschen der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1741 -+#, c-format -+msgid "usage: get_policy [-terse] policy\n" -+msgstr "Aufruf: get_policy [-terse] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1746 -+#, c-format -+msgid "while retrieving policy \"%s\"." -+msgstr "beim Abfragen der Richtlinie »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1751 -+#, c-format -+msgid "Policy: %s\n" -+msgstr "Richtlinie: »%s«\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1752 -+#, c-format -+msgid "Maximum password life: %ld\n" -+msgstr "maximale Passwortlebensdauer: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1753 -+#, c-format -+msgid "Minimum password life: %ld\n" -+msgstr "minimale Passwortlebensdauer: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1754 -+#, c-format -+msgid "Minimum password length: %ld\n" -+msgstr "minimale Passwortlänge: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1755 -+#, c-format -+msgid "Minimum number of password character classes: %ld\n" -+msgstr "minimale Anzahl von Passwortzeichenklassen: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1757 -+#, c-format -+msgid "Number of old keys kept: %ld\n" -+msgstr "Anzahl aufbewahrter alter Schlüssel: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1758 -+#, c-format -+msgid "Maximum password failures before lockout: %lu\n" -+msgstr "maximale Anzahl falscher Passworteingaben vor dem Sperren: %lu\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1760 -+#, c-format -+msgid "Password failure count reset interval: %s\n" -+msgstr "Rücksetzintervall für zu viele falsch eingebene Passwörter: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1762 -+#, c-format -+msgid "Password lockout duration: %s\n" -+msgstr "Passwortsperrdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1765 -+#, c-format -+msgid "Allowed key/salt types: %s\n" -+msgstr "erlaubte Schlüssel-/Salt-Typen: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1789 -+#, c-format -+msgid "usage: get_policies [expression]\n" -+msgstr "Aufruf: get_policies [Ausdruck]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1811 -+#, c-format -+msgid "usage: get_privs\n" -+msgstr "Aufruf: get_privs\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1816 -+msgid "while retrieving privileges" -+msgstr "beim Abfragen von Rechten" -+ -+#: ../../src/kadmin/cli/kadmin.c:1819 -+#, c-format -+msgid "current privileges:" -+msgstr "aktuelle Rechte:" -+ -+#: ../../src/kadmin/cli/kadmin.c:1845 -+#, c-format -+msgid "usage: purgekeys [-all|-keepkvno oldest_kvno_to_keep] principal\n" -+msgstr "" -+"Aufruf: purgekeys [-all|-keepkvno älteste_KVNO_die_behalten_wird] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1865 -+#, c-format -+msgid "while purging keys for principal \"%s\"" -+msgstr "beim vollständigen Löschen der Schlüssel für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1870 -+#, c-format -+msgid "All keys for principal \"%s\" removed.\n" -+msgstr "Alle Schlüssel für Principal »%s« wurden entfernt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1872 -+#, c-format -+msgid "Old keys for principal \"%s\" purged.\n" -+msgstr "Alte Schlüssel für Principal »%s« wurden entfernt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1889 -+#, c-format -+msgid "usage: get_strings principal\n" -+msgstr "Aufruf: get_strings Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1909 -+#, c-format -+msgid "while getting attributes for principal \"%s\"" -+msgstr "beim Holen von Attributen für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1914 -+#, c-format -+msgid "(No string attributes.)\n" -+msgstr "(keine Zeichenkettenattribute)\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1933 -+#, c-format -+msgid "usage: set_string principal key value\n" -+msgstr "Aufruf: set_string Principal Schlüssel Wert\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1955 -+#, c-format -+msgid "while setting attribute on principal \"%s\"" -+msgstr "beim Setzen eines Attributes für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1959 -+#, c-format -+msgid "Attribute set for principal \"%s\".\n" -+msgstr "Attribute für Principal »%s« wurden gesetzt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1974 -+#, c-format -+msgid "usage: del_string principal key\n" -+msgstr "Aufruf: del_string Principal Schlüssel\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1995 -+#, c-format -+msgid "while deleting attribute from principal \"%s\"" -+msgstr "beim Löschen eines Attributs von Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1999 -+#, c-format -+msgid "Attribute removed from principal \"%s\".\n" -+msgstr "Attribut von Principal »%s« wurde gelöscht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:56 -+#, c-format -+msgid "" -+"Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] [-norandkey] " -+"[principal | -glob princ-exp] [...]\n" -+msgstr "" -+"Aufruf: ktadd [-k[eytab] Schlüsseltabelle] [-q] [-e Schlüssel-Salt-Liste] [-" -+"norandkey] [Principal | -glob Principal-Ausdruck] […]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:59 -+#, c-format -+msgid "" -+"Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] [principal | -glob " -+"princ-exp] [...]\n" -+msgstr "" -+"Aufruf: ktadd [-k[eytab] Schlüsseltabelle] [-q] [-e Schlüssel-Salt-Liste] " -+"[Principal | -glob Principal-Ausdruck] […]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:67 -+#, c-format -+msgid "" -+"Usage: ktremove [-k[eytab] keytab] [-q] principal [kvno|\"all\"|\"old\"]\n" -+msgstr "" -+"Aufruf: ktremove [-k[eytab] Schlüsseltabelle] [-q] Principal " -+"[kvno|»all«|»old«]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:81 ../../src/kadmin/cli/keytab.c:102 -+msgid "while creating keytab name" -+msgstr "beim Erstellen des Schlüsseltabellennamens" -+ -+#: ../../src/kadmin/cli/keytab.c:86 -+msgid "while opening default keytab" -+msgstr "beim Öffnen der Standardschlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:147 -+#, c-format -+msgid "-norandkey option only valid for kadmin.local\n" -+msgstr "Die Option »-norandkey« ist nur für »kadmin.local« gültig.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:176 -+#, c-format -+msgid "cannot specify keysaltlist when not changing key\n" -+msgstr "" -+"Schlüssel-Salt-Liste kann nicht angegeben werden, wenn der Schlüssel nicht " -+"geändert wird\n" -+ -+#: ../../src/kadmin/cli/keytab.c:192 -+#, c-format -+msgid "while expanding expression \"%s\"." -+msgstr "beim Expandieren des Ausdrucks »%s«." -+ -+#: ../../src/kadmin/cli/keytab.c:211 ../../src/kadmin/cli/keytab.c:251 -+msgid "while closing keytab" -+msgstr "beim Schließen der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:275 -+#, c-format -+msgid "while parsing -add principal name %s" -+msgstr "beim Auswerten von »-add Principal-Name %s«" -+ -+#: ../../src/kadmin/cli/keytab.c:289 -+#, c-format -+msgid "%s: Principal %s does not exist.\n" -+msgstr "%s: Principal %s existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:292 -+#, c-format -+msgid "while changing %s's key" -+msgstr "beim Ändern des Schlüssels von %s" -+ -+#: ../../src/kadmin/cli/keytab.c:299 -+msgid "while retrieving principal" -+msgstr "beim Abfragen des Principals" -+ -+#: ../../src/kadmin/cli/keytab.c:311 -+msgid "while adding key to keytab" -+msgstr "beim Hinzufügen des Schlüssels zur Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:317 -+#, c-format -+msgid "" -+"Entry for principal %s with kvno %d, encryption type %s added to keytab %s.\n" -+msgstr "" -+"Der Eintrag für Principal %s mit KVNO %d und Verschlüsselungstyp %s wurde " -+"der Schlüsseltabelle %s hinzugefügt.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:326 -+msgid "while freeing principal entry" -+msgstr "beim Freigeben des Principal-Eintrags" -+ -+#: ../../src/kadmin/cli/keytab.c:373 -+#, c-format -+msgid "%s: Keytab %s does not exist.\n" -+msgstr "%s: Schlüsseltabelle %s existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:377 -+#, c-format -+msgid "%s: No entry for principal %s exists in keytab %s\n" -+msgstr "" -+"%s: Für Principal %s existiert kein Eintrag in der Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:381 -+#, c-format -+msgid "%s: No entry for principal %s with kvno %d exists in keytab %s\n" -+msgstr "" -+"%s: Für den Principal %s mit der KVNO %d existiert kein Eintrag in der " -+"Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:387 -+msgid "while retrieving highest kvno from keytab" -+msgstr "beim Abfragen der höchsten KVNO der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:420 -+msgid "while temporarily ending keytab scan" -+msgstr "beim Unterbrechen des Schlüsseltabellen-Scans" -+ -+#: ../../src/kadmin/cli/keytab.c:425 -+msgid "while deleting entry from keytab" -+msgstr "beim Löschen eines Eintrags aus der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:430 -+msgid "while restarting keytab scan" -+msgstr "bei der Wiederaufnahme des Schlüsseltabellen-Scans" -+ -+#: ../../src/kadmin/cli/keytab.c:436 -+#, c-format -+msgid "Entry for principal %s with kvno %d removed from keytab %s.\n" -+msgstr "" -+"Der Eintrag für Principal %s mit KVNO %d wurde aus der Schlüsseltabelle %s " -+"entfernt.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:458 -+#, c-format -+msgid "%s: There is only one entry for principal %s in keytab %s\n" -+msgstr "" -+"%s: Es gibt nur einen Eintrag für Principal %s in der Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/ss_wrapper.c:49 ../../src/kadmin/ktutil/ktutil.c:58 -+msgid "creating invocation" -+msgstr "Aufruf wird erstellt" -+ -+#: ../../src/kadmin/dbutil/dump.c:165 -+msgid "while allocating temporary filename dump" -+msgstr "beim Reservieren des temporären Dateinamenspeicherauszugs" -+ -+#: ../../src/kadmin/dbutil/dump.c:176 -+msgid "while renaming dump file into place" -+msgstr "während das Umbenennen der Auszugsdateien Gestalt annimmt" -+ -+#: ../../src/kadmin/dbutil/dump.c:192 -+msgid "while allocating dump_ok filename" -+msgstr "beim Reservieren des »dump_ok«-Dateinamens" -+ -+#: ../../src/kadmin/dbutil/dump.c:199 -+#, c-format -+msgid "while creating 'ok' file, '%s'" -+msgstr "beim Erstellen der Datei »ok«, »%s«" -+ -+#: ../../src/kadmin/dbutil/dump.c:206 -+#, c-format -+msgid "while locking 'ok' file, '%s'" -+msgstr "beim Sperren der Datei »ok«, »%s«" -+ -+#: ../../src/kadmin/dbutil/dump.c:248 ../../src/kadmin/dbutil/dump.c:277 -+#, c-format -+msgid "%s: regular expression error: %s\n" -+msgstr "%s: Fehler im regulären Ausdruck: %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:260 -+#, c-format -+msgid "%s: regular expression match error: %s\n" -+msgstr "%s: Fehler beim Abgleich mit regulärem Ausdruck: %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:361 -+#, c-format -+msgid "%s: tagged data list inconsistency for %s (counted %d, stored %d)\n" -+msgstr "" -+"%s: Unstimmigkeit in der markierten Datenliste für %s (%d gezählt, %d " -+"gespeichert)\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:519 -+#, c-format -+msgid "" -+"Warning! Multiple DES-CBC-CRC keys for principal %s; skipping duplicates.\n" -+msgstr "" -+"Warnung! Mehrere DES-CBC-CRC-Schlüssel für Principal %s, Duplikate werden " -+"übersprungen.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:530 -+#, c-format -+msgid "" -+"Warning! No DES-CBC-CRC key for principal %s, cannot generate OV-compatible " -+"record; skipping\n" -+msgstr "" -+"Warnung! Kein DES-CBC-CRC-Schlüssel für Principal %s, es kann kein OV-" -+"kompatibler Datensatz erzeugt werden, wird übersprungen\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:558 -+#, c-format -+msgid "while converting %s to new master key" -+msgstr "beim Umwandeln von %s in den neuen Hauptschlüssel" -+ -+#: ../../src/kadmin/dbutil/dump.c:579 -+#, c-format -+msgid "%s(%d): %s\n" -+msgstr "%s(%d): %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:622 -+#, c-format -+msgid "%s(%d): ignoring trash at end of line: " -+msgstr "%s(%d): Müll am Zeilenende wird ignoriert: " -+ -+#: ../../src/kadmin/dbutil/dump.c:685 -+msgid "cannot read tagged data type and length" -+msgstr "Markierter Datentyp und Länge können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:692 -+msgid "cannot read tagged data contents" -+msgstr "Inhalt der markierten Daten kann nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:726 -+msgid "cannot match size tokens" -+msgstr "Größenmerkmale können nicht zugeordnet werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:755 -+msgid "cannot read name string" -+msgstr "Namenszeichenkette kann nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:760 -+#, c-format -+msgid "while parsing name %s" -+msgstr "beim Auswerten des Namens %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:768 -+msgid "cannot read principal attributes" -+msgstr "Principal-Attribute können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:821 -+msgid "cannot read key size and version" -+msgstr "Schlüssellänge und -version können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:832 -+msgid "cannot read key type and length" -+msgstr "Schlüsseltyp und -länge können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:838 -+msgid "cannot read key data" -+msgstr "Schlüsseldaten können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:848 -+msgid "cannot read extra data" -+msgstr "Zusätzliche Daten können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:857 -+#, c-format -+msgid "while storing %s" -+msgstr "beim Speichern von %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:896 ../../src/kadmin/dbutil/dump.c:935 -+#: ../../src/kadmin/dbutil/dump.c:981 -+#, c-format -+msgid "cannot parse policy (%d read)\n" -+msgstr "Richtlinie kann nicht ausgewertet werden (%d gelesen)\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:904 ../../src/kadmin/dbutil/dump.c:943 -+#: ../../src/kadmin/dbutil/dump.c:1001 -+msgid "while creating policy" -+msgstr "beim Erstellen der Richtlinie" -+ -+#: ../../src/kadmin/dbutil/dump.c:908 -+#, c-format -+msgid "created policy %s\n" -+msgstr "erstellte Richtlinie %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1038 -+#, c-format -+msgid "unknown record type \"%s\"\n" -+msgstr "unbekannter Datensatztyp »%s«\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1167 -+#, c-format -+msgid "%s: Unknown iprop dump version %d\n" -+msgstr "%s: unbekannte Iprop-Auszugsversion %d\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1270 ../../src/kadmin/dbutil/dump.c:1498 -+#, c-format -+msgid "Iprop not enabled\n" -+msgstr "Iprop nicht aktiviert\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1308 -+msgid "Conditional dump is an undocumented option for use only for iprop dumps" -+msgstr "" -+"Bedingter Auszug ist eine nicht dokumentierte Option, die nur für Iprop-" -+"Auszüge benutzt wird." -+ -+#: ../../src/kadmin/dbutil/dump.c:1321 -+msgid "Database not currently opened!" -+msgstr "Die Datenbank ist zur Zeit nicht geöffnet!" -+ -+#: ../../src/kadmin/dbutil/dump.c:1335 -+#: ../../src/kadmin/dbutil/kdb5_stash.c:116 -+#: ../../src/kadmin/dbutil/kdb5_util.c:479 -+msgid "while reading master key" -+msgstr "beim Lesen des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1341 -+msgid "while verifying master key" -+msgstr "beim Prüfen des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1360 ../../src/kadmin/dbutil/dump.c:1370 -+msgid "while reading new master key" -+msgstr "beim Lesen des neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1364 -+#, c-format -+msgid "Please enter new master key....\n" -+msgstr "Bitte geben Sie den neuen Hauptschlüssel ein …\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1388 -+#, c-format -+msgid "while opening %s for writing" -+msgstr "beim Öffnen von %s zum Schreiben" -+ -+#: ../../src/kadmin/dbutil/dump.c:1403 -+msgid "while reading update log header" -+msgstr "beim Lesen der Aktualisierungsprotokollkopfzeilen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1418 ../../src/kadmin/dbutil/dump.c:1425 -+#, c-format -+msgid "performing %s dump" -+msgstr "Auszug von %s wird durchgeführt" -+ -+#: ../../src/kadmin/dbutil/dump.c:1455 -+#, c-format -+msgid "%s: error processing line %d of %s\n" -+msgstr "%s: Fehler beim Verarbeiten von Zeile %d von %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1507 -+msgid "while parsing options" -+msgstr "beim Auswerten der Optionen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1522 -+#, c-format -+msgid "while opening %s" -+msgstr "beim Öffnen von %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:1527 ../../src/kadmin/dbutil/dump.c:1626 -+msgid "standard input" -+msgstr "Standardeingabe" -+ -+#: ../../src/kadmin/dbutil/dump.c:1532 -+#, c-format -+msgid "%s: can't read dump header in %s\n" -+msgstr "%s: Kopfzeilen des Auszugs in %s können nicht gelesen werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1540 ../../src/kadmin/dbutil/dump.c:1557 -+#, c-format -+msgid "%s: dump header bad in %s\n" -+msgstr "%s: falsche Kopfzeilen des Auszugs in %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1566 -+#, c-format -+msgid "Could not open iprop ulog\n" -+msgstr "Iprop-Ulog kann nicht geöffnet werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1571 -+#, c-format -+msgid "%s: dump version %s can only be loaded with the -update flag\n" -+msgstr "" -+"%s: Die Auszugsversion %s kann nur mit dem Schalter -update geladen werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1580 ../../src/kadmin/dbutil/dump.c:1585 -+msgid "computing parameters for database" -+msgstr "Parameter für die Datenbank werden berechnet." -+ -+#: ../../src/kadmin/dbutil/dump.c:1591 -+msgid "while creating database" -+msgstr "beim Erstellen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1600 -+msgid "while opening database" -+msgstr "beim Öffnen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1610 -+msgid "while permanently locking database" -+msgstr "beim dauerhaften Sperren der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1628 -+#, c-format -+msgid "%s: %s restore failed\n" -+msgstr "%s: Wiederherstellen von %s fehlgeschlagen\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1633 -+msgid "while unlocking database" -+msgstr "beim Aufheben der Datenbanksperre" -+ -+#: ../../src/kadmin/dbutil/dump.c:1643 ../../src/kadmin/dbutil/dump.c:1662 -+msgid "while reinitializing update log" -+msgstr "beim erneuten Initialisieren des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/dump.c:1653 -+msgid "while making newly loaded database live" -+msgstr "beim Aktivieren der neu geladenen Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1669 -+msgid "while writing update log header" -+msgstr "beim Schreiben der Aktualisierungsprotokollkopfzeilen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1683 -+#, c-format -+msgid "while deleting bad database %s" -+msgstr "beim Löschen der falschen Datenbank %s" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:84 -+msgid "while looking up the Kerberos configuration" -+msgstr "beim Nachschlagen der Kerberos-Konfiguration" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:111 -+msgid "while initializing the Kerberos admin interface" -+msgstr "beim Initialisieren der Kerberos-Administrationsoberfläche" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:169 -+#, c-format -+msgid "getaddrinfo(%s): Cannot determine canonical hostname.\n" -+msgstr "" -+"getaddrinfo(%s): Die Normalform des Rechnernamens kann nicht bestimmt " -+"werden.\n" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:190 -+#: ../../src/kadmin/dbutil/kadm5_create.c:196 -+#, c-format -+msgid "Out of memory\n" -+msgstr "Speicherplatz reicht nicht aus.\n" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:270 -+msgid "while appending realm to principal" -+msgstr "beim Anhängen des Realms an den Principal" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:275 -+msgid "while parsing admin principal name" -+msgstr "beim Auswerten des Principal-Namens des Administrators" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:286 -+#, c-format -+msgid "while creating principal %s" -+msgstr "beim Erstellen des Principals %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:175 -+#: ../../src/kadmin/dbutil/kdb5_util.c:241 -+#: ../../src/kadmin/dbutil/kdb5_util.c:248 -+msgid "while parsing command arguments\n" -+msgstr "beim Auswerten der Befehlsargumente\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:198 -+#, c-format -+msgid "Loading random data\n" -+msgstr "Zufällige Daten werden geladen.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:201 -+msgid "Loading random data" -+msgstr "Zufällige Daten werden geladen." -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:211 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:242 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:435 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:591 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1149 -+#: ../../src/kadmin/dbutil/kdb5_util.c:423 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:606 -+msgid "while setting up master key name" -+msgstr "beim Einrichten des Hauptschlüsselnamens" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:222 -+#, c-format -+msgid "" -+"Initializing database '%s' for realm '%s',\n" -+"master key name '%s'\n" -+msgstr "" -+"Datenbank »%s« für Realm »%s« wird initialisiert,\n" -+"Hauptschlüsselname »%s«\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:227 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:516 -+#, c-format -+msgid "You will be prompted for the database Master Password.\n" -+msgstr "Sie werden nach dem Master-Passwort der Datenbank gefragt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:228 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:260 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:517 -+#, c-format -+msgid "It is important that you NOT FORGET this password.\n" -+msgstr "Es ist wichtig, dass Sie dieses Passwort NICHT VERGESSEN.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:234 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:266 -+msgid "while creating new master key" -+msgstr "beim Erstellen des neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:242 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:527 -+msgid "while reading master key from keyboard" -+msgstr "beim Lesen des Hauptschlüssels von der Tastatur" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:252 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:285 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:618 -+msgid "while calculating master key salt" -+msgstr "beim Berechnen des Hauptschlüssel-Salts" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:260 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:294 -+#: ../../src/kadmin/dbutil/kdb5_util.c:465 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:630 -+msgid "while transforming master key from password" -+msgstr "beim Umwandeln des Hauptschlüssels vom Passwort" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:270 -+msgid "while initializing random key generator" -+msgstr "beim Initialisieren des Zufallsschlüsselgenerators" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:275 -+#, c-format -+msgid "while creating database '%s'" -+msgstr "beim Erstellen der Datenbank »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:293 -+msgid "while creating update log" -+msgstr "beim Erstellen des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:304 -+msgid "while initializing update log" -+msgstr "beim Initialisieren des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:320 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:642 -+msgid "while adding entries to the database" -+msgstr "beim Hinzufügen von Einträgen in die Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:348 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:339 -+#: ../../src/kadmin/dbutil/kdb5_stash.c:133 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:667 -+msgid "while storing key" -+msgstr "beim Speichern des Schlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:349 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:340 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:668 -+#, c-format -+msgid "Warning: couldn't stash master key.\n" -+msgstr "Warnung: Hauptschlüssel kann nicht gelagert werden.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:57 -+msgid "while initializing krb5_context" -+msgstr "beim Initialisieren von »krb5_context«" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:63 -+#: ../../src/kadmin/dbutil/kdb5_util.c:259 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:291 -+msgid "while setting default realm name" -+msgstr "beim Einstellen des Standard-Realm-Namens" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:83 -+#, c-format -+msgid "Deleting KDC database stored in '%s', are you sure?\n" -+msgstr "" -+"Die in »%s« gespeicherte KDC-Datenbank wird gelöscht. Sind Sie sicher?\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:85 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1166 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:360 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1482 -+#, c-format -+msgid "(type 'yes' to confirm)? " -+msgstr "(Geben Sie als Bestätigung »yes« ein)? " -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:92 -+#, c-format -+msgid "OK, deleting database '%s'...\n" -+msgstr "OK, Datenbank »%s« wird gelöscht …\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:97 -+#, c-format -+msgid "deleting database '%s'" -+msgstr "Datenbank »%s« wird gelöscht." -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:106 -+#, c-format -+msgid "** Database '%s' destroyed.\n" -+msgstr "** Datenbank »%s« vernichtet\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:218 -+#, c-format -+msgid "%s is an invalid enctype" -+msgstr "%s ist ein ungültiger Verschlüsselungstyp" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:250 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:443 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:599 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:986 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1157 -+#, c-format -+msgid "while getting master key principal %s" -+msgstr "beim Holen des Hauptschlüssels von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:256 -+#, c-format -+msgid "Creating new master key for master key principal '%s'\n" -+msgstr "" -+"Es wird ein neuer Hauptschlüssel für den Hauptschlüssel-Principal »%s« " -+"erstellt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:259 -+#, c-format -+msgid "You will be prompted for a new database Master Password.\n" -+msgstr "Sie werden nach einem neuen Datenbank-Master-Passwort gefragt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:275 -+msgid "while reading new master key from keyboard" -+msgstr "beim Lesen des neuen Hauptschlüssels von der Tastatur" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:304 -+msgid "adding new master key to master principal" -+msgstr "dem Haupt-Principal wird ein neuer Hauptschlüssel hinzugefügt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:310 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:402 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:843 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1356 -+msgid "while getting current time" -+msgstr "beim Holen der aktuellen Zeit" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:317 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:544 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1363 -+msgid "while updating the master key principal modification time" -+msgstr "beim Aktulisieren der Änderungszeit des Hauptschlüssel-Principals" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:325 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:553 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1374 -+msgid "while adding master key entry to the database" -+msgstr "beim Hinzufügen des Hauptschlüsseleintrags zur Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:383 -+msgid "0 is an invalid KVNO value" -+msgstr "0 ist kein gültiger KVNO-Wert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:394 -+#, c-format -+msgid "%d is an invalid KVNO value" -+msgstr "%d ist kein gültiger KVNO-Wert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:410 -+#, c-format -+msgid "could not parse date-time string '%s'" -+msgstr "»date-time«-Zeichenkette »%s« konnte nicht ausgewertet werden" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:452 -+msgid "while looking up active version of master key" -+msgstr "beim Nachschlagen der aktiven Version des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:491 -+msgid "while adding new master key" -+msgstr "beim Hinzufügen eines neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:529 -+msgid "there must be one master key currently active" -+msgstr "ein Hauptschlüssel muss derzeit aktiv sein" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:537 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1342 -+msgid "while updating actkvno data for master principal entry" -+msgstr "beim Aktualisieren der Actkvno-Daten für den Haupt-Principal-Eintrag" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:581 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:948 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1116 -+msgid "master keylist not initialized" -+msgstr "Hauptschlüsselliste ist nicht initialisiert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:607 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:994 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1254 -+msgid "while looking up active kvno list" -+msgstr "beim Nachschlagen der Liste aktiver KVNOs" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:615 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1002 -+msgid "while looking up active master key" -+msgstr "beim Nachschlagen des aktiven Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:627 -+msgid "while getting enctype description" -+msgstr "beim Holen des Verschlüsselungsbeschreibung" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:644 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, Active on: %s *\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, aktiviert auf: %s *\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:649 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, Active on: %s\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, aktiviert auf: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:653 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, No activate time set\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, keine Aktivierungszeit gesetzt\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:658 -+msgid "asprintf could not allocate enough memory to hold output" -+msgstr "" -+"Asprintf konnte nicht genug Speicher reservieren, um die Ausgabe " -+"bereitzuhalten" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:793 -+msgid "getting string representation of principal name" -+msgstr "Principal-Name wird im Klartext geholt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:817 -+#, c-format -+msgid "determining master key used for principal '%s'" -+msgstr "Hauptschlüssel, der für Principal »%s« benutzt wird, wird bestimmt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:823 -+#, c-format -+msgid "would skip: %s\n" -+msgstr "würde übersprungen: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:825 -+#, c-format -+msgid "skipping: %s\n" -+msgstr "wird übersprungen: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:831 -+#, c-format -+msgid "would update: %s\n" -+msgstr "würde aktualisiert: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:835 -+#, c-format -+msgid "updating: %s\n" -+msgstr "wird aktualisiert: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:839 -+#, c-format -+msgid "error re-encrypting key for principal '%s'" -+msgstr "Fehler beim erneuten Verschlüsseln des Schlüssels für Principal »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:850 -+#, c-format -+msgid "while updating principal '%s' modification time" -+msgstr "beim Aktualisieren der Änderungszeit von Principal »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:857 -+#, c-format -+msgid "while updating principal '%s' key data in the database" -+msgstr "" -+"beim Aktualisieren der Schlüsseldaten von Principal »%s« in der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:889 -+#, c-format -+msgid "" -+"\n" -+"(type 'yes' to confirm)? " -+msgstr "" -+"\n" -+"(Geben Sie als Bestätigung »yes« ein) " -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:942 -+msgid "while formatting master principal name" -+msgstr "beim Formatieren des Haupt-Principal-Namens" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:959 -+#, c-format -+msgid "converting glob pattern '%s' to regular expression" -+msgstr "Platzhalter »%s« wird in einen regulären Ausdruck umgewandelt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:977 -+#, c-format -+msgid "error compiling converted regexp '%s'" -+msgstr "Fehler beim Kompilieren des umgewandelten regulären Ausdrucks »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1010 -+#, c-format -+msgid "Re-encrypt all keys not using master key vno %u?" -+msgstr "" -+"Sollen alle Schlüssel neu verschlüsselt werden, die nicht die Hauptschlüssel-" -+"VNO %u verwenden?" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1012 -+#, c-format -+msgid "OK, doing nothing.\n" -+msgstr "Ok, es wird nichts getan.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1018 -+#, c-format -+msgid "Principals whose keys WOULD BE re-encrypted to master key vno %u:\n" -+msgstr "" -+"Principals, deren Schlüssel mit dem Hauptschlüssel VNO %u neu verschlüsselt " -+"WÜRDEN:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1021 -+#, c-format -+msgid "" -+"Principals whose keys are being re-encrypted to master key vno %u if " -+"necessary:\n" -+msgstr "" -+"Principals, deren Schlüssel mit dem Hauptschlüssel VNO %u neu verschlüsselt " -+"werden, falls nötig:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1037 -+msgid "trying to process principal database" -+msgstr "es wird versucht, die Principal-Datenbank zu verarbeiten" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1042 -+#, c-format -+msgid "%u principals processed: %u would be updated, %u already current\n" -+msgstr "" -+"%u Principals verarbeitet: %u würden aktualisiert, %u bereits aktuell\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1046 -+#, c-format -+msgid "%u principals processed: %u updated, %u already current\n" -+msgstr "%u Principals verarbeitet: %u aktualisiert, %u bereits aktuell\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1164 -+#, c-format -+msgid "" -+"Will purge all unused master keys stored in the '%s' principal, are you " -+"sure?\n" -+msgstr "" -+"Sind Sie sicher, dass alle nicht verwendeten Hauptschlüssel, die für " -+"Principal »%s« gespeichert sind, vollständig entfernt werden sollen?\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1175 -+#, c-format -+msgid "OK, purging unused master keys from '%s'...\n" -+msgstr "" -+"Ok, die nicht verwendeten Hauptschlüssel von »%s« werden vollständig " -+"entfernt …\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1183 -+#, c-format -+msgid "There is only one master key which can not be purged.\n" -+msgstr "" -+"Es gibt nur einen einzigen Hauptschlüssel, der nicht vollständig entfernt " -+"werden kann.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1192 -+msgid "while allocating args.kvnos" -+msgstr "beim Reservieren von »args.kvnos«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1208 -+msgid "while finding master keys in use" -+msgstr "bei der Suche nach den gerade verwendeten Hauptschlüsseln" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1217 -+#, c-format -+msgid "Would purge the following master key(s) from %s:\n" -+msgstr "" -+"Der/Die folgende(n) Hauptschlüssel würden/würde von %s vollständig " -+"entfernt:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1220 -+#, c-format -+msgid "Purging the following master key(s) from %s:\n" -+msgstr "" -+"Der/Die folgende(n) Hauptschlüssel werden/wird von %s vollständig entfernt:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1232 -+msgid "master key stash file needs updating, command aborting" -+msgstr "" -+"Ablagedatei des Hauptschlüssels erfordert Aktualisierung, Befehl abgebrochen" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1238 -+#, c-format -+msgid "KVNO: %d\n" -+msgstr "KVNO: %d\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1243 -+#, c-format -+msgid "All keys in use, nothing purged.\n" -+msgstr "Alle Schlüssel sind in Gebrauch, keiner wurde vollständig entfernt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1248 -+#, c-format -+msgid "%d key(s) would be purged.\n" -+msgstr "%d Schlüssel würde(n) vollständig entfernt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1261 -+msgid "while looking up mkey aux data list" -+msgstr "beim Nachschlagen der Mkey-Aux-Datenliste" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1269 -+msgid "while allocating key_data" -+msgstr "beim Reservieren von »key_data«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1350 -+msgid "while updating mkey_aux data for master principal entry" -+msgstr "beim Aktualisieren der Mkey-Aux-Daten für den Haupt-Principal-Eintrag" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1378 -+#, c-format -+msgid "%d key(s) purged.\n" -+msgstr "%d Schlüssel vollständig entfernt\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:97 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:538 -+#, c-format -+msgid "while setting up enctype %d" -+msgstr "beim Einrichten des Verschlüsselungstyps %d" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:123 -+msgid "while getting master key list" -+msgstr "beim Holen der Hauptschlüsselliste" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:127 -+#, c-format -+msgid "Using existing stashed keys to update stash file.\n" -+msgstr "" -+"Zur Aktualisierung der Ablagedatei werden existierende gelagert Schlüssel " -+"verwendet.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:80 -+#, c-format -+msgid "" -+"Usage: kdb5_util [-x db_args]* [-r realm] [-d dbname] [-k mkeytype] [-M " -+"mkeyname]\n" -+"\t [-kv mkeyVNO] [-sf stashfilename] [-m] cmd [cmd_options]\n" -+"\tcreate [-s]\n" -+"\tdestroy [-f]\n" -+"\tstash [-f keyfile]\n" -+"\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" -+"\t [-mkey_convert] [-new_mkey_file mkey_file]\n" -+"\t [-rev] [-recurse] [filename [princs...]]\n" -+"\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] filename\n" -+"\tark [-e etype_list] principal\n" -+"\tadd_mkey [-e etype] [-s]\n" -+"\tuse_mkey kvno [time]\n" -+"\tlist_mkeys\n" -+msgstr "" -+"Aufruf: kdb5_util [-x Datenbankargumente]* [-r Realm] [-d Datenbankname] [-k " -+"Mkeytype] [-M Mkeyname]\n" -+"\t [-kv MkeyVNO] [-sf Ablagedateiname] [-m] Befehl [Befehlsoptionen]\n" -+"\tcreate [-s]\n" -+"\tdestroy [-f]\n" -+"\tstash [-f Schlüsseldatei]\n" -+"\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" -+"\t [-mkey_convert] [-new_mkey_file mkey-Datei]\n" -+"\t [-rev] [-recurse] [Dateiname [Principals …]]\n" -+"\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] Dateiname\n" -+"\tark [-e Etype-Liste] Principal\n" -+"\tadd_mkey [-e Etype] [-s]\n" -+"\tuse_mkey kvno [Zeit]\n" -+"\tlist_mkeys\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:98 -+#, c-format -+msgid "" -+"\tupdate_princ_encryption [-f] [-n] [-v] [princ-pattern]\n" -+"\tpurge_mkeys [-f] [-n] [-v]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"\tupdate_princ_encryption [-f] [-n] [-v] [Principal-Muster]\n" -+"\tpurge_mkeys [-f] [-n] [-v]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:211 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:260 -+msgid "while initializing Kerberos code" -+msgstr "beim Initialisieren von Kerberos-Code" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:217 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:267 -+msgid "while creating sub-command arguments" -+msgstr "beim Erstellen von Unterbefehlsargumenten" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:235 -+msgid "while parsing command arguments" -+msgstr "beim Auswerten von Befehlsargumenten" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:264 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:298 -+#, c-format -+msgid ": %s is an invalid enctype" -+msgstr ": %s ist kein gültiger Verschlüsselungstyp" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:272 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:307 -+#, c-format -+msgid ": %s is an invalid mkeyVNO" -+msgstr ": %s ist kein gültiger MkeyVNO" -+ -+# FIXME s/retreiving/retrieving/ -+#: ../../src/kadmin/dbutil/kdb5_util.c:317 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:431 -+msgid "while retreiving configuration parameters" -+msgstr "beim Abfragen der Konfigurationsparameter" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:368 -+msgid "Too few arguments" -+msgstr "zu wenige Argumente" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:369 -+#, c-format -+msgid "Usage: %s dbpathname realmname" -+msgstr "Aufruf: %s Datenbankpfadname Realm-Name" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:375 -+msgid "while closing previous database" -+msgstr "beim Schließen der vorherigen Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:412 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:877 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1497 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:564 -+msgid "while initializing database" -+msgstr "beim Initialisieren der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:429 -+msgid "while retrieving master entry" -+msgstr "beim Abfragen des Haupteintrags" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:448 -+msgid "while calculated master key salt" -+msgstr "beim Berechnen des Hauptschlüssel-Salts" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:480 -+msgid "Warning: proceeding without master key" -+msgstr "Warnung: Es wird ohne Hauptschlüssel fortgefahren" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:498 -+msgid "while seeding random number generator" -+msgstr "beim Erzeugen des Startwerts des Zufallszahlengenerators" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:508 -+#, c-format -+msgid "%s: Could not map log\n" -+msgstr "%s: Protokolldatei konnte nicht abgebildet werden\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:535 -+msgid "while closing database" -+msgstr "beim Schließen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:582 -+#, c-format -+msgid "while fetching principal %s" -+msgstr "beim Abrufen von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:605 -+msgid "while finding mkey" -+msgstr "beim Suchen nach Mkey" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:630 -+msgid "while setting changetime" -+msgstr "beim Setzen der Änderungszeit der Datei" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:638 -+#, c-format -+msgid "while saving principal %s" -+msgstr "beim Speichern von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:642 -+#, c-format -+msgid "%s changed\n" -+msgstr "%s geändert\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:73 -+#, c-format -+msgid "%s: invalid arguments\n" -+msgstr "%s: ungültige Argumente\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:78 -+msgid "while freeing ktlist" -+msgstr "beim Freigeben von »ktlist«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:89 -+#, c-format -+msgid "%s: must specify keytab to read\n" -+msgstr "" -+"%s: Die Schlüsseltabelle, die gelesen werden soll, muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:94 -+#, c-format -+msgid "while reading keytab \"%s\"" -+msgstr "beim Lesen der Schlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:104 -+#, c-format -+msgid "%s: must specify the srvtab to read\n" -+msgstr "%s: Die zu lesende Dienstschlüsseltabelle muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:109 -+#, c-format -+msgid "while reading srvtab \"%s\"" -+msgstr "beim Lesen der Dienstschlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:119 -+#, c-format -+msgid "%s: must specify keytab to write\n" -+msgstr "%s: Die zu schreibende Schlüsseltabelle muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:124 -+#, c-format -+msgid "while writing keytab \"%s\"" -+msgstr "beim Schreiben der Schlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:131 -+#, c-format -+msgid "%s: writing srvtabs is no longer supported\n" -+msgstr "" -+"%s: Schreiben der Dienstschlüsseltabelle wird nicht länger unterstützt\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:169 -+#, c-format -+msgid "usage: %s (-key | -password) -p principal -k kvno -e enctype\n" -+msgstr "" -+"Aufruf: %s (-key | -password) -p Principal -k KVNO -e Verschlüsselungstyp\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:176 -+msgid "while adding new entry" -+msgstr "beim Hinzufügen eines neuen Eintrags" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:186 -+#, c-format -+msgid "%s: must specify entry to delete\n" -+msgstr "%s: zu löschender Eintrag muss angegeben werden\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:191 -+#, c-format -+msgid "while deleting entry %d" -+msgstr "beim Löschen von Eintrag %d" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:219 -+#, c-format -+msgid "%s: usage: %s [-t] [-k] [-e]\n" -+msgstr "%s: Aufruf: %s [-t] [-k] [-e]\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:259 -+msgid "While converting enctype to string" -+msgstr "beim Umwandeln des Verschlüsselungstyps in eine Zeichenkette" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:162 -+#, c-format -+msgid "Password for %.1000s" -+msgstr "Passwort für %.1000s" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:179 -+#, c-format -+msgid "Key for %s (hex): " -+msgstr "Schlüssel für %s (hexadezimal): " -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:191 -+#, c-format -+msgid "addent: Error reading key.\n" -+msgstr "addent: Fehler beim Lesen des Schlüssels\n" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:206 -+#, c-format -+msgid "addent: Illegal character in key.\n" -+msgstr "addent: unerlaubtes Zeichen im Schlüssel\n" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:48 -+#, c-format -+msgid "Unauthorized request: %s, client=%s, service=%s, addr=%s" -+msgstr "unberechtigte Anfrage: %s, Client=%s, Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:49 -+#: ../../src/kadmin/server/ipropd_svc.c:212 -+#, c-format -+msgid "Request: %s, %s, %s, client=%s, service=%s, addr=%s" -+msgstr "Anfrage: %s, %s, %s, Client=%s, Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:146 -+#: ../../src/kadmin/server/ipropd_svc.c:271 -+#, c-format -+msgid "%s: server handle is NULL" -+msgstr "%s: Server-Identifikator ist NULL" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:156 -+#: ../../src/kadmin/server/ipropd_svc.c:284 -+#, c-format -+msgid "%s: setup_gss_names failed" -+msgstr "%s: setup_gss_names fehlgeschlagen" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:166 -+#: ../../src/kadmin/server/ipropd_svc.c:295 -+#, c-format -+msgid "%s: out of memory recording principal names" -+msgstr "%s: Speicher reicht nicht zur Aufzeichnung der Principal-Namen aus" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:195 -+#, c-format -+msgid "%s; Incoming SerialNo=%lu; Outgoing SerialNo=%lu" -+msgstr "%s; eingehende Seriennummer=%lu; ausgehende Seriennummer=%lu" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:201 -+#, c-format -+msgid "%s; Incoming SerialNo=%lu; Outgoing SerialNo=N/A" -+msgstr "%s; eingehende Seriennummer=%lu; ausgehende Seriennummer=N/A" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:320 -+#, c-format -+msgid "%s: getclhoststr failed" -+msgstr "%s: getclhoststr fehlgeschlagen" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:342 -+#, c-format -+msgid "%s: cannot construct kdb5 util dump string too long; out of memory" -+msgstr "" -+"Ausgabenzeichenkette des KDB5-Hilfswerkzeugs nicht konstruierbar, da zu " -+"lang; Speicher reicht nicht aus.%s: Die Ausgabezeichenkette des KDB5-" -+"Hilfswerkzeugs kann nicht erstellt werden, weil sie zu lang ist. Der " -+"Speicherplatz reicht nicht aus." -+ -+#: ../../src/kadmin/server/ipropd_svc.c:362 -+#, c-format -+msgid "%s: fork failed: %s" -+msgstr "%s: Verzweigen fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:374 -+#, c-format -+msgid "%s: popen failed: %s" -+msgstr "%s: popen fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:388 -+#, c-format -+msgid "%s: pclose(popen) failed: %s" -+msgstr "%s: pclose(popen) fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:405 -+#, c-format -+msgid "%s: exec failed: %s" -+msgstr "%s: exec fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:421 -+#, c-format -+msgid "Request: %s, spawned resync process %d, client=%s, service=%s, addr=%s" -+msgstr "" -+"Anfrage: %s, hervorgebrachter Neusynchronisationsprozess %d, Client=%s, " -+"Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:485 -+#: ../../src/kadmin/server/kadm_rpc_svc.c:275 -+#, c-format -+msgid "check_rpcsec_auth: failed inquire_context, stat=%u" -+msgstr "check_rpcsec_auth: inquire_context fehlgeschlagen, Stat=%u" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:515 -+#: ../../src/kadmin/server/kadm_rpc_svc.c:304 -+#, c-format -+msgid "bad service principal %.*s%s" -+msgstr "falscher Dienst-Principal %.*s%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:538 -+#, c-format -+msgid "authentication attempt failed: %s, RPC authentication flavor %d" -+msgstr "" -+"Authentifizierungsversuche gescheitert: %s, PRC-Authentifizierungsvariante %d" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:572 -+#, c-format -+msgid "RPC unknown request: %d (%s)" -+msgstr "unbekannte PRC-Anfrage: %d (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:580 -+#, c-format -+msgid "RPC svc_getargs failed (%s)" -+msgstr "RPC-»svc_getargs« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:590 -+#, c-format -+msgid "RPC svc_sendreply failed (%s)" -+msgstr "RPC-»svc_sendreply« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:596 -+#, c-format -+msgid "RPC svc_freeargs failed (%s)" -+msgstr "RPC-»svc_freeargs« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/kadm_rpc_svc.c:325 -+#, c-format -+msgid "gss_to_krb5_name: failed display_name status %d" -+msgstr "gss_to_krb5_name: display_name fehlgeschlagen, Status %d" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:86 -+#, c-format -+msgid "" -+"Usage: kadmind [-x db_args]* [-r realm] [-m] [-nofork] [-port port-number]\n" -+"\t\t[-proponly] [-p path-to-kdb5_util] [-F dump-file]\n" -+"\t\t[-K path-to-kprop] [-P pid_file]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"Aufruf: kadmind [-x Datenbankargumente]* [-r Realm] [-m] [-nofork]\n" -+"\t\t[-port Portummer] [-p Pfad_zum_KDB5-Hilfswerkzeug] [-F Auszugsdatei]\n" -+"\t\t[-K Pfad_zu_Kprop] [-P PID-Datei]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:111 -+#, c-format -+msgid "%s: %s while %s, aborting\n" -+msgstr "%s: %s bei %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:113 -+#, c-format -+msgid "%s while %s, aborting\n" -+msgstr "%s bei %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:115 -+#, c-format -+msgid "%s: %s, aborting\n" -+msgstr "%s: %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:116 -+#, c-format -+msgid "%s, aborting" -+msgstr "%s, wird abgebrochen" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:282 -+#, c-format -+msgid "" -+"WARNING! Forged/garbled request: %s, claimed client = %.*s%s, server = %.*s" -+"%s, addr = %s" -+msgstr "" -+"WARNUNG! Gefälschte/verstümmelte Anfrage: %s, geforderter Client = %.*s%s, " -+"Server = %.*s%s, Adresse = %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:288 -+#, c-format -+msgid "" -+"WARNING! Forged/garbled request: %d, claimed client = %.*s%s, server = %.*s" -+"%s, addr = %s" -+msgstr "" -+"WARNUNG! Gefälschte/verstümmelte Anfrage: %d, Client = %.*s%s, Server = " -+"%.*s%s, Adresse = %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:302 -+#, c-format -+msgid "Miscellaneous RPC error: %s, %s" -+msgstr "sonstiger PRC-Fehler: %s, %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:318 -+#, c-format -+msgid "%s Cannot decode status %d" -+msgstr "%s: Status %d kann nicht dekodiert werden" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:336 -+#, c-format -+msgid "Authentication attempt failed: %s, GSS-API error strings are:" -+msgstr "Authentifizierungsversuch fehlgeschlagen: %s, GSS-API-Fehlermeldungen:" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:341 -+msgid " GSS-API error strings complete." -+msgstr " GSS-API-Fehlermeldungen vollständig" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:378 -+#, c-format -+msgid "%s: cannot initialize. Not enough memory\n" -+msgstr "%s: kann nicht initialisiert werden: Speicher reicht nicht aus.\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:445 -+#, c-format -+msgid "%s: %s while initializing context, aborting\n" -+msgstr "%s: %s beim Initialisieren des Kontextes, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:456 -+msgid "initializing" -+msgstr "wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:460 -+msgid "getting config parameters" -+msgstr "beim Holen der Konfigurationsparameter" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:462 -+msgid "Missing required realm configuration" -+msgstr "erforderliche Realm-Konfiguration fehlt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:464 -+msgid "Missing required ACL file configuration" -+msgstr "erforderliche ACL-Dateikonfiguration fehlt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:468 -+msgid "initializing network" -+msgstr "Netzwerk wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:473 -+msgid "Cannot build GSSAPI auth names" -+msgstr "GSS-API-Authentifizierungsnamen können nicht gebildet werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:477 -+msgid "Cannot set up KDB keytab" -+msgstr "Die KDB-Schlüsseltabelle kann nicht eingerichtet werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:480 -+msgid "Cannot set GSSAPI authentication names" -+msgstr "GSS-API-Authentifizierungsnamen können nicht gesetzt werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:497 -+msgid "Cannot initialize GSSAPI service name" -+msgstr "GSSAPI-Dienstname kann nicht initialisiert werden" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:501 -+msgid "initializing ACL file" -+msgstr "ACL-Datei wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:504 -+msgid "spawning daemon process" -+msgstr "Daemon-Prozess wird erzeugt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:508 -+msgid "creating PID file" -+msgstr "PID-Datei wird erstellt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:511 -+msgid "Seeding random number generator" -+msgstr "Startwert des Zufallszahlengenerators wird erzeugt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:514 -+msgid "getting random seed" -+msgstr "Zufallsstartwert wird geholt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:521 -+msgid "mapping update log" -+msgstr "Aktualisierungsprotokoll wird abgebildet" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:525 -+#, c-format -+msgid "%s: create IPROP svc (PROG=%d, VERS=%d)\n" -+msgstr "%s: IPROP-Dienst wird erstellt (PROG=%d, VERS=%d)\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:530 -+msgid "starting" -+msgstr "startet" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:532 ../../src/kdc/main.c:1061 -+#, c-format -+msgid "%s: starting...\n" -+msgstr "%s: startet …\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:535 -+msgid "finished, exiting" -+msgstr "fertig, wird beendet" -+ -+#: ../../src/kadmin/server/schpw.c:282 -+#, c-format -+msgid "setpw request from %s by %.*s%s for %.*s%s: %s" -+msgstr "»setpw«-Anfrage von %s durch %.*s%s für %.*s%s: %s" -+ -+#: ../../src/kadmin/server/schpw.c:287 -+#, c-format -+msgid "chpw request from %s for %.*s%s: %s" -+msgstr "»chpw«-Anfrage von %s für %.*s%s: %s" -+ -+#: ../../src/kadmin/server/schpw.c:464 -+#, c-format -+msgid "chpw: Couldn't open admin keytab %s" -+msgstr "chpw«: Administratorschlüsseltabelle %s konnte nicht geöffnet werden" -+ -+#: ../../src/kadmin/server/server_stubs.c:293 -+#, c-format -+msgid "" -+"Unauthorized request: %s, %.*s%s, client=%.*s%s, service=%.*s%s, addr=%s" -+msgstr "" -+"Unauthorisierte Anfrage: %s, %.*s%s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:314 -+#: ../../src/kadmin/server/server_stubs.c:649 -+#: ../../src/kadmin/server/server_stubs.c:1792 -+msgid "success" -+msgstr "erfolgreich" -+ -+#: ../../src/kadmin/server/server_stubs.c:324 -+#, c-format -+msgid "Request: %s, %.*s%s, %s, client=%.*s%s, service=%.*s%s, addr=%s" -+msgstr "Anfrage: %s, %.*s%s, %s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:628 -+#, c-format -+msgid "" -+"Unauthorized request: kadm5_rename_principal, %.*s%s to %.*s%s, client=%.*s" -+"%s, service=%.*s%s, addr=%s" -+msgstr "" -+"Unauthorisierte Anfrage: kadm5_rename_principal, %.*s%s bis %.*s%s, Client=" -+"%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:644 -+#, c-format -+msgid "" -+"Request: kadm5_rename_principal, %.*s%s to %.*s%s, %s, client=%.*s%s, " -+"service=%.*s%s, addr=%s" -+msgstr "" -+"Anfrage: kadm5_rename_principal, %.*s%s bis %.*s%s, %s, Client=%.*s%s, " -+"Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:1788 -+#, c-format -+msgid "" -+"Request: kadm5_init, %.*s%s, %s, client=%.*s%s, service=%.*s%s, addr=%s, " -+"vers=%d, flavor=%d" -+msgstr "" -+"Anfrage: kadm5_init, %.*s%s, %s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s, " -+"Version=%d, Variante=%d" -+ -+#: ../../src/kdc/do_as_req.c:273 -+#, c-format -+msgid "AS_REQ : handle_authdata (%d)" -+msgstr "AS_REQ: handle_authdata (%d)" -+ -+#: ../../src/kdc/do_tgs_req.c:593 -+#, c-format -+msgid "TGS_REQ : handle_authdata (%d)" -+msgstr "TGS_REQ: handle_authdata (%d)" -+ -+#: ../../src/kdc/do_tgs_req.c:655 -+msgid "not checking transit path" -+msgstr "Übergangspfad wird nicht geprüft" -+ -+#: ../../src/kdc/fast_util.c:62 -+#, c-format -+msgid "%s while handling ap-request armor" -+msgstr "%s bei der Handhabung des »ap-request«-Schutzes" -+ -+#: ../../src/kdc/fast_util.c:71 -+msgid "ap-request armor for something other than the local TGS" -+msgstr "»ap-request«-Schutz für etwas anderes als den lokalen TGS" -+ -+#: ../../src/kdc/fast_util.c:80 -+msgid "ap-request armor without subkey" -+msgstr "»ap-request«-Schutz ohne Unterschlüssel" -+ -+#: ../../src/kdc/fast_util.c:162 -+msgid "Ap-request armor not permitted with TGS" -+msgstr "»ap-request«-Schutz nicht mit TGS gestattet" -+ -+#: ../../src/kdc/fast_util.c:169 -+#, c-format -+msgid "Unknown FAST armor type %d" -+msgstr "unbekanntet FAST-Schutztyp %d" -+ -+#: ../../src/kdc/fast_util.c:183 -+msgid "No armor key but FAST armored request present" -+msgstr "Es gibt keinen Schutzschlüssel aber eine FAST-geschützte Anfrage" -+ -+#: ../../src/kdc/fast_util.c:219 -+msgid "FAST req_checksum invalid; request modified" -+msgstr "FAST-»req_checksum« ungültig; Anfrage geändert" -+ -+#: ../../src/kdc/fast_util.c:225 -+msgid "Unkeyed checksum used in fast_req" -+msgstr "in fast_req wurde eine Prüfsumme ohne Schlüssel benutzt" -+ -+#: ../../src/kdc/kdc_audit.c:110 -+#, c-format -+msgid "audit plugin %s failed to open. error=%i" -+msgstr "Öffnen der Audit-Erweiterung %s fehlgeschlagen. Fehler=%i" -+ -+#: ../../src/kdc/kdc_authdata.c:292 ../../src/kdc/kdc_authdata.c:328 -+#, c-format -+msgid "authdata %s failed to initialize: %s" -+msgstr "Initialisieren von »authdata« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_authdata.c:779 -+#, c-format -+msgid "authdata (%s) handling failure: %s" -+msgstr "Handhabung von »authdata« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_log.c:82 -+#, c-format -+msgid "AS_REQ (%s) %s: ISSUE: authtime %d, %s, %s for %s" -+msgstr "AS_REQ (%s) %s: PROBLEM: Authentifizierungszeit %d, %s, %s für %s" -+ -+#: ../../src/kdc/kdc_log.c:88 -+#, c-format -+msgid "AS_REQ (%s) %s: %s: %s for %s%s%s" -+msgstr "AS_REQ (%s) %s: %s: %s für %s%s%s" -+ -+#: ../../src/kdc/kdc_log.c:159 -+#, c-format -+msgid "TGS_REQ (%s) %s: %s: authtime %d, %s%s %s for %s%s%s" -+msgstr "TGS_REQ (%s) %s: %s: Authentifizierungszeit %d, %s%s %s für %s%s%s" -+ -+#: ../../src/kdc/kdc_log.c:166 -+#, c-format -+msgid "... PROTOCOL-TRANSITION s4u-client=%s" -+msgstr "… PROTOKOLLÜBERGANG s4u-client=%s" -+ -+#: ../../src/kdc/kdc_log.c:170 -+#, c-format -+msgid "... CONSTRAINED-DELEGATION s4u-client=%s" -+msgstr "… EINHESCHRÄNKTE DELEGIERUNG s4u-client=%s" -+ -+#: ../../src/kdc/kdc_log.c:174 -+#, c-format -+msgid "TGS_REQ %s: %s: authtime %d, %s for %s, 2nd tkt client %s" -+msgstr "TGS_REQ %s: %s: Authentifizierungszeit %d, %s für %s, 2. TKT-Client %s" -+ -+#: ../../src/kdc/kdc_log.c:208 -+#, c-format -+msgid "bad realm transit path from '%s' to '%s' via '%.*s%s'" -+msgstr "falscher Realm-Übergangspfad von »%s« zu »%s« über »%.*s%s«" -+ -+#: ../../src/kdc/kdc_log.c:214 -+#, c-format -+msgid "unexpected error checking transit from '%s' to '%s' via '%.*s%s': %s" -+msgstr "" -+"unerwarteter Fehler bei der Prüfung des Übergangs von »%s« zu »%s« über »%.*s" -+"%s«: %s" -+ -+#: ../../src/kdc/kdc_log.c:232 -+msgid "TGS_REQ: issuing alternate TGT" -+msgstr "TGS_REQ: alternativer TGT wird erstellt" -+ -+#: ../../src/kdc/kdc_log.c:235 -+#, c-format -+msgid "TGS_REQ: issuing TGT %s" -+msgstr "TGS_REQ: TGT %s wird erstellt" -+ -+#: ../../src/kdc/kdc_preauth.c:328 -+#, c-format -+msgid "preauth %s failed to initialize: %s" -+msgstr "Initialisieren von »preauth« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_preauth.c:339 -+#, c-format -+msgid "preauth %s failed to setup loop: %s" -+msgstr "Einrichten der Schleife von »preauth« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_preauth.c:760 -+#, c-format -+msgid "%spreauth required but hint list is empty" -+msgstr "%spreauth benötigt, aber Hinweisliste ist leer" -+ -+#: ../../src/kdc/kdc_preauth_ec.c:75 -+msgid "Encrypted Challenge used outside of FAST tunnel" -+msgstr "verschlüsselte Aufforderung wurde außerhalb des FAST-Tunnels verwendet" -+ -+#: ../../src/kdc/kdc_preauth_ec.c:110 -+msgid "Incorrect password in encrypted challenge" -+msgstr "falsches Passwort in verschlüsselter Aufforderung" -+ -+#: ../../src/kdc/kdc_util.c:236 -+msgid "TGS_REQ: SESSION KEY or MUTUAL" -+msgstr "TGS_REQ: SITZUNGSSCHLÜSSEL oder BEIDERSEITIG" -+ -+#: ../../src/kdc/kdc_util.c:314 -+msgid "PROCESS_TGS: failed lineage check" -+msgstr "PROCESS_TGS: Abstammungsprüfung fehlgeschlagen" -+ -+#: ../../src/kdc/kdc_util.c:468 -+#, c-format -+msgid "TGS_REQ: UNKNOWN SERVER: server='%s'" -+msgstr "TGS_REQ: UNBEKANNTER SERVER: Server=»%s«" -+ -+#: ../../src/kdc/main.c:231 -+#, c-format -+msgid "while getting context for realm %s" -+msgstr "beim Holen des Kontextes für Realm %s" -+ -+#: ../../src/kdc/main.c:329 -+#, c-format -+msgid "while setting default realm to %s" -+msgstr "beim Setzen des Standard-Realms auf %s" -+ -+#: ../../src/kdc/main.c:337 -+#, c-format -+msgid "while initializing database for realm %s" -+msgstr "beim Initialisieren der Datenbank für Realm %s" -+ -+#: ../../src/kdc/main.c:346 -+#, c-format -+msgid "while setting up master key name %s for realm %s" -+msgstr "beim Einrichten des Hauptschlüsselnamens %s für Realm %s" -+ -+#: ../../src/kdc/main.c:359 -+#, c-format -+msgid "while fetching master key %s for realm %s" -+msgstr "beim Abholen des Hauptschlüssels %s für Realm %s" -+ -+#: ../../src/kdc/main.c:367 -+#, c-format -+msgid "while fetching master keys list for realm %s" -+msgstr "beim Abholen der Hauptschlüsselliste für Realm %s" -+ -+#: ../../src/kdc/main.c:376 -+#, c-format -+msgid "while resolving kdb keytab for realm %s" -+msgstr "beim Ermitteln der KDB-Schlüsseltabelle für Realm %s" -+ -+#: ../../src/kdc/main.c:385 -+#, c-format -+msgid "while building TGS name for realm %s" -+msgstr "beim Bilden des TGS-Namens für Realm %s" -+ -+#: ../../src/kdc/main.c:503 -+#, c-format -+msgid "creating %d worker processes" -+msgstr "%d Arbeitsprozesse werden erzeugt" -+ -+#: ../../src/kdc/main.c:513 -+msgid "Unable to reinitialize main loop" -+msgstr "Hauptschleife konnte nicht neu initialisiert werden" -+ -+#: ../../src/kdc/main.c:518 -+#, c-format -+msgid "Unable to initialize signal handlers in pid %d" -+msgstr "" -+"Signalbehandlungsprogramme in PID %d konnten nicht initialisiert werden" -+ -+#: ../../src/kdc/main.c:548 -+#, c-format -+msgid "worker %ld exited with status %d" -+msgstr "Arbeitsprozess %ld endete mit Status %d" -+ -+#: ../../src/kdc/main.c:572 -+#, c-format -+msgid "signal %d received in supervisor" -+msgstr "Überwachungsprogramm empfing Signal %d" -+ -+#: ../../src/kdc/main.c:591 -+#, c-format -+msgid "" -+"usage: %s [-x db_args]* [-d dbpathname] [-r dbrealmname]\n" -+"\t\t[-R replaycachename] [-m] [-k masterenctype]\n" -+"\t\t[-M masterkeyname] [-p port] [-P pid_file]\n" -+"\t\t[-n] [-w numworkers] [/]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - Any number of database specific arguments.\n" -+"\t\t\tLook at each database module documentation for \t\t\tsupported " -+"arguments\n" -+msgstr "" -+"Aufruf: %s [-x Datenbankargumente]* [-d Datenbankpfadname]\n" -+"\t\t[-r Datenbank-Realm-Name] [-m] [-k Hauptverschlüsselungstyp]\n" -+"\t\t[-M Hauptschlüsselname] [-p Port] [-P PID-Datei]\n" -+"\t\t[-n] [-w Arbeitsprozessanzahl] [/]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kdc/main.c:653 ../../src/kdc/main.c:660 ../../src/kdc/main.c:774 -+#, c-format -+msgid " KDC cannot initialize. Not enough memory\n" -+msgstr "KDC kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:679 ../../src/kdc/main.c:722 ../../src/kdc/main.c:733 -+#, c-format -+msgid "%s: KDC cannot initialize. Not enough memory\n" -+msgstr "%s: KDC kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:699 ../../src/kdc/main.c:816 -+#, c-format -+msgid "%s: cannot initialize realm %s - see log file for details\n" -+msgstr "" -+"%s: Realm %s kann nicht initialisiert werden - Einzelheiten finden Sie in " -+"der Protokolldatei\n" -+ -+#: ../../src/kdc/main.c:710 -+#, c-format -+msgid "%s: cannot initialize realm %s. Not enough memory\n" -+msgstr "" -+"%s: Realm %s kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:761 -+#, c-format -+msgid "invalid enctype %s" -+msgstr "ungültiger Verschlüsselungstyp %s" -+ -+#: ../../src/kdc/main.c:804 -+msgid "while attempting to retrieve default realm" -+msgstr "beim Versuch, den Standard-Realm abzufragen" -+ -+#: ../../src/kdc/main.c:806 -+#, c-format -+msgid "%s: %s, attempting to retrieve default realm\n" -+msgstr "%s: %s, es wird versucht, den Standard-Realm abzufragen\n" -+ -+#: ../../src/kdc/main.c:912 -+#, c-format -+msgid "%s: cannot get memory for realm list\n" -+msgstr "%s: Speicher für die Realm-Liste kann nicht erlangt werden\n" -+ -+# http://www.oreilly.de/german/freebooks/linuxdrive2ger/getcache.html -+#: ../../src/kdc/main.c:947 -+msgid "while initializing lookaside cache" -+msgstr "beim Initialisieren des Lookaside-Zwischenspeichers" -+ -+#: ../../src/kdc/main.c:955 -+msgid "while creating main loop" -+msgstr "beim Erzeugen der Hauptschleife" -+ -+# SAM=Security Accounts Manager -+#: ../../src/kdc/main.c:965 -+msgid "while initializing SAM" -+msgstr "beim Initialisieren des SAMs" -+ -+#: ../../src/kdc/main.c:1011 -+msgid "while initializing routing socket" -+msgstr "beim Initialisieren des Routing-Sockets" -+ -+#: ../../src/kdc/main.c:1017 -+msgid "while initializing signal handlers" -+msgstr "beim Initialisieren des Signalbehandlungsprogramms" -+ -+#: ../../src/kdc/main.c:1024 -+msgid "while initializing network" -+msgstr "beim Initialisieren des Netzwerks" -+ -+#: ../../src/kdc/main.c:1029 -+msgid "while detaching from tty" -+msgstr "beim Lösen vom Terminal" -+ -+#: ../../src/kdc/main.c:1036 -+msgid "while creating PID file" -+msgstr "beim Erstellen der PID-Datei" -+ -+#: ../../src/kdc/main.c:1045 -+msgid "creating worker processes" -+msgstr "Arbeitsprozesse werden erzeugt" -+ -+#: ../../src/kdc/main.c:1055 -+msgid "while loading audit plugin module(s)" -+msgstr "beim Laden des/der Auditerweiterungsmoduls/Auditerweiterungsmodule" -+ -+#: ../../src/kdc/main.c:1059 -+msgid "commencing operation" -+msgstr "Aktion wird begonnen" -+ -+#: ../../src/kdc/main.c:1067 -+msgid "shutting down" -+msgstr "wird heruntergefahren" -+ -+#: ../../src/lib/apputils/net-server.c:258 -+msgid "Got signal to request exit" -+msgstr "Signal zur Anfrage des Beendens empfangen" -+ -+#: ../../src/lib/apputils/net-server.c:272 -+msgid "Got signal to reset" -+msgstr "Signal zum Zurücksetzen empfangen" -+ -+#: ../../src/lib/apputils/net-server.c:429 -+#, c-format -+msgid "closing down fd %d" -+msgstr "Dateideskriptor %d wird geschlossen" -+ -+#: ../../src/lib/apputils/net-server.c:443 -+#, c-format -+msgid "descriptor %d closed but still in svc_fdset" -+msgstr "Deskriptor %d geschlossen, aber immer noch in »svc_fdset«" -+ -+#: ../../src/lib/apputils/net-server.c:469 -+msgid "cannot create io event" -+msgstr "E/A-Ereignis kann nicht erzeugt werden" -+ -+#: ../../src/lib/apputils/net-server.c:475 -+msgid "cannot save event" -+msgstr "Ereignis kann nicht gesichert werden" -+ -+#: ../../src/lib/apputils/net-server.c:495 -+#, c-format -+msgid "file descriptor number %d too high" -+msgstr "Dateideskriptornummer %d zu hoch" -+ -+#: ../../src/lib/apputils/net-server.c:503 -+msgid "cannot allocate storage for connection info" -+msgstr "Speicher für Verbindungsinformation kann nicht reserviert werden" -+ -+#: ../../src/lib/apputils/net-server.c:562 -+#, c-format -+msgid "Cannot create TCP server socket on %s" -+msgstr "Auf %s kann kein TCP-Server-Socket erstellt werden." -+ -+#: ../../src/lib/apputils/net-server.c:571 -+#, c-format -+msgid "TCP socket fd number %d (for %s) too high" -+msgstr "TCP-Socket-Deskriptornummer %d (für %s) zu hoch" -+ -+#: ../../src/lib/apputils/net-server.c:579 -+#, c-format -+msgid "Cannot enable SO_REUSEADDR on fd %d" -+msgstr "SO_REUSEADDR kann nicht für Dateideskriptor %d aktiviert werden" -+ -+#: ../../src/lib/apputils/net-server.c:586 -+#, c-format -+msgid "setsockopt(%d,IPV6_V6ONLY,1) failed" -+msgstr "setsockopt(%d,IPV6_V6ONLY,1) fehlgeschlagen" -+ -+#: ../../src/lib/apputils/net-server.c:588 -+#, c-format -+msgid "setsockopt(%d,IPV6_V6ONLY,1) worked" -+msgstr "setsockopt(%d,IPV6_V6ONLY,1) funktioniert" -+ -+#: ../../src/lib/apputils/net-server.c:591 -+msgid "no IPV6_V6ONLY socket option support" -+msgstr "keine Socket-Option für IPV6_V6ONLY unterstützt" -+ -+#: ../../src/lib/apputils/net-server.c:597 -+#, c-format -+msgid "Cannot bind server socket on %s" -+msgstr "Server-Socket kann nicht an %s gebunden werden" -+ -+#: ../../src/lib/apputils/net-server.c:624 -+#, c-format -+msgid "Cannot create RPC service: %s; continuing" -+msgstr "RPC-Dienst kann nicht erstellt werden: %s; es wird fortgefahren" -+ -+#: ../../src/lib/apputils/net-server.c:633 -+#, c-format -+msgid "Cannot register RPC service: %s; continuing" -+msgstr "RPC-Dienst kann nicht registriert werden: %s; es wird fortgefahren" -+ -+#: ../../src/lib/apputils/net-server.c:682 -+#, c-format -+msgid "Cannot listen on TCP server socket on %s" -+msgstr "" -+"Auf dem TCP-Server-Socket kann nicht auf eine Verbindung gewartet werden auf " -+"%s." -+ -+#: ../../src/lib/apputils/net-server.c:688 -+#, c-format -+msgid "cannot set listening tcp socket on %s non-blocking" -+msgstr "" -+"Das auf eine Verbindung wartende TCP-Socket kann nicht auf nicht-" -+"blockierendes %s gesetzt werden." -+ -+#: ../../src/lib/apputils/net-server.c:695 -+#, c-format -+msgid "disabling SO_LINGER on TCP socket on %s" -+msgstr "SO_LINGER auf dem TCP-Socket auf %s wird deaktiviert" -+ -+#: ../../src/lib/apputils/net-server.c:743 -+#: ../../src/lib/apputils/net-server.c:752 -+#, c-format -+msgid "listening on fd %d: tcp %s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: TCP %s" -+ -+#: ../../src/lib/apputils/net-server.c:757 -+msgid "assuming IPv6 socket accepts IPv4" -+msgstr "es wird davon ausgegangen, dass das IPv6-Socket IPv4 akzeptiert" -+ -+#: ../../src/lib/apputils/net-server.c:791 -+#: ../../src/lib/apputils/net-server.c:804 -+#, c-format -+msgid "listening on fd %d: rpc %s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: RPC %s" -+ -+#: ../../src/lib/apputils/net-server.c:883 -+#, c-format -+msgid "Cannot request packet info for udp socket address %s port %d" -+msgstr "" -+"Paketinformation für UDP-Socket-Adresse %s, Port %d, kann nicht abgefragt " -+"werden" -+ -+#: ../../src/lib/apputils/net-server.c:889 -+#, c-format -+msgid "listening on fd %d: udp %s%s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: UDP %s%s" -+ -+#: ../../src/lib/apputils/net-server.c:918 -+msgid "Failed to reconfigure network, exiting" -+msgstr "Neukonfiguration des Netzwerks fehlgeschlagen, wird beendet" -+ -+#: ../../src/lib/apputils/net-server.c:979 -+#, c-format -+msgid "" -+"unhandled routing message type %d, will reconfigure just for the fun of it" -+msgstr "" -+"nicht behandelter Routing-Meldungstyp %d, es wird es nur zum Spaß neu " -+"konfiguriert" -+ -+#: ../../src/lib/apputils/net-server.c:1013 -+#, c-format -+msgid "short read (%d/%d) from routing socket" -+msgstr "ungenügende Daten (%d/%d) vom Routing-Socket gelesen" -+ -+#: ../../src/lib/apputils/net-server.c:1023 -+#, c-format -+msgid "read %d from routing socket but msglen is %d" -+msgstr "%d vom Routing-Socket gelesen, Nachrichtenlänge ist jedoch %d" -+ -+#: ../../src/lib/apputils/net-server.c:1055 -+#, c-format -+msgid "couldn't set up routing socket: %s" -+msgstr "Routing-Socket konnte nicht eingerichtet werden: %s" -+ -+#: ../../src/lib/apputils/net-server.c:1058 -+#, c-format -+msgid "routing socket is fd %d" -+msgstr "Das Routing-Socket hat den Dateideskriptor %d." -+ -+#: ../../src/lib/apputils/net-server.c:1084 -+msgid "setting up network..." -+msgstr "Netzwerk wird eingerichtet …" -+ -+#: ../../src/lib/apputils/net-server.c:1101 -+#, c-format -+msgid "set up %d sockets" -+msgstr "%d Sockets werden eingerichtet" -+ -+#: ../../src/lib/apputils/net-server.c:1103 -+msgid "no sockets set up?" -+msgstr "keine Sockets eingerichtet?" -+ -+#: ../../src/lib/apputils/net-server.c:1351 -+#: ../../src/lib/apputils/net-server.c:1405 -+msgid "while dispatching (udp)" -+msgstr "beim Versenden (UDP)" -+ -+#: ../../src/lib/apputils/net-server.c:1380 -+#, c-format -+msgid "while sending reply to %s/%s from %s" -+msgstr "beim Senden der Antwort zu %s/%s von %s" -+ -+#: ../../src/lib/apputils/net-server.c:1385 -+#, c-format -+msgid "short reply write %d vs %d\n" -+msgstr "ungenügende Ausgabe der Antwort %d gegenüber %d\n" -+ -+#: ../../src/lib/apputils/net-server.c:1430 -+msgid "while receiving from network" -+msgstr "beim Empfangen vom Netzwerk" -+ -+#: ../../src/lib/apputils/net-server.c:1446 -+#, c-format -+msgid "pktinfo says local addr is %s" -+msgstr "Pktinfo sagt, die lokale Adresse sei %s" -+ -+#: ../../src/lib/apputils/net-server.c:1479 -+msgid "too many connections" -+msgstr "zu viele Verbindungen" -+ -+#: ../../src/lib/apputils/net-server.c:1502 -+#, c-format -+msgid "dropping %s fd %d from %s" -+msgstr "%s Dateideskriptor %d von %s wird verworfen" -+ -+#: ../../src/lib/apputils/net-server.c:1580 -+#, c-format -+msgid "allocating buffer for new TCP session from %s" -+msgstr "Puffer für neue TCP-Sitzung von %s wird reserviert" -+ -+#: ../../src/lib/apputils/net-server.c:1610 -+msgid "while dispatching (tcp)" -+msgstr "beim Versenden (TCP)" -+ -+#: ../../src/lib/apputils/net-server.c:1642 -+msgid "error allocating tcp dispatch private!" -+msgstr "Fehler beim Reservieren zum nicht öffentlichen TCP-Versand!" -+ -+#: ../../src/lib/apputils/net-server.c:1689 -+#, c-format -+msgid "TCP client %s wants %lu bytes, cap is %lu" -+msgstr "TCP-Client %s will %lu Byte, Cap ist %lu" -+ -+#: ../../src/lib/apputils/net-server.c:1697 -+#, c-format -+msgid "error constructing KRB_ERR_FIELD_TOOLONG error! %s" -+msgstr "Fehler beim Erzeugen des KRB_ERR_FIELD_TOOLONG-Fehlers! %s" -+ -+#: ../../src/lib/apputils/net-server.c:1876 -+#, c-format -+msgid "accepted RPC connection on socket %d from %s" -+msgstr "akzeptierte PRC-Verbindung auf Socket %d von %s" -+ -+# pseudo random function -+#: ../../src/lib/crypto/krb/cf2.c:114 -+#, c-format -+msgid "Enctype %d has no PRF" -+msgstr "Verschlüsselungstyp %d hat keine PRF" -+ -+#: ../../src/lib/crypto/krb/prng_fortuna.c:428 -+msgid "Random number generator could not be seeded" -+msgstr "Zufallszahlengenerator konnte kein Startwert zugewiesen werden" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:43 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:165 -+msgid "A required input parameter could not be read" -+msgstr "Ein benötigter Eingabeparameter konnte nicht gelesen werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:44 -+msgid "A required input parameter could not be written" -+msgstr "Ein benötigter Eingabeparameter konnte nicht geschrieben werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:45 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:175 -+msgid "A parameter was malformed" -+msgstr "Ein Parameter hatte eine falsche Form" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:48 -+msgid "calling error" -+msgstr "Aufruffehler" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:59 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:195 -+msgid "An unsupported mechanism was requested" -+msgstr "Ein nicht unterstützter Mechanismus wurde angefordert." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:60 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:199 -+msgid "An invalid name was supplied" -+msgstr "Ein ungültiger Name wurde übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:61 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:203 -+msgid "A supplied name was of an unsupported type" -+msgstr "Ein übergebener Name hatte einen nicht unterstützten Typ." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:62 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:208 -+msgid "Incorrect channel bindings were supplied" -+msgstr "Falsche Kanalbindungen wurden übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:63 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:179 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:274 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:334 -+msgid "An invalid status code was supplied" -+msgstr "Ein ungültiger Statuscode wurde übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:64 -+msgid "A token had an invalid signature" -+msgstr "Ein Merkmal hatte eine ungültige Signatur." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:65 -+msgid "No credentials were supplied" -+msgstr "Es wurden keine Anmeldedaten übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:66 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:223 -+msgid "No context has been established" -+msgstr "Es wurde keine Kontext etabliert." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:67 -+msgid "A token was invalid" -+msgstr "Ein Merkmal war ungültig." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:68 -+msgid "A credential was invalid" -+msgstr "Eine der Anmeldedaten war ungültig." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:69 -+msgid "The referenced credentials have expired" -+msgstr "Die referenzierten Anmeldedaten sind abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:70 -+msgid "The context has expired" -+msgstr "Der Kontext ist abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:71 -+msgid "Miscellaneous failure" -+msgstr "sonstiger Fehlschlag" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:72 -+msgid "The quality-of-protection requested could not be provided" -+msgstr "" -+"Die angeforderte Qualität des Schutzes konnte nicht bereitgestellt werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:73 -+msgid "The operation is forbidden by the local security policy" -+msgstr "Die Aktion wird durch die lokale Sicherheitsrichtinie verboten." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:74 -+msgid "The operation or option is not available" -+msgstr "Die Aktion oder Option ist nicht verfügbar." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:77 -+msgid "routine error" -+msgstr "Fehler in einer Routine" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:89 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:311 -+msgid "The routine must be called again to complete its function" -+msgstr "" -+"Die Routine muss erneut aufgerufen werden, um ihre Funktion zu " -+"vervollständigen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:90 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:316 -+msgid "The token was a duplicate of an earlier token" -+msgstr "Das Merkmal war ein Zweitexemplar eines früheren Merkmals." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:91 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:321 -+msgid "The token's validity period has expired" -+msgstr "Die Gültigkeitsperiode des Merkmals ist abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:92 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:325 -+msgid "A later token has already been processed" -+msgstr "Es wurde bereits ein neueres Merkmal verarbeitet." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:95 -+msgid "supplementary info code" -+msgstr "zusätzlicher Informationscode" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:106 -+#: ../lib/krb5/error_tables/krb5_err.c:23 -+msgid "No error" -+msgstr "kein Fehler" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:107 -+#, c-format -+msgid "Unknown %s (field = %d)" -+msgstr "%s unbekannt (Feld = %d)" -+ -+#: ../../src/lib/gssapi/krb5/acquire_cred.c:165 -+#, c-format -+msgid "No key table entry found matching %s" -+msgstr "Es wurde kein zu %s passender Schlüsseltabelleneintrag gefunden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:161 -+msgid "The routine completed successfully" -+msgstr "Die Routine wurde erfolgreich abgeschlossen" -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:170 -+msgid "A required output parameter could not be written" -+msgstr "Ein erforderlicher Ausgabeparameter konnte nicht geschrieben werden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:212 -+msgid "A token had an invalid Message Integrity Check (MIC)" -+msgstr "" -+"Ein Merkmal hatte eine ungültige Meldungsintegritätsprüfung (Message " -+"Integrity Check/MIC)." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:217 -+msgid "" -+"No credentials were supplied, or the credentials were unavailable or " -+"inaccessible" -+msgstr "" -+"Es wurden keine Anmeldedaten übergeben oder die Anmeldedaten waren nicht " -+"verfügbar bzw. ein Zugriff darauf nicht möglich." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:227 -+msgid "Invalid token was supplied" -+msgstr "Es wurde ein ungültiges Token übergeben." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:231 -+msgid "Invalid credential was supplied" -+msgstr "ungültige Anmeldedaten wurden übergeben" -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:235 -+msgid "The referenced credential has expired" -+msgstr "Die referenzierten Anmeldedaten sind abgelaufen." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:239 -+msgid "The referenced context has expired" -+msgstr "Der referenzierte Kontext ist abgelaufen." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:243 -+msgid "Unspecified GSS failure. Minor code may provide more information" -+msgstr "" -+"nicht spezifizierter GSS-Fehlschlag. Möglicherweise stellt der " -+"untergeordnete Code weitere Informationen bereit." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:248 -+msgid "The quality-of-protection (QOP) requested could not be provided" -+msgstr "" -+"Die Qualität des Schutzes (quality-of-protection/QOP) konnte nicht " -+"bereitgestellt werden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:253 -+msgid "The operation is forbidden by local security policy" -+msgstr "Die Aktion wird durch die lokale Sicherheitsrichtinie verboten." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:258 -+msgid "The operation or option is not available or unsupported" -+msgstr "" -+"Die Aktion oder Option ist nicht verfügbar oder wird nicht unterstützt." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:263 -+msgid "The requested credential element already exists" -+msgstr "Das angeforderte Anmeldedatenelement existiert bereits." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:268 -+msgid "The provided name was not mechanism specific (MN)" -+msgstr "Der bereitgestellte Name war nicht mechanismusspezifisch (MN)." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:329 -+msgid "An expected per-message token was not received" -+msgstr "Ein erwartetes nachrichtenspezifisches Token wurde nicht empfangen." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1860 -+msgid "SPNEGO cannot find mechanisms to negotiate" -+msgstr "SPNEGO kann keine Mechanismen zum Aushandeln finden." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1865 -+msgid "SPNEGO failed to acquire creds" -+msgstr "SPNEGO ist beim Beschaffen von Anmeldedaten gescheitert" -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1870 -+msgid "SPNEGO acceptor did not select a mechanism" -+msgstr "SPNEGO-Abnehmer hat keinen Mechanismus ausgewählt" -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1875 -+msgid "SPNEGO failed to negotiate a mechanism" -+msgstr "SPNEGO ist beim Aushandeln eines Mechanismus gescheitert." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1880 -+msgid "SPNEGO acceptor did not return a valid token" -+msgstr "SPNEGO-Abnehmer hat kein gültiges Token zurückgeliefert" -+ -+#: ../../src/lib/kadm5/alt_prof.c:854 -+#, c-format -+msgid "Cannot resolve address of admin server \"%s\" for realm \"%s\"" -+msgstr "" -+"Adresse des Admin-Servers »%s« für Realm »%s« kann nicht ermittelt werden" -+ -+#: ../../src/lib/kadm5/logger.c:56 -+#, c-format -+msgid "%s: cannot parse <%s>\n" -+msgstr "%s: <%s> kann nicht ausgewertet werden\n" -+ -+#: ../../src/lib/kadm5/logger.c:57 -+#, c-format -+msgid "%s: warning - logging entry syntax error\n" -+msgstr "%s: Warnung – Syntaxfehler bei Protokolleintrag\n" -+ -+#: ../../src/lib/kadm5/logger.c:58 -+#, c-format -+msgid "%s: error writing to %s\n" -+msgstr "%s: Fehler beim Schreiben auf %s\n" -+ -+#: ../../src/lib/kadm5/logger.c:59 -+#, c-format -+msgid "%s: error writing to %s device\n" -+msgstr "%s: Fehler beim Schreiben auf Gerät %s\n" -+ -+#: ../../src/lib/kadm5/logger.c:61 -+msgid "EMERGENCY" -+msgstr "NOTFALL" -+ -+#: ../../src/lib/kadm5/logger.c:62 -+msgid "ALERT" -+msgstr "ALARM" -+ -+#: ../../src/lib/kadm5/logger.c:63 -+msgid "CRITICAL" -+msgstr "KRITISCH" -+ -+#: ../../src/lib/kadm5/logger.c:64 -+msgid "Error" -+msgstr "Fehler" -+ -+#: ../../src/lib/kadm5/logger.c:65 -+msgid "Warning" -+msgstr "Warnung" -+ -+#: ../../src/lib/kadm5/logger.c:66 -+msgid "Notice" -+msgstr "Hinweis" -+ -+#: ../../src/lib/kadm5/logger.c:67 -+msgid "info" -+msgstr "Information" -+ -+#: ../../src/lib/kadm5/logger.c:68 -+msgid "debug" -+msgstr "Fehlersuchmeldung" -+ -+#: ../../src/lib/kadm5/logger.c:967 -+#, c-format -+msgid "Couldn't open log file %s: %s\n" -+msgstr "Protokolldatei %s konnte nicht geöffnet werden: %s\n" -+ -+#: ../../src/lib/kadm5/srv/kadm5_hook.c:119 -+#, c-format -+msgid "kadm5_hook %s failed postcommit %s: %s" -+msgstr "»kadm5_hook« %s ist beim Nach-Commit %s gescheitert: %s" -+ -+#: ../../src/lib/kadm5/srv/pwqual_dict.c:106 -+msgid "No dictionary file specified, continuing without one." -+msgstr "keine Wörterbuchdatei angegeben, es wird ohne fortgefahren" -+ -+#: ../../src/lib/kadm5/srv/pwqual_dict.c:113 -+#, c-format -+msgid "WARNING! Cannot find dictionary file %s, continuing without one." -+msgstr "" -+"WARNUNG! Wörterbuchdatei %s kann nicht gefunden werden, es wird ohne " -+"fortgefahren" -+ -+#: ../../src/lib/kadm5/srv/pwqual_empty.c:42 -+msgid "Empty passwords are not allowed" -+msgstr "Leere Passwörter sind nicht erlaubt." -+ -+#: ../../src/lib/kadm5/srv/pwqual_hesiod.c:114 -+msgid "Password may not match user information." -+msgstr "Das Passwort darf keinen Anwenderdaten entsprechen." -+ -+#: ../../src/lib/kadm5/srv/pwqual_princ.c:54 -+msgid "Password may not match principal name" -+msgstr "Das Passwort darf nicht mit dem Principal-Namen übereinstimmen." -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:89 -+#, c-format -+msgid "%s: line %d too long, truncated" -+msgstr "%s: Zeile %d zu lang, wurde gekürzt" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:90 -+#, c-format -+msgid "Unrecognized ACL operation '%c' in %s" -+msgstr "unbekannte ACL-Aktion »%c« in %s" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:92 -+#, c-format -+msgid "%s: syntax error at line %d <%10s...>" -+msgstr "%s: Syntaxfehler in Zeile %d <%10s …>" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:94 -+#, c-format -+msgid "%s while opening ACL file %s" -+msgstr "%s beim Öffnen der ACL-Datei %s" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:353 -+#, c-format -+msgid "%s: invalid restrictions: %s" -+msgstr "%s: ungültige Beschränkung: %s" -+ -+#: ../../src/lib/kadm5/srv/server_kdb.c:192 -+msgid "History entry contains no key data" -+msgstr "Chronikeintrag enthält keine Schlüsseldaten" -+ -+#: ../../src/lib/kadm5/srv/server_misc.c:128 -+#, c-format -+msgid "password quality module %s rejected password for %s: %s" -+msgstr "" -+"Das Modul %s für Passwortqualität hat das Passwort für %s abgelehnt: %s" -+ -+#: ../../src/lib/kadm5/str_conv.c:80 -+msgid "Not Postdateable" -+msgstr "nicht vordatierbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:81 -+msgid "Not Forwardable" -+msgstr "nicht weiterleitbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:82 -+msgid "No TGT-based requests" -+msgstr "keine TGT-basierten Anfragen" -+ -+#: ../../src/lib/kadm5/str_conv.c:83 -+msgid "Not renewable" -+msgstr "nicht erneuerbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:84 -+msgid "Not proxiable" -+msgstr "Proxy nicht nutzbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:85 -+msgid "No DUP_SKEY requests" -+msgstr "keine DUP_SKEY-Anfragen" -+ -+#: ../../src/lib/kadm5/str_conv.c:86 -+msgid "All Tickets Disallowed" -+msgstr "keine Tickets erlaubt" -+ -+#: ../../src/lib/kadm5/str_conv.c:87 -+msgid "Preauthentication required" -+msgstr "Vorauthentifizierung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:88 -+msgid "HW authentication required" -+msgstr "HW-Authentifizierung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:89 -+msgid "OK as Delegate" -+msgstr "OK als Vertreter" -+ -+#: ../../src/lib/kadm5/str_conv.c:90 -+msgid "Password Change required" -+msgstr "Passwortänderung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:91 -+msgid "Service Disabled" -+msgstr "Dienst deaktiviert" -+ -+#: ../../src/lib/kadm5/str_conv.c:92 -+msgid "Password Changing Service" -+msgstr "Passwortänderungsdienst" -+ -+#: ../../src/lib/kadm5/str_conv.c:93 -+msgid "RSA-MD5 supported" -+msgstr "RSA-MD5 unterstützt" -+ -+#: ../../src/lib/kadm5/str_conv.c:94 -+msgid "Protocol transition with delegation allowed" -+msgstr "Protokollübergang mit Vertretung erlaubt" -+ -+#: ../../src/lib/kadm5/str_conv.c:95 -+msgid "No authorization data required" -+msgstr "keine Autorisierungsdaten erforderlich" -+ -+#: ../../src/lib/kdb/kdb5.c:219 -+msgid "No default realm set; cannot initialize KDB" -+msgstr "kein Standard-Realm gesetzt; KDB kann nicht initialisiert werden" -+ -+#: ../../src/lib/kdb/kdb5.c:324 ../../src/lib/kdb/kdb5.c:406 -+#, c-format -+msgid "Unable to find requested database type: %s" -+msgstr "angeforderter Datenbanktyp kann nicht gefunden werden. %s" -+ -+#: ../../src/lib/kdb/kdb5.c:416 -+#, c-format -+msgid "plugin symbol 'kdb_function_table' lookup failed: %s" -+msgstr "" -+"Nachschlagen des Erweiterungssymbols »kdb_function_table« fehlgeschlagen: %s" -+ -+#: ../../src/lib/kdb/kdb5.c:426 -+#, c-format -+msgid "" -+"Unable to load requested database module '%s': plugin symbol " -+"'kdb_function_table' not found" -+msgstr "" -+"angefordertes Datenbankmodul »%s« kann nicht geladen werden: " -+"Erweiterungssymbol »kdb_function_table« nicht gefunden" -+ -+#: ../../src/lib/kdb/kdb5.c:1650 -+#, c-format -+msgid "Illegal version number for KRB5_TL_MKEY_AUX %d\n" -+msgstr "Ungültige Versionsnummer für KRB5_TL_MKEY_AUX %d\n" -+ -+#: ../../src/lib/kdb/kdb5.c:1819 -+#, c-format -+msgid "Illegal version number for KRB5_TL_ACTKVNO %d\n" -+msgstr "Ungültige Versionsnummer für KRB5_TL_ACTKVNO %d\n" -+ -+#: ../../src/lib/kdb/kdb_default.c:164 -+#, c-format -+msgid "keyfile (%s) is not a regular file: %s" -+msgstr "Schlüsseldatei (%s) ist keine normale Datei: %s" -+ -+#: ../../src/lib/kdb/kdb_default.c:177 -+msgid "Could not create temp keytab file name." -+msgstr "Temporärer Schlüsseltabellendateiname konnte nicht erstellt werden." -+ -+#: ../../src/lib/kdb/kdb_default.c:202 -+#, c-format -+msgid "Temporary stash file already exists: %s." -+msgstr "Temporäre Ablagedatei existiert bereits: %s." -+ -+#: ../../src/lib/kdb/kdb_default.c:230 -+#, c-format -+msgid "rename of temporary keyfile (%s) to (%s) failed: %s" -+msgstr "" -+"Umbenennen von temporärer Schlüsseldatei (%s) in (%s) fehlgeschlagen: %s" -+ -+#: ../../src/lib/kdb/kdb_default.c:419 -+#, c-format -+msgid "Can not fetch master key (error: %s)." -+msgstr "Hauptschlüssel kann nicht abgeholt werden (Fehler: %s)" -+ -+#: ../../src/lib/kdb/kdb_default.c:482 -+msgid "Unable to decrypt latest master key with the provided master key\n" -+msgstr "" -+"Letzter Hauptschlüssel kann nicht mit dem bereitgestellten Hauptschlüssel " -+"entschlüsselt werden.\n" -+ -+#: ../../src/lib/kdb/kdb_log.c:83 -+msgid "could not sync ulog header to disk" -+msgstr "Ulog-Kopfzeilen konnten nicht auf die Platte synchronisiert werden" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:122 -+#, c-format -+msgid "Subsidiary cache path %s has no parent directory" -+msgstr "" -+"Ergänzender Zwischenspeicherpfad %s hat kein übergeordnetes Verzeichnis." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:128 -+#, c-format -+msgid "Subsidiary cache path %s filename does not begin with \"tkt\"" -+msgstr "" -+"Dateiname des ergänzenden Zwischenspeicherpfads %s beginnt nicht mit »tkt«" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:169 -+#, c-format -+msgid "%s contains invalid filename" -+msgstr "%s enthält einen ungültigen Dateinamen." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:229 -+#, c-format -+msgid "Credential cache directory %s does not exist" -+msgstr "Anmeldedatenzwischenspeicherverzeichnis %s existiert nicht." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:235 -+#, c-format -+msgid "Credential cache directory %s exists but is not a directory" -+msgstr "" -+"Anmeldedatenzwischenspeicherverzeichnis %s existiert, ist jedoch kein " -+"Verzeichnis" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:400 -+msgid "" -+"Can't create new subsidiary cache because default cache is not a directory " -+"collection" -+msgstr "" -+"Der neue ergänzende Zwischenspeicher kann nicht erstellt werden, da der " -+"Standardzwischenspeicher keine Ansammlung von Verzeichnissen ist." -+ -+#: ../../src/lib/krb5/ccache/cc_file.c:569 -+#, c-format -+msgid "Credentials cache file '%s' not found" -+msgstr "Anmeldedatenzwischenspeicherdatei »%s« nicht gefunden" -+ -+#: ../../src/lib/krb5/ccache/cc_file.c:1575 -+#, c-format -+msgid "Credentials cache I/O operation failed (%s)" -+msgstr "Anmeldedatenzwischenspeicher-E/A-Aktion fehlgeschlagen (%s)" -+ -+#: ../../src/lib/krb5/ccache/cc_keyring.c:1151 -+msgid "" -+"Can't create new subsidiary cache because default cache is already a " -+"subsidiary" -+msgstr "" -+"Der neue ergänzende Zwischenspeicher kann nicht erstellt werden, da der " -+"Standardzwischenspeicher bereits eine Ergänzung ist." -+ -+#: ../../src/lib/krb5/ccache/cc_keyring.c:1219 -+#, c-format -+msgid "Credentials cache keyring '%s' not found" -+msgstr "Schlüsselbund %s des Anmeldedatenzwischenspeichers nicht gefunden" -+ -+#: ../../src/lib/krb5/ccache/cccursor.c:212 -+#, c-format -+msgid "Can't find client principal %s in cache collection" -+msgstr "" -+"Client-Principal %s kann nicht in der Zwischenspeicheransammlung gefunden " -+"werden" -+ -+#: ../../src/lib/krb5/ccache/cccursor.c:253 -+msgid "No Kerberos credentials available" -+msgstr "keine Kerberos-Anmeldedaten verfügbar" -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:398 -+#, c-format -+msgid "No key table entry found for %s" -+msgstr "Für %s wurde kein Schlüsseltabelleneintrag gefunden." -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:815 -+#: ../../src/lib/krb5/keytab/kt_file.c:848 -+msgid "Cannot change keytab with keytab iterators active" -+msgstr "" -+"Schlüsseltabelle mit aktiven Schlüsseltabelleniteratoren kann nicht geändert " -+"werden" -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:1047 -+#, c-format -+msgid "Key table file '%s' not found" -+msgstr "Schlüsseltabellendatei »%s« nicht gefunden" -+ -+#: ../../src/lib/krb5/keytab/ktfns.c:127 -+#, c-format -+msgid "Keytab %s is nonexistent or empty" -+msgstr "Schlüsseltabelle %s existiert nicht oder ist leer" -+ -+#: ../../src/lib/krb5/krb/chpw.c:251 -+msgid "Malformed request error" -+msgstr "Fehler wegen Anfrage in falscher Form" -+ -+#: ../../src/lib/krb5/krb/chpw.c:254 ../lib/krb5/error_tables/kdb5_err.c:58 -+msgid "Server error" -+msgstr "Serverfehler" -+ -+#: ../../src/lib/krb5/krb/chpw.c:257 -+msgid "Authentication error" -+msgstr "Authentifizierungsfehler" -+ -+#: ../../src/lib/krb5/krb/chpw.c:260 -+msgid "Password change rejected" -+msgstr "Passwortänderung abgelehnt" -+ -+#: ../../src/lib/krb5/krb/chpw.c:263 -+msgid "Access denied" -+msgstr "Zugriff verweigert" -+ -+#: ../../src/lib/krb5/krb/chpw.c:266 -+msgid "Wrong protocol version" -+msgstr "falsche Protokollversion" -+ -+#: ../../src/lib/krb5/krb/chpw.c:269 -+msgid "Initial password required" -+msgstr "Erstpasswort erforderlich" -+ -+#: ../../src/lib/krb5/krb/chpw.c:272 -+msgid "Success" -+msgstr "Erfolg" -+ -+#: ../../src/lib/krb5/krb/chpw.c:275 ../lib/krb5/error_tables/krb5_err.c:257 -+msgid "Password change failed" -+msgstr "Ändern des Passworts fehlgeschlagen" -+ -+#: ../../src/lib/krb5/krb/chpw.c:433 -+msgid "" -+"The password must include numbers or symbols. Don't include any part of " -+"your name in the password." -+msgstr "" -+"Das Passwort muss Zahlen oder Symbole enthalten. Fügen Sie keinen Teil Ihres " -+"Namens in das Passwort ein." -+ -+#: ../../src/lib/krb5/krb/chpw.c:439 -+#, c-format -+msgid "The password must contain at least %d character." -+msgid_plural "The password must contain at least %d characters." -+msgstr[0] "Das Passwort muss mindestens %d Zeichen enthalten." -+msgstr[1] "Das Passwort muss mindestens %d Zeichen enthalten." -+ -+#: ../../src/lib/krb5/krb/chpw.c:448 -+#, c-format -+msgid "The password must be different from the previous password." -+msgid_plural "The password must be different from the previous %d passwords." -+msgstr[0] "Das Passwort muss sich vom vorhergehenden Passwort unterscheiden." -+msgstr[1] "" -+"Das Passwort muss sich von den vorhergehenden %d Passwörtern unterscheiden." -+ -+#: ../../src/lib/krb5/krb/chpw.c:460 -+#, c-format -+msgid "The password can only be changed once a day." -+msgid_plural "The password can only be changed every %d days." -+msgstr[0] "Das Passwort kann nur einmal täglich geändert werden." -+msgstr[1] "Das Passwort kann nur alle %d Tage geändert werden." -+ -+#: ../../src/lib/krb5/krb/chpw.c:506 -+msgid "Try a more complex password, or contact your administrator." -+msgstr "" -+"Versuchen Sie es mit einem etwas komplexeren Passwort oder wenden Sie sich " -+"an Ihren Administrator." -+ -+#: ../../src/lib/krb5/krb/fast.c:217 -+#, c-format -+msgid "%s constructing AP-REQ armor" -+msgstr "%s-Konstruktion von AP-REQ-Schutz" -+ -+#: ../../src/lib/krb5/krb/fast.c:399 -+#, c-format -+msgid "%s while decrypting FAST reply" -+msgstr "%s beim Entschlüsseln der FAST-Antwort" -+ -+#: ../../src/lib/krb5/krb/fast.c:408 -+msgid "nonce modified in FAST response: KDC response modified" -+msgstr "" -+"Nummer für einmaligen Gebrauch in der FAST-Anwort geändert: KDC-Anwort " -+"geändert" -+ -+#: ../../src/lib/krb5/krb/fast.c:474 -+msgid "Expecting FX_ERROR pa-data inside FAST container" -+msgstr "Innerhalb des FAST-Containers wird »FX_ERROR pa-data« erwartet." -+ -+#: ../../src/lib/krb5/krb/fast.c:545 -+msgid "FAST response missing finish message in KDC reply" -+msgstr "Der FAST-Anwort fehlt die Beendigungsnachricht in der KDC-Anwort" -+ -+#: ../../src/lib/krb5/krb/fast.c:558 -+msgid "Ticket modified in KDC reply" -+msgstr "Ticket in der KDC-Antwort verändert" -+ -+#: ../../src/lib/krb5/krb/gc_via_tkt.c:208 -+#, c-format -+msgid "KDC returned error string: %.*s" -+msgstr "KDC gab eine Fehlermeldung zurück: %.*s" -+ -+#: ../../src/lib/krb5/krb/gc_via_tkt.c:217 -+#, c-format -+msgid "Server %s not found in Kerberos database" -+msgstr "Server %s wurde nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:133 -+msgid "Reply has wrong form of session key for anonymous request" -+msgstr "" -+"Antwort hat die falsche Form des Sitzungschlüssels für eine anonyme Anfrage" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:1628 -+#, c-format -+msgid "%s while storing credentials" -+msgstr "%s beim Speichern der Anmeldedaten" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:1715 -+#, c-format -+msgid "Client '%s' not found in Kerberos database" -+msgstr "Client »%s« wurde nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../../src/lib/krb5/krb/gic_keytab.c:207 -+#, c-format -+msgid "Keytab contains no suitable keys for %s" -+msgstr "Schlüsseltabelle enthält keine passenden Schlüssel für %s" -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:75 -+#, c-format -+msgid "Password for %s" -+msgstr "Passwort for %s" -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:227 -+#, c-format -+msgid "Warning: Your password will expire in less than one hour on %s" -+msgstr "" -+"Warnung: Ihr Passwort auf %s wird in weniger als einer Stunde ablaufen." -+ -+# FIXME in German impossible; plural without »s« -+#: ../../src/lib/krb5/krb/gic_pwd.c:231 -+#, c-format -+msgid "Warning: Your password will expire in %d hour%s on %s" -+msgstr "Warnung: Ihr Passwort wird in %d Stunden%s auf %s ablaufen." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:235 -+#, c-format -+msgid "Warning: Your password will expire in %d days on %s" -+msgstr "Warnung: Ihr Passwort wird in %d Tagen auf %s ablaufen." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:409 -+msgid "Password expired. You must change it now." -+msgstr "Passwort abgelaufen. Sie müssen es nun ändern." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:428 ../../src/lib/krb5/krb/gic_pwd.c:432 -+#, c-format -+msgid "%s. Please try again." -+msgstr "%s. Bitte versuchen Sie es erneut." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:471 -+#, c-format -+msgid "%.*s%s%s. Please try again.\n" -+msgstr "%.*s%s%s. Bitte versuchen Sie es erneut.\n" -+ -+#: ../../src/lib/krb5/krb/parse.c:203 -+#, c-format -+msgid "Principal %s is missing required realm" -+msgstr "Principal %s fehlt erforderlicher Realm" -+ -+#: ../../src/lib/krb5/krb/parse.c:215 -+#, c-format -+msgid "Principal %s has realm present" -+msgstr "Für Principal %s ist Realm vorhanden" -+ -+#: ../../src/lib/krb5/krb/plugin.c:165 -+#, c-format -+msgid "Invalid module specifier %s" -+msgstr "ungültiger Modulbezeichner %s" -+ -+#: ../../src/lib/krb5/krb/plugin.c:402 -+#, c-format -+msgid "Could not find %s plugin module named '%s'" -+msgstr "Das Erweiterungsmodul %s namens »%s« konnte nicht gefunden werden." -+ -+#: ../../src/lib/krb5/krb/preauth2.c:1018 -+msgid "Unable to initialize preauth context" -+msgstr "Vorauthentifizierungskontext konnte nicht initialisiert werden." -+ -+#: ../../src/lib/krb5/krb/preauth2.c:1032 -+#, c-format -+msgid "Preauth module %s: %s" -+msgstr "Vorauthentifizierungsmodul %s: %s" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:510 -+msgid "Please choose from the following:\n" -+msgstr "Bitte wählen Sie aus dem Folgenden aus:\n" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:511 -+msgid "Vendor:" -+msgstr "Anbieter:" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:523 -+msgid "Enter #" -+msgstr "Geben Sie # ein" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:559 -+msgid "OTP Challenge:" -+msgstr "Anforderung des Einwegpassworts:" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:588 -+msgid "OTP Token PIN" -+msgstr "Einwegpasswort-Token-PIN" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:702 -+msgid "OTP value doesn't match any token formats" -+msgstr "Wert des Einwegpassworts entspricht keinem Token-Format" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:769 -+msgid "Enter OTP Token Value" -+msgstr "Geben Sie den Wert des Einwegpasswort-Tokens an" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:914 -+msgid "No supported tokens" -+msgstr "keine unterstützten Token" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:49 -+msgid "Challenge for Enigma Logic mechanism" -+msgstr "Anforderung für Enigma-Logic-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:53 -+msgid "Challenge for Digital Pathways mechanism" -+msgstr "Anforderung für Digital-Pathway-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:57 -+msgid "Challenge for Activcard mechanism" -+msgstr "Anforderung für Activcard-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:60 -+msgid "Challenge for Enhanced S/Key mechanism" -+msgstr "Anforderung für erweiterten S/Key-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:63 -+msgid "Challenge for Traditional S/Key mechanism" -+msgstr "Anforderung für traditionellen S/Key-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:66 -+#: ../../src/lib/krb5/krb/preauth_sam2.c:69 -+msgid "Challenge for Security Dynamics mechanism" -+msgstr "Anforderung für Security-Dynamics-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:72 -+msgid "Challenge from authentication server" -+msgstr "Anforderung vom Authentifizierungsserver" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:166 -+msgid "SAM Authentication" -+msgstr "SAM-Authentifizierung" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:145 -+#, c-format -+msgid "Cannot find key for %s kvno %d in keytab" -+msgstr "" -+"Schlüssel für %s-KNVO %d kann nicht in der Schlüsseltabelle gefunden werden" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:150 -+#, c-format -+msgid "Cannot find key for %s kvno %d in keytab (request ticket server %s)" -+msgstr "" -+"Schlüssel für %s-KNVO %d kann nicht in der Schlüsseltabelle gefunden werden " -+"(angefragter Ticketserver %s)" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:175 -+#, c-format -+msgid "Cannot decrypt ticket for %s using keytab key for %s" -+msgstr "" -+"Ticket für %s kann nicht mittels des Schlüsseltabellenschlüssels für %s " -+"entschlüsselt werden" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:197 -+#, c-format -+msgid "Server principal %s does not match request ticket server %s" -+msgstr "Server-Principal %s passt nicht zum abgefragten Ticketserver %s" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:226 -+msgid "No keys in keytab" -+msgstr "keine Schlüssel in der Schlüsseltabelle" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:229 -+#, c-format -+msgid "Server principal %s does not match any keys in keytab" -+msgstr "" -+"Server-Principal %s hat keinen passenden Schlüssel in der Schlüsseltabelle" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:236 -+#, c-format -+msgid "" -+"Request ticket server %s found in keytab but does not match server principal " -+"%s" -+msgstr "" -+"abgefragter Ticketserver %s wurde in der Schlüsseltabelle gefunden, er passte " -+"jedoch nicht zu Server-Principal %s" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:241 -+#, c-format -+msgid "Request ticket server %s not found in keytab (ticket kvno %d)" -+msgstr "" -+"Abgefragter Ticketserver %s wurde nicht in der Schlüsseltabelle gefunden " -+"(Ticket KVNO %d)." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:247 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d not found in keytab; ticket is likely out " -+"of date" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde nicht in der Schlüsseltabelle " -+"gefunden; Ticket ist wahrscheinlich abgelaufen." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:252 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d not found in keytab; keytab is likely out " -+"of date" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde nicht in der Schlüsseltabelle " -+"gefunden; Schlüsseltabelle ist wahrscheinlich nicht mehr aktuell." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:261 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d found in keytab but not with enctype %s" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde in der Schlüsseltabelle gefunden, " -+"jedoch nicht mit Verschlüsselungstyp %s." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:266 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d enctype %s found in keytab but cannot " -+"decrypt ticket" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d mit Verschlüsselungstyp %s in der " -+"Schlüsseltabelle gefunden, Ticket kann jedoch nicht entschlüsselt werden." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:897 -+#, c-format -+msgid "Encryption type %s not permitted" -+msgstr "Verschlüsselungstyp %s nicht erlaubt" -+ -+#: ../../src/lib/krb5/os/expand_path.c:316 -+#, c-format -+msgid "Can't find username for uid %lu" -+msgstr "Zu UID %lu kann kein Benutzername gefunden werden." -+ -+#: ../../src/lib/krb5/os/expand_path.c:405 -+#: ../../src/lib/krb5/os/expand_path.c:421 -+msgid "Invalid token" -+msgstr "ungültiges Token" -+ -+#: ../../src/lib/krb5/os/expand_path.c:506 -+msgid "variable missing }" -+msgstr "Variable fehlt }" -+ -+#: ../../src/lib/krb5/os/locate_kdc.c:660 -+#, c-format -+msgid "Cannot find KDC for realm \"%.*s\"" -+msgstr "KDC für Realm »%.*s« kann nicht gefunden werden" -+ -+#: ../../src/lib/krb5/os/sendto_kdc.c:475 -+#, c-format -+msgid "Cannot contact any KDC for realm '%.*s'" -+msgstr "für Realm »%.*s« kann nicht KDC kontaktiert werden" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:106 -+#, c-format -+msgid "Cannot fstat replay cache file %s: %s" -+msgstr "»fstat« für Antwortzwischenspeicherdatei %s nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:112 -+#, c-format -+msgid "" -+"Insecure mkstemp() file mode for replay cache file %s; try running this " -+"program with umask 077" -+msgstr "" -+"unsicherer mkstemp()-Dateimodus für Antwortzwischenspeicherdatei %s; " -+"versuchen Sie, dieses Programm mit der Umask 077 auszuführen" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:144 -+#, c-format -+msgid "Cannot %s replay cache file %s: %s" -+msgstr "%s der Wiederholungszwischenspeicherdatei %s nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:149 -+#, c-format -+msgid "Cannot %s replay cache: %s" -+msgstr "%s des Wiederholungszwischenspeichers nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:272 -+#, c-format -+msgid "Insecure file mode for replay cache file %s" -+msgstr "unsicherer Dateimodus für Wiederholungszwischenspeicherdatei %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:278 -+#, c-format -+msgid "rcache not owned by %d" -+msgstr "Rcache gehört nicht %d" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:402 ../../src/lib/krb5/rcache/rc_io.c:406 -+#: ../../src/lib/krb5/rcache/rc_io.c:411 -+#, c-format -+msgid "Can't write to replay cache: %s" -+msgstr "" -+"in Wiederholungszwischenspeicherdatei kann nicht geschrieben werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:432 -+#, c-format -+msgid "Cannot sync replay cache file: %s" -+msgstr "" -+"Wiederholungszwischenspeicherdatei kann nicht synchronisiert werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:451 -+#, c-format -+msgid "Can't read from replay cache: %s" -+msgstr "aus dem Wiederholungszwischenspeicher kann nicht gelesen werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:482 ../../src/lib/krb5/rcache/rc_io.c:488 -+#: ../../src/lib/krb5/rcache/rc_io.c:493 -+#, c-format -+msgid "Can't destroy replay cache: %s" -+msgstr "Wiederholungszwischenspeicher kann nicht vernichtet werden: %s" -+ -+#: ../../src/plugins/kdb/db2/kdb_db2.c:245 -+#: ../../src/plugins/kdb/db2/kdb_db2.c:830 -+#, c-format -+msgid "Unsupported argument \"%s\" for db2" -+msgstr "nicht unterstütztes Argument »%s« für DB2" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:69 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:887 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1088 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1507 -+msgid "while reading kerberos container information" -+msgstr "beim Lesen der Kerberos-Container-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:129 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:143 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:504 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:518 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:151 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:166 -+msgid "while providing time specification" -+msgstr "beim Bereitstellen der Zeitspezifikation" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:268 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:304 -+msgid "while creating policy object" -+msgstr "beim Erstellen des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:279 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1515 -+msgid "while reading realm information" -+msgstr "beim Lesen der Realm-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:348 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:407 -+msgid "while destroying policy object" -+msgstr "beim Zerstören des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:358 -+#, c-format -+msgid "This will delete the policy object '%s', are you sure?\n" -+msgstr "Dies wird das Richtlinienobjekt »%s« löschen, sind Sie sicher?\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:473 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:663 -+msgid "while modifying policy object" -+msgstr "beim Ändern des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:487 -+#, c-format -+msgid "while reading information of policy '%s'" -+msgstr "beim Lesen der Information der Richtlinie »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:692 -+msgid "while viewing policy" -+msgstr "beim Betrachten der Richtlinie" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:701 -+#, c-format -+msgid "while viewing policy '%s'" -+msgstr "beim Betrachten der Richtlinie »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:835 -+msgid "while listing policy objects" -+msgstr "beim Auflisten der Richtlinienobjekte" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:453 -+#, c-format -+msgid "for subtree while creating realm '%s'" -+msgstr "für einen Teilbaum beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:465 -+#, c-format -+msgid "for container reference while creating realm '%s'" -+msgstr "für Container-Bezug beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:489 -+#, c-format -+msgid "invalid search scope while creating realm '%s'" -+msgstr "ungültiger Suchbereich beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:504 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:823 -+#, c-format -+msgid "'%s' is an invalid option\n" -+msgstr "»%s« ist keine gültige Option\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:512 -+#, c-format -+msgid "Initializing database for realm '%s'\n" -+msgstr "Datenbank für Realm »%s« wird initialisiert\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:536 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:696 -+#, c-format -+msgid "while creating realm '%s'" -+msgstr "beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:556 -+#, c-format -+msgid "Enter DN of Kerberos container: " -+msgstr "Geben Sie die den DN des Kerberos-Containers ein: " -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:591 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:894 -+#, c-format -+msgid "while reading information of realm '%s'" -+msgstr "beim Lesen der Information von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:733 -+msgid "while reading Kerberos container information" -+msgstr "beim Lesen der Kerberos-Container-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:774 -+#, c-format -+msgid "for subtree while modifying realm '%s'" -+msgstr "für einen Teilbaum beim Ändern von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:785 -+#, c-format -+msgid "for container reference while modifying realm '%s'" -+msgstr "für Container-Bezug beim Ändern von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:812 -+#, c-format -+msgid "specified for search scope while modifying information of realm '%s'" -+msgstr "" -+"angegeben für Suchbereich, während die Information für Realm »%s« geändert " -+"wird" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:851 -+#, c-format -+msgid "while modifying information of realm '%s'" -+msgstr "beim Ändern der Information von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:940 -+msgid "Realm Name" -+msgstr "Realm-Name" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:943 -+msgid "Subtree" -+msgstr "Teilbaum" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:946 -+msgid "Principal Container Reference" -+msgstr "Principal-Container-Bezug" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:951 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:953 -+msgid "SearchScope" -+msgstr "Suchbereich" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:951 -+msgid "Invalid !" -+msgstr "ungültig!" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:958 -+msgid "KDC Services" -+msgstr "KDC-Dienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:973 -+msgid "Admin Services" -+msgstr "Administratordienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:988 -+msgid "Passwd Services" -+msgstr "Passwortdienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1004 -+msgid "Maximum Ticket Life" -+msgstr "maximale Ticketlebensdauer" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1009 -+msgid "Maximum Renewable Life" -+msgstr "maximale verlängerbare Lebensdauer" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1016 -+msgid "Ticket flags" -+msgstr "Ticket-Flags" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1095 -+msgid "while listing realms" -+msgstr "beim Auflisten der Realms" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1439 -+msgid "while adding entries to database" -+msgstr "beim Hinzufügen von Einträgen zur Datenbank" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1480 -+#, c-format -+msgid "Deleting KDC database of '%s', are you sure?\n" -+msgstr "" -+"Sind Sie sicher, dass die KDC-Datenbank von »%s« gelöscht werden soll?\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1491 -+#, c-format -+msgid "OK, deleting database of '%s'...\n" -+msgstr "OK, die Datenbank von »%s« wird gelöscht …\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1524 -+#, c-format -+msgid "deleting database of '%s'" -+msgstr "Die Datenbank von »%s« wird gelöscht." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1529 -+#, c-format -+msgid "** Database of '%s' destroyed.\n" -+msgstr "** Datenbank von »%s« vernichtet\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:81 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:88 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:96 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:104 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:120 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:148 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:227 -+msgid "while setting service object password" -+msgstr "beim Setzen des Passworts für das Dienstobjekt" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:140 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:477 -+#, c-format -+msgid "Password for \"%s\"" -+msgstr "Passwort für »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:143 -+#, c-format -+msgid "Re-enter password for \"%s\"" -+msgstr "Geben Sie das Passwort für »%s« erneut ein." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:154 -+#, c-format -+msgid "%s: Invalid password\n" -+msgstr "%s: ungültiges Passwort\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:170 -+msgid "Failed to convert the password to hexadecimal" -+msgstr "Das Umwandeln des Passworts in Dezimalschreibweise ist fehlgeschlagen." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:183 -+#, c-format -+msgid "Failed to open file %s: %s" -+msgstr "Datei %s konnte nicht geöffnet werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:205 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:247 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:256 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:283 -+msgid "Failed to write service object password to file" -+msgstr "" -+"Schreiben des Passworts für das Dienstobjekt in eine Datei fehlgeschlagen" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:211 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:268 -+msgid "Error reading service object password file" -+msgstr "Fehler beim Lesen der Passwortdatei für das Dienstobjekt" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:236 -+#, c-format -+msgid "Error creating file %s" -+msgstr "Fehler beim Erstellen der Datei %s" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:105 -+#, c-format -+msgid "" -+"Usage: kdb5_ldap_util [-D user_dn [-w passwd]] [-H ldapuri]\n" -+"\tcmd [cmd_options]\n" -+"create [-subtrees subtree_dn_list] [-sscope search_scope] [-" -+"containerref container_reference_dn]\n" -+"\t\t[-m|-P password|-sf stashfilename] [-k mkeytype] [-kv mkeyVNO] [-s]\n" -+"\t\t[-maxtktlife max_ticket_life] [-maxrenewlife max_renewable_ticket_life]\n" -+"\t\t[ticket_flags] [-r realm]\n" -+"modify [-subtrees subtree_dn_list] [-sscope search_scope] [-" -+"containerref container_reference_dn]\n" -+"\t\t[-maxtktlife max_ticket_life] [-maxrenewlife max_renewable_ticket_life]\n" -+"\t\t[ticket_flags] [-r realm]\n" -+"view [-r realm]\n" -+"destroy [-f] [-r realm]\n" -+"list\n" -+"stashsrvpw [-f filename] service_dn\n" -+"create_policy [-r realm] [-maxtktlife max_ticket_life]\n" -+"\t\t[-maxrenewlife max_renewable_ticket_life] [ticket_flags] policy\n" -+"modify_policy [-r realm] [-maxtktlife max_ticket_life]\n" -+"\t\t[-maxrenewlife max_renewable_ticket_life] [ticket_flags] policy\n" -+"view_policy [-r realm] policy\n" -+"destroy_policy [-r realm] [-force] policy\n" -+"list_policy [-r realm]\n" -+msgstr "" -+"Aufruf: kdb5_ldap_util [-D Benutzer-DN [-w Passwort]] [-H LDAP-URI]\n" -+"\tcmd [Befehlsoptionen]\n" -+"create [-subtrees DN-Liste_Teilbäume] [-sscope Suchbereich] [-" -+"containerref Container-Bezug-DN]\n" -+"\t\t[-m|-P Passwort|-sf Ablagedateiname] [-k mkeytype] [-kv mkeyVNO] [-s]\n" -+"\t\t[-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] [-r Realm]\n" -+"modify [-subtrees DN-Liste_Teilbäume] [-sscope Suchbereich] [-" -+"containerref Container-Bezug-DN]\n" -+"\t\t[-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] [-r Realm]\n" -+"view [-r Realm]\n" -+"destroy [-f] [-r Realm]\n" -+"list\n" -+"stashsrvpw [-f Dateiname] Dienst-DN\n" -+"create_policy [-r Realm] [-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] Richtlinie\n" -+"modify_policy [-r Realm] [-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] Richtlinie\n" -+"view_policy [-r Realm] Richtlinie\n" -+"destroy_policy [-r Realm] [-force] Richtlinie\n" -+"list_policy [-r Realm]\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:325 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:333 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:341 -+msgid "while reading ldap parameters" -+msgstr "beim Lesen der LDAP-Parameter" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:439 -+msgid "while initializing error handling" -+msgstr "beim Initialisieren der Fehlerbehandlung" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:447 -+msgid "while initializing ldap handle" -+msgstr "beim Initialisieren des LDAP-Identifikators" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:461 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:470 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:483 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:525 -+msgid "while retrieving ldap configuration" -+msgstr "beim Abfragen der LDAP-Konfiguration" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:500 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:507 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:516 -+msgid "while initializing server list" -+msgstr "beim Initialisieren der Serverliste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:547 -+msgid "while setting up lib handle" -+msgstr "ein Einrichten der BibliotheksIdentifikators" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:556 -+msgid "while reading ldap configuration" -+msgstr "beim Lesen der LDAP-Konfiguration" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:68 -+msgid "Unable to read Kerberos container" -+msgstr "Kerberos-Container kann nicht gelesen werden" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:74 -+msgid "Unable to read Realm" -+msgstr "Realm kann nicht gelesen werden" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:215 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:73 -+msgid "Error processing LDAP DB params:" -+msgstr "Fehler beim Verarbeiten der LDAP-Datenbankparameter:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:222 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:80 -+msgid "Error reading LDAP server params:" -+msgstr "Fehler beim Lesen der LDAP-Server-Parameters:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:64 -+msgid "LDAP bind dn value missing" -+msgstr "LDAP-Bindungs-DN-Wert fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:69 -+msgid "LDAP bind password value missing" -+msgstr "LDAP-Bindungs-Passwortwert fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:77 -+msgid "Error reading password from stash: " -+msgstr "Fehler beim Lesen des Passworts aus der Ablage: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:85 -+msgid "Service password length is zero" -+msgstr "Länge des Dienstpassworts ist Null" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:145 -+#, c-format -+msgid "Cannot bind to LDAP server '%s' with SASL mechanism '%s': %s" -+msgstr "" -+"mit LDAP-Server »%s« kann keine Verbindung mit SASL-Mechanismus »%s« " -+"hergestellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:158 -+#, c-format -+msgid "Cannot bind to LDAP server '%s' as '%s': %s" -+msgstr "" -+"mit LDAP-Server »%s« kann keine Verbindung als »%s« hergestellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:183 -+#, c-format -+msgid "Cannot create LDAP handle for '%s': %s" -+msgstr "LDAP-Identifikator für »%s« kann nicht erstellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:131 -+msgid "could not complete roll-back, error deleting Kerberos Container" -+msgstr "" -+"Zurücksetzen kann nicht abgeschlossen werden, Fehler beim Löschen des " -+"Kerberos-Containers" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:56 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:67 -+msgid "Error reading kerberos container location from krb5.conf" -+msgstr "" -+"Fehler beim Lesen des Kerberos-Container-Speicherorts aus der »krb5.conf«." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:75 -+msgid "Kerberos container location not specified" -+msgstr "Kerberos-Container-Speicherort nicht angegeben" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:55 -+#, c-format -+msgid "Error reading '%s' attribute: %s" -+msgstr "Fehler beim Lesen des Attributs »%s«: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:218 -+msgid "KDB module requires -update argument" -+msgstr "KDB-Modul benötigt Argument »-update«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:224 -+#, c-format -+msgid "'%s' value missing" -+msgstr "Wert »%s« fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:282 -+#, c-format -+msgid "unknown option '%s'" -+msgstr "unbekannte Option »%s«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:342 -+msgid "Minimum connections required per server is 2" -+msgstr "Die benötigte Mindestanzahl von Verbindungen pro Server ist zwei" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c:159 -+msgid "Default realm not set" -+msgstr "Standard-Realm nicht gesetzt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c:262 -+msgid "DN information missing" -+msgstr "DN-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:108 -+msgid "Principal does not belong to realm" -+msgstr "Principal gehört nicht zum Realm" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:278 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:287 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:295 -+#, c-format -+msgid "%s option not supported" -+msgstr "Option %s wird nicht unterstützt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:302 -+#, c-format -+msgid "unknown option: %s" -+msgstr "unbekannte Option: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:309 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:316 -+#, c-format -+msgid "%s option value missing" -+msgstr "Wert der Option %s fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:542 -+msgid "Principal does not belong to the default realm" -+msgstr "Principal gehört nicht zum Standard-Realm" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:610 -+#, c-format -+msgid "" -+"operation can not continue, more than one entry with principal name \"%s\" " -+"found" -+msgstr "" -+"Die Aktion kann nicht fortfahren, da mehr als ein Principal namens »%s« " -+"gefunden wurde." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:673 -+#, c-format -+msgid "'%s' not found: " -+msgstr "»%s« nicht gefunden: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:751 -+msgid "DN is out of the realm subtree" -+msgstr "DN liegt außerhalb ders Teilbaums des Realms" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:807 -+#, c-format -+msgid "ldap object is already kerberized" -+msgstr "LDAP-Objekt ist bereits an Kerberos angepasst" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:827 -+#, c-format -+msgid "" -+"link information can not be set/updated as the kerberos principal belongs to " -+"an ldap object" -+msgstr "" -+"Verweisinformation kann nicht eingerichtet/aktualisiert werden, da der " -+"Kerberos-Principal zu einem LDAP-Objekt gehört." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:842 -+#, c-format -+msgid "Failed getting object references" -+msgstr "Holen von Objektbezügen fehlgeschlagen" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:849 -+#, c-format -+msgid "kerberos principal is already linked to a ldap object" -+msgstr "Kerberos-Principal ist bereits mit einem LDAP-Objekt verknüpft" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1167 -+msgid "ticket policy object value: " -+msgstr "Wert des Ticket-Richtlinienobjekts: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1215 -+#, c-format -+msgid "Principal delete failed (trying to replace entry): %s" -+msgstr "" -+"Löschen des Principals fehlgeschlagen (es wird versucht, den Eintrag zu " -+"ersetzen): %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1225 -+#, c-format -+msgid "Principal add failed: %s" -+msgstr "Hinzufügen des Principals fehlgeschlagen: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1263 -+#, c-format -+msgid "User modification failed: %s" -+msgstr "Änderung des Benutzers fehlgeschlagen: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1336 -+msgid "Error reading ticket policy. " -+msgstr "Fehler beim Lesen der Ticket-Richtlinie" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1402 -+#, c-format -+msgid "unable to decode stored principal key data (%s)" -+msgstr "" -+"Die gespeicherten Schlüsseldaten des Principals (%s) konnten nicht " -+"dekodiert werden." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:223 -+msgid "Realm information not available" -+msgstr "Realm-Information nicht verfügbar" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:294 -+msgid "Error reading ticket policy: " -+msgstr "Fehler beim Lesen der Ticket-Richtlinie:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:307 -+#, c-format -+msgid "Realm Delete FAILED: %s" -+msgstr "Löschen des Realms FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:387 -+msgid "subtree value: " -+msgstr "Wert des Teilbaums: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:404 -+msgid "container reference value: " -+msgstr "Wert des Container-Bezugs: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:487 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:550 -+msgid "Kerberos Container information is missing" -+msgstr "Kerberos-Container-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:499 -+msgid "Invalid Kerberos container DN" -+msgstr "ungültiger Kerberos-Container-DN" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:515 -+#, c-format -+msgid "Kerberos Container create FAILED: %s" -+msgstr "Erstellen des Kerberos-Containers FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:558 -+#, c-format -+msgid "Kerberos Container delete FAILED: %s" -+msgstr "Löschen des Kerberos-Containers FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:634 -+msgid "realm object value: " -+msgstr "Wert des Realm-Objekts: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:48 -+msgid "Not a hexadecimal password" -+msgstr "kein hexadezimales Passwort" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:55 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:66 -+msgid "Password corrupt" -+msgstr "Passwort beschädigt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:93 -+#, c-format -+msgid "Cannot open LDAP password file '%s': %s" -+msgstr "LDAP-Passwortdatei »%s« kann nicht geöffnet werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:123 -+#, c-format -+msgid "Bind DN entry '%s' missing in LDAP password file '%s'" -+msgstr "Bind-DN-Eintrag »%s« fehlt in der LDAP-Passwortdatei »%s«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:56 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:132 -+msgid "Ticket Policy Name missing" -+msgstr "Ticket-Richtlinienname fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:144 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:221 -+msgid "ticket policy object: " -+msgstr "Ticket-Richtlinienobjekt: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:209 -+msgid "Ticket Policy Object information missing" -+msgstr "Ticket-Richtlinienobjekt-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:300 -+msgid "Ticket Policy Object DN missing" -+msgstr "DN des Ticket-Richtlinienobjekts fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:327 -+msgid "Delete Failed: One or more Principals associated with the Ticket Policy" -+msgstr "" -+"Löschen fehlgeschlagen: Ein oder mehrere Principals gehören zur Ticket-" -+"Richtlinie." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:435 -+msgid "Error reading container object: " -+msgstr "Fehler beim Lesen des Container-Objekts: " -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_nss.c:667 -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:652 -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:4153 -+msgid "Pass phrase for" -+msgstr "Passphrase für" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1081 -+#, c-format -+msgid "Cannot create cert chain: %s" -+msgstr "Zertifikatskette kann nicht erstellt werden: %s" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1408 -+msgid "Invalid pkinit packet: octet string expected" -+msgstr "ungültiges Pkinit-Paket: Achtbit-Zeichenkette erwartet" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1427 -+msgid "wrong oid\n" -+msgstr "falsche OID\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:5994 -+#, c-format -+msgid "unknown code 0x%x" -+msgstr "unbekannter Code 0x%x" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:424 -+#, c-format -+msgid "Unsupported type while processing '%s'\n" -+msgstr "nicht unterstützter Typ bei der Verarbeitung von »%s«\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:465 -+msgid "Internal error parsing X509_user_identity\n" -+msgstr "interner Fehler beim Auswerten von »X509_user_identity«\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:560 -+msgid "No user identity options specified" -+msgstr "keine Optionen der Nutzeridentität angegeben" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:414 -+msgid "Pkinit request not signed, but client not anonymous." -+msgstr "Pkinit-Anfrage nicht signiert, Client ist jedoch nicht anonym" -+ -+# DH = Diffie-Hellman -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:447 -+msgid "Anonymous pkinit without DH public value not supported." -+msgstr "Anonymes Pkinit wird nicht ohne öffentlichen DH-Wert unterstützt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1147 -+#, c-format -+msgid "No pkinit_identity supplied for realm %s" -+msgstr "Für Realm %s wird keine »pkinit_identity« bereitgestellt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1158 -+#, c-format -+msgid "No pkinit_anchors supplied for realm %s" -+msgstr "Für Realm %s werden keine »pkinit_anchors« bereitgestellt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1346 -+msgid "No realms configured correctly for pkinit support" -+msgstr "Für Pkinit-Unterstützung wurden keine Realms korrekt konfiguriert." -+ -+#: ../../src/slave/kprop.c:85 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-r realm] [-f file] [-d] [-P port] [-s srvtab] slave_host\n" -+"\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-r Realm] [-f Datei] [-d] [-P Port] [-s Dienstschlüsseltabelle] " -+"untergeordneter_Rechner\n" -+"\n" -+ -+#: ../../src/slave/kprop.c:114 -+#, c-format -+msgid "Database propagation to %s: SUCCEEDED\n" -+msgstr "Datenbankverbreitung auf %s: ERFOLGREICH\n" -+ -+#: ../../src/slave/kprop.c:187 -+msgid "while setting client principal name" -+msgstr "beim Setzen des Client-Principal-Namens" -+ -+#: ../../src/slave/kprop.c:194 ../../src/slave/kprop.c:209 -+msgid "while setting client principal realm" -+msgstr "beim Setzen des Client-Principal-Realms" -+ -+#: ../../src/slave/kprop.c:217 -+#, c-format -+msgid "while opening credential cache %s" -+msgstr "beim Öffnen des Anmeldedatenzwischenspeichers %s" -+ -+#: ../../src/slave/kprop.c:233 -+msgid "while setting server principal name" -+msgstr "beim Setzen des Server-Principal-Namens" -+ -+#: ../../src/slave/kprop.c:255 -+msgid "while resolving keytab" -+msgstr "beim Ermitteln der Schlüsseltabelle" -+ -+#: ../../src/slave/kprop.c:264 -+msgid "while getting initial credentials\n" -+msgstr "beim Holen der Anfangsanmeldedaten\n" -+ -+#: ../../src/slave/kprop.c:301 -+msgid "while creating socket" -+msgstr "beim Erstellen eines Sockets" -+ -+#: ../../src/slave/kprop.c:317 -+msgid "while converting server address" -+msgstr "beim Umwandeln der Server-Adresse" -+ -+#: ../../src/slave/kprop.c:327 -+msgid "while connecting to server" -+msgstr "beim Verbinden mit dem Server" -+ -+#: ../../src/slave/kprop.c:334 ../../src/slave/kpropd.c:1215 -+msgid "while getting local socket address" -+msgstr "beim Holen der lokalen Socket-Adresse" -+ -+#: ../../src/slave/kprop.c:339 -+msgid "while converting local address" -+msgstr "beim Umwandeln der lokalen Socket-Adresse" -+ -+#: ../../src/slave/kprop.c:362 -+msgid "in krb5_auth_con_setaddrs" -+msgstr "in »krb5_auth_con_setaddrs«" -+ -+#: ../../src/slave/kprop.c:370 -+msgid "while authenticating to server" -+msgstr "beim Authentifizieren am Server" -+ -+#: ../../src/slave/kprop.c:374 ../../src/slave/kprop.c:573 -+#: ../../src/slave/kpropd.c:1521 -+#, c-format -+msgid "Generic remote error: %s\n" -+msgstr "allgemeiner ferner Fehler: %s\n" -+ -+#: ../../src/slave/kprop.c:380 ../../src/slave/kprop.c:579 -+msgid "signalled from server" -+msgstr "signalisiert vom Server" -+ -+#: ../../src/slave/kprop.c:382 ../../src/slave/kprop.c:581 -+#, c-format -+msgid "Error text from server: %s\n" -+msgstr "Fehlermeldung vom Server: %s\n" -+ -+#: ../../src/slave/kprop.c:410 -+#, c-format -+msgid "allocating database file name '%s'" -+msgstr "Datenbankdateiname »%s« wird reserviert" -+ -+#: ../../src/slave/kprop.c:416 -+#, c-format -+msgid "while trying to open %s" -+msgstr "beim Versuch, %s zu öffnen" -+ -+#: ../../src/slave/kprop.c:423 -+msgid "database locked" -+msgstr "Datenbank gesperrt" -+ -+#: ../../src/slave/kprop.c:426 ../../src/slave/kpropd.c:525 -+#, c-format -+msgid "while trying to lock '%s'" -+msgstr "beim Versuch, »%s« zu sperren" -+ -+#: ../../src/slave/kprop.c:430 ../../src/slave/kprop.c:438 -+#, c-format -+msgid "while trying to stat %s" -+msgstr "beim Versuch, »stat« für %s auszuführen" -+ -+#: ../../src/slave/kprop.c:434 -+msgid "while trying to malloc data_ok_fn" -+msgstr "beim Versuch, Speicher für »data_ok_fn« zu reservieren" -+ -+#: ../../src/slave/kprop.c:443 -+#, c-format -+msgid "'%s' more recent than '%s'." -+msgstr "»%s« ist aktueller als »%s«." -+ -+#: ../../src/slave/kprop.c:459 -+#, c-format -+msgid "while unlocking database '%s'" -+msgstr "beim Entsperren von Datenbank »%s«" -+ -+#: ../../src/slave/kprop.c:492 ../../src/slave/kprop.c:493 -+msgid "while encoding database size" -+msgstr "beim Aufbereiten der Datenbankgröße" -+ -+#: ../../src/slave/kprop.c:501 -+msgid "while sending database size" -+msgstr "beim Senden der Datenbankgröße" -+ -+#: ../../src/slave/kprop.c:511 -+msgid "while allocating i_vector" -+msgstr "beim Reservieren von »i_vector«" -+ -+#: ../../src/slave/kprop.c:534 -+#, c-format -+msgid "while sending database block starting at %d" -+msgstr "beim Senden des Datenbankblocks, der bei %d beginnt" -+ -+#: ../../src/slave/kprop.c:544 -+msgid "Premature EOF found for database file!" -+msgstr "vorzeitiges EOF für Datenbankdatei gefunden!" -+ -+#: ../../src/slave/kprop.c:557 -+msgid "while reading response from server" -+msgstr "beim Lesen der Antwort vom Servers" -+ -+#: ../../src/slave/kprop.c:568 -+msgid "while decoding error response from server" -+msgstr "beim Aufschlüsseln der Fehlerantwort vom Server" -+ -+#: ../../src/slave/kprop.c:599 -+#, c-format -+msgid "Kpropd sent database size %d, expecting %d" -+msgstr "Kpropd sendet Datenbankgröße %d, erwartet wurde %d" -+ -+#: ../../src/slave/kprop.c:643 -+msgid "while allocating filename for update_last_prop_file" -+msgstr "beim Reservieren des Dateinamens für »update_last_prop_file«" -+ -+#: ../../src/slave/kprop.c:648 -+#, c-format -+msgid "while creating 'last_prop' file, '%s'" -+msgstr "beim Erstellen der Datei »last_prop«, »%s«" -+ -+#: ../../src/slave/kpropd.c:170 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-r realm] [-s srvtab] [-dS] [-f slave_file]\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-r Realm] [-s Dienstschlüsseltabelle] [-dS] [-f " -+"untergeordnete_Datei]\n" -+ -+#: ../../src/slave/kpropd.c:172 -+#, c-format -+msgid "\t[-F kerberos_db_file ] [-p kdb5_util_pathname]\n" -+msgstr "\t[-F Kerberos-Datenbankdatei ] [-p KDB5-Hilfswerkzeugpfadname]\n" -+ -+#: ../../src/slave/kpropd.c:173 -+#, c-format -+msgid "\t[-x db_args]* [-P port] [-a acl_file]\n" -+msgstr "\t[-x Datenbankargumente]* [-P Port] [-a ACL-Datei]\n" -+ -+#: ../../src/slave/kpropd.c:174 -+#, c-format -+msgid "\t[-A admin_server]\n" -+msgstr "\t[-A Serveradministrator]\n" -+ -+#: ../../src/slave/kpropd.c:215 -+#, c-format -+msgid "Killing fullprop child (%d)\n" -+msgstr "Beenden des Fullprop-Kindprozesses (%d) wird erzwungen\n" -+ -+#: ../../src/slave/kpropd.c:244 -+msgid "while checking if stdin is a socket" -+msgstr "beim Prüfen, ob die Standardeingabe ein Socket ist" -+ -+#: ../../src/slave/kpropd.c:262 -+#, c-format -+msgid "ready\n" -+msgstr "bereit\n" -+ -+#: ../../src/slave/kpropd.c:272 -+#, c-format -+msgid "Could not open /dev/null: %s" -+msgstr "/dev/null konnte nicht geöffnet werden: %s" -+ -+#: ../../src/slave/kpropd.c:279 -+#, c-format -+msgid "Could not dup the inetd socket: %s" -+msgstr "Das Inetd-Socket konnte nicht dupliziert werden: %s" -+ -+#: ../../src/slave/kpropd.c:314 ../../src/slave/kpropd.c:327 -+msgid "do_iprop failed.\n" -+msgstr "»do_iprop« fehlgeschlagen\n" -+ -+#: ../../src/slave/kpropd.c:366 -+#, c-format -+msgid "getaddrinfo: %s\n" -+msgstr "getaddrinfo: %s\n" -+ -+#: ../../src/slave/kpropd.c:372 -+msgid "while obtaining socket" -+msgstr "beim Erlangen des Sockets" -+ -+#: ../../src/slave/kpropd.c:378 -+msgid "while setting SO_REUSEADDR option" -+msgstr "beim Setzen der Option SO_REUSEADDR" -+ -+#: ../../src/slave/kpropd.c:386 -+msgid "while unsetting IPV6_V6ONLY option" -+msgstr "beim Entfernen der Option IPV6_V6ONLY" -+ -+#: ../../src/slave/kpropd.c:391 -+msgid "while binding listener socket" -+msgstr "beim Anbinden an das auf Verbindung wartende Socket" -+ -+#: ../../src/slave/kpropd.c:402 -+#, c-format -+msgid "waiting for a kprop connection\n" -+msgstr "warten auf Kprop-Verbindung\n" -+ -+#: ../../src/slave/kpropd.c:408 -+msgid "while accepting connection" -+msgstr "beim Akzeptieren der Verbindung" -+ -+#: ../../src/slave/kpropd.c:414 -+msgid "while forking" -+msgstr "beim Erzeugen eines Kindprozesses" -+ -+#: ../../src/slave/kpropd.c:429 -+#, c-format -+msgid "waitpid() failed to wait for doit() (%d %s)\n" -+msgstr "waitpid() schlug beim Warten auf doit() fehl (%d %s)\n" -+ -+#: ../../src/slave/kpropd.c:433 -+msgid "while waiting to receive database" -+msgstr "beim Warten auf den Erhalt der Datenbank" -+ -+#: ../../src/slave/kpropd.c:437 -+#, c-format -+msgid "Database load process for full propagation completed.\n" -+msgstr "" -+"Der Datenbankladeprozess für eine vollständige Verbreitung ist " -+"abgeschlossen.\n" -+ -+#: ../../src/slave/kpropd.c:471 -+#, c-format -+msgid "" -+"%s: Standard input does not appear to be a network socket.\n" -+"\t(Not run from inetd, and missing the -S option?)\n" -+msgstr "" -+"%s: Bei der Standardeingabe scheint es sich nicht um ein Netzwerk-Socket zu\n" -+"\thandeln (läuft nicht aus Inetd und die Option -S fehlt?).\n" -+ -+#: ../../src/slave/kpropd.c:485 -+msgid "while attempting setsockopt (SO_KEEPALIVE)" -+msgstr "beim Versuch, »setsockopt« auszuführen (SO_KEEPALIVE)" -+ -+#: ../../src/slave/kpropd.c:490 -+#, c-format -+msgid "Connection from %s" -+msgstr "Verbindung von %s" -+ -+#: ../../src/slave/kpropd.c:510 -+#, c-format -+msgid "Rejected connection from unauthorized principal %s\n" -+msgstr "Zurückgewiesene Verbindung von nicht autorisiertem Principal %s\n" -+ -+#: ../../src/slave/kpropd.c:514 -+#, c-format -+msgid "Rejected connection from unauthorized principal %s" -+msgstr "Zurückgewiesene Verbindung von nicht authorisiertem Principal %s" -+ -+#: ../../src/slave/kpropd.c:531 -+#, c-format -+msgid "while opening database file, '%s'" -+msgstr "beim Öffnen der Datenbankdatei, »%s«" -+ -+#: ../../src/slave/kpropd.c:537 -+#, c-format -+msgid "while renaming %s to %s" -+msgstr "beim Umbenennen von %s in %s" -+ -+#: ../../src/slave/kpropd.c:543 -+#, c-format -+msgid "while downgrading lock on '%s'" -+msgstr "beim Downgrade der Sperre auf »%s«" -+ -+#: ../../src/slave/kpropd.c:550 -+#, c-format -+msgid "while unlocking '%s'" -+msgstr "beim Aufheben der Sperre »%s«" -+ -+#: ../../src/slave/kpropd.c:562 -+msgid "while sending # of received bytes" -+msgstr "beim Senden n empfangener Byte" -+ -+#: ../../src/slave/kpropd.c:568 -+msgid "while trying to close database file" -+msgstr "beim Versuch, die Datenbankdatei zu schließen" -+ -+#: ../../src/slave/kpropd.c:624 -+#, c-format -+msgid "Incremental propagation enabled\n" -+msgstr "inkrementelle Verbreitung aktiviert\n" -+ -+#: ../../src/slave/kpropd.c:634 -+msgid "Unable to get default realm" -+msgstr "Standard-Realm kann nicht geholt werden" -+ -+#: ../../src/slave/kpropd.c:647 -+#, c-format -+msgid "%s: unable to get kiprop host based service name for realm %s\n" -+msgstr "" -+"%s: Kiprop-rechnerbasierter Dienstname für Realm %s kann nicht geholt " -+"werden\n" -+ -+#: ../../src/slave/kpropd.c:658 -+msgid "while trying to construct host service principal" -+msgstr "beim Versuch, den Rechnerdienst-Principal zu erstellen" -+ -+#: ../../src/slave/kpropd.c:672 -+msgid "while determining local service principal name" -+msgstr "beim Bestimmen des lokalen Dienst-Principal-Namens" -+ -+#: ../../src/slave/kpropd.c:692 -+#, c-format -+msgid "Initializing kadm5 as client %s\n" -+msgstr "Kadm5 wird als Client %s initialisiert\n" -+ -+#: ../../src/slave/kpropd.c:706 -+#, c-format -+msgid "kadm5 initialization failed!\n" -+msgstr "Initialisierung von Kadm5 fehlgeschlagen!\n" -+ -+#: ../../src/slave/kpropd.c:715 -+msgid "while attempting to connect to master KDC ... retrying" -+msgstr "" -+"beim Versuch, eine Verbindung zum Master-KDC aufzubauen … wird erneut " -+"versucht" -+ -+#: ../../src/slave/kpropd.c:719 -+#, c-format -+msgid "Sleeping %d seconds to re-initialize kadm5 (RPC ERROR)\n" -+msgstr "" -+"Um Kadm5 neu zu initialisieren, wird %d Sekunden gewartet (RPC-FEHLER).\n" -+ -+#: ../../src/slave/kpropd.c:735 -+#, c-format -+msgid "while initializing %s interface, retrying" -+msgstr "beim Initialisieren der Schnittstelle %s, wird erneut versucht" -+ -+#: ../../src/slave/kpropd.c:739 -+#, c-format -+msgid "Sleeping %d seconds to re-initialize kadm5 (krb5kdc not running?)\n" -+msgstr "" -+"Um Kadm5 neu zu initialisieren, wird %d Sekunden gewartet (läuft Krb5kdc " -+"nicht?).\n" -+ -+#: ../../src/slave/kpropd.c:749 -+#, c-format -+msgid "kadm5 initialization succeeded\n" -+msgstr "Initialisieren von Kadm5 erfolgreich\n" -+ -+#: ../../src/slave/kpropd.c:771 -+msgid "reading update log header" -+msgstr "Aktualisierungsprotokollkopfzeilen werden gelesen" -+ -+#: ../../src/slave/kpropd.c:782 -+#, c-format -+msgid "Calling iprop_get_updates_1 (sno=%u sec=%u usec=%u)\n" -+msgstr "»iprop_get_updates_1()« wird aufgerufen (sno=%u sec=%u usec=%u)\n" -+ -+#: ../../src/slave/kpropd.c:792 -+msgid "iprop_get_updates call failed" -+msgstr "Aufruf von »iprop_get_updates« fehlgeschlagen" -+ -+#: ../../src/slave/kpropd.c:798 -+#, c-format -+msgid "Reinitializing iprop because get updates failed\n" -+msgstr "" -+"Iprop wird neu initialisiert, da Aktualisierungen fehlgeschlagen sind\n" -+ -+#: ../../src/slave/kpropd.c:819 -+#, c-format -+msgid "Still waiting for full resync\n" -+msgstr "" -+"Es wird immer noch auf das vollständige erneute Synchronisieren gewartet.\n" -+ -+#: ../../src/slave/kpropd.c:824 -+#, c-format -+msgid "Full resync needed\n" -+msgstr "erneutes vollständiges Synchronisieren erforderlich\n" -+ -+#: ../../src/slave/kpropd.c:825 -+msgid "kpropd: Full resync needed." -+msgstr "Kpropd: erneutes vollständiges Synchronisieren erforderlich" -+ -+#: ../../src/slave/kpropd.c:830 -+msgid "iprop_full_resync call failed" -+msgstr "Aufruf von »iprop_full_resync« fehlgeschlagen" -+ -+#: ../../src/slave/kpropd.c:841 -+#, c-format -+msgid "Full resync request granted\n" -+msgstr "Anfrage nach vollständigem erneuten Synchronisieren genehmigt\n" -+ -+#: ../../src/slave/kpropd.c:842 -+msgid "Full resync request granted." -+msgstr "Anfrage nach vollständigem erneuten Synchronisieren genehmigt" -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:851 -+#, c-format -+msgid "Exponential backoff\n" -+msgstr "exponentieller Wartezyklus\n" -+ -+#: ../../src/slave/kpropd.c:857 -+#, c-format -+msgid "Full resync permission denied\n" -+msgstr "vollständiges erneutes Synchronisieren nicht gestattet\n" -+ -+#: ../../src/slave/kpropd.c:858 -+msgid "Full resync, permission denied." -+msgstr "vollständiges erneutes Synchronisieren, nicht gestattet" -+ -+#: ../../src/slave/kpropd.c:863 -+#, c-format -+msgid "Full resync error from master\n" -+msgstr "Fehler beim vollständigen erneuten Synchronisieren vom Master\n" -+ -+#: ../../src/slave/kpropd.c:864 -+msgid " Full resync, error returned from master KDC." -+msgstr "" -+"vollständiges erneutes Synchronisieren, das Master-KDC gab einen Fehler " -+"zurück" -+ -+#: ../../src/slave/kpropd.c:872 -+#, c-format -+msgid "Full resync invalid result from master\n" -+msgstr "" -+"Beim vollständigen erneuten Synchronisieren gab der Master ein ungültiges " -+"Ergebnis zurück.\n" -+ -+#: ../../src/slave/kpropd.c:874 -+msgid "Full resync, invalid return from master KDC." -+msgstr "" -+"vollständiges erneutes Synchronisieren, ungültiger Rückgabewert vom Master-" -+"KDC" -+ -+#: ../../src/slave/kpropd.c:890 -+#, c-format -+msgid "Got incremental updates (sno=%u sec=%u usec=%u)\n" -+msgstr "" -+"inkrementelle Aktualisierungen erhalten (sno=%u sec=%u usec=%u)\n" -+ -+#: ../../src/slave/kpropd.c:902 -+#, c-format -+msgid "ulog_replay failed (%s), updates not registered\n" -+msgstr "" -+"»ulog_replay« fehlgeschlagen (%s), Aktualisierungen nicht registriert\n" -+ -+#: ../../src/slave/kpropd.c:905 -+#, c-format -+msgid "ulog_replay failed (%s), updates not registered." -+msgstr "»ulog_replay« fehlgeschlagen (%s), Aktualisierungen nicht registriert" -+ -+#: ../../src/slave/kpropd.c:914 -+#, c-format -+msgid "Incremental updates: %d updates / %lu us" -+msgstr "inkrementelle Aktualisierungen: %d Aktualisierungen / %lu us" -+ -+#: ../../src/slave/kpropd.c:917 -+#, c-format -+msgid "Incremental updates: %d updates / %lu us\n" -+msgstr "inkrementelle Aktualisierungen: %d Aktualisierungen / %lu us\n" -+ -+#: ../../src/slave/kpropd.c:925 -+#, c-format -+msgid "get_updates permission denied\n" -+msgstr "Zugriff bei »get_updates« verweigert\n" -+ -+#: ../../src/slave/kpropd.c:926 -+msgid "get_updates, permission denied." -+msgstr "»get_updates«, Zugriff verweigert" -+ -+#: ../../src/slave/kpropd.c:931 -+#, c-format -+msgid "get_updates error from master\n" -+msgstr "»get_updates«-Fehler vom Master\n" -+ -+#: ../../src/slave/kpropd.c:932 -+msgid "get_updates, error returned from master KDC." -+msgstr "Vom Master-KDC wurde ein »get_updates«-Fehler zurückgegeben." -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:940 -+#, c-format -+msgid "get_updates master busy; backoff\n" -+msgstr "»get_updates«-Master ausgelastet; hält sich zurück\n" -+ -+#: ../../src/slave/kpropd.c:949 -+#, c-format -+msgid "KDC is synchronized with master.\n" -+msgstr "KDC wurde mit dem Master synchronisiert.\n" -+ -+#: ../../src/slave/kpropd.c:957 -+#, c-format -+msgid "get_updates invalid result from master\n" -+msgstr "ungültiges »get_updates«-Ergebnis vom Master\n" -+ -+#: ../../src/slave/kpropd.c:958 -+msgid "get_updates, invalid return from master KDC." -+msgstr "»get_updates«, ungültiger Rückgabewert vom Master-KDC" -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:973 -+#, c-format -+msgid "Busy signal received from master, backoff for %d secs\n" -+msgstr "" -+"Vom Master wurde ein Signal empfangen, dass er ausgelastet ist, " -+"Zurückhaltung für %d Sekunden\n" -+ -+#: ../../src/slave/kpropd.c:980 -+#, c-format -+msgid "Waiting for %d seconds before checking for updates again\n" -+msgstr "" -+"vor der erneuten Prufung auf Aktualisierungen wird %d Sekunden gewartet\n" -+ -+#: ../../src/slave/kpropd.c:991 -+#, c-format -+msgid "ERROR returned by master, bailing\n" -+msgstr "FEHLER vom Master zurückgegeben, Ausstieg\n" -+ -+#: ../../src/slave/kpropd.c:992 -+msgid "ERROR returned by master KDC, bailing.\n" -+msgstr "FEHLER vom Master-KDC zurückgegeben, Ausstieg\n" -+ -+#: ../../src/slave/kpropd.c:1134 -+msgid "copying db args" -+msgstr "Datenbankargumente werden kopiert" -+ -+#: ../../src/slave/kpropd.c:1161 -+msgid "while trying to construct my service name" -+msgstr "beim Versuch, meinen Dienstnamen zu erstellen" -+ -+#: ../../src/slave/kpropd.c:1167 -+msgid "while constructing my service realm" -+msgstr "beim Erstellen meines Dienst-Realms" -+ -+#: ../../src/slave/kpropd.c:1175 -+msgid "while allocating filename for temp file" -+msgstr "beim Reservieren des Dateinamens für die temporäre Datei" -+ -+#: ../../src/slave/kpropd.c:1181 -+msgid "while initializing" -+msgstr "bei der Initialisierung" -+ -+#: ../../src/slave/kpropd.c:1189 -+msgid "Unable to map log!\n" -+msgstr "Protokoll kann nicht abgebildet werden!\n" -+ -+#: ../../src/slave/kpropd.c:1235 -+#, c-format -+msgid "Error in krb5_auth_con_ini: %s" -+msgstr "Fehler in »krb5_auth_con_ini«: %s" -+ -+#: ../../src/slave/kpropd.c:1243 -+#, c-format -+msgid "Error in krb5_auth_con_setflags: %s" -+msgstr "Fehler in »krb5_auth_con_setflags«: %s" -+ -+#: ../../src/slave/kpropd.c:1251 -+#, c-format -+msgid "Error in krb5_auth_con_setaddrs: %s" -+msgstr "Fehler in »krb5_auth_con_setaddrs«: %s" -+ -+#: ../../src/slave/kpropd.c:1259 -+#, c-format -+msgid "Error in krb5_kt_resolve: %s" -+msgstr "Fehler in »krb5_kt_resolve«: %s" -+ -+#: ../../src/slave/kpropd.c:1268 -+#, c-format -+msgid "Error in krb5_recvauth: %s" -+msgstr "Fehler in »krb5_recvauth«: %s" -+ -+#: ../../src/slave/kpropd.c:1275 -+#, c-format -+msgid "Error in krb5_copy_prinicpal: %s" -+msgstr "Fehler in »krb5_copy_prinicpal«: %s" -+ -+#: ../../src/slave/kpropd.c:1291 -+msgid "while unparsing ticket etype" -+msgstr "beim Rückgängigmachen der Auswertung des »etype«s des Tickets" -+ -+#: ../../src/slave/kpropd.c:1295 -+#, c-format -+msgid "authenticated client: %s (etype == %s)\n" -+msgstr "Authentifizierter Client: %s (etype == %s)\n" -+ -+#: ../../src/slave/kpropd.c:1374 -+msgid "while reading size of database from client" -+msgstr "beim Lesen der Datenbankgröße vom Client" -+ -+#: ../../src/slave/kpropd.c:1384 -+msgid "while decoding database size from client" -+msgstr "beim Dekodieren der Datenbankgröße vom Client" -+ -+#: ../../src/slave/kpropd.c:1397 -+msgid "while initializing i_vector" -+msgstr "beim Initialisieren von »i_vector«" -+ -+#: ../../src/slave/kpropd.c:1402 -+#, c-format -+msgid "Full propagation transfer started.\n" -+msgstr "vollständige Verbreitungsübertragung gestartet\n" -+ -+#: ../../src/slave/kpropd.c:1455 -+#, c-format -+msgid "Full propagation transfer finished.\n" -+msgstr "vollständige Verbreitungsübertragung beendet\n" -+ -+#: ../../src/slave/kpropd.c:1516 -+msgid "while decoding error packet from client" -+msgstr "beim Dekodieren des Fehlerpakets vom Client" -+ -+#: ../../src/slave/kpropd.c:1525 -+msgid "signaled from server" -+msgstr "signalisiert vom Server" -+ -+#: ../../src/slave/kpropd.c:1527 -+#, c-format -+msgid "Error text from client: %s\n" -+msgstr "Fehlermeldung vom Client: %s\n" -+ -+#: ../../src/slave/kpropd.c:1576 -+#, c-format -+msgid "while trying to fork %s" -+msgstr "beim Versuch, einen Kindprozess von %s zu erzeugen" -+ -+#: ../../src/slave/kpropd.c:1580 -+#, c-format -+msgid "while trying to exec %s" -+msgstr "beim Versuch, %s auszuführen" -+ -+#: ../../src/slave/kpropd.c:1587 -+#, c-format -+msgid "while waiting for %s" -+msgstr "beim Warten auf %s" -+ -+#: ../../src/slave/kpropd.c:1593 -+#, c-format -+msgid "%s load terminated" -+msgstr "Laden von %s beendet" -+ -+#: ../../src/slave/kpropd.c:1599 -+#, c-format -+msgid "%s returned a bad exit status (%d)" -+msgstr "%s gab einen falschen Exit-Status (%d) zurück" -+ -+#: ../../src/slave/kproplog.c:27 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-h] [-v] [-v] [-e num]\n" -+"\t%s -R\n" -+"\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-h] [-v] [-v] [-e Zahl]\n" -+"\t%s -R\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:129 -+#, c-format -+msgid "" -+"\n" -+"Couldn't allocate memory" -+msgstr "" -+"\n" -+"Speicher konnte nicht reserviert werden" -+ -+#: ../../src/slave/kproplog.c:223 -+#, c-format -+msgid "\t\tAttribute flags\n" -+msgstr "\t\tAttributschalter\n" -+ -+#: ../../src/slave/kproplog.c:228 -+#, c-format -+msgid "\t\tMaximum ticket life\n" -+msgstr "\t\tmaximale Ticketlebensdauer\n" -+ -+#: ../../src/slave/kproplog.c:233 -+#, c-format -+msgid "\t\tMaximum renewable life\n" -+msgstr "\t\tmaximale verlängerbare Lebensdauer\n" -+ -+#: ../../src/slave/kproplog.c:238 -+#, c-format -+msgid "\t\tPrincipal expiration\n" -+msgstr "\t\tAblauf des Principals\n" -+ -+#: ../../src/slave/kproplog.c:243 -+#, c-format -+msgid "\t\tPassword expiration\n" -+msgstr "\t\tAblauf des Passworts\n" -+ -+#: ../../src/slave/kproplog.c:248 -+#, c-format -+msgid "\t\tLast successful auth\n" -+msgstr "\t\tletzte erfolgreiche Authentifizierung\n" -+ -+#: ../../src/slave/kproplog.c:253 -+#, c-format -+msgid "\t\tLast failed auth\n" -+msgstr "\t\tletzte fehlgeschlagene Authentifizierung\n" -+ -+#: ../../src/slave/kproplog.c:258 -+#, c-format -+msgid "\t\tFailed passwd attempt\n" -+msgstr "\t\tfehlgeschlagener Passwortversuch\n" -+ -+#: ../../src/slave/kproplog.c:263 -+#, c-format -+msgid "\t\tPrincipal\n" -+msgstr "\t\tPrincipal\n" -+ -+#: ../../src/slave/kproplog.c:268 -+#, c-format -+msgid "\t\tKey data\n" -+msgstr "\t\tSchlüsseldaten\n" -+ -+#: ../../src/slave/kproplog.c:275 -+#, c-format -+msgid "\t\tTL data\n" -+msgstr "\t\tTL-Daten\n" -+ -+#: ../../src/slave/kproplog.c:282 -+#, c-format -+msgid "\t\tLength\n" -+msgstr "\t\tLänge\n" -+ -+#: ../../src/slave/kproplog.c:287 -+#, c-format -+msgid "\t\tPassword last changed\n" -+msgstr "\t\tletzte Passwortänderung\n" -+ -+#: ../../src/slave/kproplog.c:292 -+#, c-format -+msgid "\t\tModifying principal\n" -+msgstr "\t\ttPrincipal wird geändert\n" -+ -+#: ../../src/slave/kproplog.c:297 -+#, c-format -+msgid "\t\tModification time\n" -+msgstr "\t\tÄnderungszeit\n" -+ -+#: ../../src/slave/kproplog.c:302 -+#, c-format -+msgid "\t\tModified where\n" -+msgstr "\t\tGeändert wobei\n" -+ -+#: ../../src/slave/kproplog.c:307 -+#, c-format -+msgid "\t\tPassword policy\n" -+msgstr "\t\tPasswortrichtlinie\n" -+ -+#: ../../src/slave/kproplog.c:312 -+#, c-format -+msgid "\t\tPassword policy switch\n" -+msgstr "\t\tPasswortrichtlinienumschalter\n" -+ -+#: ../../src/slave/kproplog.c:317 -+#, c-format -+msgid "\t\tPassword history KVNO\n" -+msgstr "\t\tPasswortchronik KVNO\n" -+ -+#: ../../src/slave/kproplog.c:322 -+#, c-format -+msgid "\t\tPassword history\n" -+msgstr "\t\tPasswortchronik\n" -+ -+#: ../../src/slave/kproplog.c:356 -+#, c-format -+msgid "" -+"Corrupt update entry\n" -+"\n" -+msgstr "" -+"beschädigter Aktualisierungseintrag\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:364 -+#, c-format -+msgid "" -+"Entry data decode failure\n" -+"\n" -+msgstr "" -+"Dekodieren der eingetragenen Daten fehlgeschlagen\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:369 -+#, c-format -+msgid "Update Entry\n" -+msgstr "Aktualisierungseintrag\n" -+ -+#: ../../src/slave/kproplog.c:371 -+#, c-format -+msgid "\tUpdate serial # : %u\n" -+msgstr "\tAktualisierung der Seriennummer: %u\n" -+ -+#: ../../src/slave/kproplog.c:373 -+#, c-format -+msgid "\tUpdate operation : " -+msgstr "\tAktualisierungsaktion: " -+ -+#: ../../src/slave/kproplog.c:375 -+#, c-format -+msgid "Delete\n" -+msgstr "Löschen\n" -+ -+#: ../../src/slave/kproplog.c:377 -+#, c-format -+msgid "Add\n" -+msgstr "Hinzufügen\n" -+ -+#: ../../src/slave/kproplog.c:381 -+#, c-format -+msgid "" -+"Could not allocate principal name\n" -+"\n" -+msgstr "" -+"Der Principal-Name konnte nicht reserviert werden.\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:387 -+#, c-format -+msgid "\tUpdate principal : %s\n" -+msgstr "\tAktualisierung des Principals: %s\n" -+ -+#: ../../src/slave/kproplog.c:389 -+#, c-format -+msgid "\tUpdate size : %u\n" -+msgstr "\tGröße der Aktualisierung: %u\n" -+ -+#: ../../src/slave/kproplog.c:390 -+#, c-format -+msgid "\tUpdate committed : %s\n" -+msgstr "\tAktualisierung übergeben: %s\n" -+ -+#: ../../src/slave/kproplog.c:394 -+#, c-format -+msgid "\tUpdate time stamp : None\n" -+msgstr "\tZeitstempel der Aktualisierung: keiner\n" -+ -+#: ../../src/slave/kproplog.c:396 -+#, c-format -+msgid "\tUpdate time stamp : %s" -+msgstr "\tZeitstempel der Aktualisierung: %s" -+ -+#: ../../src/slave/kproplog.c:400 -+#, c-format -+msgid "\tAttributes changed : %d\n" -+msgstr "\tgeänderte Attribute: %d\n" -+ -+#: ../../src/slave/kproplog.c:465 -+#, c-format -+msgid "" -+"Unable to initialize Kerberos\n" -+"\n" -+msgstr "" -+"Kerberos kann nicht initialisiert werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:472 -+#, c-format -+msgid "" -+"Couldn't read database_name\n" -+"\n" -+msgstr "" -+"»database_name« kann nicht gelesen werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:476 -+#, c-format -+msgid "" -+"\n" -+"Kerberos update log (%s)\n" -+msgstr "" -+"\n" -+"Kerberos-Aktualisierungsprotokoll (%s)\n" -+ -+#: ../../src/slave/kproplog.c:480 ../../src/slave/kproplog.c:495 -+#, c-format -+msgid "" -+"Unable to map log file %s\n" -+"\n" -+msgstr "" -+"Protokolldatei %s kann nicht abgebildet werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:485 -+#, c-format -+msgid "" -+"Couldn't reinitialize ulog file %s\n" -+"\n" -+msgstr "" -+"Ulog-Datei %s konnte nicht neu initialisiert werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:489 -+#, c-format -+msgid "Reinitialized the ulog.\n" -+msgstr "Das Ulog wurde neu initialisiert.\n" -+ -+#: ../../src/slave/kproplog.c:501 -+#, c-format -+msgid "" -+"Corrupt header log, exiting\n" -+"\n" -+msgstr "" -+"beschädigtes Kopfzeilenprotokoll, wird beendet\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:505 -+#, c-format -+msgid "Update log dump :\n" -+msgstr "Aktualisierungsprotokollauszug :\n" -+ -+#: ../../src/slave/kproplog.c:506 -+#, c-format -+msgid "\tLog version # : %u\n" -+msgstr "\tProtokollversion #: %u\n" -+ -+#: ../../src/slave/kproplog.c:507 -+#, c-format -+msgid "\tLog state : " -+msgstr "\tProtokollstatus: " -+ -+#: ../../src/slave/kproplog.c:510 -+#, c-format -+msgid "Stable\n" -+msgstr "stabil\n" -+ -+#: ../../src/slave/kproplog.c:513 -+#, c-format -+msgid "Unstable\n" -+msgstr "instabil\n" -+ -+#: ../../src/slave/kproplog.c:516 -+#, c-format -+msgid "Corrupt\n" -+msgstr "beschädigt\n" -+ -+#: ../../src/slave/kproplog.c:519 -+#, c-format -+msgid "Unknown state: %d\n" -+msgstr "unbekannter Status: %d\n" -+ -+#: ../../src/slave/kproplog.c:522 -+#, c-format -+msgid "\tEntry block size : %u\n" -+msgstr "\tBlockgrößeneintrag: %u\n" -+ -+#: ../../src/slave/kproplog.c:523 -+#, c-format -+msgid "\tNumber of entries : %u\n" -+msgstr "\tAnzahl der Einträge: %u\n" -+ -+#: ../../src/slave/kproplog.c:526 -+#, c-format -+msgid "\tLast serial # : None\n" -+msgstr "\tletzte Seriennummer: keine\n" -+ -+#: ../../src/slave/kproplog.c:529 -+#, c-format -+msgid "\tFirst serial # : None\n" -+msgstr "\terste Seriennummer: keine\n" -+ -+#: ../../src/slave/kproplog.c:531 -+#, c-format -+msgid "\tFirst serial # : " -+msgstr "\terste Seriennummer: " -+ -+#: ../../src/slave/kproplog.c:535 -+#, c-format -+msgid "\tLast serial # : " -+msgstr "\tletzte Seriennummer: " -+ -+#: ../../src/slave/kproplog.c:540 -+#, c-format -+msgid "\tLast time stamp : None\n" -+msgstr "\tletzter Zeitstempel: keiner\n" -+ -+#: ../../src/slave/kproplog.c:543 -+#, c-format -+msgid "\tFirst time stamp : None\n" -+msgstr "\terster Zeitstempel: keiner\n" -+ -+#: ../../src/slave/kproplog.c:545 -+#, c-format -+msgid "\tFirst time stamp : %s" -+msgstr "\terster Zeitstempel: %s" -+ -+#: ../../src/slave/kproplog.c:549 -+#, c-format -+msgid "\tLast time stamp : %s\n" -+msgstr "\tletzter Zeitstempel: %s\n" -+ -+#: ../../src/util/support/errors.c:77 -+msgid "Kerberos library initialization failure" -+msgstr "Initialisieren der Kerberos-Bibliothek fehlgeschlagen" -+ -+#: ../../src/util/support/errors.c:93 -+#, c-format -+msgid "error %ld" -+msgstr "Fehler %ld" -+ -+#: ../../src/util/support/plugins.c:186 -+#, c-format -+msgid "unable to find plugin [%s]: %s" -+msgstr "Erweiterung [%s] konnte nicht gefunden werden: %s" -+ -+#: ../../src/util/support/plugins.c:274 -+msgid "unknown failure" -+msgstr "unbekannter Fehlschlag" -+ -+#: ../../src/util/support/plugins.c:277 -+#, c-format -+msgid "unable to load plugin [%s]: %s" -+msgstr "Erweiterung [%s] konnte nicht geladen werden: %s" -+ -+#: ../../src/util/support/plugins.c:300 -+#, c-format -+msgid "unable to load DLL [%s]" -+msgstr "DLL [%s] konnte nicht geladen werden" -+ -+#: ../../src/util/support/plugins.c:316 -+#, c-format -+msgid "plugin unavailable: %s" -+msgstr "Erweiterung nicht verfügbar: %s" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:23 -+msgid "No @ in SERVICE-NAME name string" -+msgstr "keine @ in der Namenszeichenkette SERVICE-NAME" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:24 -+msgid "STRING-UID-NAME contains nondigits" -+msgstr "STRING-UID-NAME enthält etwas anderes als Ziffern" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:25 -+msgid "UID does not resolve to username" -+msgstr "UID lässt sich nicht zu Benutzernamen ermitteln" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:26 -+msgid "Validation error" -+msgstr "Überprüfungsfehler" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:27 -+msgid "Couldn't allocate gss_buffer_t data" -+msgstr "»gss_buffer_t«-Daten konnten reserviert werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:28 -+msgid "Message context invalid" -+msgstr "Nachrichtenkontext ungültig" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:29 -+msgid "Buffer is the wrong size" -+msgstr "Puffer hat die falsche Größe" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:30 -+msgid "Credential usage type is unknown" -+msgstr "Typ des Anmeldedatenaufrufs ist unbekannt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:31 -+msgid "Unknown quality of protection specified" -+msgstr "unbekannte Schutzqualität angegeben" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:32 -+msgid "Local host name could not be determined" -+msgstr "lokaler Rechnername konnte nicht bestimmt werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:33 -+msgid "Hostname in SERVICE-NAME string could not be canonicalized" -+msgstr "" -+"Rechnername in der Zeichenkette »SERVICE-NAME« konnte nicht in Normalform " -+"gebracht werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:34 -+msgid "Mechanism is incorrect" -+msgstr "Mechanismus ist nicht korrekt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:35 -+msgid "Token header is malformed or corrupt" -+msgstr "Token-Kopfzeilen haben die falsche Form oder sind beschädigt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:36 -+msgid "Packet was replayed in wrong direction" -+msgstr "Paket wurde in falscher Richtung erneut abgespielt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:37 -+msgid "Token is missing data" -+msgstr "dem Token fehlen Daten" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:38 -+msgid "Token was reflected" -+msgstr "Token wurde zurückgeworfen" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:39 -+msgid "Received token ID does not match expected token ID" -+msgstr "Die empfangene Token-Kennung passt nicht zur erwarteten Token-Kennung." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:40 -+msgid "The given credential's usage does not match the requested usage" -+msgstr "" -+"Die Verwendung der angegebenen Anmeldedaten passt nicht zur angeforderten " -+"Verwendung." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:41 -+msgid "Storing of acceptor credentials is not supported by the mechanism" -+msgstr "" -+"Das Speichern von Abnehmeranmeldedaten wird nicht durch den Mechanismus " -+"unterstützt." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:42 -+msgid "Storing of non-default credentials is not supported by the mechanism" -+msgstr "" -+"Das Speichern von Nichtstandardanmeldedaten wird nicht durch den Mechanismus " -+"unterstützt." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:23 -+msgid "Principal in credential cache does not match desired name" -+msgstr "" -+"Principal im Anmeldedatenzwischenspeicher entspricht nicht dem gewünschten " -+"Namen" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:24 -+msgid "No principal in keytab matches desired name" -+msgstr "Kein Principal in der Schlüsseltabelle passt zum gewünschten Namen." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:25 -+msgid "Credential cache has no TGT" -+msgstr "Anmeldedatenzwischenspeicher hat kein TGT" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:26 -+msgid "Authenticator has no subkey" -+msgstr "Schlüsselziffer hat keinen Unterschlüssel" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:27 -+msgid "Context is already fully established" -+msgstr "Kontext wurde bereits vollständig eingerichtet" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:28 -+msgid "Unknown signature type in token" -+msgstr "unbekannter Signaturtyp im Token" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:29 -+msgid "Invalid field length in token" -+msgstr "falsche Feldlänge im Token" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:30 -+msgid "Attempt to use incomplete security context" -+msgstr "" -+"Es wurde versucht, einen unvollständigen Sicherheitskontext zu verwenden." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:31 -+msgid "Bad magic number for krb5_gss_ctx_id_t" -+msgstr "falsche magische Zahl für »krb5_gss_ctx_id_t«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:32 -+msgid "Bad magic number for krb5_gss_cred_id_t" -+msgstr "falsche magische Zahl für »krb5_gss_cred_id_t«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:33 -+msgid "Bad magic number for krb5_gss_enc_desc" -+msgstr "falsche magische Zahl für »krb5_gss_enc_desc«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:34 -+msgid "Sequence number in token is corrupt" -+msgstr "Sequnznummer im Token ist beschädigt" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:35 -+msgid "Credential cache is empty" -+msgstr "Anmeldedatenzwischenspeicher ist leer" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:36 -+msgid "Acceptor and Initiator share no checksum types" -+msgstr "Abnehmer und Initiator haben keinen gemeinsamen Prüfsummentyp" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:37 -+msgid "Requested lucid context version not supported" -+msgstr "angeforderte »lucid«-Kontextversion nicht unterstützt" -+ -+# PRF = Pseudo Random Function -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:38 -+msgid "PRF input too long" -+msgstr "PRF-Eingabe zu lang" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:39 -+msgid "Bad magic number for iakerb_ctx_id_t" -+msgstr "falsche magische Zahl für »iakerb_ctx_id_t«" -+ -+#: ../lib/kadm5/chpass_util_strings.c:23 -+msgid "while getting policy info." -+msgstr "beim Holen der Richtlinieninformation." -+ -+#: ../lib/kadm5/chpass_util_strings.c:24 -+msgid "while getting principal info." -+msgstr "beim Holen der Principal-Information." -+ -+#: ../lib/kadm5/chpass_util_strings.c:25 -+msgid "New passwords do not match - password not changed.\n" -+msgstr "neue Passwörter stimmen nicht überein – Passwort nicht geändert\n" -+ -+#: ../lib/kadm5/chpass_util_strings.c:26 -+msgid "New password" -+msgstr "neues Passwort" -+ -+#: ../lib/kadm5/chpass_util_strings.c:27 -+msgid "New password (again)" -+msgstr "neues Passwort (erneut)" -+ -+#: ../lib/kadm5/chpass_util_strings.c:28 -+msgid "" -+"You must type a password. Passwords must be at least one character long.\n" -+msgstr "" -+"Sie müssen ein Passwort eingeben. Passwörter müssen mindestens ein Zeichen " -+"lang sein.\n" -+ -+#: ../lib/kadm5/chpass_util_strings.c:29 -+msgid "yet no policy set! Contact your system security administrator." -+msgstr "" -+"noch keine Richtlinie gesetzt! Kontaktieren Sie Ihren " -+"Systemsicherheitsadministrator" -+ -+#: ../lib/kadm5/chpass_util_strings.c:31 -+msgid "" -+"New password was found in a dictionary of possible passwords and\n" -+"therefore may be easily guessed. Please choose another password.\n" -+"See the kpasswd man page for help in choosing a good password." -+msgstr "" -+"Das neue Passwort wurde in einem Wörterbuch mit möglichen Passwörtern " -+"gefunden\n" -+"und kann daher leicht erraten werden. Bitte wählen Sie ein anderes " -+"Passwort.\n" -+"Hilfe bei der Wahl guter Passwörter finden Sie in der Handbuchseite von\n" -+"»kpasswd«." -+ -+#: ../lib/kadm5/chpass_util_strings.c:32 -+msgid "Password not changed." -+msgstr "Passwort nicht geändert" -+ -+#: ../lib/kadm5/chpass_util_strings.c:33 -+#, c-format -+msgid "" -+"New password is too short.\n" -+"Please choose a password which is at least %d characters long." -+msgstr "" -+"Das neue Passwort ist zu kurz.\n" -+"Bitte wählen Sie ein Passwort, das mindestens %d Zeichen lang ist." -+ -+#: ../lib/kadm5/chpass_util_strings.c:34 -+#, c-format -+msgid "" -+"New password does not have enough character classes.\n" -+"The character classes are:\n" -+"\t- lower-case letters,\n" -+"\t- upper-case letters,\n" -+"\t- digits,\n" -+"\t- punctuation, and\n" -+"\t- all other characters (e.g., control characters).\n" -+"Please choose a password with at least %d character classes." -+msgstr "" -+"Das neue Passwort besteht aus zu wenigen Zeichenklassen.\n" -+"Die Zeichenklassen sind:\n" -+"\t- Kleinbuchstaben,\n" -+"\t- Großbuchstaben,\n" -+"\t- Ziffern,\n" -+"\t- Satzzeichen und\n" -+"\t- alle anderen Zeichen (z.B. Steuerzeichen).\n" -+"Bitte wählen Sie ein Passwort mit mindestens %d Zeichenklassen." -+ -+#: ../lib/kadm5/chpass_util_strings.c:35 -+#, c-format -+msgid "" -+"Password cannot be changed because it was changed too recently.\n" -+"Please wait until %s before you change it.\n" -+"If you need to change your password before then, contact your system\n" -+"security administrator." -+msgstr "" -+"Das Passwort kann nicht geändert werden, da es erst vor kurzem geändert " -+"wurde.\n" -+"Bitte warten Sie bis %s, ehe Sie es ändern.\n" -+"Falls Sie es vorher ändern müssen, kontaktieren Sie Ihren\n" -+"Systemsicherheitsadministrator." -+ -+#: ../lib/kadm5/chpass_util_strings.c:36 -+msgid "New password was used previously. Please choose a different password." -+msgstr "" -+"Das neue Passwort wurde zuvor schon benutzt. Bitte wählen Sie ein anderes " -+"Passwort." -+ -+#: ../lib/kadm5/chpass_util_strings.c:37 -+msgid "while trying to change password." -+msgstr "beim Versuch, das Passwort zu ändern." -+ -+#: ../lib/kadm5/chpass_util_strings.c:38 -+msgid "while reading new password." -+msgstr "beim Lesen des neuen Passworts." -+ -+#: ../lib/kadm5/kadm_err.c:23 -+msgid "Operation failed for unspecified reason" -+msgstr "Aktion aus nicht näher beschriebenem Grund fehlgeschlagen" -+ -+#: ../lib/kadm5/kadm_err.c:24 -+msgid "Operation requires ``get'' privilege" -+msgstr "Aktion erfordert »get«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:25 -+msgid "Operation requires ``add'' privilege" -+msgstr "Aktion erfordert »add«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:26 -+msgid "Operation requires ``modify'' privilege" -+msgstr "Aktion erfordert »modify«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:27 -+msgid "Operation requires ``delete'' privilege" -+msgstr "Aktion erfordert »delete«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:28 -+msgid "Insufficient authorization for operation" -+msgstr "unzureichende Berechtigung für diese Aktion" -+ -+#: ../lib/kadm5/kadm_err.c:29 ../lib/kdb/adb_err.c:29 -+msgid "Database inconsistency detected" -+msgstr "Datenbankinkonsistenz entdeckt" -+ -+#: ../lib/kadm5/kadm_err.c:30 ../lib/kdb/adb_err.c:24 -+msgid "Principal or policy already exists" -+msgstr "Principal oder Richtlinie existiert bereits" -+ -+#: ../lib/kadm5/kadm_err.c:31 -+msgid "Communication failure with server" -+msgstr "Kommunikation mit dem Server fehlgeschlagen" -+ -+#: ../lib/kadm5/kadm_err.c:32 -+msgid "No administration server found for realm" -+msgstr "kein Administrationsserver für den Realm gefunden" -+ -+#: ../lib/kadm5/kadm_err.c:33 -+msgid "Password history principal key version mismatch" -+msgstr "Die Passwortchronikschlüssel des Principals passen nicht zusammen." -+ -+#: ../lib/kadm5/kadm_err.c:34 -+msgid "Connection to server not initialized" -+msgstr "Verbindung zum Server nicht initialisiert" -+ -+#: ../lib/kadm5/kadm_err.c:35 -+msgid "Principal does not exist" -+msgstr "Principal existiert nicht" -+ -+#: ../lib/kadm5/kadm_err.c:36 -+msgid "Policy does not exist" -+msgstr "Richtlinie existiert nicht" -+ -+#: ../lib/kadm5/kadm_err.c:37 -+msgid "Invalid field mask for operation" -+msgstr "ungültige Feldmaske für Aktion" -+ -+#: ../lib/kadm5/kadm_err.c:38 -+msgid "Invalid number of character classes" -+msgstr "ungültige Anzahl von Zeichenklassen" -+ -+#: ../lib/kadm5/kadm_err.c:39 -+msgid "Invalid password length" -+msgstr "ungültige Passwortlänge" -+ -+#: ../lib/kadm5/kadm_err.c:40 -+msgid "Illegal policy name" -+msgstr "unzulässiger Richtlinienname" -+ -+#: ../lib/kadm5/kadm_err.c:41 -+msgid "Illegal principal name" -+msgstr "unzulässiger Principal-Name" -+ -+# FIXME s/auxillary/auxilary/ -+#: ../lib/kadm5/kadm_err.c:42 -+msgid "Invalid auxillary attributes" -+msgstr "ungültige Zusatzattribute" -+ -+#: ../lib/kadm5/kadm_err.c:43 -+msgid "Invalid password history count" -+msgstr "ungültige Passwortchronikanzahl" -+ -+#: ../lib/kadm5/kadm_err.c:44 -+msgid "Password minimum life is greater than password maximum life" -+msgstr "Die minimale Lebensdauer des Passworts ist größer als die maximale." -+ -+#: ../lib/kadm5/kadm_err.c:45 -+msgid "Password is too short" -+msgstr "Das Passwort ist zu kurz." -+ -+#: ../lib/kadm5/kadm_err.c:46 -+msgid "Password does not contain enough character classes" -+msgstr "Das Passwort enthält nicht genug Zeichenklassen." -+ -+#: ../lib/kadm5/kadm_err.c:47 -+msgid "Password is in the password dictionary" -+msgstr "Das Passwort steht im Passwortwörterbuch." -+ -+#: ../lib/kadm5/kadm_err.c:48 -+msgid "Cannot reuse password" -+msgstr "Das Passwort kann nicht erneut verwendet werden." -+ -+#: ../lib/kadm5/kadm_err.c:49 -+msgid "Current password's minimum life has not expired" -+msgstr "Die aktuell minimale Lebensdauer des Passworts ist nicht abgelaufen." -+ -+#: ../lib/kadm5/kadm_err.c:50 ../lib/krb5/error_tables/kdb5_err.c:67 -+msgid "Policy is in use" -+msgstr "Richtlinie ist in Benutzung" -+ -+#: ../lib/kadm5/kadm_err.c:51 -+msgid "Connection to server already initialized" -+msgstr "Verbindung zum Server ist bereits initialisiert" -+ -+#: ../lib/kadm5/kadm_err.c:52 -+msgid "Incorrect password" -+msgstr "falsches Passwort" -+ -+#: ../lib/kadm5/kadm_err.c:53 -+msgid "Cannot change protected principal" -+msgstr "geschützter Principal kann nicht geändert werden" -+ -+#: ../lib/kadm5/kadm_err.c:54 -+msgid "Programmer error! Bad Admin server handle" -+msgstr "Fehler des Programmierers! Falscher Admin-Server-Identifikator" -+ -+#: ../lib/kadm5/kadm_err.c:55 -+msgid "Programmer error! Bad API structure version" -+msgstr "Fehler des Programmierers! Falsche API-Strukturversion" -+ -+#: ../lib/kadm5/kadm_err.c:56 -+msgid "" -+"API structure version specified by application is no longer supported (to " -+"fix, recompile application against current KADM5 API header files and " -+"libraries)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"unterstützt. (Kompilieren Sie die Anwendung mit den aktuellen KADM5-API-" -+"Header-Dateien und -Bibliotheken, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:57 -+msgid "" -+"API structure version specified by application is unknown to libraries (to " -+"fix, obtain current KADM5 API header files and libraries and recompile " -+"application)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur ist den " -+"Bibliotheken unbekannt. (Besorgen Sie sich die aktuellen KADM5-API-Header-" -+"Dateien und -Bibliotheken und kompilieren Sie die Anwendung neu, um dies zu " -+"beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:58 -+msgid "Programmer error! Bad API version" -+msgstr "Fehler des Programmierers! Falsche API-Version" -+ -+#: ../lib/kadm5/kadm_err.c:59 -+msgid "" -+"API version specified by application is no longer supported by libraries (to " -+"fix, update application to adhere to current API version and recompile)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"von den Bibliotheken unterstützt. (Aktualisieren Sie die Anwendung, dass sie " -+"zu der aktuellen API-Version passt, und kompilieren Sie sie, um dies zu " -+"beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:60 -+msgid "" -+"API version specified by application is no longer supported by server (to " -+"fix, update application to adhere to current API version and recompile)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"vom Server unterstützt. (Aktualisieren Sie die Anwendung, dass sie zu der " -+"aktuellen API-Version passt, und kompilieren Sie sie, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:61 -+msgid "" -+"API version specified by application is unknown to libraries (to fix, obtain " -+"current KADM5 API header files and libraries and recompile application)" -+msgstr "" -+"Die von der Anwendung angegebenene API-Version ist den Bibliotheken " -+"unbekannt. (Besorgen Sie sich die aktuellen KADM5-API-Header-Dateien und -" -+"Bibliotheken und kompilieren Sie die Anwendung neu, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:62 -+msgid "" -+"API version specified by application is unknown to server (to fix, obtain " -+"and install newest KADM5 Admin Server)" -+msgstr "" -+"Die von der Anwendung angegebene API-Version ist dem Server unbekannt. " -+"(Besorgen und installieren Sie sich den neuesten KADM5-Admin-Server, um dies " -+"zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:63 -+msgid "Database error! Required KADM5 principal missing" -+msgstr "Datenbankfehler! Erforderlicher KADM5-Principal fehlt" -+ -+#: ../lib/kadm5/kadm_err.c:64 -+msgid "The salt type of the specified principal does not support renaming" -+msgstr "Der Salt-Typ des angegebenen Principals unterstützt kein Umbenennen." -+ -+#: ../lib/kadm5/kadm_err.c:65 -+msgid "Illegal configuration parameter for remote KADM5 client" -+msgstr "widerrechtlicher Konfigurationsparameter für fernen KADM5-Client" -+ -+#: ../lib/kadm5/kadm_err.c:66 -+msgid "Illegal configuration parameter for local KADM5 client" -+msgstr "widerrechtlicher Konfigurationsparameter für lokalen KADM5-Client" -+ -+#: ../lib/kadm5/kadm_err.c:67 -+msgid "Operation requires ``list'' privilege" -+msgstr "Aktion erfordert das »list«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:68 -+msgid "Operation requires ``change-password'' privilege" -+msgstr "Aktion erfordert das »change-password«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:69 -+msgid "GSS-API (or Kerberos) error" -+msgstr "GSS-API- (oder Kerberos-) Fehler" -+ -+#: ../lib/kadm5/kadm_err.c:70 -+msgid "Programmer error! Illegal tagged data list type" -+msgstr "" -+"Fehler des Programmierers! Widerrechlicher Listentyp für gekennzeichnete " -+"Daten" -+ -+#: ../lib/kadm5/kadm_err.c:71 -+msgid "Required parameters in kdc.conf missing" -+msgstr "erforderliche Parameter in »kdc.conf« fehlen" -+ -+#: ../lib/kadm5/kadm_err.c:72 -+msgid "Bad krb5 admin server hostname" -+msgstr "falscher Rechnername des KRB5-Admin-Servers" -+ -+#: ../lib/kadm5/kadm_err.c:73 -+msgid "Operation requires ``set-key'' privilege" -+msgstr "Aktion erfordert das »set-key«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:74 -+msgid "Multiple values for single or folded enctype" -+msgstr "" -+"mehrere Werte für einzelnen Verschlüsselungstyp oder Verschlüsselungstyp mit " -+"Salt" -+ -+#: ../lib/kadm5/kadm_err.c:75 -+msgid "Invalid enctype for setv4key" -+msgstr "widerrechtlicher Verschlüsselungstyp für Setv4key" -+ -+#: ../lib/kadm5/kadm_err.c:76 -+msgid "Mismatched enctypes for setkey3" -+msgstr "nicht zusammenpassende Verschlüsselungstypen für Setkey3" -+ -+#: ../lib/kadm5/kadm_err.c:77 -+msgid "Missing parameters in krb5.conf required for kadmin client" -+msgstr "für Kadmin-Client benötigte Parameter fehlen in »krb5.conf«" -+ -+#: ../lib/kadm5/kadm_err.c:78 ../lib/kdb/adb_err.c:30 -+msgid "XDR encoding error" -+msgstr "XDR-Verschlüsselungsfehler" -+ -+#: ../lib/kadm5/kadm_err.c:79 -+msgid "Cannot resolve network address for admin server in requested realm" -+msgstr "" -+"Die Netzwerkadresse für den Admin-Server im angeforderten Realm kann nicht " -+"aufgelöst werden." -+ -+#: ../lib/kadm5/kadm_err.c:80 -+msgid "Unspecified password quality failure" -+msgstr "nicht näher angegebener Passwortqualitätsfehlschlag" -+ -+#: ../lib/kadm5/kadm_err.c:81 -+msgid "Invalid key/salt tuples" -+msgstr "ungültige Schlüssel-/Salt-Tupel" -+ -+#: ../lib/kdb/adb_err.c:23 -+msgid "No Error" -+msgstr "kein Fehler" -+ -+#: ../lib/kdb/adb_err.c:25 -+msgid "Principal or policy does not exist" -+msgstr "Principal oder Richtlinie existiert nicht" -+ -+#: ../lib/kdb/adb_err.c:26 -+msgid "Database not initialized" -+msgstr "Datenbank nicht initialisiert" -+ -+#: ../lib/kdb/adb_err.c:27 -+msgid "Invalid policy name" -+msgstr "ungültiger Richtlinienname" -+ -+#: ../lib/kdb/adb_err.c:28 -+msgid "Invalid principal name" -+msgstr "ungültiger Principal-Name" -+ -+#: ../lib/kdb/adb_err.c:31 -+msgid "Failure!" -+msgstr "Fehlschlag!" -+ -+#: ../lib/kdb/adb_err.c:32 -+msgid "Bad lock mode" -+msgstr "falscher Sperrmodus" -+ -+#: ../lib/kdb/adb_err.c:33 -+msgid "Cannot lock database" -+msgstr "Datenbank kann nicht gesperrt werden" -+ -+#: ../lib/kdb/adb_err.c:34 -+msgid "Database not locked" -+msgstr "Datenbank nicht gesperrt" -+ -+#: ../lib/kdb/adb_err.c:35 -+msgid "KADM5 administration database lock file missing" -+msgstr "Sperrdatei der KADM5-Verwaltungsdatenbank fehlt" -+ -+#: ../lib/kdb/adb_err.c:36 -+msgid "Insufficient permission to lock file" -+msgstr "keine ausreichenden Rechte zum Sperren der Datei" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:23 -+msgid "Plugin does not support interface version" -+msgstr "Erweiterung unterstützt nicht die Schnittstellenversion" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:24 -+msgid "Invalid module specifier" -+msgstr "ungültige Modulangabe" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:25 -+msgid "Plugin module name not found" -+msgstr "Erweiterungsmodulname nicht gefunden" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:26 -+msgid "The KDC should discard this request" -+msgstr "Das KDC sollte diese Anfrage verwerfen" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:27 -+msgid "Can't create new subsidiary cache" -+msgstr "Der neue ergänzende Zwischenspeicher kann nicht erzeugt werden" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:28 -+msgid "Invalid keyring anchor name" -+msgstr "ungültiger Schlüsselbundverankerungsname" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:29 -+msgid "Unknown keyring collection version" -+msgstr "unbekannte Schlüsselbundsammlungsversion" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:30 -+msgid "Invalid UID in persistent keyring name" -+msgstr "ungültige UID im beständigen Schlüsselbundnamen" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:31 -+msgid "Malformed reply from KCM daemon" -+msgstr "Antwort des KCM-Daemons hat die falsche Form" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:32 -+msgid "Mach RPC error communicating with KCM daemon" -+msgstr "Mach-RPC-Fehler beim der Kommunikation mit dem KCM-Daemon" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:33 -+msgid "KCM daemon reply too big" -+msgstr "Antwort des KCM-Daemons zu groß" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:34 -+msgid "No KCM server found" -+msgstr "Kein KCM-Server gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:24 -+msgid "Client's entry in database has expired" -+msgstr "Eintrag des Clients in der Datenbank ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:25 -+msgid "Server's entry in database has expired" -+msgstr "Eintrag des Servers in der Datenbank ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:26 -+msgid "Requested protocol version not supported" -+msgstr "angeforderte Protokollversion nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:27 -+msgid "Client's key is encrypted in an old master key" -+msgstr "" -+"Der Schlüssel des Clients wurde mit einem alten Hauptschlüssel verschlüsselt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:28 -+msgid "Server's key is encrypted in an old master key" -+msgstr "" -+"Der Schlüssel des Servers wurde mit einem alten Hauptschlüssel verschlüsselt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:29 -+msgid "Client not found in Kerberos database" -+msgstr "Client nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:30 -+msgid "Server not found in Kerberos database" -+msgstr "Server nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:31 -+msgid "Principal has multiple entries in Kerberos database" -+msgstr "Principal hat in der Kerberos-Datenbank mehrere Einträge" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:32 -+msgid "Client or server has a null key" -+msgstr "Client oder Server hat einen Nullschlüssel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:33 -+msgid "Ticket is ineligible for postdating" -+msgstr "Ticket ist zum Vordatieren ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:34 -+msgid "Requested effective lifetime is negative or too short" -+msgstr "Die angeforderte effektive Lebensdauer ist negativ oder zu kurz." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:35 -+msgid "KDC policy rejects request" -+msgstr "KDC-Richtlinie weist die Anfrage zurück" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:36 -+msgid "KDC can't fulfill requested option" -+msgstr "KDC kann erforderliche Option nicht erfüllen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:37 -+msgid "KDC has no support for encryption type" -+msgstr "KDC unterstützt diesen Verschlüsselungstyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:38 -+msgid "KDC has no support for checksum type" -+msgstr "KDC unterstützt diesen Prüfsummentyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:39 -+msgid "KDC has no support for padata type" -+msgstr "KDC unterstützt diesen Padata-Typ nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:40 -+msgid "KDC has no support for transited type" -+msgstr "KDC unterstützt diesen Übergangstyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:41 -+msgid "Clients credentials have been revoked" -+msgstr "Anmeldedaten des Clients wurden widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:42 -+msgid "Credentials for server have been revoked" -+msgstr "Anmeldedaten für den Server wurden widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:43 -+msgid "TGT has been revoked" -+msgstr "TGT wurde widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:44 -+msgid "Client not yet valid - try again later" -+msgstr "Client noch nicht gültig – versuchen Sie es später noch einmal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:45 -+msgid "Server not yet valid - try again later" -+msgstr "Server noch nicht gültig – versuchen Sie es später noch einmal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:46 -+msgid "Password has expired" -+msgstr "Passwort ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:47 -+msgid "Preauthentication failed" -+msgstr "Vorauthentifizierung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:48 -+msgid "Additional pre-authentication required" -+msgstr "zusätzlich Vorauthentifizierung erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:49 -+msgid "Requested server and ticket don't match" -+msgstr "abgefragter Server und Ticket passen nicht zusammen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:50 -+msgid "Server principal valid for user2user only" -+msgstr "Der Server-Principal ist nur für »user2user« gültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:51 -+msgid "KDC policy rejects transited path" -+msgstr "KDC-Richtlinie verwirft durchgereichten Pfad" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:52 -+msgid "A service is not available that is required to process the request" -+msgstr "" -+"Ein Dienst, der zum Verarbeiten der Abfrage erforderlich ist, ist nicht " -+"verfügbar." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:53 -+msgid "KRB5 error code 30" -+msgstr "KRB5-Fehlercode 30" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:54 -+msgid "Decrypt integrity check failed" -+msgstr "Entschlüsselungsintegritätsprüfung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:55 -+msgid "Ticket expired" -+msgstr "Ticket abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:56 -+msgid "Ticket not yet valid" -+msgstr "Ticket noch nicht gültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:57 -+msgid "Request is a replay" -+msgstr "Anfrage ist eine Wiederholung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:58 -+msgid "The ticket isn't for us" -+msgstr "Das Ticket ist nicht für uns." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:59 -+msgid "Ticket/authenticator don't match" -+msgstr "Ticket/Schlüsselziffer passen nicht zueinander" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:60 -+msgid "Clock skew too great" -+msgstr "Uhrzeitabweichung zu groß" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:61 -+msgid "Incorrect net address" -+msgstr "falsche Netzwerkadresse" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:62 -+msgid "Protocol version mismatch" -+msgstr "Protokollversion passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:63 -+msgid "Invalid message type" -+msgstr "ungültiger Nachrichtentyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:64 -+msgid "Message stream modified" -+msgstr "Nachrichtendatenstrom geändert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:65 -+msgid "Message out of order" -+msgstr "Nachricht nicht in Ordnung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:66 -+msgid "Illegal cross-realm ticket" -+msgstr "Widerrechliches Realm-übergreifendes Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:67 -+msgid "Key version is not available" -+msgstr "Schlüsselversion ist nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:68 -+msgid "Service key not available" -+msgstr "Dienstschlüssel nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:69 -+#: ../lib/krb5/error_tables/krb5_err.c:181 -+msgid "Mutual authentication failed" -+msgstr "gegenseitige Authentifizierung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:70 -+msgid "Incorrect message direction" -+msgstr "falsche Nachrichtenrichtung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:71 -+msgid "Alternative authentication method required" -+msgstr "alternative Authentifizierungsmethode erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:72 -+msgid "Incorrect sequence number in message" -+msgstr "falsche Sequenznummer in der Nachricht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:73 -+msgid "Inappropriate type of checksum in message" -+msgstr "ungeeigneter Prüfsummentyp in der Nachricht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:74 -+msgid "Policy rejects transited path" -+msgstr "Richtlinie verwirft durchgereichten Pfad" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:75 -+msgid "Response too big for UDP, retry with TCP" -+msgstr "Antwort für UDP zu groß, erneuter Versuch mit TCP" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:76 -+msgid "KRB5 error code 53" -+msgstr "KRB5-Fehlercode 53" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:77 -+msgid "KRB5 error code 54" -+msgstr "KRB5-Fehlercode 54" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:78 -+msgid "KRB5 error code 55" -+msgstr "KRB5-Fehlercode 55" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:79 -+msgid "KRB5 error code 56" -+msgstr "KRB5-Fehlercode 56" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:80 -+msgid "KRB5 error code 57" -+msgstr "KRB5-Fehlercode 57" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:81 -+msgid "KRB5 error code 58" -+msgstr "KRB5-Fehlercode 58" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:82 -+msgid "KRB5 error code 59" -+msgstr "KRB5-Fehlercode 59" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:83 -+msgid "Generic error (see e-text)" -+msgstr "allgemeiner Fehler (siehe E-Text)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:84 -+msgid "Field is too long for this implementation" -+msgstr "Feld ist für diese Implementierung zu lang" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:85 -+msgid "Client not trusted" -+msgstr "Client nicht vertrauenswürdig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:86 -+msgid "KDC not trusted" -+msgstr "KDC nicht vertrauenswürdig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:87 -+msgid "Invalid signature" -+msgstr "ungültige Signatur" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:88 -+msgid "Key parameters not accepted" -+msgstr "Schlüsselparameter nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:89 -+msgid "Certificate mismatch" -+msgstr "Zertifikat passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:90 -+msgid "No ticket granting ticket" -+msgstr "kein ticketgewährendes Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:91 -+msgid "Realm not local to KDC" -+msgstr "Realm für KDC nicht lokal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:92 -+msgid "User to user required" -+msgstr "Benutzer-zu-Benutzer erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:93 -+msgid "Can't verify certificate" -+msgstr "Zertifikat kann nicht überprüft werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:94 -+msgid "Invalid certificate" -+msgstr "ungültiges Zertifikat" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:95 -+msgid "Revoked certificate" -+msgstr "widerrufenes Zertifikat" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:96 -+msgid "Revocation status unknown" -+msgstr "Widerrufsstatus unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:97 -+msgid "Revocation status unavailable" -+msgstr "Widerrufsstatus nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:98 -+msgid "Client name mismatch" -+msgstr "Client-Name passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:99 -+msgid "KDC name mismatch" -+msgstr "KDC-Name passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:100 -+msgid "Inconsistent key purpose" -+msgstr "inkonstistenter Schlüsselzweck" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:101 -+msgid "Digest in certificate not accepted" -+msgstr "Kurzfassung im Zertifikat nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:102 -+msgid "Checksum must be included" -+msgstr "Prüfsumme muss enthalten sein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:103 -+msgid "Digest in signed-data not accepted" -+msgstr "Kurzfassung in signierten Daten nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:104 -+msgid "Public key encryption not supported" -+msgstr "Asymetrische Verschlüsselung nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:105 -+msgid "KRB5 error code 82" -+msgstr "KRB5-Fehlercode 82" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:106 -+msgid "KRB5 error code 83" -+msgstr "KRB5-Fehlercode 83" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:107 -+msgid "KRB5 error code 84" -+msgstr "KRB5-Fehlercode 84" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:108 -+msgid "The IAKERB proxy could not find a KDC" -+msgstr "Der IAKERB-Proxy konnte kein KDC finden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:109 -+msgid "The KDC did not respond to the IAKERB proxy" -+msgstr "Das KDC anwortete dem IAKERB-Proxy nicht." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:110 -+msgid "KRB5 error code 87" -+msgstr "KRB5-Fehlercode 87" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:111 -+msgid "KRB5 error code 88" -+msgstr "KRB5-Fehlercode 88" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:112 -+msgid "KRB5 error code 89" -+msgstr "KRB5-Fehlercode 89" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:113 -+msgid "KRB5 error code 90" -+msgstr "KRB5-Fehlercode 90" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:114 -+msgid "KRB5 error code 91" -+msgstr "KRB5-Fehlercode 91" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:115 -+msgid "KRB5 error code 92" -+msgstr "KRB5-Fehlercode 92" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:116 -+msgid "An unsupported critical FAST option was requested" -+msgstr "Es wurde eine nicht unterstützte kritische FAST-Aktion angefordert." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:117 -+msgid "KRB5 error code 94" -+msgstr "KRB5-Fehlercode 94" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:118 -+msgid "KRB5 error code 95" -+msgstr "KRB5-Fehlercode 95" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:119 -+msgid "KRB5 error code 96" -+msgstr "KRB5-Fehlercode 96" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:120 -+msgid "KRB5 error code 97" -+msgstr "KRB5-Fehlercode 97" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:121 -+msgid "KRB5 error code 98" -+msgstr "KRB5-Fehlercode 98" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:122 -+msgid "KRB5 error code 99" -+msgstr "KRB5-Fehlercode 99" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:123 -+msgid "No acceptable KDF offered" -+msgstr "kein akzeptables KDF angeboten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:124 -+msgid "KRB5 error code 101" -+msgstr "KRB5-Fehlercode 101" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:125 -+msgid "KRB5 error code 102" -+msgstr "KRB5-Fehlercode 102" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:126 -+msgid "KRB5 error code 103" -+msgstr "KRB5-Fehlercode 103" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:127 -+msgid "KRB5 error code 104" -+msgstr "KRB5-Fehlercode 104" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:128 -+msgid "KRB5 error code 105" -+msgstr "KRB5-Fehlercode 105" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:129 -+msgid "KRB5 error code 106" -+msgstr "KRB5-Fehlercode 106" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:130 -+msgid "KRB5 error code 107" -+msgstr "KRB5-Fehlercode 107" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:131 -+msgid "KRB5 error code 108" -+msgstr "KRB5-Fehlercode 108" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:132 -+msgid "KRB5 error code 109" -+msgstr "KRB5-Fehlercode 109" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:133 -+msgid "KRB5 error code 110" -+msgstr "KRB5-Fehlercode 110" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:134 -+msgid "KRB5 error code 111" -+msgstr "KRB5-Fehlercode 111" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:135 -+msgid "KRB5 error code 112" -+msgstr "KRB5-Fehlercode 112" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:136 -+msgid "KRB5 error code 113" -+msgstr "KRB5-Fehlercode 113" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:137 -+msgid "KRB5 error code 114" -+msgstr "KRB5-Fehlercode 114" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:138 -+msgid "KRB5 error code 115" -+msgstr "KRB5-Fehlercode 115" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:139 -+msgid "KRB5 error code 116" -+msgstr "KRB5-Fehlercode 116" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:140 -+msgid "KRB5 error code 117" -+msgstr "KRB5-Fehlercode 117" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:141 -+msgid "KRB5 error code 118" -+msgstr "KRB5-Fehlercode 118" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:142 -+msgid "KRB5 error code 119" -+msgstr "KRB5-Fehlercode 119" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:143 -+msgid "KRB5 error code 120" -+msgstr "KRB5-Fehlercode 120" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:144 -+msgid "KRB5 error code 121" -+msgstr "KRB5-Fehlercode 121" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:145 -+msgid "KRB5 error code 122" -+msgstr "KRB5-Fehlercode 122" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:146 -+msgid "KRB5 error code 123" -+msgstr "KRB5-Fehlercode 123" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:147 -+msgid "KRB5 error code 124" -+msgstr "KRB5-Fehlercode 124" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:148 -+msgid "KRB5 error code 125" -+msgstr "KRB5-Fehlercode 125" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:149 -+msgid "KRB5 error code 126" -+msgstr "KRB5-Fehlercode 126" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:150 -+msgid "KRB5 error code 127" -+msgstr "KRB5-Fehlercode 127" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:151 -+#: ../lib/krb5/error_tables/kdb5_err.c:23 -+msgid "$Id$" -+msgstr "$Id$" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:152 -+msgid "Invalid flag for file lock mode" -+msgstr "ungültiger Schalter für den Datei-Sperrmodus" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:153 -+msgid "Cannot read password" -+msgstr "Passwort kann nicht gelesen werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:154 -+msgid "Password mismatch" -+msgstr "Passwort stimmt nicht überein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:155 -+msgid "Password read interrupted" -+msgstr "Lesen des Passworts unterbrochen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:156 -+msgid "Illegal character in component name" -+msgstr "ungültiges Zeichen in Komponentenname" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:157 -+msgid "Malformed representation of principal" -+msgstr "Darstellung des Principals in falscher Form" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:158 -+msgid "Can't open/find Kerberos configuration file" -+msgstr "Kerberos-Konfigurationsdatei kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:159 -+msgid "Improper format of Kerberos configuration file" -+msgstr "Format der Kerberos-Konfigurationsdatei ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:160 -+msgid "Insufficient space to return complete information" -+msgstr "Platz reicht nicht zur Rückgabe aller Informationen aus" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:161 -+msgid "Invalid message type specified for encoding" -+msgstr "der zum Kodieren angegebene Nachrichtentyp ist ungültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:162 -+msgid "Credential cache name malformed" -+msgstr "falsche Form des Anmeldedatenzwischenspeichernamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:163 -+msgid "Unknown credential cache type" -+msgstr "unbekannter Anmeldedatenzwischenspeichertyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:164 -+msgid "Matching credential not found" -+msgstr "keine passenden Anmeldedaten gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:165 -+msgid "End of credential cache reached" -+msgstr "Ende des Anmeldedatenzwischenspeichers erreicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:166 -+msgid "Request did not supply a ticket" -+msgstr "Anfrage lieferte kein Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:167 -+msgid "Wrong principal in request" -+msgstr "falscher Principal in der Anfrage" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:168 -+msgid "Ticket has invalid flag set" -+msgstr "Das Ticket hat einen falsch gesetzten Schalter." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:169 -+msgid "Requested principal and ticket don't match" -+msgstr "angeforderter Principal und Ticket passen nicht zusammen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:170 -+msgid "KDC reply did not match expectations" -+msgstr "KDC-Antwort entsprach nicht den Erwartungen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:171 -+msgid "Clock skew too great in KDC reply" -+msgstr "Zeitversatz in der KDC-Antwort zu groß" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:172 -+msgid "Client/server realm mismatch in initial ticket request" -+msgstr "" -+"Client-/Server-Realm passen in der anfänglichen Ticketanfrage nicht zusammen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:173 -+msgid "Program lacks support for encryption type" -+msgstr "" -+"Dem Programm fehlt es an der Unterstützung für den Verschlüsselungstyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:174 -+msgid "Program lacks support for key type" -+msgstr "Dem Programm fehlt es an der Unterstützung für den Schlüsseltyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:175 -+msgid "Requested encryption type not used in message" -+msgstr "" -+"Der angeforderte Verschlüsselungstyp wird in der Nachricht nicht verwendet." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:176 -+msgid "Program lacks support for checksum type" -+msgstr "Dem Programm fehlt es an der Unterstützung für den Prüfsummentyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:177 -+msgid "Cannot find KDC for requested realm" -+msgstr "KDC für angeforderten Realm kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:178 -+msgid "Kerberos service unknown" -+msgstr "Kerberos-Dienst unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:179 -+msgid "Cannot contact any KDC for requested realm" -+msgstr "Für den angeforderten Realm kann kein KDC kontaktiert werden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:180 -+msgid "No local name found for principal name" -+msgstr "Für den Principal-Namen wurde kein lokaler Name gefunden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:182 -+msgid "Replay cache type is already registered" -+msgstr "Wiederholungszwischenspeichertyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:183 -+msgid "No more memory to allocate (in replay cache code)" -+msgstr "" -+"kein Speicher mehr zu reservieren (im Wiederholungszwischenspeichercode)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:184 -+msgid "Replay cache type is unknown" -+msgstr "Wiederholungszwischenspeichertyp ist unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:185 -+msgid "Generic unknown RC error" -+msgstr "allgemeiner unbekannter Wiederholungszwischenspeicherfehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:186 -+msgid "Message is a replay" -+msgstr "Nachricht ist eine Wiederholung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:187 -+msgid "Replay cache I/O operation failed" -+msgstr "Wiederholungszwischenspeicher-E/A-Aktion fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:188 -+msgid "Replay cache type does not support non-volatile storage" -+msgstr "" -+"Wiederholungszwischenspeichertyp unterstützt keinen beständigen Speicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:189 -+msgid "Replay cache name parse/format error" -+msgstr "Auswerte-/Formatfehler im Wiederholungszwischenspeichernamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:190 -+msgid "End-of-file on replay cache I/O" -+msgstr "Dateiende bei der E/A des Wiederholungszwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:191 -+msgid "No more memory to allocate (in replay cache I/O code)" -+msgstr "" -+"kein weiterer Speicher reservierbar (im Wiederholungszwischenspeicher-E/A-" -+"Code)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:192 -+msgid "Permission denied in replay cache code" -+msgstr "Zugriff im Wiederholungszwischenspeichercode verweigert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:193 -+msgid "I/O error in replay cache i/o code" -+msgstr "E/A-Fehler im Wiederholungszwischenspeicher-E/A-Code" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:194 -+msgid "Generic unknown RC/IO error" -+msgstr "allgemeiner unbekannter Wiederholungszwischenspeicher-/E/A-Fehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:195 -+msgid "Insufficient system space to store replay information" -+msgstr "" -+"Platz im System reicht nicht zum Speichern der Wiederholungsinformationen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:196 -+msgid "Can't open/find realm translation file" -+msgstr "Realm-Übersetzungsdatei kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:197 -+msgid "Improper format of realm translation file" -+msgstr "Format der Realm-Übersetzungsdatei ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:198 -+msgid "Can't open/find lname translation database" -+msgstr "die Lname-Übersetzungsdatenbank kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:199 -+msgid "No translation available for requested principal" -+msgstr "Für den angeforderten Principal ist keine Übersetzung verfügbar." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:200 -+msgid "Improper format of translation database entry" -+msgstr "Format des Eintrags der Übersetzungsdatenbank ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:201 -+msgid "Cryptosystem internal error" -+msgstr "interner Fehler des Verschlüsselungssystems" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:202 -+msgid "Key table name malformed" -+msgstr "falsche Form des Schlüsseltabellennamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:203 -+msgid "Unknown Key table type" -+msgstr "unbekannter Schlüsseltabellentyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:204 -+msgid "Key table entry not found" -+msgstr "Schlüsseltabelleneintrag nicht gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:205 -+msgid "End of key table reached" -+msgstr "Ende der Schlüsseltabelle erreicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:206 -+msgid "Cannot write to specified key table" -+msgstr "in angegebene Schlüsseltabelle kann nicht geschrieben werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:207 -+msgid "Error writing to key table" -+msgstr "Fehler beim Schreiben in Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:208 -+msgid "Cannot find ticket for requested realm" -+msgstr "Ticket für angeforderten Realm kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:209 -+msgid "DES key has bad parity" -+msgstr "DES-Schlüssel hat falsche Parität" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:210 -+msgid "DES key is a weak key" -+msgstr "DES-Schlüssel ist schwach" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:211 -+msgid "Bad encryption type" -+msgstr "falscher Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:212 -+msgid "Key size is incompatible with encryption type" -+msgstr "Schlüssellänge ist nicht mit dem Verschlüsselungstyp kompatibel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:213 -+msgid "Message size is incompatible with encryption type" -+msgstr "Nachrichtengröße ist nicht mit Verschlüsselungstyp kompatibel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:214 -+msgid "Credentials cache type is already registered." -+msgstr "Anmeldedatenzwischenspeichertyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:215 -+msgid "Key table type is already registered." -+msgstr "Schlüsseltabellentyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:216 -+msgid "Credentials cache I/O operation failed XXX" -+msgstr "E/A-Aktion für Anmeldedatenzwischenspeicher fehlgeschlagen XXX" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:217 -+msgid "Credentials cache permissions incorrect" -+msgstr "Anmeldedatenzwischenspeicherrechte nicht korrekt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:218 -+msgid "No credentials cache found" -+msgstr "kein Anmeldedatenzwischenspeicher gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:219 -+msgid "Internal credentials cache error" -+msgstr "interner Anmeldedatenzwischenspeicherfehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:220 -+msgid "Error writing to credentials cache" -+msgstr "Fehler beim Schreiben in den Anmeldedatenzwischenspeicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:221 -+msgid "No more memory to allocate (in credentials cache code)" -+msgstr "" -+"kein weiterer Speicher zu reservieren (im Anmeldedatenzwischenspeichercode)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:222 -+msgid "Bad format in credentials cache" -+msgstr "falsches Format im Anmeldedatenzwischenspeicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:223 -+msgid "No credentials found with supported encryption types" -+msgstr "keine Anmeldedaten mit unterstützten Verschlüsselungstypen gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:224 -+msgid "Invalid KDC option combination (library internal error)" -+msgstr "ungültige Kombination von KDC-Optionen (interner Bibliotheksfehler)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:225 -+msgid "Request missing second ticket" -+msgstr "Der Anfrage fehlt das zweite Ticket." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:226 -+msgid "No credentials supplied to library routine" -+msgstr "der Bibliotheks-Routine wurden keine Anmeldedaten geliefert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:227 -+msgid "Bad sendauth version was sent" -+msgstr "Es wurde eine falsche Sendauth-Version verschickt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:228 -+msgid "Bad application version was sent (via sendauth)" -+msgstr "Es wurde eine falsche Anwendungsversion (über Sendauth) verschickt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:229 -+msgid "Bad response (during sendauth exchange)" -+msgstr "falsche Antwort (beim Sendauth-Austausch)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:230 -+msgid "Server rejected authentication (during sendauth exchange)" -+msgstr "Server wies Authentifizierung (beim Sendauth-Austausch) zurück" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:231 -+msgid "Unsupported preauthentication type" -+msgstr "nicht unterstützter Vorauthentifizierungstyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:232 -+msgid "Required preauthentication key not supplied" -+msgstr "erforderlicher Vorauthentifizierungsschlüssel nicht bereitgestellt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:233 -+msgid "Generic preauthentication failure" -+msgstr "allgemeiner Fehlschlag der Vorauthentifizierung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:234 -+msgid "Unsupported replay cache format version number" -+msgstr "" -+"nicht unterstütztes Versionsnummernformat des Wiederholungszwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:235 -+msgid "Unsupported credentials cache format version number" -+msgstr "" -+"nicht unterstütztes Versionsnummernformat des Anmeldedatenzwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:236 -+msgid "Unsupported key table format version number" -+msgstr "nicht unterstütztes Versionsnummernformat der Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:237 -+msgid "Program lacks support for address type" -+msgstr "Dem Programm fehlt es an der Unterstützung des Adresstyps." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:238 -+msgid "Message replay detection requires rcache parameter" -+msgstr "Erkennung der Antwortnachricht erfordert den Parameter »rcache«" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:239 -+msgid "Hostname cannot be canonicalized" -+msgstr "Rechnername kann nicht in Normalform gebracht werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:240 -+msgid "Cannot determine realm for host" -+msgstr "Realm für Rechner kann nicht bestimmt werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:241 -+msgid "Conversion to service principal undefined for name type" -+msgstr "Umwandlung in Dienst-Principal für Namenstyp nicht definiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:242 -+msgid "Initial Ticket response appears to be Version 4 error" -+msgstr "anfängliche Ticket-Antwort scheint ein Fehler der Version 4 zu sein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:243 -+msgid "Cannot resolve network address for KDC in requested realm" -+msgstr "" -+"Netzwerkadresse für KDC im angeforderten Realm kann nicht aufgelöst werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:244 -+msgid "Requesting ticket can't get forwardable tickets" -+msgstr "anforderndes Ticket kann keine weiterleitbaren Tickets holen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:245 -+msgid "Bad principal name while trying to forward credentials" -+msgstr "falscher Principal beim Versuch, Anmeldedaten weiterzuleiten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:246 -+msgid "Looping detected inside krb5_get_in_tkt" -+msgstr "Schleife innerhalb von »krb5_get_in_tkt« entdeckt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:247 -+msgid "Configuration file does not specify default realm" -+msgstr "Konfigurationsdatei gibt keinen Standard-Realm an" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:248 -+msgid "Bad SAM flags in obtain_sam_padata" -+msgstr "falsche SAM-Schalter in »obtain_sam_padata«" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:249 -+msgid "Invalid encryption type in SAM challenge" -+msgstr "ungültiger Verschlüsselungstyp in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:250 -+msgid "Missing checksum in SAM challenge" -+msgstr "fehlende Prüfsumme in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:251 -+msgid "Bad checksum in SAM challenge" -+msgstr "falsche Prüfsumme in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:252 -+msgid "Keytab name too long" -+msgstr "Schlüsseltabellennamen zu lang" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:253 -+msgid "Key version number for principal in key table is incorrect" -+msgstr "" -+"Schlüsselversionsnummer des Principals in der Schlüsseltabelle ist nicht " -+"korrekt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:254 -+msgid "This application has expired" -+msgstr "Diese Anwendung ist abgelaufen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:255 -+msgid "This Krb5 library has expired" -+msgstr "Diese Krb5-Bibliothek ist abgelaufen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:256 -+msgid "New password cannot be zero length" -+msgstr "Das neue Passwort kann nicht die Länge Null haben." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:258 -+msgid "Bad format in keytab" -+msgstr "falsches Format in der Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:259 -+msgid "Encryption type not permitted" -+msgstr "Verschlüsselungstyp nicht erlaubt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:260 -+msgid "No supported encryption types (config file error?)" -+msgstr "" -+"keine unterstützten Verschlüsselungstypen (Fehler in der " -+"Konfigurationsdatei?)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:261 -+msgid "Program called an obsolete, deleted function" -+msgstr "Das Programm rief eine veraltete, gelöschte Funktion auf." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:262 -+msgid "unknown getaddrinfo failure" -+msgstr "unbekannter Getaddrinfo-Fehlschlag" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:263 -+msgid "no data available for host/domain name" -+msgstr "keine Daten für Rechner/Domain-Namen verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:264 -+msgid "host/domain name not found" -+msgstr "Rechner/Domain-Name nicht gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:265 -+msgid "service name unknown" -+msgstr "Dienstname unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:266 -+msgid "Cannot determine realm for numeric host address" -+msgstr "Realm für numerische Rechneradresse kann nicht bestimmt werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:267 -+msgid "Invalid key generation parameters from KDC" -+msgstr "ungültige Parameter zum Erzeugen von Schlüsseln vom KDC" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:268 -+msgid "service not available" -+msgstr "Dienst nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:269 -+msgid "Ccache function not supported: read-only ccache type" -+msgstr "Ccache-Funktion nicht unterstützt: Ccache-Typ nur lesbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:270 -+msgid "Ccache function not supported: not implemented" -+msgstr "Ccache-Funktion nicht unterstützt: nicht implementiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:271 -+msgid "Invalid format of Kerberos lifetime or clock skew string" -+msgstr "" -+"ungültiges Format der Kerberos-Lebensdauer oder der Zeitversatzzeichenkette" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:272 -+msgid "Supplied data not handled by this plugin" -+msgstr "" -+"Die bereitgestellten Daten werden nicht von dieser Erweiterung behandelt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:273 -+msgid "Plugin does not support the operation" -+msgstr "Erweiterung unterstützt diese Aktion nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:274 -+msgid "Invalid UTF-8 string" -+msgstr "ungültige UTF-8-Zeichenkette" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:275 -+msgid "FAST protected pre-authentication required but not supported by KDC" -+msgstr "" -+"FAST-geschützte Vorauthentifizierung erforderlich, aber nicht vom KDC " -+"unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:276 -+msgid "Auth context must contain local address" -+msgstr "Authentifizierungskontext muss lokale Adresse enthalten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:277 -+msgid "Auth context must contain remote address" -+msgstr "Authentifizierungskontext muss ferne Adresse enthalten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:278 -+msgid "Tracing unsupported" -+msgstr "Verfolgung nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:24 -+msgid "Entry already exists in database" -+msgstr "Eintrag existiert bereits in der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:25 -+msgid "Database store error" -+msgstr "Datenbank-Speicherfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:26 -+msgid "Database read error" -+msgstr "Datenbank-Lesefehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:27 -+msgid "Insufficient access to perform requested operation" -+msgstr "Zugriffsrechte reichen nicht zur Durchführung der angeforderten Aktion" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:28 -+msgid "No such entry in the database" -+msgstr "kein derartiger Eintrag in der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:29 -+msgid "Illegal use of wildcard" -+msgstr "ungültige Verwendung eines Platzhalters" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:30 -+msgid "Database is locked or in use--try again later" -+msgstr "" -+"Datenbank ist gesperrt oder wird gerade benutzt – versuchen Sie es später " -+"wieder" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:31 -+msgid "Database was modified during read" -+msgstr "Datenbank wurde während des Lesens geändert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:32 -+msgid "Database record is incomplete or corrupted" -+msgstr "Datensatz ist unvollständig oder beschädigt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:33 -+msgid "Attempt to lock database twice" -+msgstr "Es wurde zweimal versucht, die Datenbank zu sperren." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:34 -+msgid "Attempt to unlock database when not locked" -+msgstr "" -+"Es wurde versucht, die Datenbank zu entsperren, obwohl sie nicht gesperrt " -+"ist." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:35 -+msgid "Invalid kdb lock mode" -+msgstr "ungültiger KDB-Sperrmodus" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:36 -+msgid "Database has not been initialized" -+msgstr "Datenbank wurde nicht initialisiert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:37 -+msgid "Database has already been initialized" -+msgstr "Datenbank wurde bereits initialisiert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:38 -+msgid "Bad direction for converting keys" -+msgstr "falsche Richtung zum Umwandeln von Schlüsseln" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:39 -+msgid "Cannot find master key record in database" -+msgstr "Hauptschlüsseldatensatz kann nicht in der Datenbank gefunden werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:40 -+msgid "Master key does not match database" -+msgstr "Hauptschlüssel passt nicht zur Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:41 -+msgid "Key size in database is invalid" -+msgstr "Die Schlüssellänge in der Datenbank ist ungültig," -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:42 -+msgid "Cannot find/read stored master key" -+msgstr "Der gespeicherte Hauptschlüssel kann nicht gefunden/gelesen werden." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:43 -+msgid "Stored master key is corrupted" -+msgstr "Der gespeicherte Hauptschlüssel ist beschädigt." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:44 -+msgid "Cannot find active master key" -+msgstr "Der aktive Hauptschlüssel kann nicht gefunden werden." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:45 -+msgid "KVNO of new master key does not match expected value" -+msgstr "KVNO des neuen Hauptschlüssels passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:46 -+msgid "Stored master key is not current" -+msgstr "gespeicherter Hauptschlüssel ist nicht aktuell" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:47 -+msgid "Insufficient access to lock database" -+msgstr "keine ausreichenden Zugriffsrechte zum Sperren der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:48 -+msgid "Database format error" -+msgstr "fehlerhaftes Datenbankformat" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:49 -+msgid "Unsupported version in database entry" -+msgstr "nicht unterstützte Version im Datenbankeintrag" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:50 -+msgid "Unsupported salt type" -+msgstr "nicht unterstützter Salt-Typ" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:51 -+msgid "Unsupported encryption type" -+msgstr "nicht unterstützter Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:52 -+msgid "Bad database creation flags" -+msgstr "falsche Schalter zum Erstellen der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:53 -+msgid "No matching key in entry having a permitted enctype" -+msgstr "" -+"kein passender Schlüssel in einem Eintrag mit erlaubtem Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:54 -+msgid "No matching key in entry" -+msgstr "kein passender Schlüssel im Eintrag" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:55 -+msgid "Unable to find requested database type" -+msgstr "angeforderter Datenbanktyp kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:56 -+msgid "Database type not supported" -+msgstr "Datenbanktyp nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:57 -+msgid "Database library failed to initialize" -+msgstr "Initialisieren der Datenbankbibliothek fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:59 -+msgid "Unable to access Kerberos database" -+msgstr "auf die Kerberos-Datenbank kann nicht zugegriffen werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:60 -+msgid "Kerberos database internal error" -+msgstr "interner Kerberos-Datenbankfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:61 -+msgid "Kerberos database constraints violated" -+msgstr "Kerberos-Datenbankbeschränkungen verletzt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:62 -+msgid "Update log conversion error" -+msgstr "Fehler beim Umwandeln des Aktualisierungsprotokolls" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:63 -+msgid "Update log is unstable" -+msgstr "Aktualisierungsprotokoll ist instabil" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:64 -+msgid "Update log is corrupt" -+msgstr "Aktualisierungsprotokoll ist beschädigt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:65 -+msgid "Generic update log error" -+msgstr "allgemeiner Aktualisierungsprotokollfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:66 -+msgid "Database module does not match KDC version" -+msgstr "Datenbankmodul passt nicht zur KDC-Version" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:68 -+msgid "Too much string mapping data" -+msgstr "zu viele zeichenkettenabbildenden Daten" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:23 -+msgid "ASN.1 failed call to system time library" -+msgstr "ASN.1 beim Aufruf der Systemzeitbibliothek gescheitert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:24 -+msgid "ASN.1 structure is missing a required field" -+msgstr "ein erforderliches Feld fehlt in der ASN.1-Struktur" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:25 -+msgid "ASN.1 unexpected field number" -+msgstr "ASN.1 unerwartete Feldnummer" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:26 -+msgid "ASN.1 type numbers are inconsistent" -+msgstr "ASN.1-Typnummern sind inkonsistent" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:27 -+msgid "ASN.1 value too large" -+msgstr "ASN.1-Wert zu groß" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:28 -+msgid "ASN.1 encoding ended unexpectedly" -+msgstr "ASN.1-Kodierung endete unerwartet" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:29 -+msgid "ASN.1 identifier doesn't match expected value" -+msgstr "ASN.1-Bezeichner passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:30 -+msgid "ASN.1 length doesn't match expected value" -+msgstr "Länge von ASN.1 passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:31 -+msgid "ASN.1 badly-formatted encoding" -+msgstr "fehlerhaft formatierte ASN.1-Kodierung" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:32 -+msgid "ASN.1 parse error" -+msgstr "ASN.1-Auswertungsfehler" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:33 -+msgid "ASN.1 bad return from gmtime" -+msgstr "ASN.1 falscher Rückgabewert von Gmtime" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:34 -+msgid "ASN.1 non-constructed indefinite encoding" -+msgstr "nicht konstruierte unbestimmte ASN.1-Kodierung" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:35 -+msgid "ASN.1 missing expected EOC" -+msgstr "ASN.1 fehlt erwartetes EOC" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:36 -+msgid "ASN.1 object omitted in sequence" -+msgstr "ASN.1-Objekt in Sequenz ausgelassen" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:23 -+msgid "Kerberos V5 magic number table" -+msgstr "Tabelle magischer Zahlen von Kerberos V5" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:24 -+msgid "Bad magic number for krb5_principal structure" -+msgstr "falsche magische Zahl für Krb5_principal-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:25 -+msgid "Bad magic number for krb5_data structure" -+msgstr "falsche magische Zahl für Krb5_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:26 -+msgid "Bad magic number for krb5_keyblock structure" -+msgstr "falsche magische Zahl für Krb5_krb5_keyblock-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:27 -+msgid "Bad magic number for krb5_checksum structure" -+msgstr "falsche magische Zahl für Krb5_krb5_checksum-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:28 -+msgid "Bad magic number for krb5_encrypt_block structure" -+msgstr "falsche magische Zahl für Krb5_encrypt_bloc-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:29 -+msgid "Bad magic number for krb5_enc_data structure" -+msgstr "falsche magische Zahl für Krb5_enc_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:30 -+msgid "Bad magic number for krb5_cryptosystem_entry structure" -+msgstr "falsche magische Zahl für Krb5_cryptosystem_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:31 -+msgid "Bad magic number for krb5_cs_table_entry structure" -+msgstr "falsche magische Zahl für Krb5_cs_table_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:32 -+msgid "Bad magic number for krb5_checksum_entry structure" -+msgstr "falsche magische Zahl für Krb5_checksum_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:33 -+msgid "Bad magic number for krb5_authdata structure" -+msgstr "falsche magische Zahl für Krb5_authdata-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:34 -+msgid "Bad magic number for krb5_transited structure" -+msgstr "falsche magische Zahl für Krb5_transited-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:35 -+msgid "Bad magic number for krb5_enc_tkt_part structure" -+msgstr "falsche magische Zahl für Krb5_enc_tkt_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:36 -+msgid "Bad magic number for krb5_ticket structure" -+msgstr "falsche magische Zahl für Krb5_ticket-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:37 -+msgid "Bad magic number for krb5_authenticator structure" -+msgstr "falsche magische Zahl für Krb5_authenticator-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:38 -+msgid "Bad magic number for krb5_tkt_authent structure" -+msgstr "falsche magische Zahl für Krb5_tkt_authent-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:39 -+msgid "Bad magic number for krb5_creds structure" -+msgstr "falsche magische Zahl für Krb5_creds-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:40 -+msgid "Bad magic number for krb5_last_req_entry structure" -+msgstr "falsche magische Zahl für Krb5_last_req_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:41 -+msgid "Bad magic number for krb5_pa_data structure" -+msgstr "falsche magische Zahl für Krb5_pa_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:42 -+msgid "Bad magic number for krb5_kdc_req structure" -+msgstr "falsche magische Zahl für Krb5_kdc_req-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:43 -+msgid "Bad magic number for krb5_enc_kdc_rep_part structure" -+msgstr "falsche magische Zahl für Krb5_enc_kdc_rep_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:44 -+msgid "Bad magic number for krb5_kdc_rep structure" -+msgstr "falsche magische Zahl für Krb5_kdc_rep-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:45 -+msgid "Bad magic number for krb5_error structure" -+msgstr "falsche magische Zahl für Krb5_error-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:46 -+msgid "Bad magic number for krb5_ap_req structure" -+msgstr "falsche magische Zahl für Krb5_ap_req-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:47 -+msgid "Bad magic number for krb5_ap_rep structure" -+msgstr "falsche magische Zahl für Krb5_ap_rep-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:48 -+msgid "Bad magic number for krb5_ap_rep_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_ap_rep_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:49 -+msgid "Bad magic number for krb5_response structure" -+msgstr "falsche magische Zahl für Krb5_response-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:50 -+msgid "Bad magic number for krb5_safe structure" -+msgstr "falsche magische Zahl für Krb5_safe-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:51 -+msgid "Bad magic number for krb5_priv structure" -+msgstr "falsche magische Zahl für Krb5_priv-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:52 -+msgid "Bad magic number for krb5_priv_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_priv_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:53 -+msgid "Bad magic number for krb5_cred structure" -+msgstr "falsche magische Zahl für Krb5_cred-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:54 -+msgid "Bad magic number for krb5_cred_info structure" -+msgstr "falsche magische Zahl für Krb5_cred_info-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:55 -+msgid "Bad magic number for krb5_cred_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_cred_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:56 -+msgid "Bad magic number for krb5_pwd_data structure" -+msgstr "falsche magische Zahl für Krb5_pwd_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:57 -+msgid "Bad magic number for krb5_address structure" -+msgstr "falsche magische Zahl für Krb5_address-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:58 -+msgid "Bad magic number for krb5_keytab_entry structure" -+msgstr "falsche magische Zahl für Krb5_keytab_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:59 -+msgid "Bad magic number for krb5_context structure" -+msgstr "falsche magische Zahl für Krb5_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:60 -+msgid "Bad magic number for krb5_os_context structure" -+msgstr "falsche magische Zahl für Krb5_os_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:61 -+msgid "Bad magic number for krb5_alt_method structure" -+msgstr "falsche magische Zahl für Krb5_alt_method-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:62 -+msgid "Bad magic number for krb5_etype_info_entry structure" -+msgstr "falsche magische Zahl für Krb5_etype_info_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:63 -+msgid "Bad magic number for krb5_db_context structure" -+msgstr "falsche magische Zahl für Krb5_db_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:64 -+msgid "Bad magic number for krb5_auth_context structure" -+msgstr "falsche magische Zahl für Krb5_auth_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:65 -+msgid "Bad magic number for krb5_keytab structure" -+msgstr "falsche magische Zahl für Krb5_keytab-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:66 -+msgid "Bad magic number for krb5_rcache structure" -+msgstr "falsche magische Zahl für Krb5_rcache-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:67 -+msgid "Bad magic number for krb5_ccache structure" -+msgstr "falsche magische Zahl für Krb5_ccache-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:68 -+msgid "Bad magic number for krb5_preauth_ops" -+msgstr "falsche magische Zahl für Krb5_preauth_ops" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:69 -+msgid "Bad magic number for krb5_sam_challenge" -+msgstr "falsche magische Zahl für Krb5_sam_challenge" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:70 -+msgid "Bad magic number for krb5_sam_challenge_2" -+msgstr "falsche magische Zahl für Krb5_sam_challenge_2" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:71 -+msgid "Bad magic number for krb5_sam_key" -+msgstr "falsche magische Zahl für Krb5_sam_key" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:72 -+#: ../lib/krb5/error_tables/kv5m_err.c:73 -+msgid "Bad magic number for krb5_enc_sam_response_enc" -+msgstr "falsche magische Zahl für Krb5_enc_sam_response_enc" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:74 -+msgid "Bad magic number for krb5_sam_response" -+msgstr "falsche magische Zahl für Krb5_sam_response" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:75 -+msgid "Bad magic number for krb5_sam_response 2" -+msgstr "falsche magische Zahl für Krb5_sam_response 2" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:76 -+msgid "Bad magic number for krb5_predicted_sam_response" -+msgstr "falsche magische Zahl für Krb5_predicted_sam_response" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:77 -+msgid "Bad magic number for passwd_phrase_element" -+msgstr "falsche magische Zahl für Passwd_phrase_element" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:78 -+msgid "Bad magic number for GSSAPI OID" -+msgstr "falsche magische Zahl für GSSAPI OID" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:79 -+msgid "Bad magic number for GSSAPI QUEUE" -+msgstr "falsche magische Zahl für GSSAPI QUEUE" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:80 -+msgid "Bad magic number for fast armored request" -+msgstr "falsche magische Zahl für per FAST geschützte Anfrage" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:81 -+msgid "Bad magic number for FAST request" -+msgstr "falsche magische Zahl für FAST-Anfrage" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:82 -+msgid "Bad magic number for FAST response" -+msgstr "falsche magische Zahl für FAST-Antwort" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:83 -+msgid "Bad magic number for krb5_authdata_context" -+msgstr "falsche magische Zahl für Krb5_authdata_context" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:23 -+msgid "Cannot convert V5 keyblock" -+msgstr "V5-Schlüsselblock kann nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:24 -+msgid "Cannot convert V5 address information" -+msgstr "V5-Adressinformationen können nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:25 -+msgid "Cannot convert V5 principal" -+msgstr "V5-Principal kann nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:26 -+msgid "V5 realm name longer than V4 maximum" -+msgstr "V5-Realm-Name ist länger als die V4-Maximallänge" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:27 -+msgid "Kerberos V4 error" -+msgstr "Kerberos-V4-Fehler" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:28 -+msgid "Encoding too large" -+msgstr "Kodierung zu lang" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:29 -+msgid "Decoding out of data" -+msgstr "Dekodieren außerhalb der Daten" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:30 -+msgid "Service not responding" -+msgstr "Dienst antwortet nicht" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:31 -+msgid "Kerberos version 4 support is disabled" -+msgstr "Kerberos 4 Unterstützung ist deaktiviert" -+ -+#~ msgid "while creating server %s principal name" -+#~ msgstr "beim Erstellen des Principal-Namens für Server %s" -+ -+# KDC = Key Distribution Center -+#~ msgid "while getting credentials from kdc" -+#~ msgstr "beim Holen der Anmeldedaten vom KDC" -+ -+# FIXME s/Retrieving/retrieving/ -+#~ msgid "while Retrieving credentials" -+#~ msgstr "beim Abfragen der Anmeldedaten" -+ -+#~ msgid "while copying principal" -+#~ msgstr "beim Kopieren des Principals" -+ -+#~ msgid "%s does not have correct permissions for %s\n" -+#~ msgstr "%s hat nicht die erforderlichen Zugriffsrechte für %s\n" -+ -+#~ msgid "no salt\n" -+#~ msgstr "kein Salt\n" -+ -+#~ msgid "%s: Couldn't grab lock\n" -+#~ msgstr "%s: Es konnte keine Sperre erlangt werden.\n" -+ -+#~ msgid "%s: Loads disallowed when iprop is enabled and a ulog is present\n" -+#~ msgstr "" -+#~ "%s: Wenn Iprop aktiviert und Ulog vorhanden ist, ist Laden nicht " -+#~ "möglich.\n" -+ -+#~ msgid "trying to lock database" -+#~ msgstr "es wird versucht, die Datenbank zu sperren" -+ -+#~ msgid "GSS-API error %s: %s\n" -+#~ msgstr "GSS-API-Fehler %s: %s\n" -+ -+#~ msgid "Couldn't create KRB5 Name NameType OID\n" -+#~ msgstr "KRB5 Name NameType OID konnte nicht erstellt werden.\n" -+ -+#~ msgid "%s: %s while initializing, aborting" -+#~ msgstr "%s: %s beim Initialisieren, wird abgebrochen" -+ -+#~ msgid "" -+#~ "%s: Missing required configuration values (%lx) while initializing, " -+#~ "aborting" -+#~ msgstr "" -+#~ "%s: Beim Initialisieren fehlen die erforderlichen Konfigurationswerte " -+#~ "(%lx), wird abgebrochen" -+ -+#~ msgid "" -+#~ "%s: Missing required configuration values (%lx) while initializing, " -+#~ "aborting\n" -+#~ msgstr "" -+#~ "%s: Beim Initialisieren fehlen die erforderlichen Konfigurationswerte " -+#~ "(%lx), wird abgebrochen\n" -+ -+#~ msgid "%s: could not initialize loop, aborting" -+#~ msgstr "%s: Schleife konnte nicht initialisiert werden, wird abgebrochen" -+ -+#~ msgid "%s: could not initialize loop, aborting\n" -+#~ msgstr "%s: Schleife konnte nicht initialisiert werden, wird abgebrochen\n" -+ -+#~ msgid "%s: %s while initializing signal handlers, aborting" -+#~ msgstr "" -+#~ "%s: %s beim Initialisieren des Signalbehandlungsprogramms, wird " -+#~ "abgebrochen" -+ -+#~ msgid "%s: %s while initializing signal handlers, aborting\n" -+#~ msgstr "" -+#~ "%s: %s beim Initialisieren des Signalbehandlungsprogramms, wird " -+#~ "abgebrochen\n" -+ -+#~ msgid "%s: %s while initializing network, aborting" -+#~ msgstr "%s: %s beim Initialisieren des Netzwerks, wird abgebrochen" -+ -+#~ msgid "%s: %s while initializing network, aborting\n" -+#~ msgstr "%s: %s beim Initialisieren des Netzwerks, wird abgebrochen\n" -+ -+#~ msgid "Cannot build GSS-API authentication names, failing." -+#~ msgstr "" -+#~ "GSS-API-Authentifizierungsnamen können nicht gebildet werden, " -+#~ "fehlgeschlagen" -+ -+#~ msgid "Can't set kdb keytab's internal context." -+#~ msgstr "" -+#~ "Der interne Kontext von KDBs Schlüsseltabelle kann nicht gesetzt werden." -+ -+#~ msgid "Can't register kdb keytab." -+#~ msgstr "Die KDB-Schlüsseltabelle kann nicht registriert werden." -+ -+#~ msgid "Can't register acceptor keytab." -+#~ msgstr "Die Empfängerschlüsseltabelle kann nicht registriert werden." -+ -+#~ msgid "" -+#~ "Cannot set GSS-API authentication names (keytab not present?), failing." -+#~ msgstr "" -+#~ "GSS-API-Authentifizierungsnamen können nicht gesetzt werden " -+#~ "(Schlüsseltabelle nicht vorhanden?), fehlgeschlagen" -+ -+#~ msgid "Cannot initialize acl file: %s" -+#~ msgstr "ACL-Datei kann nicht initialisiert werden: %s" -+ -+#~ msgid "%s: Cannot initialize acl file: %s\n" -+#~ msgstr "%s: ACL-Datei kann nicht initialisiert werden: %s\n" -+ -+#~ msgid "Cannot detach from tty: %s" -+#~ msgstr "kann nicht vom Terminal gelöst werden: %s" -+ -+#~ msgid "Cannot create PID file %s: %s" -+#~ msgstr "PID-Datei %s kann nicht erstellt werden: %s" -+ -+#~ msgid "%s: %s while mapping update log (`%s.ulog')\n" -+#~ msgstr "%s: %s beim Abbilden des Aktualisierungsprotokolls (»%s.ulog«)\n" -+ -+#~ msgid "%s while mapping update log (`%s.ulog')" -+#~ msgstr "%s beim Abbilden des Aktualisierungsprotokolls (»%s.ulog«)" -+ -+#~ msgid "%s: Cannot create IProp RPC service (PROG=%d, VERS=%d)\n" -+#~ msgstr "" -+#~ "%s: IProp-RPC-Dienst kann nicht erstellt werden (PROG=%d, VERS=%d)\n" -+ -+#~ msgid "Cannot create IProp RPC service (PROG=%d, VERS=%d), failing." -+#~ msgstr "" -+#~ "IProp-RPC-Dienst kann nicht erstellt werden (PROG=%d, VERS=%d), " -+#~ "fehlgeschlagen" -+ -+#~ msgid "%s while getting IProp svc name, failing" -+#~ msgstr "%s beim Holen des IProp-Dienstnamens, fehlgeschlagen" -+ -+#~ msgid "%s: %s while getting IProp svc name, failing\n" -+#~ msgstr "%s: %s beim Holen des IProp-Dienstnamens, fehlgeschlagen\n" -+ -+#~ msgid "Unable to set RPCSEC_GSS service name (`%s'), failing." -+#~ msgstr "" -+#~ "der RPCSEC_GSS-Dienstname (»%s«) kann nicht gesetzt werden, fehlgeschlagen" -+ -+#~ msgid "%s: Unable to set RPCSEC_GSS service name (`%s'), failing.\n" -+#~ msgstr "" -+#~ "%s: der RPCSEC_GSS-Dienstname (»%s«) kann nicht gesetzt werden, " -+#~ "fehlgeschlagen\n" -+ -+#~ msgid "GSS-API authentication error %.*s: recursive failure!" -+#~ msgstr "GSS-API-Authentifizierungsfehler %.*s: rekursiver Fehlschlag!" -+ -+#~ msgid "skipping unrecognized local address family %d" -+#~ msgstr "nicht erkannte lokale Adressfamilie %d wird übersprungen" -+ -+#~ msgid "got routing msg type %d(%s) v%d" -+#~ msgstr "Routing-Meldungstyp %d(%s) v%d erhalten" -+ -+#~ msgid "Could not create temp stash file: %s" -+#~ msgstr "Temporäre Ablagedatei konnte nicht erstellt werden: %s" -+ -+#~ msgid "ulog_sync_header: could not sync to disk" -+#~ msgstr "ulog_sync_header: kann nicht auf Platte sychronisiert werden" -+ -+#~ msgid "%s: attempt to convert non-extended krb5_get_init_creds_opt" -+#~ msgstr "" -+#~ "%s: Es wird versucht, nicht erweiterte »krb5_get_init_creds_opt« " -+#~ "umzuwandeln" -+ -+#~ msgid "krb5_sname_to_principal, while adding entries to the database" -+#~ msgstr "" -+#~ "»krb5_sname_to_principal« beim Hinzufügen von Einträgen zur Datenbank" -+ -+#~ msgid "krb5_copy_principal, while adding entries to the database" -+#~ msgstr "»krb5_copy_principal« beim Hinzufügen von Einträgen zur Datenbank" -+ -+#~ msgid "" -+#~ "Unable to check if SASL EXTERNAL mechanism is supported by LDAP server. " -+#~ "Proceeding anyway ..." -+#~ msgstr "" -+#~ "Es konnte nicht geprüft werden, ob der Mechanismus SASL EXTERNAL vom LDAP-" -+#~ "Server unterstützt wird. Es wird trotzdem fortgesetzt …" -+ -+#~ msgid "" -+#~ "SASL EXTERNAL mechanism not supported by LDAP server. Can't perform " -+#~ "certificate-based bind." -+#~ msgstr "" -+#~ "Der Mechanismus SASL EXTERNAL wird nicht vom LDAP-Server unterstützt. Es " -+#~ "kann keine zertifikatbasierte Verbindung hergestellt werden." -+ -+#~ msgid "Error reading 'ldap_servers' attribute" -+#~ msgstr "Fehler beim Lesen des Attributs »ldap_servers«" -+ -+#~ msgid "Stash file entry corrupt" -+#~ msgstr "Eintrag in der Ablagedatei beschädigt" -+ -+#~ msgid "while setting server principal realm" -+#~ msgstr "beim Setzen des Server-Principal-Realms" -+ -+#~ msgid "while getting initial ticket\n" -+#~ msgstr "beim Holen eines Anfangs-Tickets\n" -+ -+#~ msgid "while destroying ticket cache" -+#~ msgstr "beim Zerstören des Ticket-Zwischenspeichers" -+ -+#~ msgid "while closing default ccache" -+#~ msgstr "beim Schließen des Standard-Ccaches" diff --git a/Add-KDC-policy-pluggable-interface.patch b/Add-KDC-policy-pluggable-interface.patch deleted file mode 100644 index a5e029e..0000000 --- a/Add-KDC-policy-pluggable-interface.patch +++ /dev/null @@ -1,994 +0,0 @@ -From 78a1f155701f94a228c4f58f98846195a39991c4 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 27 Jun 2017 17:15:39 -0400 -Subject: [PATCH] Add KDC policy pluggable interface - -Add the header include/krb5/kdcpolicy_plugin.h, defining a pluggable -interface for modules to deny AS and TGS requests and set maximum -ticket lifetimes. This interface replaces the policy.c stub functions. - -Add check_kdcpolicy_as() and check_kdcpolicy_tgs() as entry functions. -Call them after auth indicators and ticket lifetimes have been -determined. - -Add a test module and a test script with basic kdcpolicy tests. Add -plugin interface documentation in doc/plugindev/policy.rst. - -Also authored by Matt Rogers . - -ticket: 8606 (new) -(cherry picked from commit d0969f6a8170344031ef58fd2a161190f1edfb96) -[rharwood@redhat.com: mention but do not use kadm_auth] ---- - doc/plugindev/index.rst | 1 + - doc/plugindev/kdcpolicy.rst | 24 +++ - src/Makefile.in | 1 + - src/configure.in | 1 + - src/include/Makefile.in | 1 + - src/include/k5-int.h | 4 +- - src/include/k5-trace.h | 5 + - src/include/krb5/kdcpolicy_plugin.h | 128 ++++++++++++ - src/kdc/do_as_req.c | 7 + - src/kdc/do_tgs_req.c | 6 + - src/kdc/kdc_util.c | 7 - - src/kdc/kdc_util.h | 11 - - src/kdc/main.c | 8 + - src/kdc/policy.c | 267 +++++++++++++++++++++---- - src/kdc/policy.h | 19 +- - src/kdc/tgs_policy.c | 6 - - src/lib/krb5/krb/plugin.c | 4 +- - src/plugins/kdcpolicy/test/Makefile.in | 20 ++ - src/plugins/kdcpolicy/test/deps | 0 - src/plugins/kdcpolicy/test/main.c | 111 ++++++++++ - src/plugins/kdcpolicy/test/policy_test.exports | 1 + - src/tests/Makefile.in | 1 + - src/tests/t_kdcpolicy.py | 57 ++++++ - 23 files changed, 616 insertions(+), 74 deletions(-) - create mode 100644 doc/plugindev/kdcpolicy.rst - create mode 100644 src/include/krb5/kdcpolicy_plugin.h - create mode 100644 src/plugins/kdcpolicy/test/Makefile.in - create mode 100644 src/plugins/kdcpolicy/test/deps - create mode 100644 src/plugins/kdcpolicy/test/main.c - create mode 100644 src/plugins/kdcpolicy/test/policy_test.exports - create mode 100644 src/tests/t_kdcpolicy.py - -diff --git a/doc/plugindev/index.rst b/doc/plugindev/index.rst -index 67dbc2790..0a012b82b 100644 ---- a/doc/plugindev/index.rst -+++ b/doc/plugindev/index.rst -@@ -32,5 +32,6 @@ Contents - gssapi.rst - internal.rst - certauth.rst -+ kdcpolicy.rst - - .. TODO: GSSAPI mechanism plugins -diff --git a/doc/plugindev/kdcpolicy.rst b/doc/plugindev/kdcpolicy.rst -new file mode 100644 -index 000000000..74f21f08f ---- /dev/null -+++ b/doc/plugindev/kdcpolicy.rst -@@ -0,0 +1,24 @@ -+.. _kdcpolicy_plugin: -+ -+KDC policy interface (kdcpolicy) -+================================ -+ -+The kdcpolicy interface was first introduced in release 1.16. It -+allows modules to veto otherwise valid AS and TGS requests or restrict -+the lifetime and renew time of the resulting ticket. For a detailed -+description of the kdcpolicy interface, see the header file -+````. -+ -+The optional **check_as** and **check_tgs** functions allow the module -+to perform access control. Additionally, a module can create and -+destroy module data with the **init** and **fini** methods. Module -+data objects last for the lifetime of the KDC process, and are -+provided to all other methods. The data has the type -+krb5_kdcpolicy_moddata, which should be cast to the appropriate -+internal type. -+ -+kdcpolicy modules can optionally inspect principal entries. To do -+this, the module must also include ```` to gain access to the -+principal entry structure definition. As the KDB interface is -+explicitly not as stable as other public interfaces, modules which do -+this may not retain compatibility across releases. -diff --git a/src/Makefile.in b/src/Makefile.in -index ad8565056..e47bddcb1 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -21,6 +21,7 @@ SUBDIRS=util include lib \ - plugins/kdb/db2 \ - @ldap_plugin_dir@ \ - plugins/kdb/test \ -+ plugins/kdcpolicy/test \ - plugins/preauth/otp \ - plugins/preauth/pkinit \ - plugins/preauth/test \ -diff --git a/src/configure.in b/src/configure.in -index 4ae2c07d5..ee1983043 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1470,6 +1470,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test - plugins/kdb/db2/libdb2/recno - plugins/kdb/db2/libdb2/test - plugins/kdb/test -+ plugins/kdcpolicy/test - plugins/preauth/otp - plugins/preauth/test - plugins/authdata/greet_client -diff --git a/src/include/Makefile.in b/src/include/Makefile.in -index 0239338a1..6a3fa8242 100644 ---- a/src/include/Makefile.in -+++ b/src/include/Makefile.in -@@ -144,6 +144,7 @@ install-headers-unix install: krb5/krb5.h profile.h - $(INSTALL_DATA) $(srcdir)/krb5/ccselect_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)ccselect_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/clpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)clpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/hostrealm_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)hostrealm_plugin.h -+ $(INSTALL_DATA) $(srcdir)/krb5/kdcpolicy_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)kdcpolicy_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/kdcpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)kdcpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/localauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)localauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/locate_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)locate_plugin.h -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index ed9c7bf75..39ffb9568 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1157,7 +1157,9 @@ struct plugin_interface { - #define PLUGIN_INTERFACE_TLS 8 - #define PLUGIN_INTERFACE_KDCAUTHDATA 9 - #define PLUGIN_INTERFACE_CERTAUTH 10 --#define PLUGIN_NUM_INTERFACES 11 -+#define PLUGIN_INTERFACE_KADM5_AUTH 11 -+#define PLUGIN_INTERFACE_KDCPOLICY 12 -+#define PLUGIN_NUM_INTERFACES 13 - - /* Retrieve the plugin module of type interface_id and name modname, - * storing the result into module. */ -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index c75e264e0..2885408a2 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -454,4 +454,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_GET_CRED_VIA_TKT_EXT_RETURN(c, ret) \ - TRACE(c, "Got cred; {kerr}", ret) - -+#define TRACE_KDCPOLICY_VTINIT_FAIL(c, ret) \ -+ TRACE(c, "KDC policy module failed to init vtable: {kerr}", ret) -+#define TRACE_KDCPOLICY_INIT_SKIP(c, name) \ -+ TRACE(c, "kadm5_auth module {str} declined to initialize", name) -+ - #endif /* K5_TRACE_H */ -diff --git a/src/include/krb5/kdcpolicy_plugin.h b/src/include/krb5/kdcpolicy_plugin.h -new file mode 100644 -index 000000000..c7592c5db ---- /dev/null -+++ b/src/include/krb5/kdcpolicy_plugin.h -@@ -0,0 +1,128 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/kdcpolicy_plugin.h - KDC policy plugin interface */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * Declarations for kdcpolicy plugin module implementors. -+ * -+ * The kdcpolicy pluggable interface currently has only one supported major -+ * version, which is 1. Major version 1 has a current minor version number of -+ * 1. -+ * -+ * kdcpolicy plugin modules should define a function named -+ * kdcpolicy__initvt, matching the signature: -+ * -+ * krb5_error_code -+ * kdcpolicy_modname_initvt(krb5_context context, int maj_ver, int min_ver, -+ * krb5_plugin_vtable vtable); -+ * -+ * The initvt function should: -+ * -+ * - Check that the supplied maj_ver number is supported by the module, or -+ * return KRB5_PLUGIN_VER_NOTSUPP if it is not. -+ * -+ * - Cast the vtable pointer as appropriate for maj_ver: -+ * maj_ver == 1: Cast to krb5_kdcpolicy_vtable -+ * -+ * - Initialize the methods of the vtable, stopping as appropriate for the -+ * supplied min_ver. Optional methods may be left uninitialized. -+ * -+ * Memory for the vtable is allocated by the caller, not by the module. -+ */ -+ -+#ifndef KRB5_POLICY_PLUGIN_H -+#define KRB5_POLICY_PLUGIN_H -+ -+#include -+ -+/* Abstract module datatype. */ -+typedef struct krb5_kdcpolicy_moddata_st *krb5_kdcpolicy_moddata; -+ -+/* A module can optionally include kdb.h to inspect principal entries when -+ * authorizing requests. */ -+struct _krb5_db_entry_new; -+ -+/* -+ * Optional: Initialize module data. Return 0 on success, -+ * KRB5_PLUGIN_NO_HANDLE if the module is inoperable (due to configuration, for -+ * example), and any other error code to abort KDC startup. Optionally set -+ * *data_out to a module data object to be passed to future calls. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_init_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata *data_out); -+ -+/* Optional: Clean up module data. */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_fini_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata); -+ -+/* -+ * Optional: return an error code and set status to an appropriate string -+ * literal to deny an AS request; otherwise return 0. lifetime_out, if set, -+ * restricts the ticket lifetime. renew_lifetime_out, if set, restricts the -+ * ticket renewable lifetime. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_check_as_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, -+ const struct _krb5_db_entry_new *client, -+ const struct _krb5_db_entry_new *server, -+ const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out); -+ -+/* -+ * Optional: return an error code and set status to an appropriate string -+ * literal to deny a TGS request; otherwise return 0. lifetime_out, if set, -+ * restricts the ticket lifetime. renew_lifetime_out, if set, restricts the -+ * ticket renewable lifetime. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_check_tgs_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, -+ const struct _krb5_db_entry_new *server, -+ const krb5_ticket *ticket, -+ const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out); -+ -+typedef struct krb5_kdcpolicy_vtable_st { -+ const char *name; -+ krb5_kdcpolicy_init_fn init; -+ krb5_kdcpolicy_fini_fn fini; -+ krb5_kdcpolicy_check_as_fn check_as; -+ krb5_kdcpolicy_check_tgs_fn check_tgs; -+} *krb5_kdcpolicy_vtable; -+ -+#endif /* KRB5_POLICY_PLUGIN_H */ -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index f85da6da6..f5cf8ad89 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -207,6 +207,13 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) - - state->ticket_reply.enc_part2 = &state->enc_tkt_reply; - -+ errcode = check_kdcpolicy_as(kdc_context, state->request, state->client, -+ state->server, state->auth_indicators, -+ state->kdc_time, &state->enc_tkt_reply.times, -+ &state->status); -+ if (errcode) -+ goto egress; -+ - /* - * Find the server key - */ -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index ac5864603..0009a9319 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -518,6 +518,12 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - kdc_get_ticket_renewtime(kdc_active_realm, request, header_enc_tkt, client, - server, &enc_tkt_reply); - -+ errcode = check_kdcpolicy_tgs(kdc_context, request, server, header_ticket, -+ auth_indicators, kdc_time, -+ &enc_tkt_reply.times, &status); -+ if (errcode) -+ goto cleanup; -+ - /* - * Set authtime to be the same as header or evidence ticket's - */ -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index b710aefe4..5455e2a67 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -642,7 +642,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - krb5_db_entry server, krb5_timestamp kdc_time, - const char **status, krb5_pa_data ***e_data) - { -- int errcode; - krb5_error_code ret; - - /* -@@ -750,12 +749,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); - -- /* Check against local policy. */ -- errcode = against_local_policy_as(request, client, server, -- kdc_time, status, e_data); -- if (errcode) -- return errcode; -- - return 0; - } - -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 672f94380..dcedfd538 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -166,17 +166,6 @@ kdc_err(krb5_context call_context, errcode_t code, const char *fmt, ...) - #endif - ; - --/* policy.c */ --int --against_local_policy_as (krb5_kdc_req *, krb5_db_entry, -- krb5_db_entry, krb5_timestamp, -- const char **, krb5_pa_data ***); -- --int --against_local_policy_tgs (krb5_kdc_req *, krb5_db_entry, -- krb5_ticket *, const char **, -- krb5_pa_data ***); -- - /* kdc_preauth.c */ - krb5_boolean - enctype_requires_etype_info_2(krb5_enctype enctype); -diff --git a/src/kdc/main.c b/src/kdc/main.c -index a4dffb29a..ccac3a759 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -31,6 +31,7 @@ - #include "kdc_util.h" - #include "kdc_audit.h" - #include "extern.h" -+#include "policy.h" - #include "kdc5_err.h" - #include "kdb_kt.h" - #include "net-server.h" -@@ -986,6 +987,12 @@ int main(int argc, char **argv) - - load_preauth_plugins(&shandle, kcontext, ctx); - load_authdata_plugins(kcontext); -+ retval = load_kdcpolicy_plugins(kcontext); -+ if (retval) { -+ kdc_err(kcontext, retval, _("while loading KDC policy plugin")); -+ finish_realms(); -+ return 1; -+ } - - retval = setup_sam(); - if (retval) { -@@ -1068,6 +1075,7 @@ int main(int argc, char **argv) - krb5_klog_syslog(LOG_INFO, _("shutting down")); - unload_preauth_plugins(kcontext); - unload_authdata_plugins(kcontext); -+ unload_kdcpolicy_plugins(kcontext); - unload_audit_modules(kcontext); - krb5_klog_close(kcontext); - finish_realms(); -diff --git a/src/kdc/policy.c b/src/kdc/policy.c -index 6cba4303f..e49644e06 100644 ---- a/src/kdc/policy.c -+++ b/src/kdc/policy.c -@@ -1,67 +1,246 @@ - /* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ - /* kdc/policy.c - Policy decision routines for KDC */ - /* -- * Copyright 1990 by the Massachusetts Institute of Technology. -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. - * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: - * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. - */ - - #include "k5-int.h" - #include "kdc_util.h" - #include "extern.h" -+#include "policy.h" -+#include "adm_proto.h" -+#include -+#include - --int --against_local_policy_as(register krb5_kdc_req *request, krb5_db_entry client, -- krb5_db_entry server, krb5_timestamp kdc_time, -- const char **status, krb5_pa_data ***e_data) -+typedef struct kdcpolicy_handle_st { -+ struct krb5_kdcpolicy_vtable_st vt; -+ krb5_kdcpolicy_moddata moddata; -+} *kdcpolicy_handle; -+ -+static kdcpolicy_handle *handles; -+ -+static void -+free_indicators(char **ais) - { --#if 0 -- /* An AS request must include the addresses field */ -- if (request->addresses == 0) { -- *status = "NO ADDRESS"; -- return KRB5KDC_ERR_POLICY; -- } --#endif -+ size_t i; - -- return 0; /* not against policy */ -+ if (ais == NULL) -+ return; -+ for (i = 0; ais[i] != NULL; i++) -+ free(ais[i]); -+ free(ais); -+} -+ -+/* Convert inds to a null-terminated list of C strings. */ -+static krb5_error_code -+authind_strings(krb5_data *const *inds, char ***strs_out) -+{ -+ krb5_error_code ret; -+ char **list = NULL; -+ size_t i, count; -+ -+ *strs_out = NULL; -+ -+ for (count = 0; inds != NULL && inds[count] != NULL; count++); -+ list = k5calloc(count + 1, sizeof(*list), &ret); -+ if (list == NULL) -+ goto error; -+ -+ for (i = 0; i < count; i++) { -+ list[i] = k5memdup0(inds[i]->data, inds[i]->length, &ret); -+ if (list[i] == NULL) -+ goto error; -+ } -+ -+ *strs_out = list; -+ return 0; -+ -+error: -+ free_indicators(list); -+ return ret; -+} -+ -+/* Constrain times->endtime to life and times->renew_till to rlife, relative to -+ * now. */ -+static void -+update_ticket_times(krb5_ticket_times *times, krb5_timestamp now, -+ krb5_deltat life, krb5_deltat rlife) -+{ -+ if (life) -+ times->endtime = ts_min(ts_incr(now, life), times->endtime); -+ if (rlife) -+ times->renew_till = ts_min(ts_incr(now, rlife), times->renew_till); -+} -+ -+/* Check an AS request against kdcpolicy modules, updating times with any -+ * module endtime constraints. Set an appropriate status string on error. */ -+krb5_error_code -+check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *client, const krb5_db_entry *server, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status) -+{ -+ krb5_deltat life, rlife; -+ krb5_error_code ret; -+ kdcpolicy_handle *hp, h; -+ char **ais = NULL; -+ -+ *status = NULL; -+ -+ ret = authind_strings(auth_indicators, &ais); -+ if (ret) -+ goto done; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.check_as == NULL) -+ continue; -+ -+ ret = h->vt.check_as(context, h->moddata, request, client, server, -+ (const char **)ais, status, &life, &rlife); -+ if (ret) -+ goto done; -+ -+ update_ticket_times(times, kdc_time, life, rlife); -+ } -+ -+done: -+ free_indicators(ais); -+ return ret; - } - - /* -- * This is where local policy restrictions for the TGS should placed. -+ * Check the TGS request against the local TGS policy. Accepts an -+ * authentication indicator for the module policy decisions. Returns 0 and a -+ * NULL status string on success. - */ - krb5_error_code --against_local_policy_tgs(register krb5_kdc_req *request, krb5_db_entry server, -- krb5_ticket *ticket, const char **status, -- krb5_pa_data ***e_data) -+check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *server, const krb5_ticket *ticket, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status) - { --#if 0 -- /* -- * For example, if your site wants to disallow ticket forwarding, -- * you might do something like this: -- */ -+ krb5_deltat life, rlife; -+ krb5_error_code ret; -+ kdcpolicy_handle *hp, h; -+ char **ais = NULL; - -- if (isflagset(request->kdc_options, KDC_OPT_FORWARDED)) { -- *status = "FORWARD POLICY"; -- return KRB5KDC_ERR_POLICY; -+ *status = NULL; -+ -+ ret = authind_strings(auth_indicators, &ais); -+ if (ret) -+ goto done; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.check_tgs == NULL) -+ continue; -+ -+ ret = h->vt.check_tgs(context, h->moddata, request, server, ticket, -+ (const char **)ais, status, &life, &rlife); -+ if (ret) -+ goto done; -+ -+ update_ticket_times(times, kdc_time, life, rlife); - } --#endif - -- return 0; /* not against policy */ -+done: -+ free_indicators(ais); -+ return ret; -+} -+ -+void -+unload_kdcpolicy_plugins(krb5_context context) -+{ -+ kdcpolicy_handle *hp, h; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.fini != NULL) -+ h->vt.fini(context, h->moddata); -+ free(h); -+ } -+ free(handles); -+ handles = NULL; -+} -+ -+krb5_error_code -+load_kdcpolicy_plugins(krb5_context context) -+{ -+ krb5_error_code ret; -+ krb5_plugin_initvt_fn *modules = NULL, *mod; -+ kdcpolicy_handle h; -+ size_t count; -+ -+ ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_KDCPOLICY, &modules); -+ if (ret) -+ goto cleanup; -+ -+ for (count = 0; modules[count] != NULL; count++); -+ handles = k5calloc(count + 1, sizeof(*handles), &ret); -+ if (handles == NULL) -+ goto cleanup; -+ -+ count = 0; -+ for (mod = modules; *mod != NULL; mod++) { -+ h = k5calloc(1, sizeof(*h), &ret); -+ if (h == NULL) -+ goto cleanup; -+ -+ ret = (*mod)(context, 1, 1, (krb5_plugin_vtable)&h->vt); -+ if (ret) { /* Version mismatch. */ -+ TRACE_KDCPOLICY_VTINIT_FAIL(context, ret); -+ free(h); -+ continue; -+ } -+ if (h->vt.init != NULL) { -+ ret = h->vt.init(context, &h->moddata); -+ if (ret == KRB5_PLUGIN_NO_HANDLE) { -+ TRACE_KADM5_AUTH_INIT_SKIP(context, h->vt.name); -+ free(h); -+ continue; -+ } -+ if (ret) { -+ kdc_err(context, ret, _("while loading policy module %s"), -+ h->vt.name); -+ free(h); -+ goto cleanup; -+ } -+ } -+ handles[count++] = h; -+ } -+ -+ ret = 0; -+ -+cleanup: -+ if (ret) -+ unload_kdcpolicy_plugins(context); -+ k5_plugin_free_modules(context, modules); -+ return ret; - } -diff --git a/src/kdc/policy.h b/src/kdc/policy.h -index 6b000dc90..2a57b0a01 100644 ---- a/src/kdc/policy.h -+++ b/src/kdc/policy.h -@@ -26,11 +26,22 @@ - #ifndef __KRB5_KDC_POLICY__ - #define __KRB5_KDC_POLICY__ - --extern int against_postdate_policy (krb5_timestamp); -+krb5_error_code -+load_kdcpolicy_plugins(krb5_context context); - --extern int against_flag_policy_as (const krb5_kdc_req *); -+void -+unload_kdcpolicy_plugins(krb5_context context); - --extern int against_flag_policy_tgs (const krb5_kdc_req *, -- const krb5_ticket *); -+krb5_error_code -+check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *client, const krb5_db_entry *server, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status); -+ -+krb5_error_code -+check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *server, const krb5_ticket *ticket, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status); - - #endif /* __KRB5_KDC_POLICY__ */ -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index d0f25d1b7..33cfbcd81 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -375,11 +375,5 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); - -- /* Check local policy. */ -- errcode = against_local_policy_tgs(request, server, ticket, -- status, e_data); -- if (errcode) -- return errcode; -- - return 0; - } -diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c -index 17dd6bd30..31aaf661d 100644 ---- a/src/lib/krb5/krb/plugin.c -+++ b/src/lib/krb5/krb/plugin.c -@@ -58,7 +58,9 @@ const char *interface_names[] = { - "audit", - "tls", - "kdcauthdata", -- "certauth" -+ "certauth", -+ "kadm5_auth", -+ "kdcpolicy", - }; - - /* Return the context's interface structure for id, or NULL if invalid. */ -diff --git a/src/plugins/kdcpolicy/test/Makefile.in b/src/plugins/kdcpolicy/test/Makefile.in -new file mode 100644 -index 000000000..b81f1a7ce ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/Makefile.in -@@ -0,0 +1,20 @@ -+mydir=plugins$(S)policy$(S)test -+BUILDTOP=$(REL)..$(S)..$(S).. -+ -+LIBBASE=policy_test -+LIBMAJOR=0 -+LIBMINOR=0 -+RELDIR=../plugins/kdcpolicy/test -+SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) -+ -+STLIBOBJS=main.o -+ -+SRCS=$(srcdir)/main.c -+ -+all-unix: all-libs -+install-unix: -+clean-unix:: clean-libs clean-libobjs -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/plugins/kdcpolicy/test/deps b/src/plugins/kdcpolicy/test/deps -new file mode 100644 -index 000000000..e69de29bb -diff --git a/src/plugins/kdcpolicy/test/main.c b/src/plugins/kdcpolicy/test/main.c -new file mode 100644 -index 000000000..eb8fde053 ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/main.c -@@ -0,0 +1,111 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/kdcpolicy_plugin.h - KDC policy plugin interface */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "kdb.h" -+#include -+ -+static krb5_error_code -+output_from_indicator(const char *const *auth_indicators, -+ krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out, -+ const char **status) -+{ -+ if (auth_indicators[0] == NULL) { -+ *status = NULL; -+ return 0; -+ } -+ -+ if (strcmp(auth_indicators[0], "ONE_HOUR") == 0) { -+ *lifetime_out = 3600; -+ *renew_lifetime_out = *lifetime_out * 2; -+ return 0; -+ } else if (strcmp(auth_indicators[0], "SEVEN_HOURS") == 0) { -+ *lifetime_out = 7 * 3600; -+ *renew_lifetime_out = *lifetime_out * 2; -+ return 0; -+ } -+ -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+} -+ -+static krb5_error_code -+test_check_as(krb5_context context, krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, const krb5_db_entry *client, -+ const krb5_db_entry *server, const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out) -+{ -+ if (request->client != NULL && request->client->length >= 1 && -+ data_eq_string(request->client->data[0], "fail")) { -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+ } -+ return output_from_indicator(auth_indicators, lifetime_out, -+ renew_lifetime_out, status); -+} -+ -+static krb5_error_code -+test_check_tgs(krb5_context context, krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, const krb5_db_entry *server, -+ const krb5_ticket *ticket, const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out) -+{ -+ if (request->server != NULL && request->server->length >= 1 && -+ data_eq_string(request->server->data[0], "fail")) { -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+ } -+ return output_from_indicator(auth_indicators, lifetime_out, -+ renew_lifetime_out, status); -+} -+ -+krb5_error_code -+kdcpolicy_test_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+kdcpolicy_test_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_kdcpolicy_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ -+ vt = (krb5_kdcpolicy_vtable)vtable; -+ vt->name = "test"; -+ vt->check_as = test_check_as; -+ vt->check_tgs = test_check_tgs; -+ return 0; -+} -diff --git a/src/plugins/kdcpolicy/test/policy_test.exports b/src/plugins/kdcpolicy/test/policy_test.exports -new file mode 100644 -index 000000000..9682ec74f ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/policy_test.exports -@@ -0,0 +1 @@ -+kdcpolicy_test_initvt -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 2b3112537..a2093108b 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -169,6 +169,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_kdcpolicy.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py -new file mode 100644 -index 000000000..6a745b959 ---- /dev/null -+++ b/src/tests/t_kdcpolicy.py -@@ -0,0 +1,57 @@ -+#!/usr/bin/python -+from k5test import * -+from datetime import datetime -+import re -+ -+testpreauth = os.path.join(buildtop, 'plugins', 'preauth', 'test', 'test.so') -+testpolicy = os.path.join(buildtop, 'plugins', 'kdcpolicy', 'test', -+ 'policy_test.so') -+krb5_conf = {'plugins': {'kdcpreauth': {'module': 'test:' + testpreauth}, -+ 'clpreauth': {'module': 'test:' + testpreauth}, -+ 'kdcpolicy': {'module': 'test:' + testpolicy}}} -+kdc_conf = {'realms': {'$realm': {'default_principal_flags': '+preauth', -+ 'max_renewable_life': '1d'}}} -+realm = K5Realm(krb5_conf=krb5_conf, kdc_conf=kdc_conf) -+ -+realm.run([kadminl, 'addprinc', '-pw', password('fail'), 'fail']) -+ -+def verify_time(out, target_time): -+ times = re.findall(r'\d\d/\d\d/\d\d \d\d:\d\d:\d\d', out) -+ times = [datetime.strptime(t, '%m/%d/%y %H:%M:%S') for t in times] -+ while len(times) > 0: -+ starttime = times.pop(0) -+ endtime = times.pop(0) -+ renewtime = times.pop(0) -+ -+ if str(endtime - starttime) != target_time: -+ fail('unexpected lifetime value') -+ if str(renewtime - endtime) != target_time: -+ fail('unexpected renewable value') -+ -+rflags = ['-r', '1d', '-l', '12h'] -+ -+# Test AS+TGS success path. -+realm.kinit(realm.user_princ, password('user'), -+ rflags + ['-X', 'indicators=SEVEN_HOURS']) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [SEVEN_HOURS]') -+out = realm.run([klist, realm.ccache, '-e']) -+verify_time(out, '7:00:00') -+ -+# Test AS+TGS success path with different values. -+realm.kinit(realm.user_princ, password('user'), -+ rflags + ['-X', 'indicators=ONE_HOUR']) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [ONE_HOUR]') -+out = realm.run([klist, realm.ccache, '-e']) -+verify_time(out, '1:00:00') -+ -+# Test TGS failure path (using previous creds). -+realm.run([kvno, 'fail@%s' % realm.realm], expected_code=1, -+ expected_msg='KDC policy rejects request') -+ -+# Test AS failure path. -+realm.kinit('fail@%s' % realm.realm, password('fail'), -+ expected_code=1, expected_msg='KDC policy rejects request') -+ -+success('kdcpolicy tests') diff --git a/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch b/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch deleted file mode 100644 index 94370dc..0000000 --- a/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch +++ /dev/null @@ -1,101 +0,0 @@ -From 6ce3a9416ee73fee41d0190e3fd0fde0a097c774 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Fri, 9 Dec 2016 11:43:27 -0500 -Subject: [PATCH] Add PKINIT UPN tests to t_pkinit.py - -[ghudson@mit.edu: simplify and explain tests; add test for -id-pkinit-san match against canonicalized client principal] - -ticket: 8528 -(cherry picked from commit d520fd3f032121b61b22681838af96ee505fe44d) ---- - src/tests/t_pkinit.py | 57 +++++++++++++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 57 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 526473b42..ac4d326b6 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -23,6 +23,9 @@ privkey_pem = os.path.join(certs, 'privkey.pem') - privkey_enc_pem = os.path.join(certs, 'privkey-enc.pem') - user_p12 = os.path.join(certs, 'user.p12') - user_enc_p12 = os.path.join(certs, 'user-enc.p12') -+user_upn_p12 = os.path.join(certs, 'user-upn.p12') -+user_upn2_p12 = os.path.join(certs, 'user-upn2.p12') -+user_upn3_p12 = os.path.join(certs, 'user-upn3.p12') - path = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs') - path_enc = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs-enc') - -@@ -36,6 +39,20 @@ pkinit_kdc_conf = {'realms': {'$realm': { - restrictive_kdc_conf = {'realms': {'$realm': { - 'restrict_anonymous_to_tgt': 'true' }}} - -+testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, -+ 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, -+ 'user2': {'keys': 'aes128-cts', 'flags': '+preauth'}} -+alias_kdc_conf = {'realms': {'$realm': { -+ 'default_principal_flags': '+preauth', -+ 'pkinit_eku_checking': 'none', -+ 'pkinit_allow_upn': 'true', -+ 'pkinit_identity': 'FILE:%s,%s' % (kdc_pem, privkey_pem), -+ 'database_module': 'test'}}, -+ 'dbmodules': {'test': { -+ 'db_library': 'test', -+ 'alias': {'user@krbtest.com': 'user'}, -+ 'princs': testprincs}}} -+ - file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) - file_enc_identity = 'FILE:%s,%s' % (user_pem, privkey_enc_pem) - dir_identity = 'DIR:%s' % path -@@ -45,11 +62,51 @@ dir_file_identity = 'FILE:%s,%s' % (os.path.join(path, 'user.crt'), - dir_file_enc_identity = 'FILE:%s,%s' % (os.path.join(path_enc, 'user.crt'), - os.path.join(path_enc, 'user.key')) - p12_identity = 'PKCS12:%s' % user_p12 -+p12_upn_identity = 'PKCS12:%s' % user_upn_p12 -+p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 -+p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 - p12_enc_identity = 'PKCS12:%s' % user_enc_p12 - p11_identity = 'PKCS11:soft-pkcs11.so' - p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' - 'slotid=1:token=SoftToken (token)') - -+# Start a realm with the test kdb module for the following UPN SAN tests. -+realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=alias_kdc_conf, -+ create_kdb=False) -+realm.start_kdc() -+ -+# Compatibility check: cert contains UPN "user", which matches the -+# request principal user@KRBTEST.COM if parsed as a normal principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn2_identity]) -+ -+# Compatibility check: cert contains UPN "user@KRBTEST.COM", which matches -+# the request principal user@KRBTEST.COM if parsed as a normal principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn3_identity]) -+ -+# Cert contains UPN "user@krbtest.com" which is aliased to the request -+# principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn_identity]) -+ -+# Test an id-pkinit-san match to a post-canonical principal. -+realm.kinit('user@krbtest.com', -+ flags=['-E', '-X', 'X509_user_identity=%s' % p12_identity]) -+ -+# Test a UPN match to a post-canonical principal. (This only works -+# for the cert with the UPN containing just "user", as we don't allow -+# UPN reparsing when comparing to the canonicalized client principal.) -+realm.kinit('user@krbtest.com', -+ flags=['-E', '-X', 'X509_user_identity=%s' % p12_upn2_identity]) -+ -+# Test a mismatch. -+out = realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, -+ 'user2'], expected_code=1) -+if 'kinit: Client name mismatch while getting initial credentials' not in out: -+ fail('Wrong error for UPN SAN mismatch') -+realm.stop() -+ - realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, - get_creds=False) - diff --git a/Add-PKINIT-test-case-for-generic-client-cert.patch b/Add-PKINIT-test-case-for-generic-client-cert.patch deleted file mode 100644 index e77dd5f..0000000 --- a/Add-PKINIT-test-case-for-generic-client-cert.patch +++ /dev/null @@ -1,51 +0,0 @@ -From e267849bcc3813989470c03565b22d25c71af91e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 25 Aug 2017 12:39:14 -0400 -Subject: [PATCH] Add PKINIT test case for generic client cert - -In t_pkinit.py, add a test case where a client cert with no extensions -is authorized via subject and issuer using a pkinit_cert_match string -attribute. - -ticket: 8562 -(cherry picked from commit 8c5d50888aab554239fd51306e79c5213833c898) -[rharwood@redhat.com: backport around dbmatch module] ---- - src/tests/t_pkinit.py | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index e943f4974..fa5c5199e 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -26,6 +26,7 @@ user_enc_p12 = os.path.join(certs, 'user-enc.p12') - user_upn_p12 = os.path.join(certs, 'user-upn.p12') - user_upn2_p12 = os.path.join(certs, 'user-upn2.p12') - user_upn3_p12 = os.path.join(certs, 'user-upn3.p12') -+generic_p12 = os.path.join(certs, 'generic.p12') - path = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs') - path_enc = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs-enc') - -@@ -65,6 +66,7 @@ p12_identity = 'PKCS12:%s' % user_p12 - p12_upn_identity = 'PKCS12:%s' % user_upn_p12 - p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 - p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 -+p12_generic_identity = 'PKCS12:%s' % generic_p12 - p12_enc_identity = 'PKCS12:%s' % user_enc_p12 - p11_identity = 'PKCS11:soft-pkcs11.so' - p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' -@@ -284,6 +286,14 @@ realm.run(['./responder', '-X', 'X509_user_identity=%s' % p12_enc_identity, - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - -+# Authorize a client cert with no PKINIT extensions using subject and -+# issuer. (Relies on EKU checking being turned off.) -+rule = '&&CN=user$O=MIT,' -+realm.run([kadminl, 'setstr', realm.user_princ, 'pkinit_cert_match', rule]) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_generic_identity]) -+realm.klist(realm.user_princ) -+ - if not have_soft_pkcs11: - skip_rest('PKINIT PKCS11 tests', 'soft-pkcs11.so not found') - diff --git a/Add-certauth-pluggable-interface.patch b/Add-certauth-pluggable-interface.patch deleted file mode 100644 index a9adc3e..0000000 --- a/Add-certauth-pluggable-interface.patch +++ /dev/null @@ -1,1146 +0,0 @@ -From 43418f21de72060932661242126fe611b6b17d84 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Tue, 28 Feb 2017 15:55:24 -0500 -Subject: [PATCH] Add certauth pluggable interface - -Add the header include/krb5/certauth_plugin.h, defining a pluggable -interface to control authorization of PKINIT client certificates. - -Add the "pkinit_san" and "pkinit_eku" builtin certauth modules and -related PKINIT crypto X.509 helper functions. Add authorize_cert() as -the entry function for certauth plugin module checks called in -pkinit_server_verify_padata(). Modify kdcpreauth_moddata to hold the -list of certauth module handles, and load the modules when the PKINIT -kdcpreauth server plugin is initialized. Change -crypto_retrieve_X509_sans() to return ENOENT when no SAN is found. - -Add test modules in plugins/certauth/test. Create t_certauth.py with -basic certauth tests. Add plugin interface documentation in -doc/plugindev/certauth.rst and doc/admin/krb5_conf.rst. - -[ghudson@mit.edu: simplified code, edited docs] - -ticket: 8561 (new) -(cherry picked from commit b619ce84470519bea65470be3263cd85fba94f57) ---- - doc/admin/conf_files/krb5_conf.rst | 21 ++ - doc/plugindev/certauth.rst | 27 ++ - doc/plugindev/index.rst | 1 + - src/Makefile.in | 1 + - src/configure.in | 1 + - src/include/Makefile.in | 1 + - src/include/k5-int.h | 3 +- - src/include/krb5/certauth_plugin.h | 103 +++++++ - src/lib/krb5/krb/plugin.c | 3 +- - src/plugins/certauth/test/Makefile.in | 20 ++ - src/plugins/certauth/test/certauth_test.exports | 2 + - src/plugins/certauth/test/deps | 14 + - src/plugins/certauth/test/main.c | 209 +++++++++++++ - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 + - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 30 ++ - src/plugins/preauth/pkinit/pkinit_srv.c | 335 ++++++++++++++++++--- - src/plugins/preauth/pkinit/pkinit_trace.h | 5 + - src/tests/Makefile.in | 1 + - src/tests/t_certauth.py | 47 +++ - 19 files changed, 786 insertions(+), 42 deletions(-) - create mode 100644 doc/plugindev/certauth.rst - create mode 100644 src/include/krb5/certauth_plugin.h - create mode 100644 src/plugins/certauth/test/Makefile.in - create mode 100644 src/plugins/certauth/test/certauth_test.exports - create mode 100644 src/plugins/certauth/test/deps - create mode 100644 src/plugins/certauth/test/main.c - create mode 100644 src/tests/t_certauth.py - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 02a935961..1d9bc9e34 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -859,6 +859,27 @@ built-in modules exist for this interface: - This module authorizes a principal to a local account if the - principal name maps to the local account name. - -+.. _certauth: -+ -+certauth interface -+################## -+ -+The certauth section (introduced in release 1.16) controls modules for -+the certificate authorization interface, which determines whether a -+certificate is allowed to preauthenticate a user via PKINIT. The -+following built-in modules exist for this interface: -+ -+**pkinit_san** -+ This module authorizes the certificate if it contains a PKINIT -+ Subject Alternative Name for the requested client principal, or a -+ Microsoft UPN SAN matching the principal if **pkinit_allow_upn** -+ is set to true for the realm. -+ -+**pkinit_eku** -+ This module rejects the certificate if it does not contain an -+ Extended Key Usage attribute consistent with the -+ **pkinit_eku_checking** value for the realm. -+ - - PKINIT options - -------------- -diff --git a/doc/plugindev/certauth.rst b/doc/plugindev/certauth.rst -new file mode 100644 -index 000000000..8a7f7c5eb ---- /dev/null -+++ b/doc/plugindev/certauth.rst -@@ -0,0 +1,27 @@ -+.. _certauth_plugin: -+ -+PKINIT certificate authorization interface (certauth) -+===================================================== -+ -+The certauth interface was first introduced in release 1.16. It -+allows customization of the X.509 certificate attribute requirements -+placed on certificates used by PKINIT enabled clients. For a detailed -+description of the certauth interface, see the header file -+```` -+ -+A certauth module implements the **authorize** method to determine -+whether a client's certificate is authorized to authenticate a client -+principal. **authorize** receives the DER-encoded certificate, the -+requested client principal, and a pointer to the client's -+krb5_db_entry (for modules that link against libkdb5). It returns the -+authorization status and optionally outputs a list of authentication -+indicator strings to be added to the ticket. A module must use its -+own internal or library-provided ASN.1 certificate decoder. -+ -+A module can optionally create and destroy module data with the -+**init** and **fini** methods. Module data objects last for the -+lifetime of the KDC process. -+ -+If a module allocates and returns a list of authentication indicators -+from **authorize**, it must also implement the **free_ind** method -+to free the list. -diff --git a/doc/plugindev/index.rst b/doc/plugindev/index.rst -index 3fb921778..67dbc2790 100644 ---- a/doc/plugindev/index.rst -+++ b/doc/plugindev/index.rst -@@ -31,5 +31,6 @@ Contents - profile.rst - gssapi.rst - internal.rst -+ certauth.rst - - .. TODO: GSSAPI mechanism plugins -diff --git a/src/Makefile.in b/src/Makefile.in -index 2ebf2fb4d..b0249778c 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -17,6 +17,7 @@ SUBDIRS=util include lib \ - plugins/pwqual/test \ - plugins/authdata/greet_server \ - plugins/authdata/greet_client \ -+ plugins/certauth/test \ - plugins/kdb/db2 \ - @ldap_plugin_dir@ \ - plugins/kdb/test \ -diff --git a/src/configure.in b/src/configure.in -index acf3a458b..24f653f0d 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1451,6 +1451,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test - - kdc slave config-files build-tools man doc include - -+ plugins/certauth/test - plugins/hostrealm/test - plugins/localauth/test - plugins/kadm5_hook/test -diff --git a/src/include/Makefile.in b/src/include/Makefile.in -index f5b921833..0239338a1 100644 ---- a/src/include/Makefile.in -+++ b/src/include/Makefile.in -@@ -140,6 +140,7 @@ install-headers-unix install: krb5/krb5.h profile.h - $(INSTALL_DATA) $(srcdir)/krb5.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5.h - $(INSTALL_DATA) $(srcdir)/kdb.h $(DESTDIR)$(KRB5_INCDIR)$(S)kdb.h - $(INSTALL_DATA) krb5/krb5.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)krb5.h -+ $(INSTALL_DATA) $(srcdir)/krb5/certauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)certauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/ccselect_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)ccselect_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/clpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)clpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/hostrealm_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)hostrealm_plugin.h -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 173cb0264..cea644d0a 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1156,7 +1156,8 @@ struct plugin_interface { - #define PLUGIN_INTERFACE_AUDIT 7 - #define PLUGIN_INTERFACE_TLS 8 - #define PLUGIN_INTERFACE_KDCAUTHDATA 9 --#define PLUGIN_NUM_INTERFACES 10 -+#define PLUGIN_INTERFACE_CERTAUTH 10 -+#define PLUGIN_NUM_INTERFACES 11 - - /* Retrieve the plugin module of type interface_id and name modname, - * storing the result into module. */ -diff --git a/src/include/krb5/certauth_plugin.h b/src/include/krb5/certauth_plugin.h -new file mode 100644 -index 000000000..f22fc1e84 ---- /dev/null -+++ b/src/include/krb5/certauth_plugin.h -@@ -0,0 +1,103 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/certauth_plugin.h - certauth plugin header. */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * Certificate authorization plugin interface. The PKINIT server module uses -+ * this interface to check client certificate attributes after the certificate -+ * signature has been verified. -+ */ -+#ifndef KRB5_CERTAUTH_PLUGIN_H -+#define KRB5_CERTAUTH_PLUGIN_H -+ -+#include -+#include -+ -+/* Abstract module data type. */ -+typedef struct krb5_certauth_moddata_st *krb5_certauth_moddata; -+ -+typedef struct _krb5_db_entry_new krb5_db_entry; -+ -+/* -+ * Optional: Initialize module data. -+ */ -+typedef krb5_error_code -+(*krb5_certauth_init_fn)(krb5_context context, -+ krb5_certauth_moddata *moddata_out); -+ -+/* -+ * Optional: Clean up the module data. -+ */ -+typedef void -+(*krb5_certauth_fini_fn)(krb5_context context, krb5_certauth_moddata moddata); -+ -+/* -+ * Mandatory: -+ * Return 0 if the DER-encoded cert is authorized for PKINIT authentication by -+ * princ; otherwise return one of the following error codes: -+ * - KRB5KDC_ERR_CLIENT_NAME_MISMATCH - incorrect SAN value -+ * - KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE - incorrect EKU -+ * - KRB5KDC_ERR_CERTIFICATE_MISMATCH - other extension error -+ * - KRB5_PLUGIN_NO_HANDLE - the module has no opinion about cert -+ * -+ * - opts is used by built-in modules to receive internal data, and must be -+ * ignored by other modules. -+ * - db_entry receives the client principal database entry, and can be ignored -+ * by modules that do not link with libkdb5. -+ * - *authinds_out optionally returns a null-terminated list of authentication -+ * indicator strings upon KRB5_PLUGIN_NO_HANDLE or accepted authorization. -+ */ -+typedef krb5_error_code -+(*krb5_certauth_authorize_fn)(krb5_context context, -+ krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, -+ char ***authinds_out); -+ -+/* -+ * Free indicators allocated by a module. Mandatory if authorize returns -+ * authentication indicators. -+ */ -+typedef void -+(*krb5_certauth_free_indicator_fn)(krb5_context context, -+ krb5_certauth_moddata moddata, -+ char **authinds); -+ -+typedef struct krb5_certauth_vtable_st { -+ char *name; -+ krb5_certauth_init_fn init; -+ krb5_certauth_fini_fn fini; -+ krb5_certauth_authorize_fn authorize; -+ krb5_certauth_free_indicator_fn free_ind; -+} *krb5_certauth_vtable; -+ -+#endif /* KRB5_CERTAUTH_PLUGIN_H */ -diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c -index 7d64b7c7e..17dd6bd30 100644 ---- a/src/lib/krb5/krb/plugin.c -+++ b/src/lib/krb5/krb/plugin.c -@@ -57,7 +57,8 @@ const char *interface_names[] = { - "hostrealm", - "audit", - "tls", -- "kdcauthdata" -+ "kdcauthdata", -+ "certauth" - }; - - /* Return the context's interface structure for id, or NULL if invalid. */ -diff --git a/src/plugins/certauth/test/Makefile.in b/src/plugins/certauth/test/Makefile.in -new file mode 100644 -index 000000000..d3524084c ---- /dev/null -+++ b/src/plugins/certauth/test/Makefile.in -@@ -0,0 +1,20 @@ -+mydir=plugins$(S)certauth$(S)test -+BUILDTOP=$(REL)..$(S)..$(S).. -+ -+LIBBASE=certauth_test -+LIBMAJOR=0 -+LIBMINOR=0 -+RELDIR=../plugins/certauth/test -+SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) -+ -+STLIBOBJS=main.o -+ -+SRCS=$(srcdir)/main.c -+ -+all-unix: all-libs -+install-unix: -+clean-unix:: clean-libs clean-libobjs -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/plugins/certauth/test/certauth_test.exports b/src/plugins/certauth/test/certauth_test.exports -new file mode 100644 -index 000000000..1c8cd24e2 ---- /dev/null -+++ b/src/plugins/certauth/test/certauth_test.exports -@@ -0,0 +1,2 @@ -+certauth_test1_initvt -+certauth_test2_initvt -diff --git a/src/plugins/certauth/test/deps b/src/plugins/certauth/test/deps -new file mode 100644 -index 000000000..2974b3b57 ---- /dev/null -+++ b/src/plugins/certauth/test/deps -@@ -0,0 +1,14 @@ -+# -+# Generated makefile dependencies follow. -+# -+main.so main.po $(OUTPRE)main.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -+ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/certauth_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ main.c -diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c -new file mode 100644 -index 000000000..7ef7377fb ---- /dev/null -+++ b/src/plugins/certauth/test/main.c -@@ -0,0 +1,209 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/certauth/main.c - certauth plugin test modules. */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include "krb5/certauth_plugin.h" -+ -+struct krb5_certauth_moddata_st { -+ int initialized; -+}; -+ -+/* Test module 1 returns OK with an indicator. */ -+static krb5_error_code -+test1_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ char **ais = NULL; -+ -+ ais = calloc(2, sizeof(*ais)); -+ assert(ais != NULL); -+ ais[0] = strdup("test1"); -+ assert(ais[0] != NULL); -+ *authinds_out = ais; -+ return KRB5_PLUGIN_NO_HANDLE; -+} -+ -+static void -+test_free_ind(krb5_context context, krb5_certauth_moddata moddata, -+ char **authinds) -+{ -+ size_t i; -+ -+ if (authinds == NULL) -+ return; -+ for (i = 0; authinds[i] != NULL; i++) -+ free(authinds[i]); -+ free(authinds); -+} -+ -+/* A basic moddata test. */ -+static krb5_error_code -+test2_init(krb5_context context, krb5_certauth_moddata *moddata_out) -+{ -+ krb5_certauth_moddata mod; -+ -+ mod = calloc(1, sizeof(*mod)); -+ assert(mod != NULL); -+ mod->initialized = 1; -+ *moddata_out = mod; -+ return 0; -+} -+ -+static void -+test2_fini(krb5_context context, krb5_certauth_moddata moddata) -+{ -+ free(moddata); -+} -+ -+/* Return true if cert appears to contain the CN name, based on a search of the -+ * DER encoding. */ -+static krb5_boolean -+has_cn(krb5_context context, const uint8_t *cert, size_t cert_len, -+ const char *name) -+{ -+ krb5_boolean match = FALSE; -+ uint8_t name_len, cntag[5] = "\x06\x03\x55\x04\x03"; -+ const uint8_t *c; -+ struct k5buf buf; -+ size_t c_left; -+ -+ /* Construct a DER search string of the CN AttributeType encoding followed -+ * by a UTF8String encoding containing name as the AttributeValue. */ -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add_len(&buf, cntag, sizeof(cntag)); -+ k5_buf_add(&buf, "\x0C"); -+ assert(strlen(name) < 128); -+ name_len = strlen(name); -+ k5_buf_add_len(&buf, &name_len, 1); -+ k5_buf_add_len(&buf, name, name_len); -+ assert(k5_buf_status(&buf) == 0); -+ -+ /* Check for the CN needle in the certificate haystack. */ -+ c_left = cert_len; -+ c = memchr(cert, *cntag, c_left); -+ while (c != NULL) { -+ c_left = cert_len - (c - cert); -+ if (buf.len > c_left) -+ break; -+ if (memcmp(c, buf.data, buf.len) == 0) { -+ match = TRUE; -+ break; -+ } -+ assert(c_left >= 1); -+ c = memchr(c + 1, *cntag, c_left - 1); -+ } -+ -+ k5_buf_free(&buf); -+ return match; -+} -+ -+/* -+ * Test module 2 returns OK if princ matches the CN part of the subject name, -+ * and returns indicators of the module name and princ. -+ */ -+static krb5_error_code -+test2_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ char *name = NULL, **ais = NULL; -+ -+ *authinds_out = NULL; -+ -+ assert(moddata != NULL && moddata->initialized); -+ -+ ret = krb5_unparse_name_flags(context, princ, -+ KRB5_PRINCIPAL_UNPARSE_NO_REALM, &name); -+ if (ret) -+ goto cleanup; -+ -+ if (!has_cn(context, cert, cert_len, name)) { -+ ret = KRB5KDC_ERR_CERTIFICATE_MISMATCH; -+ goto cleanup; -+ } -+ -+ /* Create an indicator list with the module name and CN. */ -+ ais = calloc(3, sizeof(*ais)); -+ assert(ais != NULL); -+ ais[0] = strdup("test2"); -+ ais[1] = strdup(name); -+ assert(ais[0] != NULL && ais[1] != NULL); -+ *authinds_out = ais; -+ -+ ais = NULL; -+ -+cleanup: -+ krb5_free_unparsed_name(context, name); -+ return ret; -+} -+ -+krb5_error_code -+certauth_test1_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+certauth_test1_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "test1"; -+ vt->authorize = test1_authorize; -+ vt->free_ind = test_free_ind; -+ return 0; -+} -+ -+krb5_error_code -+certauth_test2_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+certauth_test2_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "test2"; -+ vt->authorize = test2_authorize; -+ vt->init = test2_init; -+ vt->fini = test2_fini; -+ vt->free_ind = test_free_ind; -+ return 0; -+} -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index b483affed..49b96b8ee 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -664,4 +664,8 @@ extern const size_t krb5_pkinit_sha512_oid_len; - */ - extern krb5_data const * const supported_kdf_alg_ids[]; - -+krb5_error_code -+crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, -+ uint8_t **der_out, size_t *der_len); -+ - #endif /* _PKINIT_CRYPTO_H */ -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 8def8c542..a5b010b26 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2137,6 +2137,7 @@ crypto_retrieve_X509_sans(krb5_context context, - - if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { - pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -+ retval = ENOENT; - goto cleanup; - } - num_sans = sk_GENERAL_NAME_num(ialt); -@@ -6176,3 +6177,32 @@ crypto_get_deferred_ids(krb5_context context, - ret = (const pkinit_deferred_id *)deferred; - return ret; - } -+ -+/* Return the received certificate as DER-encoded data. */ -+krb5_error_code -+crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, -+ uint8_t **der_out, size_t *der_len) -+{ -+ int len; -+ unsigned char *der, *p; -+ -+ *der_out = NULL; -+ *der_len = 0; -+ -+ if (reqctx->received_cert == NULL) -+ return EINVAL; -+ p = NULL; -+ len = i2d_X509(reqctx->received_cert, NULL); -+ if (len <= 0) -+ return EINVAL; -+ p = der = malloc(len); -+ if (p == NULL) -+ return ENOMEM; -+ if (i2d_X509(reqctx->received_cert, &p) <= 0) { -+ free(p); -+ return EINVAL; -+ } -+ *der_out = der; -+ *der_len = len; -+ return 0; -+} -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index b5638a367..731d14eb8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -31,6 +31,25 @@ - - #include - #include "pkinit.h" -+#include "krb5/certauth_plugin.h" -+ -+/* Aliases used by the built-in certauth modules */ -+struct certauth_req_opts { -+ krb5_kdcpreauth_callbacks cb; -+ krb5_kdcpreauth_rock rock; -+ pkinit_kdc_context plgctx; -+ pkinit_kdc_req_context reqctx; -+}; -+ -+typedef struct certauth_module_handle_st { -+ struct krb5_certauth_vtable_st vt; -+ krb5_certauth_moddata moddata; -+} *certauth_handle; -+ -+struct krb5_kdcpreauth_moddata_st { -+ pkinit_kdc_context *realm_contexts; -+ certauth_handle *certauth_modules; -+}; - - static krb5_error_code - pkinit_init_kdc_req_context(krb5_context, pkinit_kdc_req_context *blob); -@@ -51,6 +70,34 @@ pkinit_find_realm_context(krb5_context context, - krb5_kdcpreauth_moddata moddata, - krb5_principal princ); - -+static void -+free_realm_contexts(krb5_context context, pkinit_kdc_context *realm_contexts) -+{ -+ int i; -+ -+ if (realm_contexts == NULL) -+ return; -+ for (i = 0; realm_contexts[i] != NULL; i++) -+ pkinit_server_plugin_fini_realm(context, realm_contexts[i]); -+ pkiDebug("%s: freeing context at %p\n", __FUNCTION__, realm_contexts); -+ free(realm_contexts); -+} -+ -+static void -+free_certauth_handles(krb5_context context, certauth_handle *list) -+{ -+ int i; -+ -+ if (list == NULL) -+ return; -+ for (i = 0; list[i] != NULL; i++) { -+ if (list[i]->vt.fini != NULL) -+ list[i]->vt.fini(context, list[i]->moddata); -+ free(list[i]); -+ } -+ free(list); -+} -+ - static krb5_error_code - pkinit_create_edata(krb5_context context, - pkinit_plg_crypto_context plg_cryptoctx, -@@ -123,7 +170,7 @@ verify_client_san(krb5_context context, - pkinit_kdc_req_context reqctx, - krb5_kdcpreauth_callbacks cb, - krb5_kdcpreauth_rock rock, -- krb5_principal client, -+ krb5_const_principal client, - int *valid_san) - { - krb5_error_code retval; -@@ -134,12 +181,15 @@ verify_client_san(krb5_context context, - char *client_string = NULL, *san_string; - #endif - -+ *valid_san = 0; - retval = crypto_retrieve_cert_sans(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &princs, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); -- if (retval) { -+ if (retval == ENOENT) { -+ goto out; -+ } else if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); - retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - goto out; -@@ -273,6 +323,73 @@ out: - return retval; - } - -+ -+/* Run the received, verified certificate through certauth modules, to verify -+ * that it is authorized to authenticate as client. */ -+static krb5_error_code -+authorize_cert(krb5_context context, certauth_handle *certauth_modules, -+ pkinit_kdc_context plgctx, pkinit_kdc_req_context reqctx, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_principal client) -+{ -+ krb5_error_code ret; -+ certauth_handle h; -+ struct certauth_req_opts opts; -+ krb5_boolean accepted = FALSE; -+ uint8_t *cert; -+ size_t i, cert_len; -+ void *db_ent = NULL; -+ char **ais = NULL, **ai = NULL; -+ -+ /* Re-encode the received certificate into DER, which is extra work, but -+ * avoids creating an X.509 library dependency in the interface. */ -+ ret = crypto_encode_der_cert(context, reqctx->cryptoctx, &cert, &cert_len); -+ if (ret) -+ goto cleanup; -+ -+ /* Set options for the builtin module. */ -+ opts.plgctx = plgctx; -+ opts.reqctx = reqctx; -+ opts.cb = cb; -+ opts.rock = rock; -+ -+ db_ent = cb->client_entry(context, rock); -+ -+ /* -+ * Check the certificate against each certauth module. For the certificate -+ * to be authorized at least one module must return 0, and no module can an -+ * error code other than KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from -+ * modules that return 0 or pass. -+ */ -+ ret = KRB5_PLUGIN_NO_HANDLE; -+ for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { -+ h = certauth_modules[i]; -+ ret = h->vt.authorize(context, h->moddata, cert, cert_len, client, -+ &opts, db_ent, &ais); -+ if (ret == 0) -+ accepted = TRUE; -+ else if (ret != KRB5_PLUGIN_NO_HANDLE) -+ goto cleanup; -+ -+ if (ais != NULL) { -+ /* Assert authentication indicators from the module. */ -+ for (ai = ais; *ai != NULL; ai++) { -+ ret = cb->add_auth_indicator(context, rock, *ai); -+ if (ret) -+ goto cleanup; -+ } -+ h->vt.free_ind(context, h->moddata, ais); -+ ais = NULL; -+ } -+ } -+ -+ ret = accepted ? 0 : KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -+ -+cleanup: -+ free(cert); -+ return ret; -+} -+ - static void - pkinit_server_verify_padata(krb5_context context, - krb5_data *req_pkt, -@@ -295,7 +412,6 @@ pkinit_server_verify_padata(krb5_context context, - pkinit_kdc_req_context reqctx = NULL; - krb5_checksum cksum = {0, 0, 0, NULL}; - krb5_data *der_req = NULL; -- int valid_eku = 0, valid_san = 0; - krb5_data k5data; - int is_signed = 1; - krb5_pa_data **e_data = NULL; -@@ -388,27 +504,11 @@ pkinit_server_verify_padata(krb5_context context, - goto cleanup; - } - if (is_signed) { -- -- retval = verify_client_san(context, plgctx, reqctx, cb, rock, -- request->client, &valid_san); -- if (retval) -- goto cleanup; -- if (!valid_san) { -- pkiDebug("%s: did not find an acceptable SAN in user " -- "certificate\n", __FUNCTION__); -- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -- goto cleanup; -- } -- retval = verify_client_eku(context, plgctx, reqctx, &valid_eku); -+ retval = authorize_cert(context, moddata->certauth_modules, plgctx, -+ reqctx, cb, rock, request->client); - if (retval) - goto cleanup; - -- if (!valid_eku) { -- pkiDebug("%s: did not find an acceptable EKU in user " -- "certificate\n", __FUNCTION__); -- retval = KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; -- goto cleanup; -- } - } else { /* !is_signed */ - if (!krb5_principal_compare(context, request->client, - krb5_anonymous_principal())) { -@@ -1245,11 +1345,15 @@ pkinit_find_realm_context(krb5_context context, - krb5_principal princ) - { - int i; -- pkinit_kdc_context *realm_contexts = (pkinit_kdc_context *)moddata; -+ pkinit_kdc_context *realm_contexts; - - if (moddata == NULL) - return NULL; - -+ realm_contexts = moddata->realm_contexts; -+ if (realm_contexts == NULL) -+ return NULL; -+ - for (i = 0; realm_contexts[i] != NULL; i++) { - pkinit_kdc_context p = realm_contexts[i]; - -@@ -1331,6 +1435,155 @@ errout: - return retval; - } - -+static krb5_error_code -+pkinit_san_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ int valid_san; -+ const struct certauth_req_opts *req_opts = opts; -+ -+ *authinds_out = NULL; -+ -+ ret = verify_client_san(context, req_opts->plgctx, req_opts->reqctx, -+ req_opts->cb, req_opts->rock, princ, &valid_san); -+ if (ret == ENOENT) -+ return KRB5_PLUGIN_NO_HANDLE; -+ else if (ret) -+ return ret; -+ -+ if (!valid_san) { -+ pkiDebug("%s: did not find an acceptable SAN in user certificate\n", -+ __FUNCTION__); -+ return KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -+ } -+ -+ return 0; -+} -+ -+static krb5_error_code -+pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ int valid_eku; -+ const struct certauth_req_opts *req_opts = opts; -+ -+ *authinds_out = NULL; -+ -+ /* Verify the client EKU. */ -+ ret = verify_client_eku(context, req_opts->plgctx, req_opts->reqctx, -+ &valid_eku); -+ if (ret) -+ return ret; -+ -+ if (!valid_eku) { -+ pkiDebug("%s: did not find an acceptable EKU in user certificate\n", -+ __FUNCTION__); -+ return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; -+ } -+ -+ return 0; -+} -+ -+static krb5_error_code -+certauth_pkinit_san_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "pkinit_san"; -+ vt->authorize = pkinit_san_authorize; -+ return 0; -+} -+ -+static krb5_error_code -+certauth_pkinit_eku_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "pkinit_eku"; -+ vt->authorize = pkinit_eku_authorize; -+ return 0; -+} -+ -+static krb5_error_code -+load_certauth_plugins(krb5_context context, certauth_handle **handle_out) -+{ -+ krb5_error_code ret; -+ krb5_plugin_initvt_fn *modules = NULL, *mod; -+ certauth_handle *list = NULL, h; -+ size_t count; -+ -+ /* Register the builtin modules. */ -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CERTAUTH, -+ "pkinit_san", certauth_pkinit_san_initvt); -+ if (ret) -+ goto cleanup; -+ -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CERTAUTH, -+ "pkinit_eku", certauth_pkinit_eku_initvt); -+ if (ret) -+ goto cleanup; -+ -+ ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_CERTAUTH, &modules); -+ if (ret) -+ goto cleanup; -+ -+ /* Allocate handle list. */ -+ for (count = 0; modules[count]; count++); -+ list = k5calloc(count + 1, sizeof(*list), &ret); -+ if (list == NULL) -+ goto cleanup; -+ -+ /* Initialize each module, ignoring ones that fail. */ -+ count = 0; -+ for (mod = modules; *mod != NULL; mod++) { -+ h = k5calloc(1, sizeof(*h), &ret); -+ if (h == NULL) -+ goto cleanup; -+ -+ ret = (*mod)(context, 1, 1, (krb5_plugin_vtable)&h->vt); -+ if (ret) { -+ TRACE_CERTAUTH_VTINIT_FAIL(context, ret); -+ free(h); -+ continue; -+ } -+ h->moddata = NULL; -+ if (h->vt.init != NULL) { -+ ret = h->vt.init(context, &h->moddata); -+ if (ret) { -+ TRACE_CERTAUTH_INIT_FAIL(context, h->vt.name, ret); -+ free(h); -+ continue; -+ } -+ } -+ list[count++] = h; -+ list[count] = NULL; -+ } -+ list[count] = NULL; -+ -+ ret = 0; -+ *handle_out = list; -+ list = NULL; -+ -+cleanup: -+ k5_plugin_free_modules(context, modules); -+ free_certauth_handles(context, list); -+ return ret; -+} -+ - static int - pkinit_server_plugin_init(krb5_context context, - krb5_kdcpreauth_moddata *moddata_out, -@@ -1338,6 +1591,8 @@ pkinit_server_plugin_init(krb5_context context, - { - krb5_error_code retval = ENOMEM; - pkinit_kdc_context plgctx, *realm_contexts = NULL; -+ certauth_handle *certauth_modules = NULL; -+ krb5_kdcpreauth_moddata moddata; - size_t i, j; - size_t numrealms; - -@@ -1368,16 +1623,22 @@ pkinit_server_plugin_init(krb5_context context, - goto errout; - } - -- *moddata_out = (krb5_kdcpreauth_moddata)realm_contexts; -- retval = 0; -- pkiDebug("%s: returning context at %p\n", __FUNCTION__, realm_contexts); -+ retval = load_certauth_plugins(context, &certauth_modules); -+ if (retval) -+ goto errout; -+ -+ moddata = k5calloc(1, sizeof(*moddata), &retval); -+ if (moddata == NULL) -+ goto errout; -+ moddata->realm_contexts = realm_contexts; -+ moddata->certauth_modules = certauth_modules; -+ *moddata_out = moddata; -+ pkiDebug("%s: returning context at %p\n", __FUNCTION__, moddata); -+ return 0; - - errout: -- if (retval) { -- pkinit_server_plugin_fini(context, -- (krb5_kdcpreauth_moddata)realm_contexts); -- } -- -+ free_realm_contexts(context, realm_contexts); -+ free_certauth_handles(context, certauth_modules); - return retval; - } - -@@ -1405,17 +1666,11 @@ static void - pkinit_server_plugin_fini(krb5_context context, - krb5_kdcpreauth_moddata moddata) - { -- pkinit_kdc_context *realm_contexts = (pkinit_kdc_context *)moddata; -- int i; -- -- if (realm_contexts == NULL) -+ if (moddata == NULL) - return; -- -- for (i = 0; realm_contexts[i] != NULL; i++) { -- pkinit_server_plugin_fini_realm(context, realm_contexts[i]); -- } -- pkiDebug("%s: freeing context at %p\n", __FUNCTION__, realm_contexts); -- free(realm_contexts); -+ free_realm_contexts(context, moddata->realm_contexts); -+ free_certauth_handles(context, moddata->certauth_modules); -+ free(moddata); - } - - static krb5_error_code -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index b3f5cbb20..458d0961e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -91,4 +91,9 @@ - #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ - TRACE(c, "PKINIT OpenSSL error: {str}", msg) - -+#define TRACE_CERTAUTH_VTINIT_FAIL(c, ret) \ -+ TRACE(c, "certauth module failed to init vtable: {kerr}", ret) -+#define TRACE_CERTAUTH_INIT_FAIL(c, name, ret) \ -+ TRACE(c, "certauth module {str} failed to init: {kerr}", name, ret) -+ - #endif /* PKINIT_TRACE_H */ -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index b55469146..0e93d6b59 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -167,6 +167,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_preauth.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_princflags.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py -new file mode 100644 -index 000000000..e64a57b0d ---- /dev/null -+++ b/src/tests/t_certauth.py -@@ -0,0 +1,47 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# Skip this test if pkinit wasn't built. -+if not os.path.exists(os.path.join(plugins, 'preauth', 'pkinit.so')): -+ skip_rest('certauth tests', 'PKINIT module not built') -+ -+certs = os.path.join(srctop, 'tests', 'dejagnu', 'pkinit-certs') -+ca_pem = os.path.join(certs, 'ca.pem') -+kdc_pem = os.path.join(certs, 'kdc.pem') -+privkey_pem = os.path.join(certs, 'privkey.pem') -+user_pem = os.path.join(certs, 'user.pem') -+ -+modpath = os.path.join(buildtop, 'plugins', 'certauth', 'test', -+ 'certauth_test.so') -+pkinit_krb5_conf = {'realms': {'$realm': { -+ 'pkinit_anchors': 'FILE:%s' % ca_pem}}, -+ 'plugins': {'certauth': {'module': ['test1:' + modpath, -+ 'test2:' + modpath], -+ 'enable_only': ['test1', 'test2']}}} -+pkinit_kdc_conf = {'realms': {'$realm': { -+ 'default_principal_flags': '+preauth', -+ 'pkinit_eku_checking': 'none', -+ 'pkinit_identity': 'FILE:%s,%s' % (kdc_pem, privkey_pem), -+ 'pkinit_indicator': ['indpkinit1', 'indpkinit2']}}} -+ -+file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) -+ -+realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, -+ get_creds=False) -+ -+# Let the test module match user to CN=user, with indicators. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity]) -+realm.klist(realm.user_princ) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], -+ expected_msg='+97: [test1, test2, user, indpkinit1, indpkinit2]') -+ -+# Let the test module mismatch with user2 to CN=user. -+realm.addprinc("user2@KRBTEST.COM") -+out = realm.kinit("user2@KRBTEST.COM", -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_code=1, -+ expected_msg='kinit: Certificate mismatch') -+ -+success("certauth tests") diff --git a/Add-hostname-based-ccselect-module.patch b/Add-hostname-based-ccselect-module.patch deleted file mode 100644 index b56b8d3..0000000 --- a/Add-hostname-based-ccselect-module.patch +++ /dev/null @@ -1,293 +0,0 @@ -From 632575ab12fc5d6c9bdc83cb8200fb8f4f422b83 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 23 Aug 2017 17:25:17 -0400 -Subject: [PATCH] Add hostname-based ccselect module - -The hostname module selects the ccache whose realm is the longest -parent domain tail of the uppercase server hostname. - -[ghudson@mit.edu: minor edits] - -ticket: 8613 (new) -(cherry picked from commit a4ddc6cf576b4155e6b994307902567f26f752b2) ---- - doc/admin/conf_files/krb5_conf.rst | 4 + - src/lib/krb5/ccache/Makefile.in | 3 + - src/lib/krb5/ccache/cc-int.h | 4 + - src/lib/krb5/ccache/ccselect.c | 5 ++ - src/lib/krb5/ccache/ccselect_hostname.c | 146 ++++++++++++++++++++++++++++++++ - src/tests/gssapi/t_ccselect.py | 9 ++ - 6 files changed, 171 insertions(+) - create mode 100644 src/lib/krb5/ccache/ccselect_hostname.c - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d9bc9e34..9c1ee94a4 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -745,6 +745,10 @@ disabled with the disable tag): - Uses the service realm to guess an appropriate cache from the - collection - -+**hostname** -+ If the service principal is host-based, uses the service hostname -+ to guess an appropriate cache from the collection -+ - .. _pwqual: - - pwqual interface -diff --git a/src/lib/krb5/ccache/Makefile.in b/src/lib/krb5/ccache/Makefile.in -index 5ac870728..f84cf793e 100644 ---- a/src/lib/krb5/ccache/Makefile.in -+++ b/src/lib/krb5/ccache/Makefile.in -@@ -34,6 +34,7 @@ STLIBOBJS= \ - ccdefops.o \ - ccmarshal.o \ - ccselect.o \ -+ ccselect_hostname.o \ - ccselect_k5identity.o \ - ccselect_realm.o \ - cc_dir.o \ -@@ -52,6 +53,7 @@ OBJS= $(OUTPRE)ccbase.$(OBJEXT) \ - $(OUTPRE)ccdefops.$(OBJEXT) \ - $(OUTPRE)ccmarshal.$(OBJEXT) \ - $(OUTPRE)ccselect.$(OBJEXT) \ -+ $(OUTPRE)ccselect_hostname.$(OBJEXT) \ - $(OUTPRE)ccselect_k5identity.$(OBJEXT) \ - $(OUTPRE)ccselect_realm.$(OBJEXT) \ - $(OUTPRE)cc_dir.$(OBJEXT) \ -@@ -70,6 +72,7 @@ SRCS= $(srcdir)/ccbase.c \ - $(srcdir)/ccdefops.c \ - $(srcdir)/ccmarshal.c \ - $(srcdir)/ccselect.c \ -+ $(srcdir)/ccselect_hostname.c \ - $(srcdir)/ccselect_k5identity.c \ - $(srcdir)/ccselect_realm.c \ - $(srcdir)/cc_dir.c \ -diff --git a/src/lib/krb5/ccache/cc-int.h b/src/lib/krb5/ccache/cc-int.h -index ee9b5e0e9..d920367ce 100644 ---- a/src/lib/krb5/ccache/cc-int.h -+++ b/src/lib/krb5/ccache/cc-int.h -@@ -123,6 +123,10 @@ k5_cccol_force_unlock(void); - krb5_error_code - krb5int_fcc_new_unique(krb5_context context, char *template, krb5_ccache *id); - -+krb5_error_code -+ccselect_hostname_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+ - krb5_error_code - ccselect_realm_initvt(krb5_context context, int maj_ver, int min_ver, - krb5_plugin_vtable vtable); -diff --git a/src/lib/krb5/ccache/ccselect.c b/src/lib/krb5/ccache/ccselect.c -index ee4b83a9b..393d39733 100644 ---- a/src/lib/krb5/ccache/ccselect.c -+++ b/src/lib/krb5/ccache/ccselect.c -@@ -71,6 +71,11 @@ load_modules(krb5_context context) - if (ret != 0) - goto cleanup; - -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CCSELECT, "hostname", -+ ccselect_hostname_initvt); -+ if (ret != 0) -+ goto cleanup; -+ - ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_CCSELECT, &modules); - if (ret != 0) - goto cleanup; -diff --git a/src/lib/krb5/ccache/ccselect_hostname.c b/src/lib/krb5/ccache/ccselect_hostname.c -new file mode 100644 -index 000000000..475cfabae ---- /dev/null -+++ b/src/lib/krb5/ccache/ccselect_hostname.c -@@ -0,0 +1,146 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* lib/krb5/ccache/ccselect_hostname.c - hostname ccselect module */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "cc-int.h" -+#include -+#include -+ -+/* Swap a and b, using tmp as an intermediate. */ -+#define SWAP(a, b, tmp) \ -+ tmp = a; \ -+ a = b; \ -+ b = tmp; -+ -+static krb5_error_code -+hostname_init(krb5_context context, krb5_ccselect_moddata *data_out, -+ int *priority_out) -+{ -+ *data_out = NULL; -+ *priority_out = KRB5_CCSELECT_PRIORITY_HEURISTIC; -+ return 0; -+} -+ -+static krb5_error_code -+hostname_choose(krb5_context context, krb5_ccselect_moddata data, -+ krb5_principal server, krb5_ccache *ccache_out, -+ krb5_principal *princ_out) -+{ -+ krb5_error_code ret; -+ char *p, *host = NULL; -+ size_t hostlen; -+ krb5_cccol_cursor col_cursor; -+ krb5_ccache ccache, tmp_ccache, best_ccache = NULL; -+ krb5_principal princ, tmp_princ, best_princ = NULL; -+ krb5_data domain; -+ -+ *ccache_out = NULL; -+ *princ_out = NULL; -+ -+ if (server->type != KRB5_NT_SRV_HST || server->length < 2) -+ return KRB5_PLUGIN_NO_HANDLE; -+ -+ /* Compute upper-case hostname. */ -+ hostlen = server->data[1].length; -+ host = k5memdup0(server->data[1].data, hostlen, &ret); -+ if (host == NULL) -+ return ret; -+ for (p = host; *p != '\0'; p++) { -+ if (islower(*p)) -+ *p = toupper(*p); -+ } -+ -+ /* Scan the collection for a cache with a client principal whose realm is -+ * the longest tail of the server hostname. */ -+ ret = krb5_cccol_cursor_new(context, &col_cursor); -+ if (ret) -+ goto done; -+ -+ for (ret = krb5_cccol_cursor_next(context, col_cursor, &ccache); -+ ret == 0 && ccache != NULL; -+ ret = krb5_cccol_cursor_next(context, col_cursor, &ccache)) { -+ ret = krb5_cc_get_principal(context, ccache, &princ); -+ if (ret) { -+ krb5_cc_close(context, ccache); -+ break; -+ } -+ -+ /* Check for a longer match than we have. */ -+ domain = make_data(host, hostlen); -+ while (best_princ == NULL || -+ best_princ->realm.length < domain.length) { -+ if (data_eq(princ->realm, domain)) { -+ SWAP(best_ccache, ccache, tmp_ccache); -+ SWAP(best_princ, princ, tmp_princ); -+ break; -+ } -+ -+ /* Try the next parent domain. */ -+ p = memchr(domain.data, '.', domain.length); -+ if (p == NULL) -+ break; -+ domain = make_data(p + 1, hostlen - (p + 1 - host)); -+ } -+ -+ if (ccache != NULL) -+ krb5_cc_close(context, ccache); -+ krb5_free_principal(context, princ); -+ } -+ -+ krb5_cccol_cursor_free(context, &col_cursor); -+ -+ if (best_ccache != NULL) { -+ *ccache_out = best_ccache; -+ *princ_out = best_princ; -+ } else { -+ ret = KRB5_PLUGIN_NO_HANDLE; -+ } -+ -+done: -+ free(host); -+ return ret; -+} -+ -+krb5_error_code -+ccselect_hostname_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_ccselect_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_ccselect_vtable)vtable; -+ vt->name = "hostname"; -+ vt->init = hostname_init; -+ vt->choose = hostname_choose; -+ return 0; -+} -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 668a2cc62..3503f9269 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -33,6 +33,7 @@ host1 = 'p:' + r1.host_princ - host2 = 'p:' + r2.host_princ - foo = 'foo.krbtest.com' - foo2 = 'foo.krbtest2.com' -+foobar = "foo.bar.krbtest.com" - - # These strings specify the target as a GSS name. The resulting - # principal will have the host-based type, with the referral realm -@@ -42,6 +43,7 @@ foo2 = 'foo.krbtest2.com' - # single component. - gssserver = 'h:host@' + foo - gssserver2 = 'h:host@' + foo2 -+gssserver_bar = 'h:host@' + foobar - gsslocal = 'h:host@localhost' - - # refserver specifies the target as a principal in the referral realm. -@@ -77,10 +79,12 @@ r1.addprinc('host/localhost') - r2.addprinc('host/localhost') - r1.addprinc('host/' + foo) - r2.addprinc('host/' + foo2) -+r1.addprinc('host/' + foobar) - r1.extract_keytab('host/localhost', r1.keytab) - r2.extract_keytab('host/localhost', r2.keytab) - r1.extract_keytab('host/' + foo, r1.keytab) - r2.extract_keytab('host/' + foo2, r2.keytab) -+r1.extract_keytab('host/' + foobar, r1.keytab) - - # Get tickets for one user in each realm (zaphod will be primary). - r1.kinit(alice, password('alice')) -@@ -128,6 +132,11 @@ output = r2.run(['./t_ccselect', gsslocal]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via default realm fallback') - -+# Check that realm ccselect fallback works correctly -+r1.run(['./t_ccselect', gssserver_bar], expected_msg=alice) -+r2.kinit(zaphod, password('zaphod')) -+r1.run(['./t_ccselect', gssserver_bar], expected_msg=alice) -+ - # Get a second cred in r1 (bob will be primary). - r1.kinit(bob, password('bob')) - diff --git a/Add-k5test-expected_msg-expected_trace.patch b/Add-k5test-expected_msg-expected_trace.patch deleted file mode 100644 index 16c1012..0000000 --- a/Add-k5test-expected_msg-expected_trace.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 9c6f61e30e11eca5c04daa3f0dce398602ef5801 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jan 2017 11:24:41 -0500 -Subject: [PATCH] Add k5test expected_msg, expected_trace - -In k5test.py, add the optional keyword argument "expected_msg" to -methods that run commands, to make it easier to look for substrings in -the command output. Add the optional keyword "expected_trace" to run -the command with KRB5_TRACE enabled and look for an ordered series of -substrings in the trace output. - -(cherry picked from commit 8bb5fce69a4aa6c3082fa7def66a93974e10e17a) -[rharwood@redhat.com: Removed .gitignore change] ---- - src/config/post.in | 2 +- - src/util/k5test.py | 37 ++++++++++++++++++++++++++++++++++--- - 2 files changed, 35 insertions(+), 4 deletions(-) - -diff --git a/src/config/post.in b/src/config/post.in -index 7c7d86dc9..3643abad1 100644 ---- a/src/config/post.in -+++ b/src/config/post.in -@@ -156,7 +156,7 @@ clean: clean-$(WHAT) - - clean-unix:: - $(RM) $(OBJS) $(DEPTARGETS_CLEAN) $(EXTRA_FILES) -- $(RM) et-[ch]-*.et et-[ch]-*.[ch] testlog -+ $(RM) et-[ch]-*.et et-[ch]-*.[ch] testlog testtrace - -$(RM) -r testdir - - clean-windows:: -diff --git a/src/util/k5test.py b/src/util/k5test.py -index c3d026377..4d30baf40 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -223,8 +223,11 @@ Scripts may use the following realm methods and attributes: - command-line debugging options. Fail if the command does not return - 0. Log the command output appropriately, and return it as a single - multi-line string. Keyword arguments can contain input='string' to -- send an input string to the command, and expected_code=N to expect a -- return code other than 0. -+ send an input string to the command, expected_code=N to expect a -+ return code other than 0, expected_msg=MSG to expect a substring in -+ the command output, and expected_trace=('a', 'b', ...) to expect an -+ ordered series of line substrings in the command's KRB5_TRACE -+ output. - - * realm.kprop_port(): Returns a port number based on realm.portbase - intended for use by kprop and kpropd. -@@ -647,10 +650,31 @@ def _stop_or_shell(stop, shell, env, ind): - subprocess.call(os.getenv('SHELL'), env=env) - - --def _run_cmd(args, env, input=None, expected_code=0): -+# Read tracefile and look for the expected strings in successive lines. -+def _check_trace(tracefile, expected): -+ output('*** Trace output for previous command:\n') -+ i = 0 -+ with open(tracefile, 'r') as f: -+ for line in f: -+ output(line) -+ if i < len(expected) and expected[i] in line: -+ i += 1 -+ if i < len(expected): -+ fail('Expected string not found in trace output: ' + expected[i]) -+ -+ -+def _run_cmd(args, env, input=None, expected_code=0, expected_msg=None, -+ expected_trace=None): - global null_input, _cmd_index, _last_cmd, _last_cmd_output, _debug - global _stop_before, _stop_after, _shell_before, _shell_after - -+ if expected_trace is not None: -+ tracefile = 'testtrace' -+ if os.path.exists(tracefile): -+ os.remove(tracefile) -+ env = env.copy() -+ env['KRB5_TRACE'] = tracefile -+ - if (_match_cmdnum(_debug, _cmd_index)): - return _debug_cmd(args, env, input) - -@@ -679,6 +703,13 @@ def _run_cmd(args, env, input=None, expected_code=0): - # Check the return code and return the output. - if code != expected_code: - fail('%s failed with code %d.' % (args[0], code)) -+ -+ if expected_msg is not None and expected_msg not in outdata: -+ fail('Expected string not found in command output: ' + expected_msg) -+ -+ if expected_trace is not None: -+ _check_trace(tracefile, expected_trace) -+ - return outdata - - diff --git a/Add-support-to-query-the-SSF-of-a-GSS-context.patch b/Add-support-to-query-the-SSF-of-a-GSS-context.patch deleted file mode 100644 index 299b0a4..0000000 --- a/Add-support-to-query-the-SSF-of-a-GSS-context.patch +++ /dev/null @@ -1,419 +0,0 @@ -From a3408731e3d73f99028f20c3f33caa5a411b430c Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Thu, 30 Mar 2017 11:27:09 -0400 -Subject: [PATCH] Add support to query the SSF of a GSS context - -Cyrus SASL provides a Security Strength Factor number to assess the -relative "strength" of the negotiated mechanism, and applications -sometimes make access control decisions based on it. - -Add a call that allows us to query the mechanism that established the -GSS security context to ask what is the current SSF, based on the -enctype of the session key. - -ticket: 8569 (new) -(cherry picked from commit 7feb7da54c0321b5a3eeb6c3797846a3cf7eda28) -[rharwood@redhat.com: hide GSS_KRB5_GET_CRED_IMPERSONATOR symbol] ---- - src/include/k5-int.h | 1 + - src/lib/crypto/krb/crypto_int.h | 1 + - src/lib/crypto/krb/enctype_util.c | 16 ++++++++++++++++ - src/lib/crypto/krb/etypes.c | 33 ++++++++++++++++++--------------- - src/lib/crypto/libk5crypto.exports | 1 + - src/lib/gssapi/generic/gssapi_ext.h | 11 +++++++++++ - src/lib/gssapi/generic/gssapi_generic.c | 9 +++++++++ - src/lib/gssapi/krb5/gssapiP_krb5.h | 6 ++++++ - src/lib/gssapi/krb5/gssapi_krb5.c | 4 ++++ - src/lib/gssapi/krb5/inq_context.c | 27 +++++++++++++++++++++++++++ - src/lib/gssapi/libgssapi_krb5.exports | 1 + - src/lib/gssapi32.def | 3 +++ - src/lib/krb5_32.def | 3 +++ - src/tests/gssapi/t_enctypes.c | 14 ++++++++++++++ - 14 files changed, 115 insertions(+), 15 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index cea644d0a..06ca2b66d 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2114,6 +2114,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **); - krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype); - - krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype); -+krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out); - - krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *, - krb5_const_pointer, krb5_kdc_rep *); -diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index d75b49c69..e5099291e 100644 ---- a/src/lib/crypto/krb/crypto_int.h -+++ b/src/lib/crypto/krb/crypto_int.h -@@ -111,6 +111,7 @@ struct krb5_keytypes { - prf_func prf; - krb5_cksumtype required_ctype; - krb5_flags flags; -+ unsigned int ssf; - }; - - #define ETYPE_WEAK 1 -diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c -index 0ed74bd6e..b1b40e7ec 100644 ---- a/src/lib/crypto/krb/enctype_util.c -+++ b/src/lib/crypto/krb/enctype_util.c -@@ -131,3 +131,19 @@ krb5_enctype_to_name(krb5_enctype enctype, krb5_boolean shortest, - return ENOMEM; - return 0; - } -+ -+/* The security of a mechanism cannot be summarized with a simple integer -+ * value, but we provide a per-enctype value for Cyrus SASL's SSF. */ -+krb5_error_code -+k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out) -+{ -+ const struct krb5_keytypes *ktp; -+ -+ *ssf_out = 0; -+ -+ ktp = find_enctype(enctype); -+ if (ktp == NULL) -+ return EINVAL; -+ *ssf_out = ktp->ssf; -+ return 0; -+} -diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c -index 0e5e977d4..53d4a5c79 100644 ---- a/src/lib/crypto/krb/etypes.c -+++ b/src/lib/crypto/krb/etypes.c -@@ -42,7 +42,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_MD4, - "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", - &krb5int_enc_des, &krb5int_hash_md4, -@@ -51,7 +51,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD4_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_MD5, - "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", - &krb5int_enc_des, &krb5int_hash_md5, -@@ -60,7 +60,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_RAW, - "des-cbc-raw", { 0 }, "DES cbc mode raw", - &krb5int_enc_des, NULL, -@@ -69,7 +69,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES3_CBC_RAW, - "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", - &krb5int_enc_des3, NULL, -@@ -78,7 +78,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 112 }, - - { ENCTYPE_DES3_CBC_SHA1, - "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, -@@ -89,7 +89,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_DES3, -- 0 /*flags*/ }, -+ 0 /*flags*/, 112 }, - - { ENCTYPE_DES_HMAC_SHA1, - "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", -@@ -99,7 +99,10 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, -+ -+ /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we -+ * consider its strength degraded and assign it an SSF value of 64. */ - { ENCTYPE_ARCFOUR_HMAC, - "arcfour-hmac", { "rc4-hmac", "arcfour-hmac-md5" }, - "ArcFour with HMAC/md5", -@@ -110,7 +113,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- 0 /*flags*/ }, -+ 0 /*flags*/, 64 }, - { ENCTYPE_ARCFOUR_HMAC_EXP, - "arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" }, - "Exportable ArcFour with HMAC/md5", -@@ -121,7 +124,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- ETYPE_WEAK -+ ETYPE_WEAK, 40 - }, - - { ENCTYPE_AES128_CTS_HMAC_SHA1_96, -@@ -133,7 +136,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes_string_to_key, k5_rand2key_direct, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_96_AES128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, - "aes256-cts-hmac-sha1-96", { "aes256-cts", "aes256-sha1" }, - "AES-256 CTS mode with 96-bit SHA-1 HMAC", -@@ -143,7 +146,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes_string_to_key, k5_rand2key_direct, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_96_AES256, -- 0 /*flags*/ }, -+ 0 /*flags*/, 256 }, - - { ENCTYPE_CAMELLIA128_CTS_CMAC, - "camellia128-cts-cmac", { "camellia128-cts" }, -@@ -155,7 +158,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_camellia_string_to_key, k5_rand2key_direct, - krb5int_dk_cmac_prf, - CKSUMTYPE_CMAC_CAMELLIA128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_CAMELLIA256_CTS_CMAC, - "camellia256-cts-cmac", { "camellia256-cts" }, - "Camellia-256 CTS mode with CMAC", -@@ -166,7 +169,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_camellia_string_to_key, k5_rand2key_direct, - krb5int_dk_cmac_prf, - CKSUMTYPE_CMAC_CAMELLIA256, -- 0 /*flags */ }, -+ 0 /*flags */, 256 }, - - { ENCTYPE_AES128_CTS_HMAC_SHA256_128, - "aes128-cts-hmac-sha256-128", { "aes128-sha2" }, -@@ -177,7 +180,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes2_string_to_key, k5_rand2key_direct, - krb5int_aes2_prf, - CKSUMTYPE_HMAC_SHA256_128_AES128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_AES256_CTS_HMAC_SHA384_192, - "aes256-cts-hmac-sha384-192", { "aes256-sha2" }, - "AES-256 CTS mode with 192-bit SHA-384 HMAC", -@@ -187,7 +190,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes2_string_to_key, k5_rand2key_direct, - krb5int_aes2_prf, - CKSUMTYPE_HMAC_SHA384_192_AES256, -- 0 /*flags*/ }, -+ 0 /*flags*/, 256 }, - }; - - const int krb5int_enctypes_length = -diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 447e45644..82eb5f30c 100644 ---- a/src/lib/crypto/libk5crypto.exports -+++ b/src/lib/crypto/libk5crypto.exports -@@ -108,3 +108,4 @@ krb5int_nfold - k5_allow_weak_pbkdf2iter - krb5_c_prfplus - krb5_c_derive_prfplus -+k5_enctype_to_ssf -diff --git a/src/lib/gssapi/generic/gssapi_ext.h b/src/lib/gssapi/generic/gssapi_ext.h -index 9ad44216d..9d3a7e736 100644 ---- a/src/lib/gssapi/generic/gssapi_ext.h -+++ b/src/lib/gssapi/generic/gssapi_ext.h -@@ -575,4 +575,15 @@ gss_import_cred( - } - #endif - -+/* -+ * When used with gss_inquire_sec_context_by_oid(), return a buffer set with -+ * the first member containing an unsigned 32-bit integer in network byte -+ * order. This is the Security Strength Factor (SSF) associated with the -+ * secure channel established by the security context. NOTE: This value is -+ * made available solely as an indication for use by APIs like Cyrus SASL that -+ * classify the strength of a secure channel via this number. The strength of -+ * a channel cannot necessarily be represented by a simple number. -+ */ -+GSS_DLLIMP extern gss_OID GSS_C_SEC_CONTEXT_SASL_SSF; -+ - #endif /* GSSAPI_EXT_H_ */ -diff --git a/src/lib/gssapi/generic/gssapi_generic.c b/src/lib/gssapi/generic/gssapi_generic.c -index 5496aa335..fa144c2bf 100644 ---- a/src/lib/gssapi/generic/gssapi_generic.c -+++ b/src/lib/gssapi/generic/gssapi_generic.c -@@ -157,6 +157,13 @@ static const gss_OID_desc const_oids[] = { - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x19"}, - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x1a"}, - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x1b"}, -+ -+ /* -+ * GSS_SEC_CONTEXT_SASL_SSF_OID 1.2.840.113554.1.2.2.5.15 -+ * iso(1) member-body(2) United States(840) mit(113554) -+ * infosys(1) gssapi(2) krb5(2) krb5-gssapi-ext(5) sasl-ssf(15) -+ */ -+ {11, (void *)"\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0f"}, - }; - - /* Here are the constants which point to the static structure above. -@@ -218,6 +225,8 @@ GSS_DLLIMP gss_const_OID GSS_C_MA_PFS = oids+33; - GSS_DLLIMP gss_const_OID GSS_C_MA_COMPRESS = oids+34; - GSS_DLLIMP gss_const_OID GSS_C_MA_CTX_TRANS = oids+35; - -+GSS_DLLIMP gss_OID GSS_C_SEC_CONTEXT_SASL_SSF = oids+36; -+ - static gss_OID_set_desc gss_ma_known_attrs_desc = { 27, oids+9 }; - gss_OID_set gss_ma_known_attrs = &gss_ma_known_attrs_desc; - -diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index d7bdef7e2..ef030707e 100644 ---- a/src/lib/gssapi/krb5/gssapiP_krb5.h -+++ b/src/lib/gssapi/krb5/gssapiP_krb5.h -@@ -1144,6 +1144,12 @@ gss_krb5int_extract_authtime_from_sec_context(OM_uint32 *, - const gss_OID, - gss_buffer_set_t *); - -+#define GET_SEC_CONTEXT_SASL_SSF_OID_LENGTH 11 -+#define GET_SEC_CONTEXT_SASL_SSF_OID "\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0f" -+OM_uint32 -+gss_krb5int_sec_context_sasl_ssf(OM_uint32 *, const gss_ctx_id_t, -+ const gss_OID, gss_buffer_set_t *); -+ - #define GSS_KRB5_IMPORT_CRED_OID_LENGTH 11 - #define GSS_KRB5_IMPORT_CRED_OID "\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0d" - -diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c -index 99092ccab..de4131980 100644 ---- a/src/lib/gssapi/krb5/gssapi_krb5.c -+++ b/src/lib/gssapi/krb5/gssapi_krb5.c -@@ -352,6 +352,10 @@ static struct { - { - {GSS_KRB5_EXTRACT_AUTHTIME_FROM_SEC_CONTEXT_OID_LENGTH, GSS_KRB5_EXTRACT_AUTHTIME_FROM_SEC_CONTEXT_OID}, - gss_krb5int_extract_authtime_from_sec_context -+ }, -+ { -+ {GET_SEC_CONTEXT_SASL_SSF_OID_LENGTH, GET_SEC_CONTEXT_SASL_SSF_OID}, -+ gss_krb5int_sec_context_sasl_ssf - } - }; - -diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c -index 9024b3c7e..d2e466e60 100644 ---- a/src/lib/gssapi/krb5/inq_context.c -+++ b/src/lib/gssapi/krb5/inq_context.c -@@ -310,3 +310,30 @@ gss_krb5int_extract_authtime_from_sec_context(OM_uint32 *minor_status, - - return generic_gss_add_buffer_set_member(minor_status, &rep, data_set); - } -+ -+OM_uint32 -+gss_krb5int_sec_context_sasl_ssf(OM_uint32 *minor_status, -+ const gss_ctx_id_t context_handle, -+ const gss_OID desired_object, -+ gss_buffer_set_t *data_set) -+{ -+ krb5_gss_ctx_id_rec *ctx; -+ krb5_key key; -+ krb5_error_code code; -+ gss_buffer_desc ssfbuf; -+ unsigned int ssf; -+ uint8_t buf[4]; -+ -+ ctx = (krb5_gss_ctx_id_rec *)context_handle; -+ key = ctx->have_acceptor_subkey ? ctx->acceptor_subkey : ctx->subkey; -+ -+ code = k5_enctype_to_ssf(key->keyblock.enctype, &ssf); -+ if (code) -+ return GSS_S_FAILURE; -+ -+ store_32_be(ssf, buf); -+ ssfbuf.value = buf; -+ ssfbuf.length = sizeof(buf); -+ -+ return generic_gss_add_buffer_set_member(minor_status, &ssfbuf, data_set); -+} -diff --git a/src/lib/gssapi/libgssapi_krb5.exports b/src/lib/gssapi/libgssapi_krb5.exports -index 9facb3f42..936540e41 100644 ---- a/src/lib/gssapi/libgssapi_krb5.exports -+++ b/src/lib/gssapi/libgssapi_krb5.exports -@@ -37,6 +37,7 @@ GSS_C_MA_CBINDINGS - GSS_C_MA_PFS - GSS_C_MA_COMPRESS - GSS_C_MA_CTX_TRANS -+GSS_C_SEC_CONTEXT_SASL_SSF - gss_accept_sec_context - gss_acquire_cred - gss_acquire_cred_with_password -diff --git a/src/lib/gssapi32.def b/src/lib/gssapi32.def -index 362b9bce8..dff057754 100644 ---- a/src/lib/gssapi32.def -+++ b/src/lib/gssapi32.def -@@ -182,3 +182,6 @@ EXPORTS - gss_verify_mic_iov @146 - ; Added in 1.14 - GSS_KRB5_CRED_NO_CI_FLAGS_X @147 DATA -+; Added in 1.16 -+; GSS_KRB5_GET_CRED_IMPERSONATOR @148 DATA -+ GSS_C_SEC_CONTEXT_SASL_SSF @149 DATA -diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def -index e5b560dfc..f7b428e16 100644 ---- a/src/lib/krb5_32.def -+++ b/src/lib/krb5_32.def -@@ -470,3 +470,6 @@ EXPORTS - krb5_get_init_creds_opt_set_pac_request @435 - krb5int_trace @436 ; PRIVATE GSSAPI - krb5_expand_hostname @437 -+ -+; new in 1.16 -+ k5_enctype_to_ssf @438 ; PRIVATE GSSAPI -diff --git a/src/tests/gssapi/t_enctypes.c b/src/tests/gssapi/t_enctypes.c -index a2ad18f47..3fd31e2f8 100644 ---- a/src/tests/gssapi/t_enctypes.c -+++ b/src/tests/gssapi/t_enctypes.c -@@ -32,6 +32,7 @@ - - #include "k5-int.h" - #include "common.h" -+#include "gssapi_ext.h" - - /* - * This test program establishes contexts with the krb5 mech, the default -@@ -86,6 +87,9 @@ main(int argc, char *argv[]) - gss_krb5_lucid_context_v1_t *ilucid, *alucid; - gss_krb5_rfc1964_keydata_t *i1964, *a1964; - gss_krb5_cfx_keydata_t *icfx, *acfx; -+ gss_buffer_set_t bufset = GSS_C_NO_BUFFER_SET; -+ gss_OID ssf_oid = GSS_C_SEC_CONTEXT_SASL_SSF; -+ unsigned int ssf; - size_t count; - void *lptr; - int c; -@@ -139,6 +143,16 @@ main(int argc, char *argv[]) - establish_contexts(&mech_krb5, icred, acred, tname, flags, &ictx, &actx, - NULL, NULL, NULL); - -+ /* Query the SSF value and range-check the result. */ -+ major = gss_inquire_sec_context_by_oid(&minor, ictx, ssf_oid, &bufset); -+ check_gsserr("gss_inquire_sec_context_by_oid(ssf)", major, minor); -+ if (bufset->elements[0].length != 4) -+ errout("SSF buffer has unexpected length"); -+ ssf = load_32_be(bufset->elements[0].value); -+ if (ssf < 56 || ssf > 256) -+ errout("SSF value not within acceptable range (56-256)"); -+ (void)gss_release_buffer_set(&minor, &bufset); -+ - /* Export to lucid contexts. */ - major = gss_krb5_export_lucid_sec_context(&minor, &ictx, 1, &lptr); - check_gsserr("gss_export_lucid_sec_context(initiator)", major, minor); diff --git a/Add-test-case-for-PKINIT-DH-renegotiation.patch b/Add-test-case-for-PKINIT-DH-renegotiation.patch deleted file mode 100644 index 89d695d..0000000 --- a/Add-test-case-for-PKINIT-DH-renegotiation.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 5faadd66bb278bcc1c618e199444e3012eeec215 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 11 Jan 2017 10:49:30 -0500 -Subject: [PATCH] Add test case for PKINIT DH renegotiation - -In t_pkinit.py, add a PKINIT test case where the KDC sends -KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED and the client retries with the -KDC's TD_DH_PARAMETERS value, using the clpreauth tryagain method. -Use the trace log to verify that the renegotiation actually takes -place. - -(cherry picked from commit 7ad7eb7fd591e6c789ea24b94eccbf74ee4d79f8) ---- - src/tests/t_pkinit.py | 18 ++++++++++++++++++ - 1 file changed, 18 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index ac4d326b6..183977750 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -174,6 +174,24 @@ realm.kinit(realm.user_princ, - '-X', 'flag_RSA_PROTOCOL=yes']) - realm.klist(realm.user_princ) - -+# Test a DH parameter renegotiation by temporarily setting a 4096-bit -+# minimum on the KDC. -+tracefile = os.path.join(realm.testdir, 'trace') -+minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} -+minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) -+realm.stop_kdc() -+realm.start_kdc(env=minbits_env) -+realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, '-X', -+ 'X509_user_identity=' + file_identity, realm.user_princ]) -+with open(tracefile, 'r') as f: -+ trace = f.read() -+if ('Key parameters not accepted' not in trace or -+ 'Preauth tryagain input types' not in trace or -+ 'trying again with KDC-provided parameters' not in trace): -+ fail('DH renegotiation steps not found in kinit trace log') -+realm.stop_kdc() -+realm.start_kdc() -+ - # Run the basic test - PKINIT with FILE: identity, with a password on the key, - # supplied by the prompter. - # Expect failure if the responder does nothing, and we have no prompter. diff --git a/Add-test-cert-generation-to-make-certs.sh.patch b/Add-test-cert-generation-to-make-certs.sh.patch deleted file mode 100644 index eb7df73..0000000 --- a/Add-test-cert-generation-to-make-certs.sh.patch +++ /dev/null @@ -1,968 +0,0 @@ -From 5e3885e9d7c7cd2a19a291cdb1e54312ca7f7e1f Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Mon, 5 Dec 2016 12:22:45 -0500 -Subject: [PATCH] Add test cert generation to make-certs.sh - -Add additional test certificates for UPN matching. Run make-certs.sh -to regenerate certs. - -ticket: 8528 -(cherry picked from commit 5a1d0388ba2e4ec510ed715ce5fbc7f748941425) ---- - src/tests/dejagnu/pkinit-certs/ca.pem | 54 ++++++++++++------------ - src/tests/dejagnu/pkinit-certs/kdc.pem | 50 ++++++++++++---------- - src/tests/dejagnu/pkinit-certs/make-certs.sh | 53 ++++++++++++++++++++++- - src/tests/dejagnu/pkinit-certs/privkey-enc.pem | 52 +++++++++++------------ - src/tests/dejagnu/pkinit-certs/privkey.pem | 50 +++++++++++----------- - src/tests/dejagnu/pkinit-certs/user-enc.p12 | Bin 3029 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user-upn.p12 | Bin 0 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user-upn2.p12 | Bin 0 -> 2813 bytes - src/tests/dejagnu/pkinit-certs/user-upn2.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user-upn3.csr | 16 +++++++ - src/tests/dejagnu/pkinit-certs/user-upn3.p12 | Bin 0 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn3.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user.p12 | Bin 3104 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user.pem | 56 ++++++++++++------------- - 15 files changed, 283 insertions(+), 132 deletions(-) - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn.pem - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn2.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn2.pem - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.csr - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.pem - -diff --git a/src/tests/dejagnu/pkinit-certs/ca.pem b/src/tests/dejagnu/pkinit-certs/ca.pem -index 55fe02c92..44c917687 100644 ---- a/src/tests/dejagnu/pkinit-certs/ca.pem -+++ b/src/tests/dejagnu/pkinit-certs/ca.pem -@@ -1,29 +1,29 @@ - -----BEGIN CERTIFICATE----- --MIIE5TCCA82gAwIBAgIJANsFDWp1HgAaMA0GCSqGSIb3DQEBBQUAMIGnMQswCQYD --VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp --ZGdlMQwwCgYDVQQKEwNNSVQxKTAnBgNVBAsTIEluc2VjdXJlIFBraW5pdCBLZXJi --ZXJvcyB0ZXN0IENBMTMwMQYDVQQDFCpwa2luaXQgdGVzdCBzdWl0ZSBDQTsgZG8g --bm90IHVzZSBvdGhlcndpc2UwHhcNMTAwMTA2MTQ1MTI3WhcNMjMwOTE1MTQ1MTI3 --WjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNV --BAcTCUNhbWJyaWRnZTEMMAoGA1UEChMDTUlUMSkwJwYDVQQLEyBJbnNlY3VyZSBQ --a2luaXQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAxQqcGtpbml0IHRlc3Qgc3Vp --dGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkqhkiG9w0BAQEFAAOC --AQ8AMIIBCgKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmn --ZejPSKdNMyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6K --ueerevR3pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY7 --5NbXGIE488iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc --5dBSqBwVcjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOW --riIRmsqq81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABo4IBEDCCAQwwHQYDVR0O --BBYEFFn82RUKgTvkFn0cgwyCQpNeWCxYMIHcBgNVHSMEgdQwgdGAFFn82RUKgTvk --Fn0cgwyCQpNeWCxYoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFz --c2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxKTAn --BgNVBAsTIEluc2VjdXJlIFBraW5pdCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQD --FCpwa2luaXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCCQDb --BQ1qdR4AGjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQBVL2Q6Xubs --gm881cAy6esku17/BSTZur7hCLHTGof1ZKNcCXALjmwNYNC3tl6owqpX8CSdBdsD --Bw/Vs9p3mqnaVEoZc8uW8zS6LoAQbcqiYdQHdEXMh3ec8uvAfmdlQsIsm5Ux8q8L --NM6bKnUOqOFOHme+RC4FGOLb8JqnnuQdwyIZaUyQP6hXbw4zyDphfgo1ZlZn20xh --I555kPfAZKEi/d3WY0oN4k+sfCs9tWRNjmqZfKkH1OqRpjCFGG0b0vY77MFRMuPz --YtN2iD3plgla7KkUMljp9th/Z8Ok79uA1TNLYKzoBjlAX0vToxfa8rrSNo1dHFKT --e5Tj7+29DE4I -+MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowgacxCzAJ -+BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i -+cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl -+cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk -+byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC -+ggEBANOWvXDyubZ/Kf8QYdPSRk/rsogzqS0rycNEJp/6rPpTS40UxGae5MyLHfmN -+l2mSevRoHSqhb7cfT6n9kR2kb3HB0qhhhecHey4sGwd+m7WMhBQgVtYaiWkuEQDC -+7/SWkRYzmYX8J41vrQulXU2/2pOQCmG4NKPsNo+vcKoT2SHl6qr3lflUaIG0wDu4 -+bFrWszkxcuSkU7SSXDf2xTTTJ8QftO6WQY3g0+dAhbjZFKxRO5uipxURez5EemVs -+Re86vXEILka85tiVS4maCn3l3FWMqcBHRFNa+/osTb0J/OmvvdQ3bzvscG7KDRtM -+bRUnpWClr5R+AbGVvKocj5I1+G0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBRrwMkO -+fMoN3ofjotSWjK0c27fYYjCB1AYDVR0jBIHMMIHJgBRrwMkOfMoN3ofjotSWjK0c -+27fYYqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ -+bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 -+IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE -+AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAN82zurZwM -+TugUG6b1symxXxOdDqwinwIlQjzXJ8mTRv31q+YwNdYvdWn1aex8v44qjFDjEP80 -+83y18CjjBHznwxsHll80QmFHjpy6xtRrUC/Ak7jfKnDiTKQYBdgmF4/UiVQu354e -+QI6jPMQlrWZXThlRuBjM55hs4tgRYeTgbd4VSZzVQXdm2ViZkg8SGqw0R2ZRnG91 -+dfXkhu/tTruguPAT3MQ2pTK/CoHHA4W2piQbBDqIl83fphRhYxyW/cCF2mvZZUhE -+AfWhgYDeTDxHKG3Jfmm+ujMo5HscgeUpJ7XjZdobNhkQjD1piyuGzFkUfo2XzA6m -+kMz4Jq4cnvpz - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/kdc.pem b/src/tests/dejagnu/pkinit-certs/kdc.pem -index 5575ab579..8820ad447 100644 ---- a/src/tests/dejagnu/pkinit-certs/kdc.pem -+++ b/src/tests/dejagnu/pkinit-certs/kdc.pem -@@ -1,25 +1,29 @@ - -----BEGIN CERTIFICATE----- --MIIEMjCCAxqgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBpzELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSkwJwYDVQQLEyBJbnNlY3VyZSBQa2luaXQgS2VyYmVyb3MgdGVz --dCBDQTEzMDEGA1UEAxQqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTEwMDEwNjE0NTgwOFoXDTIzMDkxNTE0NTgwOFowSjELMAkG --A1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxFTATBgNVBAoTDEtSQlRF --U1QuQ09NIDEMMAoGA1UECxMDS0RDMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB --CgKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmnZejPSKdN --MyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6KueerevR3 --pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY75NbXGIE4 --88iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc5dBSqBwV --cjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOWriIRmsqq --81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABo4HEMIHBMAkGA1UdEwQCMAAwCwYD --VR0PBAQDAgPoMBIGA1UdJQQLMAkGBysGAQUCAwUwHQYDVR0OBBYEFFn82RUKgTvk --Fn0cgwyCQpNeWCxYMB8GA1UdIwQYMBaAFFn82RUKgTvkFn0cgwyCQpNeWCxYMAkG --A1UdEgQCMAAwSAYDVR0RBEEwP6A9BgYrBgEFAgKgMzAxoA0bC0tSQlRFU1QuQ09N --oSAwHqADAgEBoRcwFRsGa3JidGd0GwtLUkJURVNULkNPTTANBgkqhkiG9w0BAQUF --AAOCAQEAP0byILHLWPyGlv/1HN34DfIpLdVkgGar2yceMtZ2v/7UjeA5PlZc8DFM --20bTq/vIN0eWDTPLI57e+MzQTMxs2UHsic4su0m5DG0cvQTsBXRK51CW/qUF+4n0 --qSEORULiDF6LNoo8akoLukNBhzBh+aqYt4aB46hhsmDmNZTDP1CXsNGHQI9/L52l --oqpUGx8tBpKIFos95PSajXrQn2u66rSMMi4aawitM2igurHPDMbC+XvEYMtXpOS5 --3PEzXEYiSV3TWLTzIE9ytswHeZyHCbp7XHx0LVZFxzqtIe4qmwJJOGhlbH21Izr4 --feF5h5e2ZrOVREY4cKkJmJhEwsqBVA== -+MIIE4TCCA8mgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSTELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQwwCgYDVQQDDANLREMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK -+AoIBAQDTlr1w8rm2fyn/EGHT0kZP67KIM6ktK8nDRCaf+qz6U0uNFMRmnuTMix35 -+jZdpknr0aB0qoW+3H0+p/ZEdpG9xwdKoYYXnB3suLBsHfpu1jIQUIFbWGolpLhEA -+wu/0lpEWM5mF/CeNb60LpV1Nv9qTkAphuDSj7DaPr3CqE9kh5eqq95X5VGiBtMA7 -+uGxa1rM5MXLkpFO0klw39sU00yfEH7TulkGN4NPnQIW42RSsUTuboqcVEXs+RHpl -+bEXvOr1xCC5GvObYlUuJmgp95dxVjKnAR0RTWvv6LE29Cfzpr73UN2877HBuyg0b -+TG0VJ6Vgpa+UfgGxlbyqHI+SNfhtAgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUa8DJ -+DnzKDd6H46LUloytHNu32GIwgdQGA1UdIwSBzDCByYAUa8DJDnzKDd6H46LUloyt -+HNu32GKhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl -+dHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwg -+SW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5p -+dCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZYIBATALBgNVHQ8E -+BAMCA+gwDAYDVR0TAQH/BAIwADBIBgNVHREEQTA/oD0GBisGAQUCAqAzMDGgDRsL -+S1JCVEVTVC5DT02hIDAeoAMCAQGhFzAVGwZrcmJ0Z3QbC0tSQlRFU1QuQ09NMBIG -+A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBABJpKRfoFxyOUp9i -+Z/fWql5anJuZElgBSbEC5sL2mMcmL/1vqkiYF3uF6/Z9g4X1LX4QDuvaXCJSdQ+b -+JpmhklSyFN+E/agxZtSim+AjTgYJ0y+jwNvX6kZQ8fW3VLNJZ+zbb4n4txfgSROn -+7ub+02mo4DYajyD9TE/qLzmVaiKLEKW0osjxX3fB1RN/d7zm//NDPsezzUzmKkgz -+u0ML7HGYUNY3+/SC4ShF/But1IoY3/I46lB6BMrIn9X6fsVKlipqrRFniUk0qDlJ -+fbKVB+MvGEFoqFNlMoGiufmDjnJl4PQZCVEmXO8wAVGeK8NpTBCjltAAsoVJVnjq -+AC5jSAM= - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh -index b82ef6f83..0f07709b0 100755 ---- a/src/tests/dejagnu/pkinit-certs/make-certs.sh -+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh -@@ -4,7 +4,9 @@ NAMETYPE=1 - KEYSIZE=2048 - DAYS=4000 - REALM=KRBTEST.COM -+LOWREALM=krbtest.com - KRB5_PRINCIPAL_SAN=1.3.6.1.5.2.2 -+KRB5_UPN_SAN=1.3.6.1.4.1.311.20.2.3 - PKINIT_KDC_EKU=1.3.6.1.5.2.3.5 - PKINIT_CLIENT_EKU=1.3.6.1.5.2.3.4 - TLS_SERVER_EKU=1.3.6.1.5.5.7.3.1 -@@ -85,6 +87,30 @@ keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement - basicConstraints = critical,CA:FALSE - subjectAltName = otherName:$KRB5_PRINCIPAL_SAN;SEQUENCE:krb5princ_client - extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user@$LOWREALM -+extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn2_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user -+extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn3_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user@$REALM -+extendedKeyUsage = $CLIENT_EKU_LIST - EOF - - # Generate a private key. -@@ -113,5 +139,30 @@ openssl pkcs12 -export -in user.pem -inkey privkey.pem -out user.p12 \ - openssl pkcs12 -export -in user.pem -inkey privkey.pem -out user-enc.p12 \ - -passout pass:encrypted - -+# Generate a client certificate and PKCS#12 bundles with a UPN SAN. -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn_client \ -+ -set_serial 4 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn.pem -in user-upn.csr -+openssl pkcs12 -export -in user-upn.pem -inkey privkey.pem -out user-upn.p12 \ -+ -passout pass: -+ -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn2.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn2_client \ -+ -set_serial 5 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn2.pem -in user-upn2.csr -+openssl pkcs12 -export -in user-upn2.pem -inkey privkey.pem \ -+ -out user-upn2.p12 -passout pass: -+ -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn3.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn3_client \ -+ -set_serial 6 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn3.pem -in user-upn3.csr -+openssl pkcs12 -export -in user-upn3.pem -inkey privkey.pem \ -+ -out user-upn3.p12 -passout pass: -+ - # Clean up. --rm -f openssl.cnf kdc.csr user.csr -+rm -f openssl.cnf kdc.csr user.csr user-upn.csr user-upn2.csr user-upn3.csr -diff --git a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -index 9f7816f17..837fd0b01 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -@@ -1,30 +1,30 @@ - -----BEGIN RSA PRIVATE KEY----- - Proc-Type: 4,ENCRYPTED --DEK-Info: DES-EDE3-CBC,91CA660D6286E453 -+DEK-Info: DES-EDE3-CBC,19FEC334A4D4391D - --DpJ5bo/AN37NcxTNv0Z4d5YomWqyryqYhuA43FlzWWKubld4Gp+owAv5BUd4VLx7 --Efq23ODfuiuh5zna/ZXnY+9m8RHS5AxDd2Kr1s/fVsn+m2Lw9qS69DLjxTjEuDLU --AwmVADqQUbvocZEt0Byn9oY4ku2lGOY/ax7tZ1WegLInnoCqT2xGC6TLw7Gwr3mX --z6xFB2Yv4PbvVU8y4V+ka0p5manxptYkrbAkC+vrC4LPUACdbonmpeXUxAfVV9hL --EMzY74IqY2QS1xFMhbLh2HunfjjC3HZ1wXMf1/LtLl1nnodiOk5o+MTLEHO+npaO --rJn2z3V/eQsr93M8/K5ONQcPAKZGOCmNpNQUj1UHnUHEubhpI+nqRYe3vqem5GaH --8gn+uc1/N6c/Bs037iSLWvkgk8mvHgH/26JobZ8qg9yYgVUl3AIVkkGwLGhE5+Kn --593/p4E5Mb6ttv3ZJ4f3Mz/1b84guhTENY67zxnQEGnpEjfRKoEN1vmHi6mIuWld --rrUCJ/x1Yvy2tN9eyuTNsGCcfvPeY22RrKgl7Wi0EIvBlLPKBQxqXOA7Mi9Acapd --+n5pW2Ka2FABSifZ36owa7SJEJ0GLMtdHmZPirolgIjOZVOMbSj2UuR/kXVZjZUM --LcRcVI1z8NgKF3RKs653HqkphcyRQMMQrL/A38t+v0zFA2P3HPoNWcD+BfKg0H37 --bHPjXdlvAD5yiFXKb1XN99utW5G/qCq5CdzAirm7drxR0bs4ZIV4SwTulvWLW644 --RYes8x7WKg3WUxtair++c1eTwTPhMLz/SxERYXxSUqpxJiRgYTQhwwbE22P6FCWT --H9pso5IMi6AJp35CGaYHi78NPLWVmrxgkkv2uBoDFd/iIQTac60aG/F86aozQD7V --DmHINEcsN3lVUmHinoNTcIfc5EZVEbLQIBhy3XI0UDxWuLnchVlU3ad1OKqknbbi --Ik3lmeLz07JFbpCcMk+xDlQsZYbxcRzyRh0NsWvHXuG77Hbcrnk3ndxT8wADsfOn --foXf1/R/gf7PDmte3nFlpEcJCHyeY1haIqgk4WsnUUKP56O75cGF1ylkaBrDPlLw --WaN2Li537ALo6TyB0jspdCzPqIRt8Gr4muoX0tqFjSfKaWmRb3Y7i6jbVrh8d6KV --xqLse0Vkaip4Lgf/VUWOTvlfHz9nLD0xR6OUPeQ3jxGdhLxmcYec1oRj1aVMlp6f --PyC6TN+NlPEtv6KWWB9OMc420DGOWllvS5+zsm7Ff7/5TkXlWmlhfhrkyQVy8NOe --/3ygPbpSfCFjJMwdbEX+ic/Qjk04f3CluP3FYiIG/Pd6ny6rclrhPHg08X6+sciU --Rj7QtoFpVsDvde2QO0depdoysAG1j1a+sas2lYNPG8hdzbPe20xIJCmF0fWfdxOy --BxxtKzpq46S8xKLfxAMvKrZNuZy5xhs3JMUjpxTIam7ZiQXd752LdzGx2s4CII6d --mkeQ/d32TDACAxyEK8es4Mcm3IoCAq/NjIU/ICwGDeOmfDUpsV2TMrg+aKMKcwUE --UK4bMXercw7Cs0C3o6mdCTFrTtsihHNTrbb7yyN83XK76niSc+LREbuJ8T0vp1Yh -+S6pSicLj30Jlnu2OnYM0eXCvwAHR3xMhhl2N0gheWUGkjicqTdW6ft1qCmGBre9b -+/aTSF1ajvFC+YQ/iABznWNmRNZKCzTK1dQ6P73p83uNqWt/cfe+pVYdeHw3u8NKA -+fscciBtxnHNaAs16GX5/j1XXRPb+zmUe18A+VFMRgctbaurk+KbxO8qVUkzt9NNa -+v5zHkXnaJf6ixL6zR3cOCJWPGy4GmGeFIytQos5Jgn23Pjn8BHAXf39GMs2n6g5V -+eE5RAGDeXqPv/tO1kN0/RSKDeIPvKW6REklXraRUle0PNN5g5l3umSkg4fkplusp -+nTsQCRWkqyVcMpxcf0wy7F2ZPOYIWDt1/pzAHC7y/fl0uCQPz0Qd1smwt0ABKcZv -+m9zaMq6lkKYnBOxPiYIlWVlQi3RLDiQyAWQz/nF0SKsE88SUlB83quySJsZsLKzk -+MR/C+ccSiHqMiDKVj5Ts1go+gbj8Vhlto8jH6ynQj6lrOIczyMmgUa0v0dFH3i3/ -+WL/8ydJ0otY67A8w5yH3hMzRChXQZlpTmH2dDhAv6EzKBi8eIiB0Em+laz5lDv6C -+SfNxZa1/+bSAvXr7LwllUu+Gzbu7MNLwfB2ieTqdFQGA659DjnMqyBGLFzni4Ir0 -+Hi6Uh6yQubTm07oqyUHAsChGFE4Efh4O0rCbKKPZuSVfimUZcE6JM9IjRC/0DIwr -+LZSYqsFgn44byrc62qV2JAE2ua+/4aHHI28hIZ3MDLwyYpCQL/FAUZtqZvni+zgw -+yoHLRDbdrqPps6P71T6Pw6OQzAYC7AL/FsZnLJK78nI+Yai0dpyv/QWiFSXoDEVN -+6vQoDv/VZbNIctr31OE4XyjIMiTpn3FPa3VSbKM4/h7SthjwEV2ONNfR8XQF+siz -+3NhOjEFrZ6UGHvT06wo/hp4CM7u580fNu5HvyCyIwkx9CZRLHvG6Vu0emlzDfQhE -+qxQs6L7IM8A46/LPSTtmEA8Rrn51YY9NChMdY6j3rLe4NLxxOCE6JYaGWVWBBawK -+k3y9z6L9gWRwxEfCgWIutDrYtmA2aj6y/vRS6LrotCNeN5qBx+TdRnh6uCqbi1T8 -+4rF20TVhNZ/l+pkH/ehY9OJ/zpwdbTq4FlE0wWQZB/vwbYP5CZKF+rU6IXnCZEjt -+Ak6Bka9mFm9Z/TvnKIRYiXELq32zOJAuEOQ576tkDX2rAuIQAfE9biX2qo0gbsJo -+1RIfXekRurD/HX54blv5mNqUV34gl+ngPpV5nNDy7RuTAdP77Mu7/ynaPfnM7nqu -+rECbZVv1HZSgTi+7G9SUjn4Bg36p4NiF0/dZ2W70byYIQvNPNqU1kyeSrZk/43te -+NwFgpoAKVbMD1rZ+0xM2YCFFKQZZMN1a5tn8/1TWPlPU28Tu3ZliGeWMdeKd4/MP -+vfH1pE58qVcyOngjLqGkk0L5A7WOAgu+vibKrxGxywwVLx/GfDFqnNr6H0buwXrk -+vuKBTo0r3pcbaZt3kaYBm0d3zznQI1O/pX+eGiNr/rI86j4KC+jUSoKi4BdUeuDN -+p1x6qyEK37kgVXiUyiEXO7e1arLBZMfFRTNKVsN5ewL441eCIgs5gA== - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/privkey.pem b/src/tests/dejagnu/pkinit-certs/privkey.pem -index 1825dec4e..7e9beb09a 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey.pem -@@ -1,27 +1,27 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmn --ZejPSKdNMyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6K --ueerevR3pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY7 --5NbXGIE488iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc --5dBSqBwVcjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOW --riIRmsqq81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABAoIBAQCSMh5Tu9S2yUwM --dEZmZiGxhuf+anAZZAOjqT4QeLI/Fmu3yBNM7rq+p7JrAabyp6pOq46EsXXyWtWS --SB742wWUk2quGMNVQAj0TAJyhNgGstr+XJu8k8BBPnlycobhF0lP/oH+uQifl0KR --iSoWLjEG5JTOoXs/UAD6nQMBDDhv9TweEwSyIY9jq1J5Q3wVXm/Nr/FJ/8O53guJ --/TQeo6dtdx6x2+oxKkeWinfxmy2nSoEZd0eb3WUNPZswijO7QgSJolOo83VNqFcn --lj8hYT41zUM4chple8kGnuSV4ql4a1w/52dSTLKJbgukIqvxeDtKNost344eQqkS --Lwcc+NO5AoGBAM0bR8TmFlbP4RJAEOOilXTYgP6Ttd1r1mRXGi3DRPyv4EWGT7WW --MmBHsqU6Mqz+fcoD/AIy1BBdenhaYrrwyCSvitJpoHPjqzOJDX33wUcrnYeincQ3 --PVzpF41O45vTmm692DSJ8t/uR8DhGpCzf/kxuA9ixvdKgMPgBHYeb5zlAoGBAMSY --KZvgwbtlRR25CGaUgOCHtW76puaPcyxEeCbJEKkJO1vZDAf8vi1zXOM4e/gorKHm --349ZrBQfFCrvtZG//KvI12MpjBs0Z/ijSCwS4EkYJaSH+Hm+1ygLdArwWEFkNncL --qQ+Wme1OUoDiAAxRiBKUxUF/pAQqn7X+0MGa2th3AoGBAJ8kRaFu7XJaRUZF01Ts --d4571kqxDXFKFMUyGCvd0Q9G33rSZdJ9QYUW3HP7HgrAQ5WVVdnW2lgAT+BGMUjf --PkvIsKvmLQr+YX3RH1jX/W1dWBM/h64RNll6uj14Mn5bxv2Z68GIL5y0Y5QylMwl --mmwdubSmbb6+Xf6dOJj1sKBJAoGBAJwP0tAMHp6daL2Mmk+cSaZz9KJx1bYnYB1f --CSZ47IHTc0yZQ0S/7VR1ROKXf0njOA+aEBRi8ghTF5ZyDefyySixWdI9NByQgIzP --Sca7AVLlGVTAH4694VzHosngO59FZzsfhYh7XBwW1cW8Ip+kxWlCskgphFFOaNR3 --wM5AGMRHAoGAJELs9VYPRJd7h4dPUa2RqfVPlYkcMwvoLYykY0wE5mjoNaJkQbUr --W5aKhidh4h48fImt2rpB6OYSofYC4yu3VDEr/Kl2nSb8UPE5qEd1pvmdkHSxMNkh --M2diIqot6s2v20lE/6UCqLXonlquRK1MAlyfPw9yZHP9meCvlBsYZXc= -+MIIEowIBAAKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTE -+Zp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW -+1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV -++VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6Kn -+FRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91Ddv -+O+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABAoIBAH28SS0ygFvLq4gw -+EwJOJYxeswQvNuxp5gcMm6tbyqkjEHVxDtkwuSQ304M1ufF5o2lT6Wko7/sxNyT8 -+Utz7l2JRXL7E3U6R6ohgm1tTyHIVY3OWWCP5Nwjy4BXEwdVmGCfKWAP/+P0ajQmr -+pguK4/fmk9TIIzf6Kd4u0lOvYcu7AYfaBj9OSSF08IoE1EA9gY3Mh9k8C3d3JDhG -+hoJKwMAIX0PRyx6cvmpuAJyPf+19K0/SmzpbdNOHfIXZKtfYw3HxmebhhyCxqNsY -+opI2fpn8joasvfcXICBFRHreSu4nKc8ky6FkMIc5KZRiSP//N3oFM7ZLxciMjfgl -+bCYqST0CgYEA7xfrB4atDYApsmLk92uHnC2bOmJhncfAuLHh8M35fk09Jt6CMYPx -+Ydp4cKYzMemO5zzHxdMnlmISIWWtNbm/gR74KZwOmhFFEP2LE09hpAXRBfQvN5af -+RZwMZ9uyJU5ByecXbIt0cuNerl8sKJfG1S+/maD3dZvr78K4Jd6StTcCgYEA4ozu -+okBTEZ9h7lxdBBbZcO8i/eikPeKnCEBaSryf3K3Pr/k8Ssaa7MYOT9yD+iRwU/uV -+n13BA1I9PvdcWl6ewZdOYX4jCVCIsLs7ed4wfwLxGQMZIVHPZ59lRmVsZFO08g0D -+27U/rUZBpMHl+ppq/FfBjyyUSqayKjcBoFXx0XsCgYAOzQM+pwaldE6gfWDBNEXj -+1Crs1VRHqSr0BAcBmi6cs/laI6IZoJpbvWOBTbiTmWrAQ9H2HBkyRQXsTVgIoGQL -+gThJkyCQRwtoftmSK3LW7Yk//hrCLS/U5lEaSM5hYtPNxOF9VbCywAKHdtrL9IFZ -+hygsQXuwKyPS5tHxfjLExwKBgQC1D+Hg9vvtB67jLBqDHCfopJcYywgJFc5dP+Fp -+/dreKmPkxpMzSAul1Jy3owwvrVPBKz9nwSxzlRSx8Ex1RU4odt8D+CXUWfMFHH7q -+ZXPo7tb2II3DHXlf3fq5CnJYtLXXBiPhQriDqbTpErbVVPjQeOqPnRdfml6mcpPw -+KwA7ZQKBgFzqLmWqy7ZnZdbBo4CUUt6B12eaPCW6YNpOd53zHOphaiZLq4rEhpiZ -+S6JYQTEQYugr0yd6vxsVL2An58niRg1sM6gca9QqBlGMzaQoXaPx6OrLW2WoS5+I -+MmVTeh7yvdop+6gvR8Eoh4cI0HoiJw8oQOOneiXVnh7Izk+WjKXb - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-enc.p12 b/src/tests/dejagnu/pkinit-certs/user-enc.p12 -index 107480c6d2564a2e60655f29a9984f3009c35a11..049602939def4be1fa9164649b39a801f417e74e 100644 -GIT binary patch -delta 2772 -zcmV;_3M=*17nK%3FoFva0s#Xsf(q9L2`Yw2hW8Bt2LYgh3djV43dAsi3cxUe1$PDs -zDuzgg_YDCD2B3lkXfT2WWC8&IFoFeLkw6`P>Pk7sT{fZm0s;sCfPw`u+L;oVmwM*l -z^A^(IMG+~hWX?aEZU^((3=^fBlyN^uJ1HdaB~86Bo9}9N+iX!V%5OEvtt$|1s1*AD -zSi4_@qyJcutzz!=uO|*1J0QdyMXJ9F0W$DQND|#_%aKA}$m?*9_9e@K*B!h=TVo7= -zMU9jzfb7^C(2Aqpo+PWbs`#J#x*BuH0)VGjB2ly(^0MI0lF7=F#Hzw2C+INlA^N4t -zQGyERj6sz8uZ>M&)xR&um+swj;`PYIw7WY^-c-*m>8DZZQKge>x$dqy#H-~)PY_BM$dd~(Onw}(9&Z?axg}0Z9>TNk$HM5;@0zFIm*-gU`117jbMl3DK%BxZTfFoaazy+Y;K&KQb%|%j4SGGNq>fa9~oCG -zwgvwvlgWm}c<(Owow5C6%<-HJ+#%w}d^yDVJj@KHm7O$cj$%wmqlApelQKGFkb>xi -z&5HN+ZW~fbxGRW%c2vkasI|;g8|kowoTpi`2d$&gAo5M+Cd@-p1~P_!Ft-zz7TTx- -zY=&;!yAmC`w_4KM$YX)1Rw*cdk0678Q7lj?36`+_J(4VyW}Tq4w1Njv41vgs&>dhV -zSy#O>l4{FWV8Oa^*jM@TB-&IwhQ^?iss8sqxRaAy73MP_getDL=XHMi>x{`9P;^eT -zX;^D`Rv!PAqmjC4%L#g1dGlx5N06S76*wky6q4>VTfaR`SZQ6zOcRNJ98dY`dEmKb -z8P}CmkW^L=n%B9Q9|IB&cjOfV8D0G*n}j#+Ae+CPG+aZe8MXo -z`F_a6PkRdLk^jg~O|0#pR0Kh4XB=|!R$IMS=fhN%1ASSURF+C{e}%w%@G#U5K0jS@ -zdqcB9wUuTBoobzl&7kLhWRVF4i_>Aob7rR*b{%KZvHim+x9m@8H0mf6Z^St4G8&LB -zHpTy;XI)>%!4A7DU(WgFp<~_!rjA?yBX>`Ll2{j!#;LZ@Ra|%q6ljZ~oCLM58DO2B -z@@qKlVxyM%_wk^S+2B<;eEl8dI;C75!305v&lHVB%?{%@{fN_lh0Fz3+WhU-rc;Co -zt{pd|08cdwp(y#Ey%DO75wgIM9oZx%m;M@)w+q%#yhOTzM{|0epFFl2%V2B*^zdb# -zLtg+*Pk!JU6r=SE96Y=uWXqmonUaq_U~mhe|Nhs11z$eYsq5r6GvdUIkxPbSa^!JucJ6lunrI!~CYCBHpo`Zlp7W6T -z0R}mN*!=ieFoIWHCQy@x2^a~s%8cQE!@vue=@_6@v&v+9@(+s>=GA{t>n(JibIAkC -zc_Cl8#TZq+<+)Jkbg%{Bk2vlkN)*Sm?_sK9U|~dPYRfTytvvra%6Swxv_}$>R4{GC -z9dlx?of)+8u)G1`(17)Ar}|)emc*7pvv9xmdyDM`V^qSXB8PVe5W(w!XdCZ@{~c9? -z{EuW@x+Vd(`s-b0^6A;0gJC-K(fJr!jN58A+Ayo=k&&lfG4=NM^i(BMI}xs%5TYP@ -z=E+!co_#J#@ZGJ~+ZKh%5>wJ?OBEbcqJ!fd06JoCD0sTevnh -zeYb}GmToDBVSi|c4c)}Znmx{Cob!CF^iezCh?0>3o=y9wlV)5pdPtsk3Dd6eJ&_}N -z40Iz(KJ#BVeo_0Mf!({!#P6toUoXX?w!oM7*9BVb~ -zIG--Gt9ix_oY;+?D3Yc*H_^D|!+$CDRYbeE*wlZk3z1mJyVvza8MJTbTVp{-MR$_Vb -z85o1|GO+9}*jSN6x`o$u_GevO|A1oH2-B5JUOqY2dO1Y3xg@ket~W;HF3_p3ch;8H -zA@hF(dD6pT!-L$M?9BB<@nkRrBfLfUa>Ey?Cx^`yKl#cDagwcp@|}$uh#okmH=tsN4bb+PHefW|Pj%3Vy}fha7a_E$bOa?P -z8FJ-bADHzv$dO)+ZeJzqb&rWk^O*C_S+sv1mnye;2bKg{7eI^pmn(XQKdP_lspwTr -zX3jc1V2jk!Qr(x}g`1t1=n8G+uvgT$sxT}{=y0^ob%Mg>npS<}){)aAx0%V$_o=B_ -z=~`SOSZjK3Bu&8!eRoGV7E#C8aL^u2%VNxK3R0dVoI`UXs6b26vcD9$2c%&DT-1N@ -zOi+2^=KXfZ0E|fDhH@NjFZ=~oJ&x0Gl83}Xbq*W-14JW -z5Npb?m|k`Fk1*3yniB}lEEU`;O%s240Z(1|b?~}E?*rj9DBGvik&Ix=3%@9Wr{Jf? -zK$@qQgGUoLG|`FO53OK&_7?s^fNVpBgzWs{{x=M{I0$#)RqH^t? -z%~@S*78!xW^UhVCcK6>Y=Dv}9xW+urfVcc -zu>g#>iAxh_@0-L1`M|BMF|<{62P8z2r?f5+qTVJtpE~#aF(oh~1_>&LNQU0g$6*WuPSm -z)&=BgN#*52!DdM7rK>Tl7p9;qj%3GuXDxAAtu*4h -zC~9=k?MXWaO9t8Iz|oL*2?Un2l9AE|a$=h6Ph7myik>RjLzPAKR~3exF~gXi7EvqW -zE~9J)1$c|Nk0{8hA?+9+)H9)`@X_yoFgT(r4IA^^MTMj{Qg_G_Ecp5%>Z9~6aEq$I -zqZ#8v{eFLJh^yhFyaXX+Wj){=eEmUmy`7~T2J1-8fxBIne8Km2YT>L%0ByK93;aq*c}2&1oN%Xv@sK}hC3l=wcLZg~cO)e4BA -z9A-09@Eafd$`l!^yiLb`C@H8+r5iaEM;12amg^s3a2XC}sPdDEl<$~&v&Pt^O1_1E -zQLtxqpx7ZB63jv2o#cE0mya%atND;ON*P9$5}aRRDv>sZ{ey&Aj(@1u1CJ9R>^DKP -z^ixMkvsI@5PQIVZ3yi;x99d6)uZU8`4H|tVT|k0A07DTdxKdUroElL%G2hIaX>&z- -zGBw+$uCgJ}c49uynU1`N7tso{NI`B)cx`w%*LIVJ;lKpsWLl6f9RZbB1vefXcRoxN -zf`j3p2&6|(LpTdfF`pzIs5HmQw0{t!f-w%I3Vn3;v*=k3Q$aN;z%(z;Q~Gd!!I0h)kqAw}+m -z)+NTjby%K`)VatpY0W8Hew#n^$E=RUK7nr1>4 -z>iwtm%PM>6uO=PfP>m?)-Gb0cP_7gNctp${p3IyR4R=HRqM7Ltg{E|SIaOHhlurhABd(0~x?Wl|2L82IQ(SU$e^JtfBDf7?-BFe^(x+A2}Ar^U?gLKFd_=+-4d3FF@XI)g-zh -z-YtUJqo^N$Ly5y6L8u>qux4^IlnY>!6%dVBhAqwN2zEP8eon_hpqFqKTTU&#sK5}O -zR_G2^6daRk?y%axch8{tVp@I}&7l#{P0Os;!v}UV1h?=i&-X=pfo-qbS+T++W?ZX%Us-H|5<*D)EJXiAg3Bf>mv`pr~(2A00e>r$U;JEGF6`VoCJzVa0|EX -z?r-cm#ze}S%!%psUL4|O7o)w?aL6CUL2C;@kcy;3mXmu9k5552^YysVU|y}Dt4Tre -zPV>~Ox;FGPu3FhmY0ynI1FpBTH20$$M^SakV6_70&$J`Hks;hNehz)Le^GJSJ=_GN -zH*39XikMG#7>%AiDZORRkOLt30;%lzH4I}kR@``X%@4PRBKiA11Q+_vN>vOuEud{H -z&<_ysqjijW)wp?Ok%G6mho{!?zW9O6j+^7LBvOZo|k^lr?BV+&1Np*EvfVARsB<$IWpEwLanuBXis{e8Dk%c%<_`_Vrl+ -zeqkeQsAX_5vbkPxufliV&E|2DwZd -zb0a{R1$ot?e^yQpL#pUx?VWYRLnMsW%7--ugt4*a$I(}Hbu=0C{2_Z-8}s81q&aI9 -zJV$jFX1!0#)!Qr);z4f0ALns&37-$Ja!$6RBT&!xakOnxj9v0?HEOIy+(jna|HALOL6>+lrjgECvKHr!Gf67D>%p^v_`gSa$$4e+m*4;}Ckz#l?vNJZm2-dM=-bp!>L=k|AGKa`?vcIahAIZmTnuxhxl{YICp3 -zbH$qBcKtQZ8KAYVKc9+^HbatsPu{fE0zFaZHYW(`rDO+*{EDYApMIT5Q32n4CqAZ* -z3o$&+QaVdGHLs9Cc0+|GA=Q3D8!`&+u~`8Oe;^^E@Vz;0#P`PM6$qBdZ)?J)lMoT) -zz)rs=&q(e@F^-GlakAu9)f*&p!LhhDMXuDwQi)vur?~mo6w(T -M3X5P3IRXL*0PAOtl>h($ - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn.p12 b/src/tests/dejagnu/pkinit-certs/user-upn.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..7a184f651e50d1443e5fe907b5a11455d69bc0d1 -GIT binary patch -literal 2829 -zcmV+o3-a_Zf(r=(0Ru3C3eN@!Duzgg_YDCD0ic2kzyyK{yfA_axG;hRZw3h}hDe6@ -z4FLxRpn?TpFoFeK0s#Opf(2Cu2`Yw2hW8Bt2LUh~1_~;MNQUKrWafC+r24#=H7D;`er=H*b_6X_JS?p@<Xs@2^$asn4KAS;Hr!s53%;M>!4_lI!jE@siDP@6({Y?SkW5h+LdIH$!` -z_-XqxelFC+82Tg$(YW7cLdVydSw%i;-Dj91iRUVJgL03EKjM>L^g{mUmKBVKsyAB4h;T<*EUp~k -z5rfW}jFu*r0k8Y^g;u6zO^A+%O_lMV@d%&03_Kg*X^^o_Uz{`U5MX67$xAr!e22Ui -zNAXN+;wkb+d}b~b&i1*3(p;Exz@ODQOofrIDJ4q$8bvI|QlJ^WxvF6?PHha;kGKy*Lw>`x5`pX#xOpU&t`! -z7)slT|4hs;jt~|+@{`;8_Mdj$GgX1D7bOQ^)Q}w75-Y#V2+pavIB(a*V$3IEP -zg?T;;_;l~R>6v}Ls7>PH|CSU4@((!&99d`8mJ4VP6tfU( -z4xw}bWH@+eq;9;I?L2T^2F%;7KMe9jrkMY5;~yqZdv|HCk0HHe6ELR7-?nEn3P5tpF1(5hLL=IZuz7bA2y^CwDO;azer* -z!C$qO=WhrA@3Sv;JL{~5A4{ohyNZWeqOYnSDSb7#hu$$uU(aKsIIcB?CZ9J;Z5$lu -z=Cjt}MYS&q`XV#P))k%qT34!b_#XJr>cQ`>q`i7hA!{`l0Mcf&{z`~2DbjCAeFaIZ -zsk<_2+ZB>2+Y`;uY#zb8doC4=Dl8MrvwAKUL`Q@5E -znq+%df~WK#qUD~jzbgmfQeAq_dvu$o@tNNmYJPp4oVJ2u0qBUy8Jxcoc2$6Hz}-~z -zxOwJtoxJUF&6R0oar=qp*4XgOz)zgalsD+2B(!V3Q|`x>a-lDmn?dh^U5F1;y2S0+ -zPRYG~!nEeag~ngC@l&LNQUM2ml0v1jyDvT%JrGqHcV|9L||!v`3Xn^r^f=@jKTTw|8IP`5&TRwiQNz -zuxF)@AE&AXjT8}6AiSS|MLo#|aBOswU;hdcU7DWCd`J>wJYfn542DWQmL+e#>?*H8 -zdH;kV9Zz*4#xxQrPTyNZM>hg4EpEgx#nP4#fobQPcfv18grG+nAHI;bL{ylamN8W@ -zKljh2Bb-jW^J?a^CKm+huNYxBjL<&hBZIF2SK -zVu{~Wpo9P=Pg;QoJ|*nw7DjGB4y_W^t4=uyCXy=!hMY3cGj*tx`I>011gj_pl(O=FX4%Pv8{?*qOk9 -ziMJ9kiDb%Rq~);boeQ_o6Gz>K3&BxCt+`@~nJAh%g!EqIPY9B0ewTqT;whOBDJtl59yda9Br}TXCfgC9#E~QjpuTlPa3D;Kuf{=3 -zeP!#*-6{&>E_LrM8`cuctXs|W@67%V=)pB@oy&Yus -z@2ph_mT_Bq{2J2QMk74-EEJMTAE*X9x#e!==1 -zfh0RBMQN77*2GhWj_q=-;Wz;n_ig?}US0W`OuQS?@DtZzW1f~nnyoPy(0Hx*GdchzpbQ0S0ir-J -zuHsr4irnU(ilPifZg3UpkOD}qmij*p0LDWB`u7D|00oR5NcER_L2r?C?;0s76-g9| -zoP$#^&~mk2OIS|=F_sMsnX8)@2#;-@M`*t=Bh1+Frmnm8t#fylmKL=Kk92~}LueGYkFoKdBM+&*L7DFr$HNMR#9xE?N?M^FnQZJ^OT}z~im)IwW1caxhYM;+?)l -z6FfS#9Zi+;8|~jLBE|RqTDAHS-Es(u*=ip2^4OkHCUs}hqma-3PAVfv2kYkUh7$_j -z2|o2WEq=(;OC)Sg0{2i&3wkEy+s&cco^Hy?ow{G9!#<1CX=U-w;l%M;QxsMc1X{6^ -z@6*5A?zKfo@cDpT+L%OfWgny?;`z+SIpl0Bg=fDrrRB=EaGDD+ODlERhx_l4t_MSA -zZ`6*wF0gJrmlz&9>PSWsZRGWzM9)1?B%hhQDZaPZz)@56+a=hTJ^Gd+X{KWGzD#mq -z-)pP0)q9px96kY?$-{@ArN#H3W~b5SQpD^r{( -zR2Aa>s|ul_3wCEtZPXyZ-^r|UbeSu}@3Tf;uCGgUPxvsJ_f8btP9L)4Gg}HiY);_2 -z+mOZkK=xZm%YI+y7HzaRSCY`jya)D=X|9p -z4i<_VEkh~=A|CY!+4#xR43GCR3n_n$#mB!Q*Caq98D{#S -zG2G6Qx>5L(CX1A+juY-*fdn6FiaFyDIVxdbcL^V(xEaKTCEGE?Eg-?Ir|*F}s^5!F -z?uPI=y0M>KgdCNtoMqO7WN&7|%urZN+YeMK2xf3r~lQ+GSa7%(FHQyBM;pW9P% -zaYm6(pg&99#xo>+!=(tb&Z%7-db}vcu*5eLkNkGZo -zzF*Fi3O>s*3bhY!SM}Vz^#%)mEr-e%Q@4;7yibf%Z7JO1P^k=rogOwEP53EasxnaeY|& -z@#_1`qn`I>sO}W|rUxMujvfdt)Pw>>jdIQ$6rBk!R?Dt3>HE(ioW+$zbs`si)M<^v -zD!WD8%JztN8Hd@%EZTZYNj~AzLgM)N-?t%C&ch~aytdUXOx4wsy9c5Nt&-Emq#f4- -zHl=P`cgVJINMbU#Kdm%;UPucqJ=;5x2HOrGV*FpO|#t8^HM1;b*9+* -z?Zrj8WYTa5?5X87{AmuhQ~{eUOrUJ)e#{c2RMvjrL*+(0axNW{6}k4rWO^+1h+8G`-UW2$QEGKUu2I^6J46a;(RUNp$Kxxh+7_@dXK -zD3E6J{uf}Muo{~}jVZQ{9-6OTAubq-@rVmDa-`b|`7@B!AeO10305~@Dr%6}iV8CQ -zX=X6;)T_SAFS7M$LiE@D+*=b7TUtKh#SiDT!#~CG=`dm~xS(|WMh2cwC -z9xApaX8)-#y$}a)r)<27$PL=Btmpkt47*NBvk8ah#FF41>VQUrT~(jsda)wttvb!- -zM+f8nK~3)SE8Uzv>G&lV4)_-4`%LMHreSl%ftOL3EVsbU&-o^)j+>LMjzQhwIHkzs -zj3_$2&5jM8($vnfB%~s(`|}Z1C!?xTVII!4JlFJ1^Re_w@F9G4mN$!!_KgcobwEi=6Y(|7ZRIDRJGT*_~94IW0yH%-kFs9feQJ1yJn96nt$lA -zzrxgdtPW^+9dj6s89v$x=KzGEryP`-O_BZ+GS2{l%GJ -z;Wg}AbQUBB4M?CzGy8Ssk9A|Hpi;6b7mn2$y?*zP>|QNHc|A(7fn(<1Cf>^n=D2i4 -zKzgEcD}!8bkWoA}X|O@i)yfYB<*)NprS!O-sZn>>{Fs%#IjfvVXcK`c!w>TZC_`)L -z+iDpL1H%ga{1M#fkH5W(UbJ6AdC5@ -zU_?h2EWjXR{7@lx`=c0sVEQ~^7P$v3nigDDUJKG8QvK%lSC^!oJ2OHT0o?DE{uPC?#3C(OA -zki6%DF9nBN!6h`eVtXs4W(A%(^dA#v!!&+b>kELYWpRq53rJne*K(ZpG~HB_^VCt? -zf}PYa%M7*9wP4L>v+TwLKvTK5;tbtW_0s`(G_#F47O@y)BStu}uBOf)QBy-Z*`=tIAm?i4u#!!!3KB7)I -z&S&h+XZ9MjAMs0e`O9!!0W;w!w{oKJ5c?VTVfMz1gdptZe|4k=ORxc1k(BTT-5~lg -z`SxY-DooVB&XB_ZCIRDzQB#oLrY9riA}0Z|8jeaL!SN1ZPMJZ5zHE}mPLR8nKq_{_ -NjEEGCzWl$H{1*d>HH`oO - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn2.pem b/src/tests/dejagnu/pkinit-certs/user-upn2.pem -new file mode 100644 -index 000000000..3a5094c84 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn2.pem -@@ -0,0 +1,28 @@ -+-----BEGIN CERTIFICATE----- -+MIIEuTCCA6GgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSjELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB -+CgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTEZp7kzIsd -++Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW1hqJaS4R -+AMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV+VRogbTA -+O7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6KnFRF7PkR6 -+ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91DdvO+xwbsoN -+G0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABo4IBSjCCAUYwHQYDVR0OBBYEFGvA -+yQ58yg3eh+Oi1JaMrRzbt9hiMIHUBgNVHSMEgcwwgcmAFGvAyQ58yg3eh+Oi1JaM -+rRzbt9hioYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz -+ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM -+IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu -+aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P -+BAQDAgPoMAwGA1UdEwEB/wQCMAAwHwYDVR0RBBgwFqAUBgorBgEEAYI3FAIDoAYM -+BHVzZXIwEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG9w0BAQsFAAOCAQEAElYM -+786mUr91z82s6QC0TwP380ze8yJQiaWifHYXiqIPay19M+QG91PvSm7LLZw+ersC -+gEl/mPKrC89XlAFp8b+hJnGq6t6YmeC7OI+FapEMxpxX/X8eqAOQLrGnoq7Pm9/8 -+QtWaKgo09i7rmyykKl3xSU1VktBsmlhNPPNh3x+N4bxea9OIbZonPdDtr5/Yt87/ -+6kBPsGgvUUoIxLw03OmLu8AmKAwJja0FWyu93uCUP4UZWLEGpUhSYC1uUCpAZDNy -+2AtPnxfGUDtvI9eMmyeXVGYXTfkfGZyvB3m9lyIj3VVmhbvr7qLAGQn00dbOHz16 -+r6w2aye0Me0GcU0grg== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.csr b/src/tests/dejagnu/pkinit-certs/user-upn3.csr -new file mode 100644 -index 000000000..958c1e043 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn3.csr -@@ -0,0 +1,16 @@ -+-----BEGIN CERTIFICATE REQUEST----- -+MIICjzCCAXcCAQAwSjELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+dHMxFDASBgNVBAoMC0tSQlRFU1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkq -+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJ -+w0Qmn/qs+lNLjRTEZp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7 -+LiwbB36btYyEFCBW1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2 -+j69wqhPZIeXqqveV+VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT -+50CFuNkUrFE7m6KnFRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7 -++ixNvQn86a+91DdvO+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABoAAw -+DQYJKoZIhvcNAQELBQADggEBAEMxNp5md+jV5dFC1iSKh2CYl3P4g3UMQ9NjLcyq -+upjJmFiEGkEg/LpH4CoXI03BaD885S7akKPA1J/sG2YIrbl3TpjUJKZoJ8BjNT0L -+tYc+JIODZJEONR34Fh6/1uRU7UkRcJ8Crc83+ML+71O2SRZRJDEOS3tVbdzjEOTj -+HIed6Ia3cu0XeAvhoqRSjh8J0ufoIv3CRRCtRU8ChkmMD64p3kOTlORxWspAF8sm -+Xa53bWIpyuyz/vWwpWfr+fL+Q+BQ1TU39xvy+46AYuQIIKzK9vKZdCElQwFXZs26 -+f53OyZpFjcsT9jJAM54XUxLv5rE3fqZQiBhatPZa2ThHt08= -+-----END CERTIFICATE REQUEST----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.p12 b/src/tests/dejagnu/pkinit-certs/user-upn3.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..a9d4780c47d33cd4d409d6ee657a7911381fe753 -GIT binary patch -literal 2829 -zcmV+o3-a_Zf(r=(0Ru3C3eN@!Duzgg_YDCD0ic2kzyyK{yfA_axG;hRZw3h}hDe6@ -z4FLxRpn?TpFoFeK0s#Opf(2Cu2`Yw2hW8Bt2LUh~1_~;MNQU4cR+h_S!1xwTJB>WLrfC_;4Q{WSMU*o- -zn@1qFp2kU-SDex#I*!6h8=!K8qv9pObzLDLmnzWdibwhCfJuy%lF%>17?*+`lBBJM -zmXpRI{I$vJ#9ra!;LI(a-Y;XQ;Lg(@=%$W%N@M`uG=dT?Us_5#Ydy@oR}Jqosz*ey -zVPGvYS6-Lg5~d9q+Kq_7hwvb*@x0}_hvi{GII8!JaJ+M3rIu;J>8y>3=gG`dH0^iR -z|2dL^4OS11LK|#C4SCTCdZoH|NY!h^jRkR_ZBdMalelZlJG~EQsb631B6Pems-P<2 -zy=ikP`PqC(+TZsM6awppC_f0Xl3g4K3t|VAQ*|@tqWP;7pCfxOI}DZ9(iJy)rS*nL -z8a}#DV!e3{QR4jj(Ty7a7d86H_%`o3)tY*5-w|QkembO|Ujs3}!86C73mgV0q^5iP -zuZU!CsXRr9j$1G307B=@uSo~fVS&hEIJ+>AH&cjQ2XBCfI;BM))U5*2LLkNN(0?0u`ndx|WU+*&cfWKL8;~Qf+dr$yMp*|3(UJ$X~0n_~&n<|bR -zOiCnb3@;b`fsYZW;zy3u!xk;pHehyodmHBK(b4`FY+RdV=I@k+phXazTua8A-KghY -zbHI;PA;HtNCqk1?WmxDfVMr;cPF-ev6fv2Fqj2|J6VMXUHxmH&PN -z7i%{(&ibQjorX+L&72F>74o;aDdTY|SfNampj*cW`)4?RC{QhRV~@au<4#(Y1RTbE -z+4)2+UV+lnFK&q(3AJu`R~b$_-o!)-dXZdz3uyEXkjR$GQ+@~Nrzj3Op78qsDTByr -z87^>(n=t}k--9Y2&($W_V$rpuB>QO?+3-dA-pr3g54LFhpSdbUZ|IdewW&nX@Id-7N;;8dTYiF$bj&+Vz -zp+$O4o`v}qtLqJumEjK!5TYC+&IxPxnPJ?qPwid3z%qigSZUd*O)r-j4oE29GsC=< -zw0myiDI9d*4E>t?xOcwEA~EKL0)VbEj&Uc^xro!On)Pjn$+w5R6#oT#|93jg*@V}Z -zk%j`((IQj&TOx`1Bp_153n75Eqw3)xRNoBq49xGry~PpA>RD@*p=h}-LFRPD=V~%O -zL!t(9?TCJvy{&-ipV)bfua3YR-|1T`d;?f_6b0}I+QRRVRCX;HVm@R2;PE+7K -z3Q|#cnBp2{Ho#|+7-NPyucnCX#eD8mEc6JWn6yVrPT1jqs)!%NzfUi>O@f`DTz7r- -zs6~@+cMQii)Zyfm5|I-1^j4{K7>B7|irNe8d;&TQyncnqec(ERvcvZ=HhwevKN)GU -zzDKIn4gl?ZdnRwvb(WT2#ZBk3!kjVDJEGu3Mj^N{FoFd^1_>&LNQU?&x>nfj%n^6>^V7CUp+ -zETM}jN%cj-MzspiSpQ6CYmqrq{b{-|Kj>-Fd1TKY;L3MOk&IO)fs00$bk5ZHGFaBf -zsRg6kCS^21bh?tWf1jQLIaT&uM>-1!L@?~)eWqce&iDF0qMSy`TNzT_)VB-&hdVeW -zjEeXb0i{%KpZeK!$PY01Wa=BLfB6xzk$J9wnQ+$8Q?cOhQWJ^oEshJdhCpbB9?+gW -z%#d0mHXCu4Kr$r>M+VFC+yRsa^lQ^YyqVejN5NolmXwl=j;AXtkvzSNzYdLcLS1M3v(LEqdCXAG^SL1Jy92cADy`hRveJZ&>9tO3Rq_n_U2brOPWo6XM -zre^&}huWluk$ -z+B?xm6(8=jJ-w!B_8@+OFo>mq_>DV#ryewM9%Z)!#3=XxhO#WL%G$~t4CS!5WVoB@ -z9IwU{Qb#y?ADZ8(K#I6quZz_TTCR&i8M?`ng1<++_9q(O>U=r;A$ep&O5PL~0ADX*&QcF)J*1tw=!Jp;oWW92 -zx_WL`bX!>KW=&X!8je^w5L8BljVzqd+B6(1iYw*+a2t*Og-{}@ahG~CSZjlKgN)_F -z_gX^4sG -z?|whq1p%Fu)%2@m@;098MdnS5un)e;6`RgFr)yc~xn2wcd|aAZWeZIH?b=2rqMuuF -zhM;R=1L3DiNIjP$4H_N4*lqU$eq7|>Ys3|ew5^EImFF1cx!T2jaX -zfyvmtstS0orV!Q7PL#g{*$ChxfS!0s;sCZ%;ud - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.pem b/src/tests/dejagnu/pkinit-certs/user-upn3.pem -new file mode 100644 -index 000000000..ffedb0d1a ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn3.pem -@@ -0,0 +1,28 @@ -+-----BEGIN CERTIFICATE----- -+MIIExTCCA62gAwIBAgIBBjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSjELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB -+CgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTEZp7kzIsd -++Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW1hqJaS4R -+AMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV+VRogbTA -+O7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6KnFRF7PkR6 -+ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91DdvO+xwbsoN -+G0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABo4IBVjCCAVIwHQYDVR0OBBYEFGvA -+yQ58yg3eh+Oi1JaMrRzbt9hiMIHUBgNVHSMEgcwwgcmAFGvAyQ58yg3eh+Oi1JaM -+rRzbt9hioYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz -+ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM -+IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu -+aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P -+BAQDAgPoMAwGA1UdEwEB/wQCMAAwKwYDVR0RBCQwIqAgBgorBgEEAYI3FAIDoBIM -+EHVzZXJAS1JCVEVTVC5DT00wEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG9w0B -+AQsFAAOCAQEARVeLPouequn86P3LgOZQ9LpP6IHpY2ZQwvNviiA8Zk0hsqFXnmwx -+wr3JtESim3EPuwQtJ3jXp0rxQB02r5r8sg21OjCeAB+vOz3IoF/y6WEYlz67LjMB -+XCB6Fuq80IHhVXWRi7w8dVI8xcADwIOh6fgzwbbk8qV2Lgn2Giivstp+76PnRtEn -+tavWlWW7bQlXkiROYh6u3Y8IvYYoIdlDsXQBFSRE80Rc2jR2XGKAz5CDEZNC7RAH -+Z7ON9HH6IRBOX1ijmXhBl/39QQ5t+ZYgKk8OJpL1RAZlJZtGMBwJtA1aGiAFvqTr -+aCREHZfn9NAFE/szItH7hxWJv9RISUXYmA== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/user.p12 b/src/tests/dejagnu/pkinit-certs/user.p12 -index a7c2baddf67f5a8c6ad97b661f6ff285ecd5bf37..67c3fa2eb01c9fdd543af9172dc63a3955987ed6 100644 -GIT binary patch -delta 2825 -zcmV+k3-L2N;;rqK -zSyqcBB#a`vq%RJm?UQRey5syNN;I{A1gyVwKE~n@jbWz;r@|AM -zlt-Dw4#5`C3%OE;suP^fKAkmd<0stTrax4cKBYi#wmDyWkH@HTEzF9Vzb4z(Px-u%2--OA4DL`@vMDzJ%k+he$KUV+etb#R@X1p^xjIQ -zHHCI2jR$-F?jK09io?qm@M_cn8*o;ql~XNl6dFi83)IqmcEQ`VgCdb<6p=l&wDNBh -zCsi)gZ^pn!adN6tfqjU59L{WP9ZTwex*A&&TJq-rK^pl7CaosnYypN4z4}f_$-a57 -zM>j1uIhmSFRBBso?WIxHcvNXh7@BuA#OSnOJLPr!CPo6T$^vk}CF!iZW?)pB$=3O@ -zrfxe$v8EVwa|3H6ER9y+OaA^AN?sy_V(?K!suZGEvWScYsU%j8Tm223XbjYUAviV< -zjRVqXMw@vdf|o5^9wFcIr=5rw4>$56__Xd6#^Qsv`g(v1=Q8> -ziP0(7aSZ@G=xc!){8#vY(P0#=2i#b!H0mS*tnBJn+%XiU^}ohqA;4n6-qyM>pihFy -z4Eln#fQ^@qtxx1ua<5>n{y3?85=BH@b`Rk06z{b>dCNW6Oo&}cxMKGgz!y(Zd1EKXWX|R6D%;V -zO%}A{2XK=U6Q9)>4CCpjR7Bmj5tGi0`fNAAiyy6Buzq`yQ7=G@(jo4kz~uX3a|leQ -znPbFK-QrsSWjW`ZE0l0RbzoN$EaUA3xKZT3H)vpww4;H4Y~@Fxa(N5MMgT3L3esA& -z#khOUkdtQeZ?ujc@i|b{Az$o6ji1SvfQ2P4Fl9xj(j2fRfXM91NY?TZi@9G~Q>8u> -znUEbT327qTp=2E;8j!deS!wcJtNPg6~u?|e$Cn#?wg>Gy;!h%T#ZZm!|+sp>F-1wjT0Duzgg_YDCD0ic2fG6aGJ -zE--=xDlmctCI$;ChDe6@4FL=a0Ro_c1nw|`1nMx8x&{${n%1@_Wccvq0s;sC1cC&} -z(RN}-FcTn?seem_$6vscHBDugxnx8L|3Ew+b;;a<>LT@K6&!=f&;v{-fr9J4)RI5E -zj@&%tk43H}?45`sk;yf*U$h5Rp|)9F6Mbkixr+=hea8YdyXbvVtQsqNcpBZ -z#n8MiO94WErRUY&{G8aC13PpOJ~sOK8;S<+Ie>LKd{9|1T9WiB_c>(}FfnAf;L;jb -zfNB;hfdYtGs0rLO^TE8t4y7e>6bF8CPHU5uP4jz$Yy -zbL9m*YvAtA8!^vfrnnrj&CCGA^^&svs%|+8*DEE?lL`tj- -zf`rq7l(SqSOVc@gT!bIJH%*ulo^Rrq8vp}!YD=*9th0b|XC4K5kKCIJ#G)UbZN)Ww -zSw`3^C#o(f`hsxT+he6hh$}M~2Q87|(edYIB5yDLZ(%;MTpajfq_bj!59ytas5{aU -zjlC6r#g*`SaxR%zzqQ6BW|Q6?cyz1Bvuy6fjt!Bo`$oo^9;J^!3#!XmSiw9*5%*N^ -zQ`2(jBGPjpt%+*4Ds-K8@v?N$LVXpWSJgCCtdxP8Ct2+e*4j(IdxkRy@~{XUZ}X+DyjPW+V9xWn;~GLbJO}s4^x6; -z6$reQw$IdY>X?kq_FmyYA+B|x6euPPHyfqnqwIO~_)n2=R;F+z4p%BJLy`c@dS(2- -zx1Ora8m!D>l^j=a<4^I_s^luw>R2~vsr^$6814D=So0R^I>^3!lj4S1`0<`!x&sk^ -zT)bs;3pPzQTN^KA4O2TRv6Lezb#;s2(3`&1@Is%>(bImh$?j2Wv3z`eh8z^5Kqwnx -zB9UF+NI^$^U>1@@y>$c-eUN_iXYM_d)Cc@f!jXT6&#y70UI?FBobSP=?)}8^=fZC{ -zH4+W5iQxFbHcNUHQfmMqnc71wJlHjVLAuoFS6%YV)&L9jzQ8?M-MXaXY8IG+q)TT3^jVwS*gQ@y;alU9 -zYt%DyI=C1o@+PH7AHTADb^xm{o(C~q=^;j5^A1;iPuz%5H<;GtbhX9NhsDtNX{U+Rl2#B;cyXCk!hT~J7*4P9Lt -z?sqAVi^dY}SlRgxYg^JcHm7@k-95OD4H6){G!Nrf%MW&7s(zR_*{b+Ys$MBCm0-*&fN2d -zLo!o!O^GGE95nVk4@7S03xTA;N(*fPCX`P8`Xm>azWsS23xZYFbkS9REW0}sxCq_W -zZA!1X2X1Q9)%6x;w#V%=r3cQCtdG~JmCf2ML+=s$*YLOY&xjJu6R*W@*bAA>)DitD -zLn3);mi?f8-j`_w`MPBdP9y){Ok{43vm0hfd|)sc>x+EAS}`RsBL)d7hDe6@4FL%i -zF%|?Aa~UTT2sI*=Z7gOy+Pr~M|3OA6;4m>TAutIB1uG5%0vZJX1Qf564%Dx{fH@}( -by5{;I{o2EAUPuH8o2f}+U#knW0s;sCTvk7E - -delta 3072 -zcmV+b4FB_$7N8hFFoFym0s#Xsf(zmX2`Yw2hW8Bt2LYgh3)2LG3(qiu3(GKq244mV -zDuzgg_YDCD2B3llP%wf9OacJ_FoFg}kw6`P!$C#iY;oVd0s;sCfPw}X{k^@yX8+%9 -zwBJ}5flvw?@^UAz@E_15;f|7 -z%=`IEmu8Fm{;M@9J1*`p_pIcRPLK(+FMWn?4Ww%T0x^GtUpOaX{(}d=6zfxU*O_P_ -z;{8-Vz=+PJ*fq5Q5}1P|h8#+LByXQ+P>3e*vahmych~z9*bcGZU>fX`OHPSi?VqiC -zB=Rqvb+r)J90J&GI+Fao+TB6@Z9^%48aMh$*5ZZ;bg}FUG;4;3aF(v8Mc%?$$0qwd -zc3^N%>ETq(6vTI$`2w_1OaX?h#=Tof#*z5MeSw0*v$CMQcQ$S>moyee?d|Ygd -zOSrQGiK>X-ozcDa;*JHQLCC}?$LH>?!Yi#hRsnX1OX -z*EB3%Xa}bdITw;zI$pm5MeS#lApv12PFz^)>i>;Kq;rwfsX%C~f|;W&4uX`4^{hYr=Sv0%nHrgoVxp@+Oa2pz6_!d%FIr;pRDqUYfO{2<~UWQ(O#?)HAW1rbVG%r -zq9bBAoA9db8X#}@U%8%J7?%N|4`BO{Kf`A)Bo>s1w3U?&wtbya#nq(}in*aOqVWwL -z54v^FBkaQkJ{{9QU=Swu92Ip%GvLLOIDd7VZmIBi##hu?f(v78%UHjEu7or)#XQ(K -z6nwxUcCasL?i8)8F(v3tkFjU0@B||ae%?*I6IKzV$B;Xlklq^f`Sg6cXaqJHeeaB= -zR|Kl&E3F1db<1&_nuDc1V^iiCJ{=(AE^+aqY5NBcI$5;qni~17mHn5(Ds))Qj>(fB -z!cAhp`uQ=F+SOD%%+Ha38w{~j -zo9@HR2C2O8b?-H5VC5*x&5I%i_u7WWj~_7^J#l4mNU^ZX$|TykZ>kn^P>m*4do=8) -z-lvs7RD7|XX;o@sWC$=qUP|t9tI!D(6aWp9r+d%S@i=hsUzZGj4`0ajob3mf39g=O -z%sLUXQul@047pG(XAo^Bzg#aTGeIP9XG%lsySCBt^BD;L!P?o>8|72>-F%bY1Wq+- -zQ&co>uVf4#KdH09JZl->qdH!j&5obWpC252k*~RRm`++aA -zb)ix=M5o -zkDSS^SpDZ46j6?8FSSEt!hzU2{_KAgGG#C6JOuiZ$dBlrIHJI>a!|_ci}n~u6wfBn -z1&}v(3R~EJEM#g)ZxZO$;#Uy*l%8e6KIeQxo6!Ev!p)g^jmB_%6GXqkLS>=3J;!BiP~zMs^7_ZV@z2e~h;XLQo=1(w3< -zKSrEW)`6L0#?Y=Y^OVjAPol3~Y2-UA_>BjuU<55l@tHF|>M7Zh5YYg$$Med8J1xt2 -zLP*MiFoFeS1_>&LNQUQ6J*E3t0>aCid|=?nFOo@xF7nMEwFSqGFL=q6+5@%_ -zt-z3k=H;LP>M5^($OYSZJ{(r}tFwIj -zvW>%k6&+&B`~)0-Gg;CuKJ}d10CU^>UaG3Eag)cBnkgpw6c$vz5a->`qeYY{qOzjV -z$lM&d7YnfSl+TL;$Z%XYD8P&u6+OPseP8BbQ`Co+4qNH^w^HP@t~i7h`yya}!u<oz#o;ZUj=Hp -z(TV68ifC2(4C2=wv3r~1104(jA4cs9gd=F=kJAOeb?#j`oJ0bKe65FiHPEx{!4^2M -zz^<`>c3WJhEzhxX)l8^flHtnoU_1>9oCV*rdmGdTgN`7ewco2nZuA--|EL=EaG4Nn -zpF~eT3tG2-f{+uROTHXdk{V0)X{9@F4mpkfDP7mjH8Tej5p$_wAOlRUsVV8eC0hd` -zl4Cv#L%OnpO;^-jK=n`BoqWJ#I2zzYA;sz+Y;icw<{th3N}p#_Xrp8*rEd6NEX=4@Qp-i%c1jGY-l^{T#gMCnLtFM}iUj!H}kK_5;CTggujzqx``SqC!?Fq@kO^ab0Yk*7|TX+l3@A8Z-brb&{t -zZX^wVHoyg=NeF)1EnnZ8*NrQU!QHwFx6a1u4+j8i75XaX{V` -zTejP79{ii}hnRQ)sO)7qj>Pd@U}lVl&(b}Ag$oc4za4|Y2`)pu(3@Q{oocgpL9XPg -z&ARc&g{ZqR#9lsFPr=r@2fK*A|lb4n3k%R8?I#c2D -z;=TTZZ*j*ygj57wLl>LICIh&x-2VrAPjpHqNvA6BWcuW0J`V>k -zX2DR;M<%0M5rj)YL!vo}Lr8*yNjn|jEon4LP>F3;n-~NKB>zj8a%?p*fZm_SEdJB6 -zP-Yt1+4};5@fwomsJaS~^N?NR6BXot?2jw}Jgj_7AnKjnZoO5nIY`wuDf(}pQfmod -zE}t2${x!MEq*UT6S13ie-bH%m!2V*Ai?V#!PB*W9mXC+U>&7FB$YbjRT!@-#?o3x& -ziB>ytwV(g|m}&0NES6Y|(~D_kcv$pTt6{{O5=Tjd*U#!Tli@}SuFK6QcZ9`%x3jAa -z9wib(pG>woZhqj$pub -Date: Fri, 25 Aug 2017 12:33:33 -0400 -Subject: [PATCH] Add test cert with no extensions - -Add commands to make-certs.sh to generate a test client certificate -with no certificate extensions. Re-run make-certs.sh. - -ticket: 8562 -(cherry picked from commit 0d23835660ab131d244d395e4568969b5c0dc678) ---- - src/tests/dejagnu/pkinit-certs/ca.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/generic.p12 | Bin 0 -> 2477 bytes - src/tests/dejagnu/pkinit-certs/generic.pem | 21 ++++++++++ - src/tests/dejagnu/pkinit-certs/kdc.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/make-certs.sh | 9 +++++ - src/tests/dejagnu/pkinit-certs/privkey-enc.pem | 52 ++++++++++++------------- - src/tests/dejagnu/pkinit-certs/privkey.pem | 50 ++++++++++++------------ - src/tests/dejagnu/pkinit-certs/user-enc.p12 | Bin 2837 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user-upn.p12 | Bin 2829 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn.pem | 30 +++++++------- - src/tests/dejagnu/pkinit-certs/user-upn2.p12 | Bin 2813 -> 2813 bytes - src/tests/dejagnu/pkinit-certs/user-upn2.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/user-upn3.csr | 16 -------- - src/tests/dejagnu/pkinit-certs/user-upn3.p12 | Bin 2829 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn3.pem | 30 +++++++------- - src/tests/dejagnu/pkinit-certs/user.p12 | Bin 2837 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user.pem | 30 +++++++------- - 17 files changed, 174 insertions(+), 160 deletions(-) - create mode 100644 src/tests/dejagnu/pkinit-certs/generic.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/generic.pem - delete mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.csr - -diff --git a/src/tests/dejagnu/pkinit-certs/ca.pem b/src/tests/dejagnu/pkinit-certs/ca.pem -index 44c917687..f7421ba02 100644 ---- a/src/tests/dejagnu/pkinit-certs/ca.pem -+++ b/src/tests/dejagnu/pkinit-certs/ca.pem -@@ -3,27 +3,27 @@ MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx - FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG - A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz - dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowgacxCzAJ -+b3RoZXJ3aXNlMB4XDTE3MDgyNTE4MzIxMFoXDTI4MDgwNzE4MzIxMFowgacxCzAJ - BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i - cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl - cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk - byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC --ggEBANOWvXDyubZ/Kf8QYdPSRk/rsogzqS0rycNEJp/6rPpTS40UxGae5MyLHfmN --l2mSevRoHSqhb7cfT6n9kR2kb3HB0qhhhecHey4sGwd+m7WMhBQgVtYaiWkuEQDC --7/SWkRYzmYX8J41vrQulXU2/2pOQCmG4NKPsNo+vcKoT2SHl6qr3lflUaIG0wDu4 --bFrWszkxcuSkU7SSXDf2xTTTJ8QftO6WQY3g0+dAhbjZFKxRO5uipxURez5EemVs --Re86vXEILka85tiVS4maCn3l3FWMqcBHRFNa+/osTb0J/OmvvdQ3bzvscG7KDRtM --bRUnpWClr5R+AbGVvKocj5I1+G0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBRrwMkO --fMoN3ofjotSWjK0c27fYYjCB1AYDVR0jBIHMMIHJgBRrwMkOfMoN3ofjotSWjK0c --27fYYqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+ggEBAL8HFT/+Uia/TcSFIJJd7Z7ZFvMOYLhEkCyqRhW1ggDp0xrIAoh/fyxq4qId -+S8f7Aurf39kzyS9NtDD2snKwfoLaZpunIXNLCujrlrqdhKsZdtl8aYLmjIhTLu4r -+rN5WZIRQULbkLiuqc6ZFOjOZxkR0NkC/CyfQTJO5a2TaMrweLswmY0k5KlAoevps -+h+LPXsLC66sqgYuWDD8c1Z9GlI8dW2abRPt+WUKskEgHqYJrCkjvPIZgS7UDAzpU -+OCXopDDr/qQ9dnAYzt98r/pCx621/2R4JttZbdsXQDbQaHhV69iJqACqZB0lLyKO -+Ka4Y2U5zy3++t6pd3oGlWCr96D0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBSvEuBX -+VNKtIomCkLcxpsKp9Ag9qzCB1AYDVR0jBIHMMIHJgBSvEuBXVNKtIomCkLcxpsKp -+9Ag9q6GBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 - dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ - bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 - IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE --AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAN82zurZwM --TugUG6b1symxXxOdDqwinwIlQjzXJ8mTRv31q+YwNdYvdWn1aex8v44qjFDjEP80 --83y18CjjBHznwxsHll80QmFHjpy6xtRrUC/Ak7jfKnDiTKQYBdgmF4/UiVQu354e --QI6jPMQlrWZXThlRuBjM55hs4tgRYeTgbd4VSZzVQXdm2ViZkg8SGqw0R2ZRnG91 --dfXkhu/tTruguPAT3MQ2pTK/CoHHA4W2piQbBDqIl83fphRhYxyW/cCF2mvZZUhE --AfWhgYDeTDxHKG3Jfmm+ujMo5HscgeUpJ7XjZdobNhkQjD1piyuGzFkUfo2XzA6m --kMz4Jq4cnvpz -+AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQArUoCjqxsY -+/m3nx/5BQSkBAL4T5RgWIX+L4y4GXloYYlafpw+SxRq0QffFm5fpCJBnMd21MbPl -+k/YA+oq0/76cKyQmJ6h/Wl4KHCKKMmvGuhCEXzmrevk/EJ8lJXNdPfbBueAuLeyU -+7X9tO8i9fJ59AZ9YWD9d//puOF+8xeHPxJIxHcR2jHpUOJPtm4yVu1LreHiJJTu4 -+Xotp9yMpJu/uJM3aBKVS5N/5JreraLj9N6N8nZ/7nEw9Dj1zzGHcHCcqtcxz1oOH -+Zbg5Jo8HhVhIHxKdKLvwEk60P+lkGFIE+IUmhWfcbbprTGs7VhxREwxaWyCapCOk -+qlhbJdEcjHr2 - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/generic.p12 b/src/tests/dejagnu/pkinit-certs/generic.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..238baa56bc7b4ec4a4cd66861d9a54888ae6baf8 -GIT binary patch -literal 2477 -zcmV;e2~zejf(fYt0Ru3C32z1oDuzgg_YDCD0ic2jU<85*Trh$OSTKSF4+aS;hDe6@ -z4FLxRpn?PdFoFa80s#Opf&=vi2`Yw2hW8Bt2LUh~1_~;MNQU6Cwj5&?-ITdyp+x|XE-*3B|L8H?6tR9A4HUV -zXKXC4=L{;GYOU0TZ%YIlTM6d!F~cR^uf!*<@U_-l*QqJ>xt(al?+>_BvzoP^gL1N$ -z`F-->tkpYWJQUWTg*!blr__$E(F`vAa6$tp#&2s#wO{Z+x9Qj#E{tn`2{H -zg{vzUo0|{iV-+Q+#HBbV5=@9HX*$|bj>(CQqEHI)oQ(#V>5%ee;p0M7*Ncmla{Oaw`~Lk01PKR0)2+7#ypOR -zE<@*23b5&ny_nUSu&QRYf<9ZS$K+zIxKS{-TDjaw -zil6-nf!Sd?4znmK)|t(Kh;^hMN(xELd?H&?xwpdgxQuGz&lqkC*bt7YYcgZyhS`(_ -zV#Eei3)wjY67{AC<7Jdb$1DrskBFGeZl1_X_JSlij;_AeG&Ze&pK!02Uol4a -zAU3nTn}n!jf3MeflZTds*L87yad1DS(dZEx?R=EV`~wYbzuJ+gyipE3%clL}xH|uh -z*0lFO@p4PYUlRKizgu%`-6@}1$(>d}Hi|tilS_mz$63&pG)DTS?u#a3%DdCMr6nS= -zuqM$zP9u98I!aB)2ukr=BA^QLRczSH^0a)!b6RMWsc6m2lXG@=*;qxzKpg}Q;PWP$ -zSPdG{kzh|I5&?lP;`r@Y6C5-O-aNIi>snK{0uoVguzqbh?|wC|;ZdY*FoFd^1_>&L -zNQUi7=~UOR -zVu`0Rq`j%-S6Ff=&?TzqMFSM&gz}ICHc9bAOg}ADuoHHkw?kNR=9F1w*lYN{EG@Q( -z^&Z!5aJ#r-f4w{9{l_?xms3iieP1I%l~D*(t;Nk1aGOf}qn#GuBv85jI+6|9D>yt8 -z=`CiI1xSM|6#z}e8mUO30BVUlR!<3__7-RBW%t*-clA6mka`9Ep#J89G6;43;kLxp -z*-|yA&X1<^zP0+5jK3^7X7_8Ji!05N16zPQD?*Vmuu}Oqin+2p?#8~7bHAc6s#bFC -zBNktoPt|Xx$KKi92&|HGRDq~8=dk}B3c`50V14okG{eS4V-1zL#^Hl>} -zDnU~+pT_`PO~9}`Jv`1wS!fR(ZMPa4i`@TU5bt()(#ACb9{Y+&=*3 -z?16YQJcXXtc1SY}^F0^kPKKB2!~3O%n-3mC^{G$p0l|354kxz5D%&q&VtpxbBv{)* -zpMNnNpUwwe>D5nKequv57A`7WDkH{;SWnT$m6mFQM_4sCy6`Q6+R>fF3xV>`&)a%y -zB1l^2YMSpWB_)PDnwNbAr1q&CK9%#FU7a%regezQN#m#I@aB>MWA)qZGWrv>>pVj~&d(I8p??>w1k}$4P^X -zAWnN%6sS3RRKSDNfisfVQl0_dGxCM!+1Yl>tFQeHvTap~MEH7XV84MrcTfkph~OhN -z{o=b|+k%aoLEyQSSSCuJgEO`uIb&{+Z)uzyj^e7-ow^S5`Lr4TK3IX)>y>`8oiIWy -zH0hllKCxMqW=7K+*+}M2uMG#-iv4KGvA+{{p>ck6qZXw*_yoH?4r-2LxGhvU$-SJ& -z%}Cbjx7lK8OxbcYY6+T8eDcs^;Xvdw>6;}lnp8q -zOI2Bf

+yF}Y41&9t?C1#$YRn~NWY8C%6yHl*AOeW|@!q&2^AvuxK!KnnF`7+J)np -zj6bGtii!U}#abz=^y{$*-&7lSX?~Xs2w?6rihtbpW0dcnT=iZgshJw14vAdMlwyD6 -z|23bFWaw<;jHGdx+WL{QTwvP`6=BXmumW|@H&izw=M#i7|4o2kT^B@DwWN<09-mt* -zH_scbs?(Qg+gx};zbY90=8VD210!z1E&|~fxwzSLg-MMc62*ZwTWl5YDkMj->^Hv+ -zEh;f3Fe3&DDuzgg_YDCF6)_eB6ofmTa$1pK4AutIB1uG5% -r0vZJX1QbFHUUX|Bgz^@{lOae~ZgSk8C3^%24n#rsPDd1M0s;sCf8Be; - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/generic.pem b/src/tests/dejagnu/pkinit-certs/generic.pem -new file mode 100644 -index 000000000..706c2f341 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/generic.pem -@@ -0,0 +1,21 @@ -+-----BEGIN CERTIFICATE----- -+MIIDZjCCAk4CAQcwDQYJKoZIhvcNAQELBQAwgacxCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoM -+A01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0Ex -+MzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVy -+d2lzZTAeFw0xNzA4MjUxODMyMTFaFw0yODA4MDcxODMyMTFaMEoxCzAJBgNVBAYT -+AlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNP -+TTENMAsGA1UEAwwEdXNlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB -+AL8HFT/+Uia/TcSFIJJd7Z7ZFvMOYLhEkCyqRhW1ggDp0xrIAoh/fyxq4qIdS8f7 -+Aurf39kzyS9NtDD2snKwfoLaZpunIXNLCujrlrqdhKsZdtl8aYLmjIhTLu4rrN5W -+ZIRQULbkLiuqc6ZFOjOZxkR0NkC/CyfQTJO5a2TaMrweLswmY0k5KlAoevpsh+LP -+XsLC66sqgYuWDD8c1Z9GlI8dW2abRPt+WUKskEgHqYJrCkjvPIZgS7UDAzpUOCXo -+pDDr/qQ9dnAYzt98r/pCx621/2R4JttZbdsXQDbQaHhV69iJqACqZB0lLyKOKa4Y -+2U5zy3++t6pd3oGlWCr96D0CAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAAniIG+xJ -+6rXbrH2kt40GE58fFzrIlzhG4VzncNnpFitvPEMzN0kMa5LBX5/zSYiMawQBQ7C0 -+FpCjz+n82VVW8iabCNoqUUNwOP7ZYmsoraHT9klSak/mLfAXOyOG3DUV9jntivnl -+HUIiDO7Pf6GnVVROio9psQEVOX1+W1uq9Vs79+F5GI/s0QR9dG0qXvdJ0h5UdVee -+8LVXQOi3cQKyBOwECwt0HA0pJwwcD6w9e8Y2NYTeOTamWGQVEV3NlcvtdSVuDJ8y -+lTke2YbEKyHdcsQ1vrDHtdyfEmJcgO5c9EL5ptYJB7Yv1QiwWJOhLdT13IBYvOtO -+ebOF6zAD73Bpkw== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/kdc.pem b/src/tests/dejagnu/pkinit-certs/kdc.pem -index 8820ad447..4eb811deb 100644 ---- a/src/tests/dejagnu/pkinit-certs/kdc.pem -+++ b/src/tests/dejagnu/pkinit-certs/kdc.pem -@@ -3,27 +3,27 @@ MIIE4TCCA8mgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx - FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG - A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz - dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSTELMAkG -+b3RoZXJ3aXNlMB4XDTE3MDgyNTE4MzIxMFoXDTI4MDgwNzE4MzIxMFowSTELMAkG - A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF - U1QuQ09NMQwwCgYDVQQDDANLREMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK --AoIBAQDTlr1w8rm2fyn/EGHT0kZP67KIM6ktK8nDRCaf+qz6U0uNFMRmnuTMix35 --jZdpknr0aB0qoW+3H0+p/ZEdpG9xwdKoYYXnB3suLBsHfpu1jIQUIFbWGolpLhEA --wu/0lpEWM5mF/CeNb60LpV1Nv9qTkAphuDSj7DaPr3CqE9kh5eqq95X5VGiBtMA7 --uGxa1rM5MXLkpFO0klw39sU00yfEH7TulkGN4NPnQIW42RSsUTuboqcVEXs+RHpl --bEXvOr1xCC5GvObYlUuJmgp95dxVjKnAR0RTWvv6LE29Cfzpr73UN2877HBuyg0b --TG0VJ6Vgpa+UfgGxlbyqHI+SNfhtAgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUa8DJ --DnzKDd6H46LUloytHNu32GIwgdQGA1UdIwSBzDCByYAUa8DJDnzKDd6H46LUloyt --HNu32GKhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl -+AoIBAQC/BxU//lImv03EhSCSXe2e2RbzDmC4RJAsqkYVtYIA6dMayAKIf38sauKi -+HUvH+wLq39/ZM8kvTbQw9rJysH6C2mabpyFzSwro65a6nYSrGXbZfGmC5oyIUy7u -+K6zeVmSEUFC25C4rqnOmRTozmcZEdDZAvwsn0EyTuWtk2jK8Hi7MJmNJOSpQKHr6 -+bIfiz17CwuurKoGLlgw/HNWfRpSPHVtmm0T7fllCrJBIB6mCawpI7zyGYEu1AwM6 -+VDgl6KQw6/6kPXZwGM7ffK/6Qsettf9keCbbWW3bF0A20Gh4VevYiagAqmQdJS8i -+jimuGNlOc8t/vreqXd6BpVgq/eg9AgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUrxLg -+V1TSrSKJgpC3MabCqfQIPaswgdQGA1UdIwSBzDCByYAUrxLgV1TSrSKJgpC3MabC -+qfQIPauhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl - dHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwg - SW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5p - dCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZYIBATALBgNVHQ8E - BAMCA+gwDAYDVR0TAQH/BAIwADBIBgNVHREEQTA/oD0GBisGAQUCAqAzMDGgDRsL - S1JCVEVTVC5DT02hIDAeoAMCAQGhFzAVGwZrcmJ0Z3QbC0tSQlRFU1QuQ09NMBIG --A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBABJpKRfoFxyOUp9i --Z/fWql5anJuZElgBSbEC5sL2mMcmL/1vqkiYF3uF6/Z9g4X1LX4QDuvaXCJSdQ+b --JpmhklSyFN+E/agxZtSim+AjTgYJ0y+jwNvX6kZQ8fW3VLNJZ+zbb4n4txfgSROn --7ub+02mo4DYajyD9TE/qLzmVaiKLEKW0osjxX3fB1RN/d7zm//NDPsezzUzmKkgz --u0ML7HGYUNY3+/SC4ShF/But1IoY3/I46lB6BMrIn9X6fsVKlipqrRFniUk0qDlJ --fbKVB+MvGEFoqFNlMoGiufmDjnJl4PQZCVEmXO8wAVGeK8NpTBCjltAAsoVJVnjq --AC5jSAM= -+A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBAFMX7ZTpNPdzFwkE -+hrab7fSDeoG+mN0yorY8e5Evx6sE7pXOtHgHIjQY2Ys0lk2mhbsIKptL/R6jTxWR -+rbmU6jFNFeJgn5ba3NWdhlUiZ8WKe2knp6uc9ZDIK007XaKA4rRoHlJ3vHXoF+ga -+JFOYwRzCtAlmsOCQ0UetoC3Ju6Y6NhCXIE8f81dsh6RMADoQT0n/fcLY/JtbbLXK -+ANTIWHm0oSX9wvOU/yZkYGuwcPd91cc6Mea8f3J8D/OiatMZXc3719extmeR6Cv6 -+aba31kv9wtbxVuxkR7HhjlJhzhqfzfIp3tNREaIxPb/qKGWBOjwxGRqSUkdEqMvD -+GjaSlyc= - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh -index 0f07709b0..f77ac5813 100755 ---- a/src/tests/dejagnu/pkinit-certs/make-certs.sh -+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh -@@ -164,5 +164,14 @@ SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn3_client \ - openssl pkcs12 -export -in user-upn3.pem -inkey privkey.pem \ - -out user-upn3.p12 -passout pass: - -+# Generate a client certificate and PKCS#12 bundle with no PKINIT extensions. -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out generic.csr -+SUBJECT=user openssl x509 -set_serial 7 -days $DAYS -req -CA ca.pem \ -+ -CAkey privkey.pem -out generic.pem -in generic.csr -+openssl pkcs12 -export -in generic.pem -inkey privkey.pem -out generic.p12 \ -+ -passout pass: -+ - # Clean up. - rm -f openssl.cnf kdc.csr user.csr user-upn.csr user-upn2.csr user-upn3.csr -+rm -f generic.csr -diff --git a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -index 837fd0b01..ee35e5cdc 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -@@ -1,30 +1,30 @@ - -----BEGIN RSA PRIVATE KEY----- - Proc-Type: 4,ENCRYPTED --DEK-Info: DES-EDE3-CBC,19FEC334A4D4391D -+DEK-Info: DES-EDE3-CBC,7DF54DB740F92845 - --S6pSicLj30Jlnu2OnYM0eXCvwAHR3xMhhl2N0gheWUGkjicqTdW6ft1qCmGBre9b --/aTSF1ajvFC+YQ/iABznWNmRNZKCzTK1dQ6P73p83uNqWt/cfe+pVYdeHw3u8NKA --fscciBtxnHNaAs16GX5/j1XXRPb+zmUe18A+VFMRgctbaurk+KbxO8qVUkzt9NNa --v5zHkXnaJf6ixL6zR3cOCJWPGy4GmGeFIytQos5Jgn23Pjn8BHAXf39GMs2n6g5V --eE5RAGDeXqPv/tO1kN0/RSKDeIPvKW6REklXraRUle0PNN5g5l3umSkg4fkplusp --nTsQCRWkqyVcMpxcf0wy7F2ZPOYIWDt1/pzAHC7y/fl0uCQPz0Qd1smwt0ABKcZv --m9zaMq6lkKYnBOxPiYIlWVlQi3RLDiQyAWQz/nF0SKsE88SUlB83quySJsZsLKzk --MR/C+ccSiHqMiDKVj5Ts1go+gbj8Vhlto8jH6ynQj6lrOIczyMmgUa0v0dFH3i3/ --WL/8ydJ0otY67A8w5yH3hMzRChXQZlpTmH2dDhAv6EzKBi8eIiB0Em+laz5lDv6C --SfNxZa1/+bSAvXr7LwllUu+Gzbu7MNLwfB2ieTqdFQGA659DjnMqyBGLFzni4Ir0 --Hi6Uh6yQubTm07oqyUHAsChGFE4Efh4O0rCbKKPZuSVfimUZcE6JM9IjRC/0DIwr --LZSYqsFgn44byrc62qV2JAE2ua+/4aHHI28hIZ3MDLwyYpCQL/FAUZtqZvni+zgw --yoHLRDbdrqPps6P71T6Pw6OQzAYC7AL/FsZnLJK78nI+Yai0dpyv/QWiFSXoDEVN --6vQoDv/VZbNIctr31OE4XyjIMiTpn3FPa3VSbKM4/h7SthjwEV2ONNfR8XQF+siz --3NhOjEFrZ6UGHvT06wo/hp4CM7u580fNu5HvyCyIwkx9CZRLHvG6Vu0emlzDfQhE --qxQs6L7IM8A46/LPSTtmEA8Rrn51YY9NChMdY6j3rLe4NLxxOCE6JYaGWVWBBawK --k3y9z6L9gWRwxEfCgWIutDrYtmA2aj6y/vRS6LrotCNeN5qBx+TdRnh6uCqbi1T8 --4rF20TVhNZ/l+pkH/ehY9OJ/zpwdbTq4FlE0wWQZB/vwbYP5CZKF+rU6IXnCZEjt --Ak6Bka9mFm9Z/TvnKIRYiXELq32zOJAuEOQ576tkDX2rAuIQAfE9biX2qo0gbsJo --1RIfXekRurD/HX54blv5mNqUV34gl+ngPpV5nNDy7RuTAdP77Mu7/ynaPfnM7nqu --rECbZVv1HZSgTi+7G9SUjn4Bg36p4NiF0/dZ2W70byYIQvNPNqU1kyeSrZk/43te --NwFgpoAKVbMD1rZ+0xM2YCFFKQZZMN1a5tn8/1TWPlPU28Tu3ZliGeWMdeKd4/MP --vfH1pE58qVcyOngjLqGkk0L5A7WOAgu+vibKrxGxywwVLx/GfDFqnNr6H0buwXrk --vuKBTo0r3pcbaZt3kaYBm0d3zznQI1O/pX+eGiNr/rI86j4KC+jUSoKi4BdUeuDN --p1x6qyEK37kgVXiUyiEXO7e1arLBZMfFRTNKVsN5ewL441eCIgs5gA== -+3I3F5dJkYmjX49YRQub+AzWPOJock699vQZV3oxcAabcZWtLVbQ75QBXXBPEtm3j -+LAqb3gRxfETHNHsSIEwGtN3rYre1UdKs3Bu9ROQNTvlbCwRdss3JA1kGhJu2o5bu -+hf5sjpfR+ivf2prJ4whfhb4+efCHE0Ll669V33D2kbPKX0VCokkRmxsIoVtHd2qu -+d1HM/EkjxrOy/GHZ+93mkSeWC4hz56VL5ApGOV4wHuphdvKy121mU0mjtQRKF2El -+N7DtM9/AIAkLPx5wxrTJXuELd+BBDPbRMwmvgqCX1m8sJLJT2fBzVKRKWexowp7T -+d3j9hT+kMiWCTgd4vJ+i/KPkK460Cy9PzFrzCtWut4jh6rZ+F9Tdp1g4Np0ygWAg -+q9tV4RC7ylW0DeseRTXTLuohngfu0h7mXuhutr1Xmq+SoRuhBllZyexV4jJMc1kZ -+2nv9RJ+h7mCAQbLSVvWCZpngfK2IcZhi4hfNiiQ/wqc6rE3eaBIR9E60kaCeBpWB -+rxZm4VHOrwJw0GsaCRLQez1F65Ulk4TA+7TYJWnW/MGrvBptuBamwxk28Ts6eOee -+RVwb/AdY4QBVJKKT+/e3Lfy409evmdTAA2N+tbYzALC1cH4ex4sO0BifaLmKo3t1 -+fC2FLna4P9F17bbjcS1lSWVJKodofUEt4H03X7LaMhwe+sLRuKBIoTH2nLPHLIYg -+B8NO1yFiJPFL0a8fi9kG8JJlCPkASQC5vcYg6BE40b7h7T4qw0HmkuH3i6TX6bsG -+nQlryJ2BfQM+IT3MTEh/T1iHPZcTwFLPF9HMnZ/ydL/nM2kElF6YfMClFvuDGULQ -+zmsvG4D/ndSisapJQeoevAwtCHybh8/3cy8CoAjBE9C1JlHOvP2+64rzvFVUAKfa -+z5aZQQJKcdXcKcM8u8PgEyCN5x5tBqWQjSHR904k25KRkePAh8SoiSDuNQPwtzbB -+RHesvkaSXuUaN7q1+oJzeQvzO8i79ud0Diu5y2KePrlB4HBSWCuWmvz9U+WvGBiw -+KpEUAp/YpkqB1as4IUBDNjV1Y77cyUZ+/8EkPgAvB9wltCCAyQ5xi1h70cDJdabj -+swabRD5JV1JLalFMDrOeOPZh1heaTNHXV8f7m8rMVeYVzVTM1JoQLlvKxcc3LVfN -+9RLn/vTN7Ox//+385UiozC/PAo/Cep6Z1Wz+cwsd62HH0LVimVt2mrmHRKY983cw -+U6cZyhvcTB5UOdJdhwbHfnxQipWRu//XRYY/yVdB6W2J4Gzh//adJfKOmHd8+cB+ -+y8Q1yZP3diTGkhyY9pkXS7Gv2Q9mcXlMJtoyb7rqBIL/osVTKdsZn7Cj6ZYB6ftF -++hKQKNs/bKXYs3PF09UOInfUf57pENSr1AQBQceAisAsr8znRYsFlpqZ5L8G6um7 -+XBneZ1RBj41wheB8g3kL6hj2UrXrE2rxDAw175a3BaxP/Wc2JgGcBWyJTVcZ35Ab -+f24UNlrfcJdgEFETEiy12WY2VaqJCSY3J6YSimHDbffX+ku8QgU1shZf9z8K1l1A -+OJQzbjlxPZT/k4cfw/Xi0rHdgWGcmL7tKLkTcrG/AixdEoI9KCSlQGSksI8CfFmj - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/privkey.pem b/src/tests/dejagnu/pkinit-certs/privkey.pem -index 7e9beb09a..548e5a8d5 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey.pem -@@ -1,27 +1,27 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEowIBAAKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTE --Zp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW --1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV --+VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6Kn --FRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91Ddv --O+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABAoIBAH28SS0ygFvLq4gw --EwJOJYxeswQvNuxp5gcMm6tbyqkjEHVxDtkwuSQ304M1ufF5o2lT6Wko7/sxNyT8 --Utz7l2JRXL7E3U6R6ohgm1tTyHIVY3OWWCP5Nwjy4BXEwdVmGCfKWAP/+P0ajQmr --pguK4/fmk9TIIzf6Kd4u0lOvYcu7AYfaBj9OSSF08IoE1EA9gY3Mh9k8C3d3JDhG --hoJKwMAIX0PRyx6cvmpuAJyPf+19K0/SmzpbdNOHfIXZKtfYw3HxmebhhyCxqNsY --opI2fpn8joasvfcXICBFRHreSu4nKc8ky6FkMIc5KZRiSP//N3oFM7ZLxciMjfgl --bCYqST0CgYEA7xfrB4atDYApsmLk92uHnC2bOmJhncfAuLHh8M35fk09Jt6CMYPx --Ydp4cKYzMemO5zzHxdMnlmISIWWtNbm/gR74KZwOmhFFEP2LE09hpAXRBfQvN5af --RZwMZ9uyJU5ByecXbIt0cuNerl8sKJfG1S+/maD3dZvr78K4Jd6StTcCgYEA4ozu --okBTEZ9h7lxdBBbZcO8i/eikPeKnCEBaSryf3K3Pr/k8Ssaa7MYOT9yD+iRwU/uV --n13BA1I9PvdcWl6ewZdOYX4jCVCIsLs7ed4wfwLxGQMZIVHPZ59lRmVsZFO08g0D --27U/rUZBpMHl+ppq/FfBjyyUSqayKjcBoFXx0XsCgYAOzQM+pwaldE6gfWDBNEXj --1Crs1VRHqSr0BAcBmi6cs/laI6IZoJpbvWOBTbiTmWrAQ9H2HBkyRQXsTVgIoGQL --gThJkyCQRwtoftmSK3LW7Yk//hrCLS/U5lEaSM5hYtPNxOF9VbCywAKHdtrL9IFZ --hygsQXuwKyPS5tHxfjLExwKBgQC1D+Hg9vvtB67jLBqDHCfopJcYywgJFc5dP+Fp --/dreKmPkxpMzSAul1Jy3owwvrVPBKz9nwSxzlRSx8Ex1RU4odt8D+CXUWfMFHH7q --ZXPo7tb2II3DHXlf3fq5CnJYtLXXBiPhQriDqbTpErbVVPjQeOqPnRdfml6mcpPw --KwA7ZQKBgFzqLmWqy7ZnZdbBo4CUUt6B12eaPCW6YNpOd53zHOphaiZLq4rEhpiZ --S6JYQTEQYugr0yd6vxsVL2An58niRg1sM6gca9QqBlGMzaQoXaPx6OrLW2WoS5+I --MmVTeh7yvdop+6gvR8Eoh4cI0HoiJw8oQOOneiXVnh7Izk+WjKXb -+MIIEpAIBAAKCAQEAvwcVP/5SJr9NxIUgkl3tntkW8w5guESQLKpGFbWCAOnTGsgC -+iH9/LGrioh1Lx/sC6t/f2TPJL020MPaycrB+gtpmm6chc0sK6OuWup2Eqxl22Xxp -+guaMiFMu7ius3lZkhFBQtuQuK6pzpkU6M5nGRHQ2QL8LJ9BMk7lrZNoyvB4uzCZj -+STkqUCh6+myH4s9ewsLrqyqBi5YMPxzVn0aUjx1bZptE+35ZQqyQSAepgmsKSO88 -+hmBLtQMDOlQ4JeikMOv+pD12cBjO33yv+kLHrbX/ZHgm21lt2xdANtBoeFXr2Imo -+AKpkHSUvIo4prhjZTnPLf763ql3egaVYKv3oPQIDAQABAoIBAEe7ACa8d9qm4SvX -+FYkAjjakq/JuxrDKxhyPf6utMXjoVGXtDs50matzI1DekVMxlUHe+O5VfMkvc2cj -+a5SXY5n9KqRuGKhzWFBoDnxao7Of5zn5dqE5szGJksjKS6pdZHcutXBHtHKfGbgo -+rJctuf6AaNLdKfI0TFz4NjRznrN2NyFQGhXzPpq34Qm3Rg91hVlU3A8FYjE7ez6b -+vlJBsbKqnvzxEQMWTk0z0bWC79zE1ElH3Hpwfwb2cG7H4EXf0j6N5k2zODg7C45I -+xWtlES+OpZqdDH6mKFBQojU375j6rb2plZGkTA+qxX9GvG7GsF5aOM6Wkge7SUeT -+NUY2lB0CgYEA83u0TtxCMye1p+ykZwQdcEKR+l4aSjNsM2V2s8Zy4eZseR7f5fgZ -+71ggIpzK9pjT55OiYJOwsEkZAPB0gBgiEcqJgow52w3Hg8sUU5LBEahUpx3Qm64W -+64WNIOL9oVXYQu1S/yJ3iWPMQcH1xIlDtPPC1LH+yHyEOnGe4szIeccCgYEAyNkN -+K2JEbbfK7Wsh3/MOtx5KCkzJzFClTSQZ55IxRUf+myauljKt+kI99jYV6eoicAJv -+SMHQeYurLtSkhuyptAHUqo5xgH0HZ7cE7LV1nfam2p588Yg21nIId9XLDPK4AvCx -+Phz1oznaiGMu4jB7esozuW4FKxB1kRmUikM8bdsCgYEA23jMRLFhsr6+jclPP9SD -+vKck8mtUg0Hq7EEvSEk/UMTlTiA4bhC/P/FNtiVjBfkoOXvoR+mYwK6DLUeRm80l -+GKhaXySLGhtHllK91b9Y7NOwypqjaVD5M/9EATraqEy7DUjjITsuSNd+TF/LawbX -+0wpOum5fXNRwVEYKlCFHLA0CgYApr3LeSDzvkK/batrTAj1RoEW5sYpIj4xfYFjI -+CT2UpYagaPzfS5F0WX9GtJ8Dt4aCPN8f+KnuMCDNTXEAV+o45BBhfcLs6gY5bnDl -+OBw7NtAWm8JO1viatXwwcvz7qPysD4yZ2aTZxc4ndH5sj6dxKrpliAIml/nuraJ4 -+t8+49QKBgQCxJ7ZDlM9J0quVivSui5aoZ7iLEiu6GSZ5yF1HSNXY69OnqQK3UxMl -+aERCn/cKqtquJQK3v1IE6k6uAaoM7PXDVKqKSH0Z1Jpqciqjg+J/i7Vym6oCdjer -+6zt6P7Q13f9X9uUlZBnNrT9jk5WjR9pSpxAc0vU78VKa0lZMZ3bROg== - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-enc.p12 b/src/tests/dejagnu/pkinit-certs/user-enc.p12 -index 049602939def4be1fa9164649b39a801f417e74e..b2648ceaa04be6a560966a414a7bbc8ac022c20e 100644 -GIT binary patch -delta 2706 -zcmV;D3T^e37L^u|U4IAu_0R=Q$07m(2mpYB1u!tho?ixcuO0j=`>lGTs)`UgGm<_) -zpKPe)yNdVeYJWc`4 -zF|P^R?oh5stR*_(MT+TZR4{&W9qoqi)f&pBxOiQbYZZ1lmQ#Pc4q?TD!0ns{qlu}U -zz(Odv2K+dfougnpE_VouJ0!M7bt6;%w@&*9{%SfiDrvUdRZW6CSckeD^E--2MzmZD -zliS3w_y8kT@PFwptW_3@*xAKJ7u%{U_HfDf9jg*K{X<$ZK~Z=^`bq{K)M1SMGVQ^? -zv#j3vs0HG{g~oN&R6FPVPVchC^z{P@wq`t};KFoH0iPJC$e?G@1S`jv>DCV8RB0 -zmIsXlD|}<)cCDUm$lZ#mt_Z{Bv{YU=x+YDXTvPmRZqmcS#sZMLcxp_X>UsXy*q9%5!2Sahq`0+O!z?}T -zi$jc*@c*4b82s)hz9gxO-sN=XmM&gwlz*+BOwds}(8bcfnOwG9>c4M41I>BdyIE6( -zXbn>T;bsx#*{293>WqA>Y^T8DHfefzJaoF~ZIQJHExS&`Tva3s7=r%MBNe?|IHadr -z3;)tG~fkk%kK$~?KlYIw23fnj%9teHJ@ZW*2W?&0_g?~!F -zv4KH{ocV+%s=kSCbfuiTU@S3?HSk;9`=V>fXAVPQ5yJ-A3VGtMn$hyJjBL>)Xat*f -zk>LDwCgwH<7MZbk%enw@_RMCIr@ki6QHeb;WK_J`RwaC8Mfd`O!Ox)RKq~fUu_iU>d?3o -z{a5i;hDvlYB>6O@o?_&bd+Lyi(>Q~@du=M6Hgdv6`ogLgF)jrfhJv2PHS&O?EAOq?#SMnKNcb&pBwlq5g^OegV?n;MEw^ee; -zNAm2zd3N1vCWnEDkE2q@f3WB!pgs=2pUxlBhb1$h(bH{Eh$P!rF3CGZuuACYydDn`l00e>r$h%Gmj<@&l(&Xw}Eidkz -zz@_D66&yL_Rt&B;1I)=kuf6ANgrS(5a+rcm&O0Um(1W@-qtpcTe1y@SR`1y2+!Bjk -zQw=o(lgh9Kq4o>zszLR*B2s9LY?-=8`IIV7);U#dMhstBw7oiDXdQhCe+i9pk0cnV -zMlgF0u95BdPI`jmlfO~!!}altl{kMJXBOyAE&JL=v<&Va3rMzRzEl_6c~VY?np>Zo -zc?iAu&Mt}Dt}KDnI_!(wF&W;btDeR~!+4GFOI$qsL2rSj&Nf1Z`%l4{qYJ4Qo$_}# -zJwxm6gK(!^XH`H3GDvYMf6ZXiHexfG^(D-Fhn88u;X368WggB2*>Np*Ni+Go9sUe9 -z{=o5{uwK>`NVcYMf4tOHNIsnqr!Hx^gA~eWZks4J^1j{2p{HG?g@>qFF8lS7+k^J`&{T!%j#_zl8OmX0^a|L_Hb^Bf&;C%^ -zDRf4UJIncVpMKi6e_ptRh8&L~a0c+OZyUh4xk_H*ZiVT9oPj~^=?cH{ -zvVq3YVa|#w$>d?3-K=B$mSiz|5L=0aU%z0r5=NXvy%;*bv}`8zSe%or`$-|90;plD -zBMc35ZSO>Cs2V+WJaJ0#L+Y2{w9jWYmI~V$Xh0U}91I|Pf1})&1-$>cf4IK3avbmhiO_QH -zUzb|*rY0bBQH(2Dz0^m5V`6s!4}lu+2Z4sL!Z;_w`zlgnxe2p>);eKXeRgPbE8hM) -zh`oOs<_8p$e;6ws?`vcLw-*IKpOB*Ser86?AiRqkbxtkcVjVI7;D@#G#Zz{htm%|t -z{IL@z9azcPs?vP_JN_heR0Dg%Z|rV#jIu&Cz<+D|zX&(+Uz{)Hp2UasosM?7e~B}} -z@Uc>9Lbj7eqH5pI{>XB6W3)`4gbWgDP6bb^t$0U;e~hQjWsuc=W%5osyn#COy+0Wn -zfXyb`UV#nIfFOyKcTxpXT4y|ytF%_1G!x9h^LdFL>`qCd-xJuFe=Cka?oHZzMvv?F -z4Tv$#KpEY*>=SF~eJrHN-&}^_T`nbeQ#*zvBRah$g$#AJtiay_Dr(%Vf`f5yT3Wx4 -zPw9EGe{U+zCREP#EnqfSUY`b6mlSFbnd$rpIUC2?Bx* -z&*ahaHlnLZq_)8PFZU&7S##TPwtTI){S}rL@XarlH4%tMe*>vZ$pfl61)r>6REt#6 -zA1Tmhn;*&xXn8IimR;1v;fwKcbLt}hCu@0Ke_$`LZOuZ5IpYkzdoDeo7LH_jdX(6n -zI8<+LlcXr9=#AM@2Sx-NbWd|hrC&4HEsn(_cD0F-dOu17hU<54gBG6YK=4`U_l4`A -zqM(8cTN||R5H++bkzne?q5MIh^^GwlFe3&DDuzgg_YDCF6)_eB6ccK}Vdj_r1JjB8 -zJcW?bd-abN6XY;4Fd;Ar1_dh)0|FWa00b00NU*E?J0(4Y+o=|f0;Fia+%K{O2)&NJ -M-JAb8(*gnr07yzcC;$Ke - -delta 2706 -zcmV;D3T^e37L^u|U4QCIImcZ#q51*>2mpYB1u)u~5}22I=HT-d(%(f9DXV18Kbvj` -z^Vtj&rJIy-KS(<%B=99oy)c{aYIfUfQ83DHHOZ|j5N)Uw`u|wFUxcIoSdpz_?)9%H -z4jelm#2iJczX|~|@JmP%-E7N|LSD%0aE|sR%YoM&yhB@K41Yz9lq-Pj*c;G_qu!n* -ztG256pZmHRbI1aKr&uCUv>WoW;LeiC%96yY!X+o@FzzAxrOHu)3g?VLl=`oYO=8u* -zFUXhf-E-pg$i=j~J5AnH&n@YvQR-2plWV!|u18vsOGavYQq$5K0c{Y)cD=>F@sB1~ -z#Ce~xs1%rGd4G(-!z|O%#O_xY2j{voND30(DGP7NkMXu3u$QVLc=J6%CHpuQKR%i~VGy#97gZKGgC -zQ)7)_hvF$URord*Z(4C$&;M+0oSafecrT1A>TOAXhJPO!S1Yy!|0t8mhQxU9F8H0X -z{bS7WoDJL|;>UbB#Q8kT45pQxG--}vOh}`IjL4HRI%JT7=!MOS_w{ZYQc1Wgh<|oe -z$UCUD%v2lcu!NkaS+WPMqtPJpP30!cLsAAZhJP@(6PFg+r~_<zPu>L)gER|-RptQ7t2T%-w$coS%U?y2ty)u$&%U58*x^dW7 -z`SK*%R6K^ppp&Wo_dd9jlUx<%Ga!U2uD9oPe){W-$sAC0PPA!QYj{>3|COVWx@pS^ -zdR%$)XWB=Qo{$wdCUX>$?lfD!Jxy3?UC2xmiGLhV`RaM#xn>#Hl~j;aRu7ujxtJdV -z5)OCd6$2Sv{U)1)H|`*tznwIA_Lu0xM(g7cYqXUD@0)zWD;@cM$iz>33hI&n$WKkI -z?VwZyL273la`IMNy;tYMRF(sMS(#LpN^yUMz!Pw$N2vcnTC~i=mtZwXPXpou2Y*IPGGimihPbppn_& -zRXBY89ppNtTpqy$L5I&2jYQ23<2e0@(|?7`1y3bhH4C9A`JcTJ -zs*Mq{z>yus8k4sR)=<1ex`9V?dYzvH0P5C26D4493!(r1*M9|H -zKGdn}RlVi8Q0R29 -z1>lc3?jlMQ$F%QZs$yVaL}+TuF@LQ*|2oQf6gad;5|UIfZNwdOVy>MTwDGXK0pZYq -z^=+s6V0xCsmO-;{zxI2J?FM61!lojJcLxx`>wst*?}YyyRfPPHWL&x?0k-< -z*`9-8I`q-`7+Q?mYB$<2tLTxDr(QAj_V@HuB~m*PuA2~|AbRG>SaP0yE=us-t=HQY -zg~<|Cdt7j{a8>OwxZuklbr=dfAs{AYygi_jsgM*00e>r$Ow~3k+rOeO>(s`grF?$ -zJG{bdqli57x@xMkpB3?9W>*jR4I((MPl$BvNhVhbw?_vgtkh{C4|j=)L!maakLdv;I? -zQAlp`ykIYDUK>4ac3hrzJuJgy{liWNPtKgmw!Von2J@L_?kwdzL -z*LC)1U0nZwV%P}Nl}uhfIo5hPM76mjv_P&mM&vHgsjqj|mewKje*}5b!(zjO+??#p -z^+fSxFa#sKMfh^V7pW(Q%@sfS$_a6jt%35LjT(p^IHot23x3e7QBt|q8Bx!}hMy)p -zjHIkywUCO1=vwR+a-j{-_L(+dG~7>h(22dhbKe&sw5W6hB_qBi~5%rNy$JlVt9!<+)%x(%&o+O+@b0ergOVP5w6uAeaVE|mzfALIEdE(~%cEj*Nx1l?I)xNe5I~CB-XG7RdT=};;vL@W}qgN1X%CMMTb@z`j(^Hxg -z2+k}O+$v2Ie|Z5?WpteEE^-jk3x*2kq -z{l#-|^i)J+)WGL>*FSJ+u}4ad5!NiRTj*bBOEz4N1ylP -z>^0wkW58HZsCHK&O*4YkvSMBQ2tO%OVIE`(y0uWHS!>4~{B#t&21e9&djORBw&Q`g -z2)Kc2)NTqH_|x#q1O6HWS5W|}5BOBUZ%Vo9Qw5NOKV&)yHS`wX9$DV8 -zZ6V?M9adFv7f3LmPCzozft%9ptIIDEtwklxf0b0u(0L&L4qp#ge@p=B*bmxjw(;PV -z;Cshn-XXPKyoA+FG;h}OQpsj+-)bhjhBs`0k|`c7DQ>1~Bt@|RjJJtP6KC(6#0L4m -zt*tS%Rdoj>M3SepE)k;MCOV%w_xv#>Fe3&DDuzgg_YDCF6)_eB6muCT6bLmUm2E6$ -zJled0QvX3lDc~?MFd;Ar1_dh)0|FWa00b0Mw6Ml6`rPp>w1kFoo;UO4PXV|D2xTCM -Meh!`itO5cE0QPz^F#rGn - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn.p12 b/src/tests/dejagnu/pkinit-certs/user-upn.p12 -index 7a184f651e50d1443e5fe907b5a11455d69bc0d1..6daa5b378b83e9d4134ae48f8d1ebef715bf6cf5 100644 -GIT binary patch -delta 2698 -zcmV;53U&337L68=U4J7*Cd0h`aFqfA2mpYB1t^AZ29wx*eOgc}d`r>Q7K3iXfn7bI -z-h75b<#ho7#K*k@hvV0DY72cD-+GQbBx+_M+%n71zn -z#X29cB(NtFLejt8_}`1}u<)0Fa|N#PFrop1;9l4e3fW%nAm0812NzC2PWtG5Q-Le3SkbJQ8%$`CRQF5lvDMt^VA%Nf7 -z%gqA3e;};~*2a*2L2#V&7p#=9h0m8OkwZeltqP35E+5dzCHJJcdi2I@dxk4_kjEOT -zj0U8U0++mnH-9@Zh;5`5me2`GT}33BIrtwbrAtxQU_u1LtK|{6gpV~{xkE5ejT2ih -zN^~x-hZKe}PsA-74%;xY -z%1B^HDt0=soP3^{EKJ)&_b-pfV8cwL_(1dml;Sji;(r9YP~QfvMIR=;$|FM4HE^b6 -zOll6EI_7z*5>D_vgiic>K%ddTL?+VkF!(XYy-glao-W+_2?bN*!b-%g+(*LW1WU#4Df_kOw0G_-qaOq{v+SRpmK1m*tb3kPzLIGjVa^ -z2hUFOzaEpi%o&g2^lIMNwb&tG?#XFJz%l4U56fY`oz^klt?AK -zuXwGHf}vN7zq;z1mdw(fafua(ZnorQ`;=s@1b^+)-r`oP1|(c=7dWrTM*Y3X!S+-s -z6yvzsNy6{reSb#uzqXA*j?J{*SW(elo9x=4Tgvmk7340ZG;`lvBR3tL))izIU+caHn$AdqnrQly -ze+yjHVauRy-|J4u6<7{TTLNDLr4%Jx7=JHGUoO1>1Jcfv{I7f>&cx$XLd+C6{T;$@ -z!JSbO;_3Sm(&oAtwAZTwA;V25RbO9psZt* -zln}2yx+-4*YnuuI!9EkI82olCom|r^m3LOkVwF_AlZNQc;2PpCjjVZX)YexUPnw2 -z_$_(XXS$6%xZjS13_#*rgWL;?J<7vhZ&suuk^}1zTKrxKS~8Q14u?oGg}H -zlv+EHsJHLYhdzk>*1*x?GypZ%k$)pPwmu21v!s;VGk^k+YzPtgAL>R8DmBl>#+JNk -z9u*4ll2JG9`v}C4*CP{?T!#_a+ScwglwY1hLX}2-)3S}nNh}9HZ+}fv%zwfwr^~k! -z=rp+UoO0)meUalXvhV<156HPdXB0C2j3K;I>+=s(Buy-477MAi_(gcw~VJ;|J3AUk`);%Zg&6=cfM%r$Q?RW!0hdBllOO0 -zTK$e}^K!@?la&QVe>VvCGU(Vo?g9b`00e>r$fO@bT)QV0_0B1+RtRaRQU!+^G+F8ByUATuiqPku)}3=nLROGQxsSbkkY- -zasCODE@NO&{NkW~>X(G9%rXzSV@mm{^~LPTEK*0Wm{&=#e~+kA6Ku&p0j~W>F>f{_ -zePAde#=SNS#X0&z^HzqJYAyDwxNt&TfKJc%3yAgfrUZA4_&$b8o8XaNZw=|8qY -zljvN6gHeh`L6q!)aIAW3M| -zku8zILVI$GTwtMdU?^96# -zg~=M+e>pl9)d2Z?X8#?o-z0==7jEP#m#A>bdA2062BlD8Lkw*A-P*PsR8T~|$qx;D -zg^_hvYQOo650pOQ9dBiuA#&WAk;Ae&G*Kp;Mz#)6aM7P|YSDn6RK -z2FMmd^WV`rg9qo0*gPnx{M#w}w_jIXLt?Htq?997K%)maV%KC#Lbt!#l8-tKoQ$GB -zXiH8|epkkQXRPYNxML#!2-7pL2YG28Kjpo|2b}kK?f)J1gPw({=3$W^com8c3Ye7dJ}RHz -z*vvJzwpsR6M44c_{jk~~Myb{^rc(sqe>x=O*QBRH4UGQB?z&_Bm@zH!#+>l)4pTGr -z&x}!IZ*t34iEdy8K1?hC686S+fvw2MM4b6|ovWo{VfySc*qk^hH|y;Ox->fB-fZW3 -z9P`l12ah8*RP-+LVYybf -z<$s@pM^MUhoQy-XmtfWe_GYFerm2qLg%H>?7HBLGv~=PBmQW8Ay#|QIkK#;jO;$81 -z;Ec&>RSgW` -zXj?}J-UUPY8f7(HIC6UZGfOfO72c@ABwq8tiZ0?s3(7$ -zxM}RzJuAa0`@+dpgSHC=ye;ze6=fI5jLQm5(4O@ywKR%B(SKp;94zpF34Epw$elea -z9!~P+oiqK>Q_>yAd4Fbui&Gbz+?SuIr3+{gn2}D)4zKA -zw6q+|xyzFg{C~CJXs@2^$asn4KAS;Hr!s53%;M>!4_lI!j -zE@siDP@6({Y?SkW5h+LdIH$!`_-XqxelFC+82Tg$EY9PMt$UIeu5 -zj=iT7iUSA-e*52|0Dc!;kRC(OF6vpH^HL(#b3Wr8xr5SNtP6{wfsN>aHEory -zZz-!@F_mMHzsyrd5SFu-?*f)-4@0fWC;9#&dw*SQ32o63t5Zm+f1C1bL*s$N7grel -z=O+Y!#o8f?VAUB9+;Hl3)PR91eu?p_GHL`ZzV(YKX%{M`k(!63Bb|Ob1gX^X;@_0swMf$S~y?O52J5Ow2Ei5EeZ0liT|CpLX3dRe|Y?h-)%* -z1Ahy_Q}w75-Y#V2+pavIB(a*V$3IEPg?T;;_;l~R>6v}Ls7>PH|CSU4@((!&99d`8mJ4VP6tfU(4xw}bWH@+eq;9;I?L2T^2F%;7KMe9jrkMY5 -z;~yqZdv|HCk0HHe6ELR7-?n0PnLebvx^Hl$-REUwC2Ty#$UDZRB}HY213#mttD}( -zBu{Oz+8I6(k)MzWxr$ksqyo=hI1ZhXWX&Y5JiN0mzSsk}t- -zJJ%SucVFN6AEIBj6-I!tXQhuHr>X^w6cJM(yq|zYJ;?@eY;==f{|XXanx4vhND^Z_ -zVG0NghDtq_C2zj$Dz8C#|AZkOPjw>3G!iII-&;gSHv%p#e{RGu#nP4#fobQPcfv18 -zgrG+nAHI;bL{ylamN8W@lZ^DQ(sR -zT%P@xq9c;o5?_9TBIsOs|hcX>KKPL9C6IfhyjT9og;C -zTTYklra)`+#hT@j5b!vTCMRNv-&CN403}aafd@V%?CBOpZa@yL63{b_VYz#)84%BP -zfYP3we-mmC228v;c=3=b_ySr8pLt+9&oCknyR!6tdU*&t03h4#MVDePO!=PdJKgTE -zaHJvVh#iv(yLboW+T3TYbSszMmU_pnlTuRonrN;Bt0)GPvhsgs*~x?(edh&W?F?mzlkD$J3Hfwl`moP6Hg%s+6VJf4+~1Rx+6eBhwZUl;!=3s8jgC!;aQf -zD9Z@?L2PX$Ghgizq~7d-QhTd>iMJ9kiDb%Rq~);boeQ_o6Gz>K3&BxCt+`@~nJAh% -zg!EqIPY9B0ewTqT;i1r~)!+l+G9oP%4++@@;Yo|$z -zMwTf3)yGj9S(sW_1-Kzi6+3#SgOCRWU*>*BPfO6cBnql?REk}m2!l~16V`K&3x=#~ -z05!gcR0QYhTv!?>tIt7C*)hIDp`l^Ge?{+>tH@RY7FrUffN~A>;tlE(3sD|7LUANB -zis>fX5un78BnY6sbwqF=OpLF_K}&sQ>&x9L3ga$y?=2hF63nby&Kn+_8fYj=Q%qs9^LzWtFszxdqjsR&mys<{B|EGHk9GANU8t_m0Fe?x$v -zpy|a!(Wp`ffAoA3^XaeEa(HpQ9c1?JtW^k>aa()*8q(TFBZbOowXt_)DRU3xiT^R= -z=F~RNdSDu1@)T$jO}aMmZ0Z-E9f!w814*M^g*;BUCL)C0s^{0*#IGyLz;78!^?dxg -zVlRVeg08jZ18}h9;65v{AH^?-f8aiTOIbeJluz**@tGI6G+BB)7Q~kN!AQ{g!qteM -zhqd!L(uO>k74-EEJMTAE*X9x#e!==1fh0RBMQN77*2GhWj_q=-;Wz;n_ig?}US0W` -zOuQS?@DtZzW1f~nnyoPEU4QEdRHRCfek}q52mpYB1sD{K_#Ii+3SG3sHqthXJUvY<=YDAc -z9#;0PWo-O>j);dWavz`vlnJdRTmaQEo(0cc+s7lXMT_ckx;wyC2|pOcNMhk2NQEoc -z(*6LSNK&b;J(RKHcLgS$UbyOpsCkh&(Z&4JM6@2PAel3A~|!xb3Th5gvs -z+2ZyxIT3B%aetn&kjA>&caGx0pjK-&f8Q_X>G1awp^&srIY7Je-gw)mNU&6nAKeV@ -zDUyEhZo?kDw^KqVPWeWk-%0aRE+Wjuc3X9h@7jFk@Bt8^KtvL9oxdA)#3I|;*|BOo -z->lHL_8Whhtz?3eZXiK#wkl>sh(V2h>Rg}a(k;J|xPRt2O2Tj<96swuA_=jT#@8zR -zTsY*e-_N+_<&h_dPb%s`G69d~tdf<}E{REDc=M2s^y7fW{0hfw^3IhGV>@v#&Kq3} -zhwf5UAn^i(2RW!~epxan!iiQi1q9E*i^;IyPET${O0wgRN(&2aaM8OE5y7A05(S7? -zsYqm-b$@CJke2fvwgCDwtGEZSH5p4N)(<4?9_pX)FmKp#;CJk)fx47Q!Ji=>(`gLt -zB9@RMXeL6z=WsaVZGDZy -zS;DhvL?nwM{iQ)K1<=B|aQg-X&IDSl$A~zKkYo -zhV&KKYp^vG$Xo#98^t%_%B6ouEDxE%5^=ljeyV}hvfWi+B(755(_^ -zyBq^D^D)}0ODnN{tCc;IJ~a0+z_Z4F{>vTLxtG7v-n?O6^jolP-ZweAlZ6FFe`>0B -zfhbF<9s&Xg00e>r$je4%i&omIruPaAML(chuA&9Npn@rycZovGBZ#}MmPoP7HFyS+ -z5YP1fO@E2>32IZ)3U7So39tUWihv|bt@|JD=G>W@vLbuh$`t2r-H%|(HA#7Z7W-_6 -zMx(NU&So_YHnXHr{(L?L$F@_~eG6X?q6S`WCfKOSVZ2DhB(;a-fB!!0 -zx12RrgaWp -zY5qyxizI4x;ougu@A$3NK6q`unhku}7(r*IjuEbk_W?J+^#5)TU`GEu5)6)&$OQdF -z;-goaN}BKgkRb>#!sPGo0~l6y6J_wWv)T|RQ;IHAJzqBid4iXawd)P0rV6^HMLnb$ -z)*C7%K6%-JP9aAHs48ype~zwJly9JZ$}NYKx-Mp9`1s6RNNL#vLto*^@?m;nGW+I= -zWrFX-+Ya8`rQ6nHMD*!7*jvVb6y)NbtGwi4TGa~%?hH{~D+F~WCg$qzYa5~Jg_L|t -zRR4#x%vZ6tegWzpK5qbxOZlsQw9ed@cuy1?5hFwQI5x`5k*FI1f3=Bo6N?70(6E=! -z)=e3F8h{}lF=#L0^Xd)rP>R2*=*YJFpRmnBBqPdF6~Em{>vK>4KYMxGKc(f49lQR* -zpC5e;d4$#Ea4PR55SyjScaGF=qC5ad8W_NCb&1?YgbKORkd^;He$u%fp+PlI)X|mz -zVstj3!6b2+*r!Dke}#limlzF>9>fdN{BmbrZ}WBUCLIQZ!JJo(?`OTRR|!iY(4U7e -z$^v2Fxgs0I5*}XGJhGl7%`WX>-$vfL?F|tI;2fAi`BD5;7Bd#Vy+Sw;PxmH*ra_J0uID$f8R;tP|Zy-aDWv?@#W%h -zgadvFj)f%M9Vnn?eUJrGfhc=2RDa9V -z>FxIlgkKyC(TX_6Co);|LM8Y_i725KU9m*^TC$^0OB)4Q@!qg|><#|?M~Ctb+P+hI -zkbMqX>Z6#Xe>34_&bOc2;_=J{oyk_Ny}nc=NryDiE!$)Q7+PK!i92EIEojc$?P96m -zc?iK(OD1K6|1g4R+r<@Y5|Jg!GwO8#LjQ})>Ni^dMDAw0p*0`d{zeV3zaLZ3oYpEw -zH%D+{4}P!wbSfTH=8xk$*K9Gx2wGly)4dY^K_bE!e@dLK94%Iux!tn5oCu>-ve@+_7Qen#! -zCcQI#e_G{j=hkznNe7#RtdAbEF26Pu?E0(v%|h1m<)!3M1d@Njft3yg;C}h;Dso!= -zfAFsv_<1EcnjXbW)|JR|FCL)ej`wM6w&%hWM}7Gk&X#(57o~9AdT@&Zbv}$YQU*8&0v05$6?i~s-t - -delta 2682 -zcmV-=3WfFk75x>EU4Nojn7^Afzuf`?2mpYB1sEA6cU;`CoS+7>CyWFQ$f+`W0i)xX -z1IMo8fFTH+Sz>3S>Uht|Eny;NP)?BG$3gXhG8NY)?NxVg6aGis7v1YDigSP`x?im@ -z`?Db1bRoQBgcP>Q+5v3SBB~AyAzr+=xrsL^J*kw{1hZ5%a+ -zHc2Xg8*)=q>SP@L@CC{#w>L^Z+J&6pnI}#Mq2P6X*Nyqox5QLoU(Jpxpoq&?#cuXc -zXJAXQt}I!EzNSb2ejUPkjluI$|4N3SNcUzZvV&GsmZuciaq~wn*p_S%?j(No_hj!&e-e>lt2Pg<@@fsC`72#frhb+0TlAJiVEMe+^V -zdV&&N)e5!qVh}cr=ge)HA7V6&5DHAbYHMo2Cwb?2_HFi@NgTia_2J9}>VmG;PF11h -zuX{^wYCwv%P3F#g(FX%|k23^bb3@-HU&VT%}IkJ8+A94z3vJox8pxZTm -zh96kU7&>62DbVf_jg>pF8CWC|H9xpweRbyo-+3m`BB;l^m|n5?F~-UAw2Eo|Upr51 -zfzm`i1<%YQFY4E;7^kKDXL(Z>fhax#kUom*Hj0_R>A-22fRZK89x=g|&JSE{W{2vI -z^w^gDgMa^gOhBw$Ca*O&b-vw=S;5yL^$nwu8i^;~ -zmVO3ig006aRom{J8v_Oh6k7nJM^oOvgO$e?LIcUe@rCtq|s3&RB^ -zp*ri|HnLH%?bY0wu{FJ?nTgs5ZEh;!_`)$2#t+ZJDuWwlGEIQ!^sZWqrL^=L`giqm -z34aFCQ+hfGDFnHl9}q8BCSMbhWO{0LhibaOL`8zaZw)#kDfpVL!WS$Bf|Wp#SGs8z -zuMxe^2$FU%zGSVpNVe46cBmbY6hqiGm#PP&EQ$kq_W{$pm06H0I%gFf)9CYmtx{e` -zCJomci2D?Z;c$t;*dS$k%-x!+$E95H>*!vWXOLFkcWfP(8vvqEm^ -zD7?NEyE=lGE=5{3&E1qK?Pq*of+X=YNRd~ny(2zVQ$<$apcRzL@uGb_@^{?HAb*II -z$&EQT=ZqVQpB3Q~c_g!iYNSeNLJIbf9LS;cn*N*`225y4pWcO>;8=j3zmG!aoO6zN -zSv~SZC)THX1T9jO_hUY0^=Dn#Xf}@Po+cTbq?@TM`@ji}ttmn2n;Sr4S<{d4l2a2) -zPS}ZZea)SIItKpy^!VN -z+N>iElo8@Mr$PrK`e)v)F{}y9KcSe}c^NmRCcg8to5T>| -z))WBs=1!|VB#mFx`T^_p+=Pn>y_{Zw#nr0X{?<`094{ph7>-~kbq@olS=kAbC8n;u -zqo--UqoV^)&Jq=A_HU}Cbbqn(f6FcUJe4TRe&a}TeVj?vOMT*nA50LwT!xaLWC~?z -zuR;Q1O*uQ+^mH=6@E2eV!vRW8xN1V^ -z7CvAHrt*6lqf)z5mkVEybFjWWrp|)?J*)@-OENCPO5D86?t`Ru9vD!^e;eouy|I2+ -z)$WnuN?<+4|2P~77T6MX&E~%*V{m1X=w~b<4D1y6!fa8v^q-RT@mT(ydAbR9tx)Mg -za`UP#n<^-&N3T@x%5`|IYt`Dh8FG&3*k>3@-f8ZRSjJBYOX+8{Vp2tFEQl+0M92wn~XpZ4n$&REI$O|!A -z|C&upTLIlp;Cd-QTpjF8zK+*zVNtRL8TaU#8gXF2dW4AnLSjby@N|0|VUWjIwuzP7 -z2xQObW)|z43v)#`5QOv~WpJ>Wxk#=te<$e*%Nh%31rZ;eP4F -zCW8>)15kbf%VdCj6aFwL?c2SQo#n52WiFgQTPjU)KxSQV{S``6ngGtn -z|Lk(B1|^3OZUXEj6IkMTS+tQbc2JMX@jaF0-Y)3F&iIGWY3c-<&L!MH-FQs?2>rCo -zW)YfJ#J06pbph*0FRV?dVRUI9mZe(rkQ(0v9mAEpe?l>lDrmYvy^Rh&^F$bAg9aFx -zb;PX}B%WHxJK8;Gcqh-`?*P;qO4xaQT}m-W6F`5&om0=1){V^dwH-A)3GtCm7iP)scf7`!^ -zpcfWDpn~znhuv+jW45rkqMPDQT}e67FE|w_ESX(LKd}_=1_wtRDk{{ei?VevL^v4)*gHc4wiT(y#HLe -z4qSa#+Lf4khNXr}4Pq3ujwKQ%=*c1>#@tMjIH6+JG=JUgo3n9hbV2@&`^09UzLsXx -z1Q0;yi%cyg>96()dg6wn_&qzl`iL-O?IPE57!Zi%GjLm9XfP6c3OXaDg?zmXl_m|- -zD#I>Xh}5fP8${o7N)c1RcdbKF?oNOY6SjNF1NxBu?Xn2B5^2_>uDznS=+!Ntgao5u -zB_17l5`Tuv-3}{<8W0>JB~ZN>!|UwyTJ;p$j>5;?5;Y$w%BzS>?M_-N=&9H^M5*5VIABRGi2Gd*F0<%A61E4i|HUz -zX!OLlQeM2}Z={{ENfa0g*iW|uy6#x-f>|U_zzmuM>X>mvJm2MZn#=zwdTlT-NTv)n -z$gq@JThWUCy5?f5nUaHNcqc>Wi{@iB-%8J0m(YS!7p$&;U$Mx~#YgsS#hfS;=L)-0 -z4}bqab$|EYJ#yJjn${s(M^^4b`Y9ZM%%!e@ka;J&=%N+5kQpuV&Y*NQ6%bqqrp?0c -zvkASQ^E5U0TOV~zI*%0#ts88^z*()E+lgg{*<{;CjX2|_kR5t`3b)2*_|u7AS)zCI -zddqMp*eroBDYq6%$yo$Y{G=>O3TL-|_kTW!!P_2$POnW{>xFSfio_MXs0ww-mo~hi -z=(rSEzL&BlLd#CsC*oqs6C~Fo+9Hg8?ck})d&Mf}w3xopmhhLVP`QjiQyjND61#m- -z@Ti!l54-Aa1EIxMwvv%1+o8lC5XZ?$KpMOoo;_Rth{0DdmNF=oifNM6@T>e -z7}*!D{OdLG!LDBZFZ#;gcf%2Gl4oOl6Fn~r8DNFFQ~AA?eY^)C|5Ly1pjk;wx&r6# -zDrVnH0^2DH(;P{I=T})*lyeFUa6%tU6RtX@SZ<2mTs?v7BL{(|rzuaK5kMkSf)x!P -zMII;x>mr$R@xPVtr{^r7my}%1}E!A}WmbofvFM -zcS!kljv8Z%(&&Qf>ru913`}dK`R}b6!=OYQ|L5CpY15F!mbW2qYdr|JUF9YL8WSuf -ze*bNr&bN?B+Q@E1=uUeEjhQSIS?`-Af4;LXKn5N-XLq6xc|f%_#M%w-*Pn9 -z0f3p>$dACQCD|ZcE0T;i&hLLDWC+>2e_q0`-xh{n0FH%33ag~TcZ@rg112tzut(cYLAtgLWrFG9P}7g>GqSjUx=*%5=Ei(wi;B#qD!D0DdHB=5ne3p -zz7X)28kw|s=IQ-C@X=`XBrP#XfrYOchw)SmxSL>Lf2fV;6VyWK+tGI0@;#9o`ML}b -z=Efu{JvtPd@rn|9u&5^X|3=^8Ur|_(J(G1WEIKJ0`^x9%VSj#?Nk6WwjXxRnu-6m( -zjd)VmBbBWvY@1~+Vw#!O<(3tv)oh)ricul3Rfwl%X8C3a+<33*fD-2-GI5{qDV75o -z>LqpWe?G2-@V5x^ez4WY)5DkL6ZxDB*vBE9%u;E|A>H(s6n}9bH&KQb#zdIBW7MnaIzRarxL@n!O)O -zK=8REHm-D)+!QbFDD>eFGqQGle!kP6e|@)JpgdCP;~7UeyK0@F3NK#SJ0IUT4CA() -zo39%1U#tTOc@;VYuXNuOe?N1eS){UjB$ovmaX=}kj~2dJIL}s}NbDPCos#k!q0k~& -z6(yK2z2-dNY(yJA%`mY1gCo4XY$|Rb{VRvx>}p2VB)BS18|crUeYiOaX8I5uf9e;5 -z!Sp~;hom{dK*GcnV={{eZlquY3=K$u%N;dC3YcZ7Jwid9q$w720~h8_o0`rJ#+e>}#fXz~jOgIgpH5GUFmGfeNWtu%Y@mn$$D4=DMM -z<8V+G_ROuV$#I&3s%U2e{*tn{;XFo~vnDzTiDiOa;XL2_2q1G2#|Ib<`7((J_Ta?x -z6ma$u_FJom0HA=6G# -zp;0g~Fd;Ar1_dh)0|FWa00a~tK>i(z<@;kWV;*m?sLnLjiHbx72-=Fo1r5yv^#TG2 -E0EqGn4gdfE - -delta 2698 -zcmV;53U&337L68=U4OgPIH0Ma|Ih*g2mpYB1t^cgTby1_i4bV`ET($=&EQs+%VWU! -z7EL>iJi4Z78OaT9ubV}bGdi0`Ahw>yNtjoh(jz*K!b%&Ua)hJeCBb!FAt9G4(CLat -z`Rag4jFpnmFT)s@f*z8jt%jD9#v%N*$?L>k;p5=UEuP*lV}GdN&eI?0rjB?@WB}eY -zf)XxYT1q=>J -zymMlumTAK2tc{81$;?wU?RVDyIg)}6Ru7Is8*D-idC>`arMh=W)oa9!1#zHlQH+C= -zxNFQiy$@%pUw>ciB6Pems-P<2y=ikP`PqC(+TZsM6awppC_f0Xl3g4K3t|VAQ*|@t -zqWP;7pCfxOI}DZ9(iJy)rS*nL8a}#DV!e3{QR4jj(Ty7a7d86H_%`o3)tY*5-w|Qk -zembO|Ujs3}!86C73mgV0q^5iPuZU!CsXRr9j$1G30DnT~&96xZ(_w+gVmP}nkT+9^ -zTnBG}hdQN2AJnve+R?%pEbv=8E5(bzWG-#u#DzEycabv3EOTQ^KP}Xh8CNH%dMrC| -zl_ZZqKVqcBMJt^u$Fh!)FjVOw&dWSYUg?omm_rDHAOgriM49P$d0+1``GCJ!ZsQwc -zIeSn5N`Ij~5U5@dvEBjG{TiDpjvP!%Bx(#V7yW^c5vbxvj?}{zE!H+*c6xgo=IhbX -z{ugXqn`P$jl!c&05S&~~#+%)!=U#Kbk5wVT)3ql;lTT$>=q+JLDX30eW_%PenT4Zp -z_goXztU1Ch8>MHCoD|K5H4(V-ja(n=t}k--9Y2&($W_V$rpuB>QO?+3-dA -z-pr3g54LFhpSdbUZ -z|IdewW&nX@Id-7N;;8dTYiF$bj&+Vzp?^hsO`e7M7OU$Gla=8Q4G^LnBF+hG_nBeb -zu}|$?y}&Ypv{-4`sZB4J84gG&-!sF!m9%?q;wc<-;0*nm{J3|%$s#f4g#v)CGLCU4 -z(Yc7zteW+0h{?ByycGWhd;fPj&Dn(4myw17)6pVR`dcE2`6M7x!wVsRwxjCdAb(Wf -z4D$@k@4>yr5z6XWYn7pBxh_HGbj9atGCo7126F9)ewn?kfa;&vg>e{5+wgb3)|=NA -z`o8_Sx*VNIakI&`^qCUyxWkzJM}b~6qYN&iv+v+c(UQ5=%{ok(ekXq$lZ@xKgBHx0Tl@87a+hB943i -zFD%RA(jSI%C|Xca<$+=*lWL`yEop8}Q{X%bQc-xA;u>Z)z-N*eV}?4frikpteC|{% -z^a!Dtv`0%$*x`Vxh#$niPcOGkf}NjScYXD!MU!uL497Oq;pCJOkrMUvRzj(C7>B7| -zirNe8d;&TQyncnqec(ERvcvZ=HhwevKN)GUzDKIn4gl?ZdnRwvb(WT2#ZBk3!kjVD -zJEGu3Mj^N{la&QVe+@0G1;Pz3&jJDn00e>r$OX00Alr(atOG})P|bur1*6+0Wi&x_x{|YhpPm9aRrXy+e>w{XL@?~)eWqce&iDF0 -zqMSy`TNzT_)VB-&hdVeWjEeXb0i{%KpZeK!$PY01Wa=BLfB6xzk$J9wnQ+$8Q?cOh -zQWJ^oEshJdhCpbB9?+gW%#d0mHXCu4Kr$r>M+VFC+yRsa^lQ^YyqVejN5NolmXwl= -zj;AXtkvzSNf4>f%vSi6=NX>a2^%IT&;v29li&z4uXN8vz(uEM&T*Qo=&F?5rk#RQz -zC336+`bfFPsilPKn2a5|Np2S1s2;)B2v;glXVE<%O(u+#u~*}7ksKGB=)IwePkk!6 -zKOP3PmZY@6SqGV+fn{aX%cf@iNQisE!MeAT`8h7je{pcQ%DlZS83P&0<4$9^B?j!n -z0^s^wwN->E=~xLdD_)eKs$i$WQ?$&-S=N4)kY -z8sF-Ce>waid23??s6b(A4ogu;h++fH;y`eEvd@BSm#`s!Ry -z+6L`T@d*j+#(xh*)fPw%XJxi5_WgWEv1C&^jNYt_5ZCvbDlQ07M;HV(J|PE-03cDz -zI%m{>hShEl-wN=n~{2XZ{L*9dR&>p&O5P -zL~0ADX*&QcF)J*1tw=!e<$;FCS~Q>H`vQ6<^=_{tlE=R-j`1+-CyIrhMa^l@GsOkoi*b5gc{|O)u6y -z*Eybgfl##owFc|2DqiQ%>C%TLxKNZ2)Y8q^GKz)qUCCb^Y!~Ouk~utFj^%qDAD7$7 -z4|(O*(4Us`f{<2cXiaTtd7QygQM!6=e^+!{SnFm@Sce*pSUC_>Mud$loY2}d94m?| -z<^OOSjsAsDBC2thdNWvSgLi|B<-_+{K_gsBydMbNjR&C)NZ%Y(>Bs|d@Ni&G^NWGp&(#5%4Z5twBV>={4~8{UuyO)#6}%;xPIHyY{h_i55`b4<${ihODv=^X_GvM2$(ip)-{scMp=K6z4NT0 -zh9qH{M2vDnA%B4RMJV4L3g&uG{}^y>U@_^&s079+Uw;8UwQZawTn!vsnczNryXER< -z^4t|;quLw`bl;E|eEKmn>RrwfXq1zSpT$o-918IoaQn0K1Qcv~32@A!!Yk9d$5)cI -zy{aB^id7jlNY5I{?KJ6dEI`cwQ;~`h@bsE-*#wn1qLARY;aK^Be3VEOF^3YZC -z@z)+dYJm7<$cmm$-`oMA4%n3L(y&2%bYK#IC-~*C61&8wgQwA^>q1bHC}EtDjtVc1 -zELlaHTmHT=Yj$uxFYs(>usRFRqQvn&Y=h-QA_vyh{d+oN#SEVcRq3G;MW*B4{9l6v -zq4IfK2!A=Q^+R+st9#jqW4=?osK-Q)K4Hq5%bbPzj&C#dO##MJ7oXFI1vcvc70Jw{ -zEv_S72+LnOnU;)4y)s1`vlaV>-0o^K1+!777`l65f<`flFo5nDa<3{ccfhQZ2?{|o -z7c|F5o2|#B%7Rj;vzYt{Mut5sSc(Fb-e#e^-GBAX_{?R+=$MOl)HiG~U+;&08^mvP -zHNfv;+m0CZZAMc)NCYtA@^kdgq@Aok`CYuV8^FZ~W1mpM$Y|0UcYycv$Rw~Uk-pz- -z!Dy26%)YpIB<5W?r3BX^eu*^fEgSl~ReH*mqG<*`wedGDz+{; -zx4kLMqty}CrlV-aA&gVt>cAAtAE|kT{Gl>@GBfH-*I9Ut$$mL}Z;Gm~5u@3~UH3u; -zu*RcYkh532p}cjA>7*oslZ7OgH8tToL4TJC&l=yANqs|aNom00jp9FBDbRbjK3>*1 -z%t%A$fhz|l3Z2Gti}j5NxrXYzf=4jVC`TMPTZvUT-H%YSuYeGCOl)KMa1~`sWdLxxWOlH7Hp((U}SX!YNhgfJ)IPf=;Gx -zCA}LPUS!(0kh@$b!MG*{z^TG9-c9BlhSqSqv`*cklbr=df9nY*n}fvB!vX>b00e>r$RI81nSv?+Yi!SD63Wi? -zTpz5uAf~z86j38B#-LJmrSIOk*?dx5rdvPi*JcISr -z;GrMw4kJI_;L|8E8I7#QK@8J%06j|~QeRT5YPYz2e~m|0eC*+N -z;tTbW&k|>^&OYIQAQZ)=e!ZR$EefvbbEa%e@aTI~@iZEV&h?kl_iWbBu8gqL22EWO -z9%e@s!Ln9mn5gIkKyZEbno(BO|N92gh4zi>;+t!DB# -zUD*#wq%14Ws-EP3hBY-&Ihk~ywGtQqB8-6CEv895gq+Y?Ref!PVQoN$e}ep~l&{da -zqe>QuPg-wYhtPeEN!5YpIa21fnSW1kwM|Wu{MOd})a|@aJwy*geIt_-o -zf@_GTcauuKT26Cov}Jb>o;A$hT-*SD}c|OaKX(rQfx^MRmECJ-R!H{CDx2O -ztfI!lXTISDio|vGOxL+yF(#V^*FP|1>(VxK)_HV+LW+m+hM>6nHJtbPD8$YNAI`V} -zJxt8tv;~TeJ|us*$IFJ&gYiOXa5$hQD(6={4wTTv<(s?me|tUC1}n4%7sLR#^%2Z1 -z>wB$BQPVbOEZr-HbQu^qQZZDV0B=qKLSTk0OH6ViZg6t{x4jDwj>Q2g#8kQ3r>Eji -zoCHAsSfZI^gjaN%upLrFe;LL-L(-_It&su|RC&en#x}vk5N84OPL*8oFVPE6rr}-0qN*#i8!ZNM -z-lMCaJq9;t`UH;WVM3PeWlDBk&GJ8MW!kVJPop~_JfAJz8Tv~1W~R=A -zf#mg1W3o+d#@#T-2&}3LjtVGn(SoOHnQi>T=yg_;f6ZBqH!1J@yw>z^@>NitY+5GG -z$_K1gfo*y_T~t97XgHe91xGJb>0;+13X;T-03Pf6IfLg53{}XapD=~I*1UWMmfQ!D -z7Ze1;SJ|?3B4jg+a%x7qjgRh1J9NxeFNvzi*YlS;ci9S -z#DRe^Za5%?_JurFHR(9)uJQ)yN&4iz?H -zSw@t!Q))44>uN8OaX|V82359~wEHn7Fe3&DDuzgg_YDCF6)_eB6ccK}Vdj_r1JjB8 -zJcW?bd-abN6XY;4Fd;Ar1_dh)0|FWa00a~TEWhWcHtRjAj4t&h2$Cd#3qV%{2$+b8 -MPj+1S(*gnr0E_P~i~s-t - -delta 2706 -zcmV;D3T^e37L^u|U4L0@OZ+^lY6AiS2mpYB1u&$H6w%_X?Uh+pizOtCBDzx2lCMDmI_;E4nZypk7SId1QiiG% -zoX$R-HEZK1+~1}@RF*!aKybD>UweVLW#TM}CG=Kw((`3EMgCgE%Wh7i5_PDshVd9Oz|EjKxtnoLw`TW#&7 -zQPy}=X-XKHcQwT5v|u~sb^Inq0NJ4Lak7<6+3Ya}d< -zR^Uti{uWAJB7|b_QADZ~qF1trj0LGAR*qZ!4V-8U)PEs3HV=&h(r8ATc_D(AEnMV1 -zwuVIjs`^7H=|3CS`*aB@;CnPV&TlP!Yu&aLuDOS7Sg0Cqu0xGBQP5;o#gwP}e8{0B -z7jV-rq(ifyxm<=mq)wx^ScfIWLZ7^FtdIF5!b_#_SU{v)$6P6;3c{)K{n+@;OiiQ- -z)v(k`B7Y~QMMOz0exF+cpQ;~*F-}k8OW2c^cHxE_)brp6_t{vy8?fdPQ-ctCS#H(j -z$jQY05`;BJt5Y1_E&P`i?y7~+)+fF@I~p95YmggrA_kkXkLdVu+sQe~jV^LlG=Fp{ -zGMUwQ8FM7Kg20u!G&B)cCNQ!KA|~SY(%9(~dw)NYD5>AwQTYoOym#9ju3MlAj~yL! -z+9RAIsl?+#`6IQ~$`6sGmR#$qABV!__lx-g(mg2@c}g0+B+myWGZ@B1H-hdORvFBr11a5D -zD5mD8X#7lUgZJ09DQa34oE2MSOlRl*Pk;Loc@3DRHQ-tjjjDOpdmBQ1xk?t__INBb -zA2{y5_WewW14^G6WH^SY0hmJ8^Ng^zx=ZpuY7#VI+rLN#wJ0?Q;k^@dZ=X;S&RshD -zWP{?O$!sjtgM5;`y4Wj6`G$m`1OsXIXK)R(Jwf5Zy`3r9HV=gsO7Qi4jzaFFm49h7 -zfsyLIa}fYP4lU}*uw@gGo4t5v27iR`O@MAwyFq8%w;vNMFt1G(wBrYGlM@r4)ff!p -z>8Mmh-L?^v&W!qOH^7S@tzEEwdy!EuK#bBM?x4Wr`(bkkOsAP+#8TbjTL5J_=bS5) -za6olnR}(Db?FG0|ejvnzj -zP}Lz{>_d&8$(MkIB`z>!MW@mnuqJ@W?8->i@)3)j#DPAOs8q=yg6rJ-m=-Lk7xDaXe*1RV@>aTN~)U7 -zHjL@_ge{0Jt7~qq;qj^Jlbr=df11{|CuI2Wr$kBFUM=%p0lc|48g~wmO -zlQm6cm$_s_2>(DlA9cyxg6bmmW)&QR$peuE=vJIf2HTu-u#@{ -znFBj?5I#2g`5TG`?>T^VI($%BFj|uIDfc;L5->4jxZu(nSAc33NNkgSR!9J}GSx4y -z_4M@|c;BpN-D}R->!q&&aVy|TU2Cb!tnn_pGykac3R{dXLJEv0NPZVx+TTgAeJQji@`)5{g< -zcJZ=w(L#L{pjXv2RjibOnkQN957ydC_9_$?NmM?Po^Q&34Z7W?1h2;S>~cDOEpIB3e3RmaS@`juU%CSke_Xs}bPG03Hd`AnWDQe0 -zDzTI!DRp&=;Lw}C)$l@}&C%0-vB~aHYq5NMeTEzqqd+JdVj_`U-$+46eP9-nM7?zc -z5Pgt-^k?oplhg%4^}fJ8S>3v%<7ynPniiv_Z|t!~Z%up1%zf`A$#gTl -z|Itn@fJi}H(elXg%0X;2+!%;)-lR)s0rXj$+}J!$F5z3_l55m6b2_*fC-NqxNFTql -zdv*Y;FP;Z6UFji4Uh@uDeNWtoP&b(ZdpU59uCOvye<+Qgi5uA#^8lnW?w_X5a(Zcq -zqur4>A_O|0nJ|NBvfV)Jmkk!X>5(vIem$?G-`>87E-&XqHpVEiV;~i$OoPodAQ$zu -zHfA}RyWpW+OJ@WK!YX*SO<(GZEW~rTpl2eq>|IbuqzzqN8t!)~kBi0rn7;jaAq#?4)^yQTe=NH@6SxT7)@@3!xd(1))7AABX12%e -zGo=U4kgSi_sg=#zEko}S``7Td_RokC%@eQ1Z`cc&&D0V7DMKQ8X_oz -Date: Tue, 4 Apr 2017 16:54:56 -0400 -Subject: [PATCH] Add the client_name() kdcpreauth callback - -Add a kdcpreauth callback to returns the canonicalized client principal. - -ticket: 8570 (new) -(cherry picked from commit a84f39ec30f3deeda7836da6e8b3d8dcf7a045b1) ---- - src/include/krb5/kdcpreauth_plugin.h | 6 ++++++ - src/kdc/kdc_preauth.c | 9 ++++++++- - 2 files changed, 14 insertions(+), 1 deletion(-) - -diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h -index 92aa5a5a5..fa4436b83 100644 ---- a/src/include/krb5/kdcpreauth_plugin.h -+++ b/src/include/krb5/kdcpreauth_plugin.h -@@ -232,6 +232,12 @@ typedef struct krb5_kdcpreauth_callbacks_st { - krb5_kdcpreauth_rock rock, - krb5_principal princ); - -+ /* -+ * Get an alias to the client DB entry principal (possibly canonicalized). -+ */ -+ krb5_principal (*client_name)(krb5_context context, -+ krb5_kdcpreauth_rock rock); -+ - /* End of version 4 kdcpreauth callbacks. */ - - } *krb5_kdcpreauth_callbacks; -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 0ce79c667..81d0b8cff 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -591,6 +591,12 @@ match_client(krb5_context context, krb5_kdcpreauth_rock rock, - return match; - } - -+static krb5_principal -+client_name(krb5_context context, krb5_kdcpreauth_rock rock) -+{ -+ return rock->client->princ; -+} -+ - static struct krb5_kdcpreauth_callbacks_st callbacks = { - 4, - max_time_skew, -@@ -607,7 +613,8 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { - add_auth_indicator, - get_cookie, - set_cookie, -- match_client -+ match_client, -+ client_name - }; - - static krb5_error_code diff --git a/Add-timestamp-helper-functions.patch b/Add-timestamp-helper-functions.patch deleted file mode 100644 index 54e7f59..0000000 --- a/Add-timestamp-helper-functions.patch +++ /dev/null @@ -1,80 +0,0 @@ -From 9b50a75e97cbe9cc8c0a4e37158b56b58e966f25 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 22 Apr 2017 09:49:12 -0400 -Subject: [PATCH] Add timestamp helper functions - -Add k5-int.h helper functions to manipulate krb5_timestamp values, -avoiding undefined behavior and treating negative timestamp values as -times between 2038 and 2106. Add a doxygen comment for krb5_timestamp -indicating how third-party code should use it safely. - -ticket: 8352 -(cherry picked from commit 58e9155060cd93b1a7557e37fbc9b077b76465c2) ---- - src/include/k5-int.h | 31 +++++++++++++++++++++++++++++++ - src/include/krb5/krb5.hin | 9 +++++++++ - 2 files changed, 40 insertions(+) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 06ca2b66d..82ee20760 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2353,6 +2353,37 @@ k5memdup0(const void *in, size_t len, krb5_error_code *code) - return ptr; - } - -+/* Convert a krb5_timestamp to a time_t value, treating the negative range of -+ * krb5_timestamp as times between 2038 and 2106 (if time_t is 64-bit). */ -+static inline time_t -+ts2tt(krb5_timestamp timestamp) -+{ -+ return (time_t)(uint32_t)timestamp; -+} -+ -+/* Return the delta between two timestamps (a - b) as a signed 32-bit value, -+ * without relying on undefined behavior. */ -+static inline krb5_deltat -+ts_delta(krb5_timestamp a, krb5_timestamp b) -+{ -+ return (krb5_deltat)((uint32_t)a - (uint32_t)b); -+} -+ -+/* Increment a timestamp by a signed 32-bit interval, without relying on -+ * undefined behavior. */ -+static inline krb5_timestamp -+ts_incr(krb5_timestamp ts, krb5_deltat delta) -+{ -+ return (krb5_timestamp)((uint32_t)ts + (uint32_t)delta); -+} -+ -+/* Return true if a comes after b. */ -+static inline krb5_boolean -+ts_after(krb5_timestamp a, krb5_timestamp b) -+{ -+ return (uint32_t)a > (uint32_t)b; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_get_credentials_for_user(krb5_context context, krb5_flags options, - krb5_ccache ccache, -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index cf60d6c41..53ad85384 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -187,7 +187,16 @@ typedef krb5_int32 krb5_cryptotype; - - typedef krb5_int32 krb5_preauthtype; /* This may change, later on */ - typedef krb5_int32 krb5_flags; -+ -+/** -+ * Represents a timestamp in seconds since the POSIX epoch. This legacy type -+ * is used frequently in the ABI, but cannot represent timestamps after 2038 as -+ * a positive number. Code which uses this type should cast values of it to -+ * uint32_t so that negative values are treated as timestamps between 2038 and -+ * 2106 on platforms with 64-bit time_t. -+ */ - typedef krb5_int32 krb5_timestamp; -+ - typedef krb5_int32 krb5_deltat; - - /** diff --git a/Add-timestamp-tests.patch b/Add-timestamp-tests.patch deleted file mode 100644 index ac64115..0000000 --- a/Add-timestamp-tests.patch +++ /dev/null @@ -1,599 +0,0 @@ -From 3a06f6a3cfad62da6dd8878d3446003f8293c3ae Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 29 Apr 2017 17:30:36 -0400 -Subject: [PATCH] Add timestamp tests - -Add a test program for krb5int_validate_times() covering cases before -and across the y2038 boundary. Add a GSSAPI test program to exercise -lifetime queries, and tests using it in t_gssapi.py for ticket end -times after y2038. Add a new test script t_y2038.py which only runs -on platforms with 64-bit time_t to exercise end-user operations across -and after y2038. Add an LDAP test case to test storage of post-y2038 -timestamps. - -ticket: 8352 -(cherry picked from commit 8ca62e54e89e2fbd6a089e8ab20b4e374a486003) -[rharwood@redhat.com: prune gitignore] ---- - src/Makefile.in | 1 + - src/config/pre.in | 2 + - src/configure.in | 3 + - src/lib/krb5/krb/Makefile.in | 14 ++-- - src/lib/krb5/krb/t_valid_times.c | 109 ++++++++++++++++++++++++++++++ - src/tests/Makefile.in | 1 + - src/tests/gssapi/Makefile.in | 27 ++++---- - src/tests/gssapi/t_gssapi.py | 32 +++++++++ - src/tests/gssapi/t_lifetime.c | 140 +++++++++++++++++++++++++++++++++++++++ - src/tests/t_kdb.py | 7 ++ - src/tests/t_y2038.py | 75 +++++++++++++++++++++ - 11 files changed, 395 insertions(+), 16 deletions(-) - create mode 100644 src/lib/krb5/krb/t_valid_times.c - create mode 100644 src/tests/gssapi/t_lifetime.c - create mode 100644 src/tests/t_y2038.py - -diff --git a/src/Makefile.in b/src/Makefile.in -index b0249778c..ad8565056 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -521,6 +521,7 @@ pyrunenv.vals: Makefile - done > $@ - echo "tls_impl = '$(TLS_IMPL)'" >> $@ - echo "have_sasl = '$(HAVE_SASL)'" >> $@ -+ echo "sizeof_time_t = $(SIZEOF_TIME_T)" >> $@ - - runenv.py: pyrunenv.vals - echo 'env = {}' > $@ -diff --git a/src/config/pre.in b/src/config/pre.in -index d961b5621..f23c07d9d 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -452,6 +452,8 @@ HAVE_SASL = @HAVE_SASL@ - # Whether we have libresolv 1.1.5 for URI discovery tests - HAVE_RESOLV_WRAPPER = @HAVE_RESOLV_WRAPPER@ - -+SIZEOF_TIME_T = @SIZEOF_TIME_T@ -+ - # error table rules - # - ### /* these are invoked as $(...) foo.et, which works, but could be better */ -diff --git a/src/configure.in b/src/configure.in -index 24f653f0d..4ae2c07d5 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -744,6 +744,9 @@ fi - - AC_HEADER_TIME - AC_CHECK_TYPE(time_t, long) -+AC_CHECK_SIZEOF(time_t) -+SIZEOF_TIME_T=$ac_cv_sizeof_time_t -+AC_SUBST(SIZEOF_TIME_T) - - # Determine where to put the replay cache. - -diff --git a/src/lib/krb5/krb/Makefile.in b/src/lib/krb5/krb/Makefile.in -index 0fe02a95d..55f82b147 100644 ---- a/src/lib/krb5/krb/Makefile.in -+++ b/src/lib/krb5/krb/Makefile.in -@@ -364,6 +364,7 @@ SRCS= $(srcdir)/addr_comp.c \ - $(srcdir)/t_in_ccache.c \ - $(srcdir)/t_response_items.c \ - $(srcdir)/t_sname_match.c \ -+ $(srcdir)/t_valid_times.c \ - $(srcdir)/t_vfy_increds.c - - # Someday, when we have a "maintainer mode", do this right: -@@ -457,9 +458,12 @@ t_response_items: t_response_items.o response_items.o $(KRB5_BASE_DEPLIBS) - t_sname_match: t_sname_match.o sname_match.o $(KRB5_BASE_DEPLIBS) - $(CC_LINK) -o $@ t_sname_match.o sname_match.o $(KRB5_BASE_LIBS) - -+t_valid_times: t_valid_times.o valid_times.o $(KRB5_BASE_DEPLIBS) -+ $(CC_LINK) -o $@ t_valid_times.o valid_times.o $(KRB5_BASE_LIBS) -+ - TEST_PROGS= t_walk_rtree t_kerb t_ser t_deltat t_expand t_authdata t_pac \ -- t_in_ccache t_cc_config t_copy_context \ -- t_princ t_etypes t_vfy_increds t_response_items t_sname_match -+ t_in_ccache t_cc_config t_copy_context t_princ t_etypes t_vfy_increds \ -+ t_response_items t_sname_match t_valid_times - - check-unix: $(TEST_PROGS) - $(RUN_TEST_LOCAL_CONF) ./t_kerb \ -@@ -496,6 +500,7 @@ check-unix: $(TEST_PROGS) - $(RUN_TEST) ./t_response_items - $(RUN_TEST) ./t_copy_context - $(RUN_TEST) ./t_sname_match -+ $(RUN_TEST) ./t_valid_times - - check-pytests: t_expire_warn t_vfy_increds - $(RUNPYTEST) $(srcdir)/t_expire_warn.py $(PYTESTFLAGS) -@@ -522,8 +527,9 @@ clean: - $(OUTPRE)t_ad_fx_armor$(EXEEXT) $(OUTPRE)t_ad_fx_armor.$(OBJEXT) \ - $(OUTPRE)t_vfy_increds$(EXEEXT) $(OUTPRE)t_vfy_increds.$(OBJEXT) \ - $(OUTPRE)t_response_items$(EXEEXT) \ -- $(OUTPRE)t_response_items.$(OBJEXT) $(OUTPRE)t_sname_match$(EXEEXT) \ -- $(OUTPRE)t_sname_match.$(OBJEXT) \ -+ $(OUTPRE)t_response_items.$(OBJEXT) \ -+ $(OUTPRE)t_sname_match$(EXEEXT) $(OUTPRE)t_sname_match.$(OBJEXT) \ -+ $(OUTPRE)t_valid_times$(EXEEXT) $(OUTPRE)t_valid_times.$(OBJECT) \ - $(OUTPRE)t_parse_host_string$(EXEEXT) \ - $(OUTPRE)t_parse_host_string.$(OBJEXT) - -diff --git a/src/lib/krb5/krb/t_valid_times.c b/src/lib/krb5/krb/t_valid_times.c -new file mode 100644 -index 000000000..1b469ffc2 ---- /dev/null -+++ b/src/lib/krb5/krb/t_valid_times.c -@@ -0,0 +1,109 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* lib/krb5/krb/t_valid_times.c - test program for krb5int_validate_times() */ -+/* -+ * Copyright (C) 2017 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "int-proto.h" -+ -+#define BOUNDARY (uint32_t)INT32_MIN -+ -+int -+main() -+{ -+ krb5_error_code ret; -+ krb5_context context; -+ krb5_ticket_times times = { 0, 0, 0, 0 }; -+ -+ ret = krb5_init_context(&context); -+ assert(!ret); -+ -+ /* Current time is within authtime and end time. */ -+ ret = krb5_set_debugging_time(context, 1000, 0); -+ times.authtime = 500; -+ times.endtime = 1500; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime, but within clock skew. */ -+ times.starttime = 1100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime by more than clock skew. */ -+ times.starttime = 1400; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_NYV); -+ -+ /* Current time is after end time, but within clock skew. */ -+ times.starttime = 500; -+ times.endtime = 800; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is after end time by more than clock skew. */ -+ times.endtime = 600; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_EXPIRED); -+ -+ /* Current time is within starttime and endtime; current time and -+ * endtime are across y2038 boundary. */ -+ ret = krb5_set_debugging_time(context, BOUNDARY - 100, 0); -+ assert(!ret); -+ times.starttime = BOUNDARY - 200; -+ times.endtime = BOUNDARY + 500; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime, but by less than clock skew. */ -+ times.starttime = BOUNDARY + 100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime by more than clock skew. */ -+ times.starttime = BOUNDARY + 250; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_NYV); -+ -+ /* Current time is after endtime, but by less than clock skew. */ -+ ret = krb5_set_debugging_time(context, BOUNDARY + 100, 0); -+ assert(!ret); -+ times.starttime = BOUNDARY - 1000; -+ times.endtime = BOUNDARY - 100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is after endtime by more than clock skew. */ -+ times.endtime = BOUNDARY - 300; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_EXPIRED); -+ -+ return 0; -+} -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 0e93d6b59..2b3112537 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -168,6 +168,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_princflags.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/gssapi/Makefile.in b/src/tests/gssapi/Makefile.in -index 6c1464297..604f926de 100644 ---- a/src/tests/gssapi/Makefile.in -+++ b/src/tests/gssapi/Makefile.in -@@ -15,15 +15,16 @@ SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ - $(srcdir)/t_gssexts.c $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c \ - $(srcdir)/t_invalid.c $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ - $(srcdir)/t_inq_mechs_name.c $(srcdir)/t_iov.c \ -- $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c $(srcdir)/t_pcontok.c \ -- $(srcdir)/t_prf.c $(srcdir)/t_s4u.c $(srcdir)/t_s4u2proxy_krb5.c \ -- $(srcdir)/t_saslname.c $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c -+ $(srcdir)/t_lifetime.c $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c \ -+ $(srcdir)/t_pcontok.c $(srcdir)/t_prf.c $(srcdir)/t_s4u.c \ -+ $(srcdir)/t_s4u2proxy_krb5.c $(srcdir)/t_saslname.c \ -+ $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c - - OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_ccselect.o t_ciflags.o \ - t_credstore.o t_enctypes.o t_err.o t_export_cred.o t_export_name.o \ - t_gssexts.o t_imp_cred.o t_imp_name.o t_invalid.o t_inq_cred.o \ -- t_inq_ctx.o t_inq_mechs_name.o t_iov.o t_namingexts.o t_oid.o \ -- t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ -+ t_inq_ctx.o t_inq_mechs_name.o t_iov.o t_lifetime.o t_namingexts.o \ -+ t_oid.o t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ - t_spnego.o t_srcattrs.o - - COMMON_DEPS= common.o $(GSS_DEPLIBS) $(KRB5_BASE_DEPLIBS) -@@ -31,9 +32,9 @@ COMMON_LIBS= common.o $(GSS_LIBS) $(KRB5_BASE_LIBS) - - all: ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore t_enctypes \ - t_err t_export_cred t_export_name t_gssexts t_imp_cred t_imp_name \ -- t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_namingexts \ -- t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 t_saslname t_spnego \ -- t_srcattrs -+ t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime \ -+ t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 t_saslname \ -+ t_spnego t_srcattrs - - check-unix: t_oid - $(RUN_TEST) ./t_invalid -@@ -42,8 +43,8 @@ check-unix: t_oid - - check-pytests: ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore \ - t_enctypes t_err t_export_cred t_export_name t_imp_cred t_inq_cred \ -- t_inq_ctx t_inq_mechs_name t_iov t_pcontok t_s4u t_s4u2proxy_krb5 \ -- t_spnego t_srcattrs -+ t_inq_ctx t_inq_mechs_name t_iov t_lifetime t_pcontok t_s4u \ -+ t_s4u2proxy_krb5 t_spnego t_srcattrs - $(RUNPYTEST) $(srcdir)/t_gssapi.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_ccselect.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_client_keytab.py $(PYTESTFLAGS) -@@ -88,6 +89,8 @@ t_inq_mechs_name: t_inq_mechs_name.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_inq_mechs_name.o $(COMMON_LIBS) - t_iov: t_iov.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_iov.o $(COMMON_LIBS) -+t_lifetime: t_lifetime.o $(COMMON_DEPS) -+ $(CC_LINK) -o $@ t_lifetime.o $(COMMON_LIBS) - t_namingexts: t_namingexts.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_namingexts.o $(COMMON_LIBS) - t_pcontok: t_pcontok.o $(COMMON_DEPS) -@@ -111,5 +114,5 @@ clean: - $(RM) ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore - $(RM) t_enctypes t_err t_export_cred t_export_name t_gssexts t_imp_cred - $(RM) t_imp_name t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov -- $(RM) t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 -- $(RM) t_saslname t_spnego t_srcattrs -+ $(RM) t_lifetime t_namingexts t_oid t_pcontok t_prf t_s4u -+ $(RM) t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index 397e58962..98c8df25c 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -185,4 +185,36 @@ realm.run(['./t_ciflags', 'p:' + realm.host_princ]) - # contexts. - realm.run(['./t_inq_ctx', 'user', password('user'), 'p:%s' % realm.host_princ]) - -+# Test lifetime results, using a realm with a large maximum lifetime -+# so that we can test ticket end dates after y2038. There are no -+# time_t conversions involved, so we can run these tests on platforms -+# with 32-bit time_t. -+realm.stop() -+conf = {'realms': {'$realm': {'max_life': '9000d'}}} -+realm = K5Realm(kdc_conf=conf, get_creds=False) -+ -+# Check a lifetime string result against an expected number value (or None). -+# Allow some variance due to time elapsed during the tests. -+def check_lifetime(msg, val, expected): -+ if expected is None and val != 'indefinite': -+ fail('%s: expected indefinite, got %s' % (msg, val)) -+ if expected is not None and val == 'indefinite': -+ fail('%s: expected %d, got indefinite' % (msg, expected)) -+ if expected is not None and abs(int(val) - expected) > 100: -+ fail('%s: expected %d, got %s' % (msg, expected, val)) -+ -+realm.kinit(realm.user_princ, password('user'), flags=['-l', '8500d']) -+out = realm.run(['./t_lifetime', 'p:' + realm.host_princ, str(8000 * 86400)]) -+ln = out.split('\n') -+check_lifetime('icred gss_acquire_cred', ln[0], 8500 * 86400) -+check_lifetime('icred gss_inquire_cred', ln[1], 8500 * 86400) -+check_lifetime('acred gss_acquire_cred', ln[2], None) -+check_lifetime('acred gss_inquire_cred', ln[3], None) -+check_lifetime('ictx gss_init_sec_context', ln[4], 8000 * 86400) -+check_lifetime('ictx gss_inquire_context', ln[5], 8000 * 86400) -+check_lifetime('ictx gss_context_time', ln[6], 8000 * 86400) -+check_lifetime('actx gss_accept_sec_context', ln[7], 8000 * 86400 + 300) -+check_lifetime('actx gss_inquire_context', ln[8], 8000 * 86400 + 300) -+check_lifetime('actx gss_context_time', ln[9], 8000 * 86400 + 300) -+ - success('GSSAPI tests') -diff --git a/src/tests/gssapi/t_lifetime.c b/src/tests/gssapi/t_lifetime.c -new file mode 100644 -index 000000000..8dcf18621 ---- /dev/null -+++ b/src/tests/gssapi/t_lifetime.c -@@ -0,0 +1,140 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* tests/gssapi/t_lifetime.c - display cred and context lifetimes */ -+/* -+ * Copyright (C) 2017 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include -+#include -+#include "common.h" -+ -+/* -+ * Using the default credential, exercise the GSS functions which accept or -+ * produce lifetimes. Display the following results, one per line, as ASCII -+ * integers or the string "indefinite": -+ * -+ * initiator cred lifetime according to gss_acquire_cred() -+ * initiator cred lifetime according to gss_inquire_cred() -+ * acceptor cred lifetime according to gss_acquire_cred() -+ * acceptor cred lifetime according to gss_inquire_cred() -+ * initiator context lifetime according to gss_init_sec_context() -+ * initiator context lifetime according to gss_inquire_context() -+ * initiator context lifetime according to gss_context_time() -+ * acceptor context lifetime according to gss_init_sec_context() -+ * acceptor context lifetime according to gss_inquire_context() -+ * acceptor context lifetime according to gss_context_time() -+ */ -+ -+static void -+display_time(OM_uint32 tval) -+{ -+ if (tval == GSS_C_INDEFINITE) -+ puts("indefinite"); -+ else -+ printf("%u\n", (unsigned int)tval); -+} -+ -+int -+main(int argc, char *argv[]) -+{ -+ OM_uint32 minor, major; -+ gss_cred_id_t icred, acred; -+ gss_name_t tname; -+ gss_ctx_id_t ictx = GSS_C_NO_CONTEXT, actx = GSS_C_NO_CONTEXT; -+ gss_buffer_desc itok = GSS_C_EMPTY_BUFFER, atok = GSS_C_EMPTY_BUFFER; -+ OM_uint32 time_req = GSS_C_INDEFINITE, time_rec; -+ -+ if (argc < 2 || argc > 3) { -+ fprintf(stderr, "Usage: %s targetname [time_req]\n", argv[0]); -+ return 1; -+ } -+ tname = import_name(argv[1]); -+ if (argc >= 3) -+ time_req = atoll(argv[2]); -+ -+ /* Get initiator cred and display its lifetime according to -+ * gss_acquire_cred and gss_inquire_cred. */ -+ major = gss_acquire_cred(&minor, GSS_C_NO_NAME, time_req, &mechset_krb5, -+ GSS_C_INITIATE, &icred, NULL, &time_rec); -+ check_gsserr("gss_acquire_cred(initiate)", major, minor); -+ display_time(time_rec); -+ major = gss_inquire_cred(&minor, icred, NULL, &time_rec, NULL, NULL); -+ check_gsserr("gss_inquire_cred(initiate)", major, minor); -+ display_time(time_rec); -+ -+ /* Get acceptor cred and display its lifetime according to gss_acquire_cred -+ * and gss_inquire_cred. */ -+ major = gss_acquire_cred(&minor, GSS_C_NO_NAME, time_req, &mechset_krb5, -+ GSS_C_ACCEPT, &acred, NULL, &time_rec); -+ check_gsserr("gss_acquire_cred(accept)", major, minor); -+ display_time(time_rec); -+ major = gss_inquire_cred(&minor, acred, NULL, &time_rec, NULL, NULL); -+ check_gsserr("gss_inquire_cred(accept)", major, minor); -+ display_time(time_rec); -+ -+ /* Make an initiator context and display its lifetime according to -+ * gss_init_sec_context, gss_inquire_context, and gss_context_time. */ -+ major = gss_init_sec_context(&minor, icred, &ictx, tname, &mech_krb5, 0, -+ time_req, GSS_C_NO_CHANNEL_BINDINGS, &atok, -+ NULL, &itok, NULL, &time_rec); -+ check_gsserr("gss_init_sec_context", major, minor); -+ assert(major == GSS_S_COMPLETE); -+ display_time(time_rec); -+ major = gss_inquire_context(&minor, ictx, NULL, NULL, &time_rec, NULL, -+ NULL, NULL, NULL); -+ check_gsserr("gss_inquire_context(initiate)", major, minor); -+ display_time(time_rec); -+ major = gss_context_time(&minor, ictx, &time_rec); -+ check_gsserr("gss_context_time(initiate)", major, minor); -+ display_time(time_rec); -+ -+ major = gss_accept_sec_context(&minor, &actx, acred, &itok, -+ GSS_C_NO_CHANNEL_BINDINGS, NULL, -+ NULL, &atok, NULL, &time_rec, NULL); -+ check_gsserr("gss_accept_sec_context", major, minor); -+ assert(major == GSS_S_COMPLETE); -+ display_time(time_rec); -+ major = gss_inquire_context(&minor, actx, NULL, NULL, &time_rec, NULL, -+ NULL, NULL, NULL); -+ check_gsserr("gss_inquire_context(accept)", major, minor); -+ display_time(time_rec); -+ major = gss_context_time(&minor, actx, &time_rec); -+ check_gsserr("gss_context_time(accept)", major, minor); -+ display_time(time_rec); -+ -+ (void)gss_release_buffer(&minor, &itok); -+ (void)gss_release_buffer(&minor, &atok); -+ (void)gss_release_name(&minor, &tname); -+ (void)gss_release_cred(&minor, &icred); -+ (void)gss_release_cred(&minor, &acred); -+ (void)gss_delete_sec_context(&minor, &ictx, NULL); -+ (void)gss_delete_sec_context(&minor, &actx, NULL); -+ return 0; -+} -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 44635b089..ffc043709 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -414,6 +414,13 @@ realm.run([kadminl, 'addprinc', '-policy', 'keepoldpasspol', '-pw', 'aaaa', - for p in ('bbbb', 'cccc', 'aaaa'): - realm.run([kadminl, 'cpw', '-keepold', '-pw', p, 'keepoldpassprinc']) - -+if runenv.sizeof_time_t <= 4: -+ skipped('y2038 LDAP test', 'platform has 32-bit time_t') -+else: -+ # Test storage of timestamps after y2038. -+ realm.run([kadminl, 'modprinc', '-pwexpire', '2040-02-03', 'user']) -+ realm.run([kadminl, 'getprinc', 'user'], expected_msg=' 2040\n') -+ - realm.stop() - - # Briefly test dump and load. -diff --git a/src/tests/t_y2038.py b/src/tests/t_y2038.py -new file mode 100644 -index 000000000..02e946df4 ---- /dev/null -+++ b/src/tests/t_y2038.py -@@ -0,0 +1,75 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# These tests will become much less important after the y2038 boundary -+# has elapsed, and may start exhibiting problems around the year 2075. -+ -+if runenv.sizeof_time_t <= 4: -+ skip_rest('y2038 timestamp tests', 'platform has 32-bit time_t') -+ -+# Start a KDC running roughly 21 years in the future, after the y2038 -+# boundary. Set long maximum lifetimes for later tests. -+conf = {'realms': {'$realm': {'max_life': '9000d', -+ 'max_renewable_life': '9000d'}}} -+realm = K5Realm(start_kdc=False, kdc_conf=conf) -+realm.start_kdc(['-T', '662256000']) -+ -+# kinit without preauth should succeed with clock skew correction, but -+# will result in an expired ticket, because we sent an absolute end -+# time and didn't get a chance to correct it.. -+realm.kinit(realm.user_princ, password('user')) -+realm.run([kvno, realm.host_princ], expected_code=1, -+ expected_msg='Ticket expired') -+ -+# kinit with preauth should succeed and result in a valid ticket, as -+# we get a chance to correct the end time based on the KDC time. Try -+# with encrypted timestamp and encrypted challenge. -+realm.run([kadminl, 'modprinc', '+requires_preauth', 'user']) -+realm.kinit(realm.user_princ, password('user')) -+realm.run([kvno, realm.host_princ]) -+realm.kinit(realm.user_princ, password('user'), flags=['-T', realm.ccache]) -+realm.run([kvno, realm.host_princ]) -+ -+# Test that expiration warning works after y2038, by setting a -+# password expiration time ten minutes after the KDC time. -+realm.run([kadminl, 'modprinc', '-pwexpire', '662256600 seconds', 'user']) -+out = realm.kinit(realm.user_princ, password('user')) -+if 'will expire in less than one hour' not in out: -+ fail('password expiration message') -+year = int(out.split()[-1]) -+if year < 2038 or year > 9999: -+ fail('password expiration year') -+ -+realm.stop_kdc() -+realm.start_kdc() -+realm.start_kadmind() -+realm.prep_kadmin() -+ -+# Test getdate parsing of absolute timestamps after 2038 and -+# marshalling over the kadmin protocol. The local time zone will -+# affect the display time by a little bit, so just look for the year. -+realm.run_kadmin(['modprinc', '-pwexpire', '2040-02-03', realm.host_princ]) -+realm.run_kadmin(['getprinc', realm.host_princ], expected_msg=' 2040\n') -+ -+# Get a ticket whose lifetime crosses the y2038 boundary and -+# range-check the expiration year as reported by klist. -+realm.kinit(realm.user_princ, password('user'), -+ flags=['-l', '8000d', '-r', '8500d']) -+realm.run([kvno, realm.host_princ]) -+out = realm.run([klist]) -+if int(out.split('\n')[4].split()[2].split('/')[2]) < 39: -+ fail('unexpected tgt expiration year') -+if int(out.split('\n')[5].split()[2].split('/')[2]) < 40: -+ fail('unexpected tgt rtill year') -+if int(out.split('\n')[6].split()[2].split('/')[2]) < 39: -+ fail('unexpected service ticket expiration year') -+if int(out.split('\n')[7].split()[2].split('/')[2]) < 40: -+ fail('unexpected service ticket rtill year') -+realm.kinit(realm.user_princ, None, ['-R']) -+out = realm.run([klist]) -+if int(out.split('\n')[4].split()[2].split('/')[2]) < 39: -+ fail('unexpected renewed tgt expiration year') -+if int(out.split('\n')[5].split()[2].split('/')[2]) < 40: -+ fail('unexpected renewed tgt rtill year') -+ -+success('y2038 tests') diff --git a/Add-y2038-documentation.patch b/Add-y2038-documentation.patch deleted file mode 100644 index 693a1fb..0000000 --- a/Add-y2038-documentation.patch +++ /dev/null @@ -1,59 +0,0 @@ -From 69ca5ff168f24792924b3cab0a9f27ada3eb4c4b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 4 May 2017 17:03:35 -0400 -Subject: [PATCH] Add y2038 documentation - -ticket: 8352 -(cherry picked from commit 85d64c43dbf7a7faa56a1999494cdfa49e8bd2c9) ---- - doc/appdev/index.rst | 1 + - doc/appdev/y2038.rst | 28 ++++++++++++++++++++++++++++ - 2 files changed, 29 insertions(+) - create mode 100644 doc/appdev/y2038.rst - -diff --git a/doc/appdev/index.rst b/doc/appdev/index.rst -index 3d62045ca..961bb1e9e 100644 ---- a/doc/appdev/index.rst -+++ b/doc/appdev/index.rst -@@ -5,6 +5,7 @@ For application developers - :maxdepth: 1 - - gssapi.rst -+ y2038.rst - h5l_mit_apidiff.rst - init_creds.rst - princ_handle.rst -diff --git a/doc/appdev/y2038.rst b/doc/appdev/y2038.rst -new file mode 100644 -index 000000000..bc4122dad ---- /dev/null -+++ b/doc/appdev/y2038.rst -@@ -0,0 +1,28 @@ -+Year 2038 considerations for uses of krb5_timestamp -+=================================================== -+ -+POSIX time values, which measure the number of seconds since January 1 -+1970, will exceed the maximum value representable in a signed 32-bit -+integer in January 2038. This documentation describes considerations -+for consumers of the MIT krb5 libraries. -+ -+Applications or libraries which use libkrb5 and consume the timestamps -+included in credentials or other structures make use of the -+:c:type:`krb5_timestamp` type. For historical reasons, krb5_timestamp -+is a signed 32-bit integer, even on platforms where a larger type is -+natively used to represent time values. To behave properly for time -+values after January 2038, calling code should cast krb5_timestamp -+values to uint32_t, and then to time_t:: -+ -+ (time_t)(uint32_t)timestamp -+ -+Used in this way, krb5_timestamp values can represent time values up -+until February 2106, provided that the platform uses a 64-bit or -+larger time_t type. This usage will also remain safe if a later -+version of MIT krb5 changes krb5_timestamp to an unsigned 32-bit -+integer. -+ -+The GSSAPI only uses representations of time intervals, not absolute -+times. Callers of the GSSAPI should require no changes to behave -+correctly after January 2038, provided that they use MIT krb5 release -+1.16 or later. diff --git a/Build-with-Werror-implicit-int-where-supported.patch b/Build-with-Werror-implicit-int-where-supported.patch deleted file mode 100644 index 30e3ba8..0000000 --- a/Build-with-Werror-implicit-int-where-supported.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 5f2ea38f7ecd60184e510558bdb551d0153432e0 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 10 Nov 2016 13:20:49 -0500 -Subject: [PATCH] Build with -Werror-implicit-int where supported - -(cherry picked from commit 873d864230c9c64c65ff12a24199bac3adf3bc2f) ---- - src/aclocal.m4 | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 2bfb99496..da1d6d8b4 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -529,7 +529,7 @@ if test "$GCC" = yes ; then - TRY_WARN_CC_FLAG(-Wno-format-zero-length) - # Other flags here may not be supported on some versions of - # gcc that people want to use. -- for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers ; do -+ for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int ; do - TRY_WARN_CC_FLAG(-W$flag) - done - # old-style-definition? generates many, many warnings diff --git a/Convert-some-pkiDebug-messages-to-TRACE-macros.patch b/Convert-some-pkiDebug-messages-to-TRACE-macros.patch deleted file mode 100644 index e9e27df..0000000 --- a/Convert-some-pkiDebug-messages-to-TRACE-macros.patch +++ /dev/null @@ -1,422 +0,0 @@ -From 686fa6476eb759532d566794fa8d430774d44cf7 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Wed, 29 Mar 2017 10:35:13 -0400 -Subject: [PATCH] Convert some pkiDebug messages to TRACE macros - -ticket: 8568 (new) -(cherry picked from commit 9852862a83952a94300adfafa3e333f43396ec33) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 46 ++++++--------- - src/plugins/preauth/pkinit/pkinit_identity.c | 3 - - src/plugins/preauth/pkinit/pkinit_matching.c | 1 + - src/plugins/preauth/pkinit/pkinit_srv.c | 24 ++++---- - src/plugins/preauth/pkinit/pkinit_trace.h | 68 +++++++++++++++++++++- - 5 files changed, 97 insertions(+), 45 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 90c30dbf5..70e230ec2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2320,7 +2320,6 @@ crypto_check_cert_eku(krb5_context context, - - X509_NAME_oneline(X509_get_subject_name(reqctx->received_cert), - buf, sizeof(buf)); -- pkiDebug("%s: looking for EKUs in cert = %s\n", __FUNCTION__, buf); - - if ((i = X509_get_ext_by_NID(reqctx->received_cert, - NID_ext_key_usage, -1)) >= 0) { -@@ -2354,7 +2353,6 @@ crypto_check_cert_eku(krb5_context context, - - if (found_eku) { - ASN1_BIT_STRING *usage = NULL; -- pkiDebug("%s: found acceptable EKU, checking for digitalSignature\n", __FUNCTION__); - - /* check that digitalSignature KeyUsage is present */ - X509_check_ca(reqctx->received_cert); -@@ -2363,12 +2361,10 @@ crypto_check_cert_eku(krb5_context context, - - if (!ku_reject(reqctx->received_cert, - X509v3_KU_DIGITAL_SIGNATURE)) { -- pkiDebug("%s: found digitalSignature KU\n", -- __FUNCTION__); -+ TRACE_PKINIT_EKU(context); - *valid_eku = 1; - } else -- pkiDebug("%s: didn't find digitalSignature KU\n", -- __FUNCTION__); -+ TRACE_PKINIT_EKU_NO_KU(context); - } - ASN1_BIT_STRING_free(usage); - } -@@ -4317,8 +4313,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - - fp = fopen(idopts->cert_filename, "rb"); - if (fp == NULL) { -- pkiDebug("Failed to open PKCS12 file '%s', error %d\n", -- idopts->cert_filename, errno); -+ TRACE_PKINIT_PKCS_OPEN_FAIL(context, idopts->cert_filename, errno); - goto cleanup; - } - set_cloexec_file(fp); -@@ -4326,8 +4321,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - p12 = d2i_PKCS12_fp(fp, NULL); - fclose(fp); - if (p12 == NULL) { -- pkiDebug("Failed to decode PKCS12 file '%s' contents\n", -- idopts->cert_filename); -+ TRACE_PKINIT_PKCS_DECODE_FAIL(context, idopts->cert_filename); - goto cleanup; - } - /* -@@ -4345,7 +4339,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - char *p12name = reassemble_pkcs12_name(idopts->cert_filename); - const char *tmp; - -- pkiDebug("Initial PKCS12_parse with no password failed\n"); -+ TRACE_PKINIT_PKCS_PARSE_FAIL_FIRST(context); - - if (id_cryptoctx->defer_id_prompt) { - /* Supply the identity name to be passed to the responder. */ -@@ -4386,14 +4380,14 @@ pkinit_get_certs_pkcs12(krb5_context context, - NULL, NULL, 1, &kprompt); - k5int_set_prompt_types(context, 0); - if (r) { -- pkiDebug("Failed to prompt for PKCS12 password"); -+ TRACE_PKINIT_PKCS_PROMPT_FAIL(context); - goto cleanup; - } - } - - ret = PKCS12_parse(p12, rdat.data, &y, &x, NULL); - if (ret == 0) { -- pkiDebug("Second PKCS12_parse with password failed\n"); -+ TRACE_PKINIT_PKCS_PARSE_FAIL_SECOND(context); - goto cleanup; - } - } -@@ -4516,8 +4510,7 @@ pkinit_get_certs_fs(krb5_context context, - } - - if (idopts->key_filename == NULL) { -- pkiDebug("%s: failed to get user's private key location\n", -- __FUNCTION__); -+ TRACE_PKINIT_NO_PRIVKEY(context); - goto cleanup; - } - -@@ -4545,8 +4538,7 @@ pkinit_get_certs_dir(krb5_context context, - char *dirname, *suf; - - if (idopts->cert_filename == NULL) { -- pkiDebug("%s: failed to get user's certificate directory location\n", -- __FUNCTION__); -+ TRACE_PKINIT_NO_CERT(context); - return ENOENT; - } - -@@ -4590,8 +4582,7 @@ pkinit_get_certs_dir(krb5_context context, - retval = pkinit_load_fs_cert_and_key(context, id_cryptoctx, - certname, keyname, i); - if (retval == 0) { -- pkiDebug("%s: Successfully loaded cert (and key) for %s\n", -- __FUNCTION__, dentry->d_name); -+ TRACE_PKINIT_LOADED_CERT(context, dentry->d_name); - i++; - } - else -@@ -4599,8 +4590,7 @@ pkinit_get_certs_dir(krb5_context context, - } - - if (!id_cryptoctx->defer_id_prompt && i == 0) { -- pkiDebug("%s: No cert/key pairs found in directory '%s'\n", -- __FUNCTION__, idopts->cert_filename); -+ TRACE_PKINIT_NO_CERT_AND_KEY(context, idopts->cert_filename); - retval = ENOENT; - goto cleanup; - } -@@ -5370,9 +5360,7 @@ crypto_cert_select_default(krb5_context context, - goto errout; - } - if (cert_count != 1) { -- pkiDebug("%s: ERROR: There are %d certs to choose from, " -- "but there must be exactly one.\n", -- __FUNCTION__, cert_count); -+ TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count); - retval = EINVAL; - goto errout; - } -@@ -5520,7 +5508,7 @@ load_cas_and_crls(krb5_context context, - switch(catype) { - case CATYPE_ANCHORS: - if (sk_X509_num(ca_certs) == 0) { -- pkiDebug("no anchors in file, %s\n", filename); -+ TRACE_PKINIT_NO_CA_ANCHOR(context, filename); - if (id_cryptoctx->trustedCAs == NULL) - sk_X509_free(ca_certs); - } else { -@@ -5530,7 +5518,7 @@ load_cas_and_crls(krb5_context context, - break; - case CATYPE_INTERMEDIATES: - if (sk_X509_num(ca_certs) == 0) { -- pkiDebug("no intermediates in file, %s\n", filename); -+ TRACE_PKINIT_NO_CA_INTERMEDIATE(context, filename); - if (id_cryptoctx->intermediateCAs == NULL) - sk_X509_free(ca_certs); - } else { -@@ -5540,7 +5528,7 @@ load_cas_and_crls(krb5_context context, - break; - case CATYPE_CRLS: - if (sk_X509_CRL_num(ca_crls) == 0) { -- pkiDebug("no crls in file, %s\n", filename); -+ TRACE_PKINIT_NO_CRL(context, filename); - if (id_cryptoctx->revoked == NULL) - sk_X509_CRL_free(ca_crls); - } else { -@@ -5626,14 +5614,14 @@ crypto_load_cas_and_crls(krb5_context context, - int catype, - char *id) - { -- pkiDebug("%s: called with idtype %s and catype %s\n", -- __FUNCTION__, idtype2string(idtype), catype2string(catype)); - switch (idtype) { - case IDTYPE_FILE: -+ TRACE_PKINIT_LOAD_FROM_FILE(context); - return load_cas_and_crls(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx, catype, id); - break; - case IDTYPE_DIR: -+ TRACE_PKINIT_LOAD_FROM_DIR(context); - return load_cas_and_crls_dir(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx, catype, id); - break; -diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c -index a897efa25..737552e85 100644 ---- a/src/plugins/preauth/pkinit/pkinit_identity.c -+++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -608,7 +608,6 @@ pkinit_identity_prompt(krb5_context context, - retval = pkinit_cert_matching(context, plg_cryptoctx, - req_cryptoctx, id_cryptoctx, princ); - if (retval) { -- pkiDebug("%s: No matching certificate found\n", __FUNCTION__); - crypto_free_cert_info(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx); - goto errout; -@@ -621,8 +620,6 @@ pkinit_identity_prompt(krb5_context context, - retval = crypto_cert_select_default(context, plg_cryptoctx, - req_cryptoctx, id_cryptoctx); - if (retval) { -- pkiDebug("%s: Failed while selecting default certificate\n", -- __FUNCTION__); - crypto_free_cert_info(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx); - goto errout; -diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c -index a50c50c8d..cad4c2b9a 100644 ---- a/src/plugins/preauth/pkinit/pkinit_matching.c -+++ b/src/plugins/preauth/pkinit/pkinit_matching.c -@@ -812,6 +812,7 @@ pkinit_cert_matching(krb5_context context, - goto cleanup; - } - } else { -+ TRACE_PKINIT_NO_MATCHING_CERT(context); - retval = ENOENT; /* XXX */ - goto cleanup; - } -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 32ca122f2..9c6e96c9e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -188,6 +188,7 @@ verify_client_san(krb5_context context, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); - if (retval == ENOENT) { -+ TRACE_PKINIT_SERVER_NO_SAN(context); - goto out; - } else if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); -@@ -224,7 +225,7 @@ verify_client_san(krb5_context context, - krb5_free_unparsed_name(context, san_string); - #endif - if (cb->match_client(context, rock, princs[i])) { -- pkiDebug("%s: pkinit san match found\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_MATCHING_SAN_FOUND(context); - *valid_san = 1; - retval = 0; - goto out; -@@ -252,7 +253,7 @@ verify_client_san(krb5_context context, - krb5_free_unparsed_name(context, san_string); - #endif - if (cb->match_client(context, rock, upns[i])) { -- pkiDebug("%s: upn san match found\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(context); - *valid_san = 1; - retval = 0; - goto out; -@@ -300,7 +301,7 @@ verify_client_eku(krb5_context context, - *eku_accepted = 0; - - if (plgctx->opts->require_eku == 0) { -- pkiDebug("%s: configuration requests no EKU checking\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_EKU_SKIP(context); - *eku_accepted = 1; - retval = 0; - goto out; -@@ -364,6 +365,7 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, - ret = KRB5_PLUGIN_NO_HANDLE; - for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { - h = certauth_modules[i]; -+ TRACE_PKINIT_SERVER_CERT_AUTH(context, h->vt.name); - ret = h->vt.authorize(context, h->moddata, cert, cert_len, client, - &opts, db_ent, &ais); - if (ret == 0) -@@ -449,7 +451,7 @@ pkinit_server_verify_padata(krb5_context context, - - switch ((int)data->pa_type) { - case KRB5_PADATA_PK_AS_REQ: -- pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY(context); - retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); - if (retval) { - pkiDebug("decode_krb5_pa_pk_as_req failed\n"); -@@ -472,7 +474,7 @@ pkinit_server_verify_padata(krb5_context context, - break; - case KRB5_PADATA_PK_AS_REP_OLD: - case KRB5_PADATA_PK_AS_REQ_OLD: -- pkiDebug("processing KRB5_PADATA_PK_AS_REQ_OLD\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(context); - retval = k5int_decode_krb5_pa_pk_as_req_draft9(&k5data, &reqp9); - if (retval) { - pkiDebug("decode_krb5_pa_pk_as_req_draft9 failed\n"); -@@ -500,7 +502,7 @@ pkinit_server_verify_padata(krb5_context context, - goto cleanup; - } - if (retval) { -- pkiDebug("pkcs7_signeddata_verify failed\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); - goto cleanup; - } - if (is_signed) { -@@ -830,7 +832,7 @@ pkinit_server_return_padata(krb5_context context, - return ENOENT; - } - -- pkiDebug("pkinit_return_padata: entered!\n"); -+ TRACE_PKINIT_SERVER_RETURN_PADATA(context); - reqctx = (pkinit_kdc_req_context)modreq; - - if (encrypting_key->contents) { -@@ -1463,8 +1465,7 @@ pkinit_san_authorize(krb5_context context, krb5_certauth_moddata moddata, - return ret; - - if (!valid_san) { -- pkiDebug("%s: did not find an acceptable SAN in user certificate\n", -- __FUNCTION__); -+ TRACE_PKINIT_SERVER_SAN_REJECT(context); - return KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - } - -@@ -1490,8 +1491,7 @@ pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, - return ret; - - if (!valid_eku) { -- pkiDebug("%s: did not find an acceptable EKU in user certificate\n", -- __FUNCTION__); -+ TRACE_PKINIT_SERVER_EKU_REJECT(context); - return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; - } - -@@ -1617,7 +1617,7 @@ pkinit_server_plugin_init(krb5_context context, - return ENOMEM; - - for (i = 0, j = 0; i < numrealms; i++) { -- pkiDebug("%s: processing realm '%s'\n", __FUNCTION__, realmnames[i]); -+ TRACE_PKINIT_SERVER_INIT_REALM(context, realmnames[i]); - retval = pkinit_server_plugin_init_realm(context, realmnames[i], &plgctx); - if (retval == 0 && plgctx != NULL) - realm_contexts[j++] = plgctx; -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index 458d0961e..6abe28c0c 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -52,7 +52,7 @@ - #define TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(c, expected, received) \ - TRACE(c, "PKINIT client checksum mismatch: expected {cksum}, " \ - "received {cksum}", expected, received) --#define TRACE_PKINIT_CLIENT_REP_DH(c) \ -+#define TRACE_PKINIT_CLIENT_REP_DH(c) \ - TRACE(c, "PKINIT client verified DH reply") - #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ - TRACE(c, "PKINIT client could not verify DH reply") -@@ -91,6 +91,72 @@ - #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ - TRACE(c, "PKINIT OpenSSL error: {str}", msg) - -+#define TRACE_PKINIT_SERVER_CERT_AUTH(c, modname) \ -+ TRACE(c, "PKINIT server authorizing cert with module {str}", \ -+ modname) -+#define TRACE_PKINIT_SERVER_EKU_REJECT(c) \ -+ TRACE(c, "PKINIT server found no acceptable EKU in client cert") -+#define TRACE_PKINIT_SERVER_EKU_SKIP(c) \ -+ TRACE(c, "PKINIT server skipping EKU check due to configuration") -+#define TRACE_PKINIT_SERVER_INIT_REALM(c, realm) \ -+ TRACE(c, "PKINIT server initializing realm {str}", realm) -+#define TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(c) \ -+ TRACE(c, "PKINIT server found a matching UPN SAN in client cert") -+#define TRACE_PKINIT_SERVER_MATCHING_SAN_FOUND(c) \ -+ TRACE(c, "PKINIT server found a matching SAN in client cert") -+#define TRACE_PKINIT_SERVER_NO_SAN(c) \ -+ TRACE(c, "PKINIT server found no SAN in client cert") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY(c) \ -+ TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(c) \ -+ TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ_OLD") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(c) \ -+ TRACE(c, "PKINIT server failed to verify PA data") -+#define TRACE_PKINIT_SERVER_RETURN_PADATA(c) \ -+ TRACE(c, "PKINIT server returning PA data") -+#define TRACE_PKINIT_SERVER_SAN_REJECT(c) \ -+ TRACE(c, "PKINIT server found no acceptable SAN in client cert") -+ -+#define TRACE_PKINIT_EKU(c) \ -+ TRACE(c, "PKINIT found acceptable EKU and digitalSignature KU") -+#define TRACE_PKINIT_EKU_NO_KU(c) \ -+ TRACE(c, "PKINIT found acceptable EKU but no digitalSignature KU") -+#define TRACE_PKINIT_LOADED_CERT(c, name) \ -+ TRACE(c, "PKINIT loaded cert and key for {str}", name) -+#define TRACE_PKINIT_LOAD_FROM_FILE(c) \ -+ TRACE(c, "PKINIT loading CA certs and CRLs from FILE") -+#define TRACE_PKINIT_LOAD_FROM_DIR(c) \ -+ TRACE(c, "PKINIT loading CA certs and CRLs from DIR") -+#define TRACE_PKINIT_NO_CA_ANCHOR(c, file) \ -+ TRACE(c, "PKINIT no anchor CA in file {str}", file) -+#define TRACE_PKINIT_NO_CA_INTERMEDIATE(c, file) \ -+ TRACE(c, "PKINIT no intermediate CA in file {str}", file) -+#define TRACE_PKINIT_NO_CERT(c) \ -+ TRACE(c, "PKINIT no certificate provided") -+#define TRACE_PKINIT_NO_CERT_AND_KEY(c, dirname) \ -+ TRACE(c, "PKINIT no cert and key pair found in directory {str}", \ -+ dirname) -+#define TRACE_PKINIT_NO_CRL(c, file) \ -+ TRACE(c, "PKINIT no CRL in file {str}", file) -+#define TRACE_PKINIT_NO_DEFAULT_CERT(c, count) \ -+ TRACE(c, "PKINIT error: There are {int} certs, but there must " \ -+ "be exactly one.", count) -+#define TRACE_PKINIT_NO_MATCHING_CERT(c) \ -+ TRACE(c, "PKINIT no matching certificate found") -+#define TRACE_PKINIT_NO_PRIVKEY(c) \ -+ TRACE(c, "PKINIT no private key provided") -+#define TRACE_PKINIT_PKCS_DECODE_FAIL(c, name) \ -+ TRACE(c, "PKINIT failed to decode PKCS12 file {str} contents", name) -+#define TRACE_PKINIT_PKCS_OPEN_FAIL(c, name, err) \ -+ TRACE(c, "PKINIT failed to open PKCS12 file {str}: err {errno}", \ -+ name, err) -+#define TRACE_PKINIT_PKCS_PARSE_FAIL_FIRST(c) \ -+ TRACE(c, "PKINIT initial PKCS12_parse with no password failed") -+#define TRACE_PKINIT_PKCS_PARSE_FAIL_SECOND(c) \ -+ TRACE(c, "PKINIT second PKCS12_parse with password failed") -+#define TRACE_PKINIT_PKCS_PROMPT_FAIL(c) \ -+ TRACE(c, "PKINIT failed to prompt for PKCS12 password") -+ - #define TRACE_CERTAUTH_VTINIT_FAIL(c, ret) \ - TRACE(c, "certauth module failed to init vtable: {kerr}", ret) - #define TRACE_CERTAUTH_INIT_FAIL(c, name, ret) \ diff --git a/Correct-error-handling-bug-in-prior-commit.patch b/Correct-error-handling-bug-in-prior-commit.patch deleted file mode 100644 index 6878e8c..0000000 --- a/Correct-error-handling-bug-in-prior-commit.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 08d995aaf48e75c174525ae0b47e12c3170b3f5f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 23 Mar 2017 13:42:55 -0400 -Subject: [PATCH] Correct error handling bug in prior commit - -In crypto_encode_der_cert(), if the second i2d_X509() invocation -fails, make sure to free the allocated pointer and not the -possibly-modified alias. - -ticket: 8561 -(cherry picked from commit 7fdaef7c3280c86b5df25ae061fb04cc56d8620c) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index a5b010b26..90c30dbf5 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -6196,10 +6196,10 @@ crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, - if (len <= 0) - return EINVAL; - p = der = malloc(len); -- if (p == NULL) -+ if (der == NULL) - return ENOMEM; - if (i2d_X509(reqctx->received_cert, &p) <= 0) { -- free(p); -+ free(der); - return EINVAL; - } - *der_out = der; diff --git a/Deindent-crypto_retrieve_X509_sans.patch b/Deindent-crypto_retrieve_X509_sans.patch deleted file mode 100644 index 9262e7d..0000000 --- a/Deindent-crypto_retrieve_X509_sans.patch +++ /dev/null @@ -1,263 +0,0 @@ -From d5462c96c9918ffa7d3f05de310c5aed34181941 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 4 Jan 2017 11:33:57 -0500 -Subject: [PATCH] Deindent crypto_retrieve_X509_sans() - -Fix some long lines in crypto_retrieve_X509_sans() by returning early -if X509_get_ext_by_NID() returns a negative result. Also ensure that -return parameters are always initialized. - -(cherry picked from commit c6b772523db9d7791ee1c56eb512c4626556a4e7) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 224 +++++++++++---------- - 1 file changed, 114 insertions(+), 110 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index bc6e7662e..8def8c542 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2101,11 +2101,21 @@ crypto_retrieve_X509_sans(krb5_context context, - { - krb5_error_code retval = EINVAL; - char buf[DN_BUF_LEN]; -- int p = 0, u = 0, d = 0, l; -+ int p = 0, u = 0, d = 0, ret = 0, l; - krb5_principal *princs = NULL; - krb5_principal *upns = NULL; - unsigned char **dnss = NULL; -- unsigned int i, num_found = 0; -+ unsigned int i, num_found = 0, num_sans = 0; -+ X509_EXTENSION *ext = NULL; -+ GENERAL_NAMES *ialt = NULL; -+ GENERAL_NAME *gen = NULL; -+ -+ if (princs_ret != NULL) -+ *princs_ret = NULL; -+ if (upn_ret != NULL) -+ *upn_ret = NULL; -+ if (dns_ret != NULL) -+ *dns_ret = NULL; - - if (princs_ret == NULL && upn_ret == NULL && dns_ret == NULL) { - pkiDebug("%s: nowhere to return any values!\n", __FUNCTION__); -@@ -2121,118 +2131,112 @@ crypto_retrieve_X509_sans(krb5_context context, - buf, sizeof(buf)); - pkiDebug("%s: looking for SANs in cert = %s\n", __FUNCTION__, buf); - -- if ((l = X509_get_ext_by_NID(cert, NID_subject_alt_name, -1)) >= 0) { -- X509_EXTENSION *ext = NULL; -- GENERAL_NAMES *ialt = NULL; -- GENERAL_NAME *gen = NULL; -- int ret = 0; -- unsigned int num_sans = 0; -+ l = X509_get_ext_by_NID(cert, NID_subject_alt_name, -1); -+ if (l < 0) -+ return 0; - -- if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { -- pkiDebug("%s: found no subject alt name extensions\n", -- __FUNCTION__); -+ if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { -+ pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -+ goto cleanup; -+ } -+ num_sans = sk_GENERAL_NAME_num(ialt); -+ -+ pkiDebug("%s: found %d subject alt name extension(s)\n", __FUNCTION__, -+ num_sans); -+ -+ /* OK, we're likely returning something. Allocate return values */ -+ if (princs_ret != NULL) { -+ princs = calloc(num_sans + 1, sizeof(krb5_principal)); -+ if (princs == NULL) { -+ retval = ENOMEM; - goto cleanup; - } -- num_sans = sk_GENERAL_NAME_num(ialt); -- -- pkiDebug("%s: found %d subject alt name extension(s)\n", -- __FUNCTION__, num_sans); -- -- /* OK, we're likely returning something. Allocate return values */ -- if (princs_ret != NULL) { -- princs = calloc(num_sans + 1, sizeof(krb5_principal)); -- if (princs == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- if (upn_ret != NULL) { -- upns = calloc(num_sans + 1, sizeof(krb5_principal)); -- if (upns == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- if (dns_ret != NULL) { -- dnss = calloc(num_sans + 1, sizeof(*dnss)); -- if (dnss == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- -- for (i = 0; i < num_sans; i++) { -- krb5_data name = { 0, 0, NULL }; -- -- gen = sk_GENERAL_NAME_value(ialt, i); -- switch (gen->type) { -- case GEN_OTHERNAME: -- name.length = gen->d.otherName->value->value.sequence->length; -- name.data = (char *)gen->d.otherName->value->value.sequence->data; -- if (princs != NULL -- && OBJ_cmp(plgctx->id_pkinit_san, -- gen->d.otherName->type_id) == 0) { --#ifdef DEBUG_ASN1 -- print_buffer_bin((unsigned char *)name.data, name.length, -- "/tmp/pkinit_san"); --#endif -- ret = k5int_decode_krb5_principal_name(&name, &princs[p]); -- if (ret) { -- pkiDebug("%s: failed decoding pkinit san value\n", -- __FUNCTION__); -- } else { -- p++; -- num_found++; -- } -- } else if (upns != NULL -- && OBJ_cmp(plgctx->id_ms_san_upn, -- gen->d.otherName->type_id) == 0) { -- /* Prevent abuse of embedded null characters. */ -- if (memchr(name.data, '\0', name.length)) -- break; -- ret = krb5_parse_name_flags(context, name.data, -- KRB5_PRINCIPAL_PARSE_ENTERPRISE, -- &upns[u]); -- if (ret) { -- pkiDebug("%s: failed parsing ms-upn san value\n", -- __FUNCTION__); -- } else { -- u++; -- num_found++; -- } -- } else { -- pkiDebug("%s: unrecognized othername oid in SAN\n", -- __FUNCTION__); -- continue; -- } -- -- break; -- case GEN_DNS: -- if (dnss != NULL) { -- /* Prevent abuse of embedded null characters. */ -- if (memchr(gen->d.dNSName->data, '\0', -- gen->d.dNSName->length)) -- break; -- pkiDebug("%s: found dns name = %s\n", -- __FUNCTION__, gen->d.dNSName->data); -- dnss[d] = (unsigned char *) -- strdup((char *)gen->d.dNSName->data); -- if (dnss[d] == NULL) { -- pkiDebug("%s: failed to duplicate dns name\n", -- __FUNCTION__); -- } else { -- d++; -- num_found++; -- } -- } -- break; -- default: -- pkiDebug("%s: SAN type = %d expecting %d\n", -- __FUNCTION__, gen->type, GEN_OTHERNAME); -- } -- } -- sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - } -+ if (upn_ret != NULL) { -+ upns = calloc(num_sans + 1, sizeof(krb5_principal)); -+ if (upns == NULL) { -+ retval = ENOMEM; -+ goto cleanup; -+ } -+ } -+ if (dns_ret != NULL) { -+ dnss = calloc(num_sans + 1, sizeof(*dnss)); -+ if (dnss == NULL) { -+ retval = ENOMEM; -+ goto cleanup; -+ } -+ } -+ -+ for (i = 0; i < num_sans; i++) { -+ krb5_data name = { 0, 0, NULL }; -+ -+ gen = sk_GENERAL_NAME_value(ialt, i); -+ switch (gen->type) { -+ case GEN_OTHERNAME: -+ name.length = gen->d.otherName->value->value.sequence->length; -+ name.data = (char *)gen->d.otherName->value->value.sequence->data; -+ if (princs != NULL && -+ OBJ_cmp(plgctx->id_pkinit_san, -+ gen->d.otherName->type_id) == 0) { -+#ifdef DEBUG_ASN1 -+ print_buffer_bin((unsigned char *)name.data, name.length, -+ "/tmp/pkinit_san"); -+#endif -+ ret = k5int_decode_krb5_principal_name(&name, &princs[p]); -+ if (ret) { -+ pkiDebug("%s: failed decoding pkinit san value\n", -+ __FUNCTION__); -+ } else { -+ p++; -+ num_found++; -+ } -+ } else if (upns != NULL && -+ OBJ_cmp(plgctx->id_ms_san_upn, -+ gen->d.otherName->type_id) == 0) { -+ /* Prevent abuse of embedded null characters. */ -+ if (memchr(name.data, '\0', name.length)) -+ break; -+ ret = krb5_parse_name_flags(context, name.data, -+ KRB5_PRINCIPAL_PARSE_ENTERPRISE, -+ &upns[u]); -+ if (ret) { -+ pkiDebug("%s: failed parsing ms-upn san value\n", -+ __FUNCTION__); -+ } else { -+ u++; -+ num_found++; -+ } -+ } else { -+ pkiDebug("%s: unrecognized othername oid in SAN\n", -+ __FUNCTION__); -+ continue; -+ } -+ -+ break; -+ case GEN_DNS: -+ if (dnss != NULL) { -+ /* Prevent abuse of embedded null characters. */ -+ if (memchr(gen->d.dNSName->data, '\0', gen->d.dNSName->length)) -+ break; -+ pkiDebug("%s: found dns name = %s\n", __FUNCTION__, -+ gen->d.dNSName->data); -+ dnss[d] = (unsigned char *) -+ strdup((char *)gen->d.dNSName->data); -+ if (dnss[d] == NULL) { -+ pkiDebug("%s: failed to duplicate dns name\n", -+ __FUNCTION__); -+ } else { -+ d++; -+ num_found++; -+ } -+ } -+ break; -+ default: -+ pkiDebug("%s: SAN type = %d expecting %d\n", __FUNCTION__, -+ gen->type, GEN_OTHERNAME); -+ } -+ } -+ sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - - retval = 0; - if (princs) diff --git a/Fix-bugs-in-kdcpolicy-commit.patch b/Fix-bugs-in-kdcpolicy-commit.patch deleted file mode 100644 index c4c50a1..0000000 --- a/Fix-bugs-in-kdcpolicy-commit.patch +++ /dev/null @@ -1,130 +0,0 @@ -From c8c704cdaaa15a0908024f0917344048c0df5940 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 19 Aug 2017 19:09:24 -0400 -Subject: [PATCH] Fix bugs in kdcpolicy commit - -Commit d0969f6a8170344031ef58fd2a161190f1edfb96 added tests using -"klist ccachname -e", which does not work with a POSIX-conformant -getopt() implementation such as the one in Solaris. Fix -t_kdcpolicy.py to use "klist -e ccachename" instead. - -The tests could fail if the clock second rolled over between kinit and -kvno. Divide service ticket maximum lifetimes by 2 in the test module -to correctly exercise TGS policy restrictions and ensure that service -tickets are not constrained by the TGT end time. - -Also use the correct trace macro when a kdcpolicy module declines to -initialize (my mistake when revising the commit, noted by rharwood). - -ticket: 8606 -(cherry picked from commit 09acbd91efc6df54e1572285ffc94c6acb3a9113) ---- - src/kdc/policy.c | 2 +- - src/plugins/kdcpolicy/test/main.c | 10 +++++----- - src/tests/t_kdcpolicy.py | 13 +++++++++---- - 3 files changed, 15 insertions(+), 10 deletions(-) - -diff --git a/src/kdc/policy.c b/src/kdc/policy.c -index e49644e06..26c16f97c 100644 ---- a/src/kdc/policy.c -+++ b/src/kdc/policy.c -@@ -222,7 +222,7 @@ load_kdcpolicy_plugins(krb5_context context) - if (h->vt.init != NULL) { - ret = h->vt.init(context, &h->moddata); - if (ret == KRB5_PLUGIN_NO_HANDLE) { -- TRACE_KADM5_AUTH_INIT_SKIP(context, h->vt.name); -+ TRACE_KDCPOLICY_INIT_SKIP(context, h->vt.name); - free(h); - continue; - } -diff --git a/src/plugins/kdcpolicy/test/main.c b/src/plugins/kdcpolicy/test/main.c -index eb8fde053..86c808958 100644 ---- a/src/plugins/kdcpolicy/test/main.c -+++ b/src/plugins/kdcpolicy/test/main.c -@@ -35,7 +35,7 @@ - #include - - static krb5_error_code --output_from_indicator(const char *const *auth_indicators, -+output_from_indicator(const char *const *auth_indicators, int divisor, - krb5_deltat *lifetime_out, - krb5_deltat *renew_lifetime_out, - const char **status) -@@ -46,11 +46,11 @@ output_from_indicator(const char *const *auth_indicators, - } - - if (strcmp(auth_indicators[0], "ONE_HOUR") == 0) { -- *lifetime_out = 3600; -+ *lifetime_out = 3600 / divisor; - *renew_lifetime_out = *lifetime_out * 2; - return 0; - } else if (strcmp(auth_indicators[0], "SEVEN_HOURS") == 0) { -- *lifetime_out = 7 * 3600; -+ *lifetime_out = 7 * 3600 / divisor; - *renew_lifetime_out = *lifetime_out * 2; - return 0; - } -@@ -71,7 +71,7 @@ test_check_as(krb5_context context, krb5_kdcpolicy_moddata moddata, - *status = "LOCAL_POLICY"; - return KRB5KDC_ERR_POLICY; - } -- return output_from_indicator(auth_indicators, lifetime_out, -+ return output_from_indicator(auth_indicators, 1, lifetime_out, - renew_lifetime_out, status); - } - -@@ -87,7 +87,7 @@ test_check_tgs(krb5_context context, krb5_kdcpolicy_moddata moddata, - *status = "LOCAL_POLICY"; - return KRB5KDC_ERR_POLICY; - } -- return output_from_indicator(auth_indicators, lifetime_out, -+ return output_from_indicator(auth_indicators, 2, lifetime_out, - renew_lifetime_out, status); - } - -diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py -index 6a745b959..b5d308461 100644 ---- a/src/tests/t_kdcpolicy.py -+++ b/src/tests/t_kdcpolicy.py -@@ -18,16 +18,21 @@ realm.run([kadminl, 'addprinc', '-pw', password('fail'), 'fail']) - def verify_time(out, target_time): - times = re.findall(r'\d\d/\d\d/\d\d \d\d:\d\d:\d\d', out) - times = [datetime.strptime(t, '%m/%d/%y %H:%M:%S') for t in times] -+ divisor = 1 - while len(times) > 0: - starttime = times.pop(0) - endtime = times.pop(0) - renewtime = times.pop(0) - -- if str(endtime - starttime) != target_time: -+ if str((endtime - starttime) * divisor) != target_time: - fail('unexpected lifetime value') -- if str(renewtime - endtime) != target_time: -+ if str((renewtime - endtime) * divisor) != target_time: - fail('unexpected renewable value') - -+ # Service tickets should have half the lifetime of initial -+ # tickets. -+ divisor = 2 -+ - rflags = ['-r', '1d', '-l', '12h'] - - # Test AS+TGS success path. -@@ -35,7 +40,7 @@ realm.kinit(realm.user_princ, password('user'), - rflags + ['-X', 'indicators=SEVEN_HOURS']) - realm.run([kvno, realm.host_princ]) - realm.run(['./adata', realm.host_princ], expected_msg='+97: [SEVEN_HOURS]') --out = realm.run([klist, realm.ccache, '-e']) -+out = realm.run([klist, '-e', realm.ccache]) - verify_time(out, '7:00:00') - - # Test AS+TGS success path with different values. -@@ -43,7 +48,7 @@ realm.kinit(realm.user_princ, password('user'), - rflags + ['-X', 'indicators=ONE_HOUR']) - realm.run([kvno, realm.host_princ]) - realm.run(['./adata', realm.host_princ], expected_msg='+97: [ONE_HOUR]') --out = realm.run([klist, realm.ccache, '-e']) -+out = realm.run([klist, '-e', realm.ccache]) - verify_time(out, '1:00:00') - - # Test TGS failure path (using previous creds). diff --git a/Fix-certauth-built-in-module-returns.patch b/Fix-certauth-built-in-module-returns.patch deleted file mode 100644 index 1c927d5..0000000 --- a/Fix-certauth-built-in-module-returns.patch +++ /dev/null @@ -1,124 +0,0 @@ -From 0d93e336e2cb8319bfd3e0fa096e5ee8ea3bbbbf Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 24 Aug 2017 11:11:46 -0400 -Subject: [PATCH] Fix certauth built-in module returns - -The PKINIT certauth eku module should never authoritatively authorize -a certificate, because an extended key usage does not establish a -relationship between the certificate and any specific user; it only -establishes that the certificate was created for PKINIT client -authentication. Therefore, pkinit_eku_authorize() should return -KRB5_PLUGIN_NO_HANDLE on success, not 0. - -The certauth san module should pass if it does not find any SANs of -the types it can match against; the presence of other types of SANs -should not cause it to explicitly deny a certificate. Check for an -empty result from crypto_retrieve_cert_sans() in verify_client_san(), -instead of returning ENOENT from crypto_retrieve_cert_sans() when -there are no SANs at all. - -ticket: 8561 -(cherry picked from commit 07243f85a760fb37f0622d7ff0177db3f19ab025) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 39 ++++++++++------------ - src/plugins/preauth/pkinit/pkinit_srv.c | 14 +++++--- - 2 files changed, 27 insertions(+), 26 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 70e230ec2..7fa2efd21 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2137,7 +2137,6 @@ crypto_retrieve_X509_sans(krb5_context context, - - if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { - pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -- retval = ENOENT; - goto cleanup; - } - num_sans = sk_GENERAL_NAME_num(ialt); -@@ -2240,31 +2239,29 @@ crypto_retrieve_X509_sans(krb5_context context, - sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - - retval = 0; -- if (princs) -+ if (princs != NULL && *princs != NULL) { - *princs_ret = princs; -- if (upns) -+ princs = NULL; -+ } -+ if (upns != NULL && *upns != NULL) { - *upn_ret = upns; -- if (dnss) -+ upns = NULL; -+ } -+ if (dnss != NULL && *dnss != NULL) { - *dns_ret = dnss; -+ dnss = NULL; -+ } - - cleanup: -- if (retval) { -- if (princs != NULL) { -- for (i = 0; princs[i] != NULL; i++) -- krb5_free_principal(context, princs[i]); -- free(princs); -- } -- if (upns != NULL) { -- for (i = 0; upns[i] != NULL; i++) -- krb5_free_principal(context, upns[i]); -- free(upns); -- } -- if (dnss != NULL) { -- for (i = 0; dnss[i] != NULL; i++) -- free(dnss[i]); -- free(dnss); -- } -- } -+ for (i = 0; princs != NULL && princs[i] != NULL; i++) -+ krb5_free_principal(context, princs[i]); -+ free(princs); -+ for (i = 0; upns != NULL && upns[i] != NULL; i++) -+ krb5_free_principal(context, upns[i]); -+ free(upns); -+ for (i = 0; dnss != NULL && dnss[i] != NULL; i++) -+ free(dnss[i]); -+ free(dnss); - return retval; - } - -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 9c6e96c9e..8e77606f8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -187,14 +187,18 @@ verify_client_san(krb5_context context, - &princs, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); -- if (retval == ENOENT) { -- TRACE_PKINIT_SERVER_NO_SAN(context); -- goto out; -- } else if (retval) { -+ if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); - retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - goto out; - } -+ -+ if (princs == NULL && upns == NULL) { -+ TRACE_PKINIT_SERVER_NO_SAN(context); -+ retval = ENOENT; -+ goto out; -+ } -+ - /* XXX Verify this is consistent with client side XXX */ - #if 0 - retval = call_san_checking_plugins(context, plgctx, reqctx, princs, -@@ -1495,7 +1499,7 @@ pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, - return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; - } - -- return 0; -+ return KRB5_PLUGIN_NO_HANDLE; - } - - static krb5_error_code diff --git a/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch b/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch deleted file mode 100644 index a8a53cf..0000000 --- a/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch +++ /dev/null @@ -1,58 +0,0 @@ -From e2d34698687c00504b83e1c0deb56dc6232bef42 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 24 Apr 2017 02:02:36 -0400 -Subject: [PATCH] Fix in_clock_skew() and use it in AS client code - -Add a context parameter to the in_clock_skew() macro so that it isn't -implicitly relying on a local variable. Use it in -get_in_tkt.c:verify_as_reply(). - -(cherry picked from commit 28a07a6461bb443b7fa75cc5cb859ad0db4cbb5a) ---- - src/lib/krb5/krb/gc_via_tkt.c | 2 +- - src/lib/krb5/krb/get_in_tkt.c | 4 ++-- - src/lib/krb5/krb/int-proto.h | 3 ++- - 3 files changed, 5 insertions(+), 4 deletions(-) - -diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c -index 4c0a1a461..c85d8b8d8 100644 ---- a/src/lib/krb5/krb/gc_via_tkt.c -+++ b/src/lib/krb5/krb/gc_via_tkt.c -@@ -305,7 +305,7 @@ krb5int_process_tgs_reply(krb5_context context, - goto cleanup; - - if (!in_cred->times.starttime && -- !in_clock_skew(dec_rep->enc_part2->times.starttime, -+ !in_clock_skew(context, dec_rep->enc_part2->times.starttime, - timestamp)) { - retval = KRB5_KDCREP_SKEW; - goto cleanup; -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 54badbbc3..a058f5bd7 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -287,8 +287,8 @@ verify_as_reply(krb5_context context, - return retval; - } else { - if ((request->from == 0) && -- (labs(as_reply->enc_part2->times.starttime - time_now) -- > context->clockskew)) -+ !in_clock_skew(context, as_reply->enc_part2->times.starttime, -+ time_now)) - return (KRB5_KDCREP_SKEW); - } - return 0; -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index 6da74858e..44eca359f 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -83,7 +83,8 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - krb5_creds *in_creds, krb5_creds *mcreds, - krb5_flags *fields); - --#define in_clock_skew(date, now) (labs((date)-(now)) < context->clockskew) -+#define in_clock_skew(context, date, now) \ -+ (labs((date) - (now)) < (context)->clockskew) - - #define IS_TGS_PRINC(p) ((p)->length == 2 && \ - data_eq_string((p)->data[0], KRB5_TGS_NAME)) diff --git a/Fix-more-time-manipulations-for-y2038.patch b/Fix-more-time-manipulations-for-y2038.patch deleted file mode 100644 index a57a64c..0000000 --- a/Fix-more-time-manipulations-for-y2038.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 7b28a408650c58d0ea98fddab5034642af32fdaf Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 17 May 2017 14:52:09 -0400 -Subject: [PATCH] Fix more time manipulations for y2038 - -Use timestamp helper functions to ensure that more operations are safe -after y2038, and display the current timestamp as unsigned in -krb5int_trace(). - -ticket: 8352 -(cherry picked from commit a60db180211a383bd382afe729e9309acb8dcf53) ---- - src/kadmin/server/misc.c | 2 +- - src/kdc/dispatch.c | 2 +- - src/lib/krb5/os/c_ustime.c | 8 ++++---- - src/lib/krb5/os/trace.c | 2 +- - 4 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/kadmin/server/misc.c b/src/kadmin/server/misc.c -index 27a6376af..a75b65a26 100644 ---- a/src/kadmin/server/misc.c -+++ b/src/kadmin/server/misc.c -@@ -184,7 +184,7 @@ check_min_life(void *server_handle, krb5_principal principal, - (void) kadm5_free_principal_ent(handle->lhandle, &princ); - return (ret == KADM5_UNK_POLICY) ? 0 : ret; - } -- if((now - princ.last_pwd_change) < pol.pw_min_life && -+ if(ts_delta(now, princ.last_pwd_change) < pol.pw_min_life && - !(princ.attributes & KRB5_KDB_REQUIRES_PWCHANGE)) { - if (msg_ret != NULL) { - time_t until; -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 3a169ebc7..16a35d2be 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -104,7 +104,7 @@ reseed_random(krb5_context kdc_err_context) - if (last_os_random == 0) - last_os_random = now; - /* Grab random data from OS every hour*/ -- if (now-last_os_random >= 60 * 60) { -+ if (ts_delta(now, last_os_random) >= 60 * 60) { - krb5_c_random_os_entropy(kdc_err_context, 0, NULL); - last_os_random = now; - } -diff --git a/src/lib/krb5/os/c_ustime.c b/src/lib/krb5/os/c_ustime.c -index 871d72183..68fb381f4 100644 ---- a/src/lib/krb5/os/c_ustime.c -+++ b/src/lib/krb5/os/c_ustime.c -@@ -102,17 +102,17 @@ krb5_crypto_us_timeofday(krb5_int32 *seconds, krb5_int32 *microseconds) - putting now.sec in the past. But don't just use '<' because we - need to properly handle the case where the administrator intentionally - adjusted time backwards. */ -- if ((now.sec == last_time.sec-1) || -- ((now.sec == last_time.sec) && (now.usec <= last_time.usec))) { -+ if (now.sec == ts_incr(last_time.sec, -1) || -+ (now.sec == last_time.sec && !ts_after(last_time.usec, now.usec))) { - /* Correct 'now' to be exactly one microsecond later than 'last_time'. - Note that _because_ we perform this hack, 'now' may be _earlier_ - than 'last_time', even though the system time is monotonically - increasing. */ - - now.sec = last_time.sec; -- now.usec = ++last_time.usec; -+ now.usec = ts_incr(last_time.usec, 1); - if (now.usec >= 1000000) { -- ++now.sec; -+ now.sec = ts_incr(now.sec, 1); - now.usec = 0; - } - } -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index a19246128..74c315c90 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -350,7 +350,7 @@ krb5int_trace(krb5_context context, const char *fmt, ...) - goto cleanup; - if (krb5_crypto_us_timeofday(&sec, &usec) != 0) - goto cleanup; -- if (asprintf(&msg, "[%d] %d.%d: %s\n", (int) getpid(), (int) sec, -+ if (asprintf(&msg, "[%d] %u.%d: %s\n", (int) getpid(), (unsigned int) sec, - (int) usec, str) < 0) - goto cleanup; - info.message = msg; diff --git a/Improve-PKINIT-UPN-SAN-matching.patch b/Improve-PKINIT-UPN-SAN-matching.patch deleted file mode 100644 index 26b27f1..0000000 --- a/Improve-PKINIT-UPN-SAN-matching.patch +++ /dev/null @@ -1,151 +0,0 @@ -From 03265620488b84238c31170356b5f41c80f0e9d9 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Mon, 5 Dec 2016 12:17:59 -0500 -Subject: [PATCH] Improve PKINIT UPN SAN matching - -Add the match_client() kdcpreauth callback and use it in -verify_client_san(). match_client() preserves the direct UPN to -request principal comparison and adds a direct comparison to the -client principal, falling back to an alias DB search and comparison -against the client principal. Change crypto_retreive_X509_sans() to -parse UPN values as enterprise principals. - -[ghudson@mit.edu: use match_client for both kinds of SANs] - -ticket: 8528 (new) -(cherry picked from commit 46ff765e1fb8cbec2bb602b43311269e695dbedc) ---- - src/include/krb5/kdcpreauth_plugin.h | 13 ++++++++++ - src/kdc/kdc_preauth.c | 28 ++++++++++++++++++++-- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 4 +++- - src/plugins/preauth/pkinit/pkinit_srv.c | 10 ++++---- - 4 files changed, 48 insertions(+), 7 deletions(-) - -diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h -index f455effae..92aa5a5a5 100644 ---- a/src/include/krb5/kdcpreauth_plugin.h -+++ b/src/include/krb5/kdcpreauth_plugin.h -@@ -221,6 +221,19 @@ typedef struct krb5_kdcpreauth_callbacks_st { - - /* End of version 3 kdcpreauth callbacks. */ - -+ /* -+ * Return true if princ matches the principal named in the request or the -+ * client principal (possibly canonicalized). If princ does not match, -+ * attempt a database lookup of princ with aliases allowed and compare the -+ * result to the client principal, returning true if it matches. -+ * Otherwise, return false. -+ */ -+ krb5_boolean (*match_client)(krb5_context context, -+ krb5_kdcpreauth_rock rock, -+ krb5_principal princ); -+ -+ /* End of version 4 kdcpreauth callbacks. */ -+ - } *krb5_kdcpreauth_callbacks; - - /* Optional: preauth plugin initialization function. */ -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 605fcb7ad..0ce79c667 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -568,8 +568,31 @@ set_cookie(krb5_context context, krb5_kdcpreauth_rock rock, - return kdc_fast_set_cookie(rock->rstate, pa_type, data); - } - -+static krb5_boolean -+match_client(krb5_context context, krb5_kdcpreauth_rock rock, -+ krb5_principal princ) -+{ -+ krb5_db_entry *ent; -+ krb5_boolean match = FALSE; -+ krb5_principal req_client = rock->request->client; -+ krb5_principal client = rock->client->princ; -+ -+ /* Check for a direct match against the request principal or -+ * the post-canon client principal. */ -+ if (krb5_principal_compare_flags(context, princ, req_client, -+ KRB5_PRINCIPAL_COMPARE_ENTERPRISE) || -+ krb5_principal_compare(context, princ, client)) -+ return TRUE; -+ -+ if (krb5_db_get_principal(context, princ, KRB5_KDB_FLAG_ALIAS_OK, &ent)) -+ return FALSE; -+ match = krb5_principal_compare(context, ent->princ, client); -+ krb5_db_free_principal(context, ent); -+ return match; -+} -+ - static struct krb5_kdcpreauth_callbacks_st callbacks = { -- 3, -+ 4, - max_time_skew, - client_keys, - free_keys, -@@ -583,7 +606,8 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { - client_keyblock, - add_auth_indicator, - get_cookie, -- set_cookie -+ set_cookie, -+ match_client - }; - - static krb5_error_code -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 74fffbf32..bc6e7662e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2190,7 +2190,9 @@ crypto_retrieve_X509_sans(krb5_context context, - /* Prevent abuse of embedded null characters. */ - if (memchr(name.data, '\0', name.length)) - break; -- ret = krb5_parse_name(context, name.data, &upns[u]); -+ ret = krb5_parse_name_flags(context, name.data, -+ KRB5_PRINCIPAL_PARSE_ENTERPRISE, -+ &upns[u]); - if (ret) { - pkiDebug("%s: failed parsing ms-upn san value\n", - __FUNCTION__); -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 295be25e1..b5638a367 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -121,6 +121,8 @@ static krb5_error_code - verify_client_san(krb5_context context, - pkinit_kdc_context plgctx, - pkinit_kdc_req_context reqctx, -+ krb5_kdcpreauth_callbacks cb, -+ krb5_kdcpreauth_rock rock, - krb5_principal client, - int *valid_san) - { -@@ -171,7 +173,7 @@ verify_client_san(krb5_context context, - __FUNCTION__, client_string, san_string); - krb5_free_unparsed_name(context, san_string); - #endif -- if (krb5_principal_compare(context, princs[i], client)) { -+ if (cb->match_client(context, rock, princs[i])) { - pkiDebug("%s: pkinit san match found\n", __FUNCTION__); - *valid_san = 1; - retval = 0; -@@ -199,7 +201,7 @@ verify_client_san(krb5_context context, - __FUNCTION__, client_string, san_string); - krb5_free_unparsed_name(context, san_string); - #endif -- if (krb5_principal_compare(context, upns[i], client)) { -+ if (cb->match_client(context, rock, upns[i])) { - pkiDebug("%s: upn san match found\n", __FUNCTION__); - *valid_san = 1; - retval = 0; -@@ -387,8 +389,8 @@ pkinit_server_verify_padata(krb5_context context, - } - if (is_signed) { - -- retval = verify_client_san(context, plgctx, reqctx, request->client, -- &valid_san); -+ retval = verify_client_san(context, plgctx, reqctx, cb, rock, -+ request->client, &valid_san); - if (retval) - goto cleanup; - if (!valid_san) { diff --git a/Make-timestamp-manipulations-y2038-safe.patch b/Make-timestamp-manipulations-y2038-safe.patch deleted file mode 100644 index 26bff26..0000000 --- a/Make-timestamp-manipulations-y2038-safe.patch +++ /dev/null @@ -1,1844 +0,0 @@ -From ac30f4753f157dafe93df2941a216fde591fcb69 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 22 Apr 2017 12:52:17 -0400 -Subject: [PATCH] Make timestamp manipulations y2038-safe - -Wherever we manipulate krb5_timestamp values using arithmetic, -comparison operations, or conversion to time_t, use the new helper -functions in k5-int.h to ensure that the operations work after y2038 -and do not exhibit undefined behavior. (Relying on -implementation-defined conversion to signed values is okay as we test -that in configure.in.) - -In printf format strings, use %u instead of signed types. When -exporting creds with k5_json_array_fmt(), use a long long so that -timestamps after y2038 aren't marshalled as negative numbers. When -parsing timestamps in test programs, use atoll() instead of atol() so -that positive timestamps after y2038 can be used as input. - -In ksu and klist, make printtime() take a krb5_timestamp parameter to -avoid an unnecessary conversion to time_t and back. - -As Leash does not use k5-int.h, use time_t values internally and -safely convert from libkrb5 timestamp values. - -ticket: 8352 -(cherry picked from commit a9cbbf0899f270fbb14f63ffbed1b6d542333641) ---- - src/clients/kinit/kinit.c | 2 +- - src/clients/klist/klist.c | 20 ++++------- - src/clients/ksu/ccache.c | 20 +++-------- - src/clients/ksu/ksu.h | 2 +- - src/kadmin/cli/getdate.y | 2 +- - src/kadmin/cli/kadmin.c | 5 ++- - src/kadmin/dbutil/dump.c | 27 ++++++++------- - src/kadmin/dbutil/kdb5_mkey.c | 6 ++-- - src/kadmin/dbutil/tabdump.c | 2 +- - src/kadmin/testing/util/tcl_kadm5.c | 12 +++---- - src/kdc/do_as_req.c | 2 +- - src/kdc/do_tgs_req.c | 6 ++-- - src/kdc/extern.c | 4 ++- - src/kdc/fast_util.c | 4 +-- - src/kdc/kdc_log.c | 14 ++++---- - src/kdc/kdc_util.c | 20 +++++------ - src/kdc/kdc_util.h | 2 ++ - src/kdc/replay.c | 2 +- - src/kdc/tgs_policy.c | 7 ++-- - src/lib/gssapi/krb5/accept_sec_context.c | 8 +++-- - src/lib/gssapi/krb5/acquire_cred.c | 13 ++++--- - src/lib/gssapi/krb5/context_time.c | 2 +- - src/lib/gssapi/krb5/export_cred.c | 5 +-- - src/lib/gssapi/krb5/iakerb.c | 4 +-- - src/lib/gssapi/krb5/init_sec_context.c | 9 ++--- - src/lib/gssapi/krb5/inq_context.c | 2 +- - src/lib/gssapi/krb5/inq_cred.c | 5 +-- - src/lib/gssapi/krb5/s4u_gss_glue.c | 2 +- - src/lib/kadm5/chpass_util.c | 8 ++--- - src/lib/kadm5/srv/server_acl.c | 5 +-- - src/lib/kadm5/srv/svr_principal.c | 12 +++---- - src/lib/kdb/kdb5.c | 2 +- - src/lib/krb5/asn.1/asn1_k_encode.c | 3 +- - src/lib/krb5/ccache/cc_keyring.c | 14 ++++---- - src/lib/krb5/ccache/cc_memory.c | 4 +-- - src/lib/krb5/ccache/cc_retr.c | 4 +-- - src/lib/krb5/ccache/ccapi/stdcc_util.c | 40 +++++++++++----------- - src/lib/krb5/ccache/cccursor.c | 2 +- - src/lib/krb5/keytab/kt_file.c | 6 ++-- - src/lib/krb5/krb/gc_via_tkt.c | 7 ++-- - src/lib/krb5/krb/get_creds.c | 2 +- - src/lib/krb5/krb/get_in_tkt.c | 38 ++++++-------------- - src/lib/krb5/krb/gic_pwd.c | 4 +-- - src/lib/krb5/krb/int-proto.h | 2 +- - src/lib/krb5/krb/pac.c | 2 +- - src/lib/krb5/krb/str_conv.c | 4 +-- - src/lib/krb5/krb/t_kerb.c | 12 ++----- - src/lib/krb5/krb/valid_times.c | 4 +-- - src/lib/krb5/krb/vfy_increds.c | 2 +- - src/lib/krb5/os/timeofday.c | 2 +- - src/lib/krb5/os/toffset.c | 2 +- - src/lib/krb5/os/ustime.c | 6 ++-- - src/lib/krb5/rcache/rc_dfl.c | 3 +- - src/lib/krb5/rcache/t_replay.c | 8 ++--- - src/plugins/kdb/db2/lockout.c | 8 ++--- - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 2 +- - src/plugins/kdb/ldap/libkdb_ldap/lockout.c | 8 ++--- - src/windows/cns/tktlist.c | 10 +++--- - src/windows/include/leashwin.h | 12 +++---- - src/windows/leash/KrbListTickets.cpp | 12 +++---- - src/windows/leash/LeashView.cpp | 22 ++++++------ - src/windows/leashdll/lshfunc.c | 2 +- - src/windows/ms2mit/ms2mit.c | 2 +- - 63 files changed, 230 insertions(+), 255 deletions(-) - -diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c -index f1cd1b73d..50065e32e 100644 ---- a/src/clients/kinit/kinit.c -+++ b/src/clients/kinit/kinit.c -@@ -318,7 +318,7 @@ parse_options(argc, argv, opts) - fprintf(stderr, _("Bad start time value %s\n"), optarg); - errflg++; - } else { -- opts->starttime = abs_starttime - time(0); -+ opts->starttime = ts_delta(abs_starttime, time(NULL)); - } - } - break; -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index ba19788a2..ffeecc394 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -72,7 +72,7 @@ void do_ccache_name (char *); - int show_ccache (krb5_ccache); - int check_ccache (krb5_ccache); - void do_keytab (char *); --void printtime (time_t); -+void printtime (krb5_timestamp); - void one_addr (krb5_address *); - void fillit (FILE *, unsigned int, int); - -@@ -538,10 +538,10 @@ check_ccache(krb5_ccache cache) - while (!(ret = krb5_cc_next_cred(kcontext, cache, &cur, &creds))) { - if (is_local_tgt(creds.server, &princ->realm)) { - found_tgt = TRUE; -- if (creds.times.endtime > now) -+ if (ts_after(creds.times.endtime, now)) - found_current_tgt = TRUE; - } else if (!krb5_is_config_principal(kcontext, creds.server) && -- creds.times.endtime > now) { -+ ts_after(creds.times.endtime, now)) { - found_current_cred = TRUE; - } - krb5_free_cred_contents(kcontext, &creds); -@@ -623,19 +623,13 @@ flags_string(cred) - } - - void --printtime(tv) -- time_t tv; -+printtime(krb5_timestamp ts) - { -- char timestring[BUFSIZ]; -- char fill; -+ char timestring[BUFSIZ], fill = ' '; - -- fill = ' '; -- if (!krb5_timestamp_to_sfstring((krb5_timestamp) tv, -- timestring, -- timestamp_width+1, -- &fill)) { -+ if (!krb5_timestamp_to_sfstring(ts, timestring, timestamp_width + 1, -+ &fill)) - printf("%s", timestring); -- } - } - - static void -diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c -index a0736f2da..236313b7b 100644 ---- a/src/clients/ksu/ccache.c -+++ b/src/clients/ksu/ccache.c -@@ -278,11 +278,11 @@ krb5_error_code krb5_check_exp(context, tkt_time) - context->clockskew); - - fprintf(stderr,"krb5_check_exp: currenttime - endtime %d \n", -- (currenttime - tkt_time.endtime )); -+ ts_delta(currenttime, tkt_time.endtime)); - - } - -- if (currenttime - tkt_time.endtime > context->clockskew){ -+ if (ts_delta(currenttime, tkt_time.endtime) > context->clockskew) { - retval = KRB5KRB_AP_ERR_TKT_EXPIRED ; - return retval; - } -@@ -323,21 +323,11 @@ char *flags_string(cred) - return(buf); - } - --void printtime(tv) -- time_t tv; -+void printtime(krb5_timestamp ts) - { -- char fmtbuf[18]; -- char fill; -- krb5_timestamp tstamp; -+ char fmtbuf[18], fill = ' '; - -- /* XXXX ASSUMES sizeof(krb5_timestamp) >= sizeof(time_t) */ -- (void) localtime((time_t *)&tv); -- tstamp = tv; -- fill = ' '; -- if (!krb5_timestamp_to_sfstring(tstamp, -- fmtbuf, -- sizeof(fmtbuf), -- &fill)) -+ if (!krb5_timestamp_to_sfstring(ts, fmtbuf, sizeof(fmtbuf), &fill)) - printf("%s", fmtbuf); - } - -diff --git a/src/clients/ksu/ksu.h b/src/clients/ksu/ksu.h -index ee8e9d6a0..3bf0bd438 100644 ---- a/src/clients/ksu/ksu.h -+++ b/src/clients/ksu/ksu.h -@@ -150,7 +150,7 @@ extern krb5_boolean krb5_find_princ_in_cred_list - extern krb5_error_code krb5_find_princ_in_cache - (krb5_context, krb5_ccache, krb5_principal, krb5_boolean *); - --extern void printtime (time_t); -+extern void printtime (krb5_timestamp); - - /* authorization.c */ - extern krb5_boolean fowner (FILE *, uid_t); -diff --git a/src/kadmin/cli/getdate.y b/src/kadmin/cli/getdate.y -index 4f0c56f7e..0a19c5648 100644 ---- a/src/kadmin/cli/getdate.y -+++ b/src/kadmin/cli/getdate.y -@@ -118,7 +118,7 @@ static int getdate_yyerror (char *); - - - #define EPOCH 1970 --#define EPOCH_END 2038 /* assumes 32 bits */ -+#define EPOCH_END 2106 /* assumes unsigned 32-bit range */ - #define HOUR(x) ((time_t)(x) * 60) - #define SECSPERDAY (24L * 60L * 60L) - -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index c53c677a8..aee5c83b9 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -31,8 +31,7 @@ - * library */ - - /* for "_" macro */ --#include "k5-platform.h" --#include -+#include "k5-int.h" - #include - #include - #include -@@ -144,8 +143,8 @@ strdate(krb5_timestamp when) - { - struct tm *tm; - static char out[40]; -+ time_t lcltim = ts2tt(when); - -- time_t lcltim = when; - tm = localtime(&lcltim); - strftime(out, sizeof(out), "%a %b %d %H:%M:%S %Z %Y", tm); - return out; -diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index cad53cfbf..a6fc4ea77 100644 ---- a/src/kadmin/dbutil/dump.c -+++ b/src/kadmin/dbutil/dump.c -@@ -379,11 +379,12 @@ k5beta7_common(krb5_context context, krb5_db_entry *entry, - fprintf(fp, "princ\t%d\t%lu\t%d\t%d\t%d\t%s\t", (int)entry->len, - (unsigned long)strlen(name), counter, (int)entry->n_key_data, - (int)entry->e_length, name); -- fprintf(fp, "%d\t%d\t%d\t%d\t%d\t%d\t%d\t%d", entry->attributes, -- entry->max_life, entry->max_renewable_life, entry->expiration, -- entry->pw_expiration, -- omit_nra ? 0 : entry->last_success, -- omit_nra ? 0 : entry->last_failed, -+ fprintf(fp, "%d\t%d\t%d\t%u\t%u\t%u\t%u\t%d", entry->attributes, -+ entry->max_life, entry->max_renewable_life, -+ (unsigned int)entry->expiration, -+ (unsigned int)entry->pw_expiration, -+ (unsigned int)(omit_nra ? 0 : entry->last_success), -+ (unsigned int)(omit_nra ? 0 : entry->last_failed), - omit_nra ? 0 : entry->fail_auth_count); - - /* Write out tagged data. */ -@@ -717,7 +718,7 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - { - int retval, nread, i, j; - krb5_db_entry *dbentry; -- int t1, t2, t3, t4, t5, t6, t7; -+ int t1, t2, t3, t4; - unsigned int u1, u2, u3, u4, u5; - char *name = NULL; - krb5_key_data *kp = NULL, *kd; -@@ -773,8 +774,8 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - } - - /* Get the fixed principal attributes */ -- nread = fscanf(filep, "%d\t%d\t%d\t%d\t%d\t%d\t%d\t%d\t", -- &t1, &t2, &t3, &t4, &t5, &t6, &t7, &u1); -+ nread = fscanf(filep, "%d\t%d\t%d\t%u\t%u\t%d\t%d\t%d\t", -+ &t1, &t2, &t3, &u1, &u2, &u3, &u4, &u5); - if (nread != 8) { - load_err(fname, *linenop, _("cannot read principal attributes")); - goto fail; -@@ -782,11 +783,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - dbentry->attributes = t1; - dbentry->max_life = t2; - dbentry->max_renewable_life = t3; -- dbentry->expiration = t4; -- dbentry->pw_expiration = t5; -- dbentry->last_success = t6; -- dbentry->last_failed = t7; -- dbentry->fail_auth_count = u1; -+ dbentry->expiration = u1; -+ dbentry->pw_expiration = u2; -+ dbentry->last_success = u3; -+ dbentry->last_failed = u4; -+ dbentry->fail_auth_count = u5; - dbentry->mask = KADM5_LOAD | KADM5_PRINCIPAL | KADM5_ATTRIBUTES | - KADM5_MAX_LIFE | KADM5_MAX_RLIFE | - KADM5_PRINC_EXPIRE_TIME | KADM5_LAST_SUCCESS | -diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c -index 7df8cbc83..2efe3176e 100644 ---- a/src/kadmin/dbutil/kdb5_mkey.c -+++ b/src/kadmin/dbutil/kdb5_mkey.c -@@ -44,8 +44,8 @@ static char *strdate(krb5_timestamp when) - { - struct tm *tm; - static char out[40]; -+ time_t lcltim = ts2tt(when); - -- time_t lcltim = when; - tm = localtime(&lcltim); - strftime(out, sizeof(out), "%a %b %d %H:%M:%S %Z %Y", tm); - return out; -@@ -481,7 +481,7 @@ kdb5_use_mkey(int argc, char *argv[]) - cur_actkvno != NULL; - prev_actkvno = cur_actkvno, cur_actkvno = cur_actkvno->next) { - -- if (new_actkvno->act_time < cur_actkvno->act_time) { -+ if (ts_after(cur_actkvno->act_time, new_actkvno->act_time)) { - if (prev_actkvno) { - prev_actkvno->next = new_actkvno; - new_actkvno->next = cur_actkvno; -@@ -499,7 +499,7 @@ kdb5_use_mkey(int argc, char *argv[]) - } - } - -- if (actkvno_list->act_time > now) { -+ if (ts_after(actkvno_list->act_time, now)) { - com_err(progname, EINVAL, - _("there must be one master key currently active")); - exit_status++; -diff --git a/src/kadmin/dbutil/tabdump.c b/src/kadmin/dbutil/tabdump.c -index 69a3482ec..fb36b060a 100644 ---- a/src/kadmin/dbutil/tabdump.c -+++ b/src/kadmin/dbutil/tabdump.c -@@ -148,7 +148,7 @@ write_date_iso(struct rec_args *args, krb5_timestamp when) - struct tm *tm = NULL; - struct rechandle *h = args->rh; - -- t = when; -+ t = ts2tt(when); - tm = gmtime(&t); - if (tm == NULL) { - errno = EINVAL; -diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c -index a4997c60c..9dde579ef 100644 ---- a/src/kadmin/testing/util/tcl_kadm5.c -+++ b/src/kadmin/testing/util/tcl_kadm5.c -@@ -697,13 +697,13 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - } else - Tcl_DStringAppendElement(str, "null"); - -- sprintf(buf, "%d", princ->princ_expire_time); -+ sprintf(buf, "%u", (unsigned int)princ->princ_expire_time); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_pwd_change); -+ sprintf(buf, "%u", (unsigned int)princ->last_pwd_change); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->pw_expiration); -+ sprintf(buf, "%u", (unsigned int)princ->pw_expiration); - Tcl_DStringAppendElement(str, buf); - - sprintf(buf, "%d", princ->max_life); -@@ -722,7 +722,7 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - } else - Tcl_DStringAppendElement(str, "null"); - -- sprintf(buf, "%d", princ->mod_date); -+ sprintf(buf, "%u", (unsigned int)princ->mod_date); - Tcl_DStringAppendElement(str, buf); - - if (mask & KADM5_ATTRIBUTES) { -@@ -758,10 +758,10 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - sprintf(buf, "%d", princ->max_renewable_life); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_success); -+ sprintf(buf, "%u", (unsigned int)princ->last_success); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_failed); -+ sprintf(buf, "%u", (unsigned int)princ->last_failed); - Tcl_DStringAppendElement(str, buf); - - sprintf(buf, "%d", princ->fail_auth_count); -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index a4bf91b1b..f85da6da6 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -87,7 +87,7 @@ get_key_exp(krb5_db_entry *entry) - return entry->pw_expiration; - if (entry->pw_expiration == 0) - return entry->expiration; -- return min(entry->expiration, entry->pw_expiration); -+ return ts_min(entry->expiration, entry->pw_expiration); - } - - /* -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 339259fd1..ac5864603 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -500,12 +500,12 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - - old_starttime = enc_tkt_reply.times.starttime ? - enc_tkt_reply.times.starttime : enc_tkt_reply.times.authtime; -- old_life = enc_tkt_reply.times.endtime - old_starttime; -+ old_life = ts_delta(enc_tkt_reply.times.endtime, old_starttime); - - enc_tkt_reply.times.starttime = kdc_time; - enc_tkt_reply.times.endtime = -- min(header_ticket->enc_part2->times.renew_till, -- kdc_time + old_life); -+ ts_min(header_ticket->enc_part2->times.renew_till, -+ ts_incr(kdc_time, old_life)); - } else { - /* not a renew request */ - enc_tkt_reply.times.starttime = kdc_time; -diff --git a/src/kdc/extern.c b/src/kdc/extern.c -index fe627494b..84b5c6ad5 100644 ---- a/src/kdc/extern.c -+++ b/src/kdc/extern.c -@@ -37,6 +37,8 @@ - kdc_realm_t **kdc_realmlist = (kdc_realm_t **) NULL; - int kdc_numrealms = 0; - krb5_data empty_string = {0, 0, ""}; --krb5_timestamp kdc_infinity = KRB5_INT32_MAX; /* XXX */ - krb5_keyblock psr_key; - krb5_int32 max_dgram_reply_size = MAX_DGRAM_SIZE; -+ -+/* With ts_after(), this is the largest timestamp value. */ -+krb5_timestamp kdc_infinity = -1; -diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c -index 9df940219..e05107ef3 100644 ---- a/src/kdc/fast_util.c -+++ b/src/kdc/fast_util.c -@@ -607,7 +607,7 @@ kdc_fast_read_cookie(krb5_context context, struct kdc_request_state *state, - ret = krb5_timeofday(context, &now); - if (ret) - goto cleanup; -- if (now - COOKIE_LIFETIME > cookie->time) { -+ if (ts2tt(now) > cookie->time + COOKIE_LIFETIME) { - /* Don't accept the cookie contents. Only return an error if the - * cookie is relevant to the request. */ - if (is_relevant(cookie->data, req->padata)) -@@ -700,7 +700,7 @@ kdc_fast_make_cookie(krb5_context context, struct kdc_request_state *state, - ret = krb5_timeofday(context, &now); - if (ret) - goto cleanup; -- cookie.time = now; -+ cookie.time = ts2tt(now); - cookie.data = contents; - ret = encode_krb5_secure_cookie(&cookie, &der_cookie); - if (ret) -diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c -index 94a2a1c87..c044a3553 100644 ---- a/src/kdc/kdc_log.c -+++ b/src/kdc/kdc_log.c -@@ -79,9 +79,9 @@ log_as_req(krb5_context context, const krb5_fulladdr *from, - /* success */ - char rep_etypestr[128]; - rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); -- krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %d, %s, " -+ krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, " - "%s for %s"), -- ktypestr, fromstring, authtime, -+ ktypestr, fromstring, (unsigned int)authtime, - rep_etypestr, cname2, sname2); - } else { - /* fail */ -@@ -156,10 +156,10 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - name (useful), and doesn't log ktypestr (probably not - important). */ - if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) { -- krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %d, %s%s " -+ krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s " - "%s for %s%s%s"), -- ktypestr, fromstring, status, authtime, rep_etypestr, -- !errcode ? "," : "", logcname, logsname, -+ ktypestr, fromstring, status, (unsigned int)authtime, -+ rep_etypestr, !errcode ? "," : "", logcname, logsname, - errcode ? ", " : "", errcode ? emsg : ""); - if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) - krb5_klog_syslog(LOG_INFO, -@@ -171,9 +171,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - logaltcname); - - } else -- krb5_klog_syslog(LOG_INFO, _("TGS_REQ %s: %s: authtime %d, %s for %s, " -+ krb5_klog_syslog(LOG_INFO, _("TGS_REQ %s: %s: authtime %u, %s for %s, " - "2nd tkt client %s"), -- fromstring, status, authtime, -+ fromstring, status, (unsigned int)authtime, - logcname, logsname, logaltcname); - - /* OpenSolaris: audit_krb5kdc_tgs_req(...) or -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 30c501c67..b710aefe4 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -654,7 +654,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The client must not be expired */ -- if (client.expiration && client.expiration < kdc_time) { -+ if (client.expiration && ts_after(kdc_time, client.expiration)) { - *status = "CLIENT EXPIRED"; - if (vague_errors) - return(KRB_ERR_GENERIC); -@@ -664,7 +664,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - - /* The client's password must not be expired, unless the server is - a KRB5_KDC_PWCHANGE_SERVICE. */ -- if (client.pw_expiration && client.pw_expiration < kdc_time && -+ if (client.pw_expiration && ts_after(kdc_time, client.pw_expiration) && - !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { - *status = "CLIENT KEY EXPIRED"; - if (vague_errors) -@@ -674,7 +674,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The server must not be expired */ -- if (server.expiration && server.expiration < kdc_time) { -+ if (server.expiration && ts_after(kdc_time, server.expiration)) { - *status = "SERVICE EXPIRED"; - return(KDC_ERR_SERVICE_EXP); - } -@@ -1771,9 +1771,9 @@ kdc_get_ticket_endtime(kdc_realm_t *kdc_active_realm, - if (till == 0) - till = kdc_infinity; - -- until = min(till, endtime); -+ until = ts_min(till, endtime); - -- life = until - starttime; -+ life = ts_delta(until, starttime); - - if (client != NULL && client->max_life != 0) - life = min(life, client->max_life); -@@ -1782,7 +1782,7 @@ kdc_get_ticket_endtime(kdc_realm_t *kdc_active_realm, - if (kdc_active_realm->realm_maxlife != 0) - life = min(life, kdc_active_realm->realm_maxlife); - -- *out_endtime = starttime + life; -+ *out_endtime = ts_incr(starttime, life); - } - - /* -@@ -1812,22 +1812,22 @@ kdc_get_ticket_renewtime(kdc_realm_t *realm, krb5_kdc_req *request, - if (isflagset(request->kdc_options, KDC_OPT_RENEWABLE)) - rtime = request->rtime ? request->rtime : kdc_infinity; - else if (isflagset(request->kdc_options, KDC_OPT_RENEWABLE_OK) && -- tkt->times.endtime < request->till) -+ ts_after(request->till, tkt->times.endtime)) - rtime = request->till; - else - return; - - /* Truncate it to the allowable renewable time. */ - if (tgt != NULL) -- rtime = min(rtime, tgt->times.renew_till); -+ rtime = ts_min(rtime, tgt->times.renew_till); - max_rlife = min(server->max_renewable_life, realm->realm_maxrlife); - if (client != NULL) - max_rlife = min(max_rlife, client->max_renewable_life); -- rtime = min(rtime, tkt->times.starttime + max_rlife); -+ rtime = ts_min(rtime, ts_incr(tkt->times.starttime, max_rlife)); - - /* Make the ticket renewable if the truncated requested time is larger than - * the ticket end time. */ -- if (rtime > tkt->times.endtime) { -+ if (ts_after(rtime, tkt->times.endtime)) { - setflag(tkt->flags, TKT_FLG_RENEWABLE); - tkt->times.renew_till = rtime; - } -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index bcf05fc27..672f94380 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -452,6 +452,8 @@ struct krb5_kdcpreauth_rock_st { - #define max(a, b) ((a) > (b) ? (a) : (b)) - #endif - -+#define ts_min(a, b) (ts_after(a, b) ? (b) : (a)) -+ - #define ADDRTYPE2FAMILY(X) \ - ((X) == ADDRTYPE_INET6 ? AF_INET6 : (X) == ADDRTYPE_INET ? AF_INET : -1) - -diff --git a/src/kdc/replay.c b/src/kdc/replay.c -index 8da7ac19a..fab39cf88 100644 ---- a/src/kdc/replay.c -+++ b/src/kdc/replay.c -@@ -61,7 +61,7 @@ static size_t total_size = 0; - static krb5_ui_4 seed; - - #define STALE_TIME (2*60) /* two minutes */ --#define STALE(ptr, now) (abs((ptr)->timein - (now)) >= STALE_TIME) -+#define STALE(ptr, now) (labs(ts_delta((ptr)->timein, now)) >= STALE_TIME) - - /* Return x rotated to the left by r bits. */ - static inline krb5_ui_4 -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index a30cacc66..d0f25d1b7 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -186,7 +186,7 @@ static int - check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, - krb5_timestamp kdc_time, const char **status) - { -- if (server.expiration && server.expiration < kdc_time) { -+ if (server.expiration && ts_after(kdc_time, server.expiration)) { - *status = "SERVICE EXPIRED"; - return KDC_ERR_SERVICE_EXP; - } -@@ -222,7 +222,7 @@ check_tgs_times(krb5_kdc_req *req, krb5_ticket_times *times, - KDC time. */ - if (req->kdc_options & KDC_OPT_VALIDATE) { - starttime = times->starttime ? times->starttime : times->authtime; -- if (starttime > kdc_time) { -+ if (ts_after(starttime, kdc_time)) { - *status = "NOT_YET_VALID"; - return KRB_AP_ERR_TKT_NYV; - } -@@ -231,7 +231,8 @@ check_tgs_times(krb5_kdc_req *req, krb5_ticket_times *times, - * Check the renew_till time. The endtime was already - * been checked in the initial authentication check. - */ -- if ((req->kdc_options & KDC_OPT_RENEW) && times->renew_till < kdc_time) { -+ if ((req->kdc_options & KDC_OPT_RENEW) && -+ ts_after(kdc_time, times->renew_till)) { - *status = "TKT_EXPIRED"; - return KRB_AP_ERR_TKT_EXPIRED; - } -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 580d08cbf..06967aa27 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -351,8 +351,10 @@ kg_accept_dce(minor_status, context_handle, verifier_cred_handle, - if (mech_type) - *mech_type = ctx->mech_used; - -- if (time_rec) -- *time_rec = ctx->krb_times.endtime + ctx->k5_context->clockskew - now; -+ if (time_rec) { -+ *time_rec = ts_delta(ctx->krb_times.endtime, now) + -+ ctx->k5_context->clockskew; -+ } - - /* Never return GSS_C_DELEG_FLAG since we don't support DCE credential - * delegation yet. */ -@@ -1146,7 +1148,7 @@ kg_accept_krb5(minor_status, context_handle, - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket. */ - if (time_rec) -- *time_rec = ctx->krb_times.endtime + context->clockskew - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now) + context->clockskew; - - if (ret_flags) - *ret_flags = ctx->gss_flags; -diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c -index 03ee25ec1..362ba9d86 100644 ---- a/src/lib/gssapi/krb5/acquire_cred.c -+++ b/src/lib/gssapi/krb5/acquire_cred.c -@@ -550,7 +550,7 @@ set_refresh_time(krb5_context context, krb5_ccache ccache, - char buf[128]; - krb5_data d; - -- snprintf(buf, sizeof(buf), "%ld", (long)refresh_time); -+ snprintf(buf, sizeof(buf), "%u", (unsigned int)ts2tt(refresh_time)); - d = string2data(buf); - (void)krb5_cc_set_config(context, ccache, NULL, KRB5_CC_CONF_REFRESH_TIME, - &d); -@@ -566,8 +566,9 @@ kg_cred_time_to_refresh(krb5_context context, krb5_gss_cred_id_rec *cred) - - if (krb5_timeofday(context, &now)) - return FALSE; -- if (cred->refresh_time != 0 && now >= cred->refresh_time) { -- set_refresh_time(context, cred->ccache, cred->refresh_time + 30); -+ if (cred->refresh_time != 0 && !ts_after(cred->refresh_time, now)) { -+ set_refresh_time(context, cred->ccache, -+ ts_incr(cred->refresh_time, 30)); - return TRUE; - } - return FALSE; -@@ -586,7 +587,8 @@ kg_cred_set_initial_refresh(krb5_context context, krb5_gss_cred_id_rec *cred, - return; - - /* Make a note to refresh these when they are halfway to expired. */ -- refresh = times->starttime + (times->endtime - times->starttime) / 2; -+ refresh = ts_incr(times->starttime, -+ ts_delta(times->endtime, times->starttime) / 2); - set_refresh_time(context, cred->ccache, refresh); - } - -@@ -848,7 +850,8 @@ acquire_cred_context(krb5_context context, OM_uint32 *minor_status, - GSS_C_NO_NAME); - if (GSS_ERROR(ret)) - goto error_out; -- *time_rec = (cred->expire > now) ? (cred->expire - now) : 0; -+ *time_rec = ts_after(cred->expire, now) ? -+ ts_delta(cred->expire, now) : 0; - k5_mutex_unlock(&cred->lock); - } - } -diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c -index 450593288..1fdb5a16f 100644 ---- a/src/lib/gssapi/krb5/context_time.c -+++ b/src/lib/gssapi/krb5/context_time.c -@@ -51,7 +51,7 @@ krb5_gss_context_time(minor_status, context_handle, time_rec) - return(GSS_S_FAILURE); - } - -- lifetime = ctx->krb_times.endtime - now; -+ lifetime = ts_delta(ctx->krb_times.endtime, now); - if (!ctx->initiate) - lifetime += ctx->k5_context->clockskew; - if (lifetime <= 0) { -diff --git a/src/lib/gssapi/krb5/export_cred.c b/src/lib/gssapi/krb5/export_cred.c -index 652b2604b..8054e4a77 100644 ---- a/src/lib/gssapi/krb5/export_cred.c -+++ b/src/lib/gssapi/krb5/export_cred.c -@@ -410,10 +410,11 @@ json_kgcred(krb5_context context, krb5_gss_cred_id_t cred, - if (ret) - goto cleanup; - -- ret = k5_json_array_fmt(&array, "ivvbbvvvvbiivs", cred->usage, name, imp, -+ ret = k5_json_array_fmt(&array, "ivvbbvvvvbLLvs", cred->usage, name, imp, - cred->default_identity, cred->iakerb_mech, keytab, - rcache, ccache, ckeytab, cred->have_tgt, -- cred->expire, cred->refresh_time, etypes, -+ (long long)ts2tt(cred->expire), -+ (long long)ts2tt(cred->refresh_time), etypes, - cred->password); - if (ret) - goto cleanup; -diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c -index 2dc4d0c1a..bb1072fe4 100644 ---- a/src/lib/gssapi/krb5/iakerb.c -+++ b/src/lib/gssapi/krb5/iakerb.c -@@ -494,7 +494,7 @@ iakerb_tkt_creds_ctx(iakerb_ctx_id_t ctx, - if (code != 0) - goto cleanup; - -- creds.times.endtime = now + time_req; -+ creds.times.endtime = ts_incr(now, time_req); - } - - if (cred->name->ad_context != NULL) { -@@ -669,7 +669,7 @@ iakerb_get_initial_state(iakerb_ctx_id_t ctx, - if (code != 0) - goto cleanup; - -- in_creds.times.endtime = now + time_req; -+ in_creds.times.endtime = ts_incr(now, time_req); - } - - /* Make an AS request if we have no creds or it's time to refresh them. */ -diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c -index 2a7467f54..1be1b5878 100644 ---- a/src/lib/gssapi/krb5/init_sec_context.c -+++ b/src/lib/gssapi/krb5/init_sec_context.c -@@ -214,7 +214,8 @@ static krb5_error_code get_credentials(context, cred, server, now, - * boundaries) because accept_sec_context code is also similarly - * non-forgiving. - */ -- if (!krb5_gss_dbg_client_expcreds && result_creds->times.endtime < now) { -+ if (!krb5_gss_dbg_client_expcreds && -+ ts_after(now, result_creds->times.endtime)) { - code = KRB5KRB_AP_ERR_TKT_EXPIRED; - goto cleanup; - } -@@ -573,7 +574,7 @@ kg_new_connection( - if (time_req == 0 || time_req == GSS_C_INDEFINITE) { - ctx->krb_times.endtime = 0; - } else { -- ctx->krb_times.endtime = now + time_req; -+ ctx->krb_times.endtime = ts_incr(now, time_req); - } - - if ((code = kg_duplicate_name(context, cred->name, &ctx->here))) -@@ -657,7 +658,7 @@ kg_new_connection( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto cleanup; -- *time_rec = ctx->krb_times.endtime - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now); - } - - /* set the other returns */ -@@ -871,7 +872,7 @@ mutual_auth( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto fail; -- *time_rec = ctx->krb_times.endtime - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now); - } - - if (ret_flags) -diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c -index d2e466e60..cac024da1 100644 ---- a/src/lib/gssapi/krb5/inq_context.c -+++ b/src/lib/gssapi/krb5/inq_context.c -@@ -120,7 +120,7 @@ krb5_gss_inquire_context(minor_status, context_handle, initiator_name, - - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket during authentication. */ -- lifetime = ctx->krb_times.endtime - now; -+ lifetime = ts_delta(ctx->krb_times.endtime, now); - if (!ctx->initiate) - lifetime += context->clockskew; - if (lifetime < 0) -diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c -index 4e35a0563..e662ae53a 100644 ---- a/src/lib/gssapi/krb5/inq_cred.c -+++ b/src/lib/gssapi/krb5/inq_cred.c -@@ -130,8 +130,9 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - goto fail; - } - -- if (cred->expire > 0) { -- if ((lifetime = cred->expire - now) < 0) -+ if (cred->expire != 0) { -+ lifetime = ts_delta(cred->expire, now); -+ if (lifetime < 0) - lifetime = 0; - } - else -diff --git a/src/lib/gssapi/krb5/s4u_gss_glue.c b/src/lib/gssapi/krb5/s4u_gss_glue.c -index ff1c310bc..10848c1df 100644 ---- a/src/lib/gssapi/krb5/s4u_gss_glue.c -+++ b/src/lib/gssapi/krb5/s4u_gss_glue.c -@@ -284,7 +284,7 @@ kg_compose_deleg_cred(OM_uint32 *minor_status, - if (code != 0) - goto cleanup; - -- *time_rec = cred->expire - now; -+ *time_rec = ts_delta(cred->expire, now); - } - - major_status = GSS_S_COMPLETE; -diff --git a/src/lib/kadm5/chpass_util.c b/src/lib/kadm5/chpass_util.c -index 408b0eb31..1680a5504 100644 ---- a/src/lib/kadm5/chpass_util.c -+++ b/src/lib/kadm5/chpass_util.c -@@ -4,15 +4,11 @@ - */ - - --#include "autoconf.h" --#include --#include --#include -+#include "k5-int.h" - - #include - #include "admin_internal.h" - --#include - - #define string_text error_message - -@@ -218,7 +214,7 @@ kadm5_ret_t _kadm5_chpass_principal_util(void *server_handle, - time_t until; - char *time_string, *ptr; - -- until = princ_ent.last_pwd_change + policy_ent.pw_min_life; -+ until = ts_incr(princ_ent.last_pwd_change, policy_ent.pw_min_life); - - time_string = ctime(&until); - if (*(ptr = &time_string[strlen(time_string)-1]) == '\n') -diff --git a/src/lib/kadm5/srv/server_acl.c b/src/lib/kadm5/srv/server_acl.c -index 3c2844d14..c4bb16dc7 100644 ---- a/src/lib/kadm5/srv/server_acl.c -+++ b/src/lib/kadm5/srv/server_acl.c -@@ -408,13 +408,14 @@ kadm5int_acl_impose_restrictions(kcontext, recp, maskp, rp) - } - if (rp->mask & KADM5_PRINC_EXPIRE_TIME) { - if (!(*maskp & KADM5_PRINC_EXPIRE_TIME) -- || (recp->princ_expire_time > (now + rp->princ_lifetime))) -+ || ts_after(recp->princ_expire_time, -+ ts_incr(now, rp->princ_lifetime))) - recp->princ_expire_time = now + rp->princ_lifetime; - *maskp |= KADM5_PRINC_EXPIRE_TIME; - } - if (rp->mask & KADM5_PW_EXPIRATION) { - if (!(*maskp & KADM5_PW_EXPIRATION) -- || (recp->pw_expiration > (now + rp->pw_lifetime))) -+ || ts_after(recp->pw_expiration, ts_incr(now, rp->pw_lifetime))) - recp->pw_expiration = now + rp->pw_lifetime; - *maskp |= KADM5_PW_EXPIRATION; - } -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 8f4da0e52..137e1fb64 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -400,7 +400,7 @@ kadm5_create_principal_3(void *server_handle, - kdb->pw_expiration = 0; - if (have_polent) { - if(polent.pw_max_life) -- kdb->pw_expiration = now + polent.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, polent.pw_max_life); - else - kdb->pw_expiration = 0; - } -@@ -612,7 +612,7 @@ kadm5_modify_principal(void *server_handle, - &(kdb->pw_expiration)); - if (ret) - goto done; -- kdb->pw_expiration += pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(kdb->pw_expiration, pol.pw_max_life); - } else { - kdb->pw_expiration = 0; - } -@@ -1445,7 +1445,7 @@ kadm5_chpass_principal_3(void *server_handle, - } - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -1624,7 +1624,7 @@ kadm5_randkey_principal_3(void *server_handle, - #endif - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -1774,7 +1774,7 @@ kadm5_setv4key_principal(void *server_handle, - #endif - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -2027,7 +2027,7 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - } - if (have_pol) { - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c -index 690725765..07392572e 100644 ---- a/src/lib/kdb/kdb5.c -+++ b/src/lib/kdb/kdb5.c -@@ -1297,7 +1297,7 @@ find_actkvno(krb5_actkvno_node *list, krb5_timestamp now) - * are in the future, we will return the first node; if all are in the - * past, we will return the last node. - */ -- while (list->next != NULL && list->next->act_time <= now) -+ while (list->next != NULL && !ts_after(list->next->act_time, now)) - list = list->next; - return list->act_kvno; - } -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index a827ca608..889460989 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -158,8 +158,7 @@ static asn1_error_code - encode_kerberos_time(asn1buf *buf, const void *p, taginfo *rettag, - size_t *len_out) - { -- /* Range checking for time_t vs krb5_timestamp? */ -- time_t val = *(krb5_timestamp *)p; -+ time_t val = ts2tt(*(krb5_timestamp *)p); - rettag->asn1class = UNIVERSAL; - rettag->construction = PRIMITIVE; - rettag->tagnum = ASN1_GENERALTIME; -diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c -index 4fe3f0d6f..fba710b1b 100644 ---- a/src/lib/krb5/ccache/cc_keyring.c -+++ b/src/lib/krb5/ccache/cc_keyring.c -@@ -751,7 +751,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) - for (;;) { - if (krcc_next_cred(context, id, &cursor, &creds) != 0) - break; -- if (creds.times.endtime > endtime) -+ if (ts_after(creds.times.endtime, endtime)) - endtime = creds.times.endtime; - krb5_free_cred_contents(context, &creds); - } -@@ -765,7 +765,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) - - /* Setting the timeout to zero would reset the timeout, so we set it to one - * second instead if creds are already expired. */ -- timeout = (endtime > now) ? endtime - now : 1; -+ timeout = ts_after(endtime, now) ? ts_delta(endtime, now) : 1; - (void)keyctl_set_timeout(data->cache_id, timeout); - } - -@@ -1316,8 +1316,10 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) - if (ret) - goto errout; - -- if (creds->times.endtime > now) -- (void)keyctl_set_timeout(cred_key, creds->times.endtime - now); -+ if (ts_after(creds->times.endtime, now)) { -+ (void)keyctl_set_timeout(cred_key, -+ ts_delta(creds->times.endtime, now)); -+ } - - update_keyring_expiration(context, id); - -@@ -1680,8 +1682,8 @@ static void - krcc_update_change_time(krcc_data *data) - { - krb5_timestamp now_time = time(NULL); -- data->changetime = (data->changetime >= now_time) ? -- data->changetime + 1 : now_time; -+ data->changetime = ts_after(now_time, data->changetime) ? -+ now_time : ts_incr(data->changetime, 1); - } - - /* -diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c -index 0354575c5..c5425eb3a 100644 ---- a/src/lib/krb5/ccache/cc_memory.c -+++ b/src/lib/krb5/ccache/cc_memory.c -@@ -720,8 +720,8 @@ static void - update_mcc_change_time(krb5_mcc_data *d) - { - krb5_timestamp now_time = time(NULL); -- d->changetime = (d->changetime >= now_time) ? -- d->changetime + 1 : now_time; -+ d->changetime = ts_after(now_time, d->changetime) ? -+ now_time : ts_incr(d->changetime, 1); - } - - static krb5_error_code KRB5_CALLCONV -diff --git a/src/lib/krb5/ccache/cc_retr.c b/src/lib/krb5/ccache/cc_retr.c -index 1314d24bd..1a32e00c8 100644 ---- a/src/lib/krb5/ccache/cc_retr.c -+++ b/src/lib/krb5/ccache/cc_retr.c -@@ -46,11 +46,11 @@ static krb5_boolean - times_match(const krb5_ticket_times *t1, const krb5_ticket_times *t2) - { - if (t1->renew_till) { -- if (t1->renew_till > t2->renew_till) -+ if (ts_after(t1->renew_till, t2->renew_till)) - return FALSE; /* this one expires too late */ - } - if (t1->endtime) { -- if (t1->endtime > t2->endtime) -+ if (ts_after(t1->endtime, t2->endtime)) - return FALSE; /* this one expires too late */ - } - /* only care about expiration on a times_match */ -diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c -index 9f44af3d0..6092ee432 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc_util.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c -@@ -16,8 +16,8 @@ - #include - #endif - -+#include "k5-int.h" - #include "stdcc_util.h" --#include "krb5.h" - #ifdef _WIN32 /* it's part of krb5.h everywhere else */ - #include "kv5m_err.h" - #endif -@@ -321,10 +321,10 @@ copy_cc_cred_union_to_krb5_creds (krb5_context in_context, - keyblock_contents = NULL; - - /* copy times */ -- out_creds->times.authtime = cv5->authtime + offset_seconds; -- out_creds->times.starttime = cv5->starttime + offset_seconds; -- out_creds->times.endtime = cv5->endtime + offset_seconds; -- out_creds->times.renew_till = cv5->renew_till + offset_seconds; -+ out_creds->times.authtime = ts_incr(cv5->authtime, offset_seconds); -+ out_creds->times.starttime = ts_incr(cv5->starttime, offset_seconds); -+ out_creds->times.endtime = ts_incr(cv5->endtime, offset_seconds); -+ out_creds->times.renew_till = ts_incr(cv5->renew_till, offset_seconds); - out_creds->is_skey = cv5->is_skey; - out_creds->ticket_flags = cv5->ticket_flags; - -@@ -451,11 +451,11 @@ copy_krb5_creds_to_cc_cred_union (krb5_context in_context, - cv5->keyblock.data = keyblock_data; - keyblock_data = NULL; - -- cv5->authtime = in_creds->times.authtime - offset_seconds; -- cv5->starttime = in_creds->times.starttime - offset_seconds; -- cv5->endtime = in_creds->times.endtime - offset_seconds; -- cv5->renew_till = in_creds->times.renew_till - offset_seconds; -- cv5->is_skey = in_creds->is_skey; -+ cv5->authtime = ts_incr(in_creds->times.authtime, -offset_seconds); -+ cv5->starttime = ts_incr(in_creds->times.starttime, -offset_seconds); -+ cv5->endtime = ts_incr(in_creds->times.endtime, -offset_seconds); -+ cv5->renew_till = ts_incr(in_creds->times.renew_till, -offset_seconds); -+ cv5->is_skey = in_creds->is_skey; - cv5->ticket_flags = in_creds->ticket_flags; - - if (in_creds->ticket.data) { -@@ -732,10 +732,10 @@ void dupCCtoK5(krb5_context context, cc_creds *src, krb5_creds *dest) - err = krb5_get_time_offsets(context, &offset_seconds, &offset_microseconds); - if (err) return; - #endif -- dest->times.authtime = src->authtime + offset_seconds; -- dest->times.starttime = src->starttime + offset_seconds; -- dest->times.endtime = src->endtime + offset_seconds; -- dest->times.renew_till = src->renew_till + offset_seconds; -+ dest->times.authtime = ts_incr(src->authtime, offset_seconds); -+ dest->times.starttime = ts_incr(src->starttime, offset_seconds); -+ dest->times.endtime = ts_incr(src->endtime, offset_seconds); -+ dest->times.renew_till = ts_incr(src->renew_till, offset_seconds); - dest->is_skey = src->is_skey; - dest->ticket_flags = src->ticket_flags; - -@@ -804,10 +804,10 @@ void dupK5toCC(krb5_context context, krb5_creds *creds, cred_union **cu) - err = krb5_get_time_offsets(context, &offset_seconds, &offset_microseconds); - if (err) return; - #endif -- c->authtime = creds->times.authtime - offset_seconds; -- c->starttime = creds->times.starttime - offset_seconds; -- c->endtime = creds->times.endtime - offset_seconds; -- c->renew_till = creds->times.renew_till - offset_seconds; -+ c->authtime = ts_incr(creds->times.authtime, -offset_seconds); -+ c->starttime = ts_incr(creds->times.starttime, -offset_seconds); -+ c->endtime = ts_incr(creds->times.endtime, -offset_seconds); -+ c->renew_till = ts_incr(creds->times.renew_till, -offset_seconds); - c->is_skey = creds->is_skey; - c->ticket_flags = creds->ticket_flags; - -@@ -925,11 +925,11 @@ times_match(t1, t2) - register const krb5_ticket_times *t2; - { - if (t1->renew_till) { -- if (t1->renew_till > t2->renew_till) -+ if (ts_after(t1->renew_till, t2->renew_till)) - return FALSE; /* this one expires too late */ - } - if (t1->endtime) { -- if (t1->endtime > t2->endtime) -+ if (ts_after(t1->endtime, t2->endtime)) - return FALSE; /* this one expires too late */ - } - /* only care about expiration on a times_match */ -diff --git a/src/lib/krb5/ccache/cccursor.c b/src/lib/krb5/ccache/cccursor.c -index c31a3f5f0..e631f2051 100644 ---- a/src/lib/krb5/ccache/cccursor.c -+++ b/src/lib/krb5/ccache/cccursor.c -@@ -159,7 +159,7 @@ krb5_cccol_last_change_time(krb5_context context, - ret = krb5_cccol_cursor_next(context, c, &ccache); - if (ccache) { - ret = krb5_cc_last_change_time(context, ccache, &last_time); -- if (!ret && last_time > max_change_time) { -+ if (!ret && ts_after(last_time, max_change_time)) { - max_change_time = last_time; - } - ret = 0; -diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 674d88bab..76efb71c6 100644 ---- a/src/lib/krb5/keytab/kt_file.c -+++ b/src/lib/krb5/keytab/kt_file.c -@@ -264,9 +264,11 @@ more_recent(const krb5_keytab_entry *k1, const krb5_keytab_entry *k2) - * limitations (8-bit kvno storage), pre-1.14 kadmin protocol limitations - * (8-bit kvno marshalling), or KDB limitations (16-bit kvno storage). - */ -- if (k1->timestamp >= k2->timestamp && k1->vno < 128 && k2->vno > 240) -+ if (!ts_after(k2->timestamp, k1->timestamp) && -+ k1->vno < 128 && k2->vno > 240) - return TRUE; -- if (k1->timestamp <= k2->timestamp && k1->vno > 240 && k2->vno < 128) -+ if (!ts_after(k1->timestamp, k2->timestamp) && -+ k1->vno > 240 && k2->vno < 128) - return FALSE; - - /* Otherwise do a simple version comparison. */ -diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c -index c85d8b8d8..cf1ea361f 100644 ---- a/src/lib/krb5/krb/gc_via_tkt.c -+++ b/src/lib/krb5/krb/gc_via_tkt.c -@@ -287,18 +287,19 @@ krb5int_process_tgs_reply(krb5_context context, - retval = KRB5_KDCREP_MODIFIED; - - if ((in_cred->times.endtime != 0) && -- (dec_rep->enc_part2->times.endtime > in_cred->times.endtime)) -+ ts_after(dec_rep->enc_part2->times.endtime, in_cred->times.endtime)) - retval = KRB5_KDCREP_MODIFIED; - - if ((kdcoptions & KDC_OPT_RENEWABLE) && - (in_cred->times.renew_till != 0) && -- (dec_rep->enc_part2->times.renew_till > in_cred->times.renew_till)) -+ ts_after(dec_rep->enc_part2->times.renew_till, -+ in_cred->times.renew_till)) - retval = KRB5_KDCREP_MODIFIED; - - if ((kdcoptions & KDC_OPT_RENEWABLE_OK) && - (dec_rep->enc_part2->flags & KDC_OPT_RENEWABLE) && - (in_cred->times.endtime != 0) && -- (dec_rep->enc_part2->times.renew_till > in_cred->times.endtime)) -+ ts_after(dec_rep->enc_part2->times.renew_till, in_cred->times.endtime)) - retval = KRB5_KDCREP_MODIFIED; - - if (retval != 0) -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index 110abeb2b..be5b2d18c 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -816,7 +816,7 @@ get_cached_local_tgt(krb5_context context, krb5_tkt_creds_context ctx, - return code; - - /* Check if the TGT is expired before bothering the KDC with it. */ -- if (now > tgt->times.endtime) { -+ if (ts_after(now, tgt->times.endtime)) { - krb5_free_creds(context, tgt); - return KRB5KRB_AP_ERR_TKT_EXPIRED; - } -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index a058f5bd7..40aba1905 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -39,24 +39,6 @@ static krb5_error_code sort_krb5_padata_sequence(krb5_context context, - krb5_data *realm, - krb5_pa_data **padata); - --/* -- * This function performs 32 bit bounded addition so we can generate -- * lifetimes without overflowing krb5_int32 -- */ --static krb5_int32 --krb5int_addint32 (krb5_int32 x, krb5_int32 y) --{ -- if ((x > 0) && (y > (KRB5_INT32_MAX - x))) { -- /* sum will be be greater than KRB5_INT32_MAX */ -- return KRB5_INT32_MAX; -- } else if ((x < 0) && (y < (KRB5_INT32_MIN - x))) { -- /* sum will be less than KRB5_INT32_MIN */ -- return KRB5_INT32_MIN; -- } -- -- return x + y; --} -- - /* - * Decrypt the AS reply in ctx, populating ctx->reply->enc_part2. If - * strengthen_key is not null, combine it with the reply key as specified in -@@ -267,21 +249,21 @@ verify_as_reply(krb5_context context, - (request->from != 0) && - (request->from != as_reply->enc_part2->times.starttime)) - || ((request->till != 0) && -- (as_reply->enc_part2->times.endtime > request->till)) -+ ts_after(as_reply->enc_part2->times.endtime, request->till)) - || ((request->kdc_options & KDC_OPT_RENEWABLE) && - (request->rtime != 0) && -- (as_reply->enc_part2->times.renew_till > request->rtime)) -+ ts_after(as_reply->enc_part2->times.renew_till, request->rtime)) - || ((request->kdc_options & KDC_OPT_RENEWABLE_OK) && - !(request->kdc_options & KDC_OPT_RENEWABLE) && - (as_reply->enc_part2->flags & KDC_OPT_RENEWABLE) && - (request->till != 0) && -- (as_reply->enc_part2->times.renew_till > request->till)) -+ ts_after(as_reply->enc_part2->times.renew_till, request->till)) - ) { - return KRB5_KDCREP_MODIFIED; - } - - if (context->library_options & KRB5_LIBOPT_SYNC_KDCTIME) { -- time_offset = as_reply->enc_part2->times.authtime - time_now; -+ time_offset = ts_delta(as_reply->enc_part2->times.authtime, time_now); - retval = krb5_set_time_offsets(context, time_offset, 0); - if (retval) - return retval; -@@ -790,15 +772,15 @@ set_request_times(krb5_context context, krb5_init_creds_context ctx) - return code; - - /* Omit request start time unless the caller explicitly asked for one. */ -- from = krb5int_addint32(now, ctx->start_time); -+ from = ts_incr(now, ctx->start_time); - if (ctx->start_time != 0) - ctx->request->from = from; - -- ctx->request->till = krb5int_addint32(from, ctx->tkt_life); -+ ctx->request->till = ts_incr(from, ctx->tkt_life); - - if (ctx->renew_life > 0) { - /* Don't ask for a smaller renewable time than the lifetime. */ -- ctx->request->rtime = krb5int_addint32(from, ctx->renew_life); -+ ctx->request->rtime = ts_incr(from, ctx->renew_life); - if (ctx->request->rtime < ctx->request->till) - ctx->request->rtime = ctx->request->till; - ctx->request->kdc_options &= ~KDC_OPT_RENEWABLE_OK; -@@ -1438,7 +1420,7 @@ note_req_timestamp(krb5_context context, krb5_init_creds_context ctx, - - if (k5_time_with_offset(0, 0, &now, &usec) != 0) - return; -- ctx->pa_offset = kdc_time - now; -+ ctx->pa_offset = ts_delta(kdc_time, now); - ctx->pa_offset_usec = kdc_usec - usec; - ctx->pa_offset_state = (ctx->fast_state->armor_key != NULL) ? - AUTH_OFFSET : UNAUTH_OFFSET; -@@ -1807,6 +1789,7 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - { - int i; - krb5_int32 starttime; -+ krb5_deltat lifetime; - krb5_get_init_creds_opt *opt; - krb5_error_code retval; - -@@ -1838,7 +1821,8 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - if (retval) - goto cleanup; - if (creds->times.starttime) starttime = creds->times.starttime; -- krb5_get_init_creds_opt_set_tkt_life(opt, creds->times.endtime - starttime); -+ lifetime = ts_delta(creds->times.endtime, starttime); -+ krb5_get_init_creds_opt_set_tkt_life(opt, lifetime); - } - *out = opt; - return 0; -diff --git a/src/lib/krb5/krb/gic_pwd.c b/src/lib/krb5/krb/gic_pwd.c -index 6f3a29f2c..3565a7c4c 100644 ---- a/src/lib/krb5/krb/gic_pwd.c -+++ b/src/lib/krb5/krb/gic_pwd.c -@@ -211,7 +211,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - if (ret != 0) - return; - if (!is_last_req && -- (pw_exp < now || (pw_exp - now) > 7 * 24 * 60 * 60)) -+ (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) - return; - - if (!prompter) -@@ -221,7 +221,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - if (ret != 0) - return; - -- delta = pw_exp - now; -+ delta = ts_delta(pw_exp, now); - if (delta < 3600) { - snprintf(banner, sizeof(banner), - _("Warning: Your password will expire in less than one hour " -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index 44eca359f..48bd9f8f7 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -84,7 +84,7 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - krb5_flags *fields); - - #define in_clock_skew(context, date, now) \ -- (labs((date) - (now)) < (context)->clockskew) -+ (labs(ts_delta(date, now)) < (context)->clockskew) - - #define IS_TGS_PRINC(p) ((p)->length == 2 && \ - data_eq_string((p)->data[0], KRB5_TGS_NAME)) -diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c -index 9098927b5..c70585a9e 100644 ---- a/src/lib/krb5/krb/pac.c -+++ b/src/lib/krb5/krb/pac.c -@@ -378,7 +378,7 @@ k5_time_to_seconds_since_1970(int64_t ntTime, krb5_timestamp *elapsedSeconds) - - abstime = ntTime > 0 ? ntTime - NT_TIME_EPOCH : -ntTime; - -- if (abstime > KRB5_INT32_MAX) -+ if (abstime > UINT32_MAX) - return ERANGE; - - *elapsedSeconds = abstime; -diff --git a/src/lib/krb5/krb/str_conv.c b/src/lib/krb5/krb/str_conv.c -index 3ab7eacac..f0a2ae20b 100644 ---- a/src/lib/krb5/krb/str_conv.c -+++ b/src/lib/krb5/krb/str_conv.c -@@ -207,7 +207,7 @@ krb5_error_code KRB5_CALLCONV - krb5_timestamp_to_string(krb5_timestamp timestamp, char *buffer, size_t buflen) - { - size_t ret; -- time_t timestamp2 = timestamp; -+ time_t timestamp2 = ts2tt(timestamp); - struct tm tmbuf; - const char *fmt = "%c"; /* This is to get around gcc -Wall warning that - the year returned might be two digits */ -@@ -229,7 +229,7 @@ krb5_timestamp_to_sfstring(krb5_timestamp timestamp, char *buffer, size_t buflen - struct tm *tmp; - size_t i; - size_t ndone; -- time_t timestamp2 = timestamp; -+ time_t timestamp2 = ts2tt(timestamp); - struct tm tmbuf; - - static const char * const sftime_format_table[] = { -diff --git a/src/lib/krb5/krb/t_kerb.c b/src/lib/krb5/krb/t_kerb.c -index 60cfb5b15..74ac14d9a 100644 ---- a/src/lib/krb5/krb/t_kerb.c -+++ b/src/lib/krb5/krb/t_kerb.c -@@ -5,16 +5,8 @@ - */ - - #include "autoconf.h" --#include "krb5.h" --#include --#include --#include --#include -+#include "k5-int.h" - #include --#include --#include --#include --#include - - #include "com_err.h" - -@@ -37,7 +29,7 @@ test_string_to_timestamp(krb5_context ctx, char *ktime) - com_err("krb5_string_to_timestamp", retval, 0); - return; - } -- t = (time_t) timestamp; -+ t = ts2tt(timestamp); - printf("Parsed time was %s", ctime(&t)); - } - -diff --git a/src/lib/krb5/krb/valid_times.c b/src/lib/krb5/krb/valid_times.c -index d63122183..9e509b2dd 100644 ---- a/src/lib/krb5/krb/valid_times.c -+++ b/src/lib/krb5/krb/valid_times.c -@@ -47,10 +47,10 @@ krb5int_validate_times(krb5_context context, krb5_ticket_times *times) - else - starttime = times->authtime; - -- if (starttime - currenttime > context->clockskew) -+ if (ts_delta(starttime, currenttime) > context->clockskew) - return KRB5KRB_AP_ERR_TKT_NYV; /* ticket not yet valid */ - -- if ((currenttime - times->endtime) > context->clockskew) -+ if (ts_delta(currenttime, times->endtime) > context->clockskew) - return KRB5KRB_AP_ERR_TKT_EXPIRED; /* ticket expired */ - - return 0; -diff --git a/src/lib/krb5/krb/vfy_increds.c b/src/lib/krb5/krb/vfy_increds.c -index 9786d63b5..b4878ba38 100644 ---- a/src/lib/krb5/krb/vfy_increds.c -+++ b/src/lib/krb5/krb/vfy_increds.c -@@ -120,7 +120,7 @@ get_vfy_cred(krb5_context context, krb5_creds *creds, krb5_principal server, - ret = krb5_timeofday(context, &in_creds.times.endtime); - if (ret) - goto cleanup; -- in_creds.times.endtime += 5*60; -+ in_creds.times.endtime = ts_incr(in_creds.times.endtime, 5 * 60); - ret = krb5_get_credentials(context, 0, ccache, &in_creds, &out_creds); - if (ret) - goto cleanup; -diff --git a/src/lib/krb5/os/timeofday.c b/src/lib/krb5/os/timeofday.c -index fddb12142..887f24c22 100644 ---- a/src/lib/krb5/os/timeofday.c -+++ b/src/lib/krb5/os/timeofday.c -@@ -60,7 +60,7 @@ krb5_check_clockskew(krb5_context context, krb5_timestamp date) - retval = krb5_timeofday(context, ¤ttime); - if (retval) - return retval; -- if (!(labs((date)-currenttime) < context->clockskew)) -+ if (labs(ts_delta(date, currenttime)) >= context->clockskew) - return KRB5KRB_AP_ERR_SKEW; - - return 0; -diff --git a/src/lib/krb5/os/toffset.c b/src/lib/krb5/os/toffset.c -index 456193a41..37bc69f49 100644 ---- a/src/lib/krb5/os/toffset.c -+++ b/src/lib/krb5/os/toffset.c -@@ -47,7 +47,7 @@ krb5_set_real_time(krb5_context context, krb5_timestamp seconds, krb5_int32 micr - if (retval) - return retval; - -- os_ctx->time_offset = seconds - sec; -+ os_ctx->time_offset = ts_delta(seconds, sec); - os_ctx->usec_offset = (microseconds > -1) ? microseconds - usec : 0; - - os_ctx->os_flags = ((os_ctx->os_flags & ~KRB5_OS_TOFFSET_TIME) | -diff --git a/src/lib/krb5/os/ustime.c b/src/lib/krb5/os/ustime.c -index 056357683..1c1b571eb 100644 ---- a/src/lib/krb5/os/ustime.c -+++ b/src/lib/krb5/os/ustime.c -@@ -49,13 +49,13 @@ k5_time_with_offset(krb5_timestamp offset, krb5_int32 offset_usec, - usec += offset_usec; - if (usec > 1000000) { - usec -= 1000000; -- sec++; -+ sec = ts_incr(sec, 1); - } - if (usec < 0) { - usec += 1000000; -- sec--; -+ sec = ts_incr(sec, -1); - } -- sec += offset; -+ sec = ts_incr(sec, offset); - - *time_out = sec; - *usec_out = usec; -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index c0f12ed9d..6b043844d 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -97,8 +97,7 @@ alive(krb5_int32 mytime, krb5_donot_replay *new1, krb5_deltat t) - { - if (mytime == 0) - return CMP_HOHUM; /* who cares? */ -- /* I hope we don't have to worry about overflow */ -- if (new1->ctime + t < mytime) -+ if (ts_after(mytime, ts_incr(new1->ctime, t))) - return CMP_EXPIRED; - return CMP_HOHUM; - } -diff --git a/src/lib/krb5/rcache/t_replay.c b/src/lib/krb5/rcache/t_replay.c -index db273ec2f..b99cdf1ab 100644 ---- a/src/lib/krb5/rcache/t_replay.c -+++ b/src/lib/krb5/rcache/t_replay.c -@@ -110,7 +110,7 @@ store(krb5_context ctx, char *rcspec, char *client, char *server, char *msg, - krb5_donot_replay rep; - krb5_data d; - -- if (now_timestamp > 0) -+ if (now_timestamp != 0) - krb5_set_debugging_time(ctx, now_timestamp, now_usec); - if ((retval = krb5_rc_resolve_full(ctx, &rc, rcspec))) - goto cleanup; -@@ -221,13 +221,13 @@ main(int argc, char **argv) - msg = (**argv) ? *argv : NULL; - argc--; argv++; - if (!argc) usage(progname); -- timestamp = (krb5_timestamp) atol(*argv); -+ timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - usec = (krb5_int32) atol(*argv); - argc--; argv++; - if (!argc) usage(progname); -- now_timestamp = (krb5_timestamp) atol(*argv); -+ now_timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - now_usec = (krb5_int32) atol(*argv); -@@ -249,7 +249,7 @@ main(int argc, char **argv) - rcspec = *argv; - argc--; argv++; - if (!argc) usage(progname); -- now_timestamp = (krb5_timestamp) atol(*argv); -+ now_timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - now_usec = (krb5_int32) atol(*argv); -diff --git a/src/plugins/kdb/db2/lockout.c b/src/plugins/kdb/db2/lockout.c -index 7d151b55b..3a4f41821 100644 ---- a/src/plugins/kdb/db2/lockout.c -+++ b/src/plugins/kdb/db2/lockout.c -@@ -100,7 +100,7 @@ locked_check_p(krb5_context context, - - /* If the entry was unlocked since the last failure, it's not locked. */ - if (krb5_dbe_lookup_last_admin_unlock(context, entry, &unlock_time) == 0 && -- entry->last_failed <= unlock_time) -+ !ts_after(entry->last_failed, unlock_time)) - return FALSE; - - if (max_fail == 0 || entry->fail_auth_count < max_fail) -@@ -109,7 +109,7 @@ locked_check_p(krb5_context context, - if (lockout_duration == 0) - return TRUE; /* principal permanently locked */ - -- return (stamp < entry->last_failed + lockout_duration); -+ return ts_after(ts_incr(entry->last_failed, lockout_duration), stamp); - } - - krb5_error_code -@@ -200,13 +200,13 @@ krb5_db2_lockout_audit(krb5_context context, - status == KRB5KRB_AP_ERR_BAD_INTEGRITY)) { - if (krb5_dbe_lookup_last_admin_unlock(context, entry, - &unlock_time) == 0 && -- entry->last_failed <= unlock_time) { -+ !ts_after(entry->last_failed, unlock_time)) { - /* Reset fail_auth_count after administrative unlock. */ - entry->fail_auth_count = 0; - } - - if (failcnt_interval != 0 && -- stamp > entry->last_failed + failcnt_interval) { -+ ts_after(stamp, ts_incr(entry->last_failed, failcnt_interval))) { - /* Reset fail_auth_count after failcnt_interval. */ - entry->fail_auth_count = 0; - } -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index 7ba53f959..88a170495 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -1734,7 +1734,7 @@ getstringtime(krb5_timestamp epochtime) - { - struct tm tme; - char *strtime=NULL; -- time_t posixtime = epochtime; -+ time_t posixtime = ts2tt(epochtime); - - strtime = calloc (50, 1); - if (strtime == NULL) -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -index 0fc56c2fe..1088ecc5a 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -@@ -93,7 +93,7 @@ locked_check_p(krb5_context context, - - /* If the entry was unlocked since the last failure, it's not locked. */ - if (krb5_dbe_lookup_last_admin_unlock(context, entry, &unlock_time) == 0 && -- entry->last_failed <= unlock_time) -+ !ts_after(entry->last_failed, unlock_time)) - return FALSE; - - if (max_fail == 0 || entry->fail_auth_count < max_fail) -@@ -102,7 +102,7 @@ locked_check_p(krb5_context context, - if (lockout_duration == 0) - return TRUE; /* principal permanently locked */ - -- return (stamp < entry->last_failed + lockout_duration); -+ return ts_after(ts_incr(entry->last_failed, lockout_duration), stamp); - } - - krb5_error_code -@@ -196,14 +196,14 @@ krb5_ldap_lockout_audit(krb5_context context, - status == KRB5KRB_AP_ERR_BAD_INTEGRITY)) { - if (krb5_dbe_lookup_last_admin_unlock(context, entry, - &unlock_time) == 0 && -- entry->last_failed <= unlock_time) { -+ !ts_after(entry->last_failed, unlock_time)) { - /* Reset fail_auth_count after administrative unlock. */ - entry->fail_auth_count = 0; - entry->mask |= KADM5_FAIL_AUTH_COUNT; - } - - if (failcnt_interval != 0 && -- stamp > entry->last_failed + failcnt_interval) { -+ ts_after(stamp, ts_incr(entry->last_failed, failcnt_interval))) { - /* Reset fail_auth_count after failcnt_interval */ - entry->fail_auth_count = 0; - entry->mask |= KADM5_FAIL_AUTH_COUNT; -diff --git a/src/windows/cns/tktlist.c b/src/windows/cns/tktlist.c -index f2805f5cd..26e699fae 100644 ---- a/src/windows/cns/tktlist.c -+++ b/src/windows/cns/tktlist.c -@@ -35,6 +35,8 @@ - #include "cns.h" - #include "tktlist.h" - -+#define ts2tt(t) (time_t)(uint32_t)(t) -+ - /* - * Ticket information for a list line - */ -@@ -167,10 +169,10 @@ ticket_init_list (HWND hwnd) - - ncred++; - strcpy (buf, " "); -- strncat(buf, short_date (c.times.starttime - kwin_get_epoch()), -+ strncat(buf, short_date(ts2tt(c.times.starttime) - kwin_get_epoch()), - sizeof(buf) - 1 - strlen(buf)); - strncat(buf, " ", sizeof(buf) - 1 - strlen(buf)); -- strncat(buf, short_date (c.times.endtime - kwin_get_epoch()), -+ strncat(buf, short_date(ts2tt(c.times.endtime) - kwin_get_epoch()), - sizeof(buf) - 1 - strlen(buf)); - strncat(buf, " ", sizeof(buf) - 1 - strlen(buf)); - -@@ -192,8 +194,8 @@ ticket_init_list (HWND hwnd) - return -1; - - lpinfo->ticket = TRUE; -- lpinfo->issue_time = c.times.starttime - kwin_get_epoch(); -- lpinfo->lifetime = c.times.endtime - c.times.starttime; -+ lpinfo->issue_time = ts2tt(c.times.starttime) - kwin_get_epoch(); -+ lpinfo->lifetime = ts2tt(c.times.endtime) - c.times.starttime; - strcpy(lpinfo->buf, buf); - - rc = ListBox_AddItemData(hwnd, lpinfo); -diff --git a/src/windows/include/leashwin.h b/src/windows/include/leashwin.h -index 9577365a7..325dce2e9 100644 ---- a/src/windows/include/leashwin.h -+++ b/src/windows/include/leashwin.h -@@ -111,9 +111,9 @@ struct TicketList { - TicketList *next; - char *service; - char *encTypes; -- krb5_timestamp issued; -- krb5_timestamp valid_until; -- krb5_timestamp renew_until; -+ time_t issued; -+ time_t valid_until; -+ time_t renew_until; - unsigned long flags; - }; - -@@ -124,9 +124,9 @@ struct TICKETINFO { - char *ccache_name; - TicketList *ticket_list; - int btickets; /* Do we have tickets? */ -- long issued; /* The issue time */ -- long valid_until; /* */ -- long renew_until; /* The Renew time (k5 only) */ -+ time_t issued; /* The issue time */ -+ time_t valid_until; /* */ -+ time_t renew_until; /* The Renew time (k5 only) */ - unsigned long flags; - }; - -diff --git a/src/windows/leash/KrbListTickets.cpp b/src/windows/leash/KrbListTickets.cpp -index beab0ea11..5dd37b05a 100644 ---- a/src/windows/leash/KrbListTickets.cpp -+++ b/src/windows/leash/KrbListTickets.cpp -@@ -92,10 +92,10 @@ etype_string(krb5_enctype enctype) - static void - CredToTicketInfo(krb5_creds KRBv5Credentials, TICKETINFO *ticketinfo) - { -- ticketinfo->issued = KRBv5Credentials.times.starttime; -- ticketinfo->valid_until = KRBv5Credentials.times.endtime; -+ ticketinfo->issued = (DWORD)KRBv5Credentials.times.starttime; -+ ticketinfo->valid_until = (DWORD)KRBv5Credentials.times.endtime; - ticketinfo->renew_until = KRBv5Credentials.ticket_flags & TKT_FLG_RENEWABLE ? -- KRBv5Credentials.times.renew_till : 0; -+ (DWORD)KRBv5Credentials.times.renew_till : (DWORD)0; - _tzset(); - if ( ticketinfo->valid_until - time(0) <= 0L ) - ticketinfo->btickets = EXPD_TICKETS; -@@ -137,10 +137,10 @@ CredToTicketList(krb5_context ctx, krb5_creds KRBv5Credentials, - functionName = "calloc()"; - goto cleanup; - } -- list->issued = KRBv5Credentials.times.starttime; -- list->valid_until = KRBv5Credentials.times.endtime; -+ list->issued = (DWORD)KRBv5Credentials.times.starttime; -+ list->valid_until = (DWORD)KRBv5Credentials.times.endtime; - if (KRBv5Credentials.ticket_flags & TKT_FLG_RENEWABLE) -- list->renew_until = KRBv5Credentials.times.renew_till; -+ list->renew_until = (DWORD)KRBv5Credentials.times.renew_till; - else - list->renew_until = 0; - -diff --git a/src/windows/leash/LeashView.cpp b/src/windows/leash/LeashView.cpp -index ef2a5a3e0..253ae3f06 100644 ---- a/src/windows/leash/LeashView.cpp -+++ b/src/windows/leash/LeashView.cpp -@@ -229,22 +229,22 @@ static HFONT CreateBoldItalicFont(HFONT font) - - bool change_icon_size = true; - --void krb5TimestampToFileTime(krb5_timestamp t, LPFILETIME pft) -+void TimestampToFileTime(time_t t, LPFILETIME pft) - { - // Note that LONGLONG is a 64-bit value -- LONGLONG ll; -+ ULONGLONG ll; - -- ll = Int32x32To64(t, 10000000) + 116444736000000000; -+ ll = UInt32x32To64((DWORD)t, 10000000) + 116444736000000000; - pft->dwLowDateTime = (DWORD)ll; - pft->dwHighDateTime = ll >> 32; - } - - // allocate outstr --void krb5TimestampToLocalizedString(krb5_timestamp t, LPTSTR *outStr) -+void TimestampToLocalizedString(time_t t, LPTSTR *outStr) - { - FILETIME ft, lft; - SYSTEMTIME st; -- krb5TimestampToFileTime(t, &ft); -+ TimestampToFileTime(t, &ft); - FileTimeToLocalFileTime(&ft, &lft); - FileTimeToSystemTime(&lft, &st); - TCHAR timeFormat[80]; // 80 is max required for LOCALE_STIMEFORMAT -@@ -1125,9 +1125,9 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - CCacheDisplayData *elem, - int iItem, - char *principal, -- long issued, -- long valid_until, -- long renew_until, -+ time_t issued, -+ time_t valid_until, -+ time_t renew_until, - char *encTypes, - unsigned long flags, - char *ccache_name) -@@ -1145,7 +1145,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - if (issued == 0) { - list.SetItemText(iItem, iSubItem++, "Unknown"); - } else { -- krb5TimestampToLocalizedString(issued, &localTimeStr); -+ TimestampToLocalizedString(issued, &localTimeStr); - list.SetItemText(iItem, iSubItem++, localTimeStr); - } - } -@@ -1155,7 +1155,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - } else if (valid_until < now) { - list.SetItemText(iItem, iSubItem++, "Expired"); - } else if (renew_until) { -- krb5TimestampToLocalizedString(renew_until, &localTimeStr); -+ TimestampToLocalizedString(renew_until, &localTimeStr); - DurationToString(renew_until - now, &durationStr); - if (localTimeStr && durationStr) { - _snprintf(tempStr, MAX_DURATION_STR, "%s %s", localTimeStr, durationStr); -@@ -1172,7 +1172,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - } else if (valid_until < now) { - list.SetItemText(iItem, iSubItem++, "Expired"); - } else { -- krb5TimestampToLocalizedString(valid_until, &localTimeStr); -+ TimestampToLocalizedString(valid_until, &localTimeStr); - DurationToString(valid_until - now, &durationStr); - if (localTimeStr && durationStr) { - _snprintf(tempStr, MAX_DURATION_STR, "%s %s", localTimeStr, durationStr); -diff --git a/src/windows/leashdll/lshfunc.c b/src/windows/leashdll/lshfunc.c -index 0f76cc334..8dafb7bed 100644 ---- a/src/windows/leashdll/lshfunc.c -+++ b/src/windows/leashdll/lshfunc.c -@@ -2898,7 +2898,7 @@ static BOOL cc_have_tickets(krb5_context ctx, krb5_ccache cache) - _tzset(); - while (!(code = pkrb5_cc_next_cred(ctx, cache, &cur, &creds))) { - if ((!pkrb5_is_config_principal(ctx, creds.server)) && -- (creds.times.endtime - time(0) > 0)) -+ ((time_t)(DWORD)creds.times.endtime - time(0) > 0)) - have_tickets = TRUE; - - pkrb5_free_cred_contents(ctx, &creds); -diff --git a/src/windows/ms2mit/ms2mit.c b/src/windows/ms2mit/ms2mit.c -index c3325034a..2b4373cc1 100644 ---- a/src/windows/ms2mit/ms2mit.c -+++ b/src/windows/ms2mit/ms2mit.c -@@ -74,7 +74,7 @@ cc_has_tickets(krb5_context kcontext, krb5_ccache ccache, int *has_tickets) - break; - - if (!krb5_is_config_principal(kcontext, creds.server) && -- creds.times.endtime > now) -+ ts_after(creds.times.endtime, now)) - *has_tickets = 1; - - krb5_free_cred_contents(kcontext, &creds); diff --git a/Remove-incomplete-PKINIT-OCSP-support.patch b/Remove-incomplete-PKINIT-OCSP-support.patch deleted file mode 100644 index 2f40965..0000000 --- a/Remove-incomplete-PKINIT-OCSP-support.patch +++ /dev/null @@ -1,134 +0,0 @@ -From 466d09c9b2c456d663672cb6d5f661ef86e8536e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 31 Jul 2017 16:03:41 -0400 -Subject: [PATCH] Remove incomplete PKINIT OCSP support - -pkinit_kdc_ocsp is non-functional in the PKINIT OpenSSL crypto -implementation, so remove most traces of it, including its man page -entry. If it is present in kdc.conf, error out of PKINIT -initialization instead of silently ignoring the realm entirely. - -ticket: 8603 (new) -(cherry picked from commit 3ff426b9048a8024e5c175256c63cd0ad0572320) ---- - doc/admin/conf_files/kdc_conf.rst | 3 --- - src/man/kdc.conf.man | 3 --- - src/plugins/preauth/pkinit/pkinit.h | 2 +- - src/plugins/preauth/pkinit/pkinit_identity.c | 11 ----------- - src/plugins/preauth/pkinit/pkinit_srv.c | 12 ++++++++++-- - 5 files changed, 11 insertions(+), 20 deletions(-) - -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 4e54f7e1d..d00e7926c 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -765,9 +765,6 @@ For information about the syntax of some of these options, see - pkinit is used to authenticate. This option may be specified - multiple times. (New in release 1.14.) - --**pkinit_kdc_ocsp** -- Specifies the location of the KDC's OCSP. -- - **pkinit_pool** - Specifies the location of intermediate certificates which may be - used by the KDC to complete the trust chain between a client's -diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index d207ebd7f..c47da0117 100644 ---- a/src/man/kdc.conf.man -+++ b/src/man/kdc.conf.man -@@ -886,9 +886,6 @@ Specifies an authentication indicator to include in the ticket if - pkinit is used to authenticate. This option may be specified - multiple times. (New in release 1.14.) - .TP --.B \fBpkinit_kdc_ocsp\fP --Specifies the location of the KDC\(aqs OCSP. --.TP - .B \fBpkinit_pool\fP - Specifies the location of intermediate certificates which may be - used by the KDC to complete the trust chain between a client\(aqs -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index 876db94c3..a49f3078e 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -73,6 +73,7 @@ - #define KRB5_CONF_PKINIT_IDENTITIES "pkinit_identities" - #define KRB5_CONF_PKINIT_IDENTITY "pkinit_identity" - #define KRB5_CONF_PKINIT_KDC_HOSTNAME "pkinit_kdc_hostname" -+/* pkinit_kdc_ocsp has been removed */ - #define KRB5_CONF_PKINIT_KDC_OCSP "pkinit_kdc_ocsp" - #define KRB5_CONF_PKINIT_POOL "pkinit_pool" - #define KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING "pkinit_require_crl_checking" -@@ -173,7 +174,6 @@ typedef struct _pkinit_identity_opts { - char **anchors; - char **intermediates; - char **crls; -- char *ocsp; - int idtype; - char *cert_filename; - char *key_filename; -diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c -index 177a2cad8..a897efa25 100644 ---- a/src/plugins/preauth/pkinit/pkinit_identity.c -+++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -125,7 +125,6 @@ pkinit_init_identity_opts(pkinit_identity_opts **idopts) - opts->anchors = NULL; - opts->intermediates = NULL; - opts->crls = NULL; -- opts->ocsp = NULL; - - opts->cert_filename = NULL; - opts->key_filename = NULL; -@@ -174,12 +173,6 @@ pkinit_dup_identity_opts(pkinit_identity_opts *src_opts, - if (retval) - goto cleanup; - -- if (src_opts->ocsp != NULL) { -- newopts->ocsp = strdup(src_opts->ocsp); -- if (newopts->ocsp == NULL) -- goto cleanup; -- } -- - if (src_opts->cert_filename != NULL) { - newopts->cert_filename = strdup(src_opts->cert_filename); - if (newopts->cert_filename == NULL) -@@ -674,10 +667,6 @@ pkinit_identity_prompt(krb5_context context, - if (retval) - goto errout; - } -- if (idopts->ocsp != NULL) { -- retval = ENOTSUP; -- goto errout; -- } - - errout: - return retval; -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 731d14eb8..32ca122f2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -1252,7 +1252,7 @@ static krb5_error_code - pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) - { - krb5_error_code retval; -- char *eku_string = NULL; -+ char *eku_string = NULL, *ocsp_check = NULL; - - pkiDebug("%s: entered for realm %s\n", __FUNCTION__, plgctx->realmname); - retval = pkinit_kdcdefault_string(context, plgctx->realmname, -@@ -1287,7 +1287,15 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) - - pkinit_kdcdefault_string(context, plgctx->realmname, - KRB5_CONF_PKINIT_KDC_OCSP, -- &plgctx->idopts->ocsp); -+ &ocsp_check); -+ if (ocsp_check != NULL) { -+ free(ocsp_check); -+ retval = ENOTSUP; -+ krb5_set_error_message(context, retval, -+ _("OCSP is not supported: (realm: %s)"), -+ plgctx->realmname); -+ goto errout; -+ } - - pkinit_kdcdefault_integer(context, plgctx->realmname, - KRB5_CONF_PKINIT_DH_MIN_BITS, diff --git a/Use-GSSAPI-fallback-skiptest.patch b/Use-GSSAPI-fallback-skiptest.patch deleted file mode 100644 index 118df5a..0000000 --- a/Use-GSSAPI-fallback-skiptest.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 6d0b40b26e7fea1cd394618c1ab6d5e366bbc069 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 1 Mar 2017 17:46:22 -0500 -Subject: [PATCH] Use GSSAPI fallback skiptest - -Also-authored-by: Matt Rogers -[rharwood@redhat.com: Adjusted patch to apply] ---- - src/appl/gss-sample/Makefile.in | 6 +++++- - 1 file changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/appl/gss-sample/Makefile.in b/src/appl/gss-sample/Makefile.in -index 28e59f90f..9806fd327 100644 ---- a/src/appl/gss-sample/Makefile.in -+++ b/src/appl/gss-sample/Makefile.in -@@ -6,6 +6,8 @@ SRCS= $(srcdir)/gss-client.c $(srcdir)/gss-misc.c $(srcdir)/gss-server.c - - OBJS= gss-client.o gss-misc.o gss-server.o - -+LBITS = $(shell /usr/bin/getconf LONG_BIT) -+ - all-unix: gss-server gss-client - - ##WIN32##VERSIONRC = $(BUILDTOP)\windows\version.rc -@@ -43,7 +45,9 @@ clean-unix:: - $(RM) gss-server gss-client - - check-pytests: -- $(RUNPYTEST) $(srcdir)/t_gss_sample.py $(PYTESTFLAGS) -+ if ! [ $(LBITS) -eq 32 ]; then \ -+ $(RUNPYTEST) $(srcdir)/t_gss_sample.py $(PYTESTFLAGS); \ -+ fi - - install-unix: - $(INSTALL_PROGRAM) gss-client $(DESTDIR)$(CLIENT_BINDIR)/gss-client diff --git a/Use-expected_msg-in-test-scripts.patch b/Use-expected_msg-in-test-scripts.patch deleted file mode 100644 index d4dc83e..0000000 --- a/Use-expected_msg-in-test-scripts.patch +++ /dev/null @@ -1,2584 +0,0 @@ -From 24ac588502b1731a7fd2629804f8d9ed1668297e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 18 Jan 2017 11:22:58 -0500 -Subject: [PATCH] Use expected_msg in test scripts - -(cherry picked from commit d406afa363554097ac48646a29249c04f498c88e) ---- - src/appl/gss-sample/t_gss_sample.py | 18 ++- - src/appl/user_user/t_user2user.py | 6 +- - src/kdc/t_emptytgt.py | 5 +- - src/lib/krb5/krb/t_expire_warn.py | 13 +- - src/tests/gssapi/t_authind.py | 5 +- - src/tests/gssapi/t_ccselect.py | 10 +- - src/tests/gssapi/t_client_keytab.py | 60 +++------ - src/tests/gssapi/t_enctypes.py | 4 +- - src/tests/gssapi/t_export_cred.py | 4 +- - src/tests/gssapi/t_gssapi.py | 97 +++++--------- - src/tests/gssapi/t_s4u.py | 21 ++- - src/tests/t_audit.py | 11 +- - src/tests/t_authdata.py | 58 +++----- - src/tests/t_ccache.py | 38 ++---- - src/tests/t_crossrealm.py | 14 +- - src/tests/t_dump.py | 31 ++--- - src/tests/t_general.py | 12 +- - src/tests/t_hostrealm.py | 5 +- - src/tests/t_iprop.py | 103 ++++++--------- - src/tests/t_kadm5_hook.py | 10 +- - src/tests/t_kadmin_acl.py | 254 ++++++++++++++---------------------- - src/tests/t_kadmin_parsing.py | 30 ++--- - src/tests/t_kdb.py | 127 +++++++----------- - src/tests/t_kdb_locking.py | 5 +- - src/tests/t_keydata.py | 16 +-- - src/tests/t_keyrollover.py | 16 +-- - src/tests/t_keytab.py | 50 +++---- - src/tests/t_kprop.py | 13 +- - src/tests/t_localauth.py | 5 +- - src/tests/t_mkey.py | 45 +++---- - src/tests/t_otp.py | 10 +- - src/tests/t_pkinit.py | 27 ++-- - src/tests/t_policy.py | 101 +++++--------- - src/tests/t_preauth.py | 14 +- - src/tests/t_pwqual.py | 25 ++-- - src/tests/t_referral.py | 10 +- - src/tests/t_renew.py | 5 +- - src/tests/t_salt.py | 12 +- - src/tests/t_skew.py | 22 ++-- - src/tests/t_stringattr.py | 4 +- - 40 files changed, 475 insertions(+), 841 deletions(-) - -diff --git a/src/appl/gss-sample/t_gss_sample.py b/src/appl/gss-sample/t_gss_sample.py -index 8a6b0304f..0299e4590 100755 ---- a/src/appl/gss-sample/t_gss_sample.py -+++ b/src/appl/gss-sample/t_gss_sample.py -@@ -31,22 +31,20 @@ gss_server = os.path.join(appdir, 'gss-server') - # Run a gss-server process and a gss-client process, with additional - # gss-client flags given by options and additional gss-server flags - # given by server_options. Return the output of gss-client. --def run_client_server(realm, options, server_options, expected_code=0): -+def run_client_server(realm, options, server_options, **kwargs): - portstr = str(realm.server_port()) - server_args = [gss_server, '-export', '-port', portstr] - server_args += server_options + ['host'] - server = realm.start_server(server_args, 'starting...') -- out = realm.run([gss_client, '-port', portstr] + options + -- [hostname, 'host', 'testmsg'], expected_code=expected_code) -+ realm.run([gss_client, '-port', portstr] + options + -+ [hostname, 'host', 'testmsg'], **kwargs) - stop_daemon(server) -- return out - - # Run a gss-server and gss-client process, and verify that gss-client - # displayed the expected output for a successful negotiation. - def server_client_test(realm, options, server_options): -- out = run_client_server(realm, options, server_options) -- if 'Signature verified.' not in out: -- fail('Expected message not seen in gss-client output') -+ run_client_server(realm, options, server_options, -+ expected_msg='Signature verified.') - - # Make up a filename to hold user's initial credentials. - def ccache_savefile(realm): -@@ -81,10 +79,10 @@ def pw_test(realm, options, server_options=[]): - # IAKERB, gss_aqcuire_cred_with_password() otherwise). - def wrong_pw_test(realm, options, server_options=[], iakerb=False): - options = options + ['-user', realm.user_princ, '-pass', 'wrongpw'] -- out = run_client_server(realm, options, server_options, expected_code=1) - failed_op = 'initializing context' if iakerb else 'acquiring creds' -- if 'GSS-API error ' + failed_op not in out: -- fail('Expected error not seen in gss-client output') -+ msg = 'GSS-API error ' + failed_op -+ run_client_server(realm, options, server_options, expected_code=1, -+ expected_msg=msg) - - # Perform a test of the server and client with initial credentials - # obtained with the client keytab -diff --git a/src/appl/user_user/t_user2user.py b/src/appl/user_user/t_user2user.py -index 8bdef8e07..2a7d03f8d 100755 ---- a/src/appl/user_user/t_user2user.py -+++ b/src/appl/user_user/t_user2user.py -@@ -10,9 +10,9 @@ for realm in multipass_realms(): - else: - srv_output = realm.start_server(['./uuserver', '9999'], 'Server started') - -- output = realm.run(['./uuclient', hostname, 'testing message', '9999']) -- if 'uu-client: server says \"Hello, other end of connection.\"' not in output: -- fail('Message not echoed back.') -+ msg = 'uu-client: server says "Hello, other end of connection."' -+ realm.run(['./uuclient', hostname, 'testing message', '9999'], -+ expected_msg=msg) - - - success('User-2-user test programs') -diff --git a/src/kdc/t_emptytgt.py b/src/kdc/t_emptytgt.py -index 8f7717a01..2d0432e33 100755 ---- a/src/kdc/t_emptytgt.py -+++ b/src/kdc/t_emptytgt.py -@@ -2,7 +2,6 @@ - from k5test import * - - realm = K5Realm(create_host=False) --output = realm.run([kvno, 'krbtgt/'], expected_code=1) --if 'not found in Kerberos database' not in output: -- fail('TGT lookup for empty realm failed in unexpected way') -+realm.run([kvno, 'krbtgt/'], expected_code=1, -+ expected_msg='not found in Kerberos database') - success('Empty tgt lookup.') -diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py -index e021379ab..aed39e399 100755 ---- a/src/lib/krb5/krb/t_expire_warn.py -+++ b/src/lib/krb5/krb/t_expire_warn.py -@@ -39,15 +39,10 @@ realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '3 days', 'days']) - output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0']) - if output: - fail('Unexpected output for noexpire') --output = realm.run(['./t_expire_warn', 'minutes', 'pass', '0']) --if ' less than one hour on ' not in output: -- fail('Expected warning not seen for minutes') --output = realm.run(['./t_expire_warn', 'hours', 'pass', '0']) --if ' hours on ' not in output: -- fail('Expected warning not seen for hours') --output = realm.run(['./t_expire_warn', 'days', 'pass', '0']) --if ' days on ' not in output: -- fail('Expected warning not seen for days') -+realm.run(['./t_expire_warn', 'minutes', 'pass', '0'], -+ expected_msg=' less than one hour on ') -+realm.run(['./t_expire_warn', 'hours', 'pass', '0'], expected_msg=' hours on ') -+realm.run(['./t_expire_warn', 'days', 'pass', '0'], expected_msg=' days on ') - - # Check for expected expire callback behavior. These tests are - # carefully agnostic about whether the KDC supports last_req fields, -diff --git a/src/tests/gssapi/t_authind.py b/src/tests/gssapi/t_authind.py -index 316bc4093..dfd0a9a04 100644 ---- a/src/tests/gssapi/t_authind.py -+++ b/src/tests/gssapi/t_authind.py -@@ -24,9 +24,8 @@ if ('Attribute auth-indicators Authenticated Complete') not in out: - if '73757065727374726f6e67' not in out: - fail('Expected auth indicator not seen in name attributes') - --out = realm.run(['./t_srcattrs', 'p:service/2'], expected_code=1) --if 'gss_init_sec_context: KDC policy rejects request' not in out: -- fail('Expected error message not seen for indicator mismatch') -+msg = 'gss_init_sec_context: KDC policy rejects request' -+realm.run(['./t_srcattrs', 'p:service/2'], expected_code=1, expected_msg=msg) - - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=one two']) - out = realm.run(['./t_srcattrs', 'p:service/2']) -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 6be6b4ec0..1ea614d30 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -45,9 +45,8 @@ refserver = 'p:host/' + hostname + '@' - - # Verify that we can't get initiator creds with no credentials in the - # collection. --output = r1.run(['./t_ccselect', host1, '-'], expected_code=1) --if 'No Kerberos credentials available' not in output: -- fail('Expected error not seen in output when no credentials available') -+r1.run(['./t_ccselect', host1, '-'], expected_code=1, -+ expected_msg='No Kerberos credentials available') - - # Make a directory collection and use it for client commands in both realms. - ccdir = os.path.join(r1.testdir, 'cc') -@@ -117,8 +116,7 @@ if output != (zaphod + '\n'): - output = r1.run(['./t_ccselect', refserver]) - if output != (bob + '\n'): - fail('bob not chosen via primary cache when no .k5identity line matches.') --output = r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1) --if 'Can\'t find client principal noprinc' not in output: -- fail('Expected error not seen when k5identity selects bad principal.') -+r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1, -+ expected_msg="Can't find client principal noprinc") - - success('GSSAPI credential selection tests') -diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py -index 4c8747a50..2da87f45b 100755 ---- a/src/tests/gssapi/t_client_keytab.py -+++ b/src/tests/gssapi/t_client_keytab.py -@@ -15,9 +15,7 @@ realm.extract_keytab(realm.user_princ, realm.client_keytab) - realm.extract_keytab(bob, realm.client_keytab) - - # Test 1: no name/cache specified, pick first principal from client keytab --out = realm.run(['./t_ccselect', phost]) --if realm.user_princ not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost], expected_msg=realm.user_princ) - realm.run([kdestroy]) - - # Test 2: no name/cache specified, pick principal from k5identity -@@ -25,36 +23,27 @@ k5idname = os.path.join(realm.testdir, '.k5identity') - k5id = open(k5idname, 'w') - k5id.write('%s service=host host=%s\n' % (bob, hostname)) - k5id.close() --out = realm.run(['./t_ccselect', gssserver]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', gssserver], expected_msg=bob) - os.remove(k5idname) - realm.run([kdestroy]) - - # Test 3: no name/cache specified, default ccache has name but no creds - realm.run(['./ccinit', realm.ccache, bob]) --out = realm.run(['./t_ccselect', phost]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost], expected_msg=bob) - # Leave tickets for next test. - - # Test 4: name specified, non-collectable default cache doesn't match --out = realm.run(['./t_ccselect', phost, puser], expected_code=1) --if 'Principal in credential cache does not match desired name' not in out: -- fail('Expected error not seen') -+msg = 'Principal in credential cache does not match desired name' -+realm.run(['./t_ccselect', phost, puser], expected_code=1, expected_msg=msg) - realm.run([kdestroy]) - - # Test 5: name specified, nonexistent default cache --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Leave tickets for next test. - - # Test 6: name specified, matches default cache, time to refresh - realm.run(['./ccrefresh', realm.ccache, '1']) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - out = realm.run(['./ccrefresh', realm.ccache]) - if int(out) < 1000: - fail('Credentials apparently not refreshed') -@@ -67,9 +56,8 @@ realm.run([kdestroy]) - - # Test 8: ccache specified with name but no creds; name not in client keytab - realm.run(['./ccinit', realm.ccache, realm.host_princ]) --out = realm.run(['./t_imp_cred', phost], expected_code=1) --if 'Credential cache is empty' not in out: -- fail('Expected error not seen') -+realm.run(['./t_imp_cred', phost], expected_code=1, -+ expected_msg='Credential cache is empty') - realm.run([kdestroy]) - - # Test 9: ccache specified with name but no creds; name in client keytab -@@ -104,16 +92,12 @@ realm.env['KRB5CCNAME'] = ccname - # Test 12: name specified, matching cache in collection with no creds - bobcache = os.path.join(ccdir, 'tktbob') - realm.run(['./ccinit', bobcache, bob]) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Leave tickets for next test. - - # Test 13: name specified, matching cache in collection, time to refresh - realm.run(['./ccrefresh', bobcache, '1']) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - out = realm.run(['./ccrefresh', bobcache]) - if int(out) < 1000: - fail('Credentials apparently not refreshed') -@@ -121,22 +105,15 @@ realm.run([kdestroy, '-A']) - - # Test 14: name specified, collection has default for different principal - realm.kinit(realm.user_princ, password('user')) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') --out = realm.run([klist]) --if 'Default principal: %s\n' % realm.user_princ not in out: -- fail('Default cache overwritten by acquire_cred') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) -+msg = 'Default principal: %s\n' % realm.user_princ -+realm.run([klist], expected_msg=msg) - realm.run([kdestroy, '-A']) - - # Test 15: name specified, collection has no default cache --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Make sure the tickets we acquired didn't become the default --out = realm.run([klist], expected_code=1) --if 'No credentials cache found' not in out: -- fail('Expected error not seen') -+realm.run([klist], expected_code=1, expected_msg='No credentials cache found') - realm.run([kdestroy, '-A']) - - # Test 16: default client keytab cannot be resolved, but valid -@@ -145,8 +122,7 @@ conf = {'libdefaults': {'default_client_keytab_name': '%{'}} - bad_cktname = realm.special_env('bad_cktname', False, krb5_conf=conf) - del bad_cktname['KRB5_CLIENT_KTNAME'] - realm.kinit(realm.user_princ, password('user')) --out = realm.run(['./t_ccselect', phost], env=bad_cktname) --if realm.user_princ not in out: -- fail('Expected principal not seen for bad client keytab name') -+realm.run(['./t_ccselect', phost], env=bad_cktname, -+ expected_msg=realm.user_princ) - - success('Client keytab tests') -diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index 862f22989..f513db2b5 100755 ---- a/src/tests/gssapi/t_enctypes.py -+++ b/src/tests/gssapi/t_enctypes.py -@@ -58,9 +58,7 @@ def test(msg, ienc, aenc, tktenc='', tktsession='', proto='', isubkey='', - # and check that it fails with the expected error message. - def test_err(msg, ienc, aenc, expected_err): - shutil.copyfile(os.path.join(realm.testdir, 'save'), realm.ccache) -- out = realm.run(cmdline(ienc, aenc), expected_code=1) -- if expected_err not in out: -- fail(msg) -+ realm.run(cmdline(ienc, aenc), expected_code=1, expected_msg=expected_err) - - - # By default, all of the key enctypes should be aes256. -diff --git a/src/tests/gssapi/t_export_cred.py b/src/tests/gssapi/t_export_cred.py -index 698835928..b98962788 100755 ---- a/src/tests/gssapi/t_export_cred.py -+++ b/src/tests/gssapi/t_export_cred.py -@@ -23,9 +23,7 @@ def ccache_restore(realm): - def check(realm, args): - ccache_restore(realm) - realm.run(['./t_export_cred'] + args) -- output = realm.run([klist, '-f']) -- if 'Flags: Ff' not in output: -- fail('Forwarded tickets not found in ccache after t_export_cred') -+ realm.run([klist, '-f'], expected_msg='Flags: Ff') - - # Check a given set of arguments with no specified mech and with krb5 - # and SPNEGO as the specified mech. -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index e23c936d7..397e58962 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -28,57 +28,40 @@ realm.run([kadminl, 'renprinc', 'service1/abraham', 'service1/andrew']) - - # Test with no acceptor name, including client/keytab principal - # mismatch (non-fatal) and missing keytab entry (fatal). --output = realm.run(['./t_accname', 'p:service1/andrew']) --if 'service1/abraham' not in output: -- fail('Expected service1/abraham in t_accname output') --output = realm.run(['./t_accname', 'p:service1/barack']) --if 'service1/barack' not in output: -- fail('Expected service1/barack in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin']) --if 'service2/calvin' not in output: -- fail('Expected service1/barack in t_accname output') --output = realm.run(['./t_accname', 'p:service2/dwight'], expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:service1/andrew'], -+ expected_msg='service1/abraham') -+realm.run(['./t_accname', 'p:service1/barack'], expected_msg='service1/barack') -+realm.run(['./t_accname', 'p:service2/calvin'], expected_msg='service2/calvin') -+realm.run(['./t_accname', 'p:service2/dwight'], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test with acceptor name containing service only, including - # client/keytab hostname mismatch (non-fatal) and service name - # mismatch (fatal). --output = realm.run(['./t_accname', 'p:service1/andrew', 'h:service1']) --if 'service1/abraham' not in output: -- fail('Expected service1/abraham in t_accname output') --output = realm.run(['./t_accname', 'p:service1/andrew', 'h:service2'], -- expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin', 'h:service2']) --if 'service2/calvin' not in output: -- fail('Expected service2/calvin in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], -- expected_code=1) --if ' found in keytab but does not match server principal' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:service1/andrew', 'h:service1'], -+ expected_msg='service1/abraham') -+realm.run(['./t_accname', 'p:service1/andrew', 'h:service2'], expected_code=1, -+ expected_msg=' not found in keytab') -+realm.run(['./t_accname', 'p:service2/calvin', 'h:service2'], -+ expected_msg='service2/calvin') -+realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], expected_code=1, -+ expected_msg=' found in keytab but does not match server principal') - - # Test with acceptor name containing service and host. Use the - # client's un-canonicalized hostname as acceptor input to mirror what - # many servers do. --output = realm.run(['./t_accname', 'p:' + realm.host_princ, -- 'h:host@%s' % socket.gethostname()]) --if realm.host_princ not in output: -- fail('Expected %s in t_accname output' % realm.host_princ) --output = realm.run(['./t_accname', 'p:host/-nomatch-', -- 'h:host@%s' % socket.gethostname()], -- expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:' + realm.host_princ, -+ 'h:host@%s' % socket.gethostname()], expected_msg=realm.host_princ) -+realm.run(['./t_accname', 'p:host/-nomatch-', -+ 'h:host@%s' % socket.gethostname()], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test krb5_gss_import_cred. - realm.run(['./t_imp_cred', 'p:service1/barack']) - realm.run(['./t_imp_cred', 'p:service1/barack', 'service1/barack']) - realm.run(['./t_imp_cred', 'p:service1/andrew', 'service1/abraham']) --output = realm.run(['./t_imp_cred', 'p:service2/dwight'], expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_imp_cred output') -+realm.run(['./t_imp_cred', 'p:service2/dwight'], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test credential store extension. - tmpccname = 'FILE:' + os.path.join(realm.testdir, 'def_cache') -@@ -116,10 +99,8 @@ ignore_conf = {'libdefaults': {'ignore_acceptor_hostname': 'true'}} - realm = K5Realm(krb5_conf=ignore_conf) - realm.run([kadminl, 'addprinc', '-randkey', 'host/-nomatch-']) - realm.run([kadminl, 'xst', 'host/-nomatch-']) --output = realm.run(['./t_accname', 'p:host/-nomatch-', -- 'h:host@%s' % socket.gethostname()]) --if 'host/-nomatch-' not in output: -- fail('Expected host/-nomatch- in t_accname output') -+realm.run(['./t_accname', 'p:host/-nomatch-', -+ 'h:host@%s' % socket.gethostname()], expected_msg='host/-nomatch-') - - realm.stop() - -@@ -141,41 +122,25 @@ r3.stop() - realm = K5Realm() - - # Test deferred resolution of the default ccache for initiator creds. --output = realm.run(['./t_inq_cred']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) --output = realm.run(['./t_inq_cred', '-k']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) --output = realm.run(['./t_inq_cred', '-s']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) -+realm.run(['./t_inq_cred'], expected_msg=realm.user_princ) -+realm.run(['./t_inq_cred', '-k'], expected_msg=realm.user_princ) -+realm.run(['./t_inq_cred', '-s'], expected_msg=realm.user_princ) - - # Test picking a name from the keytab for acceptor creds. --output = realm.run(['./t_inq_cred', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) --output = realm.run(['./t_inq_cred', '-k', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) --output = realm.run(['./t_inq_cred', '-s', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) -+realm.run(['./t_inq_cred', '-a'], expected_msg=realm.host_princ) -+realm.run(['./t_inq_cred', '-k', '-a'], expected_msg=realm.host_princ) -+realm.run(['./t_inq_cred', '-s', '-a'], expected_msg=realm.host_princ) - - # Test client keytab initiation (non-deferred) with a specified name. - realm.extract_keytab(realm.user_princ, realm.client_keytab) - os.remove(realm.ccache) --output = realm.run(['./t_inq_cred', '-k']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) -+realm.run(['./t_inq_cred', '-k'], expected_msg=realm.user_princ) - - # Test deferred client keytab initiation and GSS_C_BOTH cred usage. - os.remove(realm.client_keytab) - os.remove(realm.ccache) - shutil.copyfile(realm.keytab, realm.client_keytab) --output = realm.run(['./t_inq_cred', '-k', '-b']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) -+realm.run(['./t_inq_cred', '-k', '-b'], expected_msg=realm.host_princ) - - # Test gss_export_name behavior. - out = realm.run(['./t_export_name', 'u:x']) -diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py -index 7366e3915..e4cd68469 100755 ---- a/src/tests/gssapi/t_s4u.py -+++ b/src/tests/gssapi/t_s4u.py -@@ -42,10 +42,8 @@ if ('auth1: ' + realm.user_princ not in output or - # result in no delegated credential being created by - # accept_sec_context. - realm.kinit(realm.user_princ, password('user'), ['-c', usercache]) --output = realm.run(['./t_s4u2proxy_krb5', usercache, storagecache, pservice1, -- pservice1, pservice2]) --if 'no credential delegated' not in output: -- fail('krb5 -> no delegated cred') -+realm.run(['./t_s4u2proxy_krb5', usercache, storagecache, pservice1, -+ pservice1, pservice2], expected_msg='no credential delegated') - - # Try S4U2Self. Ask for an S4U2Proxy step; this won't happen because - # service/1 isn't allowed to get a forwardable S4U2Self ticket. -@@ -61,17 +59,15 @@ if ('Warning: no delegated cred handle' not in output or - # Correct that problem and try again. As above, the S4U2Proxy step - # won't actually succeed since we don't support that in DB2. - realm.run([kadminl, 'modprinc', '+ok_to_auth_as_delegate', service1]) --output = realm.run(['./t_s4u', puser, pservice2], expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in output: -- fail('s4u2self') -+realm.run(['./t_s4u', puser, pservice2], expected_code=1, -+ expected_msg='NOT_ALLOWED_TO_DELEGATE') - - # Again with SPNEGO. This uses SPNEGO for the initial authentication, - # but still uses krb5 for S4U2Proxy--the delegated cred is returned as - # a krb5 cred, not a SPNEGO cred, and t_s4u uses the delegated cred - # directly rather than saving and reacquiring it. --output = realm.run(['./t_s4u', '--spnego', puser, pservice2], expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in output: -- fail('s4u2self') -+realm.run(['./t_s4u', '--spnego', puser, pservice2], expected_code=1, -+ expected_msg='NOT_ALLOWED_TO_DELEGATE') - - realm.stop() - -@@ -148,9 +144,8 @@ realm.stop() - # fail, but we can check that the right server principal was used. - r1, r2 = cross_realms(2, create_user=False) - r1.run([kinit, '-k', r1.host_princ]) --out = r1.run(['./t_s4u', 'p:' + r2.host_princ], expected_code=1) --if 'Server not found in Kerberos database' not in out: -- fail('cross-realm s4u2self (t_s4u output)') -+r1.run(['./t_s4u', 'p:' + r2.host_princ], expected_code=1, -+ expected_msg='Server not found in Kerberos database') - r1.stop() - r2.stop() - with open(os.path.join(r2.testdir, 'kdc.log')) as f: -diff --git a/src/tests/t_audit.py b/src/tests/t_audit.py -index 69c9251e0..00e96bfea 100755 ---- a/src/tests/t_audit.py -+++ b/src/tests/t_audit.py -@@ -14,18 +14,15 @@ realm.run([kvno, 'target']) - - # Make S4U2Self and S4U2Proxy requests so they will be audited. The - # S4U2Proxy request is expected to fail. --out = realm.run([kvno, '-k', realm.keytab, '-U', 'user', '-P', 'target'], -- expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in out: -- fail('Unexpected error for S4U2Proxy') -+realm.run([kvno, '-k', realm.keytab, '-U', 'user', '-P', 'target'], -+ expected_code=1, expected_msg='NOT_ALLOWED_TO_DELEGATE') - - # Make a U2U request so it will be audited. - uuserver = os.path.join(buildtop, 'appl', 'user_user', 'uuserver') - uuclient = os.path.join(buildtop, 'appl', 'user_user', 'uuclient') - port_arg = str(realm.server_port()) - realm.start_server([uuserver, port_arg], 'Server started') --output = realm.run([uuclient, hostname, 'testing message', port_arg]) --if 'Hello' not in output: -- fail('U2U request failed unexpectedly') -+realm.run([uuclient, hostname, 'testing message', port_arg], -+ expected_msg='Hello') - - success('Audit tests') -diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 33525022b..dd92b338f 100644 ---- a/src/tests/t_authdata.py -+++ b/src/tests/t_authdata.py -@@ -24,10 +24,8 @@ if ' -5: test1' not in out or '?-6: test2' not in out: - if 'fake' in out: - fail('KDC-only authdata not filtered for request with authdata') - --out = realm.run(['./adata', realm.host_princ, '!-1', 'mandatoryforkdc'], -- expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('Wrong error seen for mandatory-for-kdc failure') -+realm.run(['./adata', realm.host_princ, '!-1', 'mandatoryforkdc'], -+ expected_code=1, expected_msg='KDC policy rejects request') - - # The no_auth_data_required server flag should suppress SIGNTICKET, - # but not module or request authdata. -@@ -98,45 +96,32 @@ realm2.extract_keytab('krbtgt/LOCAL', realm.keytab) - # AS request to local-realm service - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl', '-r', '2d', '-S', realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for AS req to service') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Ticket modification request - realm.kinit(realm.user_princ, None, ['-R', '-S', realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for ticket modification request') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # AS request to cross TGT - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl', '-S', 'krbtgt/FOREIGN']) --out = realm.run(['./adata', 'krbtgt/FOREIGN']) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for AS req to cross-realm TGT') -+realm.run(['./adata', 'krbtgt/FOREIGN'], expected_msg='+97: [indcl]') - - # Multiple indicators - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl indcl2 indcl3']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indcl, indcl2, indcl3]' not in out: -- fail('multiple auth-indicators not seen for normal AS req') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indcl, indcl2, indcl3]') - - # AS request to local TGT (resulting creds are used for TGS tests) - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=indcl']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for normal AS req') -+realm.run(['./adata', realm.krbtgt_princ], expected_msg='+97: [indcl]') - - # Local TGS request for local realm service --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for local TGS req') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Local TGS request for cross TGT service --out = realm.run(['./adata', 'krbtgt/FOREIGN']) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for TGS req to cross-realm TGT') -+realm.run(['./adata', 'krbtgt/FOREIGN'], expected_msg='+97: [indcl]') - - # We don't yet have support for passing auth indicators across realms, - # so just verify that indicators don't survive cross-realm requests. -@@ -152,16 +137,13 @@ if '97:' in out: - - # Test that the CAMMAC signature still works during a krbtgt rollover. - realm.run([kadminl, 'cpw', '-randkey', '-keepold', realm.krbtgt_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for local TGS req after krbtgt rotation') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Test indicator enforcement. - realm.addprinc('restricted') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'superstrong']) --out = realm.run([kvno, 'restricted'], expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('expected error not seen for auth indicator enforcement') -+realm.run([kvno, 'restricted'], expected_code=1, -+ expected_msg='KDC policy rejects request') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'indcl']) - realm.run([kvno, 'restricted']) - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=ind1 ind2']) -@@ -222,13 +204,11 @@ if '+97: [indcl]' not in out or '[inds1]' in out: - # Test that KDB module authdata is included in an AS request, by - # default or with an explicit PAC request. - realm.kinit(realm.user_princ, None, ['-k']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen in default AS request') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='-456: db-authdata-test') - realm.kinit(realm.user_princ, None, ['-k', '--request-pac']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen with --request-pac') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='-456: db-authdata-test') - - # Test that KDB module authdata is suppressed in an AS request by a - # negative PAC request. -@@ -238,9 +218,7 @@ if '-456: db-authdata-test' in out: - fail('DB authdata not suppressed by --no-request-pac') - - # Test that KDB authdata is included in a TGS request by default. --out = realm.run(['./adata', 'service/1']) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen in TGS request') -+realm.run(['./adata', 'service/1'], expected_msg='-456: db-authdata-test') - - # Test that KDB authdata is suppressed in a TGS request by the - # +no_auth_data_required flag. -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index 47d963130..2dcd19102 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -35,15 +35,11 @@ if not test_keyring: - - # Test kdestroy and klist of a non-existent ccache. - realm.run([kdestroy]) --output = realm.run([klist], expected_code=1) --if 'No credentials cache found' not in output: -- fail('Expected error message not seen in klist output') -+realm.run([klist], expected_code=1, expected_msg='No credentials cache found') - - # Test kinit with an inaccessible ccache. --out = realm.run([kinit, '-c', 'testdir/xx/yy', realm.user_princ], -- input=(password('user') + '\n'), expected_code=1) --if 'Failed to store credentials' not in out: -- fail('Expected error message not seen in kinit output') -+realm.kinit(realm.user_princ, password('user'), flags=['-c', 'testdir/xx/yy'], -+ expected_code=1, expected_msg='Failed to store credentials') - - # Test klist -s with a single ccache. - realm.run([klist, '-s'], expected_code=1) -@@ -65,9 +61,7 @@ def collection_test(realm, ccname): - - realm.run([klist, '-A', '-s'], expected_code=1) - realm.kinit('alice', password('alice')) -- output = realm.run([klist]) -- if 'Default principal: alice@' not in output: -- fail('Initial kinit failed to get credentials for alice.') -+ realm.run([klist], expected_msg='Default principal: alice@') - realm.run([klist, '-A', '-s']) - realm.run([kdestroy]) - output = realm.run([klist], expected_code=1) -@@ -130,25 +124,20 @@ if test_keyring: - realm.env['KRB5CCNAME'] = 'KEYRING:' + cname - realm.run([kdestroy, '-A']) - realm.kinit(realm.user_princ, password('user')) -- out = realm.run([klist, '-l']) -- if 'KEYRING:legacy:' + cname + ':' + cname not in out: -- fail('Wrong initial primary name in keyring legacy collection') -+ msg = 'KEYRING:legacy:' + cname + ':' + cname -+ realm.run([klist, '-l'], expected_msg=msg) - # Make sure this cache is linked to the session keyring. - id = realm.run([keyctl, 'search', '@s', 'keyring', cname]) -- out = realm.run([keyctl, 'list', id.strip()]) -- if 'user: __krb5_princ__' not in out: -- fail('Legacy cache not linked into session keyring') -+ realm.run([keyctl, 'list', id.strip()], -+ expected_msg='user: __krb5_princ__') - # Remove the collection keyring. When the collection is - # reinitialized, the legacy cache should reappear inside it - # automatically as the primary cache. - cleanup_keyring('@s', col_ringname) -- out = realm.run([klist]) -- if realm.user_princ not in out: -- fail('Cannot see legacy cache after removing collection') -+ realm.run([klist], expected_msg=realm.user_princ) - coll_id = realm.run([keyctl, 'search', '@s', 'keyring', '_krb_' + cname]) -- out = realm.run([keyctl, 'list', coll_id.strip()]) -- if (id.strip() + ':') not in out: -- fail('Legacy cache did not reappear in collection after klist') -+ msg = id.strip() + ':' -+ realm.run([keyctl, 'list', coll_id.strip()], expected_msg=msg) - # Destroy the cache and check that it is unlinked from the session keyring. - realm.run([kdestroy]) - realm.run([keyctl, 'search', '@s', 'keyring', cname], expected_code=1) -@@ -160,8 +149,7 @@ conf = {'libdefaults': {'default_ccache_name': 'testdir/%{null}abc%{uid}'}} - realm = K5Realm(krb5_conf=conf, create_kdb=False) - del realm.env['KRB5CCNAME'] - uidstr = str(os.getuid()) --out = realm.run([klist], expected_code=1) --if 'testdir/abc%s' % uidstr not in out: -- fail('Wrong ccache in klist') -+msg = 'testdir/abc%s' % uidstr -+realm.run([klist], expected_code=1, expected_msg=msg) - - success('Credential cache tests') -diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py -index 0d967b8a5..1fa48793a 100755 ---- a/src/tests/t_crossrealm.py -+++ b/src/tests/t_crossrealm.py -@@ -25,9 +25,7 @@ - from k5test import * - - def test_kvno(r, princ, test, env=None): -- output = r.run([kvno, princ], env=env) -- if princ not in output: -- fail('%s: principal %s not in kvno output' % (test, princ)) -+ r.run([kvno, princ], env=env, expected_msg=princ) - - - def stop(*realms): -@@ -85,9 +83,8 @@ capaths = {'capaths': {'A': {'C': 'B'}}} - r1, r2, r3 = cross_realms(3, xtgts=((0,1), (1,2)), - args=({'realm': 'A', 'krb5_conf': capaths}, - {'realm': 'B'}, {'realm': 'C'})) --output = r1.run([kvno, r3.host_princ], expected_code=1) --if 'KDC policy rejects request' not in output: -- fail('transited 1: Expected error message not in output') -+r1.run([kvno, r3.host_princ], expected_code=1, -+ expected_msg='KDC policy rejects request') - stop(r1, r2, r3) - - # Test a different kind of transited error. The KDC for D does not -@@ -99,9 +96,8 @@ r1, r2, r3, r4 = cross_realms(4, xtgts=((0,1), (1,2), (2,3)), - {'realm': 'B', 'krb5_conf': capaths}, - {'realm': 'C', 'krb5_conf': capaths}, - {'realm': 'D'})) --output = r1.run([kvno, r4.host_princ], expected_code=1) --if 'Illegal cross-realm ticket' not in output: -- fail('transited 2: Expected error message not in output') -+r1.run([kvno, r4.host_princ], expected_code=1, -+ expected_msg='Illegal cross-realm ticket') - stop(r1, r2, r3, r4) - - success('Cross-realm tests') -diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py -index 5d3a43762..8a9462bd8 100755 ---- a/src/tests/t_dump.py -+++ b/src/tests/t_dump.py -@@ -36,12 +36,10 @@ if 'Expiration date: [never]' not in out or 'MKey: vno 1' not in out: - out = realm.run([kadminl, 'getpols']) - if 'fred\n' not in out or 'barney\n' not in out: - fail('Missing policy after load') --out = realm.run([kadminl, 'getpol', 'compat']) --if 'Number of old keys kept: 5' not in out: -- fail('Policy (1.8 format) has wrong value after load') --out = realm.run([kadminl, 'getpol', 'barney']) --if 'Number of old keys kept: 1' not in out: -- fail('Policy has wrong value after load') -+realm.run([kadminl, 'getpol', 'compat'], -+ expected_msg='Number of old keys kept: 5') -+realm.run([kadminl, 'getpol', 'barney'], -+ expected_msg='Number of old keys kept: 1') - - # Dump/load again, and make sure everything is still there. - realm.run([kdb5_util, 'dump', dumpfile]) -@@ -81,15 +79,10 @@ dump_compare(realm, ['-ov'], srcdump_ov) - def load_dump_check_compare(realm, opt, srcfile): - realm.run([kdb5_util, 'destroy', '-f']) - realm.run([kdb5_util, 'load'] + opt + [srcfile]) -- out = realm.run([kadminl, 'getprincs']) -- if 'user@' not in out: -- fail('Loaded dumpfile missing user principal') -- out = realm.run([kadminl, 'getprinc', 'nokeys']) -- if 'Number of keys: 0' not in out: -- fail('Loading dumpfile did not process zero-key principal') -- out = realm.run([kadminl, 'getpols']) -- if 'testpol' not in out: -- fail('Loaded dumpfile missing test policy') -+ realm.run([kadminl, 'getprincs'], expected_msg='user@') -+ realm.run([kadminl, 'getprinc', 'nokeys'], -+ expected_msg='Number of keys: 0') -+ realm.run([kadminl, 'getpols'], expected_msg='testpol') - dump_compare(realm, opt, srcfile) - - # Load each format of dump, check it, re-dump it, and compare. -@@ -99,12 +92,8 @@ load_dump_check_compare(realm, ['-b7'], srcdump_b7) - - # Loading the last (-b7 format) dump won't have loaded the - # per-principal kadm data. Load that incrementally with -ov. --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Policy: [none]' not in out: -- fail('Loaded b7 dump unexpectedly contains user policy reference') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: [none]') - realm.run([kdb5_util, 'load', '-update', '-ov', srcdump_ov]) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Policy: testpol' not in out: -- fail('Loading ov dump did not add user policy reference') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: testpol') - - success('Dump/load tests') -diff --git a/src/tests/t_general.py b/src/tests/t_general.py -index 16bf6c5e3..6621b7230 100755 ---- a/src/tests/t_general.py -+++ b/src/tests/t_general.py -@@ -3,10 +3,9 @@ from k5test import * - - for realm in multipass_realms(create_host=False): - # Check that kinit fails appropriately with the wrong password. -- output = realm.run([kinit, realm.user_princ], input='wrong\n', -- expected_code=1) -- if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') -+ msg = 'Password incorrect while getting initial credentials' -+ realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg=msg) - - # Check that we can kinit as a different principal. - realm.kinit(realm.admin_princ, password('admin')) -@@ -42,9 +41,8 @@ realm.run(['./responder', '-r', 'password=%s' % password('user'), - # Test that WRONG_REALM responses aren't treated as referrals unless - # they contain a crealm field pointing to a different realm. - # (Regression test for #8060.) --out = realm.run([kinit, '-C', 'notfoundprinc'], expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Expected error message not seen in kinit -C output') -+realm.run([kinit, '-C', 'notfoundprinc'], expected_code=1, -+ expected_msg='not found in Kerberos database') - - # Spot-check KRB5_TRACE output - expected_trace = ('Sending initial UDP request', -diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py -index 76b282d2a..224c067ef 100755 ---- a/src/tests/t_hostrealm.py -+++ b/src/tests/t_hostrealm.py -@@ -20,9 +20,8 @@ def test(realm, args, expected_realms, msg, env=None): - fail(msg) - - def test_error(realm, args, expected_error, msg, env=None): -- out = realm.run(['./hrealm'] + args, env=env, expected_code=1) -- if expected_error not in out: -- fail(msg) -+ realm.run(['./hrealm'] + args, env=env, expected_code=1, -+ expected_msg=expected_error) - - def testh(realm, host, expected_realms, msg, env=None): - test(realm, ['-h', host], expected_realms, msg, env=env) -diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py -index e64fdd279..8e23cd5de 100755 ---- a/src/tests/t_iprop.py -+++ b/src/tests/t_iprop.py -@@ -214,9 +214,8 @@ check_ulog(7, 1, 7, [None, pr1, pr3, pr2, pr2, pr2, pr2]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 6, 7) - check_ulog(2, 6, 7, [None, pr2], slave1) --out = realm.run([kadminl, 'getprinc', pr2], env=slave1) --if 'Attributes: DISALLOW_ALL_TIX' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr2], env=slave1, -+ expected_msg='Attributes: DISALLOW_ALL_TIX') - - # Start kadmind -proponly for slave1. (Use the slave1m environment - # which defines iprop_port to $port8.) -@@ -245,15 +244,13 @@ check_ulog(8, 1, 8, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 7, 8) - check_ulog(3, 6, 8, [None, pr2, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:20:00' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:20:00') - kpropd3.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd3, False, 7, 8) - check_ulog(2, 7, 8, [None, pr1], slave3) --out = realm.run([kadminl, '-r', realm.realm, 'getprinc', pr1], env=slave3) --if 'Maximum ticket life: 0 days 00:20:00' not in out: -- fail('slave3 does not have modification from slave1') -+realm.run([kadminl, '-r', realm.realm, 'getprinc', pr1], env=slave3, -+ expected_msg='Maximum ticket life: 0 days 00:20:00') - stop_daemon(kpropd3) - - # Test dissimilar default_realm and domain_realm map settings (no -r realm). -@@ -287,15 +284,13 @@ check_ulog(9, 1, 9, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 8, 9) - check_ulog(4, 6, 9, [None, pr2, pr1, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum renewable life: 0 days 22:00:00\n' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum renewable life: 0 days 22:00:00\n') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 8, 9) - check_ulog(3, 7, 9, [None, pr1, pr1], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2) --if 'Maximum renewable life: 0 days 22:00:00\n' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, -+ expected_msg='Maximum renewable life: 0 days 22:00:00\n') - - # Reset the ulog on slave1 to force a full resync from master. The - # resync will use the old dump file and then propagate changes. -@@ -317,15 +312,11 @@ check_ulog(10, 1, 10, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1, pr1, pr2]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 9, 10) - check_ulog(5, 6, 10, [None, pr2, pr1, pr1, pr2], slave1) --out = realm.run([kadminl, 'getprinc', pr2], env=slave1) --if 'Attributes:\n' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr2], env=slave1, expected_msg='Attributes:\n') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 9, 10) - check_ulog(4, 7, 10, [None, pr1, pr1, pr2], slave2) --out = realm.run([kadminl, 'getprinc', pr2], env=slave2) --if 'Attributes:\n' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr2], env=slave2, expected_msg='Attributes:\n') - - # Create a policy and check that it propagates via full resync. - realm.run([kadminl, 'addpol', '-minclasses', '2', 'testpol']) -@@ -333,15 +324,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 10, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum number of password character classes: 2' not in out: -- fail('slave1 does not have policy from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum number of password character classes: 2') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 10, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2) --if 'Minimum number of password character classes: 2' not in out: -- fail('slave2 does not have policy from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, -+ expected_msg='Minimum number of password character classes: 2') - - # Modify the policy and test that it also propagates via full resync. - realm.run([kadminl, 'modpol', '-minlength', '17', 'testpol']) -@@ -349,15 +338,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 1, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum password length: 17' not in out: -- fail('slave1 does not have policy change from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum password length: 17') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 1, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2) --if 'Minimum password length: 17' not in out: -- fail('slave2 does not have policy change from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, -+ expected_msg='Minimum password length: 17') - - # Delete the policy and test that it propagates via full resync. - realm.run([kadminl, 'delpol', 'testpol']) -@@ -365,15 +352,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 1, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1, expected_code=1) --if 'Policy does not exist' not in out: -- fail('slave1 did not get policy deletion from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, expected_code=1, -+ expected_msg='Policy does not exist') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 1, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2, expected_code=1) --if 'Policy does not exist' not in out: -- fail('slave2 did not get policy deletion from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, expected_code=1, -+ expected_msg='Policy does not exist') - - # Modify a principal on the master and test that it propagates incrementally. - realm.run([kadminl, 'modprinc', '-maxlife', '10 minutes', pr1]) -@@ -381,15 +366,13 @@ check_ulog(2, 1, 2, [None, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 1, 2) - check_ulog(2, 1, 2, [None, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:10:00' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:10:00') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 1, 2) - check_ulog(2, 1, 2, [None, pr1], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2) --if 'Maximum ticket life: 0 days 00:10:00' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, -+ expected_msg='Maximum ticket life: 0 days 00:10:00') - - # Delete a principal and test that it propagates incrementally. - realm.run([kadminl, 'delprinc', pr3]) -@@ -397,15 +380,13 @@ check_ulog(3, 1, 3, [None, pr1, pr3]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 2, 3) - check_ulog(3, 1, 3, [None, pr1, pr3], slave1) --out = realm.run([kadminl, 'getprinc', pr3], env=slave1, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave1 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr3], env=slave1, expected_code=1, -+ expected_msg='Principal does not exist') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 2, 3) - check_ulog(3, 1, 3, [None, pr1, pr3], slave2) --out = realm.run([kadminl, 'getprinc', pr3], env=slave2, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave2 does not have principal deletion from slave1') -+realm.run([kadminl, 'getprinc', pr3], env=slave2, expected_code=1, -+ expected_msg='Principal does not exist') - - # Rename a principal and test that it propagates incrementally. - renpr = "quacked@" + realm.realm -@@ -414,16 +395,14 @@ check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 3, 6) - check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave1 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, expected_code=1, -+ expected_msg='Principal does not exist') - realm.run([kadminl, 'getprinc', renpr], env=slave1) - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 3, 6) - check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave2 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, expected_code=1, -+ expected_msg='Principal does not exist') - realm.run([kadminl, 'getprinc', renpr], env=slave2) - - pr1 = renpr -@@ -455,9 +434,8 @@ out = realm.run_kpropd_once(slave1, ['-d']) - if 'Got incremental updates (sno=2 ' not in out: - fail('Expected full dump and synchronized from kpropd -t') - check_ulog(2, 1, 2, [None, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:05:00' not in out: -- fail('slave1 does not have modification from master after kpropd -t') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:05:00') - - # Propagate a policy change via full resync. - realm.run([kadminl, 'addpol', '-minclasses', '3', 'testpol']) -@@ -467,8 +445,7 @@ if ('Full propagation transfer finished' not in out or - 'KDC is synchronized' not in out): - fail('Expected full dump and synchronized from kpropd -t') - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum number of password character classes: 3' not in out: -- fail('slave1 does not have policy from master after kpropd -t') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum number of password character classes: 3') - - success('iprop tests') -diff --git a/src/tests/t_kadm5_hook.py b/src/tests/t_kadm5_hook.py -index 708e328b0..c1c8c9419 100755 ---- a/src/tests/t_kadm5_hook.py -+++ b/src/tests/t_kadm5_hook.py -@@ -7,12 +7,10 @@ plugin = os.path.join(buildtop, "plugins", "kadm5_hook", "test", - hook_krb5_conf = {'plugins': {'kadm5_hook': { 'module': 'test:' + plugin}}} - - realm = K5Realm(krb5_conf=hook_krb5_conf, create_user=False, create_host=False) --output = realm.run([kadminl, 'addprinc', '-randkey', 'test']) --if "create: stage precommit" not in output: -- fail('kadm5_hook test output not found') -+realm.run([kadminl, 'addprinc', '-randkey', 'test'], -+ expected_msg='create: stage precommit') - --output = realm.run([kadminl, 'renprinc', 'test', 'test2']) --if "rename: stage precommit" not in output: -- fail('kadm5_hook test output not found') -+realm.run([kadminl, 'renprinc', 'test', 'test2'], -+ expected_msg='rename: stage precommit') - - success('kadm5_hook') -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 188929a76..bbbbae99e 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -87,27 +87,24 @@ for pw in (['-pw', 'newpw'], ['-randkey']): - args = pw + ks - kadmin_as(all_changepw, ['cpw'] + args + ['unselected']) - kadmin_as(some_changepw, ['cpw'] + args + ['selected']) -- out = kadmin_as(none, ['cpw'] + args + ['selected'], expected_code=1) -- if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('cpw failure (no perms)') -- out = kadmin_as(some_changepw, ['cpw'] + args + ['unselected'], -- expected_code=1) -- if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('cpw failure (target)') -- out = kadmin_as(none, ['cpw'] + args + ['none']) -+ msg = "Operation requires ``change-password'' privilege" -+ kadmin_as(none, ['cpw'] + args + ['selected'], expected_code=1, -+ expected_msg=msg) -+ kadmin_as(some_changepw, ['cpw'] + args + ['unselected'], -+ expected_code=1, expected_msg=msg) -+ kadmin_as(none, ['cpw'] + args + ['none']) - realm.run([kadminl, 'modprinc', '-policy', 'minlife', 'none']) -- out = kadmin_as(none, ['cpw'] + args + ['none'], expected_code=1) -- if 'Current password\'s minimum life has not expired' not in out: -- fail('cpw failure (minimum life)') -+ msg = "Current password's minimum life has not expired" -+ kadmin_as(none, ['cpw'] + args + ['none'], expected_code=1, -+ expected_msg=msg) - realm.run([kadminl, 'modprinc', '-clearpolicy', 'none']) - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - - kadmin_as(all_add, ['addpol', 'policy']) - realm.run([kadminl, 'delpol', 'policy']) --out = kadmin_as(none, ['addpol', 'policy'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('addpol failure (no perms)') -+kadmin_as(none, ['addpol', 'policy'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - - # addprinc can generate two different RPC calls depending on options. - for ks in ([], ['-e', 'aes256-cts']): -@@ -117,89 +114,62 @@ for ks in ([], ['-e', 'aes256-cts']): - kadmin_as(some_add, ['addprinc'] + args + ['selected']) - realm.run([kadminl, 'delprinc', 'selected']) - kadmin_as(restricted_add, ['addprinc'] + args + ['unselected']) -- out = realm.run([kadminl, 'getprinc', 'unselected']) -- if 'REQUIRES_PRE_AUTH' not in out: -- fail('addprinc success (restrictions) -- restriction check') -+ realm.run([kadminl, 'getprinc', 'unselected'], -+ expected_msg='REQUIRES_PRE_AUTH') - realm.run([kadminl, 'delprinc', 'unselected']) -- out = kadmin_as(none, ['addprinc'] + args + ['selected'], expected_code=1) -- if 'Operation requires ``add\'\' privilege' not in out: -- fail('addprinc failure (no perms)') -- out = kadmin_as(some_add, ['addprinc'] + args + ['unselected'], -- expected_code=1) -- if 'Operation requires ``add\'\' privilege' not in out: -- fail('addprinc failure (target)') -+ kadmin_as(none, ['addprinc'] + args + ['selected'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") -+ kadmin_as(some_add, ['addprinc'] + args + ['unselected'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - - realm.addprinc('unselected', 'pw') - kadmin_as(all_delete, ['delprinc', 'unselected']) - realm.addprinc('selected', 'pw') - kadmin_as(some_delete, ['delprinc', 'selected']) - realm.addprinc('unselected', 'pw') --out = kadmin_as(none, ['delprinc', 'unselected'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('delprinc failure (no perms)') --out = kadmin_as(some_delete, ['delprinc', 'unselected'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('delprinc failure (no target)') -+kadmin_as(none, ['delprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(some_delete, ['delprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") - realm.run([kadminl, 'delprinc', 'unselected']) - --out = kadmin_as(all_inquire, ['getpol', 'minlife']) --if 'Policy: minlife' not in out: -- fail('getpol success (acl)') --out = kadmin_as(none, ['getpol', 'minlife'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getpol failure (no perms)') -+kadmin_as(all_inquire, ['getpol', 'minlife'], expected_msg='Policy: minlife') -+kadmin_as(none, ['getpol', 'minlife'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") - realm.run([kadminl, 'modprinc', '-policy', 'minlife', 'none']) --out = kadmin_as(none, ['getpol', 'minlife']) --if 'Policy: minlife' not in out: -- fail('getpol success (self policy exemption)') -+kadmin_as(none, ['getpol', 'minlife'], expected_msg='Policy: minlife') - realm.run([kadminl, 'modprinc', '-clearpolicy', 'none']) - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') --out = kadmin_as(all_inquire, ['getprinc', 'unselected']) --if 'Principal: unselected@KRBTEST.COM' not in out: -- fail('getprinc success (acl)') --out = kadmin_as(some_inquire, ['getprinc', 'selected']) --if 'Principal: selected@KRBTEST.COM' not in out: -- fail('getprinc success (target)') --out = kadmin_as(none, ['getprinc', 'selected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getprinc failure (no perms)') --out = kadmin_as(some_inquire, ['getprinc', 'unselected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getprinc failure (target)') --out = kadmin_as(none, ['getprinc', 'none']) --if 'Principal: none@KRBTEST.COM' not in out: -- fail('getprinc success (self exemption)') -+kadmin_as(all_inquire, ['getprinc', 'unselected'], -+ expected_msg='Principal: unselected@KRBTEST.COM') -+kadmin_as(some_inquire, ['getprinc', 'selected'], -+ expected_msg='Principal: selected@KRBTEST.COM') -+kadmin_as(none, ['getprinc', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(some_inquire, ['getprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(none, ['getprinc', 'none'], -+ expected_msg='Principal: none@KRBTEST.COM') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - --out = kadmin_as(all_list, ['listprincs']) --if 'K/M@KRBTEST.COM' not in out: -- fail('listprincs success (acl)') --out = kadmin_as(none, ['listprincs'], expected_code=1) --if 'Operation requires ``list\'\' privilege' not in out: -- fail('listprincs failure (no perms)') -+kadmin_as(all_list, ['listprincs'], expected_msg='K/M@KRBTEST.COM') -+kadmin_as(none, ['listprincs'], expected_code=1, -+ expected_msg="Operation requires ``list'' privilege") - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - realm.run([kadminl, 'setstr', 'selected', 'key', 'value']) - realm.run([kadminl, 'setstr', 'unselected', 'key', 'value']) --out = kadmin_as(all_inquire, ['getstrs', 'unselected']) --if 'key: value' not in out: -- fail('getstrs success (acl)') --out = kadmin_as(some_inquire, ['getstrs', 'selected']) --if 'key: value' not in out: -- fail('getstrs success (target)') --out = kadmin_as(none, ['getstrs', 'selected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getstrs failure (no perms)') --out = kadmin_as(some_inquire, ['getstrs', 'unselected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getstrs failure (target)') --out = kadmin_as(none, ['getstrs', 'none']) --if '(No string attributes.)' not in out: -- fail('getstrs success (self exemption)') -+kadmin_as(all_inquire, ['getstrs', 'unselected'], expected_msg='key: value') -+kadmin_as(some_inquire, ['getstrs', 'selected'], expected_msg='key: value') -+kadmin_as(none, ['getstrs', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(some_inquire, ['getstrs', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(none, ['getstrs', 'none'], expected_msg='(No string attributes.)') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -207,27 +177,21 @@ out = kadmin_as(all_modify, ['modpol', '-maxlife', '1 hour', 'policy'], - expected_code=1) - if 'Operation requires' in out: - fail('modpol success (acl)') --out = kadmin_as(none, ['modpol', '-maxlife', '1 hour', 'policy'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('modpol failure (no perms)') -+kadmin_as(none, ['modpol', '-maxlife', '1 hour', 'policy'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['modprinc', '-maxlife', '1 hour', 'unselected']) - kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'selected']) - kadmin_as(restricted_modify, ['modprinc', '-maxlife', '1 hour', 'unselected']) --out = realm.run([kadminl, 'getprinc', 'unselected']) --if 'REQUIRES_PRE_AUTH' not in out: -- fail('addprinc success (restrictions) -- restriction check') --out = kadmin_as(all_inquire, ['modprinc', '-maxlife', '1 hour', 'selected'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('addprinc failure (no perms)') --out = kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'unselected'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('modprinc failure (target)') -+realm.run([kadminl, 'getprinc', 'unselected'], -+ expected_msg='REQUIRES_PRE_AUTH') -+kadmin_as(all_inquire, ['modprinc', '-maxlife', '1 hour', 'selected'], -+ expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'unselected'], -+ expected_code=1, expected_msg='Operation requires') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -235,12 +199,10 @@ realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['purgekeys', 'unselected']) - kadmin_as(some_modify, ['purgekeys', 'selected']) --out = kadmin_as(none, ['purgekeys', 'selected'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('purgekeys failure (no perms)') --out = kadmin_as(some_modify, ['purgekeys', 'unselected'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('purgekeys failure (target)') -+kadmin_as(none, ['purgekeys', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['purgekeys', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - kadmin_as(none, ['purgekeys', 'none']) - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) -@@ -250,36 +212,27 @@ kadmin_as(all_rename, ['renprinc', 'from', 'to']) - realm.run([kadminl, 'renprinc', 'to', 'from']) - kadmin_as(some_rename, ['renprinc', 'from', 'to']) - realm.run([kadminl, 'renprinc', 'to', 'from']) --out = kadmin_as(all_add, ['renprinc', 'from', 'to'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('renprinc failure (no delete perms)') --out = kadmin_as(all_delete, ['renprinc', 'from', 'to'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (no add perms)') --out = kadmin_as(some_rename, ['renprinc', 'from', 'notto'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (new target)') -+kadmin_as(all_add, ['renprinc', 'from', 'to'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_delete, ['renprinc', 'from', 'to'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") -+kadmin_as(some_rename, ['renprinc', 'from', 'notto'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - realm.run([kadminl, 'renprinc', 'from', 'notfrom']) --out = kadmin_as(some_rename, ['renprinc', 'notfrom', 'to'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('renprinc failure (old target)') --out = kadmin_as(restricted_rename, ['renprinc', 'notfrom', 'to'], -- expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (restrictions)') -+kadmin_as(some_rename, ['renprinc', 'notfrom', 'to'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(restricted_rename, ['renprinc', 'notfrom', 'to'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - realm.run([kadminl, 'delprinc', 'notfrom']) - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['setstr', 'unselected', 'key', 'value']) - kadmin_as(some_modify, ['setstr', 'selected', 'key', 'value']) --out = kadmin_as(none, ['setstr', 'selected', 'key', 'value'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('addprinc failure (no perms)') --out = kadmin_as(some_modify, ['setstr', 'unselected', 'key', 'value'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('modprinc failure (target)') -+kadmin_as(none, ['setstr', 'selected', 'key', 'value'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['setstr', 'unselected', 'key', 'value'], -+ expected_code=1, expected_msg='Operation requires') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -287,28 +240,21 @@ kadmin_as(admin, ['addprinc', '-pw', 'pw', 'anytarget']) - realm.run([kadminl, 'delprinc', 'anytarget']) - kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card']) - realm.run([kadminl, 'delprinc', 'wild/card']) --out = kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card/extra'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('addprinc failure (target wildcard extra component)') -+kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card/extra'], -+ expected_code=1, expected_msg='Operation requires') - realm.addprinc('admin/user', 'pw') - kadmin_as(admin, ['delprinc', 'admin/user']) --out = kadmin_as(admin, ['delprinc', 'none'], expected_code=1) --if 'Operation requires' not in out: -- fail('delprinc failure (wildcard backreferences not matched)') -+kadmin_as(admin, ['delprinc', 'none'], expected_code=1, -+ expected_msg='Operation requires') - realm.addprinc('four/one/three', 'pw') - kadmin_as(onetwothreefour, ['delprinc', 'four/one/three']) - - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', 'type1']) --out = realm.run([kadminl, 'getprinc', 'type1']) --if 'Policy: minlife' not in out: -- fail('restriction (policy)') -+realm.run([kadminl, 'getprinc', 'type1'], expected_msg='Policy: minlife') - realm.run([kadminl, 'delprinc', 'type1']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-policy', 'minlife', - 'type2']) --out = realm.run([kadminl, 'getprinc', 'type2']) --if 'Policy: [none]' not in out: -- fail('restriction (clearpolicy)') -+realm.run([kadminl, 'getprinc', 'type2'], expected_msg='Policy: [none]') - realm.run([kadminl, 'delprinc', 'type2']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-maxlife', '1 minute', - 'type3']) -@@ -319,40 +265,32 @@ if ('Maximum ticket life: 0 days 00:01:00' not in out or - realm.run([kadminl, 'delprinc', 'type3']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-maxrenewlife', '1 day', - 'type3']) --out = realm.run([kadminl, 'getprinc', 'type3']) --if 'Maximum renewable life: 0 days 02:00:00' not in out: -- fail('restriction (maxrenewlife high)') -+realm.run([kadminl, 'getprinc', 'type3'], -+ expected_msg='Maximum renewable life: 0 days 02:00:00') - - realm.run([kadminl, 'addprinc', '-pw', 'pw', 'extractkeys']) --out = kadmin_as(all_wildcard, ['ktadd', '-norandkey', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``extract-keys\'\' privilege' not in out: -- fail('extractkeys failure (all_wildcard)') -+kadmin_as(all_wildcard, ['ktadd', '-norandkey', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``extract-keys'' privilege") - kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys']) - realm.kinit('extractkeys', flags=['-k']) - os.remove(realm.keytab) - - kadmin_as(all_modify, ['modprinc', '+lockdown_keys', 'extractkeys']) --out = kadmin_as(all_changepw, ['cpw', '-pw', 'newpw', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('extractkeys failure (all_changepw)') -+kadmin_as(all_changepw, ['cpw', '-pw', 'newpw', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``change-password'' privilege") - kadmin_as(all_changepw, ['cpw', '-randkey', 'extractkeys']) --out = kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``extract-keys\'\' privilege' not in out: -- fail('extractkeys failure (all_extract)') --out = kadmin_as(all_delete, ['delprinc', 'extractkeys'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('extractkeys failure (all_delete)') --out = kadmin_as(all_rename, ['renprinc', 'extractkeys', 'renamedprinc'], -- expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('extractkeys failure (all_rename)') --out = kadmin_as(all_modify, ['modprinc', '-lockdown_keys', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('extractkeys failure (all_modify)') -+kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys'], expected_code=1, -+ expected_msg="Operation requires ``extract-keys'' privilege") -+kadmin_as(all_delete, ['delprinc', 'extractkeys'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_rename, ['renprinc', 'extractkeys', 'renamedprinc'], -+ expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_modify, ['modprinc', '-lockdown_keys', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - realm.run([kadminl, 'modprinc', '-lockdown_keys', 'extractkeys']) - kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys']) - realm.kinit('extractkeys', flags=['-k']) -diff --git a/src/tests/t_kadmin_parsing.py b/src/tests/t_kadmin_parsing.py -index 92d72d2b0..8de387c64 100644 ---- a/src/tests/t_kadmin_parsing.py -+++ b/src/tests/t_kadmin_parsing.py -@@ -57,33 +57,27 @@ realm = K5Realm(create_host=False, get_creds=False) - realm.run([kadminl, 'addpol', 'pol']) - for instr, outstr in intervals: - realm.run([kadminl, 'modprinc', '-maxlife', instr, realm.user_princ]) -- out = realm.run([kadminl, 'getprinc', realm.user_princ]) -- if 'Maximum ticket life: ' + outstr + '\n' not in out: -- fail('princ maxlife: ' + instr) -+ msg = 'Maximum ticket life: ' + outstr + '\n' -+ realm.run([kadminl, 'getprinc', realm.user_princ], expected_msg=msg) - - realm.run([kadminl, 'modprinc', '-maxrenewlife', instr, realm.user_princ]) -- out = realm.run([kadminl, 'getprinc', realm.user_princ]) -- if 'Maximum renewable life: ' + outstr + '\n' not in out: -- fail('princ maxrenewlife: ' + instr) -+ msg = 'Maximum renewable life: ' + outstr + '\n' -+ realm.run([kadminl, 'getprinc', realm.user_princ], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-maxlife', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Maximum password life: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Maximum password life: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-minlife', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Minimum password life: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Minimum password life: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-failurecountinterval', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Password failure count reset interval: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Password failure count reset interval: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-lockoutduration', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Password lockout duration: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Password lockout duration: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - success('kadmin command parsing tests') -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 185225afa..44635b089 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -167,47 +167,31 @@ if out != 'KRBTEST.COM\n': - # because we're sticking a krbPrincipalAux objectclass onto a subtree - # krbContainer, but it works and it avoids having to load core.schema - # in the test LDAP server. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], -- expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm dn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) --out = realm.run([kadminl, 'getprinc', 'princ1']) --if 'Principal: princ1' not in out: -- fail('Unexpected kadmin.local output after creating princ1') --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', -- 'again'], expected_code=1) --if 'ldap object is already kerberized' not in out: -- fail('Unexpected kadmin.local output trying to re-kerberize DN') -+realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], -+ expected_code=1, expected_msg='ldap object is already kerberized') - # Check that we can't set linkdn on a non-standalone object. --out = realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t1,cn=krb5', 'princ1'], -- expected_code=1) --if 'link information can not be set' not in out: -- fail('Unexpected kadmin.local output trying to set linkdn on princ1') -+realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t1,cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='link information can not be set') - - # Create a principal with a specified linkdn. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=krb5', 'princ2'], -- expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm linkdn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=krb5', 'princ2'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=t1,cn=krb5', 'princ2']) - # Check that we can't reset linkdn. --out = realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t2,cn=krb5', 'princ2'], -- expected_code=1) --if 'kerberos principal is already linked' not in out: -- fail('Unexpected kadmin.local output for re-specified linkdn') -+realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t2,cn=krb5', 'princ2'], -+ expected_code=1, expected_msg='kerberos principal is already linked') - - # Create a principal with a specified containerdn. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', -- 'princ3'], expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm containerdn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', 'princ3'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', - 'princ3']) --out = realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', -- 'princ3'], expected_code=1) --if 'containerdn option not supported' not in out: -- fail('Unexpected kadmin.local output trying to reset containerdn') -+realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], -+ expected_code=1, expected_msg='containerdn option not supported') - - # Create and modify a ticket policy. - kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', -@@ -255,9 +239,8 @@ if out: - kldaputil(['create_policy', 'tktpol2']) - - # Try to create a password policy conflicting with a ticket policy. --out = realm.run([kadminl, 'addpol', 'tktpol2'], expected_code=1) --if 'Already exists while creating policy "tktpol2"' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, 'addpol', 'tktpol2'], expected_code=1, -+ expected_msg='Already exists while creating policy "tktpol2"') - - # Try to create a ticket policy conflicting with a password policy. - realm.run([kadminl, 'addpol', 'pwpol']) -@@ -266,16 +249,13 @@ if 'Already exists while creating policy object' not in out: - fail('Expected error not seen in kdb5_ldap_util output') - - # Try to use a password policy as a ticket policy. --out = realm.run([kadminl, 'modprinc', '-x', 'tktpolicy=pwpol', 'princ4'], -- expected_code=1) --if 'Object class violation' not in out: -- fail('Expected error not seem in kadmin.local output') -+realm.run([kadminl, 'modprinc', '-x', 'tktpolicy=pwpol', 'princ4'], -+ expected_code=1, expected_msg='Object class violation') - - # Use a ticket policy as a password policy (CVE-2014-5353). This - # works with a warning; use kadmin.local -q so the warning is shown. --out = realm.run([kadminl, '-q', 'modprinc -policy tktpol2 princ4']) --if 'WARNING: policy "tktpol2" does not exist' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, '-q', 'modprinc -policy tktpol2 princ4'], -+ expected_msg='WARNING: policy "tktpol2" does not exist') - - # Do some basic tests with a KDC against the LDAP module, exercising the - # db_args processing code. -@@ -298,9 +278,8 @@ if 'krbPrincipalAuthInd: otp' not in out: - if 'krbPrincipalAuthInd: radius' not in out: - fail('Expected krbPrincipalAuthInd value not in output') - --out = realm.run([kadminl, 'getstrs', 'authind']) --if 'require_auth: otp radius' not in out: -- fail('Expected auth indicators value not in output') -+realm.run([kadminl, 'getstrs', 'authind'], -+ expected_msg='require_auth: otp radius') - - # Test service principal aliases. - realm.addprinc('canon', password('canon')) -@@ -311,12 +290,10 @@ ldap_modify('dn: krbPrincipalName=canon@KRBTEST.COM,cn=t1,cn=krb5\n' - '-\n' - 'add: krbCanonicalName\n' - 'krbCanonicalName: canon@KRBTEST.COM\n') --out = realm.run([kadminl, 'getprinc', 'alias']) --if 'Principal: canon@KRBTEST.COM\n' not in out: -- fail('Could not fetch canon through alias') --out = realm.run([kadminl, 'getprinc', 'canon']) --if 'Principal: canon@KRBTEST.COM\n' not in out: -- fail('Could not fetch canon through canon') -+realm.run([kadminl, 'getprinc', 'alias'], -+ expected_msg='Principal: canon@KRBTEST.COM\n') -+realm.run([kadminl, 'getprinc', 'canon'], -+ expected_msg='Principal: canon@KRBTEST.COM\n') - realm.run([kvno, 'alias']) - realm.run([kvno, 'canon']) - out = realm.run([klist]) -@@ -334,9 +311,8 @@ ldap_modify('dn: krbPrincipalName=krbtgt/KRBTEST.COM@KRBTEST.COM,' - '-\n' - 'add: krbCanonicalName\n' - 'krbCanonicalName: krbtgt/KRBTEST.COM@KRBTEST.COM\n') --out = realm.run([kadminl, 'getprinc', 'tgtalias']) --if 'Principal: krbtgt/KRBTEST.COM@KRBTEST.COM' not in out: -- fail('Could not fetch krbtgt through tgtalias') -+realm.run([kadminl, 'getprinc', 'tgtalias'], -+ expected_msg='Principal: krbtgt/KRBTEST.COM@KRBTEST.COM') - realm.kinit(realm.user_princ, password('user')) - realm.run([kvno, 'tgtalias']) - realm.klist(realm.user_princ, 'tgtalias@KRBTEST.COM') -@@ -352,9 +328,8 @@ realm.klist(realm.user_princ, 'alias@KRBTEST.COM') - - # Test client principal aliases, with and without preauth. - realm.kinit('canon', password('canon')) --out = realm.kinit('alias', password('canon'), expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Wrong error message for kinit to alias without -C flag') -+realm.kinit('alias', password('canon'), expected_code=1, -+ expected_msg='not found in Kerberos database') - realm.kinit('alias', password('canon'), ['-C']) - realm.run([kvno, 'alias']) - realm.klist('canon@KRBTEST.COM', 'alias@KRBTEST.COM') -@@ -413,31 +388,24 @@ realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts,aes128-cts', - 'kvnoprinc']) - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'kvnoprinc']) --out = realm.run([kadminl, 'getprinc', 'kvnoprinc']) --if 'Number of keys: 4' not in out: -- fail('After cpw -keepold, wrong number of keys') -+realm.run([kadminl, 'getprinc', 'kvnoprinc'], expected_msg='Number of keys: 4') - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'kvnoprinc']) --out = realm.run([kadminl, 'getprinc', 'kvnoprinc']) --if 'Number of keys: 6' not in out: -- fail('After cpw -keepold, wrong number of keys') -+realm.run([kadminl, 'getprinc', 'kvnoprinc'], expected_msg='Number of keys: 6') - - # Regression test for #8041 (NULL dereference on keyless principals). - realm.run([kadminl, 'addprinc', '-nokey', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 0' not in out: -- fail('Failed to create a principal with no keys') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 0') - realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts,aes128-cts', - 'keylessprinc']) - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 4' not in out: -- fail('Failed to add keys to keylessprinc') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 4') - realm.run([kadminl, 'purgekeys', '-all', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 0' not in out: -- fail('After purgekeys -all, keys remain') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 0') - - # Test for 8354 (old password history entries when -keepold is used) - realm.run([kadminl, 'addpol', '-history', '2', 'keepoldpasspol']) -@@ -451,9 +419,8 @@ realm.stop() - # Briefly test dump and load. - dumpfile = os.path.join(realm.testdir, 'dump') - realm.run([kdb5_util, 'dump', dumpfile]) --out = realm.run([kdb5_util, 'load', dumpfile], expected_code=1) --if 'KDB module requires -update argument' not in out: -- fail('Unexpected error from kdb5_util load without -update') -+realm.run([kdb5_util, 'load', dumpfile], expected_code=1, -+ expected_msg='KDB module requires -update argument') - realm.run([kdb5_util, 'load', '-update', dumpfile]) - - # Destroy the realm. -@@ -501,14 +468,10 @@ realm.addprinc(realm.user_princ, password('user')) - realm.kinit(realm.user_princ, password('user')) - realm.stop() - # Exercise DB options, which should cause binding to fail. --out = realm.run([kadminl, '-x', 'sasl_authcid=ab', 'getprinc', 'user'], -- expected_code=1) --if 'Cannot bind to LDAP server' not in out: -- fail('Expected error not seen in kadmin.local output') --out = realm.run([kadminl, '-x', 'bindpwd=wrong', 'getprinc', 'user'], -- expected_code=1) --if 'Cannot bind to LDAP server' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, '-x', 'sasl_authcid=ab', 'getprinc', 'user'], -+ expected_code=1, expected_msg='Cannot bind to LDAP server') -+realm.run([kadminl, '-x', 'bindpwd=wrong', 'getprinc', 'user'], -+ expected_code=1, expected_msg='Cannot bind to LDAP server') - realm.run([kdb5_ldap_util, 'destroy', '-f']) - - # We could still use tests to exercise: -diff --git a/src/tests/t_kdb_locking.py b/src/tests/t_kdb_locking.py -index e8d86e09b..aac0a220f 100755 ---- a/src/tests/t_kdb_locking.py -+++ b/src/tests/t_kdb_locking.py -@@ -21,9 +21,8 @@ if not os.path.exists(kadm5_lock): - fail('kadm5 lock file not created: ' + kadm5_lock) - os.unlink(kadm5_lock) - --output = realm.kinit(p, p, [], expected_code=1) --if 'A service is not available' not in output: -- fail('krb5kdc should have returned service not available error') -+realm.kinit(p, p, [], expected_code=1, -+ expected_msg='A service is not available') - - f = open(kadm5_lock, 'w') - f.close() -diff --git a/src/tests/t_keydata.py b/src/tests/t_keydata.py -index 686e543bd..5c04a8523 100755 ---- a/src/tests/t_keydata.py -+++ b/src/tests/t_keydata.py -@@ -5,27 +5,19 @@ realm = K5Realm(create_user=False, create_host=False) - - # Create a principal with no keys. - realm.run([kadminl, 'addprinc', '-nokey', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Number of keys: 0' not in out: -- fail('getprinc (addprinc -nokey)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Number of keys: 0') - - # Change its password and check the resulting kvno. - realm.run([kadminl, 'cpw', '-pw', 'password', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'vno 1' not in out: -- fail('getprinc (cpw -pw)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='vno 1') - - # Delete all of its keys. - realm.run([kadminl, 'purgekeys', '-all', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Number of keys: 0' not in out: -- fail('getprinc (purgekeys)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Number of keys: 0') - - # Randomize its keys and check the resulting kvno. - realm.run([kadminl, 'cpw', '-randkey', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'vno 1' not in out: -- fail('getprinc (cpw -randkey)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='vno 1') - - # Return true if patype appears to have been received in a hint list - # from a KDC error message, based on the trace file fname. -diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 35d0b61b8..bfd38914b 100755 ---- a/src/tests/t_keyrollover.py -+++ b/src/tests/t_keyrollover.py -@@ -23,25 +23,17 @@ realm.run([kvno, princ1]) - realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) - # Make sure an old TGT fails after purging old TGS key. - realm.run([kvno, princ2], expected_code=1) --output = realm.run([klist, '-e']) -- --expected = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ -+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ - (realm.realm, realm.realm) -- --if expected not in output: -- fail('keyrollover: expected TGS enctype not found') -+realm.run([klist, '-e'], expected_msg=msg) - - # Check that new key actually works. - realm.kinit(realm.user_princ, password('user')) - realm.run([kvno, realm.host_princ]) --output = realm.run([klist, '-e']) -- --expected = 'krbtgt/%s@%s\n\tEtype (skey, tkt): ' \ -+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): ' \ - 'aes256-cts-hmac-sha1-96, aes256-cts-hmac-sha1-96' % \ - (realm.realm, realm.realm) -- --if expected not in output: -- fail('keyrollover: expected TGS enctype not found after change') -+realm.run([klist, '-e'], expected_msg=msg) - - # Test that the KDC only accepts the first enctype for a kvno, for a - # local-realm TGS request. To set this up, we abuse an edge-case -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index a06e6c296..a48740ba5 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -14,9 +14,8 @@ realm.run([ktutil], input=('rkt %s\ndelent 1\nwkt %s\n' % - realm.kinit(realm.host_princ, flags=['-k', '-t', pkeytab]) - - # Test kinit with no keys for client in keytab. --output = realm.kinit(realm.user_princ, flags=['-k'], expected_code=1) --if 'no suitable keys' not in output: -- fail('Expected error not seen in kinit output') -+realm.kinit(realm.user_princ, flags=['-k'], expected_code=1, -+ expected_msg='no suitable keys') - - # Test kinit and klist with client keytab defaults. - realm.extract_keytab(realm.user_princ, realm.client_keytab); -@@ -31,14 +30,12 @@ if realm.client_keytab not in out or realm.user_princ not in out: - - # Test implicit request for keytab (-i or -t without -k) - realm.run([kdestroy]) --output = realm.kinit(realm.host_princ, flags=['-t', realm.keytab]) --if 'keytab specified, forcing -k' not in output: -- fail('Expected output not seen from kinit -t keytab') -+realm.kinit(realm.host_princ, flags=['-t', realm.keytab], -+ expected_msg='keytab specified, forcing -k') - realm.klist(realm.host_princ) - realm.run([kdestroy]) --output = realm.kinit(realm.user_princ, flags=['-i']) --if 'keytab specified, forcing -k' not in output: -- fail('Expected output not seen from kinit -i') -+realm.kinit(realm.user_princ, flags=['-i'], -+ expected_msg='keytab specified, forcing -k') - realm.klist(realm.user_princ) - - # Test extracting keys with multiple key versions present. -@@ -70,12 +67,10 @@ def test_key_rotate(realm, princ, expected_kvno): - realm.run_kadmin(['ktadd', '-k', realm.keytab, princ]) - realm.run([kadminl, 'ktrem', princ, 'old']) - realm.kinit(princ, flags=['-k']) -- out = realm.run([klist, '-k']) -- if ('%d %s' % (expected_kvno, princ)) not in out: -- fail('kvno %d not listed in keytab' % expected_kvno) -- out = realm.run_kadmin(['getprinc', princ]) -- if ('Key: vno %d,' % expected_kvno) not in out: -- fail('vno %d not seen in getprinc output' % expected_kvno) -+ msg = '%d %s' % (expected_kvno, princ) -+ out = realm.run([klist, '-k'], expected_msg=msg) -+ msg = 'Key: vno %d,' % expected_kvno -+ out = realm.run_kadmin(['getprinc', princ], expected_msg=msg) - - princ = 'foo/bar@%s' % realm.realm - realm.addprinc(princ) -@@ -109,9 +104,8 @@ f = open(realm.keytab, 'w') - f.write('\x05\x02\x00\x00\x00' + chr(len(record))) - f.write(record) - f.close() --out = realm.run([klist, '-k']) --if (' 2 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 2 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure zero-fill isn't treated as a 32-bit kvno. - f = open(realm.keytab, 'w') -@@ -119,9 +113,8 @@ f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) - f.write(record) - f.write('\x00\x00\x00\x00') - f.close() --out = realm.run([klist, '-k']) --if (' 2 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 2 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure a hand-crafted 32-bit kvno is recognized. - f = open(realm.keytab, 'w') -@@ -129,9 +122,8 @@ f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) - f.write(record) - f.write('\x00\x00\x00\x03') - f.close() --out = realm.run([klist, '-k']) --if (' 3 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 3 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Test parameter expansion in profile variables - realm.stop() -@@ -142,11 +134,9 @@ realm = K5Realm(krb5_conf=conf, create_kdb=False) - del realm.env['KRB5_KTNAME'] - del realm.env['KRB5_CLIENT_KTNAME'] - uidstr = str(os.getuid()) --out = realm.run([klist, '-k'], expected_code=1) --if 'FILE:testdir/abc%s' % uidstr not in out: -- fail('Wrong keytab in klist -k output') --out = realm.run([klist, '-ki'], expected_code=1) --if 'FILE:testdir/xyz%s' % uidstr not in out: -- fail('Wrong keytab in klist -ki output') -+msg = 'FILE:testdir/abc%s' % uidstr -+out = realm.run([klist, '-k'], expected_code=1, expected_msg=msg) -+msg = 'FILE:testdir/xyz%s' % uidstr -+out = realm.run([klist, '-ki'], expected_code=1, expected_msg=msg) - - success('Keytab-related tests') -diff --git a/src/tests/t_kprop.py b/src/tests/t_kprop.py -index 02cdfeec2..39169675d 100755 ---- a/src/tests/t_kprop.py -+++ b/src/tests/t_kprop.py -@@ -43,9 +43,7 @@ for realm in multipass_realms(create_user=False): - realm.run([kprop, '-f', dumpfile, '-P', str(realm.kprop_port()), hostname]) - check_output(kpropd) - -- out = realm.run([kadminl, 'listprincs'], slave) -- if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+ realm.run([kadminl, 'listprincs'], slave, expected_msg='wakawaka') - - # default_realm tests follow. - # default_realm and domain_realm different than realm.realm (test -r argument). -@@ -79,9 +77,8 @@ realm.run([kdb5_util, 'dump', dumpfile]) - realm.run([kprop, '-r', realm.realm, '-f', dumpfile, '-P', - str(realm.kprop_port()), hostname]) - check_output(kpropd) --out = realm.run([kadminl, '-r', realm.realm, 'listprincs'], slave2) --if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+realm.run([kadminl, '-r', realm.realm, 'listprincs'], slave2, -+ expected_msg='wakawaka') - - stop_daemon(kpropd) - -@@ -90,8 +87,6 @@ kpropd = realm.start_kpropd(slave3, ['-d']) - realm.run([kdb5_util, 'dump', dumpfile]) - realm.run([kprop, '-f', dumpfile, '-P', str(realm.kprop_port()), hostname]) - check_output(kpropd) --out = realm.run([kadminl, 'listprincs'], slave3) --if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+realm.run([kadminl, 'listprincs'], slave3, expected_msg='wakawaka') - - success('kprop tests') -diff --git a/src/tests/t_localauth.py b/src/tests/t_localauth.py -index 4590485ac..aa625d038 100755 ---- a/src/tests/t_localauth.py -+++ b/src/tests/t_localauth.py -@@ -14,9 +14,8 @@ def test_an2ln(env, aname, result, msg): - fail(msg) - - def test_an2ln_err(env, aname, err, msg): -- out = realm.run(['./localauth', aname], env=env, expected_code=1) -- if err not in out: -- fail(msg) -+ realm.run(['./localauth', aname], env=env, expected_code=1, -+ expected_msg=err) - - def test_userok(env, aname, lname, ok, msg): - out = realm.run(['./localauth', aname, lname], env=env) -diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index c53b71b45..615cd91ca 100755 ---- a/src/tests/t_mkey.py -+++ b/src/tests/t_mkey.py -@@ -92,9 +92,8 @@ def check_stash(*expected): - - # Verify that the user principal has the expected mkvno. - def check_mkvno(princ, expected_mkvno): -- out = realm.run([kadminl, 'getprinc', princ]) -- if ('MKey: vno %d\n' % expected_mkvno) not in out: -- fail('Unexpected mkvno in user DB entry') -+ msg = 'MKey: vno %d\n' % expected_mkvno -+ realm.run([kadminl, 'getprinc', princ], expected_msg=msg) - - - # Change the password using either kadmin.local or kadmin, then check -@@ -160,9 +159,8 @@ check_mkvno(realm.user_princ, 1) - collisionfile = os.path.join(realm.testdir, 'stash_tmp') - f = open(collisionfile, 'w') - f.close() --output = realm.run([kdb5_util, 'stash'], expected_code=1) --if 'Temporary stash file already exists' not in output: -- fail('Did not detect temp stash file collision') -+realm.run([kdb5_util, 'stash'], expected_code=1, -+ expected_msg='Temporary stash file already exists') - os.unlink(collisionfile) - - # Add a new master key with no options. Verify that: -@@ -179,9 +177,8 @@ change_password_check_mkvno(True, realm.user_princ, 'abcd', 1) - change_password_check_mkvno(False, realm.user_princ, 'user', 1) - - # Verify that use_mkey won't make all master keys inactive. --out = realm.run([kdb5_util, 'use_mkey', '1', 'now+1day'], expected_code=1) --if 'there must be one master key currently active' not in out: -- fail('Unexpected error from use_mkey making all mkeys inactive') -+realm.run([kdb5_util, 'use_mkey', '1', 'now+1day'], expected_code=1, -+ expected_msg='there must be one master key currently active') - check_mkey_list((2, defetype, False, False), (1, defetype, True, True)) - - # Make the new master key active. Verify that: -@@ -194,9 +191,8 @@ change_password_check_mkvno(True, realm.user_princ, 'abcd', 2) - change_password_check_mkvno(False, realm.user_princ, 'user', 2) - - # Check purge_mkeys behavior with both master keys still in use. --out = realm.run([kdb5_util, 'purge_mkeys', '-f', '-v']) --if 'All keys in use, nothing purged.' not in out: -- fail('Unexpected output from purge_mkeys with both mkeys in use') -+realm.run([kdb5_util, 'purge_mkeys', '-f', '-v'], -+ expected_msg='All keys in use, nothing purged.') - - # Do an update_princ_encryption dry run and for real. Verify that: - # 1. The target master key is 2 (the active mkvno). -@@ -226,9 +222,8 @@ update_princ_encryption(False, 2, nprincs - 1, 0) - check_mkvno(realm.user_princ, 2) - - # Test the safety check for purging with an outdated stash file. --out = realm.run([kdb5_util, 'purge_mkeys', '-f'], expected_code=1) --if 'stash file needs updating' not in out: -- fail('Unexpected error from purge_mkeys safety check') -+realm.run([kdb5_util, 'purge_mkeys', '-f'], expected_code=1, -+ expected_msg='stash file needs updating') - - # Update the master stash file and check it. Save a copy of the old - # one for a later test. -@@ -253,18 +248,15 @@ check_mkey_list((2, defetype, True, True)) - check_master_dbent(2, (2, defetype)) - os.rename(stash_file, stash_file + '.save') - os.rename(stash_file + '.old', stash_file) --out = realm.run([kadminl, 'getprinc', 'user'], expected_code=1) --if 'Unable to decrypt latest master key' not in out: -- fail('Unexpected error from kadmin.local with old stash file') -+realm.run([kadminl, 'getprinc', 'user'], expected_code=1, -+ expected_msg='Unable to decrypt latest master key') - os.rename(stash_file + '.save', stash_file) - realm.run([kdb5_util, 'stash']) - check_stash((2, defetype)) --out = realm.run([kdb5_util, 'use_mkey', '1'], expected_code=1) --if '1 is an invalid KVNO value' not in out: -- fail('Unexpected error from use_mkey with invalid kvno') --out = realm.run([kdb5_util, 'purge_mkeys', '-f', '-v']) --if 'There is only one master key which can not be purged.' not in out: -- fail('Unexpected output from purge_mkeys with one mkey') -+realm.run([kdb5_util, 'use_mkey', '1'], expected_code=1, -+ expected_msg='1 is an invalid KVNO value') -+realm.run([kdb5_util, 'purge_mkeys', '-f', '-v'], -+ expected_msg='There is only one master key which can not be purged.') - - # Add a third master key with a specified enctype. Verify that: - # 1. The new master key receives the correct number. -@@ -331,8 +323,7 @@ check_mkey_list((2, defetype, True, True), (1, des3, True, False)) - # Regression test for #8395. Purge the master key and verify that a - # master key fetch does not segfault. - realm.run([kadminl, 'purgekeys', '-all', 'K/M']) --out = realm.run([kadminl, 'getprinc', realm.user_princ], expected_code=1) --if 'Cannot find master key record in database' not in out: -- fail('Unexpected output from failed master key fetch') -+realm.run([kadminl, 'getprinc', realm.user_princ], expected_code=1, -+ expected_msg='Cannot find master key record in database') - - success('Master key rollover tests') -diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py -index f098374f9..9b18ff94b 100755 ---- a/src/tests/t_otp.py -+++ b/src/tests/t_otp.py -@@ -199,9 +199,8 @@ realm.run([kadminl, 'setstr', realm.user_princ, 'otp', otpconfig('udp')]) - realm.kinit(realm.user_princ, 'accept', flags=flags) - verify(daemon, queue, True, realm.user_princ.split('@')[0], 'accept') - realm.extract_keytab(realm.krbtgt_princ, realm.keytab) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indotp1, indotp2]' not in out: -- fail('auth indicators not seen in OTP ticket') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indotp1, indotp2]') - - # Repeat with an indicators override in the string attribute. - daemon = UDPRadiusDaemon(args=(server_addr, secret_file, 'accept', queue)) -@@ -212,9 +211,8 @@ realm.run([kadminl, 'setstr', realm.user_princ, 'otp', oconf]) - realm.kinit(realm.user_princ, 'accept', flags=flags) - verify(daemon, queue, True, realm.user_princ.split('@')[0], 'accept') - realm.extract_keytab(realm.krbtgt_princ, realm.keytab) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indtok1, indtok2]' not in out: -- fail('auth indicators not seen in OTP ticket') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indtok1, indtok2]') - - # Detect upstream pyrad bug - # https://github.com/wichert/pyrad/pull/18 -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index f56141564..e943f4974 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -101,10 +101,9 @@ realm.kinit('user@krbtest.com', - flags=['-E', '-X', 'X509_user_identity=%s' % p12_upn2_identity]) - - # Test a mismatch. --out = realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, -- 'user2'], expected_code=1) --if 'kinit: Client name mismatch while getting initial credentials' not in out: -- fail('Wrong error for UPN SAN mismatch') -+msg = 'kinit: Client name mismatch while getting initial credentials' -+realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, 'user2'], -+ expected_code=1, expected_msg=msg) - realm.stop() - - realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, -@@ -118,9 +117,8 @@ realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - - # Test anonymous PKINIT. --out = realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Wrong error for anonymous PKINIT without anonymous enabled') -+realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1, -+ expected_msg='not found in Kerberos database') - realm.addprinc('WELLKNOWN/ANONYMOUS') - realm.kinit('@%s' % realm.realm, flags=['-n']) - realm.klist('WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS') -@@ -135,9 +133,8 @@ f.write('WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS a *') - f.close() - realm.start_kadmind() - realm.run([kadmin, '-n', 'addprinc', '-pw', 'test', 'testadd']) --out = realm.run([kadmin, '-n', 'getprinc', 'testadd'], expected_code=1) --if "Operation requires ``get'' privilege" not in out: -- fail('Anonymous kadmin has too much privilege') -+realm.run([kadmin, '-n', 'getprinc', 'testadd'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") - realm.stop_kadmind() - - # Test with anonymous restricted; FAST should work but kvno should fail. -@@ -146,9 +143,8 @@ realm.stop_kdc() - realm.start_kdc(env=r_env) - realm.kinit('@%s' % realm.realm, flags=['-n']) - realm.kinit('@%s' % realm.realm, flags=['-n', '-T', realm.ccache]) --out = realm.run([kvno, realm.host_princ], expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('Wrong error for restricted anonymous PKINIT') -+realm.run([kvno, realm.host_princ], expected_code=1, -+ expected_msg='KDC policy rejects request') - - # Regression test for #8458: S4U2Self requests crash the KDC if - # anonymous is restricted. -@@ -200,9 +196,8 @@ realm.kinit(realm.user_princ, - password='encrypted') - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indpkinit1, indpkinit2]' not in out: -- fail('auth indicators not seen in PKINIT ticket') -+realm.run(['./adata', realm.host_princ], -+ expected_msg='+97: [indpkinit1, indpkinit2]') - - # Run the basic test - PKINIT with FILE: identity, with a password on the key, - # supplied by the responder. -diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py -index bfec96a93..26c4e466e 100755 ---- a/src/tests/t_policy.py -+++ b/src/tests/t_policy.py -@@ -7,35 +7,27 @@ realm = K5Realm(create_host=False, start_kadmind=True) - # Test password quality enforcement. - realm.run([kadminl, 'addpol', '-minlength', '6', '-minclasses', '2', 'pwpol']) - realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'pwpol', 'pwuser']) --out = realm.run([kadminl, 'cpw', '-pw', 'sh0rt', 'pwuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password') --out = realm.run([kadminl, 'cpw', '-pw', 'longenough', 'pwuser'], -- expected_code=1) --if 'Password does not contain enough character classes' not in out: -- fail('insufficient character classes') -+realm.run([kadminl, 'cpw', '-pw', 'sh0rt', 'pwuser'], expected_code=1, -+ expected_msg='Password is too short') -+realm.run([kadminl, 'cpw', '-pw', 'longenough', 'pwuser'], expected_code=1, -+ expected_msg='Password does not contain enough character classes') - realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) - - # Test some password history enforcement. Even with no history value, - # the current password should be denied. --out = realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of current password') -+realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - realm.run([kadminl, 'modpol', '-history', '2', 'pwpol']) - realm.run([kadminl, 'cpw', '-pw', 'an0therpw', 'pwuser']) --out = realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of old password') -+realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) - realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) - - # Test references to nonexistent policies. - realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'newpol', 'newuser']) --out = realm.run([kadminl, 'getprinc', 'newuser']) --if 'Policy: newpol [does not exist]\n' not in out: -- fail('getprinc output for principal referencing nonexistent policy') -+realm.run([kadminl, 'getprinc', 'newuser'], -+ expected_msg='Policy: newpol [does not exist]\n') - realm.run([kadminl, 'modprinc', '-policy', 'newpol', 'pwuser']) - # pwuser should allow reuse of the current password since newpol doesn't exist. - realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) -@@ -45,29 +37,20 @@ realm.run([kadmin, '-p', 'pwuser', '-w', '3rdpassword', 'cpw', '-pw', - - # Create newpol and verify that it is enforced. - realm.run([kadminl, 'addpol', '-minlength', '3', 'newpol']) --out = realm.run([kadminl, 'getprinc', 'pwuser']) --if 'Policy: newpol\n' not in out: -- fail('getprinc after creating policy (pwuser)') --out = realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password after creating policy (pwuser)') --out = realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of current password after creating policy') -+realm.run([kadminl, 'getprinc', 'pwuser'], expected_msg='Policy: newpol\n') -+realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser'], expected_code=1, -+ expected_msg='Password is too short') -+realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - --out = realm.run([kadminl, 'getprinc', 'newuser']) --if 'Policy: newpol\n' not in out: -- fail('getprinc after creating policy (newuser)') --out = realm.run([kadminl, 'cpw', '-pw', 'aa', 'newuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password after creating policy (newuser)') -+realm.run([kadminl, 'getprinc', 'newuser'], expected_msg='Policy: newpol\n') -+realm.run([kadminl, 'cpw', '-pw', 'aa', 'newuser'], expected_code=1, -+ expected_msg='Password is too short') - - # Delete the policy and verify that it is no longer enforced. - realm.run([kadminl, 'delpol', 'newpol']) --out = realm.run([kadminl, 'getpol', 'newpol'], expected_code=1) --if 'Policy does not exist' not in out: -- fail('deletion of referenced policy') -+realm.run([kadminl, 'getpol', 'newpol'], expected_code=1, -+ expected_msg='Policy does not exist') - realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser']) - - # Test basic password lockout support. -@@ -78,18 +61,14 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', '-policy', 'lockout', - 'user']) - - # kinit twice with the wrong password. --output = realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1) --if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') --output = realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1) --if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') -+realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg='Password incorrect while getting initial credentials') -+realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg='Password incorrect while getting initial credentials') - - # Now the account should be locked out. --output = realm.run([kinit, realm.user_princ], expected_code=1) --if 'Client\'s credentials have been revoked while getting initial credentials' \ -- not in output: -- fail('Expected lockout error message not seen in kinit output') -+m = 'Client\'s credentials have been revoked while getting initial credentials' -+realm.run([kinit, realm.user_princ], expected_code=1, expected_msg=m) - - # Check that modprinc -unlock allows a further attempt. - realm.run([kadminl, 'modprinc', '-unlock', 'user']) -@@ -113,10 +92,8 @@ realm.run([kadminl, 'cpw', '-pw', 'pw2', 'user']) - # Swap the keys, simulating older kadmin having chosen the second entry. - realm.run(['./hist', 'swap']) - # Make sure we can read the history entry. --out = realm.run([kadminl, 'cpw', '-pw', password('user'), 'user'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('Expected error not seen in output') -+realm.run([kadminl, 'cpw', '-pw', password('user'), 'user'], expected_code=1, -+ expected_msg='Cannot reuse password') - - # Test key/salt constraints. - -@@ -142,9 +119,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts', 'server']) - - # Test modpol. - realm.run([kadminl, 'modpol', '-allowedkeysalts', 'aes256-cts,rc4-hmac', 'ak']) --out = realm.run([kadminl, 'getpol', 'ak']) --if not 'Allowed key/salt types: aes256-cts,rc4-hmac' in out: -- fail('getpol does not implement allowedkeysalts?') -+realm.run([kadminl, 'getpol', 'ak'], -+ expected_msg='Allowed key/salt types: aes256-cts,rc4-hmac') - - # Test subsets and full set. - realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac', 'server']) -@@ -153,19 +129,14 @@ realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts,rc4-hmac', 'server']) - realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes256-cts', 'server']) - - # Check that the order we got is the one from the policy. --out = realm.run([kadminl, 'getprinc', '-terse', 'server']) --if not '2\t1\t6\t18\t0\t1\t6\t23\t0' in out: -- fail('allowed_keysalts policy did not preserve order') -+realm.run([kadminl, 'getprinc', '-terse', 'server'], -+ expected_msg='2\t1\t6\t18\t0\t1\t6\t23\t0') - - # Test partially intersecting sets. --out = realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes128-cts', -- 'server'], expected_code=1) --if not 'Invalid key/salt tuples' in out: -- fail('allowed_keysalts policy not applied properly') --out = realm.run([kadminl, 'cpw', '-randkey', '-e', -- 'rc4-hmac,aes256-cts,aes128-cts', 'server'], expected_code=1) --if not 'Invalid key/salt tuples' in out: -- fail('allowed_keysalts policy not applied properly') -+realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes128-cts', 'server'], -+ expected_code=1, expected_msg='Invalid key/salt tuples') -+realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes256-cts,aes128-cts', -+ 'server'], expected_code=1, expected_msg='Invalid key/salt tuples') - - # Test reset of allowedkeysalts. - realm.run([kadminl, 'modpol', '-allowedkeysalts', '-', 'ak']) -diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py -index 0ef8bbca4..1823a797d 100644 ---- a/src/tests/t_preauth.py -+++ b/src/tests/t_preauth.py -@@ -10,18 +10,12 @@ realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) - realm.run([kadminl, 'modprinc', '+requires_preauth', realm.user_princ]) - realm.run([kadminl, 'setstr', realm.user_princ, 'teststring', 'testval']) - realm.run([kadminl, 'addprinc', '-nokey', '+requires_preauth', 'nokeyuser']) --out = realm.run([kinit, realm.user_princ], input=password('user')+'\n') --if 'testval' not in out: -- fail('Decrypted string attribute not in kinit output') --out = realm.run([kinit, 'nokeyuser'], input=password('user')+'\n', -- expected_code=1) --if 'no key' not in out: -- fail('Expected "no key" message not in kinit output') -+realm.kinit(realm.user_princ, password('user'), expected_msg='testval') -+realm.kinit('nokeyuser', password('user'), expected_code=1, -+ expected_msg='no key') - - # Exercise KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. - realm.run([kadminl, 'setstr', realm.user_princ, '2rt', 'secondtrip']) --out = realm.run([kinit, realm.user_princ], input=password('user')+'\n') --if '2rt: secondtrip' not in out: -- fail('multi round-trip cookie test') -+realm.kinit(realm.user_princ, password('user'), expected_msg='2rt: secondtrip') - - success('Pre-authentication framework tests') -diff --git a/src/tests/t_pwqual.py b/src/tests/t_pwqual.py -index 0d1d387d8..011110bd1 100755 ---- a/src/tests/t_pwqual.py -+++ b/src/tests/t_pwqual.py -@@ -18,29 +18,24 @@ f.close() - realm.run([kadminl, 'addpol', 'pol']) - - # The built-in "empty" module rejects empty passwords even without a policy. --out = realm.run([kadminl, 'addprinc', '-pw', '', 'p1'], expected_code=1) --if 'Empty passwords are not allowed' not in out: -- fail('Expected error not seen for empty password') -+realm.run([kadminl, 'addprinc', '-pw', '', 'p1'], expected_code=1, -+ expected_msg='Empty passwords are not allowed') - - # The built-in "dict" module rejects dictionary words, but only with a policy. - realm.run([kadminl, 'addprinc', '-pw', 'birds', 'p2']) --out = realm.run([kadminl, 'addprinc', '-pw', 'birds', '-policy', 'pol', 'p3'], -- expected_code=1) --if 'Password is in the password dictionary' not in out: -- fail('Expected error not seen from dictionary password') -+realm.run([kadminl, 'addprinc', '-pw', 'birds', '-policy', 'pol', 'p3'], -+ expected_code=1, -+ expected_msg='Password is in the password dictionary') - - # The built-in "princ" module rejects principal components, only with a policy. - realm.run([kadminl, 'addprinc', '-pw', 'p4', 'p4']) --out = realm.run([kadminl, 'addprinc', '-pw', 'p5', '-policy', 'pol', 'p5'], -- expected_code=1) --if 'Password may not match principal name' not in out: -- fail('Expected error not seen from principal component') -+realm.run([kadminl, 'addprinc', '-pw', 'p5', '-policy', 'pol', 'p5'], -+ expected_code=1, -+ expected_msg='Password may not match principal name') - - # The dynamic "combo" module rejects pairs of dictionary words. --out = realm.run([kadminl, 'addprinc', '-pw', 'birdsoranges', 'p6'], -- expected_code=1) --if 'Password may not be a pair of dictionary words' not in out: -- fail('Expected error not seen from combo module') -+realm.run([kadminl, 'addprinc', '-pw', 'birdsoranges', 'p6'], expected_code=1, -+ expected_msg='Password may not be a pair of dictionary words') - - # These plugin ordering tests aren't specifically related to the - # password quality interface, but are convenient to put here. -diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py -index 559fbd5f7..9765116aa 100755 ---- a/src/tests/t_referral.py -+++ b/src/tests/t_referral.py -@@ -23,9 +23,8 @@ def testref(realm, nametype): - # Get credentials and check that we get an error, not a referral. - def testfail(realm, nametype): - shutil.copyfile(savefile, realm.ccache) -- out = realm.run(['./gcred', nametype, 'a/x.d'], expected_code=1) -- if 'not found in Kerberos database' not in out: -- fail('unexpected error') -+ realm.run(['./gcred', nametype, 'a/x.d'], expected_code=1, -+ expected_msg='not found in Kerberos database') - - # Create a modified KDC environment and restart the KDC. - def restart_kdc(realm, kdc_conf): -@@ -116,9 +115,8 @@ r1, r2 = cross_realms(2, xtgts=(), - create_host=False) - r2.addprinc('abc\@XYZ', 'pw') - r1.start_kdc() --out = r1.kinit('user', expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Expected error not seen for referral without canonicalize flag') -+r1.kinit('user', expected_code=1, -+ expected_msg='not found in Kerberos database') - r1.kinit('user', password('user'), ['-C']) - r1.klist('user@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') - r1.kinit('abc@XYZ', 'pw', ['-E']) -diff --git a/src/tests/t_renew.py b/src/tests/t_renew.py -index a5f0d4bc1..106c8ecd3 100755 ---- a/src/tests/t_renew.py -+++ b/src/tests/t_renew.py -@@ -32,9 +32,8 @@ realm.run([kvno, realm.user_princ]) - - # Make sure we can't renew non-renewable tickets. - test('non-renewable', '1h', '1h', False) --out = realm.kinit(realm.user_princ, flags=['-R'], expected_code=1) --if "KDC can't fulfill requested option" not in out: -- fail('expected error not seen renewing non-renewable ticket') -+realm.kinit(realm.user_princ, flags=['-R'], expected_code=1, -+ expected_msg="KDC can't fulfill requested option") - - # Test that -allow_renewable on the client principal works. - realm.run([kadminl, 'modprinc', '-allow_renewable', 'user']) -diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index e923c92d1..ddb1905ed 100755 ---- a/src/tests/t_salt.py -+++ b/src/tests/t_salt.py -@@ -62,13 +62,11 @@ for ks in dup_kstypes: - # fails. - def test_reject_afs3(realm, etype): - query = 'ank -e ' + etype + ':afs3 -pw password princ1' -- out = realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', -- 'princ1'], expected_code=1) -- if 'Invalid key generation parameters from KDC' not in out: -- fail('Allowed afs3 salt for ' + etype) -- out = realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1) -- if 'Principal does not exist' not in out: -- fail('Created principal with afs3 salt and enctype ' + etype) -+ realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', -+ 'princ1'], expected_code=1, -+ expected_msg='Invalid key generation parameters from KDC') -+ realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1, -+ expected_msg='Principal does not exist') - - # Verify that the afs3 salt is rejected for arcfour and pbkdf2 enctypes. - # We do not currently do any verification on the key-generation parameters -diff --git a/src/tests/t_skew.py b/src/tests/t_skew.py -index b72971070..f2ae06695 100755 ---- a/src/tests/t_skew.py -+++ b/src/tests/t_skew.py -@@ -37,22 +37,16 @@ realm.kinit(realm.user_princ, password('user'), - - # kinit should detect too much skew in the KDC response. kinit with - # FAST should fail from the KDC since the armor AP-REQ won't be valid. --out = realm.kinit(realm.user_princ, password('user'), expected_code=1) --if 'Clock skew too great in KDC reply' not in out: -- fail('Expected error message not seen in kinit skew case') --out = realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], -- expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit FAST skew case') -+realm.kinit(realm.user_princ, password('user'), expected_code=1, -+ expected_msg='Clock skew too great in KDC reply') -+realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], expected_code=1, -+ expected_msg='Clock skew too great while') - - # kinit (with preauth) should fail from the KDC, with or without FAST. - realm.run([kadminl, 'modprinc', '+requires_preauth', 'user']) --out = realm.kinit(realm.user_princ, password('user'), expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit skew case (preauth)') --out = realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], -- expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit FAST skew case (preauth)') -+realm.kinit(realm.user_princ, password('user'), expected_code=1, -+ expected_msg='Clock skew too great while') -+realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], expected_code=1, -+ expected_msg='Clock skew too great while') - - success('Clock skew tests') -diff --git a/src/tests/t_stringattr.py b/src/tests/t_stringattr.py -index 281c8726f..5672a0f20 100755 ---- a/src/tests/t_stringattr.py -+++ b/src/tests/t_stringattr.py -@@ -28,9 +28,7 @@ realm = K5Realm(start_kadmind=True, create_host=False, get_creds=False) - - realm.prep_kadmin() - --out = realm.run_kadmin(['getstrs', 'user']) --if '(No string attributes.)' not in out: -- fail('Empty attribute query') -+realm.run_kadmin(['getstrs', 'user'], expected_msg='(No string attributes.)') - - realm.run_kadmin(['setstr', 'user', 'attr1', 'value1']) - realm.run_kadmin(['setstr', 'user', 'attr2', 'value2']) diff --git a/Use-expected_trace-in-test-scripts.patch b/Use-expected_trace-in-test-scripts.patch deleted file mode 100644 index 74516ea..0000000 --- a/Use-expected_trace-in-test-scripts.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 35a00879008457d21ccc6e623835976a21f5000b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jan 2017 11:25:22 -0500 -Subject: [PATCH] Use expected_trace in test scripts - -(cherry picked from commit 7b7e5d964e5d020fdda3fb9843d9b8cf8b29a6f8) ---- - src/tests/t_general.py | 24 ++++++++---------------- - src/tests/t_pkinit.py | 15 ++++++--------- - 2 files changed, 14 insertions(+), 25 deletions(-) - -diff --git a/src/tests/t_general.py b/src/tests/t_general.py -index 6d523fe45..16bf6c5e3 100755 ---- a/src/tests/t_general.py -+++ b/src/tests/t_general.py -@@ -47,21 +47,13 @@ if 'not found in Kerberos database' not in out: - fail('Expected error message not seen in kinit -C output') - - # Spot-check KRB5_TRACE output --tracefile = os.path.join(realm.testdir, 'trace') --realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, realm.user_princ], -- input=(password('user') + "\n")) --f = open(tracefile, 'r') --trace = f.read() --f.close() --expected = ('Sending initial UDP request', -- 'Received answer', -- 'Selected etype info', -- 'AS key obtained', -- 'Decrypted AS reply', -- 'FAST negotiation: available', -- 'Storing user@KRBTEST.COM') --for e in expected: -- if e not in trace: -- fail('Expected output not in kinit trace log') -+expected_trace = ('Sending initial UDP request', -+ 'Received answer', -+ 'Selected etype info', -+ 'AS key obtained', -+ 'Decrypted AS reply', -+ 'FAST negotiation: available', -+ 'Storing user@KRBTEST.COM') -+realm.kinit(realm.user_princ, password('user'), expected_trace=expected_trace) - - success('FAST kinit, trace logging') -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 183977750..f56141564 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -176,19 +176,16 @@ realm.klist(realm.user_princ) - - # Test a DH parameter renegotiation by temporarily setting a 4096-bit - # minimum on the KDC. --tracefile = os.path.join(realm.testdir, 'trace') - minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} - minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) - realm.stop_kdc() - realm.start_kdc(env=minbits_env) --realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, '-X', -- 'X509_user_identity=' + file_identity, realm.user_princ]) --with open(tracefile, 'r') as f: -- trace = f.read() --if ('Key parameters not accepted' not in trace or -- 'Preauth tryagain input types' not in trace or -- 'trying again with KDC-provided parameters' not in trace): -- fail('DH renegotiation steps not found in kinit trace log') -+expected_trace = ('Key parameters not accepted', -+ 'Preauth tryagain input types', -+ 'trying again with KDC-provided parameters') -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_trace=expected_trace) - realm.stop_kdc() - realm.start_kdc() - diff --git a/Use-fallback-realm-for-GSSAPI-ccache-selection.patch b/Use-fallback-realm-for-GSSAPI-ccache-selection.patch deleted file mode 100644 index bc0591a..0000000 --- a/Use-fallback-realm-for-GSSAPI-ccache-selection.patch +++ /dev/null @@ -1,185 +0,0 @@ -From feee4c633a7db348ef99f1f0c99a5c2e6cb70f92 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Fri, 10 Feb 2017 12:53:42 -0500 -Subject: [PATCH] Use fallback realm for GSSAPI ccache selection - -In krb5_cc_select(), if the server principal has an empty realm, use -krb5_get_fallback_host_realm() and set the server realm to the first -fallback found. This helps with the selection of a non-default ccache -when there is no [domain_realms] configuration for the server domain. -Modify t_ccselect.py tests to account for fallback behavior. - -ticket: 8549 (new) -(cherry picked from commit 234b64bd6139d5b75dadd5abbd5bef5a162e298a) ---- - src/lib/krb5/ccache/ccselect.c | 37 ++++++++++++++++++++++++++----- - src/tests/gssapi/t_ccselect.py | 50 +++++++++++++++++++++++++++++++++--------- - 2 files changed, 72 insertions(+), 15 deletions(-) - -diff --git a/src/lib/krb5/ccache/ccselect.c b/src/lib/krb5/ccache/ccselect.c -index 2f3071a27..ee4b83a9b 100644 ---- a/src/lib/krb5/ccache/ccselect.c -+++ b/src/lib/krb5/ccache/ccselect.c -@@ -132,6 +132,8 @@ krb5_cc_select(krb5_context context, krb5_principal server, - struct ccselect_module_handle **hp, *h; - krb5_ccache cache; - krb5_principal princ; -+ krb5_principal srvcp = NULL; -+ char **fbrealms = NULL; - - *cache_out = NULL; - *princ_out = NULL; -@@ -139,7 +141,27 @@ krb5_cc_select(krb5_context context, krb5_principal server, - if (context->ccselect_handles == NULL) { - ret = load_modules(context); - if (ret) -- return ret; -+ goto cleanup; -+ } -+ -+ /* Try to use the fallback host realm for the server if there is no -+ * authoritative realm. */ -+ if (krb5_is_referral_realm(&server->realm) && -+ server->type == KRB5_NT_SRV_HST && server->length == 2) { -+ ret = krb5_get_fallback_host_realm(context, &server->data[1], -+ &fbrealms); -+ if (ret) -+ goto cleanup; -+ -+ /* Make a copy with the first fallback realm. */ -+ ret = krb5_copy_principal(context, server, &srvcp); -+ if (ret) -+ goto cleanup; -+ ret = krb5_set_principal_realm(context, srvcp, fbrealms[0]); -+ if (ret) -+ goto cleanup; -+ -+ server = srvcp; - } - - /* Consult authoritative modules first, then heuristic ones. */ -@@ -155,20 +177,25 @@ krb5_cc_select(krb5_context context, krb5_principal server, - princ); - *cache_out = cache; - *princ_out = princ; -- return 0; -+ goto cleanup; - } else if (ret == KRB5_CC_NOTFOUND) { - TRACE_CCSELECT_MODNOTFOUND(context, h->vt.name, server, princ); - *princ_out = princ; -- return ret; -+ goto cleanup; - } else if (ret != KRB5_PLUGIN_NO_HANDLE) { - TRACE_CCSELECT_MODFAIL(context, h->vt.name, ret, server); -- return ret; -+ goto cleanup; - } - } - } - - TRACE_CCSELECT_NOTFOUND(context, server); -- return KRB5_CC_NOTFOUND; -+ ret = KRB5_CC_NOTFOUND; -+ -+cleanup: -+ krb5_free_principal(context, srvcp); -+ krb5_free_host_realm(context, fbrealms); -+ return ret; - } - - void -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 1ea614d30..668a2cc62 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -31,12 +31,18 @@ r2 = K5Realm(create_user=False, realm='KRBTEST2.COM', portbase=62000, - - host1 = 'p:' + r1.host_princ - host2 = 'p:' + r2.host_princ -+foo = 'foo.krbtest.com' -+foo2 = 'foo.krbtest2.com' - --# gsserver specifies the target as a GSS name. The resulting --# principal will have the host-based type, but the realm won't be --# known before the client cache is selected (since k5test realms have --# no domain-realm mapping by default). --gssserver = 'h:host@' + hostname -+# These strings specify the target as a GSS name. The resulting -+# principal will have the host-based type, with the referral realm -+# (since k5test realms have no domain-realm mapping by default). -+# krb5_cc_select() will use the fallback realm, which is either the -+# uppercased parent domain, or the default realm if the hostname is a -+# single component. -+gssserver = 'h:host@' + foo -+gssserver2 = 'h:host@' + foo2 -+gsslocal = 'h:host@localhost' - - # refserver specifies the target as a principal in the referral realm. - # The principal won't be treated as a host principal by the -@@ -66,6 +72,16 @@ r1.addprinc(alice, password('alice')) - r1.addprinc(bob, password('bob')) - r2.addprinc(zaphod, password('zaphod')) - -+# Create host principals and keytabs for fallback realm tests. -+r1.addprinc('host/localhost') -+r2.addprinc('host/localhost') -+r1.addprinc('host/' + foo) -+r2.addprinc('host/' + foo2) -+r1.extract_keytab('host/localhost', r1.keytab) -+r2.extract_keytab('host/localhost', r2.keytab) -+r1.extract_keytab('host/' + foo, r1.keytab) -+r2.extract_keytab('host/' + foo2, r2.keytab) -+ - # Get tickets for one user in each realm (zaphod will be primary). - r1.kinit(alice, password('alice')) - r2.kinit(zaphod, password('zaphod')) -@@ -93,10 +109,24 @@ if output != (zaphod + '\n'): - fail('zaphod not chosen as default initiator name for server in r1') - - # Check that primary cache is used if server realm is unknown. --output = r2.run(['./t_ccselect', gssserver]) -+output = r2.run(['./t_ccselect', refserver]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via primary cache for unknown server realm') --r1.run(['./t_ccselect', gssserver], expected_code=1) -+r1.run(['./t_ccselect', gssserver2], expected_code=1) -+# Check ccache selection using a fallback realm. -+output = r1.run(['./t_ccselect', gssserver]) -+if output != (alice + '\n'): -+ fail('alice not chosen via parent domain fallback') -+output = r2.run(['./t_ccselect', gssserver2]) -+if output != (zaphod + '\n'): -+ fail('zaphod not chosen via parent domain fallback') -+# Check ccache selection using a fallback realm (default realm). -+output = r1.run(['./t_ccselect', gsslocal]) -+if output != (alice + '\n'): -+ fail('alice not chosen via default realm fallback') -+output = r2.run(['./t_ccselect', gsslocal]) -+if output != (zaphod + '\n'): -+ fail('zaphod not chosen via default realm fallback') - - # Get a second cred in r1 (bob will be primary). - r1.kinit(bob, password('bob')) -@@ -104,19 +134,19 @@ r1.kinit(bob, password('bob')) - # Try some cache selections using .k5identity. - k5id = open(os.path.join(r1.testdir, '.k5identity'), 'w') - k5id.write('%s realm=%s\n' % (alice, r1.realm)) --k5id.write('%s service=ho*t host=%s\n' % (zaphod, hostname)) -+k5id.write('%s service=ho*t host=localhost\n' % zaphod) - k5id.write('noprinc service=bogus') - k5id.close() - output = r1.run(['./t_ccselect', host1]) - if output != (alice + '\n'): - fail('alice not chosen via .k5identity realm line.') --output = r2.run(['./t_ccselect', gssserver]) -+output = r2.run(['./t_ccselect', gsslocal]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via .k5identity service/host line.') - output = r1.run(['./t_ccselect', refserver]) - if output != (bob + '\n'): - fail('bob not chosen via primary cache when no .k5identity line matches.') --r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1, -+r1.run(['./t_ccselect', 'h:bogus@' + foo2], expected_code=1, - expected_msg="Can't find client principal noprinc") - - success('GSSAPI credential selection tests') diff --git a/Use-krb5_timestamp-where-appropriate.patch b/Use-krb5_timestamp-where-appropriate.patch deleted file mode 100644 index c5b4c25..0000000 --- a/Use-krb5_timestamp-where-appropriate.patch +++ /dev/null @@ -1,327 +0,0 @@ -From 0ae9141d53a8d9fe048542f89d17760990bd5bc4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 17 May 2017 15:14:15 -0400 -Subject: [PATCH] Use krb5_timestamp where appropriate - -Where krb5_int32 is used to hold the number of seconds since the -epoch, use krb5_timestamp instead. - -(cherry picked from commit ae25f6ec5558140a546db34fea389412d81c0631) ---- - src/clients/klist/klist.c | 2 +- - src/include/k5-int.h | 2 +- - src/kadmin/server/misc.c | 2 +- - src/kdc/dispatch.c | 4 ++-- - src/lib/kadm5/srv/server_acl.c | 2 +- - src/lib/kadm5/srv/server_kdb.c | 2 +- - src/lib/kadm5/srv/svr_principal.c | 10 +++++----- - src/lib/krb5/krb/gen_save_subkey.c | 3 ++- - src/lib/krb5/krb/get_in_tkt.c | 2 +- - src/lib/krb5/krb/init_ctx.c | 3 ++- - src/lib/krb5/os/c_ustime.c | 7 +++++-- - src/lib/krb5/os/toffset.c | 3 ++- - src/lib/krb5/os/trace.c | 3 ++- - src/lib/krb5/os/ustime.c | 3 ++- - src/lib/krb5/rcache/rc_dfl.c | 10 +++++----- - src/tests/create/kdb5_mkdums.c | 2 +- - 16 files changed, 34 insertions(+), 26 deletions(-) - -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index ffeecc394..4334415be 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -56,7 +56,7 @@ int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0; - int show_config = 0; - char *defname; - char *progname; --krb5_int32 now; -+krb5_timestamp now; - unsigned int timestamp_width; - - krb5_context kcontext; -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 82ee20760..ed9c7bf75 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -721,7 +721,7 @@ krb5_error_code krb5int_c_copy_keyblock_contents(krb5_context context, - const krb5_keyblock *from, - krb5_keyblock *to); - --krb5_error_code krb5_crypto_us_timeofday(krb5_int32 *, krb5_int32 *); -+krb5_error_code krb5_crypto_us_timeofday(krb5_timestamp *, krb5_int32 *); - - /* - * End "los-proto.h" -diff --git a/src/kadmin/server/misc.c b/src/kadmin/server/misc.c -index a75b65a26..ba672d714 100644 ---- a/src/kadmin/server/misc.c -+++ b/src/kadmin/server/misc.c -@@ -159,7 +159,7 @@ kadm5_ret_t - check_min_life(void *server_handle, krb5_principal principal, - char *msg_ret, unsigned int msg_len) - { -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_ret_t ret; - kadm5_policy_ent_rec pol; - kadm5_principal_ent_rec princ; -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 16a35d2be..4ecc23481 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -94,8 +94,8 @@ static void - reseed_random(krb5_context kdc_err_context) - { - krb5_error_code retval; -- krb5_int32 now, now_usec; -- krb5_int32 usec_difference; -+ krb5_timestamp now; -+ krb5_int32 now_usec, usec_difference; - krb5_data data; - - retval = krb5_crypto_us_timeofday(&now, &now_usec); -diff --git a/src/lib/kadm5/srv/server_acl.c b/src/lib/kadm5/srv/server_acl.c -index c4bb16dc7..679fc7c41 100644 ---- a/src/lib/kadm5/srv/server_acl.c -+++ b/src/lib/kadm5/srv/server_acl.c -@@ -375,7 +375,7 @@ kadm5int_acl_impose_restrictions(kcontext, recp, maskp, rp) - restriction_t *rp; - { - krb5_error_code code; -- krb5_int32 now; -+ krb5_timestamp now; - - DPRINT(DEBUG_CALLS, acl_debug_level, - ("* kadm5int_acl_impose_restrictions(..., *maskp=0x%08x, rp=0x%08x)\n", -diff --git a/src/lib/kadm5/srv/server_kdb.c b/src/lib/kadm5/srv/server_kdb.c -index 612553ba3..f4b8aef2b 100644 ---- a/src/lib/kadm5/srv/server_kdb.c -+++ b/src/lib/kadm5/srv/server_kdb.c -@@ -365,7 +365,7 @@ kdb_put_entry(kadm5_server_handle_t handle, - krb5_db_entry *kdb, osa_princ_ent_rec *adb) - { - krb5_error_code ret; -- krb5_int32 now; -+ krb5_timestamp now; - XDR xdrs; - krb5_tl_data tl_data; - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 137e1fb64..89f34482b 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -296,7 +296,7 @@ kadm5_create_principal_3(void *server_handle, - osa_princ_ent_rec adb; - kadm5_policy_ent_rec polent; - krb5_boolean have_polent = FALSE; -- krb5_int32 now; -+ krb5_timestamp now; - krb5_tl_data *tl_data_tail; - unsigned int ret; - kadm5_server_handle_t handle = server_handle; -@@ -1322,7 +1322,7 @@ kadm5_chpass_principal_3(void *server_handle, - int n_ks_tuple, krb5_key_salt_tuple *ks_tuple, - char *password) - { -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - osa_princ_ent_rec adb; - krb5_db_entry *kdb; -@@ -1544,7 +1544,7 @@ kadm5_randkey_principal_3(void *server_handle, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - int ret, last_pwd, n_new_keys; - krb5_boolean have_pol = FALSE; -@@ -1686,7 +1686,7 @@ kadm5_setv4key_principal(void *server_handle, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - krb5_keysalt keysalt; - int i, kvno, ret; -@@ -1891,7 +1891,7 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - krb5_key_data *new_key_data = NULL; - int i, j, ret, n_new_key_data = 0; -diff --git a/src/lib/krb5/krb/gen_save_subkey.c b/src/lib/krb5/krb/gen_save_subkey.c -index 61f36aa36..bc2c46d30 100644 ---- a/src/lib/krb5/krb/gen_save_subkey.c -+++ b/src/lib/krb5/krb/gen_save_subkey.c -@@ -38,7 +38,8 @@ k5_generate_and_save_subkey(krb5_context context, - to guarantee randomness, but to make it less likely that multiple - sessions could pick the same subkey. */ - struct { -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - } rnd_data; - krb5_data d; - krb5_error_code retval; -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 40aba1905..7178bd87b 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1788,7 +1788,7 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - krb5_creds *creds) - { - int i; -- krb5_int32 starttime; -+ krb5_timestamp starttime; - krb5_deltat lifetime; - krb5_get_init_creds_opt *opt; - krb5_error_code retval; -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index cf226fdba..4246c5dd2 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -139,7 +139,8 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - krb5_context ctx = 0; - krb5_error_code retval; - struct { -- krb5_int32 now, now_usec; -+ krb5_timestamp now; -+ krb5_int32 now_usec; - long pid; - } seed_data; - krb5_data seed; -diff --git a/src/lib/krb5/os/c_ustime.c b/src/lib/krb5/os/c_ustime.c -index 68fb381f4..f69f2ea4c 100644 ---- a/src/lib/krb5/os/c_ustime.c -+++ b/src/lib/krb5/os/c_ustime.c -@@ -29,7 +29,10 @@ - - k5_mutex_t krb5int_us_time_mutex = K5_MUTEX_PARTIAL_INITIALIZER; - --struct time_now { krb5_int32 sec, usec; }; -+struct time_now { -+ krb5_timestamp sec; -+ krb5_int32 usec; -+}; - - #if defined(_WIN32) - -@@ -73,7 +76,7 @@ get_time_now(struct time_now *n) - static struct time_now last_time; - - krb5_error_code --krb5_crypto_us_timeofday(krb5_int32 *seconds, krb5_int32 *microseconds) -+krb5_crypto_us_timeofday(krb5_timestamp *seconds, krb5_int32 *microseconds) - { - struct time_now now; - krb5_error_code err; -diff --git a/src/lib/krb5/os/toffset.c b/src/lib/krb5/os/toffset.c -index 37bc69f49..4bbcdde52 100644 ---- a/src/lib/krb5/os/toffset.c -+++ b/src/lib/krb5/os/toffset.c -@@ -40,7 +40,8 @@ krb5_error_code KRB5_CALLCONV - krb5_set_real_time(krb5_context context, krb5_timestamp seconds, krb5_int32 microseconds) - { - krb5_os_context os_ctx = &context->os_context; -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - krb5_error_code retval; - - retval = krb5_crypto_us_timeofday(&sec, &usec); -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 74c315c90..8750b7650 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -340,7 +340,8 @@ krb5int_trace(krb5_context context, const char *fmt, ...) - va_list ap; - krb5_trace_info info; - char *str = NULL, *msg = NULL; -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - - if (context == NULL || context->trace_callback == NULL) - return; -diff --git a/src/lib/krb5/os/ustime.c b/src/lib/krb5/os/ustime.c -index 1c1b571eb..a80fdf68c 100644 ---- a/src/lib/krb5/os/ustime.c -+++ b/src/lib/krb5/os/ustime.c -@@ -40,7 +40,8 @@ krb5_error_code - k5_time_with_offset(krb5_timestamp offset, krb5_int32 offset_usec, - krb5_timestamp *time_out, krb5_int32 *usec_out) - { -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - krb5_error_code retval; - - retval = krb5_crypto_us_timeofday(&sec, &usec); -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index 6b043844d..41ebf94da 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -93,7 +93,7 @@ cmp(krb5_donot_replay *old, krb5_donot_replay *new1, krb5_deltat t) - } - - static int --alive(krb5_int32 mytime, krb5_donot_replay *new1, krb5_deltat t) -+alive(krb5_timestamp mytime, krb5_donot_replay *new1, krb5_deltat t) - { - if (mytime == 0) - return CMP_HOHUM; /* who cares? */ -@@ -129,7 +129,7 @@ struct authlist - - static int - rc_store(krb5_context context, krb5_rcache id, krb5_donot_replay *rep, -- krb5_int32 now, krb5_boolean fromfile) -+ krb5_timestamp now, krb5_boolean fromfile) - { - struct dfl_data *t = (struct dfl_data *)id->data; - unsigned int rephash; -@@ -536,7 +536,7 @@ krb5_rc_dfl_recover_locked(krb5_context context, krb5_rcache id) - krb5_error_code retval; - long max_size; - int expired_entries = 0; -- krb5_int32 now; -+ krb5_timestamp now; - - if ((retval = krb5_rc_io_open(context, &t->d, t->name))) { - return retval; -@@ -706,7 +706,7 @@ krb5_rc_dfl_store(krb5_context context, krb5_rcache id, krb5_donot_replay *rep) - { - krb5_error_code ret; - struct dfl_data *t; -- krb5_int32 now; -+ krb5_timestamp now; - - ret = krb5_timeofday(context, &now); - if (ret) -@@ -762,7 +762,7 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - struct authlist **qt; - struct authlist *r; - struct authlist *rt; -- krb5_int32 now; -+ krb5_timestamp now; - - if (krb5_timestamp(context, &now)) - now = 0; -diff --git a/src/tests/create/kdb5_mkdums.c b/src/tests/create/kdb5_mkdums.c -index 622f549f9..7c0666601 100644 ---- a/src/tests/create/kdb5_mkdums.c -+++ b/src/tests/create/kdb5_mkdums.c -@@ -247,7 +247,7 @@ add_princ(context, str_newprinc) - - { - /* Add mod princ to db entry */ -- krb5_int32 now; -+ krb5_timestamp now; - - retval = krb5_timeofday(context, &now); - if (retval) { diff --git a/Use-the-canonical-client-principal-name-for-OTP.patch b/Use-the-canonical-client-principal-name-for-OTP.patch deleted file mode 100644 index c96aeb5..0000000 --- a/Use-the-canonical-client-principal-name-for-OTP.patch +++ /dev/null @@ -1,28 +0,0 @@ -From 7998de0b9ccd0c8813159cc3f1d49fe107e3e0ba Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Wed, 5 Apr 2017 16:48:55 -0400 -Subject: [PATCH] Use the canonical client principal name for OTP - -In the OTP module, when constructing the RADIUS request, use the -canonicalized client principal (using the new client_name kdcpreauth -callback) instead of the request client principal. - -ticket: 8571 (new) ---- - src/plugins/preauth/otp/main.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/plugins/preauth/otp/main.c b/src/plugins/preauth/otp/main.c -index 2649e9a90..a1b681682 100644 ---- a/src/plugins/preauth/otp/main.c -+++ b/src/plugins/preauth/otp/main.c -@@ -331,7 +331,8 @@ otp_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, - - /* Send the request. */ - otp_state_verify((otp_state *)moddata, cb->event_context(context, rock), -- request->client, config, req, on_response, rs); -+ cb->client_name(context, rock), config, req, on_response, -+ rs); - cb->free_string(context, rock, config); - - k5_free_pa_otp_req(context, req); diff --git a/ci.fmf b/ci.fmf new file mode 100644 index 0000000..c5aa0e0 --- /dev/null +++ b/ci.fmf @@ -0,0 +1 @@ +resultsdb-testcase: separate diff --git a/gating.yaml b/gating.yaml new file mode 100644 index 0000000..af37a4c --- /dev/null +++ b/gating.yaml @@ -0,0 +1,8 @@ +--- !Policy +product_versions: +- fedora-* +decision_contexts: +- bodhi_update_push_stable +subject_type: koji_build +rules: +- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tests.functional} diff --git a/kadmin.service b/kadmin.service index 49657f6..daa08b1 100644 --- a/kadmin.service +++ b/kadmin.service @@ -1,13 +1,14 @@ [Unit] Description=Kerberos 5 Password-changing and Administration -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target AssertPathExists=!/var/kerberos/krb5kdc/kpropd.acl [Service] Type=forking -PIDFile=/var/run/kadmind.pid +PIDFile=/run/kadmind.pid EnvironmentFile=-/etc/sysconfig/kadmin -ExecStart=/usr/sbin/kadmind -P /var/run/kadmind.pid $KADMIND_ARGS +ExecStart=/usr/sbin/kadmind -P /run/kadmind.pid $KADMIND_ARGS ExecReload=/bin/kill -HUP $MAINPID [Install] diff --git a/kadmind.logrotate b/kadmind.logrotate index 52a66c4..f00aa4d 100644 --- a/kadmind.logrotate +++ b/kadmind.logrotate @@ -4,6 +4,6 @@ monthly rotate 12 postrotate - /bin/kill -HUP `cat /var/run/kadmind.pid 2>/dev/null` 2> /dev/null || true + systemctl reload kadmin.service || true endscript } diff --git a/kdc.conf b/kdc.conf index e99219a..7b788e5 100644 --- a/kdc.conf +++ b/kdc.conf @@ -1,12 +1,20 @@ +[libdefaults] +# Allow RC4 HMAC-MD5 for session keys (see CVE-2022-37966) +#allow_rc4 = true + [kdcdefaults] - kdc_ports = 88 - kdc_tcp_ports = 88 + kdc_ports = 88 + kdc_tcp_ports = 88 + spake_preauth_kdc_challenge = edwards25519 [realms] - EXAMPLE.COM = { - #master_key_type = aes256-cts - acl_file = /var/kerberos/krb5kdc/kadm5.acl - dict_file = /usr/share/dict/words - admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab - supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal - } +EXAMPLE.COM = { + master_key_type = aes256-cts-hmac-sha384-192 + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + default_principal_flags = +preauth + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal camellia256-cts-cmac:normal camellia128-cts-cmac:normal arcfour-hmac-md5:normal + # Supported encryption types for FIPS mode: + #supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal +} diff --git a/kprop.service b/kprop.service index 4bbf8eb..7b5d4b9 100644 --- a/kprop.service +++ b/kprop.service @@ -1,6 +1,7 @@ [Unit] Description=Kerberos 5 Propagation -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target AssertPathExists=/var/kerberos/krb5kdc/kpropd.acl [Service] diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch deleted file mode 100644 index e68fb05..0000000 --- a/krb5-1.11-kpasswdtest.patch +++ /dev/null @@ -1,21 +0,0 @@ -From fb8f32ebdf3293d8a6bdb9478fe1f902a399ba7a Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:52:01 -0400 -Subject: [PATCH] krb5-1.11-kpasswdtest.patch - ---- - src/kadmin/testing/proto/krb5.conf.proto | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index 00c442978..9c4bc1de7 100644 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ b/src/kadmin/testing/proto/krb5.conf.proto -@@ -9,6 +9,7 @@ - __REALM__ = { - kdc = __KDCHOST__:1750 - admin_server = __KDCHOST__:1751 -+ kpasswd_server = __KDCHOST__:1752 - database_module = foobar_db2_module_blah - } - diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch deleted file mode 100644 index ad93b8a..0000000 --- a/krb5-1.11-run_user_0.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 9c45f66fbc6afb472589dbeb5166f46ad266d319 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:49:57 -0400 -Subject: [PATCH] krb5-1.11-run_user_0.patch - -A hack: if we're looking at creating a ccache directory directly below -the /run/user/0 directory, and /run/user/0 doesn't exist, try to create -it, too. ---- - src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c -index 73f0fe62d..4850c0d07 100644 ---- a/src/lib/krb5/ccache/cc_dir.c -+++ b/src/lib/krb5/ccache/cc_dir.c -@@ -61,6 +61,8 @@ - - #include - -+#define ROOT_SPECIAL_DCC_PARENT "/run/user/0" -+ - extern const krb5_cc_ops krb5_dcc_ops; - extern const krb5_cc_ops krb5_fcc_ops; - -@@ -237,6 +239,18 @@ verify_dir(krb5_context context, const char *dirname) - - if (stat(dirname, &st) < 0) { - if (errno == ENOENT) { -+ if (strncmp(dirname, ROOT_SPECIAL_DCC_PARENT "/", -+ sizeof(ROOT_SPECIAL_DCC_PARENT)) == 0 && -+ stat(ROOT_SPECIAL_DCC_PARENT, &st) < 0 && -+ errno == ENOENT) { -+#ifdef USE_SELINUX -+ selabel = krb5int_push_fscreatecon_for(ROOT_SPECIAL_DCC_PARENT); -+#endif -+ status = mkdir(ROOT_SPECIAL_DCC_PARENT, S_IRWXU); -+#ifdef USE_SELINUX -+ krb5int_pop_fscreatecon(selabel); -+#endif -+ } - #ifdef USE_SELINUX - selabel = krb5int_push_fscreatecon_for(dirname); - #endif diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch deleted file mode 100644 index c5bc2e5..0000000 --- a/krb5-1.12-api.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 107a2b8728f1b76feb16df9201919444482e3981 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:47:00 -0400 -Subject: [PATCH] krb5-1.12-api.patch - -Reference docs don't define what happens if you call krb5_realm_compare() with -malformed krb5_principal structures. Define a behavior which keeps it from -crashing if applications don't check ahead of time. ---- - src/lib/krb5/krb/princ_comp.c | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/src/lib/krb5/krb/princ_comp.c b/src/lib/krb5/krb/princ_comp.c -index a6936107d..0ed78833b 100644 ---- a/src/lib/krb5/krb/princ_comp.c -+++ b/src/lib/krb5/krb/princ_comp.c -@@ -36,6 +36,10 @@ realm_compare_flags(krb5_context context, - const krb5_data *realm1 = &princ1->realm; - const krb5_data *realm2 = &princ2->realm; - -+ if (princ1 == NULL || princ2 == NULL) -+ return FALSE; -+ if (realm1 == NULL || realm2 == NULL) -+ return FALSE; - if (realm1->length != realm2->length) - return FALSE; - if (realm1->length == 0) -@@ -88,6 +92,9 @@ krb5_principal_compare_flags(krb5_context context, - krb5_principal upn2 = NULL; - krb5_boolean ret = FALSE; - -+ if (princ1 == NULL || princ2 == NULL) -+ return FALSE; -+ - if (flags & KRB5_PRINCIPAL_COMPARE_ENTERPRISE) { - /* Treat UPNs as if they were real principals */ - if (princ1->type == KRB5_NT_ENTERPRISE_PRINCIPAL) { diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch deleted file mode 100644 index 7f92b1d..0000000 --- a/krb5-1.12-ksu-path.patch +++ /dev/null @@ -1,22 +0,0 @@ -From 93b86d94b871aed49b14d7fc1a2a9f23c16cbe0f Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:32:09 -0400 -Subject: [PATCH] krb5-1.12-ksu-path.patch - -Set the default PATH to the one set by login. ---- - src/clients/ksu/Makefile.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in -index 5755bb58a..9d58f29b5 100644 ---- a/src/clients/ksu/Makefile.in -+++ b/src/clients/ksu/Makefile.in -@@ -1,6 +1,6 @@ - mydir=clients$(S)ksu - BUILDTOP=$(REL)..$(S).. --DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"' -+DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"' - - KSU_LIBS=@KSU_LIBS@ - PAM_LIBS=@PAM_LIBS@ diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch deleted file mode 100644 index a941082..0000000 --- a/krb5-1.12-ktany.patch +++ /dev/null @@ -1,366 +0,0 @@ -From efee9f8598ba84f2be0983fc1d07a9a72d0ff1b7 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:33:53 -0400 -Subject: [PATCH] krb5-1.12-ktany.patch - -Adds an "ANY" keytab type which is a list of other keytab locations to search -when searching for a specific entry. When iterated through, it only presents -the contents of the first keytab. ---- - src/lib/krb5/keytab/Makefile.in | 3 + - src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++++++++++ - src/lib/krb5/keytab/ktbase.c | 7 +- - 3 files changed, 301 insertions(+), 1 deletion(-) - create mode 100644 src/lib/krb5/keytab/kt_any.c - -diff --git a/src/lib/krb5/keytab/Makefile.in b/src/lib/krb5/keytab/Makefile.in -index 2a8fceb00..ffd179fb2 100644 ---- a/src/lib/krb5/keytab/Makefile.in -+++ b/src/lib/krb5/keytab/Makefile.in -@@ -12,6 +12,7 @@ STLIBOBJS= \ - ktfr_entry.o \ - ktremove.o \ - ktfns.o \ -+ kt_any.o \ - kt_file.o \ - kt_memory.o \ - kt_srvtab.o \ -@@ -24,6 +25,7 @@ OBJS= \ - $(OUTPRE)ktfr_entry.$(OBJEXT) \ - $(OUTPRE)ktremove.$(OBJEXT) \ - $(OUTPRE)ktfns.$(OBJEXT) \ -+ $(OUTPRE)kt_any.$(OBJEXT) \ - $(OUTPRE)kt_file.$(OBJEXT) \ - $(OUTPRE)kt_memory.$(OBJEXT) \ - $(OUTPRE)kt_srvtab.$(OBJEXT) \ -@@ -36,6 +38,7 @@ SRCS= \ - $(srcdir)/ktfr_entry.c \ - $(srcdir)/ktremove.c \ - $(srcdir)/ktfns.c \ -+ $(srcdir)/kt_any.c \ - $(srcdir)/kt_file.c \ - $(srcdir)/kt_memory.c \ - $(srcdir)/kt_srvtab.c \ -diff --git a/src/lib/krb5/keytab/kt_any.c b/src/lib/krb5/keytab/kt_any.c -new file mode 100644 -index 000000000..1b9b7765b ---- /dev/null -+++ b/src/lib/krb5/keytab/kt_any.c -@@ -0,0 +1,292 @@ -+/* -+ * lib/krb5/keytab/kt_any.c -+ * -+ * Copyright 1998, 1999 by the Massachusetts Institute of Technology. -+ * All Rights Reserved. -+ * -+ * Export of this software from the United States of America may -+ * require a specific license from the United States Government. -+ * It is the responsibility of any person or organization contemplating -+ * export to obtain such a license before exporting. -+ * -+ * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -+ * distribute this software and its documentation for any purpose and -+ * without fee is hereby granted, provided that the above copyright -+ * notice appear in all copies and that both that copyright notice and -+ * this permission notice appear in supporting documentation, and that -+ * the name of M.I.T. not be used in advertising or publicity pertaining -+ * to distribution of the software without specific, written prior -+ * permission. M.I.T. makes no representations about the suitability of -+ * this software for any purpose. It is provided "as is" without express -+ * or implied warranty. -+ * -+ * -+ * krb5_kta_ops -+ */ -+ -+#include "k5-int.h" -+ -+typedef struct _krb5_ktany_data { -+ char *name; -+ krb5_keytab *choices; -+ int nchoices; -+} krb5_ktany_data; -+ -+typedef struct _krb5_ktany_cursor_data { -+ int which; -+ krb5_kt_cursor cursor; -+} krb5_ktany_cursor_data; -+ -+static krb5_error_code krb5_ktany_resolve -+ (krb5_context, -+ const char *, -+ krb5_keytab *); -+static krb5_error_code krb5_ktany_get_name -+ (krb5_context context, -+ krb5_keytab id, -+ char *name, -+ unsigned int len); -+static krb5_error_code krb5_ktany_close -+ (krb5_context context, -+ krb5_keytab id); -+static krb5_error_code krb5_ktany_get_entry -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_const_principal principal, -+ krb5_kvno kvno, -+ krb5_enctype enctype, -+ krb5_keytab_entry *entry); -+static krb5_error_code krb5_ktany_start_seq_get -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_kt_cursor *cursorp); -+static krb5_error_code krb5_ktany_next_entry -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_keytab_entry *entry, -+ krb5_kt_cursor *cursor); -+static krb5_error_code krb5_ktany_end_seq_get -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_kt_cursor *cursor); -+static void cleanup -+ (krb5_context context, -+ krb5_ktany_data *data, -+ int nchoices); -+ -+struct _krb5_kt_ops krb5_kta_ops = { -+ 0, -+ "ANY", /* Prefix -- this string should not appear anywhere else! */ -+ krb5_ktany_resolve, -+ krb5_ktany_get_name, -+ krb5_ktany_close, -+ krb5_ktany_get_entry, -+ krb5_ktany_start_seq_get, -+ krb5_ktany_next_entry, -+ krb5_ktany_end_seq_get, -+ NULL, -+ NULL, -+ NULL, -+}; -+ -+static krb5_error_code -+krb5_ktany_resolve(context, name, id) -+ krb5_context context; -+ const char *name; -+ krb5_keytab *id; -+{ -+ const char *p, *q; -+ char *copy; -+ krb5_error_code kerror; -+ krb5_ktany_data *data; -+ int i; -+ -+ /* Allocate space for our data and remember a copy of the name. */ -+ if ((data = (krb5_ktany_data *)malloc(sizeof(krb5_ktany_data))) == NULL) -+ return(ENOMEM); -+ if ((data->name = (char *)malloc(strlen(name) + 1)) == NULL) { -+ free(data); -+ return(ENOMEM); -+ } -+ strcpy(data->name, name); -+ -+ /* Count the number of choices and allocate memory for them. */ -+ data->nchoices = 1; -+ for (p = name; (q = strchr(p, ',')) != NULL; p = q + 1) -+ data->nchoices++; -+ if ((data->choices = (krb5_keytab *) -+ malloc(data->nchoices * sizeof(krb5_keytab))) == NULL) { -+ free(data->name); -+ free(data); -+ return(ENOMEM); -+ } -+ -+ /* Resolve each of the choices. */ -+ i = 0; -+ for (p = name; (q = strchr(p, ',')) != NULL; p = q + 1) { -+ /* Make a copy of the choice name so we can terminate it. */ -+ if ((copy = (char *)malloc(q - p + 1)) == NULL) { -+ cleanup(context, data, i); -+ return(ENOMEM); -+ } -+ memcpy(copy, p, q - p); -+ copy[q - p] = 0; -+ -+ /* Try resolving the choice name. */ -+ kerror = krb5_kt_resolve(context, copy, &data->choices[i]); -+ free(copy); -+ if (kerror) { -+ cleanup(context, data, i); -+ return(kerror); -+ } -+ i++; -+ } -+ if ((kerror = krb5_kt_resolve(context, p, &data->choices[i]))) { -+ cleanup(context, data, i); -+ return(kerror); -+ } -+ -+ /* Allocate and fill in an ID for the caller. */ -+ if ((*id = (krb5_keytab)malloc(sizeof(**id))) == NULL) { -+ cleanup(context, data, i); -+ return(ENOMEM); -+ } -+ (*id)->ops = &krb5_kta_ops; -+ (*id)->data = (krb5_pointer)data; -+ (*id)->magic = KV5M_KEYTAB; -+ -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_get_name(context, id, name, len) -+ krb5_context context; -+ krb5_keytab id; -+ char *name; -+ unsigned int len; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ -+ if (len < strlen(data->name) + 1) -+ return(KRB5_KT_NAME_TOOLONG); -+ strcpy(name, data->name); -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_close(context, id) -+ krb5_context context; -+ krb5_keytab id; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ -+ cleanup(context, data, data->nchoices); -+ id->ops = 0; -+ free(id); -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_get_entry(context, id, principal, kvno, enctype, entry) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_const_principal principal; -+ krb5_kvno kvno; -+ krb5_enctype enctype; -+ krb5_keytab_entry *entry; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_error_code kerror = KRB5_KT_NOTFOUND; -+ int i; -+ -+ for (i = 0; i < data->nchoices; i++) { -+ if ((kerror = krb5_kt_get_entry(context, data->choices[i], principal, -+ kvno, enctype, entry)) != ENOENT) -+ return kerror; -+ } -+ return kerror; -+} -+ -+static krb5_error_code -+krb5_ktany_start_seq_get(context, id, cursorp) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_kt_cursor *cursorp; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata; -+ krb5_error_code kerror = ENOENT; -+ int i; -+ -+ if ((cdata = (krb5_ktany_cursor_data *) -+ malloc(sizeof(krb5_ktany_cursor_data))) == NULL) -+ return(ENOMEM); -+ -+ /* Find a choice which can handle the serialization request. */ -+ for (i = 0; i < data->nchoices; i++) { -+ if ((kerror = krb5_kt_start_seq_get(context, data->choices[i], -+ &cdata->cursor)) == 0) -+ break; -+ else if (kerror != ENOENT) { -+ free(cdata); -+ return(kerror); -+ } -+ } -+ -+ if (i == data->nchoices) { -+ /* Everyone returned ENOENT, so no go. */ -+ free(cdata); -+ return(kerror); -+ } -+ -+ cdata->which = i; -+ *cursorp = (krb5_kt_cursor)cdata; -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_next_entry(context, id, entry, cursor) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_keytab_entry *entry; -+ krb5_kt_cursor *cursor; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata = (krb5_ktany_cursor_data *)*cursor; -+ krb5_keytab choice_id; -+ -+ choice_id = data->choices[cdata->which]; -+ return(krb5_kt_next_entry(context, choice_id, entry, &cdata->cursor)); -+} -+ -+static krb5_error_code -+krb5_ktany_end_seq_get(context, id, cursor) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_kt_cursor *cursor; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata = (krb5_ktany_cursor_data *)*cursor; -+ krb5_keytab choice_id; -+ krb5_error_code kerror; -+ -+ choice_id = data->choices[cdata->which]; -+ kerror = krb5_kt_end_seq_get(context, choice_id, &cdata->cursor); -+ free(cdata); -+ return(kerror); -+} -+ -+static void -+cleanup(context, data, nchoices) -+ krb5_context context; -+ krb5_ktany_data *data; -+ int nchoices; -+{ -+ int i; -+ -+ free(data->name); -+ for (i = 0; i < nchoices; i++) -+ krb5_kt_close(context, data->choices[i]); -+ free(data->choices); -+ free(data); -+} -diff --git a/src/lib/krb5/keytab/ktbase.c b/src/lib/krb5/keytab/ktbase.c -index 0d39b2940..6534d7c52 100644 ---- a/src/lib/krb5/keytab/ktbase.c -+++ b/src/lib/krb5/keytab/ktbase.c -@@ -57,14 +57,19 @@ extern const krb5_kt_ops krb5_ktf_ops; - extern const krb5_kt_ops krb5_ktf_writable_ops; - extern const krb5_kt_ops krb5_kts_ops; - extern const krb5_kt_ops krb5_mkt_ops; -+extern const krb5_kt_ops krb5_kta_ops; - - struct krb5_kt_typelist { - const krb5_kt_ops *ops; - const struct krb5_kt_typelist *next; - }; -+static struct krb5_kt_typelist krb5_kt_typelist_any = { -+ &krb5_kta_ops, -+ NULL -+}; - const static struct krb5_kt_typelist krb5_kt_typelist_srvtab = { - &krb5_kts_ops, -- NULL -+ &krb5_kt_typelist_any - }; - const static struct krb5_kt_typelist krb5_kt_typelist_memory = { - &krb5_mkt_ops, diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch deleted file mode 100644 index 9b0178c..0000000 --- a/krb5-1.13-dirsrv-accountlock.patch +++ /dev/null @@ -1,75 +0,0 @@ -From f2df0b75dfbc9796bf8e1477f4661dfb7cdcf8d4 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:47:44 -0400 -Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch - -Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from -original version filed as RT#5891. ---- - src/aclocal.m4 | 9 +++++++++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c | 3 +++ - 3 files changed, 29 insertions(+) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index f5667c35f..2bfb99496 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -1656,6 +1656,15 @@ if test "$with_ldap" = yes; then - AC_MSG_NOTICE(enabling OpenLDAP database backend module support) - OPENLDAP_PLUGIN=yes - fi -+AC_ARG_WITH([dirsrv-account-locking], -+[ --with-dirsrv-account-locking compile 389/Red Hat/Fedora/Netscape Directory Server database backend module], -+[case "$withval" in -+ yes | no) ;; -+ *) AC_MSG_ERROR(Invalid option value --with-dirsrv-account-locking="$withval") ;; -+esac], with_dirsrv_account_locking=no) -+if test $with_dirsrv_account_locking = yes; then -+ AC_DEFINE(HAVE_DIRSRV_ACCOUNT_LOCKING,1,[Define if LDAP KDB interface should heed 389 DS's nsAccountLock attribute.]) -+fi - ])dnl - dnl - dnl If libkeyutils exists (on Linux) include it and use keyring ccache -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -index 32efc4f54..af8b2db7b 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -@@ -1674,6 +1674,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, - ret = krb5_dbe_update_tl_data(context, entry, &userinfo_tl_data); - if (ret) - goto cleanup; -+#ifdef HAVE_DIRSRV_ACCOUNT_LOCKING -+ { -+ krb5_timestamp expiretime=0; -+ char *is_login_disabled=NULL; -+ -+ /* LOGIN DISABLED */ -+ ret = krb5_ldap_get_string(ld, ent, "nsAccountLock", &is_login_disabled, -+ &attr_present); -+ if (ret) -+ goto cleanup; -+ if (attr_present == TRUE) { -+ if (strcasecmp(is_login_disabled, "TRUE")== 0) -+ entry->attributes |= KRB5_KDB_DISALLOW_ALL_TIX; -+ free (is_login_disabled); -+ } -+ } -+#endif - - ret = krb5_read_tkt_policy(context, ldap_context, entry, tktpolname); - if (ret) -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -index d722dbfa6..5e8e9a897 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -@@ -54,6 +54,9 @@ char *principal_attributes[] = { "krbprincipalname", - "krbLastFailedAuth", - "krbLoginFailedCount", - "krbLastSuccessfulAuth", -+#ifdef HAVE_DIRSRV_ACCOUNT_LOCKING -+ "nsAccountLock", -+#endif - "krbLastPwdChange", - "krbLastAdminUnlock", - "krbPrincipalAuthInd", diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch deleted file mode 100644 index 276c254..0000000 --- a/krb5-1.15-beta1-buildconf.patch +++ /dev/null @@ -1,70 +0,0 @@ -From ae5bb11c0f06fdf92f51d237e94c1d410c59aa04 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:45:26 -0400 -Subject: [PATCH] krb5-1.15-beta1-buildconf.patch - -Build binaries in this package as RELRO PIEs, libraries as partial RELRO, -and install shared libraries with the execute bit set on them. Prune out -the -L/usr/lib* and PIE flags where they might leak out and affect -apps which just want to link with the libraries. FIXME: needs to check and -not just assume that the compiler supports using these flags. ---- - src/build-tools/krb5-config.in | 7 +++++++ - src/config/pre.in | 2 +- - src/config/shlib.conf | 5 +++-- - 3 files changed, 11 insertions(+), 3 deletions(-) - -diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index c17cb5eb5..1891dea99 100755 ---- a/src/build-tools/krb5-config.in -+++ b/src/build-tools/krb5-config.in -@@ -226,6 +226,13 @@ if test -n "$do_libs"; then - -e 's#\$(PTHREAD_CFLAGS)#'"$PTHREAD_CFLAGS"'#' \ - -e 's#\$(CFLAGS)##'` - -+ if test `dirname $libdir` = /usr ; then -+ lib_flags=`echo $lib_flags | sed -e "s#-L$libdir##" -e "s#$RPATH_FLAG$libdir##"` -+ fi -+ lib_flags=`echo $lib_flags | sed -e "s#-fPIE##g" -e "s#-pie##g"` -+ lib_flags=`echo $lib_flags | sed -e "s#-Wl,-z,relro##g"` -+ lib_flags=`echo $lib_flags | sed -e "s#-Wl,-z,now##g"` -+ - if test $library = 'kdb'; then - lib_flags="$lib_flags -lkdb5 $KDB5_DB_LIB" - library=krb5 -diff --git a/src/config/pre.in b/src/config/pre.in -index fcea229bd..d961b5621 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) - INSTALL_SCRIPT=@INSTALL_PROGRAM@ - INSTALL_DATA=@INSTALL_DATA@ - INSTALL_SHLIB=@INSTALL_SHLIB@ --INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root -+INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 - ## This is needed because autoconf will sometimes define @exec_prefix@ to be - ## ${prefix}. - prefix=@prefix@ -diff --git a/src/config/shlib.conf b/src/config/shlib.conf -index 3e4af6c02..2b20c3fda 100644 ---- a/src/config/shlib.conf -+++ b/src/config/shlib.conf -@@ -423,7 +423,7 @@ mips-*-netbsd*) - # Linux ld doesn't default to stuffing the SONAME field... - # Use objdump -x to examine the fields of the library - # UNDEF_CHECK is suppressed by --enable-asan -- LDCOMBINE='$(CC) -shared -fPIC -Wl,-h,$(LIBPREFIX)$(LIBBASE)$(SHLIBSEXT) $(UNDEF_CHECK)' -+ LDCOMBINE='$(CC) -shared -fPIC -Wl,-h,$(LIBPREFIX)$(LIBBASE)$(SHLIBSEXT) $(UNDEF_CHECK) -Wl,-z,relro -Wl,--warn-shared-textrel' - UNDEF_CHECK='-Wl,--no-undefined' - # $(EXPORT_CHECK) runs export-check.pl when in maintainer mode. - LDCOMBINE_TAIL='-Wl,--version-script binutils.versions $(EXPORT_CHECK)' -@@ -435,7 +435,8 @@ mips-*-netbsd*) - SHLIB_EXPFLAGS='$(SHLIB_RPATH_FLAGS) $(SHLIB_DIRS) $(SHLIB_EXPLIBS)' - PROFFLAGS=-pg - PROG_RPATH_FLAGS='$(RPATH_FLAG)$(PROG_RPATH)' -- CC_LINK_SHARED='$(CC) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CFLAGS) $(LDFLAGS)' -+ CC_LINK_SHARED='$(CC) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CFLAGS) -pie -Wl,-z,relro -Wl,-z,now $(LDFLAGS)' -+ INSTALL_SHLIB='${INSTALL} -m755' - CC_LINK_STATIC='$(CC) $(PROG_LIBPATH) $(CFLAGS) $(LDFLAGS)' - CXX_LINK_SHARED='$(CXX) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CXXFLAGS) $(LDFLAGS)' - CXX_LINK_STATIC='$(CXX) $(PROG_LIBPATH) $(CXXFLAGS) $(LDFLAGS)' diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch deleted file mode 100644 index 766226f..0000000 --- a/krb5-1.3.1-dns.patch +++ /dev/null @@ -1,22 +0,0 @@ -From 1b95f8a488d1e70bf7698c8b49412306a1b8aba0 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:46:21 -0400 -Subject: [PATCH] krb5-1.3.1-dns.patch - -We want to be able to use --with-netlib and --enable-dns at the same time. ---- - src/aclocal.m4 | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 607859f17..f5667c35f 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -703,6 +703,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), - LIBS="$LIBS $withval" - AC_MSG_RESULT("netlib will use \'$withval\'") - fi -+ KRB5_AC_ENABLE_DNS - ],dnl - [AC_LIBRARY_NET] - )])dnl diff --git a/krb5-krb5kdc.conf b/krb5-krb5kdc.conf index eadeb51..5160b28 100644 --- a/krb5-krb5kdc.conf +++ b/krb5-krb5kdc.conf @@ -1 +1 @@ -d /var/run/krb5kdc 0755 root root +d /run/krb5kdc 0755 root root diff --git a/krb5-tests b/krb5-tests new file mode 100644 index 0000000..6754f3f --- /dev/null +++ b/krb5-tests @@ -0,0 +1,18 @@ +#!/bin/sh +set -e + +export RPM_PACKAGE_NAME={{ name }} +export RPM_PACKAGE_VERSION={{ version }} +export RPM_PACKAGE_RELEASE={{ release }} +export RPM_ARCH={{ arch }} +export RPM_BUILD_NCPUS="$(getconf _NPROCESSORS_ONLN)" + +testdir="$(mktemp -d)" +trap "rm -rf ${testdir}" EXIT + +build_flags="$(eval "echo $(rpm --eval '%{_smp_mflags}')")" + +mkdir "${testdir}/{{ name }}-tests" +cp -rp /usr/share/{{ name }}-tests/{{ arch }} "${testdir}/{{ name }}-tests/" +make -C "${testdir}/{{ name }}-tests/{{ arch }}/" $build_flags +keyctl session - make -C "${testdir}/{{ name }}-tests/{{ arch }}/" check diff --git a/krb5.conf b/krb5.conf index cf23f53..5e474d1 100644 --- a/krb5.conf +++ b/krb5.conf @@ -3,22 +3,26 @@ includedir /etc/krb5.conf.d/ [logging] - default = FILE:/var/log/krb5libs.log - kdc = FILE:/var/log/krb5kdc.log - admin_server = FILE:/var/log/kadmind.log + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log [libdefaults] - dns_lookup_realm = false - ticket_lifetime = 24h - renew_lifetime = 7d - forwardable = true - rdns = false -# default_realm = EXAMPLE.COM + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt + spake_preauth_groups = edwards25519 + dns_canonicalize_hostname = fallback + qualify_shortname = "" +# default_realm = EXAMPLE.COM [realms] # EXAMPLE.COM = { -# kdc = kerberos.example.com -# admin_server = kerberos.example.com +# kdc = kerberos.example.com +# admin_server = kerberos.example.com # } [domain_realm] diff --git a/krb5.rpmlintrc b/krb5.rpmlintrc new file mode 100644 index 0000000..e1d2f0b --- /dev/null +++ b/krb5.rpmlintrc @@ -0,0 +1,14 @@ +addFilter(r'spelling-error .* en_US (unencrypted)') +addFilter(r'hidden-file-or-dir /usr/share/man/man5/.k5identity.5.gz') +addFilter(r'non-standard-dir-in-var kerberos') +addFilter(r'explicit-lib-dependency libverto-module-base') +addFilter(r'shared-lib-calls-exit') +addFilter(r'dir-or-file-in-var-run /var/run/krb5kdc') +addFilter(r'devel-file-in-non-devel-package /usr/lib64/libkadm5(clnt|srv)_mit.so') +addFilter(r'non-readable /var/kerberos/krb5kdc') +addFilter(r'devel-file-in-non-devel-package /usr/lib64/libkdb_ldap.so') +addFilter(r'/usr/bin/ksu') +addFilter(r'no-documentation') +addFilter(r'invalid-directory-reference .*pkgconfig') +addFilter(r'incoherent-logrotate-file /etc/logrotate.d/k') +addFilter(r'library-not-linked-against-libc') diff --git a/krb5.spec b/krb5.spec index df62457..4c5b542 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,5 +1,3 @@ -%global WITH_DIRSRV 1 - # Set this so that find-lang.sh will recognize the .po files. %global gettext_domain mit-krb5 # Guess where the -libs subpackage's docs are going to go. @@ -8,150 +6,135 @@ %global configure_default_ccache_name 1 %global configured_default_ccache_name KEYRING:persistent:%%{uid} -# leave empty or set to e.g., -beta2 -%global prerelease %{nil} +# Use baserelease to set the release number! +# +# baserelease is what we have standardized across Fedora and what +# rpmdev-bumpspec knows how to handle. +%global baserelease 11 + +# This should be e.g. beta1 or %%nil +%global pre_release %nil + +%global krb5_release %{baserelease} +%if "x%{?pre_release}" != "x" +%global krb5_release 0.%{baserelease}.%{pre_release} +%global krb5_pre_release -%{pre_release} +%endif + +%global krb5_version_major 1 +%global krb5_version_minor 21 +# For a release without a patch number set to %%nil +%global krb5_version_patch 3 + +%global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} +%global krb5_version %{krb5_version_major_minor} +%if "x%{?krb5_version_patch}" != "x" +%global krb5_version %{krb5_version_major_minor}.%{krb5_version_patch} +%endif # Should be in form 5.0, 6.1, etc. -%global kdbversion 6.1 +%global kdbversion 9.0 Summary: The Kerberos network authentication system Name: krb5 -Version: 1.15.2 -# for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 2%{?dist} +Version: %{krb5_version} +Release: %{krb5_release}%{?dist} -# lookaside-cached sources; two downloads and a build artifact -Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in -Source1: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz.asc -# This source is generated during the build because it is documentation. -# To override this behavior (e.g., new upstream version), do: -# tar cfT krb5-1.15.2-pdfs.tar /dev/null -# or the like. This logic persists due to how slow the stranger Fedora -# architecture builders are. 5 minutes on my laptop, 45 on koji easy. -Source3: krb5-%{version}%{prerelease}-pdfs.tar +Source0: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz +Source1: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz.asc -# Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service -Source4: kadmin.service -Source5: krb5kdc.service -Source6: krb5.conf -Source10: kdc.conf -Source11: kadm5.acl -Source19: krb5kdc.sysconfig -Source20: kadmin.sysconfig -Source21: kprop.sysconfig -Source29: ksu.pamd -Source33: krb5kdc.logrotate -Source34: kadmind.logrotate -Source39: krb5-krb5kdc.conf +Source3: kadmin.service +Source4: krb5kdc.service +Source5: krb5.conf +Source6: kdc.conf +Source7: kadm5.acl +Source8: krb5kdc.sysconfig +Source9: kadmin.sysconfig +Source10: kprop.sysconfig +Source11: ksu.pamd +Source12: krb5kdc.logrotate +Source13: kadmind.logrotate +Source14: krb5-krb5kdc.conf +Source15: %{name}-tests -# Carry this locally until it's available in a packaged form. -Source100: noport.c +Patch0001: 0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch +Patch0002: 0002-downstream-ksu-pam-integration.patch +Patch0003: 0003-downstream-SELinux-integration.patch +Patch0004: 0004-downstream-fix-debuginfo-with-y.tab.c.patch +Patch0005: 0005-downstream-Remove-3des-support.patch +Patch0006: 0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch0007: 0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +Patch0008: 0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +Patch0009: 0009-downstream-Include-missing-OpenSSL-FIPS-header.patch +Patch0010: 0010-downstream-Do-not-set-root-as-ksu-file-owner.patch +Patch0011: 0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +Patch0012: 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch +Patch0013: 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch +Patch0014: 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch +Patch0015: 0015-Replace-ssl.wrap_socket-for-tests.patch +Patch0016: 0016-Eliminate-old-style-function-declarations.patch +Patch0017: 0017-Fix-two-unlikely-memory-leaks.patch +Patch0018: 0018-Fix-unimportant-memory-leaks.patch +Patch0019: 0019-Remove-klist-s-defname-global-variable.patch +Patch0020: 0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch +Patch0021: 0021-Add-request_timeout-configuration-parameter.patch +Patch0022: 0022-Wait-indefinitely-on-KDC-TCP-connections.patch +Patch0023: 0023-Remove-PKINIT-RSA-support.patch +Patch0024: 0024-Fix-various-issues-detected-by-static-analysis.patch +Patch0025: 0025-Generate-and-verify-message-MACs-in-libkrad.patch +Patch0026: 0026-PKINIT-ECDH-support.patch +Patch0027: 0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch +Patch0028: 0028-Get-rid-of-pkinit_crypto_openssl.h.patch +Patch0029: 0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch +Patch0030: 0030-Simplify-PKINIT-cert-representation.patch +Patch0031: 0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch +Patch0032: 0032-Improve-PKCS11-error-reporting-in-PKINIT.patch +Patch0033: 0033-Set-missing-mask-flags-for-kdb5_util-operations.patch +Patch0034: 0034-Prevent-overflow-when-calculating-ulog-block-size.patch +Patch0035: 0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch +Patch0036: 0036-downstream-Remove-3des-support-cumulative-1.patch +Patch0037: 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch +Patch0038: 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch +Patch0039: 0039-Fix-strchr-conformance-to-C23.patch +Patch0040: 0040-automated-fast.patch +Patch0041: 0041-bail-if-prompter-is-not-specified-but-required.patch -Patch26: krb5-1.12.1-pam.patch -Patch27: krb5-1.15.1-selinux-label.patch -Patch28: krb5-1.12-ksu-path.patch -Patch29: krb5-1.12-ktany.patch -Patch30: krb5-1.15-beta1-buildconf.patch -Patch31: krb5-1.3.1-dns.patch -Patch32: krb5-1.12-api.patch -Patch33: krb5-1.13-dirsrv-accountlock.patch -Patch34: krb5-1.9-debuginfo.patch -Patch35: krb5-1.11-run_user_0.patch -Patch36: krb5-1.11-kpasswdtest.patch -Patch37: Build-with-Werror-implicit-int-where-supported.patch -Patch38: Add-PKINIT-UPN-tests-to-t_pkinit.py.patch -Patch39: Add-test-case-for-PKINIT-DH-renegotiation.patch -Patch40: Use-expected_trace-in-test-scripts.patch -Patch41: Use-expected_msg-in-test-scripts.patch -Patch42: Use-fallback-realm-for-GSSAPI-ccache-selection.patch -Patch43: Use-GSSAPI-fallback-skiptest.patch -Patch44: Improve-PKINIT-UPN-SAN-matching.patch -Patch45: Add-test-cert-generation-to-make-certs.sh.patch -Patch46: Deindent-crypto_retrieve_X509_sans.patch -Patch47: Add-the-client_name-kdcpreauth-callback.patch -Patch48: Use-the-canonical-client-principal-name-for-OTP.patch -Patch49: Add-certauth-pluggable-interface.patch -Patch50: Correct-error-handling-bug-in-prior-commit.patch -Patch51: Add-k5test-expected_msg-expected_trace.patch -Patch53: Add-support-to-query-the-SSF-of-a-GSS-context.patch -Patch55: Remove-incomplete-PKINIT-OCSP-support.patch -Patch57: Fix-in_clock_skew-and-use-it-in-AS-client-code.patch -Patch58: Add-timestamp-helper-functions.patch -Patch59: Make-timestamp-manipulations-y2038-safe.patch -Patch60: Add-timestamp-tests.patch -Patch61: Add-y2038-documentation.patch -Patch62: Fix-more-time-manipulations-for-y2038.patch -Patch63: Use-krb5_timestamp-where-appropriate.patch -Patch64: Add-KDC-policy-pluggable-interface.patch -Patch65: Fix-bugs-in-kdcpolicy-commit.patch -Patch66: Convert-some-pkiDebug-messages-to-TRACE-macros.patch -Patch67: Fix-certauth-built-in-module-returns.patch -Patch68: Add-test-cert-with-no-extensions.patch -Patch69: Add-PKINIT-test-case-for-generic-client-cert.patch -Patch70: Add-hostname-based-ccselect-module.patch -Patch71: Add-German-translation.patch - -License: MIT -URL: http://web.mit.edu/kerberos/www/ -Group: System Environment/Libraries -BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) -BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed +License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision +URL: https://web.mit.edu/kerberos/www/ +BuildRequires: autoconf, bison, make, flex, gawk, gettext, pkgconfig, sed +BuildRequires: gcc, gcc-c++ BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel -BuildRequires: python2-sphinx, texlive-pdftex, latexmk - -# For autosetup -BuildRequires: git - -# Originally from \usepackage directives produced by sphinx: -BuildRequires: tex(babel.sty) -BuildRequires: tex(bookmark.sty) -BuildRequires: tex(capt-of.sty) -BuildRequires: tex(eqparbox.sty) -BuildRequires: tex(fancybox.sty) -BuildRequires: tex(fncychap.sty) -BuildRequires: tex(fontenc.sty) -BuildRequires: tex(framed.sty) -BuildRequires: tex(hyperref.sty) -BuildRequires: tex(ifthen.sty) -BuildRequires: tex(inputenc.sty) -BuildRequires: tex(longtable.sty) -BuildRequires: tex(multirow.sty) -BuildRequires: tex(needspace.sty) -BuildRequires: tex(report.cls) -BuildRequires: tex(tabulary.sty) -BuildRequires: tex(threeparttable.sty) -BuildRequires: tex(times.sty) -BuildRequires: tex(titlesec.sty) -BuildRequires: tex(upquote.sty) -BuildRequires: tex(wrapfig.sty) - -# Typical fonts, and the commands which we need to have present. -BuildRequires: texlive, texlive-latex, texlive-texmf-fonts -BuildRequires: /usr/bin/pdflatex /usr/bin/makeindex +BuildRequires: python3, python3-sphinx BuildRequires: keyutils, keyutils-libs-devel >= 1.5.8 BuildRequires: libselinux-devel BuildRequires: pam-devel BuildRequires: systemd-units - -# For the test framework. -BuildRequires: perl-interpreter, dejagnu, tcl-devel -BuildRequires: net-tools, rpcbind -BuildRequires: hostname -BuildRequires: iproute -BuildRequires: python2-pyrad +BuildRequires: tcl-devel BuildRequires: libverto-devel BuildRequires: openldap-devel -BuildRequires: openssl-devel >= 0.9.8 +BuildRequires: lmdb-devel +BuildRequires: perl-interpreter -%ifarch %{ix86} x86_64 -BuildRequires: yasm +# For autosetup +BuildRequires: git + +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 +# Need KDFs. This is the "real" version +BuildRequires: openssl-devel >= 1:3.0.0 +%else +# Need KDFs. This is the backported version +BuildRequires: openssl-devel >= 1:1.1.1d-4 +BuildRequires: openssl-devel < 1:3.0.0 %endif -BuildRequires: nss_wrapper -BuildRequires: socket_wrapper +# Enable compilation of optional tests +BuildRequires: resolv_wrapper +BuildRequires: libcmocka-devel +BuildRequires: opensc +BuildRequires: softhsm %description Kerberos V5 is a trusted-third-party network authentication system, @@ -160,13 +143,14 @@ practice of sending passwords over the network in unencrypted form. %package devel Summary: Development files needed to compile Kerberos 5 programs -Group: Development/Libraries Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} Requires: libcom_err-devel Requires: keyutils-libs-devel, libselinux-devel Requires: libverto-devel -Provides: krb5-kdb-version = %{kdbversion} +Provides: krb5-kdb-devel-version = %{kdbversion} +# IPA wants ^ to be a separate symbol because they don't trust package +# managers to match -server and -devel in version. Just go with it. %description devel Kerberos is a network authentication system. The krb5-devel package @@ -176,8 +160,13 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 -Group: System Environment/Libraries -Requires: coreutils, gawk, grep, sed +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 +Requires: openssl-libs >= 1:3.0.0 +%else +Requires: openssl-libs >= 1:1.1.1d-4 +Requires: openssl-libs < 1:3.0.0 +%endif +Requires: coreutils Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -187,29 +176,21 @@ contains the shared libraries needed by Kerberos 5. If you are using Kerberos, you need to install this package. %package server -Group: System Environment/Daemons Summary: The KDC and related programs for Kerberos 5 Requires: %{name}-libs%{?_isa} = %{version}-%{release} +Requires: %{name}-pkinit%{?_isa} = %{version}-%{release} Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units # we drop files in its directory, but we don't want to own that directory Requires: logrotate -# we specify /usr/share/dict/words as the default dict_file in kdc.conf -Requires: /usr/share/dict/words +# we specify /usr/share/dict/words (provided by words) as the default dict_file in kdc.conf +Requires: words # for run-time, and for parts of the test suite BuildRequires: libverto-module-base Requires: libverto-module-base -%ifarch x86_64 -Obsoletes: %{name}-server-%{version}-%{release}.i686 -%endif -%ifarch ppc64 -Obsoletes: %{name}-server-%{version}-%{release}.ppc -%endif -%ifarch s390x -Obsoletes: %{name}-server-%{version}-%{release}.s390 -%endif Requires: libkadm5%{?_isa} = %{version}-%{release} +Provides: krb5-kdb-version = %{kdbversion} %description server Kerberos is a network authentication system. The krb5-server package @@ -219,20 +200,10 @@ you need to install this package (in other words, most people should NOT install this package). %package server-ldap -Group: System Environment/Daemons Summary: The LDAP storage plugin for the Kerberos 5 KDC Requires: %{name}-server%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} -%ifarch x86_64 -Obsoletes: %{name}-server-ldap-%{version}-%{release}.i686 -%endif -%ifarch ppc64 -Obsoletes: %{name}-server-ldap-%{version}-%{release}.ppc -%endif -%ifarch s390x -Obsoletes: %{name}-server-ldap-%{version}-%{release}.s390 -%endif %description server-ldap Kerberos is a network authentication system. The krb5-server package @@ -243,8 +214,8 @@ realm, you need to install this package. %package workstation Summary: Kerberos 5 programs for use on workstations -Group: System Environment/Base Requires: %{name}-libs%{?_isa} = %{version}-%{release} +Requires: %{name}-pkinit%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} %description workstation @@ -255,7 +226,6 @@ installed on every workstation. %package pkinit Summary: The PKINIT module for Kerberos 5 -Group: System Environment/Libraries Requires: %{name}-libs%{?_isa} = %{version}-%{release} Obsoletes: krb5-pkinit-openssl < %{version}-%{release} Provides: krb5-pkinit-openssl = %{version}-%{release} @@ -268,7 +238,6 @@ certificate. %package -n libkadm5 Summary: Kerberos 5 Administrative libraries -Group: System Environment/Base Requires: %{name}-libs%{?_isa} = %{version}-%{release} %description -n libkadm5 @@ -276,12 +245,58 @@ Kerberos is a network authentication system. The libkadm5 package contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. -%prep -%autosetup -S git -n %{name}-%{version}%{prerelease} -a 3 -ln NOTICE LICENSE +%package tests +Summary: Test sources for krb5 build -# Take the execute bit off of documentation. -chmod -x doc/ccapi/*.html +# Build dependencies +Requires: coreutils, gawk, sed +Requires: gcc-c++ +Requires: gettext +Requires: libcom_err-devel +Requires: libselinux-devel +Requires: libss-devel +Requires: libverto-devel +Requires: lmdb-devel +Requires: openldap-devel +Requires: pam-devel +Requires: redhat-rpm-config +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 +Requires: openssl-devel >= 1:3.0.0 +%else +Requires: openssl-devel >= 1:1.1.1d-4 +Requires: openssl-devel < 1:3.0.0 +%endif + +# Test dependencies +Requires: dejagnu +Requires: hostname +Requires: iproute +Requires: keyutils, keyutils-libs-devel >= 1.5.8 +Requires: libcmocka-devel +Requires: libverto-module-base +Requires: logrotate +Requires: net-tools, rpcbind +Requires: perl-interpreter +Requires: procps-ng +Requires: python3-kdcproxy +Requires: resolv_wrapper +Requires: /etc/crypto-policies/back-ends/krb5.config +Requires: words +Requires: opensc +Requires: softhsm +Recommends: python3-pyrad + +# Restore once openldap upstream tests are fixed +#Recommends: openldap-servers +#Recommends: openldap-clients + +%description tests +FOR TESTING PURPOSE ONLY +Test sources for krb5 build, with pre-defined compilation parameters + +%prep +%autosetup -S git_am -n %{name}-%{version}%{?dashpre} +ln NOTICE LICENSE # Generate an FDS-compatible LDIF file. inldif=src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif @@ -289,9 +304,7 @@ cat > '60kerberos.ldif' << EOF # This is a variation on kerberos.ldif which 389 Directory Server will like. dn: cn=schema EOF -egrep -iv '(^$|^dn:|^changetype:|^add:)' $inldif | \ -sed -r 's,^ , ,g' | \ -sed -r 's,^ , ,g' >> 60kerberos.ldif +grep -Eiv '(^$|^dn:|^changetype:|^add:)' $inldif >> 60kerberos.ldif touch -r $inldif 60kerberos.ldif # Rebuild the configure scripts. @@ -301,10 +314,7 @@ popd # Mess with some of the default ports that we use for testing, so that multiple # builds going on the same host don't step on each other. -cfg="src/kadmin/testing/proto/kdc.conf.proto \ - src/kadmin/testing/proto/krb5.conf.proto \ - src/lib/kadm5/unit-test/api.current/init-v2.exp \ - src/util/k5test.py" +cfg="src/util/k5test.py" LONG_BIT=`getconf LONG_BIT` PORT=`expr 61000 + $LONG_BIT - 48` sed -i -e s,61000,`expr "$PORT" + 0`,g $cfg @@ -320,108 +330,94 @@ PORT=`expr 7777 + $LONG_BIT - 48` sed -i -e s,7777,`expr "$PORT" + 0`,g $cfg sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg +# Fix kadmind port hard-coded in tests +PORT=`expr 61000 + $LONG_BIT - 48` +sed -i -e \ + "s,params.kadmind_port = 61001;,params.kadmind_port = $((PORT + 1));," \ + src/lib/kadm5/t_kadm5.c + + %build # Go ahead and supply tcl info, because configure doesn't know how to find it. source %{_libdir}/tclConfig.sh pushd src -# Set this so that configure will have a value even if the current version of -# autoconf doesn't set one. -export runstatedir=%{_localstatedir}/run +# This should be safe to remove once we have autoconf >= 2.70 +export runstatedir=/run + # Work out the CFLAGS and CPPFLAGS which we intend to use. INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" CPPFLAGS="`echo $DEFINES $INCLUDES`" %configure \ - CC="%{__cc}" \ - CFLAGS="$CFLAGS" \ - CPPFLAGS="$CPPFLAGS" \ - SS_LIB="-lss" \ - --enable-shared \ - --localstatedir=%{_var}/kerberos \ - --disable-rpath \ - --without-krb5-config \ - --with-system-et \ - --with-system-ss \ - --with-netlib=-lresolv \ - --with-tcl \ - --enable-dns-for-realm \ - --with-ldap \ -%if %{WITH_DIRSRV} - --with-dirsrv-account-locking \ -%endif - --enable-pkinit \ - --with-pkinit-crypto-impl=openssl \ - --with-tls-impl=openssl \ - --with-system-verto \ - --with-pam \ - --with-selinux \ - --with-prng-alg=os -# Now build it. -make -popd + CC="%{__cc}" \ + CFLAGS="$CFLAGS" \ + CPPFLAGS="$CPPFLAGS" \ + SS_LIB="-lss" \ + PKCS11_MODNAME="p11-kit-proxy.so" \ + --enable-shared \ + --runstatedir=/run \ + --localstatedir=%{_var}/kerberos \ + --disable-rpath \ + --without-krb5-config \ + --with-system-et \ + --with-system-ss \ + --with-tcl \ + --enable-dns-for-realm \ + --with-ldap \ + --with-dirsrv-account-locking \ + --enable-pkinit \ + --with-crypto-impl=openssl \ + --with-tls-impl=openssl \ + --with-system-verto \ + --with-pam \ + --with-selinux \ + --with-prng-alg=os \ + --with-lmdb \ + || (cat config.log; exit 1) + +# Check we have required features enabled +for x in DNS_LOOKUP DNS_LOOKUP_REALM; do + grep -q "#define KRB5_${x} 1" include/autoconf.h +done # Sanity check the KDC_RUN_DIR. -configured_kdcrundir=`grep KDC_RUN_DIR src/include/osconf.h | awk '{print $NF}'` -configured_kdcrundir=`eval echo $configured_kdcrundir` -if test "$configured_kdcrundir" != %{_localstatedir}/run/krb5kdc ; then - exit 1 +pushd include +make osconf.h +popd +configured_dir=`grep KDC_RUN_DIR include/osconf.h | awk '{print $NF}'` +configured_dir=`eval echo $configured_dir` +if test "$configured_dir" != /run/krb5kdc ; then + echo Failed to configure KDC_RUN_DIR. + exit 1 fi +# Build fast, but get better errors if we fail +make %{?_smp_mflags} || make -j1 +popd + # Build the docs. make -C src/doc paths.py version.py cp src/doc/paths.py doc/ -mkdir -p build-man build-html build-pdf +mkdir -p build-man build-html sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources -sphinx-build -a -b latex -t pathsubs doc build-pdf -# Build the PDFs if we didn't have pre-built ones. -for pdf in admin appdev basic build plugindev user ; do - test -s build-pdf/$pdf.pdf || make -C build-pdf -done -# new krb5-%{version}-pdf -tar -cf "krb5-%{version}-pdfs.tar.new" build-pdf/*.pdf - -# We need to cut off any access to locally-running nameservers, too. -%{__cc} -fPIC -shared -o noport.so -Wall -Wextra $RPM_SOURCE_DIR/noport.c - -%check -mkdir nss_wrapper - -# Set things up to use the test wrappers. -export NSS_WRAPPER_HOSTNAME=test.example.com -export NSS_WRAPPER_HOSTS="$PWD/nss_wrapper/fakehosts" -echo "127.0.0.1 $NSS_WRAPPER_HOSTNAME localhost" > $NSS_WRAPPER_HOSTS -export NOPORT='53,111' -export SOCKET_WRAPPER_DIR="$PWD/sockets" ; mkdir -p $SOCKET_WRAPPER_DIR -export LD_PRELOAD="$PWD/noport.so:libnss_wrapper.so:libsocket_wrapper.so" - -# Run the test suite. We can't actually run the whole thing in the build -# system, but we can at least run more than we used to. The build system may -# give us a revoked session keyring, so run affected tests with a new one. -make -C src runenv.py -: make -C src check TMPDIR=%{_tmppath} -keyctl session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes -make -C src/kdc check TMPDIR=%{_tmppath} -keyctl session - make -C src/appl check TMPDIR=%{_tmppath} -make -C src/clients check TMPDIR=%{_tmppath} -keyctl session - make -C src/util check TMPDIR=%{_tmppath} %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" # Sample KDC config files (bundled kdc.conf and kadm5.acl). mkdir -p $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc -install -pm 600 %{SOURCE10} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ -install -pm 600 %{SOURCE11} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ +install -pm 600 %{SOURCE6} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ +install -pm 600 %{SOURCE7} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ # Where per-user keytabs live by default. mkdir -p $RPM_BUILD_ROOT%{_var}/kerberos/krb5/user # Default configuration file for everything. mkdir -p $RPM_BUILD_ROOT/etc -install -pm 644 %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf +install -pm 644 %{SOURCE5} $RPM_BUILD_ROOT/etc/krb5.conf # Default include on this directory mkdir -p $RPM_BUILD_ROOT/etc/krb5.conf.d @@ -440,51 +436,47 @@ mkdir -m 755 -p $RPM_BUILD_ROOT/etc/gss/mech.d %if 0%{?configure_default_ccache_name} export DEFCCNAME="%{configured_default_ccache_name}" awk '{print} - /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ - %{SOURCE6} > $RPM_BUILD_ROOT/etc/krb5.conf -touch -r %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf + /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ + %{SOURCE5} > $RPM_BUILD_ROOT/etc/krb5.conf +touch -r %{SOURCE5} $RPM_BUILD_ROOT/etc/krb5.conf grep default_ccache_name $RPM_BUILD_ROOT/etc/krb5.conf %endif # Server init scripts (krb5kdc,kadmind,kpropd) and their sysconfig files. mkdir -p $RPM_BUILD_ROOT%{_unitdir} for unit in \ - %{SOURCE5}\ - %{SOURCE4} \ - %{SOURCE2} ; do - # In the past, the init script was supposed to be named after the - # service that the started daemon provided. Changing their names - # is an upgrade-time problem I'm in no hurry to deal with. - install -pm 644 ${unit} $RPM_BUILD_ROOT%{_unitdir} + %{SOURCE4}\ + %{SOURCE3} \ + %{SOURCE2} ; do + # In the past, the init script was supposed to be named after the service + # that the started daemon provided. Changing their names is an + # upgrade-time problem I'm in no hurry to deal with. + install -pm 644 ${unit} $RPM_BUILD_ROOT%{_unitdir} done mkdir -p $RPM_BUILD_ROOT/%{_tmpfilesdir} -install -pm 644 %{SOURCE39} $RPM_BUILD_ROOT/%{_tmpfilesdir}/ +install -pm 644 %{SOURCE14} $RPM_BUILD_ROOT/%{_tmpfilesdir}/ mkdir -p $RPM_BUILD_ROOT/%{_localstatedir}/run/krb5kdc mkdir -p $RPM_BUILD_ROOT/etc/sysconfig -for sysconfig in \ - %{SOURCE19}\ - %{SOURCE20}\ - %{SOURCE21} ; do - install -pm 644 ${sysconfig} \ - $RPM_BUILD_ROOT/etc/sysconfig/`basename ${sysconfig} .sysconfig` +for sysconfig in %{SOURCE8} %{SOURCE9} %{SOURCE10} ; do + install -pm 644 ${sysconfig} \ + $RPM_BUILD_ROOT/etc/sysconfig/`basename ${sysconfig} .sysconfig` done # logrotate configuration files mkdir -p $RPM_BUILD_ROOT/etc/logrotate.d/ for logrotate in \ - %{SOURCE33} \ - %{SOURCE34} ; do - install -pm 644 ${logrotate} \ - $RPM_BUILD_ROOT/etc/logrotate.d/`basename ${logrotate} .logrotate` + %{SOURCE12} \ + %{SOURCE13} ; do + install -pm 644 ${logrotate} \ + $RPM_BUILD_ROOT/etc/logrotate.d/`basename ${logrotate} .logrotate` done # PAM configuration files. mkdir -p $RPM_BUILD_ROOT/etc/pam.d/ -for pam in \ - %{SOURCE29} ; do - install -pm 644 ${pam} \ - $RPM_BUILD_ROOT/etc/pam.d/`basename ${pam} .pamd` +for pam in %{SOURCE11} ; do + install -pm 644 ${pam} \ + $RPM_BUILD_ROOT/etc/pam.d/`basename ${pam} .pamd` done # Plug-in directories. @@ -493,31 +485,32 @@ install -pdm 755 $RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/kdb install -pdm 755 $RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/authdata # The rest of the binaries, headers, libraries, and docs. -make -C src DESTDIR=$RPM_BUILD_ROOT EXAMPLEDIR=%{libsdocdir}/examples install +%make_install -C src EXAMPLEDIR=%{libsdocdir}/examples # Munge krb5-config yet again. This is totally wrong for 64-bit, but chunks # of the buildconf patch already conspire to strip out /usr/ from the # list of link flags, and it helps prevent file conflicts on multilib systems. sed -r -i -e 's|^libdir=/usr/lib(64)?$|libdir=/usr/lib|g' $RPM_BUILD_ROOT%{_bindir}/krb5-config -# Temporay workaround for krb5-config reading too much from LDFLAGS. -# Upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8159 -sed -r -i -e "s/-specs=\/.+?\/redhat-hardened-ld//g" $RPM_BUILD_ROOT%{_bindir}/krb5-config - -if [[ "$(< $RPM_BUILD_ROOT%{_bindir}/krb5-config )" == *redhat-hardened-ld* ]] ; then - printf '# redhat-hardened-ld for krb5-config failed' 1>&2 - exit 1 -fi +# Workaround krb5-config reading too much from LDFLAGS. +# https://bugzilla.redhat.com/show_bug.cgi?id=1997021 +# https://bugzilla.redhat.com/show_bug.cgi?id=2048909 +sed -i -r -e 's/^(LDFLAGS=).*/\1/' $RPM_BUILD_ROOT%{_bindir}/krb5-config # Install processed man pages. for section in 1 5 8 ; do - install -m 644 build-man/*.${section} \ - $RPM_BUILD_ROOT/%{_mandir}/man${section}/ + install -m 644 build-man/*.${section} \ + $RPM_BUILD_ROOT/%{_mandir}/man${section}/ done -# This script just tells you to send bug reports to krb5-bugs@mit.edu, but -# since we don't have a man page for it, just drop it. +# I'm tired of warnings about these not having man pages rm -- "$RPM_BUILD_ROOT/%{_sbindir}/krb5-send-pr" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/sim_server" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/gss-server" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/uuserver" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/sim_client" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/gss-client" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/uuclient" # These files are already packaged elsewhere rm -- "$RPM_BUILD_ROOT/%{_docdir}/krb5-libs/examples/kdc.conf" @@ -527,24 +520,46 @@ rm -- "$RPM_BUILD_ROOT/%{_docdir}/krb5-libs/examples/services.append" # This is only needed for tests rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" +# Generate tests launching script +sed -e 's/{{ name }}/%{name}/g' \ + -e 's/{{ version }}/%{krb5_version}/g' \ + -e 's/{{ release }}/%{krb5_release}/g' \ + -e 's/{{ arch }}/%{_arch}/g' \ + -i %{SOURCE15} +mkdir -p $RPM_BUILD_ROOT%{_libexecdir} +install -pm 755 %{SOURCE15} $RPM_BUILD_ROOT%{_libexecdir}/%{name}-tests-%{_arch} + +# Copy source files from build folder to system data folder +install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch} +pushd src +cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" \ + $(find . -type f -exec file -i "{}" + \ + | sed -n \ + -e 's|^\./\([^:]\+\): \+text/.\+$|\1|p' \ + -e 's|^\./\([^:]\+\): \+application/x-pem-file.\+$|\1|p' \ + -e 's|^\./\([^:]\+\): \+application/json.\+$|\1|p' \ + | grep -Ev '~$') +popd + +# Copy binary test files +install -pm 644 src/tests/pkinit-certs/*.p12 \ + "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/tests/pkinit-certs/" + +# Unset executable bit if no shebang in script +for f in $(find "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" -type f -executable) +do + head -n1 "$f" | grep -Eq '^#!' || chmod a-x "$f" +done + +# Remove broken shebang Perl scripts +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/config/wconfig.pl" +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/kadmin/kdbkeys/do-test.pl" + %find_lang %{gettext_domain} -%clean -[ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" +%ldconfig_scriptlets libs -%post libs -p /sbin/ldconfig - -%triggerun libs -- krb5-libs < 1.15.1-5 -if ! grep -q 'includedir /etc/krb5.conf.d' /etc/krb5.conf ; then - sed -i '1i # To opt out of the system crypto-policies configuration of krb5, remove the\n# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.\nincludedir /etc/krb5.conf.d/\n' /etc/krb5.conf -fi -exit 0 - -%postun libs -p /sbin/ldconfig - -%post server-ldap -p /sbin/ldconfig - -%postun server-ldap -p /sbin/ldconfig +%ldconfig_scriptlets server-ldap %post server %systemd_post krb5kdc.service kadmin.service kprop.service @@ -560,16 +575,12 @@ exit 0 %systemd_postun_with_restart krb5kdc.service kadmin.service kprop.service exit 0 -%post -n libkadm5 -p /sbin/ldconfig - -%postun -n libkadm5 -p /sbin/ldconfig +%ldconfig_scriptlets -n libkadm5 %files workstation -%defattr(-,root,root,-) %doc src/config-files/services.append %doc src/config-files/krb5.conf %doc build-html/* -%doc build-pdf/user.pdf build-pdf/basic.pdf %attr(0755,root,root) %doc src/config-files/convert-config-files # Clients of the KDC, including tools you're likely to need if you're running @@ -600,9 +611,7 @@ exit 0 %config(noreplace) /etc/pam.d/ksu %files server -%defattr(-,root,root,-) %docdir %{_mandir} -%doc build-pdf/admin.pdf build-pdf/build.pdf %doc src/config-files/kdc.conf %{_unitdir}/krb5kdc.service %{_unitdir}/kadmin.service @@ -627,6 +636,7 @@ exit 0 %dir %{_libdir}/krb5/plugins/authdata %{_libdir}/krb5/plugins/preauth/otp.so %{_libdir}/krb5/plugins/kdb/db2.so +%{_libdir}/krb5/plugins/kdb/klmdb.so # KDC binaries and configuration. %{_mandir}/man5/kadm5.acl.5* @@ -654,7 +664,6 @@ exit 0 %{_mandir}/man8/sserver.8* %files server-ldap -%defattr(-,root,root,-) %docdir %{_mandir} %doc src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif %doc src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema @@ -669,7 +678,6 @@ exit 0 %{_sbindir}/kdb5_ldap_util %files libs -f %{gettext_domain}.lang -%defattr(-,root,root,-) %doc README NOTICE %{!?_licensedir:%global license %%doc} %license LICENSE @@ -679,12 +687,13 @@ exit 0 %dir /etc/gss/mech.d %dir /etc/krb5.conf.d %config(noreplace) /etc/krb5.conf -%config(noreplace) /etc/krb5.conf.d/crypto-policies +%config(noreplace,missingok) /etc/krb5.conf.d/crypto-policies /%{_mandir}/man5/.k5identity.5* /%{_mandir}/man5/.k5login.5* /%{_mandir}/man5/k5identity.5* /%{_mandir}/man5/k5login.5* /%{_mandir}/man5/krb5.conf.5* +/%{_mandir}/man7/kerberos.7* %{_libdir}/libgssapi_krb5.so.* %{_libdir}/libgssrpc.so.* %{_libdir}/libk5crypto.so.* @@ -696,21 +705,19 @@ exit 0 %dir %{_libdir}/krb5/plugins %dir %{_libdir}/krb5/plugins/* %{_libdir}/krb5/plugins/tls/k5tls.so +%{_libdir}/krb5/plugins/preauth/spake.so %dir %{_var}/kerberos %dir %{_var}/kerberos/krb5 %dir %{_var}/kerberos/krb5/user %files pkinit -%defattr(-,root,root,-) %dir %{_libdir}/krb5 %dir %{_libdir}/krb5/plugins %dir %{_libdir}/krb5/plugins/preauth %{_libdir}/krb5/plugins/preauth/pkinit.so %files devel -%defattr(-,root,root,-) %docdir %{_mandir} -%doc build-pdf/appdev.pdf build-pdf/plugindev.pdf %{_includedir}/* %{_libdir}/libgssapi_krb5.so @@ -725,18 +732,7 @@ exit 0 %{_bindir}/krb5-config %{_mandir}/man1/krb5-config.1* -# Protocol test clients. -%{_bindir}/sim_client -%{_bindir}/gss-client -%{_bindir}/uuclient - -# Protocol test servers. -%{_sbindir}/sim_server -%{_sbindir}/gss-server -%{_sbindir}/uuserver - %files -n libkadm5 -%defattr(-,root,root,-) %{_libdir}/libkadm5clnt.so %{_libdir}/libkadm5clnt_mit.so %{_libdir}/libkadm5srv.so @@ -744,7 +740,893 @@ exit 0 %{_libdir}/libkadm5clnt_mit.so.* %{_libdir}/libkadm5srv_mit.so.* +%files tests +%{_libexecdir}/%{name}-tests-%{_arch} +%{_datarootdir}/%{name}-tests/%{_arch} + %changelog +* Mon Jan 05 2026 Julien Rische - 1.21.3-11 +- Fix strchr() conformance to C23 + +* Mon Oct 20 2025 Alexander Bokovoy - 1.21.3-10 +- Update the prompter patch to upstream version + Resolves: rhbz#2403513 + +* Wed Oct 15 2025 Alexander Bokovoy - 1.21.3-9 +- do not crash when prompter is not available in GSSAPI + Resolves: rhbz#2403513 + +* Fri Sep 26 2025 Alexander Bokovoy - 1.21.3-8 +- Add automated FAST channel for kinit +- https://github.com/krb5/krb5/pull/1447 - work in progress + +* Thu Jul 24 2025 Fedora Release Engineering - 1.21.3-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Wed Jun 04 2025 Julien Rische - 1.21.3-6 +- Do not block HMAC-MD4/5 in FIPS mode + Resolves: rhbz#2370259 +- PKINIT: implement paChecksum2 from MS-PKCA v20230920 + Resolves: rhbz#2357215 +- Disallow RC4 HMAC-MD5 session keys by default (CVE-2025-3576) + Resolves: rhbz#2359705 + +* Wed Jan 29 2025 Julien Rische - 1.21.3-5 +- Prevent overflow when calculating ulog block size (CVE-2025-24528) + Resolves: rhbz#2342798 +- Support PKCS11 EC client certs in PKINIT + Resolves: rhbz#2341962 +- kdb5_util: fix DB entry flags on modification + Resolves: rhbz#2336555 +- Add ECDH support for PKINIT (RFC5349) + Resolves: rhbz#2214326 +- Remove dependency of krb5-libs on gawk and sed + Resolves: rhbz#2323859 + +* Fri Jan 17 2025 Fedora Release Engineering - 1.21.3-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Wed Oct 30 2024 Julien Rische - 1.21.3-3 +- libkrad: implement support for Message-Authenticator (CVE-2024-3596) + Resolves: rhbz#2304071 +- Fix various issues detected by static analysis + Resolves: rhbz#2322704 +- Remove RSA protocol for PKINIT + Resolves: rhbz#2322706 +- Make TCP waiting time configurable + Resolves: rhbz#2322711 + +* Thu Jul 18 2024 Fedora Release Engineering - 1.21.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Tue Jul 09 2024 Julien Rische - 1.21.3-1 +- New upstream version (1.21.3) +- CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c + Resolves: rhbz#2266732 +- CVE-2024-26461: Memory leak in src/lib/gssapi/krb5/k5sealv3.c + Resolves: rhbz#2266741 +- CVE-2024-26462: Memory leak in src/kdc/ndr.c + Resolves: rhbz#2266743 +- Add missing SPDX license identifiers + Resolves: rhbz#2265333 + +* Mon Jul 08 2024 Julien Rische - 1.21.2-6 +- CVE-2024-37370 CVE-2024-37371: GSS message token handling + Resolves: rhbz#2294678 rhbz#2294680 +- Fix double free in klist's show_ccache() + Resolves: rhbz#2257301 +- Do not include files with "~" termination in krb5-tests + +* Thu Jan 25 2024 Fedora Release Engineering - 1.21.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 1.21.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Wed Jan 17 2024 Julien Rische - 1.21.2-3 +- Fix double free in klist's show_ccache() + Resolves: rhbz#2257301 +- Store krb5-tests files in architecture-specific directories + Resolves: rhbz#2244601 + +* Tue Oct 10 2023 Julien Rische - 1.21.2-2 +- Use SPDX expression for license tag +- Fix unimportant memory leaks + Resolves: rhbz#2223274 + +* Wed Aug 16 2023 Julien Rische - 1.21.2-1 +- New upstream version (1.21.2) +- Fix double-free in KDC TGS processing (CVE-2023-39975) + Resolves: rhbz#2229113 +- Make tests compatible with Python 3.12 + Resolves: rhbz#2224013 + +* Thu Jul 20 2023 Fedora Release Engineering - 1.21-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Jun 29 2023 Marek Blaha - 1.21-2 +- Replace file dependency with package name + Resolves: rhbz#2216903 + +* Mon Jun 12 2023 Julien Rische - 1.21-1 +- New upstream version (1.21) +- Do not disable PKINIT if some of the well-known DH groups are unavailable + Resolves: rhbz#2214297 +- Make PKINIT CMS SHA-1 signature verification available in FIPS mode + Resolves: rhbz#2214300 +- Allow to set PAC ticket signature as optional + Resolves: rhbz#2181311 +- Add support for MS-PAC extended KDC signature (CVE-2022-37967) + Resolves: rhbz#2166001 +- Fix syntax error in aclocal.m4 + Resolves: rhbz#2143306 + +* Tue Jan 31 2023 Julien Rische - 1.20.1-9 +- Add support for MS-PAC extended KDC signature (CVE-2022-37967) + Resolves: rhbz#2166001 + +* Mon Jan 30 2023 Julien Rische - 1.20.1-8 +- Bypass FIPS restrictions to use KRB5KDF in case AES SHA-1 HMAC is enabled +- Lazily load MD4/5 from OpenSSL if using RADIUS or RC4 enctype in FIPS mode + +* Thu Jan 19 2023 Fedora Release Engineering - 1.20.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Wed Jan 18 2023 Julien Rische - 1.20.1-6 +- Set aes256-cts-hmac-sha384-192 as EXAMLE.COM master key in kdc.conf +- Add AES SHA-2 HMAC family as EXAMPLE.COM supported etypes in kdc.conf + Resolves: rhbz#2114771 + +* Mon Jan 09 2023 Julien Rische - 1.20.1-5 +- Strip debugging data from ksu executable file + +* Thu Jan 05 2023 Julien Rische - 1.20.1-4 +- Include missing OpenSSL FIPS header +- Make tests compatible with sssd_krb5_locator_plugin.so + +* Tue Dec 06 2022 Julien Rische - 1.20.1-3 +- Enable TMT integration with Fedora CI + +* Thu Dec 1 2022 Alexander Bokovoy - 1.20.1-2 +- Bump KDB ABI version provide to 9.0 + +* Wed Nov 23 2022 Julien Rische - 1.20.1-1 +- New upstream version (1.20.1) + Resolves: rhbz#2124463 +- Restore "supportedCMSTypes" attribute in PKINIT preauth requests +- Set SHA-512 or SHA-256 with RSA as preferred CMS signature algorithms + Resolves: rhbz#2114766 +- Update error checking for OpenSSL CMS_verify + Resolves: rhbz#2119704 +- Remove invalid password expiry warning + Resolves: rhbz#2129113 + +* Wed Nov 09 2022 Julien Rische - 1.19.2-13 +- Fix integer overflows in PAC parsing (CVE-2022-42898) + Resolves: rhbz#2143011 + +* Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 +- Use baserelease to set the release number +- Do not define netlib, but use autoconf detection for res_* functions +- Add missing BR for resolv_wrapper to run t_discover_uri.py + +* Thu Jul 21 2022 Fedora Release Engineering - 1.19.2-11.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Wed Jun 15 2022 Julien Rische - 1.19.2-11 +- Allow libkrad UDP/TCP connection to localhost in FIPS mode + Resolves: rhbz#2082189 +- Read GSS configuration files with mtime 0 + +* Mon May 2 2022 Julien Rische - 1.19.2-10 +- Use p11-kit as default PKCS11 module + Resolves: rhbz#2073274 +- Try harder to avoid password change replay errors + Resolves: rhbz#2072059 + +* Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-9 +- Fix libkrad client cleanup +- Fixes rhbz#2072059 + +* Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-8 +- Allow use of larger RADIUS attributes in krad library + +* Wed Mar 23 2022 Julien Rische - 1.19.2-7 +- Use SHA-256 instead of SHA-1 for PKINIT CMS digest + +* Tue Feb 8 2022 Zbigniew Jędrzejewski-Szmek - 1.19.2-6 +- Drop old trigger scriplet +- Reenable package notes and strip LDFLAGS from krb5-config (rhbz#2048909) + +* Wed Feb 02 2022 Alexander Bokovoy - 1.19.2-5 +- Temporarily remove package note to unblock krb5-dependent packages + Resolves: rhbz#2048909 + +* Thu Jan 20 2022 Fedora Release Engineering - 1.19.2-4.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Fri Dec 3 2021 Antonio Torres - 1.19.2-4 +- Add patches to support OpenSLL 3.0.0 +- Remove TCL-based libkadm5 API tests + +* Tue Sep 14 2021 Sahana Prasad - 1.19.2-3.1 +- Rebuilt with OpenSSL 3.0.0 + +* Tue Aug 24 2021 Robbie Harwood - 1.19.2-3 +- Remove -specs= from krb5-config output + +* Thu Aug 19 2021 Robbie Harwood - 1.19.2-2 +- Fix KDC null deref on TGS inner body null server (CVE-2021-37750) + +* Mon Jul 26 2021 Robbie Harwood - 1.19.2-1 +- New upstream version (1.19.2) + +* Wed Jul 21 2021 Robbie Harwood - 1.19.1-15 +- Fix defcred leak in krb5 gss_inquire_cred() + +* Mon Jul 12 2021 Robbie Harwood - 1.19.1-14 +- Fix KDC null deref on bad encrypted challenge (CVE-2021-36222) + +* Thu Jul 01 2021 Robbie Harwood - 1.19.1-13 +- Fix use-after-free during krad remote_shutdown() + +* Mon Jun 28 2021 Robbie Harwood - 1.19.1-12 +- MEMORY locking fix and static analysis pullup + +* Mon Jun 21 2021 Robbie Harwood - 1.19.1-11 +- Add the backward-compatible parts of openssl3 support + +* Wed Jun 09 2021 Robbie Harwood - 1.19.1-10 +- Fix three canonicalization cases for fallback + +* Wed Jun 02 2021 Robbie Harwood - 1.19.1-9 +- Fix doc build for Sphinx 4.0 + +* Thu May 20 2021 Robbie Harwood - 1.19.1-8 +- Add all the sssd-kcm workarounds + +* Thu May 20 2021 Robbie Harwood - 1.19.1-7 +- Fix context for previous backport + +* Thu May 20 2021 Robbie Harwood - 1.19.1-6 +- Add KCM_OP_GET_CRED_LIST and KCM_OP_RETRIEVE support + +* Tue May 04 2021 Robbie Harwood - 1.19.1-5 +- Suppress static analyzer warning in FIPS override + +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 1.19.1-3.1 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + +* Mon Mar 01 2021 Robbie Harwood - 1.19.1-3 +- Further test dependency fixes; no code changes + +* Mon Mar 01 2021 Robbie Harwood - 1.19.1-2 +- Make test dependencies contingent on skipcheck; no code changes + +* Thu Feb 18 2021 Robbie Harwood - 1.19.1-1 +- New upstream version (1.19.1) + +* Wed Feb 17 2021 Robbie Harwood - 1.19-3 +- Restore krb5_set_default_tgs_ktypes() + +* Fri Feb 05 2021 Robbie Harwood - 1.19-2 +- No code change; just coping with reverted autoconf + +* Tue Feb 02 2021 Robbie Harwood - 1.19-1 +- New upstream version (1.19) + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.5 +- Support host-based GSS initiator names + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.4 +- Require krb5-pkinit from krb5-{server,workstation} + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.3 +- Fix up weird mass rebuild versioning + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.2.2 +- Add APIs for marshalling credentials + +* Wed Jan 27 2021 Robbie Harwood - 1.19-0.beta2.1.2 +- Cope with new autotools behavior wrt runstatedir + +* Tue Jan 26 2021 Fedora Release Engineering - 1.19-0.beta2.1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Tue Jan 12 2021 Robbie Harwood - 1.19-1 +- New upstream version (1.19-beta2) + +* Wed Dec 16 2020 Robbie Harwood - 1.19-0.beta1.2 +- New upstream version (1.19-beta1) + +* Wed Dec 16 2020 Robbie Harwood - 1.18.3-5 +- Fix runstatedir configuration +- Why couldn't systemd just leave it alone? + +* Tue Nov 24 2020 Robbie Harwood - 1.18.3-4 +- Document -k option in kvno(1) synopsis + +* Fri Nov 20 2020 Robbie Harwood - 1.18.3-3 +- Upstream executable shared libraries patch + +* Wed Nov 18 2020 Robbie Harwood - 1.18.3-2 +- Fix build failure in -1 + +* Wed Nov 18 2020 Robbie Harwood - 1.18.3-1 +- New upstream version (1.18.3) + +* Tue Nov 17 2020 Robbie Harwood - 1.18.2-30 +- Migrate /var/run to /run, an exercise in pointlessness + Resolves: rhbz#1898410 + +* Thu Nov 05 2020 Robbie Harwood - 1.18.2-29 +- Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) + +* Fri Oct 23 2020 Robbie Harwood - 1.18.2-28 +- Fix minor static analysis defects + +* Wed Oct 21 2020 Robbie Harwood - 1.18.2-27 +- Fix build of previous + +* Wed Oct 21 2020 Robbie Harwood - 1.18.2-26 +- Cross-realm s4u fixes for samba (rhbz#1836630) + +* Thu Oct 15 2020 Robbie Harwood - 1.18.2-25 +- Unify kvno option documentation + +* Fri Oct 02 2020 Robbie Harwood - 1.18.2-24 +- Add md5 override to krad + +* Thu Sep 10 2020 Robbie Harwood - 1.18.2-23 +- Use `systemctl reload` to HUP the KDC during logrotate + Resolves: rhbz#1877692 + +* Wed Sep 09 2020 Robbie Harwood - 1.18.2-22 +- Fix input length checking in SPNEGO DER decoding + +* Fri Aug 28 2020 Robbie Harwood - 1.18.2-21 +- Mark crypto-polices snippet as missingok + Resolves: rhbz#1868379 + +* Thu Aug 13 2020 Robbie Harwood - 1.18.2-20 +- Temporarily dns_canonicalize_hostname=fallback changes +- Hopefully unbreak IPA while we debug further + +* Fri Aug 07 2020 Robbie Harwood - 1.18.2-19 +- Expand dns_canonicalize_hostname=fallback support + +* Tue Aug 04 2020 Robbie Harwood - 1.18.2-18 +- Fix leak in KERB_AP_OPTIONS_CBT server support + +* Mon Aug 03 2020 Robbie Harwood - 1.18.2-17 +- Revert qualify_shortname removal + +* Mon Aug 03 2020 Robbie Harwood - 1.18.2-16 +- Disable tests on s390x + Resolves: rhbz#1863952 + +* Sat Aug 01 2020 Fedora Release Engineering - 1.18.2-15 +- Second attempt - Rebuilt for + https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Fri Jul 31 2020 Robbie Harwood - 1.18.2-14 +- Revert qualify_shortname changes + +* Tue Jul 28 2020 Fedora Release Engineering - 1.18.2-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Wed Jul 22 2020 Robbie Harwood - 1.18.2-12 +- Ignore bad enctypes in krb5_string_to_keysalts() +- Allow gss_unwrap_iov() of unpadded RC4 tokens + +* Wed Jul 15 2020 Robbie Harwood - 1.18.2-11 +- Ignore bad enctypes in krb5_string_to_keysalts() + +* Wed Jul 08 2020 Robbie Harwood - 1.18.2-10 +- Set qualify_shortname empty in default configuration + Resolves: rhbz#1852041 + +* Mon Jun 15 2020 Robbie Harwood - 1.18.2-9 +- Use two queues for concurrent t_otp.py daemons + +* Mon Jun 15 2020 Robbie Harwood - 1.18.2-8 +- Match Heimdal behavior for channel bindings + +* Mon Jun 08 2020 Robbie Harwood - 1.18.2-7 +- Fix test suite by removing wrapper workarounds + +* Mon Jun 08 2020 Robbie Harwood - 1.18.2-6 +- Omit PA_FOR_USER if we can't compute its checksum + +* Sat May 30 2020 Robbie Harwood - 1.18.2-5 +- Replace gssrpc tests with a Python script + +* Sat May 30 2020 Robbie Harwood - 1.18.2-4 +- Default dns_canonicalize_hostname to "fallback" + +* Tue May 26 2020 Robbie Harwood - 1.18.2-3 +- dns_canonicalize_hostname = fallback + +* Tue May 26 2020 Robbie Harwood - 1.18.2-2 +- Pass channel bindings through SPNEGO + +* Fri May 22 2020 Robbie Harwood - 1.18.2-1 +- New upstream release (1.18.2) + +* Fri May 22 2020 Robbie Harwood - 1.18.1-6 +- Fix SPNEGO acceptor mech filtering + +* Mon May 18 2020 Robbie Harwood - 1.18.1-5 +- Fix typo ("in in") in the ksu man page + +* Fri May 08 2020 Robbie Harwood - 1.18.1-4 +- Omit KDC indicator check for S4U2Self requests + +* Tue Apr 28 2020 Robbie Harwood - 1.18.1-3 +- Pass gss_localname() through SPNEGO + +* Tue Apr 14 2020 Robbie Harwood - 1.18-1.1 +- Drop yasm requirement since we don't use builtin crypto + +* Tue Apr 14 2020 Robbie Harwood - 1.18.1-1 +- New upstream version (1.18.1) + +* Tue Apr 07 2020 Robbie Harwood - 1.18-12 +- Make ksu honor KRB5CCNAME again + +* Thu Apr 02 2020 Robbie Harwood - 1.18-11 +- Do expiration warnings for all init_creds APIs + +* Wed Apr 01 2020 Robbie Harwood - 1.18-10 +- Correctly import "service@" GSS host-based name + +* Thu Mar 26 2020 Robbie Harwood - 1.18-9 +- Eliminate redundant PKINIT responder invocation + +* Thu Mar 26 2020 Robbie Harwood - 1.18-8 +- Add finalization safety check to com_err + +* Fri Mar 20 2020 Robbie Harwood - 1.18-7 +- Add maximum openssl version in preparation for openssl 3 + +* Tue Mar 17 2020 Robbie Harwood - 1.18-6 +- Document client keytab usage + +* Tue Mar 03 2020 Robbie Harwood - 1.18-5 +- Refresh manually acquired creds from client keytab + +* Fri Feb 28 2020 Robbie Harwood - 1.18-4 +- Allow deletion of require_auth with LDAP KDB + +* Thu Feb 27 2020 Robbie Harwood - 1.18-3 +- Allow certauth modules to set hw-authent flag + +* Fri Feb 21 2020 Robbie Harwood - 1.18-2 +- Fix AS-REQ checking of KDB-modified indicators + +* Wed Feb 12 2020 Robbie Harwood - 1.18-1 +- New upstream version (1.18) + +* Fri Feb 07 2020 Robbie Harwood - 1.18-0.beta2.3 +- Don't assume OpenSSL failures are memory errors + +* Thu Feb 06 2020 Robbie Harwood - 1.18-0.beta2.2 +- Put KDB authdata first + +* Fri Jan 31 2020 Robbie Harwood - 1.18-0.beta2.1 +- New upstream beta release - 1.18-beta2 +- Adjust naming convention for downstream patches + +* Fri Jan 10 2020 Robbie Harwood - 1.18-0.beta1.1 +- New upstream beta release - 1.18-beta1 + +* Wed Jan 08 2020 Robbie Harwood - 1.17.1-5 +- Fix LDAP policy enforcement of pw_expiration +- Fix handling of invalid CAMMAC service verifier + +* Mon Jan 06 2020 Robbie Harwood - 1.17.1-4 +- Fix xdr_bytes() strict-aliasing violations + +* Fri Jan 03 2020 Robbie Harwood - 1.17.1-3 +- Don't warn in kadmin when no policy is specified +- Do not always canonicalize enterprise principals + +* Fri Dec 13 2019 Robbie Harwood - 1.17.1-2 +- Enable the LMDB backend for the KDB + +* Thu Dec 12 2019 Robbie Harwood - 1.17.1-1 +- New upstream version - 1.17.1 +- Stop building and packaging PDFs + +* Fri Dec 06 2019 Robbie Harwood - 1.17-54 +- Qualify short hostnames when not using DNS + +* Wed Nov 27 2019 Robbie Harwood - 1.17-53 +- Various gssalloc fixes + +* Thu Nov 21 2019 Robbie Harwood - 1.17-52 +- Turns out openssl has an epoch + +* Wed Nov 20 2019 Robbie Harwood - 1.17-51 +- Fix runtime openssl version to actually propogate + +* Wed Nov 20 2019 Robbie Harwood - 1.17-50 +- Add runtime openssl version requirement too + +* Wed Nov 20 2019 Robbie Harwood - 1.17-49 +- Fix kadmin addprinc -randkey -kvno + +* Tue Nov 19 2019 Robbie Harwood - 1.17-48 +- Use OpenSSL's backported KDFs +- Restore MD4 in FIPS mode (for samba) + +* Fri Nov 08 2019 Robbie Harwood - 1.17-47 +- Add default_principal_flags to example kdc.conf + +* Wed Oct 02 2019 Robbie Harwood - 1.17-46 +- Log unknown enctypes as unsupported in KDC + +* Wed Sep 25 2019 Robbie Harwood - 1.17-45 +- Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) + +* Thu Sep 12 2019 Robbie Harwood - 1.17-44 +- Static analyzer appeasement + +* Tue Aug 27 2019 Robbie Harwood - 1.17-43 +- Simplify krb5_dbe_def_search_enctype() + +* Thu Aug 22 2019 Robbie Harwood - 1.17-42 +- Update FIPS patches to remove SPAKE + +* Thu Aug 15 2019 Robbie Harwood - 1.17-41 +- Fix KCM client time offset propagation + +* Fri Aug 09 2019 Robbie Harwood - 1.17-40 +- Initialize life/rlife in kdcpolicy interface + +* Tue Aug 06 2019 Robbie Harwood - 1.17-39 +- Fix memory leaks in soft-pkcs11 code + +* Tue Jul 30 2019 Robbie Harwood - 1.17-38 +- Add soft-pkcs11 and use it for testing + +* Thu Jul 25 2019 Fedora Release Engineering - 1.17-37 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Thu Jul 18 2019 Robbie Harwood - 1.17-36 +- Filter enctypes in gss_set_allowable_enctypes() + +* Mon Jul 15 2019 Robbie Harwood - 1.17-35 +- Don't error on invalid enctypes in keytab + Resolves: rhbz#1724380 + +* Tue Jul 02 2019 Robbie Harwood - 1.17-34 +- Remove now-unused checksum functions + +* Wed Jun 26 2019 Robbie Harwood - 1.17-33 +- Fix typo in 3des commit + +* Wed Jun 26 2019 Robbie Harwood - 1.17-32 +- Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) + +* Mon Jun 10 2019 Robbie Harwood - 1.17-31 +- Remove strerror() calls from k5_get_error() + +* Fri Jun 07 2019 Robbie Harwood - 1.17-30 +- Remove 3des from kdc.conf example + +* Mon Jun 03 2019 Robbie Harwood - 1.17-29 +- Remove 3DES support + +* Mon Jun 03 2019 Robbie Harwood - 1.17-28 +- Remove 3des support + +* Thu May 30 2019 Robbie Harwood - 1.17-27 +- Remove krb5int_c_combine_keys() and no-flags SAM-2 preauth + +* Tue May 28 2019 Robbie Harwood - 1.17-26 +- Remove support for single-DES and CRC + +* Wed May 22 2019 Robbie Harwood - 1.17-25 +- Add missing newlines to deprecation warnings +- Switch to upstream's ksu path patch + +* Tue May 21 2019 Robbie Harwood - 1.17-24 +- Update default krb5kdc mkey manual-entry enctype +- Also update account lockout patch to upstream version + +* Mon May 20 2019 Robbie Harwood - 1.17-23 +- Test & docs fixes in preparation for DES removal + +* Wed May 15 2019 Robbie Harwood - 1.17-22 +- Drop krb5_realm_compare() etc. NULL check patches + + +* Wed May 15 2019 Robbie Harwood - 1.17-21 +- Re-provide krb5-kdb-version in -devel as well (IPA wants it) + +* Tue May 14 2019 Robbie Harwood - 1.17-20 +- (Patch consolidation; hopefully no changes) + +* Tue May 14 2019 Robbie Harwood - 1.17-19 +- Remove checksum type profile variables + +* Fri May 10 2019 Robbie Harwood - 1.17-18 +- Pull in 2019-05-02 static analysis updates + +* Fri May 03 2019 Robbie Harwood - 1.17-17 +- Move krb5-kdb-version provide into krb5-server for freeipa + +* Wed May 01 2019 Robbie Harwood - 1.17-16 +- Use secure_getenv() where appropriate + +* Wed Apr 24 2019 Robbie Harwood - 1.17-15 +- Fix us up real nice with rpmlint + +* Wed Apr 24 2019 Robbie Harwood - 1.17-14 +- Add dns_canonicalize_hostname=fallback support + +* Wed Apr 24 2019 Robbie Harwood - 1.17-13 +- Check more errors in OpenSSL crypto backend + +* Mon Apr 22 2019 Robbie Harwood - 1.17-12 +- Fix potential close(-1) in cc_file.c + +* Wed Apr 17 2019 Robbie Harwood - 1.17-11 +- Remove ovsec_adm_export and confvalidator + +* Wed Apr 17 2019 Robbie Harwood - 1.17-10 +- Fix config realm change logic in FILE remove_cred + +* Thu Apr 11 2019 Robbie Harwood - 1.17-9 +- Remove Kerberos v4 support vestiges (including ktany support) + +* Thu Apr 11 2019 Robbie Harwood - 1.17-8 +- Implement krb5_cc_remove_cred for remaining types + Resolves: rhbz#1693836 + +* Mon Apr 01 2019 Robbie Harwood - 1.17-7 +- FIPS-aware SPAKE group negotiation + +* Mon Feb 25 2019 Robbie Harwood - 1.17-6 +- Fix memory leak in 'none' replay cache type +- Silence a coverity warning while we're here. + +* Fri Feb 01 2019 Robbie Harwood - 1.17-5 +- Update FIPS blocking for RC4 + +* Fri Feb 01 2019 Fedora Release Engineering - 1.17-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Thu Jan 17 2019 Robbie Harwood - 1.17-3 +- enctype logging and explicit_bzero() + +* Tue Jan 08 2019 Robbie Harwood - 1.17-2 +- New upstream version (1.17) + +* Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.6 +- Use openssl's PRNG in FIPS mode + +* Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.5 +- Address some optimized-out memset() calls + +* Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.4 +- Remove incorrect KDC assertion + +* Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.3 +- Fix syntax on pkinit_anchors field in default krb5.conf + +* Mon Dec 17 2018 Robbie Harwood - 1.17-1.beta2.2 +- Restore pdfs source file + Resolves: rhbz#1659716 + +* Thu Dec 06 2018 Robbie Harwood - 1.17-1.beta2.1 +- New upstream release (1.17-beta2) +- Drop pdfs source file + +* Thu Nov 29 2018 Robbie Harwood - 1.17-1.beta1.3 +- Add tests for KCM ccache type + +* Mon Nov 12 2018 Robbie Harwood - 1.17-1.beta1.2 +- Gain FIPS awareness + +* Thu Nov 08 2018 Robbie Harwood - 1.17-1.beta1.1 +- Fix spurious errors from kcmio_unix_socket_write + Resolves: rhbz#1645912 + +* Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta1.1 +- New upstream beta release + +* Wed Oct 24 2018 Robbie Harwood - 1.16.1-25 +- Update man pages to reference kerberos(7) + Resolves: rhbz#1143767 + +* Wed Oct 17 2018 Robbie Harwood - 1.16.1-24 +- Use port-sockets.h macros in cc_kcm, sendto_kdc + Resolves: rhbz#1631998 + +* Wed Oct 17 2018 Robbie Harwood - 1.16.1-23 +- Correct kpasswd_server description in krb5.conf(5) + Resolves: rhbz#1640272 + +* Mon Oct 15 2018 Robbie Harwood - 1.16.1-22 +- Prefer TCP to UDP for password changes + Resolves: rhbz#1637611 + +* Tue Oct 09 2018 Adam Williamson - 1.16.1-21 +- Revert the patch from -20 for now as it seems to make FreeIPA worse + +* Tue Oct 02 2018 Robbie Harwood - 1.16.1-20 +- Fix bugs with concurrent use of MEMORY ccaches + +* Wed Aug 01 2018 Robbie Harwood - 1.16.1-19 +- In FIPS mode, add plaintext fallback for RC4 usages and taint + +* Thu Jul 26 2018 Robbie Harwood - 1.16.1-18 +- Fix k5test prompts for Python 3 + +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-17 +- Remove outdated note in krb5kdc man page + +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-16 +- Make krb5kdc -p affect TCP ports + +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-15 +- Eliminate preprocessor-disabled dead code + +* Wed Jul 18 2018 Robbie Harwood - 1.16.1-14 +- Fix some broken tests for Python 3 + +* Mon Jul 16 2018 Robbie Harwood - 1.16.1-13 +- Zap copy of secret in RC4 string-to-key + +* Thu Jul 12 2018 Robbie Harwood - 1.16.1-12 +- Convert Python tests to Python 3 + +* Wed Jul 11 2018 Robbie Harwood - 1.16.1-11 +- Add build dependency on gcc + +* Tue Jul 10 2018 Robbie Harwood - 1.16.1-10 +- Use SHA-256 instead of MD5 for audit ticket IDs + +* Fri Jul 06 2018 Robbie Harwood - 1.16.1-9 +- Add BuildRequires on python2 so we can run tests at build-time + +* Fri Jul 06 2018 Robbie Harwood - 1.16.1-8 +- Explicitly look for python2 in configure.in + +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-7 +- Add flag to disable encrypted timestamp on client + +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-6 +- Switch to python3-sphinx for docs + Resolves: rhbz#1590928 + +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-5 +- Make docs build python3-compatible + Resolves: rhbz#1590928 + +* Thu Jun 07 2018 Robbie Harwood - 1.16.1-4 +- Update includedir processing to match upstream + +* Fri Jun 01 2018 Robbie Harwood - 1.16.1-3 +- Log when non-root ksu authorization fails + Resolves: rhbz#1575771 + +* Fri May 04 2018 Robbie Harwood - 1.16.1-2 +- Remove "-nodes" option from make-certs scripts + +* Fri May 04 2018 Robbie Harwood - 1.16.1-1 +- New upstream release - 1.16.1 + +* Thu May 03 2018 Robbie Harwood - 1.16-27 +- Fix configuration of default ccache name to match file indentation + +* Mon Apr 30 2018 Robbie Harwood - 1.16-26 +- Set error message on KCM get_princ failure + +* Mon Apr 30 2018 Robbie Harwood - 1.16-25 +- Set error message on KCM get_princ failure + +* Tue Apr 24 2018 Robbie Harwood - 1.16-24 +- Fix KDC null dereference on large TGS replies + +* Mon Apr 23 2018 Robbie Harwood - 1.16-23 +- Explicitly use openssl rather than builtin crypto + Resolves: rhbz#1570910 + +* Tue Apr 17 2018 Robbie Harwood - 1.16-22 +- Merge duplicate subsections in profile library + +* Mon Apr 09 2018 Robbie Harwood - 1.16-21 +- Restrict pre-authentication fallback cases + +* Tue Apr 03 2018 Robbie Harwood - 1.16-20 +- Be more careful asking for AS key in SPAKE client + +* Mon Apr 02 2018 Robbie Harwood - 1.16-19 +- Zap data when freeing krb5_spake_factor + +* Thu Mar 29 2018 Robbie Harwood - 1.16-18 +- Continue after KRB5_CC_END in KCM cache iteration + +* Tue Mar 27 2018 Robbie Harwood - 1.16-17 +- Fix SPAKE memory leak + +* Tue Mar 27 2018 Robbie Harwood - 1.16-16 +- Fix gitignore problem with previous patchset + +* Tue Mar 27 2018 Robbie Harwood - 1.16-15 +- Add SPAKE support +- Improve protections on internal sensitive buffers +- Improve internal hex encoding/decoding + +* Tue Mar 20 2018 Robbie Harwood - 1.16-14 +- Fix problem with ccache_name logic in previous build + +* Tue Mar 20 2018 Robbie Harwood - 1.16-13 +- Add pkinit_anchors default value to krb5.conf +- Reindent krb5.conf to not be terrible + +* Tue Mar 20 2018 Robbie Harwood - 1.16-12 +- Log preauth names in trace output +- Misc bugfixes from upstream + +* Mon Mar 19 2018 Robbie Harwood - 1.16-11 +- Add PKINIT KDC support for freshness token + +* Wed Mar 14 2018 Robbie Harwood - 1.16-10 +- Exit with status 0 from kadmind + +* Tue Mar 13 2018 Robbie Harwood - 1.16-9 +- Fix hex conversion of PKINIT certid strings + +* Wed Mar 07 2018 Robbie Harwood - 1.16-8 +- Fix capaths "." values on client + Resolves: 1551099 + +* Tue Feb 13 2018 Robbie Harwood - 1.16-7 +- Fix flaws in LDAP DN checking +- CVE-2018-5729, CVE-2018-5730 + +* Mon Feb 12 2018 Robbie Harwood - 1.16-6 +- Fix a leak in the previous commit +- Restore dist macro that was accidentally removed + Resolves: rhbz#1540939 + +* Wed Feb 07 2018 Fedora Release Engineering - 1.16-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Sat Feb 03 2018 Igor Gnatenko - 1.16-4 +- Switch to %%ldconfig_scriptlets + +* Mon Jan 29 2018 Robbie Harwood - 1.16-3 +- Process included directories in alphabetical order + +* Tue Dec 12 2017 Robbie Harwood - 1.16-2 +- Fix network service dependencies + Resolves: rhbz#1525230 + +* Wed Dec 06 2017 Robbie Harwood - 1.16-1 +- New upstream release (1.16) +- No changes from beta2 + +* Mon Nov 27 2017 Robbie Harwood - 1.16-0.beta2.1 +- New upstream prerelease (1.16-beta2) + +* Tue Oct 24 2017 Robbie Harwood - 1.16-0.beta1.4 +- Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) + +* Mon Oct 23 2017 Robbie Harwood - 1.16-0.beta1.3 +- Drop dependency on python2-pyrad (dead upstream, broken with new python) + +* Mon Oct 09 2017 Robbie Harwood - 1.16-0.beta1.2 +- Actually bump kdbversion like I was supposed to + +* Thu Oct 05 2017 Robbie Harwood - 1.16-0.beta1.1 +- New upstream prerelease (1.16-beta1) + * Thu Sep 28 2017 Robbie Harwood - 1.15.2-2 - Add German translation @@ -754,12 +1636,12 @@ exit 0 * Wed Sep 06 2017 Robbie Harwood - 1.15.1-28 - Save other programs from worrying about CVE-2017-11462 -- Resolves: #1488873 -- Resolves: #1488874 + Resolves: rhbz#1488873 + Resolves: rhbz#1488874 * Tue Sep 05 2017 Robbie Harwood - 1.15.1-27 - Add hostname-based ccselect module -- Resolves: #1463665 + Resolves: rhbz#1463665 * Tue Sep 05 2017 Robbie Harwood - 1.15.1-26 - Backport upstream certauth EKU fixes @@ -802,15 +1684,15 @@ exit 0 * Mon Jun 26 2017 Robbie Harwood - 1.15.1-13 - Fix arch name (ppc64le, not ppc64el) -- Related-to: #1464381 +- Related-to: rhbz#1464381 * Mon Jun 26 2017 Robbie Harwood - 1.15.1-12 - Skip test suite on ppc64el -- Related-to: #1464381 +- Related-to: rhbz#1464381 * Fri Jun 23 2017 Robbie Harwood - 1.15.1-11 - Include more test suite changes from upstream -- Resolves: #1464381 + Resolves: rhbz#1464381 * Wed Jun 07 2017 Robbie Harwood - 1.15.1-10 - Fix custom build with -DDEBUG @@ -826,12 +1708,12 @@ exit 0 * Thu Apr 13 2017 Robbie Harwood - 1.15.1-6 - Include fixes for previous commit -- Resolves: #1433083 + Resolves: rhbz#1433083 * Thu Apr 13 2017 Robbie Harwood - 1.15.1-5 - Automatically add includedir where not present - Try removing sleep statement to see if it is still needed -- Resolves: #1433083 + Resolves: rhbz#1433083 * Fri Apr 07 2017 Robbie Harwood - 1.15.1-4 - Fix use of enterprise principals with forwarding @@ -841,7 +1723,7 @@ exit 0 * Tue Mar 07 2017 Robbie Harwood - 1.15.1-2 - Remove duplication between subpackages -- Resolves: #1250228 + Resolves: rhbz#1250228 * Fri Mar 03 2017 Robbie Harwood - 1.15.1-1 - New upstream release - 1.15.1 @@ -875,14 +1757,14 @@ exit 0 * Thu Oct 20 2016 Robbie Harwood - 1.15-beta1-1 - New upstream release - Update selinux with RHEL hygene -- Resolves: #1314096 + Resolves: rhbz#1314096 * Tue Oct 11 2016 Tomáš Mráz - 1.14.4-6 - rebuild with OpenSSL 1.1.0, added backported upstream patch * Fri Sep 30 2016 Robbie Harwood - 1.14.4-5 - Properly close krad sockets -- Resolves: #1380836 + Resolves: rhbz#1380836 * Fri Sep 30 2016 Robbie Harwood - 1.14.4-4 - Fix backward check in kprop.service @@ -901,42 +1783,42 @@ exit 0 * Mon Sep 19 2016 Robbie Harwood - 1.14.3-9 - Add krb5_db_register_keytab -- Resolves: #1376812 + Resolves: rhbz#1376812 * Mon Aug 29 2016 Robbie Harwood - 1.14.3-8 - Use responder for non-preauth AS requests -- Resolves: #1370622 + Resolves: rhbz#1370622 * Mon Aug 29 2016 Robbie Harwood - 1.14.3-7 - Guess Samba client mutual flag using ap_option -- Resolves: #1370980 + Resolves: rhbz#1370980 * Thu Aug 25 2016 Robbie Harwood - 1.14.3-6 - Fix KDC return code and set prompt types for OTP client preauth -- Resolves: #1370072 + Resolves: rhbz#1370072 * Mon Aug 15 2016 Robbie Harwood - 1.14.3-5 - Turn OFD locks back on with glibc workaround -- Resolves: #1274922 + Resolves: rhbz#1274922 * Wed Aug 10 2016 Robbie Harwood - 1.14.3-4 - Fix use of KKDCPP with SNI -- Resolves: #1365027 + Resolves: rhbz#1365027 * Fri Aug 05 2016 Robbie Harwood - 1.14.3-3 - Make krb5-devel depend on libkadm5 -- Resolves: #1364487 + Resolves: rhbz#1364487 * Wed Aug 03 2016 Robbie Harwood - 1.14.3-2 - Up-port a bunch of stuff from the el-7.3 cycle -- Resolves: #1255450, #1314989 + Resolves: rhbz#1255450, rhbz#1314989 * Mon Aug 01 2016 Robbie Harwood - 1.14.3-1 - New upstream version 1.14.3 * Thu Jul 28 2016 Robbie Harwood - 1.14.1-9 - Fix CVE-2016-3120 -- Resolves: #1361051 + Resolves: rhbz#1361051 * Wed Jun 22 2016 Robbie Harwood - 1.14.1-8 - Fix incorrect recv() size calculation in libkrad @@ -949,18 +1831,18 @@ exit 0 * Tue Apr 05 2016 Robbie Harwood - 1.14.1-5 - Use the correct patches this time. -- Resolves: #1321135 + Resolves: rhbz#1321135 * Mon Apr 04 2016 Robbie Harwood - 1.14.1-4 - Add send/receive sendto_kdc hooks and corresponding tests -- Resolves: #1321135 + Resolves: rhbz#1321135 * Fri Mar 18 2016 Robbie Harwood - 1.14.1-3 - Fix CVE-2016-3119 (NULL deref in LDAP module) * Thu Mar 17 2016 Robbie Harwood - 1.14.1-2 - Backport OID mech fix -- Resolves: #1317609 + Resolves: rhbz#1317609 * Mon Feb 29 2016 Robbie Harwood - 1.14.1-1 - New rawhide, new upstream version @@ -970,7 +1852,7 @@ exit 0 * Mon Feb 22 2016 Robbie Harwood - 1.14-23 - Fix log file permissions patch with our selinux -- Resolves: #1309421 + Resolves: rhbz#1309421 * Fri Feb 19 2016 Robbie Harwood - 1.14-22 - Backport my interposer fixes from upstream @@ -979,7 +1861,7 @@ exit 0 * Tue Feb 16 2016 Robbie Harwood - 1.14-21 - Adjust dependency on crypto-polices to be just the file we want - Patch courtesy of lslebodn -- Resolves: #1308984 + Resolves: rhbz#1308984 * Thu Feb 04 2016 Fedora Release Engineering - 1.14-20 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild @@ -987,21 +1869,21 @@ exit 0 * Thu Jan 28 2016 Robbie Harwood - 1.14-19 - Replace _kadmin/_kprop with systemd macros - Remove traces of upstart from fedora package per policy -- Resolves: #1290185 + Resolves: rhbz#1290185 * Wed Jan 27 2016 Robbie Harwood - 1.14-18 - Fix CVE-2015-8629, CVE-2015-8630, CVE-2015-8631 * Thu Jan 21 2016 Robbie Harwood - 1.14-17 - Make krb5kdc.log not world-readable by default -- Resolves: #1276484 + Resolves: rhbz#1276484 * Thu Jan 21 2016 Robbie Harwood - 1.14-16 - Allow verification of attributes on krb5.conf * Wed Jan 20 2016 Robbie Harwood - 1.14-15 - Use "new" systemd macros for service handling. (Thanks vpavlin!) -- Resolves: #850399 + Resolves: rhbz#850399 * Wed Jan 20 2016 Robbie Harwood - 1.14-14 - Remove WITH_NSS macro (always false) @@ -1011,13 +1893,13 @@ exit 0 * Fri Jan 08 2016 Robbie Harwood - 1.14-13 - Backport fix for chrome crash in spnego_gss_inquire_context -- Resolves: #1295893 + Resolves: rhbz#1295893 * Wed Dec 16 2015 Robbie Harwood - 1.14-12 - Backport patch to fix mechglue for gss_inqure_attrs_for_mech() * Thu Dec 03 2015 Robbie Harwood - 1.14-11 -- Backport interposer fix (#1284985) +- Backport interposer fix (rhbz#1284985) - Drop workaround pwsize initialization patch (gcc has been fixed) * Tue Nov 24 2015 Robbie Harwood - 1.14-10 @@ -1052,7 +1934,7 @@ exit 0 - New upstream beta version * Thu Oct 08 2015 Robbie Harwood - 1.13.2-13 -- Work around KDC client prinicipal in referrals issue (#1259844) +- Work around KDC client prinicipal in referrals issue (rhbz#1259844) * Thu Oct 01 2015 Robbie Harwood - 1.13.2-12 - Enable building with bad system /etc/krb5.conf @@ -1065,7 +1947,7 @@ exit 0 - Nix /usr/share/krb5.conf.d to reduce complexity * Wed Sep 23 2015 Robbie Harwood - 1.13.2-9 -- Depend on crypto-policies which provides /etc/krb5.conf.d (#1225792) +- Depend on crypto-policies which provides /etc/krb5.conf.d (rhbz#1225792) * Thu Sep 10 2015 Robbie Harwood - 1.13.2-8 - Remove dependency on systemd-sysv which is no longer needed for fedora > 20 @@ -1074,7 +1956,7 @@ exit 0 * Thu Sep 10 2015 Robbie Harwood - 1.13.2-7 - Support config snippets in /etc/krb5.conf.d/ and /usr/share/krb5.conf.d/ - (#1225792, #1146370, #1145808) + (rhbz#1225792, rhbz#1146370, rhbz#1145808) * Thu Jun 25 2015 Roland Mainz - 1.13.2-6 - Use system nss_wrapper and socket_wrapper for testing. @@ -1082,8 +1964,8 @@ exit 0 * Thu Jun 25 2015 Roland Mainz - 1.13.2-5 - Remove Zanata test glue and related workarounds - - Bug #1234292 ("IPA server cannot be run in container due to incorrect /usr/sbin/_kadmind") - - Bug #1234326 ("krb5-server introduces new rpm dependency on ksh") + - rhbz#1234292 ("IPA server cannot be run in container due to incorrect /usr/sbin/_kadmind") + - rhbz#1234326 ("krb5-server introduces new rpm dependency on ksh") * Thu Jun 18 2015 Roland Mainz - 1.13.2-4 - Fix dependicy on binfmt.service @@ -1092,12 +1974,12 @@ exit 0 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Tue Jun 2 2015 Roland Mainz - 1.13.2-2 -- Add patch to fix Redhat Bug #1227542 ("[SELinux] AVC denials may appear +- Add patch to fix Redhat rhbz#1227542 ("[SELinux] AVC denials may appear when kadmind starts"). The issue was caused by an unneeded |htons()| which triggered SELinux AVC denials due to the "random" port usage. * Thu May 21 2015 Roland Mainz - 1.13.2-1 -- Add fix for RedHat Bug #1164304 ("Upstream unit tests loads +- Add fix for RedHat rhbz#1164304 ("Upstream unit tests loads the installed shared libraries instead the ones from the build") * Thu May 14 2015 Roland Mainz - 1.13.2-0 @@ -1108,7 +1990,7 @@ exit 0 - Minor spec cleanup * Mon May 4 2015 Roland Mainz - 1.13.1-4 -- fix for CVE-2015-2694 (#1216133) "requires_preauth bypass +- fix for CVE-2015-2694 (rhbz#1216133) "requires_preauth bypass in PKINIT-enabled KDC". In MIT krb5 1.12 and later, when the KDC is configured with PKINIT support, an unauthenticated remote attacker can @@ -1118,13 +2000,13 @@ exit 0 dictionary attack against the user's password. * Wed Mar 25 2015 Roland Mainz - 1.13.1-3 -- Add temporay workaround for RH bug #1204646 ("krb5-config +- Add temporay workaround for RH rhbz#1204646 ("krb5-config returns wrong -specs path") which modifies krb5-config post build so that development of krb5 dependicies gets unstuck. This MUST be removed before rawhide becomes F23 ... * Thu Mar 19 2015 Roland Mainz - 1.13.1-2 -- fix for CVE-2014-5355 (#1193939) "krb5: unauthenticated +- fix for CVE-2014-5355 (rhbz#1193939) "krb5: unauthenticated denial of service in recvauth_common() and others" * Fri Feb 13 2015 Roland Mainz - 1.13.1-1 @@ -1135,13 +2017,13 @@ exit 0 - Minor spec cleanup * Wed Feb 4 2015 Roland Mainz - 1.13-8 -- fix for CVE-2014-5352 (#1179856) "gss_process_context_token() +- fix for CVE-2014-5352 (rhbz#1179856) "gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9421 (#1179857) "kadmind doubly frees partial +- fix for CVE-2014-9421 (rhbz#1179857) "kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9422 (#1179861) "kadmind incorrectly +- fix for CVE-2014-9422 (rhbz#1179861) "kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9423 (#1179863) "libgssrpc server applications +- fix for CVE-2014-9423 (rhbz#1179863) "libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001)" * Wed Feb 4 2015 Roland Mainz - 1.13-7 @@ -1153,17 +2035,17 @@ exit 0 - Support KDC_ERR_MORE_PREAUTH_DATA_REQUIRED (RT#8063) * Mon Jan 26 2015 Roland Mainz - 1.13-5 -- fix for kinit -C loops (#1184629, MIT/krb5 issue 243, "Do not +- fix for kinit -C loops (rhbz#1184629, MIT/krb5 issue 243, "Do not loop on principal unknown errors"). - Added "python-sphinx-latex" to the build requirements to fix build failures on F22 machines. * Thu Dec 18 2014 Roland Mainz - 1.13-4 -- fix for CVE-2014-5354 (#1174546) "krb5: NULL pointer +- fix for CVE-2014-5354 (rhbz#1174546) "krb5: NULL pointer dereference when using keyless entries" * Wed Dec 17 2014 Roland Mainz - 1.13-3 -- fix for CVE-2014-5353 (#1174543) "Fix LDAP misused policy +- fix for CVE-2014-5353 (rhbz#1174543) "Fix LDAP misused policy name crash" * Wed Oct 29 2014 Roland Mainz - 1.13-2 @@ -1173,18 +2055,18 @@ exit 0 * Wed Oct 29 2014 Roland Mainz - 1.13-1 - Update from krb5-1.13-alpha1 to final krb5-1.13 -- Removed patch for CVE-2014-5351 (#1145425) "krb5: current +- Removed patch for CVE-2014-5351 (rhbz#1145425) "krb5: current keys returned when randomizing the keys for a service principal" - now part of upstream sources -- Use patch for glibc |eventfd()| prototype mismatch (#1147887) only +- Use patch for glibc |eventfd()| prototype mismatch (rhbz#1147887) only for Fedora > 20 * Tue Sep 30 2014 Roland Mainz - 1.13-0.alpha1.3 - fix build failure caused by change of prototype for glibc - |eventfd()| (#1147887) + |eventfd()| (rhbz#1147887) * Mon Sep 29 2014 Roland Mainz - 1.13-0.alpha1.3 -- fix for CVE-2014-5351 (#1145425) "krb5: current keys returned when +- fix for CVE-2014-5351 (rhbz#1145425) "krb5: current keys returned when randomizing the keys for a service principal" * Mon Sep 8 2014 Nalin Dahyabhai - 1.13-0.alpha1.3 @@ -1200,7 +2082,7 @@ exit 0 * Wed Aug 20 2014 Nalin Dahyabhai - 1.12.2-3 - pull in upstream fix for an incorrect check on the value returned by a - strdup() call (#1132062) + strdup() call (rhbz#1132062) * Sun Aug 17 2014 Fedora Release Engineering - 1.12.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild @@ -1208,7 +2090,7 @@ exit 0 * Fri Aug 15 2014 Nalin Dahyabhai - 1.12.2-1 - update to 1.12.2 - drop patch for RT#7820, fixed in 1.12.2 - - drop patch for #231147, fixed as RT#3277 in 1.12.2 + - drop patch for rhbz#231147, fixed as RT#3277 in 1.12.2 - drop patch for RT#7818, fixed in 1.12.2 - drop patch for RT#7836, fixed in 1.12.2 - drop patch for RT#7858, fixed in 1.12.2 @@ -1219,7 +2101,7 @@ exit 0 - drop patch for CVE-2014-4344, included in 1.12.2 - drop patch for CVE-2014-4345, included in 1.12.2 - replace older proposed changes for ksu with backports of the changes - after review and merging upstream (#1015559, #1026099, #1118347) + after review and merging upstream (rhbz#1015559, rhbz#1026099, rhbz#1118347) * Thu Aug 7 2014 Nalin Dahyabhai - 1.12.1-14 - incorporate fix for MITKRB5-SA-2014-001 (CVE-2014-4345) @@ -1230,21 +2112,21 @@ exit 0 * Wed Jul 16 2014 Nalin Dahyabhai - 1.12.1-12 - gssapi: pull in proposed fix for a double free in initiators (David - Woodhouse, CVE-2014-4343, #1117963) + Woodhouse, CVE-2014-4343, rhbz#1117963) * Sat Jul 12 2014 Tom Callaway - 1.12.1-11 - fix license handling * Mon Jul 7 2014 Nalin Dahyabhai - 1.12.1-10 - pull in fix for denial of service by injection of malformed GSSAPI tokens - (CVE-2014-4341, CVE-2014-4342, #1116181) + (CVE-2014-4341, CVE-2014-4342, rhbz#1116181) * Tue Jun 24 2014 Nalin Dahyabhai - 1.12.1-9 - pull in changes from upstream which add processing of the contents of - /etc/gss/mech.d/*.conf when loading GSS modules (#1102839) + /etc/gss/mech.d/*.conf when loading GSS modules (rhbz#1102839) * Thu Jun 12 2014 Nalin Dahyabhai - 1.12.1-8 -- pull in fix for building against tcl 8.6 (#1107061) +- pull in fix for building against tcl 8.6 (rhbz#1107061) * Sun Jun 08 2014 Fedora Release Engineering - 1.12.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild @@ -1256,14 +2138,14 @@ exit 0 - spnego: pull in patch from master to restore preserving the OID of the mechanism the initiator requested when we have multiple OIDs for the same mechanism, so that we reply using the same mechanism OID and the initiator - doesn't get confused (#1066000, RT#7858) + doesn't get confused (rhbz#1066000, RT#7858) * Fri Feb 7 2014 Nalin Dahyabhai - 1.12.1-4 - pull in patch from master to move the default directory which the KDC uses when computing the socket path for a local OTP daemon from the database directory (/var/kerberos/krb5kdc) to the newly-added run directory (/run/krb5kdc), in line with what we're expecting in 1.13 (RT#7859, more - of #1040056 as #1063905) + of rhbz#1040056 as rhbz#1063905) - add a tmpfiles.d configuration file to have /run/krb5kdc created at boot-time - own /var/run/krb5kdc @@ -1273,12 +2155,12 @@ exit 0 * Fri Jan 31 2014 Nalin Dahyabhai - add currently-proposed changes to teach ksu about credential cache - collections and the default_ccache_name setting (#1015559,#1026099) + collections and the default_ccache_name setting (rhbz#1015559,rhbz#1026099) * Tue Jan 21 2014 Nalin Dahyabhai - 1.12.1-2 - pull in multiple changes to allow replay caches to be added to a GSS - credential store as "rcache"-type credentials (RT#7818/#7819/#7836, - #1056078/#1056080) + credential store as "rcache"-type credentials (RT#7818/rhbz#7819/rhbz#7836, + rhbz#1056078/rhbz#1056080) * Fri Jan 17 2014 Nalin Dahyabhai - 1.12.1-1 - update to 1.12.1 @@ -1291,11 +2173,11 @@ exit 0 - drop patches for RT#7813 and RT#7815, included now - add patch to always retrieve the KDC time offsets from keyring caches, so that we don't mistakenly interpret creds as expired before their - time when our clock is ahead of the KDC's (RT#7820, #1030607) + time when our clock is ahead of the KDC's (RT#7820, rhbz#1030607) * Mon Jan 13 2014 Nalin Dahyabhai - 1.12-11 - update the PIC patch for iaesx86.s to not use ELF relocations to the version - that landed upstream (RT#7815, #1045699) + that landed upstream (RT#7815, rhbz#1045699) * Thu Jan 9 2014 Nalin Dahyabhai - pass -Wl,--warn-shared-textrel to the compiler when we're creating shared @@ -1310,16 +2192,16 @@ exit 0 master - make a guess at making the 32-bit AES-NI implementation sufficiently position-independent to not require execmod permissions for libk5crypto - (more of #1045699) + (more of rhbz#1045699) * Thu Jan 2 2014 Nalin Dahyabhai - 1.12-8 - add patch from Dhiru Kholia for the AES-NI implementations to allow libk5crypto to be properly marked as not needing an executable stack - on arches where they're used (#1045699, and so many others) + on arches where they're used (rhbz#1045699, and so many others) * Thu Jan 2 2014 Nalin Dahyabhai - 1.12-7 - revert that last change for a bit while sorting out execstack when we - use AES-NI (#1045699) + use AES-NI (rhbz#1045699) * Thu Dec 19 2013 Nalin Dahyabhai - 1.12-6 - add yasm as a build requirement for AES-NI support, on arches that have @@ -1327,7 +2209,7 @@ exit 0 * Thu Dec 19 2013 Nalin Dahyabhai - 1.12-5 - pull in fix from master to make reporting of errors encountered by - the SPNEGO mechanism work better (RT#7045, part of #1043962) + the SPNEGO mechanism work better (RT#7045, part of rhbz#1043962) * Thu Dec 19 2013 Nalin Dahyabhai - update a test wrapper to properly handle things that the new libkrad does, @@ -1337,19 +2219,19 @@ exit 0 - revise previous patch to initialize one more element * Wed Dec 18 2013 Nalin Dahyabhai - 1.12-3 -- backport fixes to krb5_copy_context (RT#7807, #1044735/#1044739) +- backport fixes to krb5_copy_context (RT#7807, rhbz#1044735/rhbz#1044739) * Wed Dec 18 2013 Nalin Dahyabhai - 1.12-2 - pull in fix from master to return a NULL pointer rather than allocating zero bytes of memory if we read a zero-length input token (RT#7794, part of - #1043962) + rhbz#1043962) - pull in fix from master to ignore an empty token from an acceptor if - we've already finished authenticating (RT#7797, part of #1043962) + we've already finished authenticating (RT#7797, part of rhbz#1043962) - pull in fix from master to avoid a memory leak when a mechanism's - init_sec_context function fails (RT#7803, part of #1043962) + init_sec_context function fails (RT#7803, part of rhbz#1043962) - pull in fix from master to avoid a memory leak in a couple of error cases which could occur while obtaining acceptor credentials (RT#7805, part - of #1043962) + of rhbz#1043962) * Wed Dec 11 2013 Nalin Dahyabhai - 1.12-1 - update to 1.12 final @@ -1366,9 +2248,9 @@ exit 0 * Mon Nov 18 2013 Nalin Dahyabhai - 1.11.4-2 - pull in fix to store KDC time offsets in keyring credential caches (RT#7768, - #1030607) + rhbz#1030607) - pull in fix to set expiration times on credentials stored in keyring - credential caches (RT#7769, #1031724) + credential caches (RT#7769, rhbz#1031724) * Tue Nov 12 2013 Nalin Dahyabhai - 1.11.4-1 - update to 1.11.4 @@ -1377,21 +2259,21 @@ exit 0 - drop patch for CVE-2013-1418/CVE-2013-6800, included in 1.11.4 * Tue Nov 12 2013 Nalin Dahyabhai - 1.11.3-31 -- switch to the simplified version of the patch for #1029110 (RT#7764) +- switch to the simplified version of the patch for rhbz#1029110 (RT#7764) * Mon Nov 11 2013 Nalin Dahyabhai - 1.11.3-30 - check more thoroughly for errors when resolving KEYRING ccache names of type "persistent", which should only have a numeric UID as the next part of the - name (#1029110) + name (rhbz#1029110) * Tue Nov 5 2013 Nalin Dahyabhai - 1.11.3-29 - incorporate upstream patch for remote crash of KDCs which serve multiple realms simultaneously (RT#7756, CVE-2013-1418/CVE-2013-6800, - #1026997/#1031501) + rhbz#1026997/rhbz#1031501) * Mon Nov 4 2013 Nalin Dahyabhai - 1.11.3-28 - drop patch to add additional access() checks to ksu - they add to breakage - when non-FILE: caches are in use (#1026099), shouldn't be resulting in any + when non-FILE: caches are in use (rhbz#1026099), shouldn't be resulting in any benefit, and clash with proposed changes to fix its cache handling * Tue Oct 22 2013 Nalin Dahyabhai - 1.11.3-27 @@ -1420,22 +2302,22 @@ exit 0 - BuildRequires: pkgconfig, since configure uses it * Wed Oct 16 2013 Nalin Dahyabhai - 1.11.3-26 -- create and own /etc/gss (#1019937) +- create and own /etc/gss (rhbz#1019937) * Tue Oct 15 2013 Nalin Dahyabhai - 1.11.3-25 - pull up fix for importing previously-exported credential caches in the - gssapi library (RT# 7706, #1019420) + gssapi library (RT# 7706, rhbz#1019420) * Mon Oct 14 2013 Nalin Dahyabhai - 1.11.3-24 - backport the callback to use the libkrb5 prompter when we can't load PEM - files for PKINIT (RT#7590, includes part of #965721/#1016690) -- extract the rest of the fix #965721/#1016690 from the changes for RT#7680 + files for PKINIT (RT#7590, includes part of rhbz#965721/rhbz#1016690) +- extract the rest of the fix rhbz#965721/rhbz#1016690 from the changes for RT#7680 * Mon Oct 14 2013 Nalin Dahyabhai - 1.11.3-23 -- fix trigger scriptlet's invocation of sed (#1016945) +- fix trigger scriptlet's invocation of sed (rhbz#1016945) * Fri Oct 4 2013 Nalin Dahyabhai - 1.11.3-22 -- rebuild with keyutils 1.5.8 (part of #1012043) +- rebuild with keyutils 1.5.8 (part of rhbz#1012043) * Wed Oct 2 2013 Nalin Dahyabhai - 1.11.3-21 - switch to the version of persistent-keyring that was just merged to @@ -1445,7 +2327,7 @@ exit 0 * Mon Sep 30 2013 Nalin Dahyabhai - 1.11.3-20 - pull up fix for not calling a kdb plugin's check-transited-path method before calling the library's default version, which only knows - how to read what's in the configuration file (RT#7709, #1013664) + how to read what's in the configuration file (RT#7709, rhbz#1013664) * Thu Sep 26 2013 Nalin Dahyabhai - 1.11.3-19 - configure --without-krb5-config so that we don't pull in the old default @@ -1456,7 +2338,7 @@ exit 0 - fix broken dependency on awk (should be gawk, rdieter) * Wed Sep 25 2013 Nalin Dahyabhai - 1.11.3-17 -- add missing dependency on newer keyutils-libs (#1012034) +- add missing dependency on newer keyutils-libs (rhbz#1012034) * Tue Sep 24 2013 Nalin Dahyabhai - 1.11.3-16 - back out setting default_ccache_name to the new default for now, resetting @@ -1464,11 +2346,11 @@ exit 0 * Mon Sep 23 2013 Nalin Dahyabhai - 1.11.3-15 - add explicit build-time dependency on a version of keyutils that's new - enough to include keyctl_get_persistent() (more of #991148) + enough to include keyctl_get_persistent() (more of rhbz#991148) * Thu Sep 19 2013 Nalin Dahyabhai - 1.11.3-14 - incorporate Simo's updated backport of his updated persistent-keyring changes - (more of #991148) + (more of rhbz#991148) * Fri Sep 13 2013 Nalin Dahyabhai - 1.11.3-13 - don't break during %%check when the session keyring is revoked @@ -1482,17 +2364,17 @@ exit 0 * Mon Sep 9 2013 Nalin Dahyabhai 1.11.3-11 - don't let comments intended for one scriptlet become part of the "script" - that gets passed to ldconfig as part of another one (Mattias Ellert, #1005675) + that gets passed to ldconfig as part of another one (Mattias Ellert, rhbz#1005675) * Fri Sep 6 2013 Nalin Dahyabhai 1.11.3-10 -- incorporate Simo's backport of his persistent-keyring changes (#991148) +- incorporate Simo's backport of his persistent-keyring changes (rhbz#991148) - restore build-time default DEFCCNAME on Fedora 21 and later and EL, and instead set default_ccache_name in the default krb5.conf's [libdefaults] - section (#991148) + section (rhbz#991148) - on releases where we expect krb5.conf to be configured with a default_ccache_name, add it whenever we upgrade from an older version of the package that wouldn't have included it in its default configuration - file (#991148) + file (rhbz#991148) * Fri Aug 23 2013 Nalin Dahyabhai 1.11.3-9 - take another stab at accounting for UnversionedDocdirs for the -libs @@ -1507,7 +2389,7 @@ exit 0 of files which dictate particular exit codes before exec'ing the actual binaries, instead of trying to use ConditionPathExists in the unit files to accomplish that, so that we exit with failure properly when what we - expect isn't actually in effect on the system (#800343) + expect isn't actually in effect on the system (rhbz#800343) * Mon Jul 29 2013 Nalin Dahyabhai 1.11.3-7 - attempt to account for UnversionedDocdirs for the -libs subpackage @@ -1519,11 +2401,11 @@ exit 0 * Mon Jul 22 2013 Nalin Dahyabhai 1.11.3-5 - pull up changes to allow GSSAPI modules to provide more functions - (RT#7682, #986564/#986565) + (RT#7682, rhbz#986564/rhbz#986565) * Fri Jul 19 2013 Nalin Dahyabhai 1.11.3-4 - use (a bundled, for now, copy of) nss_wrapper to let us run some of the - self-tests at build-time in more places than we could previously (#978756) + self-tests at build-time in more places than we could previously (rhbz#978756) - cover inconsistencies in whether or not there's a local caching nameserver that's willing to answer when the build environment doesn't have a resolver configuration, so that nss_wrapper's faking of the local @@ -1531,23 +2413,23 @@ exit 0 * Mon Jul 1 2013 Nalin Dahyabhai 1.11.3-3 - specify dependencies on the same arch of krb5-libs by using the %%{?_isa} - suffix, to avoid dragging 32-bit libraries onto 64-bit systems (#980155) + suffix, to avoid dragging 32-bit libraries onto 64-bit systems (rhbz#980155) * Thu Jun 13 2013 Nalin Dahyabhai 1.11.3-2 - special-case /run/user/0, attempting to create it when resolving a directory cache below it fails due to ENOENT and we find that it doesn't already exist, either, before attempting to create the directory cache - (maybe helping, maybe just making things more confusing for #961235) + (maybe helping, maybe just making things more confusing for rhbz#961235) * Tue Jun 4 2013 Nalin Dahyabhai 1.11.3-1 - update to 1.11.3 - drop patch for RT#7605, fixed in this release - drop patch for CVE-2002-2443, fixed in this release - drop patch for RT#7369, fixed in this release -- pull upstream fix for breaking t_skew.py by adding the patch for #961221 +- pull upstream fix for breaking t_skew.py by adding the patch for rhbz#961221 * Fri May 31 2013 Nalin Dahyabhai 1.11.2-10 -- respin with updated version of patch for RT#7650 (#969331) +- respin with updated version of patch for RT#7650 (rhbz#969331) * Thu May 30 2013 Nalin Dahyabhai 1.11.2-9 - don't forget to set the SELinux label when creating the directory for @@ -1563,22 +2445,22 @@ exit 0 * Tue May 28 2013 Nalin Dahyabhai 1.11.2-7 - backport fix for not being able to verify the list of transited realms - in GSS acceptors (RT#7639, #959685) + in GSS acceptors (RT#7639, rhbz#959685) - backport fix for not being able to pass an empty password to the - get-init-creds APIs and have them actually use it (RT#7642, #960001) + get-init-creds APIs and have them actually use it (RT#7642, rhbz#960001) - add backported proposed fix to use the unauthenticated server time as the basis for computing the requested credential expiration times, rather than the client's idea of the current time, which could be - significantly incorrect (#961221) + significantly incorrect (rhbz#961221) * Tue May 21 2013 Nalin Dahyabhai 1.11.2-6 - pull in upstream fix to start treating a KRB5CCNAME value that begins with DIR:: the same as it would a DIR: value with just one ccache file - in it (RT#7172, #965574) + in it (RT#7172, rhbz#965574) * Mon May 13 2013 Nalin Dahyabhai 1.11.2-5 - pull up fix for UDP ping-pong flaw in kpasswd service (CVE-2002-2443, - #962531,#962534) + rhbz#962531,rhbz#962534) * Mon Apr 29 2013 Nathaniel McCallum 1.11.2-4 - Update otp patches @@ -1598,11 +2480,11 @@ exit 0 - drop pulled in patch for RT#7586, included in this release - drop pulled in patch for RT#7592, included in this release - pull in fix for keeping track of the message type when parsing FAST requests - in the KDC (RT#7605, #951843) (also #951965) + in the KDC (RT#7605, rhbz#951843) (also rhbz#951965) * Fri Apr 12 2013 Nalin Dahyabhai 1.11.1-9 - move the compiled-in default ccache location from the previous default of - FILE:/tmp/krb5cc_%%{uid} to DIR:/run/user/%%{uid}/krb5cc (part of #949588) + FILE:/tmp/krb5cc_%%{uid} to DIR:/run/user/%%{uid}/krb5cc (part of rhbz#949588) * Tue Apr 09 2013 Nathaniel McCallum - 1.11.1-8 - Update otp backport patches (libk5radius => libkrad) @@ -1623,8 +2505,8 @@ exit 0 * Tue Mar 26 2013 Nalin Dahyabhai 1.11.1-5 - pull up Simo's patch to mark the correct mechanism on imported GSSAPI contexts (RT#7592) -- go back to using reconf to run autoconf and autoheader (part of #925640) -- add temporary patch to use newer config.guess/config.sub (more of #925640) +- go back to using reconf to run autoconf and autoheader (part of rhbz#925640) +- add temporary patch to use newer config.guess/config.sub (more of rhbz#925640) * Mon Mar 18 2013 Nalin Dahyabhai - fix a version comparison to expect newer texlive build requirements when @@ -1635,12 +2517,12 @@ exit 0 - Add otp support * Thu Feb 28 2013 Nalin Dahyabhai 1.11.1-3 -- fix a memory leak when acquiring credentials using a keytab (RT#7586, #911110) +- fix a memory leak when acquiring credentials using a keytab (RT#7586, rhbz#911110) * Wed Feb 27 2013 Nalin Dahyabhai 1.11.1-2 -- prebuild PDF docs to reduce multilib differences (internal tooling, #884065) +- prebuild PDF docs to reduce multilib differences (internal tooling, rhbz#884065) - drop the kerberos-iv portreserve file, and drop the rest on systemd systems -- escape uses of macros in comments (more of #884065) +- escape uses of macros in comments (more of rhbz#884065) * Mon Feb 25 2013 Nalin Dahyabhai 1.11.1-1 - update to 1.11.1 @@ -1648,7 +2530,7 @@ exit 0 wrapper in the client transmit functions * Fri Feb 8 2013 Nalin Dahyabhai 1.11-2 -- set "rdns = false" in the default krb5.conf (#908323,#908324) +- set "rdns = false" in the default krb5.conf (rhbz#908323,rhbz#908324) * Tue Dec 18 2012 Nalin Dahyabhai 1.11-1 - update to 1.11 release @@ -1658,7 +2540,7 @@ exit 0 * Thu Dec 13 2012 Nalin Dahyabhai - when building with our bundled copy of libverto, package it in with -libs - rather than with -server (#886049) + rather than with -server (rhbz#886049) * Wed Nov 21 2012 Nalin Dahyabhai 1.11-0.beta1.0 - update to 1.11 beta 1 @@ -1680,9 +2562,9 @@ exit 0 * Thu Nov 15 2012 Nalin Dahyabhai - update to 1.11 alpha 1 - - drop backported patch for RT #7406 - - drop backported patch for RT #7407 - - drop backported patch for RT #7408 + - drop backported patch for RT rhbz#7406 + - drop backported patch for RT rhbz#7407 + - drop backported patch for RT rhbz#7408 - the new docs system generates PDFs, so stop including them as sources - drop backported patch to allow deltat.y to build with the usual warning flags and the current gcc @@ -1706,27 +2588,27 @@ exit 0 %%{?_rawbuild} builds (zmraz) * Tue Sep 25 2012 Nalin Dahyabhai 1.10.3-6 -- actually pull up the patch for RT#7063, and not some other ticket (#773496) +- actually pull up the patch for RT#7063, and not some other ticket (rhbz#773496) * Mon Sep 10 2012 Nalin Dahyabhai 1.10.3-5 - add patch based on one from Filip Krska to not call poll() with a negative - timeout when the caller's intent is for us to just stop calling it (#838548) + timeout when the caller's intent is for us to just stop calling it (rhbz#838548) * Fri Sep 7 2012 Nalin Dahyabhai - on EL6, conflict with libsmbclient before 3.5.10-124, which is when it - stopped linking with a symbol which we no longer export (#771687) + stopped linking with a symbol which we no longer export (rhbz#771687) - pull up patch for RT#7063, in which not noticing a prompt for a long time throws the client library's idea of the time difference between it - and the KDC really far out of whack (#773496) + and the KDC really far out of whack (rhbz#773496) - add a backport of more patches to set the client's list of supported enctypes when using a keytab to be the list of types of keys in the keytab, plus the list of other types the client supports but for which it doesn't have keys, in that order, so that KDCs have a better chance of being able to issue - tickets with session keys of types that the client can use (#837855) + tickets with session keys of types that the client can use (rhbz#837855) * Thu Sep 6 2012 Nalin Dahyabhai 1.10.3-4 - cut down the number of times we load SELinux labeling configuration from - a minimum of two times to actually one (more of #845125) + a minimum of two times to actually one (more of rhbz#845125) * Thu Aug 30 2012 Nalin Dahyabhai 1.10.3-3 - backport patch to disable replay detection in krb5_verify_init_creds() @@ -1744,7 +2626,7 @@ exit 0 * Thu Aug 2 2012 Nalin Dahyabhai 1.10.2-7 - selinux: hang on to the list of selinux contexts, freeing and reloading it only when the file we read it from is modified, freeing it when the - shared library is being unloaded (#845125) + shared library is being unloaded (rhbz#845125) * Thu Aug 2 2012 Nalin Dahyabhai 1.10.2-6 - go back to not messing with library file paths on Fedora 17: it breaks @@ -1754,7 +2636,7 @@ exit 0 * Tue Jul 31 2012 Nalin Dahyabhai 1.10.2-5 - add upstream patch to fix freeing an uninitialized pointer and dereferencing another uninitialized pointer in the KDC (MITKRB5-SA-2012-001, CVE-2012-1014 - and CVE-2012-1015, #844779 and #844777) + and CVE-2012-1015, rhbz#844779 and rhbz#844777) - fix a thinko in whether or not we mess around with devel .so symlinks on systems without a separate /usr (sbose) @@ -1780,7 +2662,7 @@ exit 0 - add a backport of Stef's patch to set the client's list of supported enctypes to match the types of keys that we have when we are using a keytab to try to get initial credentials, so that a KDC won't send us - an AS reply that we can't encrypt (RT#2131, #748528) + an AS reply that we can't encrypt (RT#2131, rhbz#748528) - don't shuffle around any shared libraries on releases with no-separate-/usr, since /usr/lib is the same place as /lib - add explicit buildrequires: on 'hostname', for the tests, on systems where @@ -1789,15 +2671,15 @@ exit 0 * Mon May 7 2012 Nalin Dahyabhai - skip the setfscreatecon() if fopen() is passed "rb" as the open mode (part - of #819115) + of rhbz#819115) * Tue May 1 2012 Nalin Dahyabhai 1.10.1-3 - have -server require /usr/share/dict/words, which we set as the default - dict_file in kdc.conf (#817089) + dict_file in kdc.conf (rhbz#817089) * Tue Mar 20 2012 Nalin Dahyabhai 1.10.1-2 -- change back dns_lookup_kdc to the default setting (Stef Walter, #805318) -- comment out example.com examples in default krb5.conf (Stef Walter, #805320) +- change back dns_lookup_kdc to the default setting (Stef Walter, rhbz#805318) +- comment out example.com examples in default krb5.conf (Stef Walter, rhbz#805320) * Fri Mar 9 2012 Nalin Dahyabhai 1.10.1-1 - update to 1.10.1 @@ -1808,7 +2690,7 @@ exit 0 * Wed Mar 7 2012 Nalin Dahyabhai 1.10-5 - when removing -workstation, remove our files from the info index while the file is still there, in %%preun, rather than %%postun, and use the - compressed file's name (#801035) + compressed file's name (rhbz#801035) * Tue Feb 21 2012 Nathaniel McCallum - 1.10-4 - Fix string RPC ACLs (RT#7093); CVE-2012-1012 @@ -1818,7 +2700,7 @@ exit 0 * Mon Jan 30 2012 Nalin Dahyabhai 1.10-2 - add patch to accept keytab entries with vno==0 as matches when we're - searching for an entry with a specific name/kvno (#230382/#782211,RT#3349) + searching for an entry with a specific name/kvno (rhbz#230382/rhbz#782211,RT#3349) * Mon Jan 30 2012 Nalin Dahyabhai 1.10-1 - update to 1.10 final @@ -1843,21 +2725,21 @@ exit 0 * Tue Dec 13 2011 Nalin Dahyabhai 1.10-0.alpha1.3 - pull in patch for RT#7046: tag a ccache containing credentials obtained via - S4U2Proxy with the principal name of the proxying principal (part of #761317) + S4U2Proxy with the principal name of the proxying principal (part of rhbz#761317) so that the default principal name can be set to that of the client for which it is proxying, which results in the ccache looking more normal to consumers of the ccache that don't care that there's proxying going on - pull in patch for RT#7047: allow tickets obtained via S4U2Proxy to be cached - (more of #761317) + (more of rhbz#761317) - pull in patch for RT#7048: allow PAC verification to only bother trying to - verify the signature with keys that it's given (still more of #761317) + verify the signature with keys that it's given (still more of rhbz#761317) * Tue Dec 6 2011 Nalin Dahyabhai 1.10-0.alpha1.2 - apply upstream patch to fix a null pointer dereference when processing - TGS requests (CVE-2011-1530, #753748) + TGS requests (CVE-2011-1530, rhbz#753748) * Wed Nov 30 2011 Nalin Dahyabhai 1.10-0.alpha1.1 -- correct a bug in the fix for #754001 so that the file creation context is +- correct a bug in the fix for rhbz#754001 so that the file creation context is consistently reset * Tue Nov 15 2011 Nalin Dahyabhai 1.10-0.alpha1.0 @@ -1872,27 +2754,27 @@ exit 0 should be able to run inside of the build system without issue * Wed Oct 26 2011 Fedora Release Engineering - 1.9.1-19 -- Rebuilt for glibc bug#747377 +- Rebuilt for glibc rhbz#747377 * Tue Oct 18 2011 Nalin Dahyabhai 1.9.1-18 - apply upstream patch to fix a null pointer dereference with the LDAP kdb - backend (CVE-2011-1527, #744125), an assertion failure with multiple kdb + backend (CVE-2011-1527, rhbz#744125), an assertion failure with multiple kdb backends (CVE-2011-1528), and a null pointer dereference with multiple kdb - backends (CVE-2011-1529) (#737711) + backends (CVE-2011-1529) (rhbz#737711) * Thu Oct 13 2011 Nalin Dahyabhai 1.9.1-17 - pull in patch from trunk to rename krb5int_pac_sign() to krb5_pac_sign() and - make it public (#745533) + make it public (rhbz#745533) * Fri Oct 7 2011 Nalin Dahyabhai 1.9.1-16 -- kadmin.service: fix #723723 again +- kadmin.service: fix rhbz#723723 again - kadmin.service,krb5kdc.service: remove optional use of $KRB5REALM in command lines, because systemd parsing doesn't handle alternate value shell variable syntax - kprop.service: add missing Type=forking so that systemd doesn't assume simple - kprop.service: expect the ACL configuration to be there, not absent - handle a harder-to-trigger assertion failure that starts cropping up when we - exit the transmit loop on time (#739853) + exit the transmit loop on time (rhbz#739853) * Sun Oct 2 2011 Tom Callaway 1.9.1-15 - hardcode pid file as option in krb5kdc.service @@ -1905,50 +2787,50 @@ exit 0 * Tue Sep 6 2011 Nalin Dahyabhai 1.9.1-12 - pull in upstream patch for RT#6952, confusion following referrals for - cross-realm auth (#734341) + cross-realm auth (rhbz#734341) - pull in build-time deps for the tests * Thu Sep 1 2011 Nalin Dahyabhai 1.9.1-11 -- switch to the upstream patch for #727829 +- switch to the upstream patch for rhbz#727829 * Wed Aug 31 2011 Nalin Dahyabhai 1.9.1-10 - handle an assertion failure that starts cropping up when the patch for - using poll (#701446) meets servers that aren't running KDCs or against - which the connection fails for other reasons (#727829, #734172) + using poll (rhbz#701446) meets servers that aren't running KDCs or against + which the connection fails for other reasons (rhbz#727829, rhbz#734172) * Mon Aug 8 2011 Nalin Dahyabhai 1.9.1-9 - override the default build rules to not delete temporary y.tab.c files, so that they can be packaged, allowing debuginfo files which point to them - do so usefully (#729044) + do so usefully (rhbz#729044) * Fri Jul 22 2011 Nalin Dahyabhai 1.9.1-8 -- build shared libraries with partial RELRO support (#723995) +- build shared libraries with partial RELRO support (rhbz#723995) - filter out potentially multiple instances of -Wl,-z,relro from krb5-config output, now that it's in the buildroot's default LDFLAGS - pull in a patch to fix losing track of the replay cache FD, from SVN by way of Kevin Coffman * Wed Jul 20 2011 Nalin Dahyabhai 1.9.1-7 -- kadmind.init: drop the attempt to detect no-database-present errors (#723723), +- kadmind.init: drop the attempt to detect no-database-present errors (rhbz#723723), which is too fragile in cases where the database has been manually moved or is accessed through another kdb plugin * Tue Jul 19 2011 Nalin Dahyabhai 1.9.1-6 - backport fixes to teach libkrb5 to use descriptors higher than FD_SETSIZE - to talk to a KDC by using poll() if it's detected at compile-time (#701446, + to talk to a KDC by using poll() if it's detected at compile-time (rhbz#701446, RT#6905) * Thu Jun 23 2011 Nalin Dahyabhai 1.9.1-5 - pull a fix from SVN to try to avoid triggering a PTR lookup in getaddrinfo() during krb5_sname_to_principal(), and to let getaddrinfo() decide whether or not to ask for an IPv6 address based on the set of configured interfaces - (#717378, RT#6922) + (rhbz#717378, RT#6922) - pull a fix from SVN to use AI_ADDRCONFIG more often (RT#6923) * Mon Jun 20 2011 Nalin Dahyabhai 1.9.1-4 - apply upstream patch by way of Burt Holzman to fall back to a non-referral method in cases where we might be derailed by a KDC that rejects the - canonicalize option (for example, those from the RHEL 2.1 or 3 era) (#715074) + canonicalize option (for example, those from the RHEL 2.1 or 3 era) (rhbz#715074) * Tue Jun 14 2011 Nalin Dahyabhai 1.9.1-3 - pull a fix from SVN to get libgssrpc clients (e.g. kadmin) authenticating @@ -1956,13 +2838,13 @@ exit 0 * Tue Jun 14 2011 Nalin Dahyabhai - incorporate a fix to teach the file labeling bits about when replay caches - are expunged (#576093) + are expunged (rhbz#576093) * Thu May 26 2011 Nalin Dahyabhai -- switch to the upstream patch for #707145 +- switch to the upstream patch for rhbz#707145 * Wed May 25 2011 Nalin Dahyabhai 1.9.1-2 -- klist: don't trip over referral entries when invoked with -s (#707145, +- klist: don't trip over referral entries when invoked with -s (rhbz#707145, RT#6915) * Fri May 6 2011 Nalin Dahyabhai @@ -1975,26 +2857,26 @@ exit 0 CVE-2011-0282, CVE-2011-0283, CVE-2011-0284, CVE-2011-0285 * Wed Apr 13 2011 Nalin Dahyabhai 1.9-9 -- kadmind: add upstream patch to fix free() on an invalid pointer (#696343, +- kadmind: add upstream patch to fix free() on an invalid pointer (rhbz#696343, MITKRB5-SA-2011-004, CVE-2011-0285) * Mon Apr 4 2011 Nalin Dahyabhai - don't discard the error code from an error message received in response - to a change-password request (#658871, RT#6893) + to a change-password request (rhbz#658871, RT#6893) * Fri Apr 1 2011 Nalin Dahyabhai - override INSTALL_SETUID at build-time so that ksu is installed into - the buildroot with the right permissions (part of #225974) + the buildroot with the right permissions (part of rhbz#225974) * Fri Mar 18 2011 Nalin Dahyabhai 1.9-8 - backport change from SVN to fix a computed-value-not-used warning in - kpropd (#684065) + kpropd (rhbz#684065) * Tue Mar 15 2011 Nalin Dahyabhai 1.9-7 - turn off NSS as the backend for libk5crypto for now to work around its - DES string2key not working (#679012) + DES string2key not working (rhbz#679012) - add revised upstream patch to fix double-free in KDC while returning - typed-data with errors (MITKRB5-SA-2011-003, CVE-2011-0284, #674325) + typed-data with errors (MITKRB5-SA-2011-003, CVE-2011-0284, rhbz#674325) * Thu Feb 17 2011 Nalin Dahyabhai - throw in a not-applied-by-default patch to try to make pkinit debugging @@ -2007,14 +2889,14 @@ exit 0 * Wed Feb 9 2011 Nalin Dahyabhai 1.9-5 - krb5kdc init script: prototype some changes to do a quick spot-check of the TGS and kadmind keys and warn if there aren't any non-weak keys - on file for them (to flush out parts of #651466) + on file for them (to flush out parts of rhbz#651466) * Tue Feb 8 2011 Nalin Dahyabhai 1.9-4 - add upstream patches to fix standalone kpropd exiting if the per-client child process exits with an error (MITKRB5-SA-2011-001), a hang or crash in the KDC when using the LDAP kdb backend, and an uninitialized pointer - use in the KDC (MITKRB5-SA-2011-002) (CVE-2010-4022, #664009, - CVE-2011-0281, #668719, CVE-2011-0282, #668726, CVE-2011-0283, #676126) + use in the KDC (MITKRB5-SA-2011-002) (CVE-2010-4022, rhbz#664009, + CVE-2011-0281, rhbz#668719, CVE-2011-0282, rhbz#668726, CVE-2011-0283, rhbz#676126) * Mon Feb 07 2011 Fedora Release Engineering - 1.9-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild @@ -2025,11 +2907,11 @@ exit 0 * Tue Feb 1 2011 Nalin Dahyabhai - properly advertise that the kpropd init script now supports force-reload - (Zbysek Mraz, #630587) + (Zbysek Mraz, rhbz#630587) * Wed Jan 26 2011 Nalin Dahyabhai 1.9-2 - pkinit: when verifying signed data, use the CMS APIs for better - interoperability (#636985, RT#6851) + interoperability (rhbz#636985, RT#6851) * Wed Dec 22 2010 Nalin Dahyabhai 1.9-1 - update to 1.9 final @@ -2049,56 +2931,56 @@ exit 0 * Fri Nov 5 2010 Nalin Dahyabhai 1.9-0.beta1.0 - start moving to 1.9 with beta 1 - drop patches for RT#5755, RT#6762, RT#6774, RT#6775 - - drop no-longer-needed backport patch for #539423 + - drop no-longer-needed backport patch for rhbz#539423 - drop no-longer-needed patch for CVE-2010-1322 - if WITH_NSS is set, built with --with-crypto-impl=nss (requires NSS 3.12.9) * Tue Oct 5 2010 Nalin Dahyabhai 1.8.3-8 - incorporate upstream patch to fix uninitialized pointer crash in the KDC's - authorization data handling (CVE-2010-1322, #636335) + authorization data handling (CVE-2010-1322, rhbz#636335) * Mon Oct 4 2010 Nalin Dahyabhai 1.8.3-7 - rebuild * Mon Oct 4 2010 Nalin Dahyabhai 1.8.3-6 - pull down patches from trunk to implement k5login_authoritative and - k5login_directory settings for krb5.conf (#539423) + k5login_directory settings for krb5.conf (rhbz#539423) * Wed Sep 29 2010 jkeating - 1.8.3-5 -- Rebuilt for gcc bug 634757 +- Rebuilt for gcc rhbz#634757 * Wed Sep 15 2010 Nalin Dahyabhai 1.8.3-4 - fix reading of keyUsage extensions when attempting to select pkinit client - certs (part of #629022, RT#6775) + certs (part of rhbz#629022, RT#6775) - fix selection of pkinit client certs when one or more don't include a - subjectAltName extension (part of #629022, RT#6774) + subjectAltName extension (part of rhbz#629022, RT#6774) * Fri Sep 3 2010 Nalin Dahyabhai 1.8.3-3 - build with -fstack-protector-all instead of the default -fstack-protector, - so that we add checking to more functions (i.e., all of them) (#629950) -- also link binaries with -Wl,-z,relro,-z,now (part of #629950) + so that we add checking to more functions (i.e., all of them) (rhbz#629950) +- also link binaries with -Wl,-z,relro,-z,now (part of rhbz#629950) * Tue Aug 24 2010 Nalin Dahyabhai 1.8.3-2 -- fix a logic bug in computing key expiration times (RT#6762, #627022) +- fix a logic bug in computing key expiration times (RT#6762, rhbz#627022) * Wed Aug 4 2010 Nalin Dahyabhai 1.8.3-1 - update to 1.8.3 - drop backports of fixes for gss context expiration and error table registration/deregistration mismatch - - drop patch for upstream #6750 + - drop patch for upstream rhbz#6750 * Wed Jul 7 2010 Nalin Dahyabhai 1.8.2-3 - tell krb5kdc and kadmind to create pid files, since they can -- add logrotate configuration files for krb5kdc and kadmind (#462658) -- fix parsing of the pidfile option in the KDC (upstream #6750) +- add logrotate configuration files for krb5kdc and kadmind (rhbz#462658) +- fix parsing of the pidfile option in the KDC (upstream rhbz#6750) * Mon Jun 21 2010 Nalin Dahyabhai 1.8.2-2 - libgssapi: pull in patch from svn to stop returning context-expired errors - when the ticket which was used to set up the context expires (#605366, - upstream #6739) + when the ticket which was used to set up the context expires (rhbz#605366, + upstream rhbz#6739) * Mon Jun 21 2010 Nalin Dahyabhai -- pull up fix for upstream #6745, in which the gssapi library would add the +- pull up fix for upstream rhbz#6745, in which the gssapi library would add the wrong error table but subsequently attempt to unload the right one * Thu Jun 10 2010 Nalin Dahyabhai 1.8.2-1 @@ -2110,8 +2992,8 @@ exit 0 * Thu May 27 2010 Nalin Dahyabhai - ksu: move session management calls to before we drop privileges, like - su does (#596887), and don't skip the PAM account check for root or the - same user (more of #540769) + su does (rhbz#596887), and don't skip the PAM account check for root or the + same user (more of rhbz#540769) * Mon May 24 2010 Nalin Dahyabhai 1.8.1-6 - make krb5-server-ldap also depend on the same version-release of krb5-libs, @@ -2124,20 +3006,20 @@ exit 0 * Tue May 18 2010 Nalin Dahyabhai 1.8.1-5 - add patch to correct GSSAPI library null pointer dereference which could be - triggered by malformed client requests (CVE-2010-1321, #582466) + triggered by malformed client requests (CVE-2010-1321, rhbz#582466) * Tue May 4 2010 Nalin Dahyabhai 1.8.1-4 -- fix output of kprop's init script's "status" and "reload" commands (#588222) +- fix output of kprop's init script's "status" and "reload" commands (rhbz#588222) * Tue Apr 20 2010 Nalin Dahyabhai 1.8.1-3 -- incorporate patch to fix double-free in the KDC (CVE-2010-1320, #581922) +- incorporate patch to fix double-free in the KDC (CVE-2010-1320, rhbz#581922) * Wed Apr 14 2010 Nalin Dahyabhai 1.8.1-2 - fix a typo in kerberos.ldif * Fri Apr 9 2010 Nalin Dahyabhai 1.8.1-1 - update to 1.8.1 - - no longer need patches for #555875, #561174, #563431, RT#6661, CVE-2010-0628 + - no longer need patches for rhbz#555875, rhbz#561174, rhbz#563431, RT#6661, CVE-2010-0628 - replace buildrequires on tetex-latex with one on texlive-latex, which is the package that provides it now @@ -2147,21 +3029,21 @@ exit 0 * Thu Apr 8 2010 Nalin Dahyabhai - drop patch to suppress key expiration warnings sent from the KDC in the last-req field, as the KDC is expected to just be configured to either - send them or not as a particular key approaches expiration (#556495) + send them or not as a particular key approaches expiration (rhbz#556495) * Tue Mar 23 2010 Nalin Dahyabhai - 1.8-5 -- add upstream fix for denial-of-service in SPNEGO (CVE-2010-0628, #576325) +- add upstream fix for denial-of-service in SPNEGO (CVE-2010-0628, rhbz#576325) - kdc.conf: no more need to suggest keeping keys with v4-compatible salting * Fri Mar 19 2010 Nalin Dahyabhai - 1.8-4 - remove the krb5-appl bits (the -workstation-clients and -workstation-servers subpackages) now that krb5-appl is its own package -- replace our patch for #563431 (kpasswd doesn't fall back to guessing your +- replace our patch for rhbz#563431 (kpasswd doesn't fall back to guessing your principal name using your user name if you don't have a ccache) with the one upstream uses * Fri Mar 12 2010 Nalin Dahyabhai - 1.8-3 -- add documentation for the ticket_lifetime option (#561174) +- add documentation for the ticket_lifetime option (rhbz#561174) * Mon Mar 8 2010 Nalin Dahyabhai - 1.8-2 - pull up patch to get the client libraries to correctly perform password @@ -2181,28 +3063,28 @@ exit 0 - fix a null pointer dereference and crash introduced in our PAM patch that would happen if ftpd was given the name of a user who wasn't known to the local system, limited to being triggerable by gssapi-authenticated clients by - the default xinetd config (Olivier Fourdan, #569472) + the default xinetd config (Olivier Fourdan, rhbz#569472) * Tue Mar 2 2010 Nalin Dahyabhai - 1.7.1-5 -- fix a regression (not labeling a kdb database lock file correctly, #569902) +- fix a regression (not labeling a kdb database lock file correctly, rhbz#569902) * Thu Feb 25 2010 Nalin Dahyabhai - 1.7.1-4 - move the package changelog to the end to match the usual style (jdennis) -- scrub out references to $RPM_SOURCE_DIR (jdennis) +- scrub out references to RPM_SOURCE_DIR (jdennis) - include a symlink to the readme with the name LICENSE so that people can find it more easily (jdennis) * Wed Feb 17 2010 Nalin Dahyabhai - 1.7.1-3 - pull up the change to make kpasswd's behavior better match the docs - when there's no ccache (#563431) + when there's no ccache (rhbz#563431) * Tue Feb 16 2010 Nalin Dahyabhai - 1.7.1-2 - apply patch from upstream to fix KDC denial of service (CVE-2010-0283, - #566002) + rhbz#566002) * Wed Feb 3 2010 Nalin Dahyabhai - 1.7.1-1 - update to 1.7.1 - - don't trip AD lockout on wrong password (#542687, #554351) + - don't trip AD lockout on wrong password (rhbz#542687, rhbz#554351) - incorporates fixes for CVE-2009-4212 and CVE-2009-3295 - fixes gss_krb5_copy_ccache() when SPNEGO is used - move sim_client/sim_server, gss-client/gss-server, uuclient/uuserver to @@ -2212,7 +3094,7 @@ exit 0 depends on -workstation which also includes them * Mon Jan 25 2010 Nalin Dahyabhai - 1.7-23 -- tighten up default permissions on kdc.conf and kadm5.acl (#558343) +- tighten up default permissions on kdc.conf and kadm5.acl (rhbz#558343) * Fri Jan 22 2010 Nalin Dahyabhai - 1.7-22 - use portreserve correctly -- portrelease takes the basename of the file @@ -2221,47 +3103,47 @@ exit 0 * Mon Jan 18 2010 Nalin Dahyabhai - 1.7-21 - suppress warnings of impending password expiration if expiration is more than seven days away when the KDC reports it via the last-req field, just as we - already do when it reports expiration via the key-expiration field (#556495) + already do when it reports expiration via the key-expiration field (rhbz#556495) - link with libtinfo rather than libncurses, when we can, in future RHEL * Fri Jan 15 2010 Nalin Dahyabhai - 1.7-20 - krb5_get_init_creds_password: check opte->flags instead of options->flags - when checking whether or not we get to use the prompter callback (#555875) + when checking whether or not we get to use the prompter callback (rhbz#555875) * Thu Jan 14 2010 Nalin Dahyabhai - 1.7-19 - use portreserve to make sure the KDC can always bind to the kerberos-iv port, kpropd can always bind to the krb5_prop port, and that kadmind can - always bind to the kerberos-adm port (#555279) + always bind to the kerberos-adm port (rhbz#555279) - correct inadvertent use of macros in the changelog (rpmlint) * Tue Jan 12 2010 Nalin Dahyabhai - 1.7-18 - add upstream patch for integer underflow during AES and RC4 decryption - (CVE-2009-4212), via Tom Yu (#545015) + (CVE-2009-4212), via Tom Yu (rhbz#545015) * Wed Jan 6 2010 Nalin Dahyabhai - 1.7-17 - put the conditional back for the -devel subpackage -- back down to the earlier version of the patch for #551764; the backported +- back down to the earlier version of the patch for rhbz#551764; the backported alternate version was incomplete * Tue Jan 5 2010 Nalin Dahyabhai - 1.7-16 - use %%global instead of %%define - pull up proposed patch for creating previously-not-there lock files for - kdb databases when 'kdb5_util' is called to 'load' (#551764) + kdb databases when 'kdb5_util' is called to 'load' (rhbz#551764) * Mon Jan 4 2010 Dennis Gregorovic - fix conditional for future RHEL * Mon Jan 4 2010 Nalin Dahyabhai - 1.7-15 - add upstream patch for KDC crash during referral processing (CVE-2009-3295), - via Tom Yu (#545002) + via Tom Yu (rhbz#545002) * Mon Dec 21 2009 Nalin Dahyabhai - 1.7-14 -- refresh patch for #542868 from trunk +- refresh patch for rhbz#542868 from trunk * Thu Dec 10 2009 Nalin Dahyabhai - move man pages that live in the -libs subpackage into the regular %%{_mandir} tree where they'll still be found if that package is the - only one installed (#529319) + only one installed (rhbz#529319) * Wed Dec 9 2009 Nalin Dahyabhai - 1.7-13 - and put it back in @@ -2270,14 +3152,14 @@ exit 0 - back that last change out * Tue Dec 8 2009 Nalin Dahyabhai - 1.7-12 -- try to make gss_krb5_copy_ccache() work correctly for spnego (#542868) +- try to make gss_krb5_copy_ccache() work correctly for spnego (rhbz#542868) * Fri Dec 4 2009 Nalin Dahyabhai -- make krb5-config suppress CFLAGS output when called with --libs (#544391) +- make krb5-config suppress CFLAGS output when called with --libs (rhbz#544391) * Thu Dec 3 2009 Nalin Dahyabhai - 1.7-11 - ksu: move account management checks to before we drop privileges, like - su does (#540769) + su does (rhbz#540769) - selinux: set the user part of file creation contexts to match the current context instead of what we looked up - configure with --enable-dns-for-realm instead of --enable-dns, which isn't @@ -2285,7 +3167,7 @@ exit 0 * Fri Nov 20 2009 Nalin Dahyabhai - 1.7-10 - move /etc/pam.d/ksu from krb5-workstation-servers to krb5-workstation, - where it's actually needed (#538703) + where it's actually needed (rhbz#538703) * Fri Oct 23 2009 Nalin Dahyabhai - 1.7-9 - add some conditional logic to simplify building on older Fedora releases @@ -2296,11 +3178,11 @@ exit 0 * Mon Sep 14 2009 Nalin Dahyabhai - 1.7-8 - specify the location of the subsystem lock when using the status() function in the kadmind and kpropd init scripts, so that we get the right error when - we're dead but have a lock file - requires initscripts 8.99 (#521772) + we're dead but have a lock file - requires initscripts 8.99 (rhbz#521772) * Tue Sep 8 2009 Nalin Dahyabhai - if the init script fails to start krb5kdc/kadmind/kpropd because it's already - running (according to status()), return 0 (part of #521772) + running (according to status()), return 0 (part of rhbz#521772) * Mon Aug 24 2009 Nalin Dahyabhai - 1.7-7 - work around a compile problem with new openssl @@ -2359,7 +3241,7 @@ exit 0 - drop static build logic - drop pam_krb5-specific configuration from the default krb5.conf - drop only-use-v5 flags being passed to various things started by xinetd -- put %%{krb5prefix}/sbin in everyone's path, too (#504525) +- put %%{krb5prefix}/sbin in everyone's path, too (rhbz#504525) * Tue May 19 2009 Nalin Dahyabhai 1.6.3-106 - add an auth stack to ksu's PAM configuration so that pam_setcred() calls @@ -2383,7 +3265,7 @@ exit 0 - add LSB-style init script info * Fri Apr 17 2009 Nalin Dahyabhai -- explicitly run the pdf generation script using sh (part of #225974) +- explicitly run the pdf generation script using sh (part of rhbz#225974) * Tue Apr 7 2009 Nalin Dahyabhai 1.6.3-101 - add patches for read overflow and null pointer dereference in the @@ -2399,14 +3281,14 @@ exit 0 - use triggeruns to properly shut down and disable krb524d when -server and -workstation-servers gets upgraded, because it's gone now - move the libraries to /%%{_lib}, but leave --libdir alone so that plugins - get installed and are searched for in the same locations (#473333) + get installed and are searched for in the same locations (rhbz#473333) - clean up buildprereq/prereqs, explicit mktemp requires, and add the - ldconfig for the -server-ldap subpackage (part of #225974) -- escape possible macros in the changelog (part of #225974) -- fixup summary texts (part of #225974) -- take the execute bit off of the protocol docs (part of #225974) -- unflag init scripts as configuration files (part of #225974) -- make the kpropd init script treat 'reload' as 'restart' (part of #225974) + ldconfig for the -server-ldap subpackage (part of rhbz#225974) +- escape possible macros in the changelog (part of rhbz#225974) +- fixup summary texts (part of rhbz#225974) +- take the execute bit off of the protocol docs (part of rhbz#225974) +- unflag init scripts as configuration files (part of rhbz#225974) +- make the kpropd init script treat 'reload' as 'restart' (part of rhbz#225974) * Tue Mar 17 2009 Nalin Dahyabhai 1.6.3-19 - libgssapi_krb5: backport fix for some errors which can occur when @@ -2421,7 +3303,7 @@ exit 0 * Thu Sep 4 2008 Nalin Dahyabhai - if we successfully change the user's password during an attempt to get initial credentials, but then fail to get initial creds from a non-master - using the new password, retry against the master (#432334) + using the new password, retry against the master (rhbz#432334) * Tue Aug 5 2008 Tom "spot" Callaway 1.6.3-16 - fix license tag @@ -2444,7 +3326,7 @@ exit 0 * Wed Apr 16 2008 Nalin Dahyabhai 1.6.3-13 - ftp: use the correct local filename during mget when the 'case' option is - enabled (#442713) + enabled (rhbz#442713) * Fri Apr 4 2008 Nalin Dahyabhai 1.6.3-12 - stop exporting kadmin keys to a keytab file when kadmind starts -- the @@ -2458,17 +3340,17 @@ exit 0 * Tue Mar 18 2008 Nalin Dahyabhai 1.6.3-10 - add fixes from MITKRB5-SA-2008-001 for use of null or dangling pointer when v4 compatibility is enabled on the KDC (CVE-2008-0062, CVE-2008-0063, - #432620, #432621) + rhbz#432620, rhbz#432621) - add fixes from MITKRB5-SA-2008-002 for array out-of-bounds accesses when - high-numbered descriptors are used (CVE-2008-0947, #433596) + high-numbered descriptors are used (CVE-2008-0947, rhbz#433596) - add backport bug fix for an attempt to free non-heap memory in - libgssapi_krb5 (CVE-2007-5901, #415321) + libgssapi_krb5 (CVE-2007-5901, rhbz#415321) - add backport bug fix for a double-free in out-of-memory situations in - libgssapi_krb5 (CVE-2007-5971, #415351) + libgssapi_krb5 (CVE-2007-5971, rhbz#415351) * Tue Mar 18 2008 Nalin Dahyabhai 1.6.3-9 - rework file labeling patch to not depend on fragile preprocessor trickery, - in another attempt at fixing #428355 and friends + in another attempt at fixing rhbz#428355 and friends * Tue Feb 26 2008 Nalin Dahyabhai 1.6.3-8 - ftp: add patch to fix "runique on" case when globbing fixes applied @@ -2476,12 +3358,12 @@ exit 0 * Mon Feb 25 2008 Nalin Dahyabhai - add patch to suppress double-processing of /etc/krb5.conf when we build - with --sysconfdir=/etc, thereby suppressing double-logging (#231147) + with --sysconfdir=/etc, thereby suppressing double-logging (rhbz#231147) * Mon Feb 25 2008 Nalin Dahyabhai - remove a patch, to fix problems with interfaces which are "up" but which have no address assigned, which conflicted with a different fix for the same - problem in 1.5 (#200979) + problem in 1.5 (rhbz#200979) * Mon Feb 25 2008 Nalin Dahyabhai - ftp: don't lose track of a descriptor on passive get when the server fails to @@ -2505,22 +3387,22 @@ exit 0 * Tue Feb 12 2008 Nalin Dahyabhai 1.6.3-5 - enable patch for key-expiration reporting -- enable patch to make kpasswd fall back to TCP if UDP fails (#251206) +- enable patch to make kpasswd fall back to TCP if UDP fails (rhbz#251206) - enable patch to make kpasswd use the right sequence number on retransmit - enable patch to allow mech-specific creds delegated under spnego to be found when searching for creds * Wed Jan 2 2008 Nalin Dahyabhai 1.6.3-4 - some init script cleanups - - drop unquoted check and silent exit for "$NETWORKING" (#426852, #242502) + - drop unquoted check and silent exit for "$NETWORKING" (rhbz#426852, rhbz#242502) - krb524: don't barf on missing database if it looks like we're using kldap, same as for kadmin - return non-zero status for missing files which cause startup to - fail (#242502) + fail (rhbz#242502) * Tue Dec 18 2007 Nalin Dahyabhai 1.6.3-3 - allocate space for the nul-terminator in the local pathname when looking up - a file context, and properly free a previous context (Jose Plans, #426085) + a file context, and properly free a previous context (Jose Plans, rhbz#426085) * Wed Dec 5 2007 Nalin Dahyabhai 1.6.3-2 - rebuild @@ -2536,7 +3418,7 @@ exit 0 * Fri Oct 12 2007 Nalin Dahyabhai - make krb5.conf %%verify(not md5 size mtime) in addition to - %%config(noreplace), like /etc/nsswitch.conf (#329811) + %%config(noreplace), like /etc/nsswitch.conf (rhbz#329811) * Mon Oct 1 2007 Nalin Dahyabhai 1.6.2-9 - apply the fix for CVE-2007-4000 instead of the experimental patch for @@ -2553,7 +3435,7 @@ exit 0 * Thu Sep 6 2007 Nalin Dahyabhai 1.6.2-6 - incorporate updated fix for CVE-2007-3999 (CVE-2007-4743) -- fix incorrect call to "test" in the kadmin init script (#252322,#287291) +- fix incorrect call to "test" in the kadmin init script (rhbz#252322,rhbz#287291) * Tue Sep 4 2007 Nalin Dahyabhai 1.6.2-5 - incorporate fixes for MITKRB5-SA-2007-006 (CVE-2007-3999, CVE-2007-4000) @@ -2566,7 +3448,7 @@ exit 0 - rebuild * Thu Jul 26 2007 Nalin Dahyabhai 1.6.2-2 -- kdc.conf: default to listening for TCP clients, too (#248415) +- kdc.conf: default to listening for TCP clients, too (rhbz#248415) * Thu Jul 19 2007 Nalin Dahyabhai 1.6.2-1 - update to 1.6.2 @@ -2592,13 +3474,13 @@ exit 0 - rebuild * Sun Jun 24 2007 Nalin Dahyabhai 1.6.1-3 -- label all files at creation-time according to the SELinux policy (#228157) +- label all files at creation-time according to the SELinux policy (rhbz#228157) * Fri Jun 22 2007 Nalin Dahyabhai -- perform PAM account / session management in krshd (#182195,#195922) +- perform PAM account / session management in krshd (rhbz#182195,rhbz#195922) - perform PAM authentication and account / session management in ftpd - perform PAM authentication, account / session management, and password- - changing in login.krb5 (#182195,#195922) + changing in login.krb5 (rhbz#182195,rhbz#195922) * Fri Jun 22 2007 Nalin Dahyabhai - preprocess kerberos.ldif into a format FDS will like better, and include @@ -2608,7 +3490,7 @@ exit 0 - switch man pages to being generated with the right paths in them - drop old, incomplete SELinux patch - add patch from Greg Hudson to make srvtab routines report missing-file errors - at same point that keytab routines do (#241805) + at same point that keytab routines do (rhbz#241805) * Thu May 24 2007 Nalin Dahyabhai 1.6.1-2 - pull patch from svn to undo unintentional chattiness in ftp @@ -2629,7 +3511,7 @@ exit 0 * Wed May 16 2007 Nalin Dahyabhai 1.6-6 - omit dependent libraries from the krb5-config --libs output, as using shared libraries (no more static libraries) makes them unnecessary and - they're not part of the libkrb5 interface (patch by Rex Dieter, #240220) + they're not part of the libkrb5 interface (patch by Rex Dieter, rhbz#240220) (strips out libkeyutils, libresolv, libdl) * Fri May 4 2007 Nalin Dahyabhai 1.6-5 @@ -2644,17 +3526,17 @@ exit 0 * Fri Apr 13 2007 Nalin Dahyabhai - move the default acl_file, dict_file, and admin_keytab settings to the part of the default/example kdc.conf where they'll actually have - an effect (#236417) + an effect (rhbz#236417) * Thu Apr 5 2007 Nalin Dahyabhai 1.5-24 - merge security fixes from RHSA-2007:0095 * Tue Apr 3 2007 Nalin Dahyabhai 1.6-3 - add patch to correct unauthorized access via krb5-aware telnet - daemon (#229782, CVE-2007-0956) + daemon (rhbz#229782, CVE-2007-0956) - add patch to fix buffer overflow in krb5kdc and kadmind - (#231528, CVE-2007-0957) -- add patch to fix double-free in kadmind (#231537, CVE-2007-1216) + (rhbz#231528, CVE-2007-0957) +- add patch to fix double-free in kadmind (rhbz#231537, CVE-2007-1216) * Thu Mar 22 2007 Nalin Dahyabhai - back out buildrequires: keyutils-libs-devel for now @@ -2670,19 +3552,19 @@ exit 0 * Thu Mar 15 2007 Nalin Dahyabhai 1.5-21 - add preliminary patch to fix buffer overflow in krb5kdc and kadmind - (#231528, CVE-2007-0957) -- add preliminary patch to fix double-free in kadmind (#231537, CVE-2007-1216) + (rhbz#231528, CVE-2007-0957) +- add preliminary patch to fix double-free in kadmind (rhbz#231537, CVE-2007-1216) * Wed Feb 28 2007 Nalin Dahyabhai - add patch to build semi-useful static libraries, but don't apply it unless we need them * Tue Feb 27 2007 Nalin Dahyabhai - 1.5-20 -- temporarily back out %%post changes, fix for #143289 for security update +- temporarily back out %%post changes, fix for rhbz#143289 for security update - add preliminary patch to correct unauthorized access via krb5-aware telnet * Mon Feb 19 2007 Nalin Dahyabhai -- make profile.d scriptlets mode 644 instead of 755 (part of #225974) +- make profile.d scriptlets mode 644 instead of 755 (part of rhbz#225974) * Tue Jan 30 2007 Nalin Dahyabhai 1.6-1 - clean up quoting of command-line arguments passed to the krsh/krlogin @@ -2690,22 +3572,22 @@ exit 0 * Mon Jan 22 2007 Nalin Dahyabhai - initial update to 1.6, pre-package-reorg -- move workstation daemons to a new subpackage (#81836, #216356, #217301), and - make the new subpackage require xinetd (#211885) +- move workstation daemons to a new subpackage (rhbz#81836, rhbz#216356, rhbz#217301), and + make the new subpackage require xinetd (rhbz#211885) * Mon Jan 22 2007 Nalin Dahyabhai - 1.5-18 -- make use of install-info more failsafe (Ville Skyttä, #223704) +- make use of install-info more failsafe (Ville Skyttä, rhbz#223704) - preserve timestamps on shell scriptlets at %%install-time * Tue Jan 16 2007 Nalin Dahyabhai - 1.5-17 -- move to using pregenerated PDF docs to cure multilib conflicts (#222721) +- move to using pregenerated PDF docs to cure multilib conflicts (rhbz#222721) * Fri Jan 12 2007 Nalin Dahyabhai - 1.5-16 -- update backport of the preauth module interface (part of #194654) +- update backport of the preauth module interface (part of rhbz#194654) * Tue Jan 9 2007 Nalin Dahyabhai - 1.5-14 -- apply fixes from Tom Yu for MITKRB5-SA-2006-002 (CVE-2006-6143) (#218456) -- apply fixes from Tom Yu for MITKRB5-SA-2006-003 (CVE-2006-6144) (#218456) +- apply fixes from Tom Yu for MITKRB5-SA-2006-002 (CVE-2006-6143) (rhbz#218456) +- apply fixes from Tom Yu for MITKRB5-SA-2006-003 (CVE-2006-6144) (rhbz#218456) * Wed Dec 20 2006 Nalin Dahyabhai - 1.5-12 - update backport of the preauth module interface @@ -2723,21 +3605,21 @@ exit 0 been applicable for a while * Wed Oct 18 2006 Nalin Dahyabhai - 1.5-10 -- rename krb5.sh and krb5.csh so that they don't overlap (#210623) -- way-late application of added error info in kadmind.init (#65853) +- rename krb5.sh and krb5.csh so that they don't overlap (rhbz#210623) +- way-late application of added error info in kadmind.init (rhbz#65853) * Wed Oct 18 2006 Nalin Dahyabhai - 1.5-9.pal_18695 -- add backport of in-development preauth module interface (#208643) +- add backport of in-development preauth module interface (rhbz#208643) * Mon Oct 9 2006 Nalin Dahyabhai - 1.5-9 -- provide docs in PDF format instead of as tex source (Enrico Scholz, #209943) +- provide docs in PDF format instead of as tex source (Enrico Scholz, rhbz#209943) * Wed Oct 4 2006 Nalin Dahyabhai - 1.5-8 -- add missing shebang headers to krsh and krlogin wrapper scripts (#209238) +- add missing shebang headers to krsh and krlogin wrapper scripts (rhbz#209238) * Wed Sep 6 2006 Nalin Dahyabhai - 1.5-7 - set SS_LIB at configure-time so that libss-using apps get working readline - support (#197044) + support (rhbz#197044) * Fri Aug 18 2006 Nalin Dahyabhai - 1.5-6 - switch to the updated patch for MITKRB-SA-2006-001 @@ -2748,7 +3630,7 @@ exit 0 * Mon Aug 7 2006 Nalin Dahyabhai - 1.5-4 - ensure that the gssapi library's been initialized before walking the internal mechanism list in gss_release_oid(), needed if called from - gss_release_name() right after a gss_import_name() (#198092) + gss_release_name() right after a gss_import_name() (rhbz#198092) * Tue Jul 25 2006 Nalin Dahyabhai - 1.5-3 - rebuild @@ -2769,7 +3651,7 @@ exit 0 - update to 1.5 * Fri Jun 23 2006 Nalin Dahyabhai 1.4.3-9 -- mark profile.d config files noreplace (Laurent Rineau, #196447) +- mark profile.d config files noreplace (Laurent Rineau, rhbz#196447) * Thu Jun 8 2006 Nalin Dahyabhai 1.4.3-8 - add buildprereq for autoconf @@ -2777,11 +3659,11 @@ exit 0 * Mon May 22 2006 Nalin Dahyabhai 1.4.3-7 - further munge krb5-config so that 'libdir=/usr/lib' is given even on 64-bit architectures, to avoid multilib conflicts; other changes will conspire to - strip out the -L flag which uses this, so it should be harmless (#192692) + strip out the -L flag which uses this, so it should be harmless (rhbz#192692) * Fri Apr 28 2006 Nalin Dahyabhai 1.4.3-6 - adjust the patch which removes the use of rpath to also produce a - krb5-config which is okay in multilib environments (#190118) + krb5-config which is okay in multilib environments (rhbz#190118) - make the name-of-the-tempfile comment which compile_et adds to error code headers always list the same file to avoid conflicts on multilib installations - strip SIZEOF_LONG out of krb5.h so that it doesn't conflict on multilib boxes @@ -2796,7 +3678,7 @@ exit 0 * Mon Feb 6 2006 Nalin Dahyabhai 1.4.3-4 - give a little bit more information to the user when kinit gets the catch-all - I/O error (#180175) + I/O error (rhbz#180175) * Thu Jan 19 2006 Nalin Dahyabhai 1.4.3-3 - rebuild properly when pthread_mutexattr_setrobust_np() is defined but not @@ -2810,23 +3692,23 @@ exit 0 * Thu Dec 1 2005 Nalin Dahyabhai - login: don't truncate passwords before passing them into crypt(), in - case they're significant (#149476) + case they're significant (rhbz#149476) * Thu Nov 17 2005 Nalin Dahyabhai 1.4.3-1 - update to 1.4.3 -- make ksu setuid again (#137934, others) +- make ksu setuid again (rhbz#137934, others) * Tue Sep 13 2005 Nalin Dahyabhai 1.4.2-4 - mark %%{krb5prefix}/man so that files which are packaged within it are - flagged as %%doc (#168163) + flagged as %%doc (rhbz#168163) * Tue Sep 6 2005 Nalin Dahyabhai 1.4.2-3 - add an xinetd configuration file for encryption-only telnetd, parallelling - the kshell/ekshell pair (#167535) + the kshell/ekshell pair (rhbz#167535) * Wed Aug 31 2005 Nalin Dahyabhai 1.4.2-2 - change the default configured encryption type for KDC databases to the - compiled-in default of des3-hmac-sha1 (#57847) + compiled-in default of des3-hmac-sha1 (rhbz#57847) * Thu Aug 11 2005 Nalin Dahyabhai 1.4.2-1 - update to 1.4.2, incorporating the fixes for MIT-KRB5-SA-2005-002 and @@ -2837,23 +3719,23 @@ exit 0 * Wed Jun 29 2005 Nalin Dahyabhai 1.4.1-5 - fix telnet client environment variable disclosure the same way NetKit's - telnet client did (CAN-2005-0488) (#159305) + telnet client did (CAN-2005-0488) (rhbz#159305) - keep apps which call krb5_principal_compare() or krb5_realm_compare() with malformed or NULL principal structures from crashing outright (Thomas Biege) - (#161475) + (rhbz#161475) * Tue Jun 28 2005 Nalin Dahyabhai - apply fixes from draft of MIT-KRB5-SA-2005-002 (CAN-2005-1174,CAN-2005-1175) - (#157104) -- apply fixes from draft of MIT-KRB5-SA-2005-003 (CAN-2005-1689) (#159755) + (rhbz#157104) +- apply fixes from draft of MIT-KRB5-SA-2005-003 (CAN-2005-1689) (rhbz#159755) * Fri Jun 24 2005 Nalin Dahyabhai 1.4.1-4 - fix double-close in keytab handling -- add port of fixes for CAN-2004-0175 to krb5-aware rcp (#151612) +- add port of fixes for CAN-2004-0175 to krb5-aware rcp (rhbz#151612) * Fri May 13 2005 Nalin Dahyabhai 1.4.1-3 - prevent spurious EBADF in krshd when stdin is closed by the client while - the command is running (#151111) + the command is running (rhbz#151111) * Fri May 13 2005 Martin Stransky 1.4.1-2 - add deadlock patch, removed old patch @@ -2912,18 +3794,18 @@ exit 0 - rebuild * Mon Nov 22 2004 Nalin Dahyabhai 1.3.5-3 -- fix predictable-tempfile-name bug in krb5-send-pr (CAN-2004-0971, #140036) +- fix predictable-tempfile-name bug in krb5-send-pr (CAN-2004-0971, rhbz#140036) * Tue Nov 16 2004 Nalin Dahyabhai - silence compiler warning in kprop by using an in-memory ccache with a fixed name instead of an on-disk ccache with a name generated by tmpnam() * Tue Nov 16 2004 Nalin Dahyabhai 1.3.5-2 -- fix globbing patch port mode (#139075) +- fix globbing patch port mode (rhbz#139075) * Mon Nov 1 2004 Nalin Dahyabhai 1.3.5-1 - fix segfault in telnet due to incorrect checking of gethostbyname_r result - codes (#129059) + codes (rhbz#129059) * Fri Oct 15 2004 Nalin Dahyabhai - remove rc4-hmac:norealm and rc4-hmac:onlyrealm from the default list of @@ -2948,11 +3830,11 @@ exit 0 * Mon Aug 23 2004 Nalin Dahyabhai 1.3.4-3 - incorporate fixes from Tom Yu for CAN-2004-0642, CAN-2004-0772 - (MITKRB5-SA-2004-002, #130732) -- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, #130732) + (MITKRB5-SA-2004-002, rhbz#130732) +- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, rhbz#130732) * Tue Jul 27 2004 Nalin Dahyabhai 1.3.4-2 -- fix indexing error in server sorting patch (#127336) +- fix indexing error in server sorting patch (rhbz#127336) * Tue Jun 15 2004 Elliot Lee - rebuilt @@ -2977,7 +3859,7 @@ exit 0 - rebuild * Tue Jun 1 2004 Nalin Dahyabhai 1.3.3-4 -- apply patch from MITKRB5-SA-2004-001 (#125001) +- apply patch from MITKRB5-SA-2004-001 (rhbz#125001) * Wed May 12 2004 Thomas Woerner 1.3.3-3 - removed rpath @@ -3007,17 +3889,17 @@ exit 0 * Mon Feb 2 2004 Nalin Dahyabhai 1.3.1-9 - remove patch to set TERM in klogind which, combined with the upstream fix in - 1.3.1, actually produces the bug now (#114762) + 1.3.1, actually produces the bug now (rhbz#114762) * Mon Jan 19 2004 Nalin Dahyabhai 1.3.1-8 - when iterating over lists of interfaces which are "up" from getifaddrs(), - skip over those which have no address (#113347) + skip over those which have no address (rhbz#113347) * Mon Jan 12 2004 Nalin Dahyabhai - prefer the kdc which last replied to a request when sending requests to kdcs * Mon Nov 24 2003 Nalin Dahyabhai 1.3.1-7 -- fix combination of --with-netlib and --enable-dns (#82176) +- fix combination of --with-netlib and --enable-dns (rhbz#82176) * Tue Nov 18 2003 Nalin Dahyabhai - remove libdefault ticket_lifetime option from the default krb5.conf, it is @@ -3226,12 +4108,12 @@ exit 0 * Wed Jun 27 2001 Nalin Dahyabhai - add patch to support "ANY" keytab type (i.e., "default_keytab_name = ANY:FILE:/etc/krb5.keytab,SRVTAB:/etc/srvtab" - patch from Gerald Britton, #42551) -- build with -D_FILE_OFFSET_BITS=64 to get large file I/O in ftpd (#30697) + patch from Gerald Britton, rhbz#42551) +- build with -D_FILE_OFFSET_BITS=64 to get large file I/O in ftpd (rhbz#30697) - patch ftpd to use long long and %%lld format specifiers to support the SIZE - command on large files (also #30697) -- don't use LOG_AUTH as an option value when calling openlog() in ksu (#45965) -- implement reload in krb5kdc and kadmind init scripts (#41911) + command on large files (also rhbz#30697) +- don't use LOG_AUTH as an option value when calling openlog() in ksu (rhbz#45965) +- implement reload in krb5kdc and kadmind init scripts (rhbz#41911) - lose the krb5server init script (not using it any more) * Sun Jun 24 2001 Elliot Lee @@ -3244,7 +4126,7 @@ exit 0 - rebuild in new environment * Thu Apr 26 2001 Nalin Dahyabhai -- add patch from Tom Yu to fix ftpd overflows (#37731) +- add patch from Tom Yu to fix ftpd overflows (rhbz#37731) * Wed Apr 18 2001 Than Ngo - disable optimizations on the alpha again @@ -3268,7 +4150,7 @@ exit 0 - own %%{_var}/kerberos * Tue Feb 6 2001 Nalin Dahyabhai -- own the directories which are created for each package (#26342) +- own the directories which are created for each package (rhbz#26342) * Tue Jan 23 2001 Nalin Dahyabhai - gettextize init scripts @@ -3278,7 +4160,7 @@ exit 0 - re-enable optimization on alphas * Mon Jan 15 2001 Nalin Dahyabhai -- fix krb5-send-pr (#18932) and move it from -server to -workstation +- fix krb5-send-pr (rhbz#18932) and move it from -server to -workstation - buildprereq libtermcap-devel - temporariliy disable optimization on alphas - gettextize init scripts @@ -3290,29 +4172,29 @@ exit 0 - rebuild in new environment * Tue Oct 31 2000 Nalin Dahyabhai -- add bison as a BuildPrereq (#20091) +- add bison as a BuildPrereq (rhbz#20091) * Mon Oct 30 2000 Nalin Dahyabhai -- change /usr/dict/words to /usr/share/dict/words in default kdc.conf (#20000) +- change /usr/dict/words to /usr/share/dict/words in default kdc.conf (rhbz#20000) * Thu Oct 5 2000 Nalin Dahyabhai - apply kpasswd bug fixes from David Wragg * Wed Oct 4 2000 Nalin Dahyabhai -- make krb5-libs obsolete the old krb5-configs package (#18351) +- make krb5-libs obsolete the old krb5-configs package (rhbz#18351) - don't quit from the kpropd init script if there's no principal database so that you can propagate the first time without running kpropd manually - don't complain if /etc/ld.so.conf doesn't exist in the -libs %%post * Tue Sep 12 2000 Nalin Dahyabhai - fix credential forwarding problem in klogind (goof in KRB5CCNAME handling) - (#11588) -- fix heap corruption bug in FTP client (#14301) + (rhbz#11588) +- fix heap corruption bug in FTP client (rhbz#14301) * Wed Aug 16 2000 Nalin Dahyabhai - fix summaries and descriptions - switched the default transfer protocol from PORT to PASV as proposed on - bugzilla (#16134), and to match the regular ftp package's behavior + bugzilla (rhbz#16134), and to match the regular ftp package's behavior * Wed Jul 19 2000 Jeff Johnson - rebuild to compress man pages. @@ -3388,7 +4270,7 @@ exit 0 * Sat Jun 3 2000 Nalin Dahyabhai - use %%{_infodir} to better comply with FHS - move .so files to -devel subpackage -- tweak xinetd config files (bugs #11833, #11835, #11836, #11840) +- tweak xinetd config files (bugs rhbz#11833, rhbz#11835, rhbz#11836, rhbz#11840) - fix package descriptions again * Wed May 24 2000 Nalin Dahyabhai @@ -3425,7 +4307,7 @@ exit 0 - fix configure stuff for ia64 * Mon Apr 10 2000 Nalin Dahyabhai -- add LDCOMBINE=-lc to configure invocation to use libc versioning (bug #10653) +- add LDCOMBINE=-lc to configure invocation to use libc versioning (rhbz#10653) - change Requires: for/in subpackages to include %%{version} * Wed Apr 05 2000 Nalin Dahyabhai diff --git a/krb5kdc.logrotate b/krb5kdc.logrotate index 1100ed3..cfc4539 100644 --- a/krb5kdc.logrotate +++ b/krb5kdc.logrotate @@ -4,6 +4,6 @@ monthly rotate 12 postrotate - /bin/kill -HUP `cat /var/run/krb5kdc.pid 2>/dev/null` 2> /dev/null || true + systemctl reload krb5kdc.service || true endscript } diff --git a/krb5kdc.service b/krb5kdc.service index bc49204..40e23d6 100644 --- a/krb5kdc.service +++ b/krb5kdc.service @@ -1,12 +1,13 @@ [Unit] Description=Kerberos 5 KDC -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target [Service] Type=forking -PIDFile=/var/run/krb5kdc.pid +PIDFile=/run/krb5kdc.pid EnvironmentFile=-/etc/sysconfig/krb5kdc -ExecStart=/usr/sbin/krb5kdc -P /var/run/krb5kdc.pid $KRB5KDC_ARGS +ExecStart=/usr/sbin/krb5kdc -P /run/krb5kdc.pid $KRB5KDC_ARGS ExecReload=/bin/kill -HUP $MAINPID [Install] diff --git a/noport.c b/noport.c deleted file mode 100644 index 22088eb..0000000 --- a/noport.c +++ /dev/null @@ -1,111 +0,0 @@ -#define _GNU_SOURCE -#include -#include -#include -#include -#include -#include - -static int -port_is_okay(unsigned short port) -{ - char *p, *q; - long l; - - p = getenv("NOPORT"); - while ((p != NULL) && (*p != '\0')) { - l = strtol(p, &q, 10); - if ((q == NULL) || (q == p)) { - break; - } - if ((*q == '\0') || (*q == ',')) { - if (port == l) { - errno = ECONNREFUSED; - return -1; - } - } - p = q; - p += strspn(p, ","); - } - return 0; -} - -int -connect(int sockfd, const struct sockaddr *addr, socklen_t addrlen) -{ - unsigned short port; - static int (*next_connect)(int, const struct sockaddr *, socklen_t); - - if (next_connect == NULL) { - next_connect = dlsym(RTLD_NEXT, "connect"); - if (next_connect == NULL) { - errno = ENOSYS; - return -1; - } - } - - if (getenv("NOPORT") == NULL) { - return next_connect(sockfd, addr, addrlen); - } - - switch (addr->sa_family) { - case AF_INET: - port = ntohs(((struct sockaddr_in *)addr)->sin_port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - case AF_INET6: - port = ntohs(((struct sockaddr_in6 *)addr)->sin6_port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - default: - break; - } - return next_connect(sockfd, addr, addrlen); -} - -ssize_t -sendto(int sockfd, const void *buf, size_t len, int flags, - const struct sockaddr *dest_addr, socklen_t addrlen) -{ - unsigned short port; - static int (*next_sendto)(int, const void *, size_t, int, - const struct sockaddr *, socklen_t); - - if (next_sendto == NULL) { - next_sendto = dlsym(RTLD_NEXT, "sendto"); - if (next_sendto == NULL) { - errno = ENOSYS; - return -1; - } - } - - if (getenv("NOPORT") == NULL) { - return next_sendto(sockfd, buf, len, flags, dest_addr, addrlen); - } - - if (dest_addr != NULL) { - switch (dest_addr->sa_family) { - case AF_INET: - port = ((struct sockaddr_in *)dest_addr)->sin_port; - port = ntohs(port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - case AF_INET6: - port = ((struct sockaddr_in6 *)dest_addr)->sin6_port; - port = ntohs(port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - default: - break; - } - } - return next_sendto(sockfd, buf, len, flags, dest_addr, addrlen); -} diff --git a/plans/tests.fmf b/plans/tests.fmf new file mode 100644 index 0000000..970ae2e --- /dev/null +++ b/plans/tests.fmf @@ -0,0 +1,5 @@ +summary: Tests +discover: + how: fmf +execute: + how: tmt diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..a31a5e3 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,17 @@ +--- +inspections: + # https://bugzilla.redhat.com/show_bug.cgi?id=1956479 + badfuncs: off + + # Not a Java package + javabytecode: off + + # I need to be able to *add* functions, and also we export internal + # functions that are not considered part of our ABI. + abidiff: off + + # These just flag when things change "too much" + changedfiles: off + filesize: off + patches: off + upstream: off diff --git a/sources b/sources index a72430d..e8b99ef 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ -SHA512 (krb5-1.15.2-pdfs.tar) = 5875efde7ed88dcccd6f624a5252c5c70844fe94015ce4acfdf7f6ccabf52c86965c5a661b161c73e37b46e51aa5e9ea19602ab32e8b50682ecb0a450f0553b6 -SHA512 (krb5-1.15.2.tar.gz) = e5814bb66384b13637c37918df694c6b9933c29c2d952da0ed0dcd2e623b269060b4c16b6c02162039dadebdab99ff1085e37e7621ae4748dafb036424e612c2 -SHA512 (krb5-1.15.2.tar.gz.asc) = 37cee442de29229fa821539c3f1724eb4d37fa9ce5eee644869a7311c8fe10218dac36da3a5297d45168d8fb1ad64dbd614f10d3384d54e4070e56e7fe8a1e63 +SHA512 (krb5-1.21.3.tar.gz) = 87bc06607f4d95ff604169cea22180703a42d667af05f66f1569b8bd592670c42820b335e5c279e8b4f066d1e7da20f1948a1e4def7c5d295c170cbfc7f49c71 +SHA512 (krb5-1.21.3.tar.gz.asc) = 8992a5f5247315b9846aa73be4ee1ea223c0231a52d5c6c28718b1f3e3b45d62e2dad4aa5543a83163d1369bb79886b6c1c22766f22d8aa2f6b2575c54d0075c diff --git a/tests/got-audit/got-audit.gdb b/tests/got-audit/got-audit.gdb new file mode 100644 index 0000000..6661297 --- /dev/null +++ b/tests/got-audit/got-audit.gdb @@ -0,0 +1,2 @@ +gef config gef.disable_color True +got-audit --all diff --git a/tests/got-audit/kdc.conf b/tests/got-audit/kdc.conf new file mode 100644 index 0000000..ed7299f --- /dev/null +++ b/tests/got-audit/kdc.conf @@ -0,0 +1,12 @@ +[kdcdefaults] + kdc_ports = 88 + kdc_tcp_ports = 88 + +[realms] + ${krb5REALM1} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } diff --git a/tests/got-audit/krb5.conf b/tests/got-audit/krb5.conf new file mode 100644 index 0000000..6979cb7 --- /dev/null +++ b/tests/got-audit/krb5.conf @@ -0,0 +1,29 @@ +# To opt out of the system crypto-policies configuration of krb5, remove the +# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated. +includedir /etc/krb5.conf.d/ + +[logging] + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log + +[libdefaults] + default_realm = ${krb5REALM1} + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + default_ccache_name = KEYRING:persistent:%{uid} + +[realms] + ${krb5REALM1} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + +[domain_realm] + ${krb5HostName} = ${krb5REALM1} + +[capaths] + ${krb5REALM1} = . diff --git a/tests/got-audit/main.fmf b/tests/got-audit/main.fmf new file mode 100644 index 0000000..f2c1f97 --- /dev/null +++ b/tests/got-audit/main.fmf @@ -0,0 +1,12 @@ +summary: Audit the GOT for signs of tampering +description: | + Pointers in the server process GOT will be checked to ensure that + each function pointer's value is within a shared object file + that exports a symbol of that name, and that no shared object + files export conflicting symbols. +contact: Gordon Messmer +require+: + - gdb-gef # needed to test got-audit + - krb5-server +test: ./runtest.sh +framework: beakerlib diff --git a/tests/got-audit/runtest.sh b/tests/got-audit/runtest.sh new file mode 100755 index 0000000..925a04e --- /dev/null +++ b/tests/got-audit/runtest.sh @@ -0,0 +1,121 @@ +#!/bin/bash +# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/openssh/Sanity/got-audit +# Description: Check pointers in the server process GOT for signs of tampering +# Author: Gordon Messmer +# + +# Include Beaker environment +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +krb5REALM1='TEST1.REDHAT.COM' +krb5HostName=`hostname` +krb5DomainName=`hostname -d` +krb5User='alice' +krb5UserPass='alice' +krb5UserKrbPass='aaa' +krb5User2='bob' +krb5User3='carl' +krb5KDCPass='qwe' +krb5RootPass='rrr' + +krb5conf="/etc/krb5.conf" +krb5confdir="/etc/krb5.conf.d" +krb5kdcconf="/var/kerberos/krb5kdc/kdc.conf" +krb5kadmacl="/var/kerberos/krb5kdc/kadm5.acl" + +rlJournalStart + rlPhaseStartSetup + rlServiceStart sshd + rlRun "TestDir=\$(pwd)" + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlRun "auditfile=\$(mktemp --tmpdir=${TmpDir})" + rlPhaseEnd + + rlPhaseStartSetup "KDC and kadmind setup" + # Stop and backup + rlRun "rlServiceStop kadmin krb5kdc" + rlRun "rm -f /var/kerberos/krb5kdc/principal* /var/kerberos/krb5kdc/.k5*" + rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} /etc/hosts + rlFileBackup --clean /root/.k5login + [ -e /etc/krb5.keytab ] && rlFileBackup /etc/krb5.keytab + [ -e $krb5confdir ] && rlFileBackup $krb5confdir + # Basic setup of KDC and krb5.conf + rlRun "sed -i \"s/\[libdefaults\]/[libdefaults]\n default_realm = $krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM1 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + else + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n $krb5HostName = $krb5REALM1/\" $krb5conf" + fi + rlRun "sed -i s/EXAMPLE.COM/$krb5REALM1/ $krb5kdcconf" + # Configure the kadmin ACL + rlRun "echo \"*/master@$krb5REALM1 *\" > $krb5kadmacl" + if rlIsFedora '>=31';then + rlLog "Modify supported_enctypes for Fedora >=31. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + elif rlIsRHEL '8' && [ `rpm -q --qf '%{VERSION}' krb5-server | cut -d"." -f2` -lt 18 ];then + rlLog "Modify supported_enctypes for RHEL-8." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + else + #RHEL-8 Bug 1802334 - [Rebase] krb5: rebase to 1.18: + #- Removal of *DES encryption types + #https://bugzilla.redhat.com/show_bug.cgi?id=1802334 + rlLog "Modify supported_enctypes for RHEL-8 with krb-1.18. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + fi + # Create the realm databases + rlRun "rngd -r /dev/urandom" + rlRun "kdb5_util create -s -r $krb5REALM1 -P $krb5KDCPass" + rlRun "rlServiceStart kadmin krb5kdc" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5RootPass root/master\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5UserKrbPass $krb5User\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"ktadd host/$krb5HostName\"" + # Create test system user + [ $krb5User != "root" ] && rlRun "useradd $krb5User" + rlRun "echo $krb5UserPass | passwd --stdin $krb5User" + rlPhaseEnd + + rlPhaseStartTest "Run GEF got-audit" + rlRun "systemctl restart krb5kdc.service" + rlRun "systemctl restart kadmin.service" + rlRun "systemctl --no-pager status krb5kdc.service" + rlRun "systemctl --no-pager status kadmin.service" + + rlRun "SERVICE_PID=\$( systemctl show --property=MainPID krb5kdc.service | cut -f2 -d= )" + rlRun "echo SERVICE_PID is '$SERVICE_PID'" + [ -n "$SERVICE_PID" ] || rlFail "No service pid was found" + rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'" + # Basic test: ensure that at least one symbol is found in libc.so, + # to verify that the report looks plausible. + rlAssertGrep " : /.*/libc.so" "$auditfile" + # Ensure the got-audit did not report any errors + rlAssertNotGrep " :: ERROR" "$auditfile" + rlRun "cp '$auditfile' '$TMT_TEST_DATA'/krb5kdc-got-audit.txt" + + rlRun "SERVICE_PID=\$( systemctl show --property=MainPID kadmin.service | cut -f2 -d= )" + rlRun "echo SERVICE_PID is '$SERVICE_PID'" + [ -n "$SERVICE_PID" ] || rlFail "No service pid was found" + rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'" + # Basic test: ensure that at least one symbol is found in libc.so, + # to verify that the report looks plausible. + rlAssertGrep " : /.*/libc.so" "$auditfile" + # Ensure the got-audit did not report any errors + rlAssertNotGrep " :: ERROR" "$auditfile" + rlRun "cp '$auditfile' '$TMT_TEST_DATA'/kadmin-got-audit.txt" + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "rm -rf /var/kerberos/krb5kdc/* /var/kerberos/krb5kdc/.k5* /etc/krb5* /etc/sysconfig/{kadmin,krb5kdc}" + rlFileRestore + rlServiceRestore krb5kdc kadmin + [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalPrintText +rlJournalEnd diff --git a/tests/inplace-upgrade-sanity/Makefile b/tests/inplace-upgrade-sanity/Makefile new file mode 100644 index 0000000..cfff69d --- /dev/null +++ b/tests/inplace-upgrade-sanity/Makefile @@ -0,0 +1,65 @@ +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Makefile of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +# Description: Verifies basic scenarios which should work after inplace upgrade. +# Author: Patrik Kis +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Copyright (c) 2014 Red Hat, Inc. +# +# This copyrighted material is made available to anyone wishing +# to use, modify, copy, or redistribute it subject to the terms +# and conditions of the GNU General Public License version 2. +# +# This program is distributed in the hope that it will be +# useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR +# PURPOSE. See the GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public +# License along with this program; if not, write to the Free +# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, +# Boston, MA 02110-1301, USA. +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +export TEST=/CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +export TESTVERSION=1.0 + +BUILT_FILES= + +FILES=$(METADATA) runtest.sh Makefile PURPOSE + +.PHONY: all install download clean + +run: $(FILES) build + ./runtest.sh + +build: $(BUILT_FILES) + test -x runtest.sh || chmod a+x runtest.sh + +clean: + rm -f *~ $(BUILT_FILES) + + +include /usr/share/rhts/lib/rhts-make.include + +$(METADATA): Makefile + @echo "Owner: Patrik Kis " > $(METADATA) + @echo "Name: $(TEST)" >> $(METADATA) + @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) + @echo "Path: $(TEST_DIR)" >> $(METADATA) + @echo "Description: Verifies basic scenarios which should work after inplace upgrade." >> $(METADATA) + @echo "Type: Sanity" >> $(METADATA) + @echo "TestTime: 20m" >> $(METADATA) + @echo "RunFor: krb5" >> $(METADATA) + @echo "Requires: expect krb5-server krb5-workstation openssh-clients openssh-server rng-tools" >> $(METADATA) + @echo "Requires: setools-console" >> $(METADATA) + @echo "Priority: Normal" >> $(METADATA) + @echo "License: GPLv2" >> $(METADATA) + @echo "Confidential: no" >> $(METADATA) + @echo "Destructive: no" >> $(METADATA) + @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5" >> $(METADATA) + + rhts-lint $(METADATA) diff --git a/tests/inplace-upgrade-sanity/PURPOSE b/tests/inplace-upgrade-sanity/PURPOSE new file mode 100644 index 0000000..763d5a1 --- /dev/null +++ b/tests/inplace-upgrade-sanity/PURPOSE @@ -0,0 +1,3 @@ +PURPOSE of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +Description: Verifies basic scenarios which should work after inplace upgrade. +Author: Patrik Kis diff --git a/tests/inplace-upgrade-sanity/TC#0378369.fmf b/tests/inplace-upgrade-sanity/TC#0378369.fmf new file mode 100644 index 0000000..8d54d68 --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0378369.fmf @@ -0,0 +1,21 @@ +tag: + - CI-Tier-1 + - CI-Tier-1-krb5 + - Fedora 31 + - Fedora 32 + - FedoraReady + - IDM-CI-gating + - NoRHEL4 + - NoRHEL5 + - TIPpass + - TIPpass_Security + - Tier1 + - Tier1security + - rhel_upgrade +tier: '1' +adjust: + - enabled: false + when: distro == rhel-4, rhel-5 + continue: false +extra-nitrate: TC#0378369 +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test diff --git a/tests/inplace-upgrade-sanity/TC#0552039.fmf b/tests/inplace-upgrade-sanity/TC#0552039.fmf new file mode 100644 index 0000000..7f2731d --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0552039.fmf @@ -0,0 +1,17 @@ +link: + - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1394908 +tag: + - NoRHEL4 + - NoRHEL5 + - TIPpass + - TIPpass_Security + - Tier2 +tier: '2' +adjust: + - enabled: false + when: distro == rhel-4, rhel-5, rhel-6 + continue: false +environment: + TEST_ENTROPY_SOURCE: yes +extra-nitrate: TC#0552039 +extra-summary: 'BZ#1394908: Enable faster getrandom-based entropy system' diff --git a/tests/inplace-upgrade-sanity/TC#0608992.fmf b/tests/inplace-upgrade-sanity/TC#0608992.fmf new file mode 100644 index 0000000..440308f --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0608992.fmf @@ -0,0 +1,14 @@ +tag: + - Fedora 31 + - Fedora 32 + - FedoraReady + - NoRHEL4 + - NoRHEL5 + - rhel_upgrade +adjust: + - enabled: false + when: distro == rhel-4, rhel-5 + continue: false +manual: true +extra-nitrate: TC#0608992 +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test-manual diff --git a/tests/inplace-upgrade-sanity/kdc.conf b/tests/inplace-upgrade-sanity/kdc.conf new file mode 100644 index 0000000..d2212d0 --- /dev/null +++ b/tests/inplace-upgrade-sanity/kdc.conf @@ -0,0 +1,19 @@ +[kdcdefaults] + kdc_ports = 88 + kdc_tcp_ports = 88 + +[realms] + ${krb5REALM1} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } + ${krb5REALM2} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } diff --git a/tests/inplace-upgrade-sanity/krb5.conf b/tests/inplace-upgrade-sanity/krb5.conf new file mode 100644 index 0000000..18b40b6 --- /dev/null +++ b/tests/inplace-upgrade-sanity/krb5.conf @@ -0,0 +1,36 @@ +# To opt out of the system crypto-policies configuration of krb5, remove the +# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated. +includedir /etc/krb5.conf.d/ + +[logging] + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log + +[libdefaults] + default_realm = ${krb5REALM1} + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + default_ccache_name = KEYRING:persistent:%{uid} + +[realms] + ${krb5REALM1} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + ${krb5REALM2} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + +[domain_realm] + ${krb5HostName} = ${krb5REALM1} + ${krb5HostName} = ${krb5REALM2} + +[capaths] + ${krb5REALM1} = { + ${krb5REALM2} = . + } diff --git a/tests/inplace-upgrade-sanity/main.fmf b/tests/inplace-upgrade-sanity/main.fmf new file mode 100644 index 0000000..40e0a0e --- /dev/null +++ b/tests/inplace-upgrade-sanity/main.fmf @@ -0,0 +1,19 @@ +summary: Verifies basic scenarios which should work after inplace upgrade. +enabled: true +contact: Filip Dvorak +component: +- krb5 +test: ./runtest.sh +path: /tests/inplace-upgrade-sanity +framework: beakerlib +require: +- expect +- krb5-server +- krb5-workstation +- openssh-clients +- openssh-server +- rng-tools +- setools-console +duration: 20m +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +extra-task: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test diff --git a/tests/inplace-upgrade-sanity/runtest.sh b/tests/inplace-upgrade-sanity/runtest.sh new file mode 100755 index 0000000..c6e3d45 --- /dev/null +++ b/tests/inplace-upgrade-sanity/runtest.sh @@ -0,0 +1,376 @@ +#!/bin/bash +# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +# Description: Verifies basic scenarios which should work after inplace upgrade. +# Author: Patrik Kis +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Copyright (c) 2014 Red Hat, Inc. +# +# This copyrighted material is made available to anyone wishing +# to use, modify, copy, or redistribute it subject to the terms +# and conditions of the GNU General Public License version 2. +# +# This program is distributed in the hope that it will be +# useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR +# PURPOSE. See the GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public +# License along with this program; if not, write to the Free +# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, +# Boston, MA 02110-1301, USA. +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +# Include Beaker environment +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +PACKAGE="krb5" +PACKAGES="krb5-libs krb5-server krb5-workstation openssh" + +TEST_ENTROPY_SOURCE=${TEST_ENTROPY_SOURCE:-no} +echo TEST_ENTROPY_SOURCE=$TEST_ENTROPY_SOURCE + +krb5REALM1='TEST1.REDHAT.COM' +krb5REALM2='TEST2.REDHAT.COM' +krb5HostName=`hostname` +krb5DomainName=`hostname -d` +krb5User='alice' +krb5UserPass='alice' +krb5UserKrbPass='aaa' +krb5User2='bob' +krb5User3='carl' +krb5KDCPass='qwe' +krb5RootPass='rrr' + +krb5conf="/etc/krb5.conf" +krb5confdir="/etc/krb5.conf.d" +krb5kdcconf="/var/kerberos/krb5kdc/kdc.conf" +krb5kadmacl="/var/kerberos/krb5kdc/kadm5.acl" + + + +rlJournalStart + rlPhaseStartSetup + for pkg in $PACKAGES; do + rlAssertRpm $pkg + done + rlRun "TmpDir=\$(mktemp -d)" + rlRun "pushd $TmpDir" + echo "-----/etc/krb5.conf----"; cat /etc/krb5.conf + echo "-----/var/kerberos/krb5kdc/kdc.conf-----"; cat /var/kerberos/krb5kdc/kdc.conf + rlPhaseEnd + + # Run this part on OLD and in "normal" mode + if [[ -z $IN_PLACE_UPGRADE || $IN_PLACE_UPGRADE == old ]]; then + rlPhaseStartSetup "KDC and kadmind setup" + # Stop and backup + rlRun "rlServiceStop kadmin krb5kdc" + rlRun "rm -f /var/kerberos/krb5kdc/principal* /var/kerberos/krb5kdc/.k5*" + rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} /etc/hosts + rlFileBackup --clean /root/.k5login + [ -e /etc/krb5.keytab ] && rlFileBackup /etc/krb5.keytab + [ -e $krb5confdir ] && rlFileBackup $krb5confdir + # Make sure IPv4 is used for ssh connection + if ! grep `hostname` /etc/hosts; then + DEF_DEV=`ip route |grep default |awk '{print $5}'` + echo DEF_DEV=$DEF_DEV + DEF_IP=`ip -o -4 addr show dev $DEF_DEV |awk '{print $4}' |grep -v '/32' |sed 's|/.*||'` + echo DEF_IP=$DEF_IP + rlRun "echo '$DEF_IP `hostname`' >>/etc/hosts" + grep `hostname` /etc/hosts + fi + # Basic setup of KDC and krb5.conf + if rlIsRHEL 6; then + rlRun "sed -i \"s/EXAMPLE.COM/$krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/kerberos.example.com/$krb5HostName/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/example.com/$krb5DomainName/\" $krb5conf" + fi + else + rlRun "sed -i \"s/\[libdefaults\]/[libdefaults]\n default_realm = $krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM1 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + else + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n $krb5HostName = $krb5REALM1/\" $krb5conf" + fi + fi + rlRun "sed -i s/EXAMPLE.COM/$krb5REALM1/ $krb5kdcconf" + # Configure the kadmin ACL + rlRun "echo \"*/master@$krb5REALM1 *\" > $krb5kadmacl" + # Configure the 2nd realmd + cat >>$krb5kdcconf <<_EOF + + $krb5REALM2 = { + #master_key_type = aes256-cts + database_name = /var/kerberos/krb5kdc/principal.$krb5REALM1 + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal +} +_EOF + + +if rlIsRHEL '7'; then + rlLog "Modify supported_enctypes for RHEL-7." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal/\" /var/kerberos/krb5kdc/kdc.conf" + # Remove 3DES and DES cipher suite from kdc.conf - Fedora 31 + # Fedora 31 - krb5 will be removing support for DES, 3DES, and crc-32 entirely + # they will not be allowed in session keys or long-term keys. (BZ#1670398) + # https://fedoraproject.org/wiki/Changes/krb5_crypto_modernization +elif rlIsFedora '>=31';then + rlLog "Modify supported_enctypes for Fedora >=31. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +elif rlIsRHEL '8' && [ `rpm -q --qf '%{VERSION}' krb5-server | cut -d"." -f2` -lt 18 ];then + rlLog "Modify supported_enctypes for RHEL-8." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +else + #RHEL-8 Bug 1802334 - [Rebase] krb5: rebase to 1.18: + #- Removal of *DES encryption types + #https://bugzilla.redhat.com/show_bug.cgi?id=1802334 + rlLog "Modify supported_enctypes for RHEL-8 with krb-1.18. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +fi + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM2 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + cat >> $krb5conf << _EOF + +[capaths] + $krb5REALM1 = { + $krb5REALM2 = . + } +_EOF + # BZ#1394908: Test the entropy source (not relevant for RHEL6) + if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then + rlLog "BZ#1394908: The source of entropy will be tested as well" + # Check number of audit rules + number_rules=$(auditctl -l | grep -v "No rules" | wc -l) + if [[ ${number_rules} -ne 0 ]];then + truncate -s0 /var/log/audit/audit.log + rlRun "auditctl -D" 0 "Delete previous audit rules" + fi + START_DATE=`date +%H:%M:%S` + echo START_DATE=$START_DATE + sleep 1 + rlRun "auditctl -w /dev/random -p rwxa -k RAND" + auditctl -l + sleep 5 + rlRun "ausearch -i -k RAND -ts $START_DATE" + fi + + echo "-----/etc/krb5.conf----"; cat /etc/krb5.conf + echo "-----/var/kerberos/krb5kdc/kdc.conf-----"; cat /var/kerberos/krb5kdc/kdc.conf + + # Create the realm databases + rlRun "rngd -r /dev/urandom" + rlRun "kdb5_util create -s -r $krb5REALM1 -P $krb5KDCPass" + rlRun "kdb5_util create -s -r $krb5REALM2 -P $krb5KDCPass" + # Configure KDC to handle 2 realms + if rlIsRHEL 6; then + rlRun "echo \"KRB5REALM=$krb5REALM1\" > /etc/sysconfig/krb5kdc" + rlRun "echo KRB5KDC_ARGS=\\\"-r $krb5REALM2\\\" >> /etc/sysconfig/krb5kdc" + else + rlRun "echo KRB5KDC_ARGS=\\\"-r $krb5REALM1 -r $krb5REALM2 \\\" >/etc/sysconfig/krb5kdc" + fi + rlRun "rlServiceStart kadmin krb5kdc" + # Add krb5 principals for the 2nd realm + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5RootPass root/master\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5UserKrbPass $krb5User\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"ktadd host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" + # Add krb5 principals for the 2nd realm + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5UserKrbPass $krb5User2\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" + # Create test system user + [ $krb5User != "root" ] && rlRun "useradd $krb5User" + rlRun "echo $krb5UserPass | passwd --stdin $krb5User" + rlPhaseEnd + fi + + rlPhaseStartTest "Daemon start and log file test" + # Make sure there is enough entropy and start recording of the logs + rlRun "rngd -r /dev/urandom" + if grep -q krb5kdc /var/log/krb5kdc.log; then + tail -n0 -f /var/log/krb5kdc.log &> krb5kdc.log.record & + KRB5KDC_LOG_PID=$! + echo "log_record_start: PID = $KRB5KDC_LOG_PID" + sleep 1 + elif journalctl |grep -q krb5kdc; then + journalctl -f &> krb5kdc.log.record & + KRB5KDC_LOG_PID=$! + echo "log_record_start: PID = $KRB5KDC_LOG_PID" + sleep 1 + else + rlFail "Could not find krb5kdc logs" + echo "journalctl:" + journalctl -n 100 + ls -la /var/log/krb5kdc* + echo "/var/log/krb5kdc.log:" + tail -n 100 /var/log/krb5kdc.log + fi + if grep -q kadmind /var/log/kadmind.log; then + tail -n0 -f /var/log/kadmind.log &> kadmind.log.record & + KADMIND_LOG_PID=$! + echo "log_record_start: PID = $KADMIND_LOG_PID" + sleep 1 + elif journalctl |grep -q kadmind; then + journalctl -f &> kadmind.log.record & + KADMIND_LOG_PID=$! + echo "log_record_start: PID = $KADMIND_LOG_PID" + sleep 1 + else + rlFail "Could not find kadmind logs" + echo "journalctl:" + journalctl -n 100 + ls -la /var/log/kadmind* + echo "/var/log/kadmind.log:" + tail -n 100 /var/log/kadmind.log + fi + + #add 'list' privilege for root/master + sed -i -e '$a*/master@EXAMPLE.COM *' /var/kerberos/krb5kdc/kadm5.acl + + # Restart daemon auto start + if rlIsRHEL 6; then + rlRun "service krb5kdc restart" + rlRun "service kadmin restart" + rlRun "service krb5kdc status" + rlRun "service kadmin status" + else + rlRun "systemctl restart krb5kdc.service" + rlRun "systemctl restart kadmin.service" + rlRun "systemctl --no-pager status krb5kdc.service" + rlRun "systemctl --no-pager status kadmin.service" + fi + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "kdestroy" + rlRun "kadmin -p root/master -w rrr -q 'getprincs'" + rlAssertGrep "AS_REQ.*$krb5User@$krb5REALM1.*krbtgt/$krb5REALM1@$krb5REALM1" krb5kdc.log.record + +#The principal related to kadmin are not created with hostname (kadmin/hostname@REALM) during creating krb5 DB +#RHEL9 constains only kadmin/admin@REALM - this change was intentional - Don't create hostbased principals in new KDBs +#https://krbdev.mit.edu/rt/Ticket/Display.html?id=8935 + if rlIsRHEL 9 || rlIsFedora '>=33';then + kadmin_princ="Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/admin@$krb5REALM1" + else + kadmin_princ="Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/.*`hostname`@$krb5REALM1" + fi + rlAssertGrep "${kadmin_princ}" kadmind.log.record + #rlAssertGrep "Request: kadm5_init.*root\/master@$krb5REALM1.*service=kadmin\/(admin|.*`hostname`)@$krb5REALM1" kadmind.log.record -E + echo "***krb5kdc.log.record***" && cat krb5kdc.log.record + echo "***kadmind.log.record***" && cat kadmind.log.record + # Stop log recording + kill $KADMIND_LOG_PID + kill $KRB5KDC_LOG_PID + rlPhaseEnd + + rlPhaseStartTest "SSH test" + cat > sshtest.exp <<'_EOF' +#!/usr/bin/expect -f +set USER [lindex $argv 0] +set HOST [lindex $argv 1] +set timeout 15 +spawn ssh $USER@$HOST pwd +expect { + -re ".*(yes/no).*" { send -- "yes\r"; exp_continue } + -re ".*password:.*" { exit 1 } + "/home/$USER" { exit 0 } + timeout { exit 2 } + eof { exit 3 } +} +exit 4 +_EOF + chmod 744 sshtest.exp + rlAssertExists sshtest.exp + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "./sshtest.exp $krb5User $krb5HostName"; echo + rlRun "klist &>klist.log" + cat klist.log + rlAssertGrep "host/`hostname`@$krb5REALM1" klist.log + rlRun "kdestroy" + #BZ1841488-sshd cannot write into reply cache (/var/tmp/krb5_0.rcache2) due to security context + #The problem is that this file had security context: system_u:object_r:kadmind_tmp_t:s0. + #This is a problem when the ssh via krb5-GSSAPI is used because sshd service cannot write into this file. + if rlIsRHEL '>=8.3' || rlIsFedora '>=32'; then + rlLog "BZ1841488-sshd cannot write into reply cache (/var/tmp/krb5_0.rcache2) due to security context" + rlRun "sesearch -s sshd_t -t kadmind_tmp_t -c file -p write --allow | grep ^allow" + fi + rlPhaseEnd + + rlPhaseStartTest "Basic kadmin and kpasswd test" + rlRun "kadmin.local -q \"listprincs\" |grep -v Authenticating >lplocal" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"listprincs\" |grep -v Authenticating >lpremote" + rlAssertNotDiffer lplocal lpremote || diff -u lplocal lpremote + diff lplocal lpremote + rlRun "kadmin -p root/master -w $krb5RootPass -q \"addprinc -pw $krb5User2 $krb5User2@$krb5REALM1\"" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"listprincs\" | grep \"$krb5User2@$krb5REALM1\"" + + rlRun "echo $krb5User2 | kinit $krb5User2" + rlRun "echo -e \"$krb5User2\nqwerty\nqwerty\" | kpasswd &>kpasswd.log" + cat kpasswd.log + rlAssertGrep "Password changed." kpasswd.log + rlRun "echo qwerty | kinit $krb5User2" + rlRun "kdestroy" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"delprinc -force $krb5User2@$krb5REALM1\"" + rlPhaseEnd + + rlPhaseStartTest "Basic ksu test" + [[ -f /root/.k5login ]] && rlRun "mv /root/.k5login ." + rlRun "echo $krb5User@$krb5REALM1 > /root/.k5login" + rlRun "su - $krb5User -c \"echo $krb5UserKrbPass | kinit $krb5User\"" + rlRun "su - $krb5User -c \"ksu -e /usr/bin/id\" &> ksu.log" + cat ksu.log + rlAssertGrep "^uid=0(root) gid=0(root)" ksu.log + rlRun "su - $krb5User -c kdestroy" + [[ -f .k5login ]] && rlRun "mv .k5login /root/.k5login" + rlPhaseEnd + + rlPhaseStartTest "Cross realm test" + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "kvno host/`hostname`@$krb5REALM2" + rlRun "klist &>klist.log" + cat klist.log + rlAssertGrep "krbtgt/$krb5REALM1@$krb5REALM1" klist.log + rlAssertGrep "krbtgt/$krb5REALM2@$krb5REALM1" klist.log + rlAssertGrep "host/`hostname`@$krb5REALM2" klist.log + rlRun "kdestroy" + rlPhaseEnd + + # BZ#1394908: Test the entropy source (not relevant for RHEL6) + if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then + rlPhaseStartTest "BZ#1394908: Enable faster getrandom-based entropy system" + echo START_DATE=$START_DATE + auditctl -l + sleep 5 + rlRun "ausearch -i -k RAND -ts $START_DATE" + rlRun "ausearch -i -k RAND -ts $START_DATE |grep comm= | grep -v comm=auditctl |grep -v 'comm=rngd'" 1 + rlRun "auditctl -D" + rlPhaseEnd + fi + + # Run this part on "normal" mode; in inplace upgrade no cleanup is needed + if [[ -z $IN_PLACE_UPGRADE ]]; then + rlPhaseStartCleanup "KDC and kadmind cleanup" + rlRun "rm -rf /var/kerberos/krb5kdc/* /var/kerberos/krb5kdc/.k5* /etc/krb5* /etc/sysconfig/{kadmin,krb5kdc}" + rlFileRestore + rlRun "rlServiceRestore krb5kdc kadmin" + [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" + rlPhaseEnd + fi + + rlPhaseStartCleanup + rlRun "kdestroy -A" + rlRun "popd" + rlRun "rm -r $TmpDir" + rlPhaseEnd +rlJournalPrintText +rlJournalEnd diff --git a/tests/upstream/main.fmf b/tests/upstream/main.fmf new file mode 100644 index 0000000..66718fa --- /dev/null +++ b/tests/upstream/main.fmf @@ -0,0 +1,7 @@ +summary: Run upstream tests +test: ./test.sh +enabled: true +path: /tests/upstream +require: +- krb5-tests +duration: 20m diff --git a/tests/upstream/test.sh b/tests/upstream/test.sh new file mode 100755 index 0000000..fd4aeeb --- /dev/null +++ b/tests/upstream/test.sh @@ -0,0 +1,7 @@ +#!/bin/sh -eux +rc=0 +for test_exec in /usr/libexec/krb5-tests-* +do + "$test_exec" || rc=1 +done +exit $rc